TL;DR for the DPO
November 2025: Spain's AEPD fines Aena (airport operator) EUR 10,043,002. The facial-recognition boarding system was launched at 8 airports WITHOUT an adequate DPIA. The Authority's conclusion was not that the system was insecure: it was that the preventive impact assessment required by Art. 35 GDPR for high-risk biometric processing was missing. Biometrics is the 2025-2026 enforcement focus.
The facts
Aena, the operator of Spanish airports, deployed a facial-recognition boarding system at eight major airports. The processing involves biometric data, a special category under Art. 9 GDPR, high-risk by definition. The AEPD found Aena had launched the programme without completing an adequate DPIA before activation.
The point: a fine WITHOUT a breach
Aena suffered no data breach. No data was compromised. The fine is for a failure of PREVENTIVE accountability: not having done the adequate DPIA BEFORE activating the processing. Authorities no longer wait for the incident.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free