Back to all lessons
Awareness Lessons
4 days ago

RFEF Fined €100K for Collecting Excess Data on Minors

The Royal Spanish Soccer Federation violated GDPR's data minimisation principle by requiring two identity documents from minors when one would have sufficed under FIFA's own guidelines. Collecting more personal data than necessary — especially from vulnerable individuals such as children — amplifies privacy risks and exposure in the event of a breach or misuse. This case illustrates that organisations must align their data collection practices with both regulatory requirements and the least-invasive standard permitted by governing bodies. The €100,000 fine underscores that regulators will hold organisations accountable even for procedural over-collection, not just technical breaches.

Tactical Insight

Immediate actions

  • Audit all current data collection forms and processes to ensure only the minimum necessary data is requested, particularly for minors.
  • Align internal data collection requirements with the least-restrictive option permitted by relevant governing bodies (e.g., FIFA, UEFA) rather than defaulting to more.

Policy & Governance improvements

  • Establish a formal Data Minimisation Policy that requires documented justification for every data field collected, subject to periodic review.
  • Appoint or empower a Data Protection Officer (DPO) to review data collection workflows before deployment and flag any over-collection.
  • Create a special handling category for data relating to minors, with stricter approval gates and enhanced privacy impact assessments.

Training & Awareness measures

  • Train administrative and compliance staff on GDPR principles — especially data minimisation (Article 5(1)(c)) and the heightened obligations when processing children's data.
  • Conduct annual privacy-by-design workshops to embed minimal data collection thinking into operational and registration processes from the outset.