On 3 March, the Spanish Data Protection Agency (AEPD) published its Decision in the sanctioning proceedings against Futbol Club Barcelona (FCB or the Club). The proceedings were initiated following several complaints submitted by members after receiving a request from the Club to identify themselves through an online process in order to keep the members’ register up to date.
The procedure consisted of comparing a photograph of the National Identity Document or Passport with real-time, moving selfies. The purpose of the update was not only to comply with the Club’s Statutes, but also to prevent fraud, such as relatives failing to inform the Club of the death of a member in order to continue using that member’s season ticket, or the transfer of membership and season tickets to third parties for payment. Failure to complete the process resulted in termination of membership.
In addition, the process allowed members, on a voluntary basis, to create a digital profile by recording their voice in order to prevent fraud in remote procedures, such as ticket purchases, free seat management, and similar transactions.
In its response to the transfer of the complaint and request for information, FCB stated, among other things: (i) that the procedure was not mandatory, as members could attend the OAB, the Supporters’ Services Office, in person, although it was proven that the Club prioritised the online procedure and did not clearly indicate the possibility of appearing in person to complete the process; (ii) that the data collected could not be considered special categories of data, as the system compared two photographs and did not perform a unique comparison of the member against a database of individuals; (iii) that the Club had analysed the data lifecycle and assessed the risks, concluding that the risk was low and that, therefore, it was not necessary to carry out a Data Protection Impact Assessment (DPIA); and (iv) that the proportionality assessment concluded that the system was the most suitable due to the number of members —143,000, of whom 14,511 were minors— and their geographical dispersion.
However, the AEPD rejected all of FCB’s arguments, placing particular emphasis on the alleged lack of need to carry out a DPIA. In this regard, the AEPD argued that a DPIA was indeed required because the processing operations, both the update of the members’ register and the creation of a digital profile, met five of the criteria included in the indicative list of types of processing requiring a data protection impact assessment under Article 35.4 of the GDPR. These criteria were: automated decision-making, since the comparison was carried out without human intervention through algorithms; the use of biometric data; large-scale processing, as it affected all members; the processing of data relating to vulnerable data subjects, namely children under the age of 14; and the use of new technologies.
Although FCB initially informed the AEPD that its risk assessment had concluded that a DPIA was not necessary, following the commencement of the sanctioning proceedings, the Club submitted two analysis reports which, in its view, contained the essential elements of a DPIA and therefore had technically been carried out.
After examining the reports submitted, the AEPD concluded that the reports provided by FCB could not be regarded either as a DPIA or as a risk analysis, as they suffered from the following deficiencies: (i) the reports were dated after the engagement of the processors. It was therefore impossible for the risks to have been determined when deciding what security measures the processor had to implement, or even when determining whether the processing could be carried out at all; (ii) the document set out conclusions without any documentary support. There was no prior work supported by documentation demonstrating proactive accountability; (iii) the recommendation of the DPO was included, stating that the online updating of the members’ register should be voluntary, which indicated the existence of a less intrusive alternative, given that most members resided in Barcelona and its metropolitan area; (iv) the reports justified the need for the processing by stating that other alternatives had been ruled out, without examining —or even identifying— those alternatives, which revealed a deficient assessment of the necessity and proportionality of the processing; (v) there was a lack of knowledge of the processing operation, as the AEPD considered that the data lifecycle described in the documents was so generic that it could apply to any processing operation. Without a detailed description, it is difficult to determine the risks, their likelihood and impact, and the appropriate technical and organisational measures to be adopted; (vi) there was no evidence that the opinion of members had been sought, which is an explicit requirement in the content of a DPIA; and (vii) no action and monitoring plan was defined.
Finally, the AEPD stated that the reports “appear rather to be a mere formal endorsement of a decision already taken”, recalling that risk assessments and impact assessments are not mere formalities, but genuine substantive obligations required to comply with the principle of proactive accountability and to “support the pillar of the GDPR’s risk-based approach”.
This Decision is in line with the also recent sanction imposed on AENA for creating a facial recognition system without first carrying out the corresponding risk analysis. In that case, the AEPD concluded that the DPIA did not include all the concurrent risks, did not contain the inherent risk but only the residual risk of each measure, that the mitigation measures were not truly such and, in many cases, were not even classified as mitigation, elimination, or similar measures, and, above all, that it did not contain an assessment of the overall level of risk. In addition, the AEPD considered that the proportionality analysis had not been carried out from a data protection perspective, but rather from the standpoint of commercial service, effectiveness and efficiency criteria.
Therefore, this Decision once again emphasises the importance of the Principle of Proactive Accountability and Data Protection by Design and by Default. The failure to comply with these principles has cost FCB a fine of €500,000 and AENA a fine of €10,000,000, equivalent to 0.228% of its turnover.





