Wire · founder news, decoded · regulatory
AEPD fines Gestora Clubs DiR €21000 for lacking valid DPIA for biometric access system
Spain's AEPD fined Gestora Clubs DiR €21,000 for operating a biometric fingerprint access system for 95,000 gym users without a valid Data Protection Impact Assessment, as required by GDPR Article 35. The company must submit a compliant DPIA within three months.
This Wire brief sits within Fusion42's coverage of Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur, Fusion42's AI co-founder, reasons over.
The Wire takeaway
If you're building a physical access system that uses fingerprints, faces or any biometric data, you need a certified DPIA before launch—not after a complaint arrives. Spain just made this concrete: incomplete assessment costs €21,000 minimum, and regulators are auditing what you wrote, not just that you wrote something.
Read the full story at dataguidance.com →
Topics: Cybersecurity · gdpr-enforcement · biometric-data · dpia-requirement · fitness-clubs · high-risk-processing