All news
Enforcement May 25, 2026 8 min

Spain: AEPD fines Aena EUR 10 million for biometric boarding without adequate DPIA

November 2025 - the Spanish airport operator launched facial recognition at 8 airports without a complete impact assessment. Biometrics is the new enforcement frontier

TL;DR for the DPO

November 2025: Spain's AEPD fines Aena (airport operator) EUR 10,043,002. The facial-recognition boarding system was launched at 8 airports WITHOUT an adequate DPIA. The Authority's conclusion was not that the system was insecure: it was that the preventive impact assessment required by Art. 35 GDPR for high-risk biometric processing was missing. Biometrics is the 2025-2026 enforcement focus.

The facts

Aena, the operator of Spanish airports, deployed a facial-recognition boarding system at eight major airports. The processing involves biometric data, a special category under Art. 9 GDPR, high-risk by definition. The AEPD found Aena had launched the programme without completing an adequate DPIA before activation.

10MEUR
AEPD fine
8
Airports involved

The point: a fine WITHOUT a breach

Aena suffered no data breach. No data was compromised. The fine is for a failure of PREVENTIVE accountability: not having done the adequate DPIA BEFORE activating the processing. Authorities no longer wait for the incident.

Official source:Spanish Compliance Institute

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement
26complaints, and no fine

You declare contract, then you reject the objections: Norway shows how the two mistakes travel together

SATS asked members for a photo kept in the membership system and used at the desk to check the identity of people coming in. Datatilsynet found the notice stated the wrong legal basis, failed to explain the right to object, and that objections were rejected without demonstrating compelling legitimate grounds. The deadline to fix it is 11 September 2026.

Aug 26, 2026New 6 min
Enforcement
825 mln €the second-largest fine ever

Eight hundred and twenty-five million for an algorithm that deactivated accounts with nobody looking

It is the second-largest fine ever imposed under the GDPR, behind only Meta's 1.2 billion. It is not about a data transfer or a security breach: it is about Article 22, the rule on automated decisions that almost nobody documents because it looks like a big-platform problem. It is in fact about anyone who lets software decide something that weighs on a person's life.

Aug 24, 2026New 5 min
Enforcement
64 mln złagainst 14 the year before

Poland quadrupled its fines in a year, and the three highest ever all date from 2025

For years Poland was treated as a low-enforcement market. That assumption no longer holds: in twelve months the total went from fourteen to over sixty-four million zloty, and the three largest fines in the country's history all carry the same year. If you look after a client with a branch, a supplier or a service centre in Poland, the risk calculation has changed.

Aug 24, 2026New 4 min