← Back

Wire · regulatory

AEPD fines Gestora Clubs DiR €21000 for lacking valid DPIA for biometric access system

Published

16 July 2026

Topic

regulatory

Sectors

Cybersecurity

Geography

Spain

Source

Read at dataguidance.com

Verified

Fusion42 · 16 July 2026 · Fusion42 review

Spain's AEPD fined Gestora Clubs DiR €21,000 for operating a biometric fingerprint access system for 95,000 gym users without a valid Data Protection Impact Assessment, as required by GDPR Article 35. The company must submit a compliant DPIA within three months.

This Wire brief sits within Fusion42's coverage of Cybersecurity.

◆ The Wire takeaway

If you're building a physical access system that uses fingerprints, faces or any biometric data, you need a certified DPIA before launch—not after a complaint arrives. Spain just made this concrete: incomplete assessment costs €21,000 minimum, and regulators are auditing what you wrote, not just that you wrote something.

Coverage

1 source · 16 Jul 2026

Related on Wire

Topics

Cybersecuritygdpr-enforcementbiometric-datadpia-requirementfitness-clubshigh-risk-processing