The Spanish authority imposes a sanction on the Spanish Cycling Federation for a personal data breach affecting over 260,000 individuals

The Spanish Data Protection Authority has fined the Spanish Cycling Federation €4,800 for a security failure that led to a personal data breach affecting more than 260,000 individuals, including nearly 15,000 minors, due to a vulnerability allowing unauthorized access through simple URL manipulation.

Facts and context

The Spanish Data Protection Authority (AEPD) today published a sanction decision against the Spanish Cycling Federation, including the imposition of a €4,800 fine, for failures related to the security of personal data following a data breach.

The case originated from a personal data breach notification by the federation itself on August 8, 2024, after detecting massive and unauthorized consultations of licensee records.

Grounds for the decision

  • Obligation of integrity and confidentiality (Article 5(1)(f) of the GDPR): The authority concluded a violation of this principle due to the absence of appropriate technical and organizational measures to ensure data security. A vulnerability on the federation's platform allowed an authenticated user to access the personal data of 261,965 other licensees, including 14,912 minors, by manipulating the consultation URL. This flaw, active from July 24 to September 30, 2024, exposed various data including names, contact details, photographs, and identity document numbers. The AEPD considered that the lack of basic measures, such as multi-factor authentication, constituted negligence by the data controller.

Authority's decision

Consequently, the authority imposed a €4,800 fine on the Spanish Cycling Federation. The initial amount of €8,000 was reduced by 40% following the recognition of responsibility and voluntary payment by the organization.

Furthermore, the authority ordered the federation to notify it, within six months from the finality of the decision, of the corrective measures implemented to comply with the regulation.

Lessons learned

This decision reminds that:

  • The absence of fundamental security measures, such as multi-factor authentication, to protect access to personal data, is likely to be qualified as negligence by a supervisory authority.
  • The processing of personal data concerning a large number of minors constitutes an aggravating factor in assessing the severity of a breach and calculating the sanction.
  • Active cooperation with the authority, notably through recognition of responsibility and prompt payment of the sanction, can allow a significant reduction of the fine amount.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire