UNIQUE IDENTIFICATION UNDER THE GDPR AND MEMBER STATE LAW: THE CASE OF SPAIN

Authors

  • Daria Bulgakova Advocate, PhD in International Law, Kryvyi Rih, Ukraine; Associate Professor, Department of Law and Public Administration, Zaporizhzhia Institute of Economics and Information Technologies, Zaporizhzhia, Ukraine Author ORCID Icon https://orcid.org/0000-0002-8640-3622
  • Hanna Hulievska PhD in Law, Associate Professor, Head of the Department of Law and Public Administration, Zaporizhzhia Institute of Economics and Information Technologies, Zaporizhzhia, Ukraine Author ORCID Icon https://orcid.org/0000-0001-7643-8162

DOI:

https://doi.org/10.69635/mssl.2026.2.3.56

Keywords:

Biometric Data, Personal Data Protection Law, Access Control, Supervisory Enforcement, Agencia Española de Protección de Datos, SIDECU, S.A., Burgos Club de Fútbol, S.A.D.

Abstract

The study infers that biometric access control systems, including facial recognition and fingerprint verification, involve the processing of special categories of personal data under Articles 4(14) and 9 of the General Data Protection Regulation whenever they facilitate or substantiate the unique identification of individuals. The distinction between biometric identification (1:N) and verification (1:1) does not exclude the relevance of Article 9 GDPR if tag effects arise.

Generic requests of public interest or security objectives are low to justify such processing under Article 9(2)(g) GDPR.

Spanish constitutional doctrine and EU data protection law direct that a law of acceptable rank establish any hindrance of the fundamental right to data protection, clearly express the substantial public welfare pursued, and provide precise, foreseeable, and robust safeguards.

The research finds that Article 13(1) of Spanish Law 19/2007 does not meet these requirements, as it neither expressly authorizes the processing of biometric data nor establishes appropriate safeguards. National regulation and administrative measures mandating biometric access systems in sports venues lack a valid legal basis under Article 9(2) GDPR and are incompatible with the EU data protection framework.

Decisions and prior consultations by the Agencia Española de Protección de Datos demonstrate strict enforcement of GDPR principles, including necessity, proportionality, transparency, and data minimisation. Biometric recognition was invariably considered unlawful due to the absence of a valid legal basis, invalid consent, lack of DPIAs, and the availability of less intrusive alternatives.

Therefore, the authors confirm that technical design choices do not alter the legal qualification of biometric data. Unique identification capability is decisive, and biometric systems must stay exceptional rather than authoritative means in access control practices.

References

Article 29 Data Protection Working Party. (2007). Opinion 4/2007 on the concept of personal data (WP 136). European Commission. https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2007/wp136_en.pdf

Article 29 Data Protection Working Party. (2012). Opinion 3/2012 on developments in biometric technologies (WP 196). European Commission. https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2012/wp196_en.pdf

AEPD (Spanish Data Protection Authority). (2023). Advisory opinion, Case 0098/2022, Comisión Estatal contra la Violencia, el Racismo, la Xenofobia y la Intolerancia (Relevant law: Art. 6(1)(e) & 9(2)(g) GDPR). https://www.aepd.es/documento/2022-0098.pdf

AEPD (Spanish Data Protection Authority). (2024). Burgos Club de Fútbol, S.A.D.: Complaint upheld under GDPR Articles 5(1)(c), 8, 9, 13 and 35, and Law 39/2015 (Case No. EXP202213792). https://www.aepd.es/documento/ps-00483-2023.pdf

AEPD (Spanish Data Protection Authority). (2025). SIDECU S.A.: Complaint upheld under GDPR Articles 4(14), 6(1), 9(1), 9(2)(a), 9(2)(g), 13 and 35 (Case No. EXP202313347). https://www.aepd.es/documento/ps-00289-2024.pdf

Bulgakova, D. (2025). Between security and violation of the right to protection of biometric data in the “Burgos” case. In Human rights and democracy: Proceedings of the scientific and practical conference dedicated to Europe Day (pp. 17–21). Pravo. https://www.aseu.com.ua/wp-content/uploads/2025/05/%D0%97%D0%B1%D1%96%D1%80%D0%BD%D0%B8%D0%BA_%D0%9F%D1%80%D0%B0%D0%B2%D0%B0-%D0%BB%D1%8E%D0%B4%D0%B8%D0%BD%D0%B8-%D1%82%D0%B0-%D0%B4%D0%B5%D0%BC%D0%BE%D0%BA%D1%80%D0%B0%D1%82%D1%96%D1%8F_%D0%9A%D0%BE%D0%BC%D0%B0%D1%80%D0%BE%D0%B2%D0%B0_2025.pdf

Council of Europe. (2021). European Convention on Human Rights (as amended by Protocols Nos. 11, 14, 15 and supplemented by Protocols Nos. 1, 4, 6, 7, 12, 13, 16). https://www.echr.coe.int/documents/d/echr/Convention_ENG

Council of Europe. (2021). Guidelines on facial recognition. https://rm.coe.int/guidelines-facial-recognition-web-a5-2750-3427-6868-1/1680a31751

Ebers, M., & Sein, K. (Eds.). (2025). Privacy, data protection and data-driven technologies. Routledge.

European Commission. (2018). Proposal for a Council decision authorising Member States to sign, in the interest of the European Union, the Protocol amending the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (ETS No. 108) (COM(2018) 449 final). https://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX:52018PC0449

European Commission. (2020). White paper on artificial intelligence: A European approach to excellence and trust (COM(2020) 65 final). https://commission.europa.eu/system/files/2020-02/commission-white-paper-artificial-intelligence-feb2020_en.pdf

European Data Protection Board. (2023). Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement (Version 2.0). https://www.edpb.europa.eu/system/files/2023-05/edpb_guidelines_202304_frtlawenforcement_v2_en.pdf

European Parliament & Council of the European Union. (1995). Directive 95/46/EC on the protection of individuals with regard to the processing of personal data and on the free movement of such data. Official Journal of the European Communities, L 281. https://eur-lex.europa.eu/eli/dir/1995/46/oj/eng

European Parliament & Council of the European Union. (2002). Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector. Official Journal of the European Communities, L 201. https://eur-lex.europa.eu/eli/dir/2002/58/oj/eng

European Parliament & Council of the European Union. (2016). Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation). Official Journal of the European Union, L 119, 1–88. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng

Kindt, E. J. (2013). Privacy and data protection issues of biometric applications: A comparative legal analysis. Springer Netherlands. https://doi.org/10.1007/978-94-007-7522-0

Menéndez González, N., & Mobilio, G. (Eds.). (2025). Next democratic frontiers for facial recognition technology (FRT): The legal, ethical and democratic implications of FRT. Springer Nature Switzerland. https://doi.org/10.1007/978-3-031-89794-8

Salice, D., & Salice, J. (2024). Foundations and opportunities of biometrics: An introduction to technology, applications, and responsibilities. Apress. https://doi.org/10.1007/979-8-8688-0509-7

Smith, M., & Miller, S. (2021). Biometric identification, law and ethics. Springer International Publishing AG. https://doi.org/10.1007/978-3-030-90256-8

Spain. (2007). Law 19/2007 of 11 July on combating violence, racism, xenophobia and intolerance in sport. Boletín Oficial del Estado, 166, 29946–29964. https://www.boe.es/buscar/doc.php?id=BOE-A-2007-13408

Spain. (2015). Law 39/2015 of 1 October on the common administrative procedure of public administrations. Boletín Oficial del Estado, 236. https://www.boe.es/buscar/act.php?id=BOE-A-2015-10565

Spain. (2018). Organic Law 3/2018 of 5 December on the protection of personal data and guarantee of digital rights. Boletín Oficial del Estado, 294. https://www.boe.es/diario_boe/txt.php?id=BOE-A-2018-16673

Spanish Constitutional Court. (2000). Judgment No. 292/2000 of 30 November 2000. https://www.tribunalconstitucional.es/en/jurisprudencia/Paginas/resoluciones-traducidas.aspx

Spanish Constitutional Court. (2019). Judgment No. 76/2019 of 22 May 2019. https://www.tribunalconstitucional.es/en/jurisprudencia/Paginas/resoluciones-traducidas.aspx

van der Sloot, B., & Van Schendel, S. (2024). The boundaries of data. Amsterdam University Press. https://doi.org/10.1515/9789048557998

Vielhauer, C. (Ed.). (2018). User-centric privacy and security in biometrics. The Institution of Engineering and Technology.

Downloads

Views: 73

  |  

Downloads: 22

Published

2026-08-31

Issue

Section

Digital Identity, Privacy, and Cybersecurity

How to Cite

Bulgakova, D., & Hulievska, H. (2026). UNIQUE IDENTIFICATION UNDER THE GDPR AND MEMBER STATE LAW: THE CASE OF SPAIN. Metaverse Science, Society and Law, 2(3). https://doi.org/10.69635/mssl.2026.2.3.56

Similar Articles

11-20 of 39

You may also start an advanced similarity search for this article.