UNIQUE IDENTIFICATION UNDER THE GDPR AND MEMBER STATE LAW: THE CASE OF SPAIN
DOI:
https://doi.org/10.69635/mssl.2026.2.3.56Keywords:
Biometric Data, Personal Data Protection Law, Access Control, Supervisory Enforcement, Agencia Española de Protección de Datos, SIDECU, S.A., Burgos Club de Fútbol, S.A.D.Abstract
The study infers that biometric access control systems, including facial recognition and fingerprint verification, involve the processing of special categories of personal data under Articles 4(14) and 9 of the General Data Protection Regulation whenever they facilitate or substantiate the unique identification of individuals. The distinction between biometric identification (1:N) and verification (1:1) does not exclude the relevance of Article 9 GDPR if tag effects arise.
Generic requests of public interest or security objectives are low to justify such processing under Article 9(2)(g) GDPR.
Spanish constitutional doctrine and EU data protection law direct that a law of acceptable rank establish any hindrance of the fundamental right to data protection, clearly express the substantial public welfare pursued, and provide precise, foreseeable, and robust safeguards.
The research finds that Article 13(1) of Spanish Law 19/2007 does not meet these requirements, as it neither expressly authorizes the processing of biometric data nor establishes appropriate safeguards. National regulation and administrative measures mandating biometric access systems in sports venues lack a valid legal basis under Article 9(2) GDPR and are incompatible with the EU data protection framework.
Decisions and prior consultations by the Agencia Española de Protección de Datos demonstrate strict enforcement of GDPR principles, including necessity, proportionality, transparency, and data minimisation. Biometric recognition was invariably considered unlawful due to the absence of a valid legal basis, invalid consent, lack of DPIAs, and the availability of less intrusive alternatives.
Therefore, the authors confirm that technical design choices do not alter the legal qualification of biometric data. Unique identification capability is decisive, and biometric systems must stay exceptional rather than authoritative means in access control practices.
References
Article 29 Data Protection Working Party. (2007). Opinion 4/2007 on the concept of personal data (WP 136). European Commission. https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2007/wp136_en.pdf
Article 29 Data Protection Working Party. (2012). Opinion 3/2012 on developments in biometric technologies (WP 196). European Commission. https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2012/wp196_en.pdf
AEPD (Spanish Data Protection Authority). (2023). Advisory opinion, Case 0098/2022, Comisión Estatal contra la Violencia, el Racismo, la Xenofobia y la Intolerancia (Relevant law: Art. 6(1)(e) & 9(2)(g) GDPR). https://www.aepd.es/documento/2022-0098.pdf
AEPD (Spanish Data Protection Authority). (2024). Burgos Club de Fútbol, S.A.D.: Complaint upheld under GDPR Articles 5(1)(c), 8, 9, 13 and 35, and Law 39/2015 (Case No. EXP202213792). https://www.aepd.es/documento/ps-00483-2023.pdf
AEPD (Spanish Data Protection Authority). (2025). SIDECU S.A.: Complaint upheld under GDPR Articles 4(14), 6(1), 9(1), 9(2)(a), 9(2)(g), 13 and 35 (Case No. EXP202313347). https://www.aepd.es/documento/ps-00289-2024.pdf
Bulgakova, D. (2025). Between security and violation of the right to protection of biometric data in the “Burgos” case. In Human rights and democracy: Proceedings of the scientific and practical conference dedicated to Europe Day (pp. 17–21). Pravo. https://www.aseu.com.ua/wp-content/uploads/2025/05/%D0%97%D0%B1%D1%96%D1%80%D0%BD%D0%B8%D0%BA_%D0%9F%D1%80%D0%B0%D0%B2%D0%B0-%D0%BB%D1%8E%D0%B4%D0%B8%D0%BD%D0%B8-%D1%82%D0%B0-%D0%B4%D0%B5%D0%BC%D0%BE%D0%BA%D1%80%D0%B0%D1%82%D1%96%D1%8F_%D0%9A%D0%BE%D0%BC%D0%B0%D1%80%D0%BE%D0%B2%D0%B0_2025.pdf
Council of Europe. (2021). European Convention on Human Rights (as amended by Protocols Nos. 11, 14, 15 and supplemented by Protocols Nos. 1, 4, 6, 7, 12, 13, 16). https://www.echr.coe.int/documents/d/echr/Convention_ENG
Council of Europe. (2021). Guidelines on facial recognition. https://rm.coe.int/guidelines-facial-recognition-web-a5-2750-3427-6868-1/1680a31751
Ebers, M., & Sein, K. (Eds.). (2025). Privacy, data protection and data-driven technologies. Routledge.
European Commission. (2018). Proposal for a Council decision authorising Member States to sign, in the interest of the European Union, the Protocol amending the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (ETS No. 108) (COM(2018) 449 final). https://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX:52018PC0449
European Commission. (2020). White paper on artificial intelligence: A European approach to excellence and trust (COM(2020) 65 final). https://commission.europa.eu/system/files/2020-02/commission-white-paper-artificial-intelligence-feb2020_en.pdf
European Data Protection Board. (2023). Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement (Version 2.0). https://www.edpb.europa.eu/system/files/2023-05/edpb_guidelines_202304_frtlawenforcement_v2_en.pdf
European Parliament & Council of the European Union. (1995). Directive 95/46/EC on the protection of individuals with regard to the processing of personal data and on the free movement of such data. Official Journal of the European Communities, L 281. https://eur-lex.europa.eu/eli/dir/1995/46/oj/eng
European Parliament & Council of the European Union. (2002). Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector. Official Journal of the European Communities, L 201. https://eur-lex.europa.eu/eli/dir/2002/58/oj/eng
European Parliament & Council of the European Union. (2016). Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation). Official Journal of the European Union, L 119, 1–88. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
Kindt, E. J. (2013). Privacy and data protection issues of biometric applications: A comparative legal analysis. Springer Netherlands. https://doi.org/10.1007/978-94-007-7522-0
Menéndez González, N., & Mobilio, G. (Eds.). (2025). Next democratic frontiers for facial recognition technology (FRT): The legal, ethical and democratic implications of FRT. Springer Nature Switzerland. https://doi.org/10.1007/978-3-031-89794-8
Salice, D., & Salice, J. (2024). Foundations and opportunities of biometrics: An introduction to technology, applications, and responsibilities. Apress. https://doi.org/10.1007/979-8-8688-0509-7
Smith, M., & Miller, S. (2021). Biometric identification, law and ethics. Springer International Publishing AG. https://doi.org/10.1007/978-3-030-90256-8
Spain. (2007). Law 19/2007 of 11 July on combating violence, racism, xenophobia and intolerance in sport. Boletín Oficial del Estado, 166, 29946–29964. https://www.boe.es/buscar/doc.php?id=BOE-A-2007-13408
Spain. (2015). Law 39/2015 of 1 October on the common administrative procedure of public administrations. Boletín Oficial del Estado, 236. https://www.boe.es/buscar/act.php?id=BOE-A-2015-10565
Spain. (2018). Organic Law 3/2018 of 5 December on the protection of personal data and guarantee of digital rights. Boletín Oficial del Estado, 294. https://www.boe.es/diario_boe/txt.php?id=BOE-A-2018-16673
Spanish Constitutional Court. (2000). Judgment No. 292/2000 of 30 November 2000. https://www.tribunalconstitucional.es/en/jurisprudencia/Paginas/resoluciones-traducidas.aspx
Spanish Constitutional Court. (2019). Judgment No. 76/2019 of 22 May 2019. https://www.tribunalconstitucional.es/en/jurisprudencia/Paginas/resoluciones-traducidas.aspx
van der Sloot, B., & Van Schendel, S. (2024). The boundaries of data. Amsterdam University Press. https://doi.org/10.1515/9789048557998
Vielhauer, C. (Ed.). (2018). User-centric privacy and security in biometrics. The Institution of Engineering and Technology.
Published
Issue
Section
License
Copyright (c) 2026 Daria Bulgakova, Hanna Hulievska (Author)

This work is licensed under a Creative Commons Attribution 4.0 International License.
All articles are published as open access and are licensed under a Creative Commons Attribution 4.0 International License (CC BY 4.0). This means that authors retain the copyright to the content of their articles. Under the CC BY 4.0 license, the content can be copied, adapted, displayed, distributed, republished, or otherwise reused for any purpose, including commercial use, provided that proper attribution is given to the original authors.
https://orcid.org/0000-0002-8640-3622
