Spain’s top professional football league, La Liga, has been hit with a €1 million fine by the Spanish Data Protection Agency (AEPD) for violations related to its biometric access systems. The penalty comes amid increasing regulatory scrutiny of biometric data collection practices across Europe.
The AEPD determined that La Liga implemented biometric access controls, likely including facial recognition or fingerprint scanning technology, without establishing proper legal grounds or implementing necessary data protection safeguards as required under the General Data Protection Regulation (GDPR).
This fine follows a similar penalty issued to Spanish football club Osasuna in January, where the club was fined €200,000 for unauthorized facial recognition systems at their stadium. The escalating fines suggest Spanish authorities are taking an increasingly strict stance on biometric data protection compliance in sports venues.
The AEPD’s investigation revealed two primary GDPR violations: La Liga failed to establish legitimate legal grounds for processing sensitive biometric data and did not implement sufficient protective measures for the collected personal information. These requirements are particularly crucial given the EU’s ongoing development of comprehensive AI and data protection regulations.
The timing of this enforcement action is significant as La Liga has been expanding its technological initiatives, including recent partnerships in blockchain and cryptocurrency sectors. The substantial fine may impact how the organization approaches future technology implementations, particularly those involving personal data collection.
La Liga has not yet issued a public response to the fine, and it remains unclear whether the organization plans to appeal the decision or what specific measures it will take to address the identified GDPR violations.
This case reflects a broader trend of increased regulatory oversight of biometric systems across various sectors. Recent legislative updates in jurisdictions worldwide have introduced stricter rules for handling biometric data, emphasizing the need for organizations to carefully consider privacy implications before implementing such technologies.
Sources: MLex, PR Newswire
—
March 1, 2025 – by the ID Tech Editorial Team





Follow Us