Wireby Fusion42
Read this story on the live Wire →

Wire · founder news, decoded · regulatory

AEPD fines Gestora Clubs DiR €21000 for lacking valid DPIA for biometric access system

Spain's AEPD fined Gestora Clubs DiR €21,000 for operating a biometric fingerprint access system for 95,000 gym users without a valid Data Protection Impact Assessment, as required by GDPR Article 35. The company must submit a compliant DPIA within three months.

This Wire brief sits within Fusion42's coverage of Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur, Fusion42's AI co-founder, reasons over.

The Wire takeaway

If you're building a physical access system that uses fingerprints, faces or any biometric data, you need a certified DPIA before launch—not after a complaint arrives. Spain just made this concrete: incomplete assessment costs €21,000 minimum, and regulators are auditing what you wrote, not just that you wrote something.

Read the full story at dataguidance.com

Topics: Cybersecurity · gdpr-enforcement · biometric-data · dpia-requirement · fitness-clubs · high-risk-processing

Related on Wire

Verified 16 July 2026 · Sources: Fusion42 review

AEPD fines Gestora Clubs DiR €21000 for lacking valid… | Fusion42