fineConcluded€10,043,002

Agencia Espanola de Proteccion de Datos (AEPD) AENA, S.M.E., S.A.

November 26, 2025 · Spain

The AEPD fined airport operator AENA over EUR 10 million (PS/00431/2024) for an Article 35 GDPR breach, having deployed a facial-recognition passenger boarding/identification system at eight airports without a valid DPIA, and confirmed suspension until a compliant DPIA is done.

Key takeaway — how to prevent this

Biometric data (faces, iris, fingerprints) needs an explicit lawful basis or consent. Scraping or capturing it without one is unlawful across the EU/UK and many US states (e.g. Illinois BIPA) — and draws the largest fines.

Inclusion does not imply wrongdoing or liability. Status reflects the latest information we have — always check the official source for current status.