RFEF Fined €100,000 for Excessive Data Collection from Minors
The Royal Spanish Football Federation violated GDPR's data minimisation principle by requiring minors to submit two residency documents when governing rules (FIFA guidelines) explicitly permitted either one alone. Collecting more personal data than necessary — especially from children — amplifies privacy risks, including unnecessary exposure of sensitive information. This case underscores that organisations must continuously audit what data they collect, why they collect it, and whether a less invasive alternative exists. Regulatory bodies like the AEPD treat children's data with heightened scrutiny, making over-collection a high-risk compliance failure with significant financial consequences.
Tactical Insight
Immediate actions
- Audit all current data collection forms and processes to ensure only the minimum necessary personal data is requested, especially for minors.
- Update registration procedures to align with the least invasive option permitted by applicable governing-body guidelines (e.g., accept either document, not both).
Policy & governance improvements
- Establish a formal Data Minimisation Policy that requires documented justification for every personal data field collected before any form or system goes live.
- Implement a Privacy Impact Assessment (PIA/DPIA) process specifically for services involving children's data, with mandatory sign-off from a Data Protection Officer.
- Train staff responsible for designing registration workflows on GDPR principles, with emphasis on data minimisation and children's privacy rights.
Monitoring & compliance measures
- Schedule periodic compliance reviews of all data collection touchpoints to ensure ongoing alignment with GDPR requirements and relevant governing-body rules.
- Maintain a Records of Processing Activities (RoPA) log that documents the legal basis and necessity of each data element collected, enabling rapid audit response.