[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$feFlB7Ll8bWJeNZjIZL-tAAX-c04DR3BrS8U84aLUP38":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"4435bb0a-3ddd-477c-b59c-4144a2874cc5","rfef-fined-100000-for-excessive-data-collection-from-minors","08dd4e06-3a5a-4067-87d8-a9d7ee6e1811","RFEF Fined €100,000 for Excessive Data Collection from Minors","The Royal Spanish Football Federation violated GDPR's data minimisation principle by requiring minors to submit two residency documents when governing rules (FIFA guidelines) explicitly permitted either one alone. Collecting more personal data than necessary — especially from children — amplifies privacy risks, including unnecessary exposure of sensitive information. This case underscores that organisations must continuously audit what data they collect, why they collect it, and whether a less invasive alternative exists. Regulatory bodies like the AEPD treat children's data with heightened scrutiny, making over-collection a high-risk compliance failure with significant financial consequences.","**Immediate actions:**\n- Audit all current data collection forms and processes to ensure only the minimum necessary personal data is requested, especially for minors.\n- Update registration procedures to align with the least invasive option permitted by applicable governing-body guidelines (e.g., accept either document, not both).\n\n**Policy & governance improvements:**\n- Establish a formal Data Minimisation Policy that requires documented justification for every personal data field collected before any form or system goes live.\n- Implement a Privacy Impact Assessment (PIA\u002FDPIA) process specifically for services involving children's data, with mandatory sign-off from a Data Protection Officer.\n- Train staff responsible for designing registration workflows on GDPR principles, with emphasis on data minimisation and children's privacy rights.\n\n**Monitoring & compliance measures:**\n- Schedule periodic compliance reviews of all data collection touchpoints to ensure ongoing alignment with GDPR requirements and relevant governing-body rules.\n- Maintain a Records of Processing Activities (RoPA) log that documents the legal basis and necessity of each data element collected, enabling rapid audit response.",[12,13,14,15,16,17,18,19],"GDPR Article 5(1)(c) – Data Minimisation Principle","GDPR Article 25 – Data Protection by Design and by Default","GDPR Article 35 – Data Protection Impact Assessment (DPIA)","GDPR Article 8 – Conditions Applicable to Child's Consent","NIST Privacy Framework PR.DS-P1 – Data Minimisation","CIS Control 3 – Data Protection","ISO\u002FIEC 27701 – Privacy Information Management","CNIL\u002FAEPD Guidelines on Children's Data Processing","published","2026-10-02T08:20:19.401725+00:00","2026-10-02T08:20:19.278+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_PS\u002F00339\u002F2024&diff=53280&oldid=0","aepd-spain-ps-00339-2024-da30f1","AEPD (Spain) - PS\u002F00339\u002F2024",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":35,"name":36,"slug":37,"description":38,"color":39},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]