Support Centre

You have out of 5 free articles left for the month

Signup for a trial to access unlimited content.

Start Trial

Continue reading on DataGuidance with:

Free Member

Limited Articles

Create an account to continue accessing select articles, resources, and guidance notes.

Free Trial

Unlimited Access

Start your free trial to access unlimited articles, resources, guidance notes, and workspaces.

Spain: AEPD fines GSMA €200,000 for failing to carry out DPIA

The Spanish data protection authority ('AEPD') published, on 4 May 2023, its decision in Proceeding No. PS-00553-2021, as issued on 24 February 2023, in which it imposed a fine of €200,000 on GSMA, Ltd., for violation of Article 35 of the General Data Protection Regulation (Regulation (EU) 2016/679) ('GDPR'), following a complaint submitted by an individual.

Background to the decision

In particular, the AEPD stated that the complainant, a British citizen, who was invited as a speaker to the Mobile World Congress ('MWC') in Barcelona, stated that they were mandatorily required to upload an image of their passport when attending MWC, even when doing so virtually.

Findings of the AEPD

In light of its investigation, the AEPD found that GSMA had established an identification system for physical attendees that enabled access to MWC based on facial recognition and biometric tokens managed in a computer program whose service was offered by a third party. In this regard, the AEPD held that GSMA did not examine substantive aspects of the system, nor did it asses the risks or the proportionality and necessity of the implementation of the system and its effect on the rights and freedoms of the interested parties, among other elements. Thus, the AEPD highlighted that GSMA failed to carry out a Data Protection Impact Assessment ('DPIA'), breaching Article 35 of the GDPR.

Outcomes

In light of the above, the AEPD imposed the abovementioned fine on GSMA.

You can read the decision, only available in Spanish, here.

UPDATE (9 May 2023)

AEPD dismisses GSMA's appeal for reconsideration

The AEPD published, on 5 May 2023, its decision in Proceeding No. PS-00553-2021, in which it dismissed GSMA's appeal for reconsideration, lodged on 24 March 2023, as the same had not provided new facts or legal arguments that would have allowed the reconsideration of the contested decision.

You can read the decision, only available in Spanish, here.