Wire · regulatory
AEPD fines Gestora Clubs DiR €21000 for lacking valid DPIA for biometric access system
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 16 July 2026 · Fusion42 review
Spain's AEPD fined Gestora Clubs DiR €21,000 for operating a biometric fingerprint access system for 95,000 gym users without a valid Data Protection Impact Assessment, as required by GDPR Article 35. The company must submit a compliant DPIA within three months.
This Wire brief sits within Fusion42's coverage of Cybersecurity.
◆ ◆ The Wire takeaway
If you're building a physical access system that uses fingerprints, faces or any biometric data, you need a certified DPIA before launch—not after a complaint arrives. Spain just made this concrete: incomplete assessment costs €21,000 minimum, and regulators are auditing what you wrote, not just that you wrote something.
◆ Coverage
1 source · 16 Jul 2026
◆ Related on Wire
◆ Topics