[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fdPI6ui4NZPGzjpXno-fzAgOAowhf-qZzaLzCkOv8pLM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"8dcef8bc-19c3-4202-9f12-f3536269b1d3","rfef-fined-100k-for-collecting-excessive-data-on-minor-soccer-players","5bbbdef7-92fe-4996-81e1-ffe50c4f9d00","RFEF Fined €100K for Collecting Excessive Data on Minor Soccer Players","The Royal Spanish Soccer Federation violated GDPR's data minimisation principle by collecting more personal information from minor players than FIFA's own guidelines required, demonstrating a fundamental misunderstanding of lawful data processing obligations. This case highlights that organisations must only collect data that is strictly necessary for the specified purpose — collecting 'more than needed just in case' is not a legally defensible position under GDPR. The involvement of minors significantly elevates the risk and regulatory scrutiny, as children represent a specially protected category of data subjects. Regulators across the EU are increasingly enforcing data minimisation proactively, meaning organisations cannot rely on vague justifications to legitimise excessive collection.","**Immediate actions:**\n- Conduct a data inventory audit of all registration forms and processes to identify fields that exceed legal or operational necessity.\n- Remove or anonymise any personal data fields that cannot be justified by a clear, documented lawful basis.\n\n**Policy & governance improvements:**\n- Implement a Data Protection Impact Assessment (DPIA) process for any processing activity involving minors before it goes live.\n- Establish a formal data minimisation review policy requiring sign-off from a Data Protection Officer (DPO) for all new data collection workflows.\n- Map all data collection requirements against applicable external guidelines (e.g., FIFA, sector regulators) to ensure alignment and avoid over-collection.\n\n**Training & awareness measures:**\n- Train staff responsible for form design and registration processes on GDPR's data minimisation and purpose limitation principles.\n- Create internal guidelines specifically addressing the heightened obligations when processing personal data of children.",[12,13,14,15,16,17,18,19],"GDPR Article 5(1)(c) – Data minimisation principle","GDPR Article 25 – Data protection by design and by default","GDPR Article 35 – Data Protection Impact Assessment (DPIA)","GDPR Article 8 – Conditions applicable to child's consent","NIST SP 800-53 PT-2 (Authority to Process Personally Identifiable Information)","NIST Privacy Framework PR.DS-P1 (Data Minimisation)","CIS Control 3 – Data Protection","ISO 27701 Section 7.2.1 – Purpose Limitation and Data Minimisation","published","2026-10-06T16:21:26.232015+00:00","2026-10-06T16:21:26.124+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_PS\u002F00339\u002F2024&diff=53310&oldid=53280","aepd-spain-ps-00339-2024-99158e","AEPD (Spain) - PS\u002F00339\u002F2024",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":35,"name":36,"slug":37,"description":38,"color":39},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]