AEPD (Spain) - EXP202305134

From GDPRhub
AEPD - EXP202305134
Authority: AEPD (Spain)
Jurisdiction: Spain
Relevant Law: Article 4(14) GDPR
Article 9 GDPR
Article 9(1) GDPR
Article 9(2) GDPR
Article 35 GDPR
Type: Complaint
Outcome: Upheld
Started: 21.04.2023
Decided:
Published: 04.03.2026
Fine: n/a
Parties: Fútbol Club Barcelona
National Case Number/Name: EXP202305134
European Case Law Identifier: n/a
Appeal: n/a
Original Language(s): Spanish
Original Source: AEPD (in ES)
Initial Contributor: RP

The DPA fined FC Barcelona €500,000 for failing to conduct a required DPIA under Article 35 GDPR regarding the implementation of biometric technology processing voice and facial data.

English Summary

Facts

On 21 April 2023, a data subject lodged a complaint with the Spanish Data Protection Agency (AEPD) against Fútbol Club Barcelona (the controller).

The controller had launched a campaign to update its membership census. Under the Club’s Statutes, members had a duty to keep their personal data up to date. The controller stated that the update was necessary to ensure correct democratic representation within the Club and to prevent fraud, such as the unlawful transfer of membership cards and season tickets.

The controller offered a digital procedure for the update. Members could access an online platform, scan their identity document, take a real-time selfie, and move their head following on-screen instructions. The system compared the image from the identity document with the selfie. The data subject argued that this process required the collection of facial biometric data without explicit consent and that they could not complete the digital update without undergoing facial recognition.

The controller explained that the system performed a one-to-one facial comparison. The software generated biometric vectors from both images and compared them in real time. They stated that it deleted the identity document image after the comparison and kept only the updated photograph. The biometric vectors remained encrypted for seven days on servers located in the European Economic Area and were then deleted. The Club relied on Article 6(1)(b) GDPR as the legal basis, arguing that the processing was necessary for the performance of the membership contract and for compliance with members’ statutory obligations.

The controller also offered an optional voice recording for future telephone authentication. Members had to give separate consent for this voice recording. According to the controller, members could avoid biometric processing by updating their data in person at the Club’s offices. Around 12,000 members used this in-person option.

Before launching the system, the controller carried out a risk assessment and concluded that it did not need to conduct a data protection impact assessment (DPIA) under Article 35 GDPR. The controller argued that the processing did not involve special categories of data under Article 9 GDPR because it only performed verification (one-to-one matching) and did not create a biometric database for broader identification.

Holding

The AEPD found that the controller processed biometric data within the meaning of Article 4(14) GDPR. The authority held that the system involved specific technical processing of facial characteristics in order to uniquely identify a person. This qualified as processing of special categories of personal data under Article 9(1) GDPR.

The AEPD rejected the controller’s argument that one-to-one verification fell outside Article 9 GDPR. The authority explained that the decisive element was the use of biometric data for identification or authentication. It did not matter whether the system compared one image to many (one-to-many) or one image to a single reference (one-to-one). The generation and comparison of biometric vectors for identity confirmation triggered the application of Article 9(1) GDPR.

The AEPD then examined whether any exception under Article 9(2) GDPR applied. The controller relied on Article 6(1)(b) GDPR. However, the AEPD held that Article 6 GDPR could not override the prohibition in Article 9(1) GDPR. The controller had to identify a valid exception under Article 9(2) GDPR. The AEPD found that none of the exceptions applied.

In particular, the controller had not obtained explicit consent under Article 9(2)(a) GDPR for facial biometric processing. The digital procedure required facial comparison as a mandatory step. Although members could choose an in-person alternative, they could not refuse facial recognition within the digital process itself. The AEPD concluded that the controller did not demonstrate freely given and explicit consent for the biometric processing.

The AEPD also assessed necessity and proportionality. The authority acknowledged that they had a legitimate interest in preventing fraud and ensuring accurate membership records. However, it found that the systematic use of facial biometric technology for more than 140,000 members was highly intrusive. Biometric data are sensitive by nature because they are unique and permanent. The controller did not show that less intrusive measures could not achieve the same objective.

Finally, the AEPD held that the controller should have conducted a DPIA under Article 35 GDPR. The processing involved large-scale use of innovative biometric technology and was likely to result in a high risk to the rights and freedoms of data subjects. The internal risk assessment carried out by the controller did not replace the formal DPIA required by the GDPR.

Consequently, the AEPD imposed a €500,000 fine for FCB’s violation of Article 35 GDPR due to the failure to conduct a required DPIA for large-scale biometric processing. Although the authority found issues under Article 9 regarding facial biometric data, it ultimately closed the Article 9 infringement, focusing the sanction solely on the breach under Article 35.

Comment

The decision to close Article 9, despite the AEPD finding illegal processing, lacks any consistent explanation in the ruling.

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.

1/139

• File No.: EXP202305134

RESOLUTION OF SANCTIONING PROCEEDINGS

From the proceedings initiated by the Spanish Data Protection Agency and based on the following:

BACKGROUND

FIRST: Filing of the first complaint
On April 21, 2023, the Spanish Data Protection Agency received

a first complaint from COMPLAINANT 1 (hereinafter R1, SEE GENERAL ANNEX). The complaint is directed against FÚTBOL CLUB BARCELONA (FCB) with Tax Identification Number G08266298 (hereinafter, FCB), of which the complainant is a member. The grounds on which the claim is based are as follows:

FC Barcelona has launched a campaign to update the census data of its members, which, according to the Club's website, is mandatory in accordance with the entity's Statutes and must be completed before June 30, 2023. To this end, the claimant received an email containing a link which they clicked to begin the process. It states that:

“Once the process begins, it is indicated, regarding its purpose, that the use of biometric data will only be carried out if consent is given (in fact, there is a box requesting authorization for voice recording). However, once the process begins, and despite being told that a simple photo of the face (selfie) will be requested, the user is asked to move their head up and down (and after that, I suppose, from right to left), which constitutes the collection of biometric data related to the face, for which no express consent has been requested and which is necessary to complete the census update process. I believe that obtaining biometric data for the update of a sports club census does not correspond to the purpose for which the data is requested. Furthermore, in this case, the process cannot be completed without providing facial biometric data. Therefore, I request that you initiate The

necessary actions to ensure that FC Barcelona modifies the
census update procedure so that it no longer requires providing facial biometric data without
express consent.

Provides:
1-Screenshot of the relevant section of the Club's website; “What is the

Membership Register: Updating your data is a statutory obligation that
makes it possible to regularize the Club's membership register.

The register is a record of all members of the organization and
collects the personal data necessary for the Club.

As stated in the FC Barcelona statutes, you must:
Provide an address or other information for the delivery of Club communications and

duly notify any changes of address.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 2/139

Provide your bank account details at a credit institution, where your membership fees or contributions can be debited, or where payments made by the Club can be credited.

Complete the procedures for updating the electoral register initiated by the Club, whether
by requesting the presence of the member or providing the required data.”

2-screenshot: “New Member Census 2023 More digital, more personal
Create your BARÇA digital profile now, and access better services,” with the following information:

“Create your digital profile

It’s a quick, very simple, 100% digital process.

Who can create their profile?

Members who are of legal age must complete the entire process. Access will be opened to members under the age of 18 later, at which time the Club will inform them of the procedure they will have to follow.

What will you need?

An electronic device such as a computer, tablet, or mobile phone with a camera and microphone

built-in.

Your ID card, NIE, or passport on hand. Find a place with good lighting, avoid glare and background noise.” “It will only take a few minutes.”

It explains 8 steps:

1- Through the Club's website or members' app, go to "New Membership Registration" and log in with your password and personal code (PIN).

2- Go to the "New Membership Registration Procedures" section.

3- Select the country and the type of official identity document.

4- Show your official identity document to the camera and it will be scanned automatically.

5- Take a selfie.

6- And record your voice for 5 seconds.

7- Finally, access the data form, complete it, and verify your Barça profile.

8- The process will end with certification that it has been completed correctly.

3- A partial page of the process, showing: “Now a selfie” to follow

the movement instructions: 1. “Fit your face in the frame and wait for the countdown. 2. Slowly move your head in the direction indicated by the arrows. 3. When the screen indicates that you have done it correctly, look back at the center,” and below it, the “start the process” tab.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 3/139

4- Screenshot of “nou cens socis I socies 2023. Bienvenidos al nuevo censo
de socios y socias del FC Barcelona”. The notice includes contact information for any questions and a paragraph on "data protection information" with FC Barcelona as the

data controller, and:

"Purposes: management, relationship, and identification with the member. Procedures and

management related to season tickets. Right to use the seat, use of biometric data for
contact with the Club and for member authentication and identification for
access to the Club's facilities with the member's express consent, sending communications related to FC Barcelona, electronic sending
of commercial information from FC Barcelona and/or affiliated/subsidiaries,

as well as from its sponsors or partners.

Rights: You may object to receiving commercial communications and exercise your
right of access, rectification, erasure, portability, and restriction of processing," including an

email address and further information via a link.

Two boxes follow for marking with an "x".

The first, “I accept the Privacy Policy,” with a link that clicks.

The second, “I accept the recording, registration, and use of my voice as biometric data in accordance with the Privacy Policy I have accepted.”

No document containing a visual representation of the aforementioned “Privacy Policy” is provided.

SECOND: Forwarding the complaint
In accordance with Article 65.4 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter LOPDGDD), on April 21, 2023, this complaint was forwarded to FCB so that they could analyze it and inform this Agency, within one month, of the actions taken to comply with the requirements of data protection regulations.

The transfer, which was carried out in accordance with the regulations established in Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), was received on April 21, 2023.

On May 22, 2023, this Agency received a written response to the transfer and the requested information, indicating:

1- As background, FCB refers to:

1) the specific characteristics of FCB,

2) the digitization process, and

3) the application of the facial comparison method used.

FCB indicates that it is a private, non-profit sports association of individuals with its own legal personality and capacity to act, whose ownership belongs to its members, whose status is personal and non-transferable.

“At FC Barcelona, this is especially relevant because the members decide
on the Club's operation and democratically elect the Board of Directors, who, through their delegates, accept the Board's proposals.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 4/139

Additionally, members can also hold season ticket holder status, which
grants them the right to temporary use of certain seats in the Camp Nou stadium.

These season tickets are automatically renewed each

season. “Given the Club’s problem with the stadium’s limited seating capacity, which is insufficient to satisfy the interest of fans and

members in obtaining season tickets to attend matches, FCB, aware of this
limitation, is trying to adopt possible measures to mitigate certain practices of
illegal transfer of membership cards and season tickets to
third parties. For example:

It is common practice that when a member dies, the Club is not notified, and thus their
family members can continue using the aforementioned card, as well as the
season ticket, if they have one, including the assigned seat, and irregularly enjoying the benefits associated with membership and

season tickets.

Another fraudulent practice consists of transferring the membership and
season ticket to a third party completely unrelated to FCB, for a fee, so that, without having
the Membership status or no connection with the Club, illegitimately use the

assignee's membership card, including conducting business with it, is prohibited by the
Statutes governing the entity and classified as an infraction.

These circumstances make it vitally important to have an up-to-date, accurate, and reliable membership list to prevent the fraudulent use of both membership cards and season tickets by third parties who are not the rightful holders.

Given the specific characteristics of FC Barcelona membership and its importance for the club's proper functioning, on June 21, 2022, the Board of Directors approved updating the membership list, considering that a renewed list is crucial to ensuring that the data accurately reflects reality. Members, among other things, guarantee the democratic representation of the governing bodies and make decisions through their delegates, as well as being the ones who can interact financially with FC Barcelona.

It should be emphasized that the accuracy of the data and keeping it updated is a duty of all FCB members, an obligation that is included in the Club's Statutes. “

“When carrying out this census update process, the choice and use of a system that allows for “real authentication of the member” is of particular importance, in order to verify that they are indeed who they claim to be.

Consequently, when assessing which processing system was most suitable for
carrying it out, FC Barcelona had to take these circumstances into account and choose
the mechanism that would allow it to authenticate the interested party with greater security and
certainty. Furthermore, a system was sought that did not necessarily imply the

physical presence of members at FC Barcelona facilities, taking into account the
geographical dispersion and avoiding the inconvenience of members having to
travel.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 5/139

Taking advantage of the membership census update, FC Barcelona has launched a digital initiative to, among other things, streamline procedures and, given the importance of its functions, ensure a better authentication process that is secure and that

allows for and helps prevent potential fraud and identity theft of members.

For the last membership census update, an online system was chosen

using forms only for members from outside the city of
Barcelona. This generated complaints from local members who were forced to complete the process in person. This circumstance was taken into account when
choosing the update system, aiming to avoid unfair treatment.

“One of the main reasons and objectives for digitizing the membership update process is, given the number of members (143,000) and their geographical dispersion, to allow members who wish to do so to update their personal information without having to travel to the Club's facilities.

In the communication sent to members, while it is true that FC Barcelona has prioritized the digital process as it is considered more suitable and convenient for both members and the Club, it has never forced them to use this method of updating their information. Members who wish to do so, due to a lack of access to digital resources or unfamiliarity with digital environments, can visit the Club's facilities and contact FC Barcelona to complete the process in person at its offices. In fact, some members have already done so.

A comparison system has been chosen for this digital process.” facial recognition, which
compares two images of the same person in real time,
one photograph taken from a trusted document, such as
the photograph contained in an ID card or passport, is compared with a

real-time photograph of the person. This allows for the authentication of the individual to
confirm that it is the same person appearing in both images and guarantees that
it is the person behind the camera taking the photograph in real time, thus preventing
another individual from simply uploading two photographs of another
person.


Likewise, for members, “the system asks them to move their face from side to side during the process, solely as a mechanism to verify that they are alive and demonstrate their presence, thus preventing the real image from being replaced by

another photograph of the ID card holder that someone else might upload.
Once the comparison has been made, the ID card photograph is deleted, and only

the image taken in real time is kept as the member's updated photograph, but without any biometric data. That is, at no time are biometric data recorded in FCB's databases, and the comparison is strictly limited to the moment of facial comparison of both images. In this way, the system allows for the authentication and comparison of an image provided by the member

with another taken at that same moment, without the need to record their facial biometric data, so it is not possible to reuse the facial features
used to compare the images.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 6/139

2- Regarding the legal basis that legitimizes the processing of the biometric facial recognition system, SBRF, FCB states that it is Article 6.1.b) of the GDPR: “the processing is necessary for the performance of a contract to which the data subject is a party,” derived from the “obligation of FCB members, according to Article 11.8 of the Club Statutes, to carry out the procedures for updating the electoral register promoted by the Club,” “either by requiring the member's presence or by providing the required data.”

“To conclude that the facial features obtained during the facial comparison process do not qualify as biometric data as stipulated in the GDPR, the decision was based on the provisions of Articles 4.14, 9.1 and Recital 51 of the GDPR, and on the various reports and documents with recommendations published by Data Protection supervisory bodies, specifically:

Regarding the distinctions between unique identification and verification, the report of the Legal Department of the Spanish Data Protection Agency (AEPD) No. 36/2020, Opinion 3/2012 of Working Party 29 on the evolution of biometric technologies, and the European Commission's White Paper on artificial intelligence.”

“In this regard, we find that the facial comparison system
used by FCB is intended to authenticate its members by comparing a

static image (photograph of the ID card) with a selfie taken by the
members in real time and while moving, without this at any time
implying a one-to-one comparison of the member with a
database of a group.”

“The partial comparison system used by FCB, being based on a
simple authentication system (one-to-one) that does not generate a biometric
database of Club members, is considered not to constitute
a special category of data and does not require the

consent of the data subjects. Furthermore, the use of facial verification systems is not mandatory at any time,
although it has been prioritized for logistical and operational reasons.”

3- Regarding the guarantees for the protection of the rights and freedoms of individuals,

FCB responded that:
- It has a GDPR and LOPDGDD compliance protocol that allows it to

carry out continuous monitoring.

- It has an internal organizational structure composed of professionals related to
privacy and data protection, and an external law firm responsible for the
continuous verification of compliance, which conducts an annual comprehensive audit of
the processing activities.

- An external Data Protection Officer (DPO) with more than 20 years of experience in privacy and data protection.

- An internal IT department that ensures the security of the systems where personal data processing takes place.

- An external security and cybersecurity company that supports the IT department and
audits the systems. -The representatives of these areas and entities form an "Operational Commission"

for Data Protection, "led by the DPO" which meets regularly to

analyze points related to the processing of personal data carried out by FC Barcelona.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 7/139

improvements are proposed and potential new data processing activities are presented for subsequent evaluation.

Furthermore, it outlines the actions they have taken to guarantee and comply with data protection regulations:

-Record of Processing Activities (ROPA)
-A risk assessment of data processing activities has been carried out, and when

the need has been identified or determined in the risk assessment, the corresponding impact assessments of certain processing activities have been conducted.

-A general privacy policy is in place regarding the processing of personal data
of the various data subjects whose personal data FC Barcelona may process.
-If a supplier processes personal data, an external service assesses whether they meet the

guarantees to act as a data processor, and together with the IT department, they evaluate the
security measures provided by these suppliers to ensure the security
of the data they may access.

-A security protocol ensures compliance with all

security measures, managed by the internal IT department and an external IT and cybersecurity company.

-A security breach management protocol is in place.

-Data protection training has been provided to
employees who process personal data.

-A system is in place for handling requests to exercise data protection rights.

4- Regarding the DPIA carried out or the reasons why it has not been carried out, FCB responded that:
“Once the decision was made to opt for the facial comparison system, since it was demonstrated, in our opinion, that it was the most efficient, safe, and convenient for our members, a double analysis was carried out before launching the service.

On the one hand, a RISK ASSESSMENT was carried out to determine, based on its conclusions, whether or not a DPIA should be carried out, and to assess the risks of the processing. Upon concluding that it was not necessary, it was deemed necessary to carry out an analysis to determine if the system is proportionate.”

FCB states that, to assess the need for a DPIA, it carried out a triple analysis.


“At a first level, the processing activity “subject to assessment” is not included in the GDPR list, specifically Articles 35.4 and 35.5.

At a second level, its purpose does not include the systematic monitoring or evaluation of personal data, nor does it involve large-scale processing.

At a third level, as provided for in Article 35, it indicates that the following have been verified:

the nature of the processing.

the scope of the processing.

its context.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 8/139

Purposes of the processing.
Technologies used for the processing.
Data transfers and international transfers.

Perception of a high risk by the data controller.

Third parties involved – suppliers.

Systems used in the processing.”

Regarding the RISK ASSESSMENT analysis, the main risks considered for the assessment number up to 19.

FCB adds that: “The data lifecycle has been analyzed and the risks have been assessed based on:

• Risk typology:

Risks associated with information protection
Risks associated with regulatory compliance
Legitimacy of processing and transfers
International transfers

Data quality
Access, Rectification, Cancellation, and Opposition (ARCO) rights
Security

• Related risks

• Probability of occurrence and their impact on a scale of 1 to 4:

• Degree of risk

Negligible

Limited

Significant

High/Critical

• Control measures to mitigate or eliminate the risk”

“Based on this risk analysis, it has been concluded that the process of updating the FCB member census through The facial comparison system described
does not present significant risks, since, of the 17 risk types analyzed, 14 yielded a result of “Low Risk” and 3 of them showed a “Negligible” risk. Consequently, it is observed that the risk of the analyzed data processing is minimal, and the small risk detected is

more than offset by the proposed control measures.

“Regarding PROPORTIONALITY, it is concluded that the processing and the system

used for it are proportionate, as the legitimacy has been weighed against the potential infringement of the rights and freedoms of the data subjects. In particular, it is determined that the rights and freedoms of the data subjects are not at risk of being
infringed due to the low impact of the data processing, since only biometric features are processed temporarily, almost

instantaneously, and only for facial comparison (one-to-one authentication).

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 9/139

Consequently, this party understands that there is a proper balance between the
processing and the rights and freedoms of individuals, as there is no significant
intrusion into their privacy.

These conclusions derive from the analysis of the following aspects and considerations:

o Necessity: It has been analyzed whether opting for the The use of this system is essential to
fulfill the identified purpose, which is the statutory obligation to update the
FCB membership register. In other words, is this system essential to
achieve the intended purpose or was it chosen solely for its speed or

cost-effectiveness?

To this end, it is concluded that this system is indeed proportionate, as it is
necessary to fulfill the obligation required in the FCB Statutes to

maintain an up-to-date membership register and because it is not
simply the fastest or cheapest system, but rather the most suitable, taking into account
several aspects such as: the system's resilience, the number of members (143,000) who must update their information, and the possibility that all members,
regardless of their geographical location, can use it without having to

travel to FCB's headquarters in Barcelona, as well as the guarantees
of security and authenticity that It offers. Therefore, it is imperative to have a system that allows updating the census from different locations with the highest guarantees of reliability, something that can only be achieved, without the data being able to be manipulated, with a system of this type.

This report has concluded that, although other systems and possible alternatives exist, they are not equally valid, as they do not offer the same degree of protection and accuracy. Therefore, these alternative mechanisms could lead to a failure to achieve the purpose of updating the census and have thus been discarded, determining the need for the chosen system.

Effectiveness: As a second factor, the effectiveness of the system in meeting the need in relation to the characteristics and use of biometric technology has been considered.

This system has been proven effective because it is a system that cannot be manipulated and that the user cannot deceive, so that no third party or the members themselves can access it. Members will not be able to impersonate each other.

It is therefore concluded that choosing any other system entails risks of impersonation (whether through cards, codes, paper forms, online forms, etc.), and thus would not be effective in achieving the intended purpose.

In this regard, it is determined that there is no loss of privacy whatsoever, since, although the system collects biometric data, it is simply a facial comparison between the ID card image and a real-time selfie. Once the comparison is made, any biometric features are removed, leaving only the real-time photograph as the member's updated image, and it is not possible to recover the biometric features used for the facial comparison.

Furthermore, the loss of privacy that the use of other systems (cards, codes, forms, etc.) would entail has been analyzed, and it has been concluded that the benefits obtained with this system far outweigh the potential loss. Privacy, if it exists

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 10/139

that it can be considered that it exists and, even, that said loss is
less than with the implementation of other alternative systems.

or Existence of less invasive means: As a fourth aspect to evaluate the
suitability of the analyzed biometric system and its proportionality, consideration has been given to whether there are other less invasive means for privacy that allow
achieving the same desired end.

After analyzing the alternatives, it has been verified that they cannot achieve
the same end, for the following reasons:

Firstly, because all the alternative systems analyzed lack
defense mechanisms against impersonation, since it is easier to impersonate another
person if you have their access credentials, ID cards, etc.

Furthermore, these mechanisms entail the possibility of loss or theft of said
credentials (ID cards, codes, etc.), thus implying a greater risk of

identification and, as mentioned in the previous point, loss of privacy for
those concerned.

Finally, the option of manual or online registration was also considered,
something very difficult to manage when the number of interested parties is high.
These alternatives would also pose a greater risk and be more dangerous
due to the limited control these methods offer over the veracity of the
registrations made in writing or online, without any additional mechanism to
verify the identity of the person making the registration.

As general conclusions, the following points stand out:

“Regarding the context of the processing, despite the use of new technologies, given their security, the type of biometric data processed, and the facial comparison performed to authenticate the member, the processing is not considered to pose a risk to FC Barcelona members.”

“The software used has been tested and determined to be completely secure. Furthermore, VERIDAS DIGITAL AUTHENTICATION SOLUTIONS S.L., the software owner (hereinafter VERIDAS), holds the most recognized certifications, therefore we consider that its use does not pose any risk to FC Barcelona members.”

The data controller does not perceive that the main processing activity
involves a high risk. Therefore, based on the three levels of analysis and the
questionnaire responses, it is concluded that the processing of biometric data for
facial comparison in the process of updating the FCB member census does not require an impact assessment.

5- Regarding the categories of interested parties and the information provided to them, FCB
includes in DOCUMENT 1 a copy of the “specific information provided to FCB members regarding the processing of their personal data, based on a first and second layer of information.”

What it calls the first layer includes an informative screenshot titled “New Member Census 2023,” which begins with “Welcome to the new membership census.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 11/139

This coincides with the copy of the document provided by Claimant 1 and is thus referenced in FACT ONE, which is submitted as document 4, its content being considered reproduced herein.

What it calls the second layer of the “privacy policy” is contained in a document with that title, and it does not only contain a reference to the processing of the update of the census, but of all the processing carried out by

FCB with the data of its members (six pages). It indicates that it may be subject to modification, this being the version of February 14, 2023.

The most noteworthy is:

In “purposes, legal basis, and retention of data processing carried out or

sent through”: up to TEN different categories are listed:

One of them, “a. APPLICATION FOR MEMBERSHIP AND MANAGEMENT OF RELATED PROCEDURES:

another: “b. UPDATING OF THE MEMBERSHIP CENSUS”.

Other data processing activities carried out or sent through include:

-Authorization, transfer of temporary use of your season ticket to a third-party assignee.

-Season ticket management.
-Payment and financing of membership fees.
-Member contact and feedback/Submission of appeals.

- Activation of minor passports/children's passports.

- Registration and, if applicable, payment. Participation in events and activities for members.
- Request for invitations/tickets for members' family members.
- Registration, information sessions, delegates' assembly.

6- FCB Statement. Regarding the decision made in response to this complaint, despite the fact that the call for the update of the membership census has been sent to 143,000 people, "to date only a total of five complaints have been received, and the other four in writing. For the sake of transparency in the process and to prioritize the protection of members, the Club opted to deactivate the service on April 5, 2023, despite the potential harm this could cause to FC Barcelona, while the entire process was reviewed with the help of the Club's Data Protection Officer, external lawyers, and the software provider, thus reaffirming its legality and the system's compliance with data protection regulations. The service was reactivated on May 4, 2023."

7- FCB states regarding the causes that led to the incident that gave rise to the complaint, that it is unaware of the member's motivation.

8- FCB states regarding the measures adopted to prevent similar incidents, implementation dates, and controls carried out to verify their effectiveness that “after conducting another analysis of the legality and security of the

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 12/139

system, the service has been reactivated, but this time it has been decided to include an additional section with specific information that clearly and transparently explains how the facial comparison service works, the type of data it processes,

including a brief definition of the authentication system, to ensure that the member understands the process and its security.

In parallel, brief information protocols have been drafted for members who wish to access them. They can contact our official member services channels so we can inform them and provide them with even more detailed information about the entire process.

A new letter has also been written to members, announcing the reactivation of the service. This letter includes a new explanation of the update process and, specifically, the facial comparison system. As previously mentioned, a thorough review of the entire procedure has also been carried out, both from a legal and technical perspective. Regarding the implementation dates, all measures related to informing FC Barcelona members will be implemented in parallel with the reactivation of the service.

9- The FCB states, regarding the security measures adopted for data processing, that given that data processing throughout the census update process is carried out using the FCB's IT systems in combination with the "das-face" facial comparison software provided by the service provider VERIDAS DIGITAL AUTHENTICATION SOLUTIONS S.L. (VERIDAS), it has been deemed important to describe both the security measures of the application used and the security and cybersecurity measures implemented by the FCB and VERIDAS.

I. DAS-FACE SOFTWARE: This is facial comparison software from VERIDAS, a company of recognized prestige and certified with the highest guarantees of reliability. The solution captures the unique features and characteristics of a face, generating a facial biometric descriptor that uniquely characterizes the person. The facial biometric descriptor is a mathematical representation obtained from the A specific set of features found on a person's face. Converting a face image into a biometric descriptor is technically irreversible, so it is not possible to recover a person's face from the resulting descriptor.

The algorithm's performance is shown in the "face biometry performance report" document. das-face calculates the similarity between faces registered in images, among other operations. The main operations implemented in this product are of the "1:1 matching" type, which compares two face images to determine if they belong to the same individual. This solution allows the entire identity verification process to be carried out remotely, without the need for travel and with significant savings in the personnel and material resources required.

During the registration process, whether through an app or a website, a photograph or video is taken of the user and a document that allows them to prove their identity. All the data contained in both the document and the face image will be sent to the validation systems. Developed by VERIDAS

This technology works, broadly speaking, as follows:

“Data is collected and processed by the biometric engine. This engine processes the data, generating what is known as a “biometric vector,” which is simply a way of representing facial features.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 13/139

At first glance, it is a very long numerical string, which has the following advantages regarding data security:

- It is irreversible: it is not possible to reconstruct a face or voice from the vector. Unlike other methods used in the past, which, for example, created a "map" of a person's face and then encrypted it, these numbers don't represent distances between characteristic points on your face. Instead, they represent a unique interpretation that the biometric engine makes of it, and only it will understand it.

- It's not interoperable: this vector cannot be used in other systems, whether they are different biometric engines or different versions of the same engine that created it. This also means that simply updating the biometric engine version would render the vectors created by the previous version useless. Therefore, in case of theft or unauthorized access, this data would be completely worthless, and all that would remain is a string of meaningless numbers.

“VERIDAS does not retain either the user's personal data or the biometric vectors
that have been created. Once the process for which our service was contracted has been completed and the relevant information has been sent to the FCB, the provider automatically deletes all the
information that was on its servers. In this phase,

the document's authenticity will be analyzed (through the processing of the data contained therein) and the person's identity. For this purpose, two
biometric vectors will be created: one from the photo contained in the document, and another from the selfie taken by the user at that moment. By comparing them (in a process known as 1:1 or one-to-one), it is possible to verify that a person is

who they claim to be. After the verification, this data is sent to the FCB and VERIDAS' systems are
deleted instantly.”

VERIDAS-accredited certifications

-“National Institute of Standards and Technology (NIST): VERIDAS is the only company in the world to participate in NIST 1:1 and 1:N assessments for facial recognition and speech recognition (1:1).

-ISO 30107-3 iBeta certification approving the liveness verification and biometric facial identity verification technology.

-Adhered to the Digital Pact of the Spanish Data Protection Agency.

-ISO 27001 Information Security certification.

-Certified under the National Security Scheme (ENS).

-ISO 9001 Quality Management certification.

FC Barcelona Certifications

-Management of member photos during online registration, in-person registration, and the 2023 Census:

Images generated during the FC Barcelona member update process are stored in ***SERVICE.5, linked to each member, along with documents related to their contact information and procedures.

- Simultaneously, the images are saved as an image in the contact form of (…) ***SERVICE.2.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 14/139

- The photos are saved in low resolution, passport photo size, and only the last photo is saved.

Security measures for the technologies involved:

- The organization's cybersecurity maturity level is assessed annually by an external specialist provider (...).

- Four independent layers of security protection (protection against (…)).

- The application infrastructure is located in a ***SERVICE.1
with private access and various security measures (…).

- Clear assignment of responsibilities and access permissions for information, ensuring logical access (based on the principle of least privilege).

- Management of users, permissions, and roles for information assets.

Periodic user maintenance is performed.

- Mechanisms for accessing resources are in place.

- A log of user actions on information assets is maintained.

- A secure procedure is in place for generating, assigning, and distributing passwords.

- A testing environment is available for new features.

- A policy and procedures are in place for change management.

- Secure remote connections are maintained via VPN.

- Cross-functional controls are in place throughout the organization to prevent and mitigate data leakage attempts (email, USB drives, SharePoint, etc.).

- Backups are in place to prevent data loss in case of accidental or intentional destruction.

- The frequency, scope, storage location, and restoration process for backups are described in a specific procedure. - A procedure is in place (…) that prevents unauthorized access to information, as well as the processing of personal data (…).

- Regular training and awareness campaigns are conducted for all FCB employees.

- Technology has been developed to inventory and classify information assets, ensuring adequate protection based on their level of confidentiality.

- Periodic reviews are conducted (…) (***SERVICE.1) of the Club.

- Initiatives and projects have been developed to adequately secure the Club's email and O365 environment.

- (…) and remediation tasks are performed.

- A cybersecurity incident response service is in place (…).

THIRD: Admission for processing 5/07/2023

On 5/07/2023, in accordance with Article 65 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights), the claim submitted by R1 was admitted for processing.


C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 15/139

FOURTH: Preliminary Investigative Actions

The Deputy Directorate General for Data Inspection carried out preliminary investigative actions to clarify the facts in question, pursuant to the functions assigned to supervisory authorities in Article 57.1 and the powers granted in Article 58.1 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Title VII, Chapter I, Section Two, of the LOPDGDD (Spanish Organic Law on the Protection of Personal Data and Guarantee of Digital Rights), having learned the following:
In order to investigate the occurrence of the events described, on October 30, 2023, a request for information was made to FCB, specifically:
1- Date from which the FC Barcelona (FCB) members can update their information digitally. Approximate number of members who have updated their information digitally.

The response was received on November 29, 2023.
FCB states that the update campaign began on March 21, 2023, and that, after receiving the notification from the Spanish Data Protection Agency (AEPD), they paused the process to verify that the procedure complied with the required regulations and to confirm its legality. The number of members who have updated their information digitally is 96,343, and in person:
10,138.

2- Explanation and documentary evidence of whether members are informed that they can also update their membership information in person.

FCB states that the strongest evidence is that 10,138 members did so in person.

FCB indicates that members have been given the option to complete the process in person at the Club's offices through various means:

A- In the first mailing to all members on March 20, 2023: "The possibility of completing the process digitally is offered, explaining the advantages of the system, but without obligation to do so online, as it offers the possibility of contacting the Club through different channels," and provides, for illustrative purposes,

DOCUMENT 1.

In this document, dated March 20, 2023, the Board of Directors' agreement (adopted on June 21, 2022) to initiate "the new membership census is announced, a renewal that aims to regularize the membership and improve security, communication, and services between the Club and its members."

The method is also indicated:

"through a digital process and from an electronic device that has With the addition of a camera and microphone, members will be able to update their personal data without having to travel to the Club's facilities. This procedure will allow all members of the Entity to be identified and has become a strictly necessary step for the modernization of the Club and the management of the Espai Barça project.

It is important to note that updating data is a duty of members as outlined in the Statutes.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 16/139

It continues: “The new census will also be geared towards the Club's digital strategy to understand the preferences of all members and to provide more personalized and targeted information based on their preferences.” This will also allow us to improve the identification process,

update any unreported cancellations, and recover
any unused memberships. This regularization of our membership
will also facilitate any necessary procedures, access to
sports facilities, participation in Club activities, and involvement in
consultation processes or elections.”

Through the QR code at the end of this document, you can access
the Club's website and consult all the information related to this

membership registration campaign. Once you have accessed the Online Procedures platform with your Personal Password and PIN, you must go to the tab

“NEW MEMBERS REGISTRATION” to then complete the

digital identification process, which will require you to photograph both sides of your ID card,

take a photo of your face, and record a short
voice message.

In any case, for any questions or concerns you may have,
you can contact the Club by phone, email

cens2023@fcbarcelona.cat, or in person at the Fan Services Office, open Monday to Friday from 9:00 a.m. to 8:00 p.m.

B-Another method, according to FCB, is that a second postal mailing was sent to
members, an “extension of the census” which is provided as DOCUMENT 2, without
specifying the date of mailing, “informing them that the deadline for
completing the census has been extended until November 30, 2023,” and adding that: “Members who
have not yet updated their information can do so digitally,
through the Club's website and the Socis App, or in person, by requesting

an appointment at the Fan Services Office from Monday to Friday, 9 a.m. to 6 p.m.”

The third method, according to FCB, was sending the census extension notice via email and SMS, "until November 30th," specifying the option to complete the process not only through the Club's website, but also via the
Socis App or in person at the Barcelona fan services office.

Document 3 is provided, which is the same as Document 2, in the form of an official Club bulletin, containing service information for members.

D-Other means: It indicates email and SMS communications. It also includes Document 4, an informational document reminding members that the Census update process is pending, although the notice in this case refers to the fact that the process ends on October 31, 2023.

E-Announcements are made through the Club's website and on-screen and public address announcements on match days.

FCB adds as “evidence of the explanation of how to complete the procedure
in person during the process,” indicating that “To begin the process

of updating the census, the member must access the “member census” area

of the Club's website, where they will find various information, explaining the
sections that comprise it, including “more information,” where

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 17/139

the FAQs are located, with a specific point detailing how to
complete the procedure in person, with the wording “Can I complete the census
in person?” The process is digital and easy to complete, but if any member

wants in-person assistance, they can come to the OAB by appointment.”

This is stated in DOCUMENT 5, which they provide.

FCB adds that at the beginning of the census update process and before
accepting the Privacy Policy, members are again offered several options
to contact the Club, especially the OAB office, and emphasizes that in
case of doubt or if they so wish, they can request an appointment to complete the
census update in person. They provide DOCUMENT 6, which is the

same screenshot provided as DOCUMENT 1 in
point 5 of the SECOND FACT regarding transfer and response, and which begins the privacy policy, first layer, or section by R1 in the first fact, point 4.

3- Explanation of how the voice of the member who accepts its recording, registration, and

use is used. Purpose of the processing.

FCB states that the voice is personal data. which, if accepted, is being recorded during the census update process, but its use is not intended for this procedure. It will be used once the census is completed, as explained below:

“A. The data collection and storage process is as follows:

a- The member records their voice, and certain biometric data is captured to allow for authentication.

b- The voice data is stored (…).

c- When the member contacts the Club by phone and identifies themselves, if their voice is recorded, it will allow for comparison with the stored voice characteristics and identification, enabling them to complete certain procedures by phone.”

“It should be noted that, as with the facial comparison process, the voice recording and processing process may not qualify as biometric data, according to the provisions of Legal Report 0036/2020 of the Spanish Data Protection Agency (AEPD) and Opinion 3/2012 of Working Party 29. This is because it involves a process of comparing biometric data with a single biometric template stored on a device; in other words, a one-to-one matching search.

B. Purposes of Processing

The sole purpose is to authenticate the member using their voice in order to facilitate any procedure, such as purchasing tickets or using a free seat, that can be carried out by phone, and thus prevent the impersonation of members that has been occurring.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 18/139

4- Explanation and documentary evidence of what happens when a member “accepts the privacy policy and does not accept the recording, registration, and use of their voice as biometric data” displayed on the welcome screen of the “new 2023 membership census.”

FCB responded that before the start of the census update process, the member

can consent or not to the processing of their voice data.

“If the consent box is not checked: The voice recording screen is automatically skipped, and the member goes directly to the screen where they must validate and, if necessary, update their personal data.”

Yes, if the consent box is checked: The voice registration screen is accessed,
where the member must confirm the voice registration, displaying the text:

“I confirm I will perform this biometric operation using my own voice. Start recording,” as shown in the screenshot of DOCUMENT 7 provided.

5- Explanation and documentary evidence of where the additional section has been included
of specific information, clearly and transparently explaining how
the facial comparison service works, the type of data it processes, including
a brief definition of the authentication system, to reinforce the member's understanding of the process and its security, as indicated in point 8 of their
letter of response to the transfer mentioned in point two.

FC Barcelona responded that the information was provided through:

a) In the census process FAQs:

https://www.fcbarcelona.es/esficha/3052201/faqs): (attached DOCUMENT 8)

“What does facial biometric comparison consist of?

To authenticate that the member is who they claim to be, we use this
facial comparison system, which does not store any biometric trace of the member
and is very easy and simple to use.

How does it work?

We simply compare the image on your ID card with the selfie we take,

and the software validates that you are the same person. Once the two
images are compared, we delete your ID card and only save the current photo without any biometric trace.

And why do we ask you to move your head?

We ask this to verify that it is a real-time photo and to demonstrate your

physical presence, thus preventing the selfie from being taken from another photo.

Does FC Barcelona Does Barcelona create a database with our biometric data?

No, once the two images are compared, all biometric comparisons

disappear and are irreversible. We only keep your updated photo.

Is it mandatory to use this system?

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 19/139

We have opted for this system because it offers many advantages to members, since
they do not have to travel to our offices. However, if you prefer to complete
this procedure in person, please contact us and we will schedule an appointment for you to complete

the procedure at our offices. In any case, we would like to inform you that we have conducted
a prior study of this system to validate its complete legality and security.

b) Through the communication channels with the Club that are made

available to members before starting the census process, specifically

before accepting the privacy policy.

All members who have contacted the Club through the available channels have been given a detailed explanation of the process, and where applicable, have been offered the option of completing the procedure in person.

c) Video explaining the process in the Census section of the FCB website.

6- Letter sent to members explaining the update process and, specifically, the facial comparison system. Date sent.
Documentary evidence of how it was made available to members.

FCB responded that “Members have received information about the need to update the census through various means and repeatedly, as noted in point TWO and in the FAQs, point FIVE.”

They provide DOCUMENT 9, which details the dates and type of communication sent: BOC (institutional, which cannot be omitted as it is not commercial communication), INFOSOCIS, and SMS messages, including content, web links, and direct communication to members (March to October).

7- Description of the biometric data processed during member identity verification, where it is stored (indicating whether the servers are internal or external and their location), and for how long. Identification and purpose of the biometric data that remains in the system after the member identity verification process, how and where it is stored (indicating whether the servers are internal or external and their location), and the planned deletion timeframe.

FCB responded that to carry out the member authentication process, it has
used the facial recognition software from VERIDAS Digital Authentication

Solutions S.L., which acts as a partner of INDRA SOLUCIONES TECNOLÓGICAS DE
LA INFORMACIÓN, S.L.U. and SISTEMAS INFORMÁTICOS ABIERTOS, S.A. (SIA),

an INDRA GROUP company, as the main providers of the IT process for
updating the member census.

“The VERIDAS (das-Face) solution captures the unique features and characteristics of a face, generating a facial biometric descriptor that uniquely characterizes the person.

During the authentication process, a photograph of the member and a photograph of a document that allows them to prove their identity (ID card, passport) are taken.

The software processes the data and generates a unique biometric vector, which is a long and irreversible numerical string, making it impossible to reconstruct the image. This biometric vector is not interoperable and cannot be used in other systems, rendering it useless for any subsequent action or processing.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 20/139


This biometric vector is not interoperable and cannot be used in other systems, rendering it useless for any subsequent action or processing. “Once the facial comparison process is completed, the ID card is deleted by FCB, and the biometric data remains encrypted by SIA for seven days on its own servers located within the European Economic Area. VERIDAS does not host any biometric data on its own or third-party servers.”

8- Description of the actions taken when the facial comparison result is negative (registration, notification, deletion, etc.), identification of the personal data that remains in the system, and an explanation of how and where it is stored.

FCB responded that if the facial comparison result is negative, a message appears indicating that the process cannot continue, and, consequently, the member must update their registration in person at the OAB. Members have communication channels with the OAB and the Club for these situations.

9- Explanation of the "geographic scope of processing" aspect included in the Impact Assessment section, Level Two.

They provided DOCUMENT 10, showing the worldwide geographic distribution of

FC Barcelona members, according to the registry of November 8, 2023, reaching a total of 146,808.

10- Regarding the privacy policy: "Use of
biometric data for the authentication, identification, and validation of members and
validation of member access to Club facilities and for

remote/online procedures with FC Barcelona." Description of how they use
biometric data for member access validation at Club facilities.

They responded that, currently, and until the census update process is completed, they do not foresee using any biometric data.

Once this is completed, in the future, and with the prior consent of FC Barcelona members, the data may be used for the following purposes:

“Access to Club facilities: By having an updated image of the members, VERIDAS' solution, das-face, will allow the collection of biometric vectors that facilitate access to Club facilities. Before implementing this process, an impact assessment will be carried out, and the consent of members who wish to use this system to authenticate and identify themselves for access to Club facilities will be requested. Those members who do not wish to use this system may continue to access the facilities using the current barcode validation system at the turnstiles.

The sole purpose is to authenticate members using their voice to facilitate any procedure (procedures, ticket purchases, use of facilities).

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 21/139

of the available seat…) that can be done by telephone and prevent the
impersonation of the member.

Although some of the purposes of the processing may
begin to be carried out some time from now, for the sake of transparency towards the

members of FC Barcelona, it has been decided to inform them of the
current and future purposes that may be carried out through biometric systems.

11- Copy of the Register referred to in Article 30 of the GDPR of all
biometric personal data processing activities carried out under your
responsibility.

Provides DOCUMENT 11, record of the activity UPDATING THE CENSUS of the
RAT.


12- List of participating entities, processors, and sub-processors of biometric data, description of their role, copy of the contract signed by FCB
with the processors, and clauses relating to the processing of personal data, and a copy

of the sub-processors' authorizations, if applicable.

FCB responded:
Data Controller:

FC BARCELONA

Data Processor (Provider):

INDRA INFORMATION TECHNOLOGY SOLUTIONS, S.L.U. (INDRA)

The service agreement signed between
INDRA and FCB, dated October 24, 2022, is attached as Document No. 12.

In Annex I, the technical and economic offer for the "renewal of the membership census" is presented for September 2022.

INDRA provides the service of developing the applications for updating the membership census through electronic digital identification and integrating the data into SERVICE.2 of the Social area. (Clause One -

Purpose).

Clause Eight and Annex II relate to the protection of data that is owned by FC Barcelona, and the provider is authorized to collect and use the data within the framework of providing services. The aforementioned annex, "Data Processing Agreement," complies with the requirements of Article 28 et seq. of the GDPR, and may access, among other information, facial and voice biometric data. Section 4 states that the
processor must implement appropriate security and organizational measures
to guarantee the protection of personal data belonging to the

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 22/139

data controller as described in Article 32, and ADDENDUM I contains
the technical and organizational measures.

Annex I contains the technical and economic offer, which includes “access to the VERIDAS digital onboarding service for a complete package of 140,000 processes -
including document capture and validation + facial biometrics + ISO 30107 Level 2 liveness test + video identification.”

As part of the offer, details of access via the FCB website or app are included in the "proposed scope," where the app will redirect users to the web portal. A tool in ***SERVICE.3 is offered to view members who still need to undergo biometric validation, allowing them to be included in a campaign.

The solution description, including the steps for facial biometrics, is also provided.

Sub-processors:

SISTEMAS INFORMÁTICOS ABIERTOS, S.A. (SIA)
An INDRA GROUP company that provides licensing services for VERIDAS digital identity and digital accreditation products and professional services for the implementation of the Digital Identity Accreditation Service deployed in the SIA cloud.

Attached as Document No. 13 is a copy of the processing agreement

INTRAGROUP PROCESSING signed between INDRA and SIA on November 14, 2022.

Clause 6, Subcontracting, express authorization is given for the subcontracting

with VERIDAS Digital Authentication Solutions S.L. of the digital identity accreditation service for FCB members through the use of VERIDAS licenses,

and according to the scope of activities included in the offer sent
to the client FCB, on behalf of INDRA SOLUCIONES, which will act as
the data processor for the main client. The processing description states:

"Identification of FCB members with VERIDAS licenses for
updating the member census, biometric data for identification purposes (image and voice) and for identifying purposes in 'categories of
data subjects and data types,' with data storage hosted on
proprietary servers within the EEA.

VERIDAS Digital Authentication Solutions S.L.

INDRA partner for the use of the das-face facial comparison software and
das-peak voice authentication.

The agreement signed between SIA and VERIDAS is provided as DOCUMENT No. 14,

referring to a commercial partner agreement dated March 4, 2021, with an addendum dated
June 30, 2021, and an addendum dated June 23, 2023. Document 14 indicates that

biometric data is processed for identification purposes (image and voice) and for identifying purposes.

Point 4 establishes among VERIDAS' obligations The

use of the data accessed, for the purposes of the assignment and processing thereof,

in accordance with the instructions received, the obligation to provide a general description
of the technical and organizational security measures relating to:

-The pseudonymization and encryption of personal data.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 23/139

-The ability to guarantee the ongoing confidentiality, integrity,

availability, and resilience of the processing systems and services.

-The ability to quickly restore the availability of and access to personal data in the event of a physical or technical incident.

-The process for regularly verifying, assessing, and evaluating the effectiveness of the technical and organizational measures to ensure the security of the processing.

13- Specify whether the processing activities involve international transfers of personal data and, if so, detail the safeguards applied.

FCB responded that they do not.

On June 26, 2024, FCB was asked to provide further information, specifically:

14- Justification for why it is necessary for all members to create their digital profile.

Date from which members can create their digital profile.
Number of members who have a digital profile.

A written response was received on July 17, 2024. FCB states that: “As we explained in previous responses to information requests, creating a digital profile is voluntary for members, although FCB intends for the majority of members to have one, to allow us to interact with them in an agile and, above all, secure manner, given the special circumstances of FCB members, namely their geographical dispersion,

certain problems with membership impersonation and illegitimate transfers of membership cards, which can even lead to security problems at football matches, as we explained in point (I.) of the FIRST allegation in our response to the first information request.

These circumstances have led us to seek a system that not only allows us to have an accurate membership census, but also provides us with tools that will allow us to interact with members in an agile and secure manner in the future, and that no
requires members to visit the FCB offices for any procedure.”

It should be emphasized that, while FCB has prioritized the digital process because it is considered the most suitable, convenient, and secure for both members and the Club, members have never been required to create a digital profile; this is entirely voluntary. Furthermore, it should be noted that, currently, the only “digital profile” that FCB has for its members is their voice record. “

The date from which members can create their digital profile coincides with the start of the census update process, which began on March 21, 2023.

Currently, of the 124,864 members who completed the census update process, 72,187 have accepted their digital voice profile.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 24/139

15- Explanation of the following text, which appears at the end of the SECOND response to the document sent to this Agency in response to the complaint on May 22, 2023: “All of this is without prejudice to the fact that, as previously mentioned,

members are not obligated to use the facial comparison system, although for logistical and operational reasons. Yes, it was prioritized.

FCB states that, “after analyzing the different means to carry out the census update process, and taking into account the specific characteristics of FCB members, it was determined, after analyzing the system's security and the reports and criteria that the Spanish Data Protection Agency had at that time regarding biometrics, that the facial comparison system was the most effective and secure way to carry out the census update process, and, above all, the most convenient for FCB members. Therefore, and on a voluntary basis, this system was chosen and prioritized.”

16- Explanation of whether the Census update process requires, in any case, the creation of a member's digital profile. If applicable, justification of the need for a member's digital profile for the in-person Census update process. Number of members who have updated their Census.

FCB responded: “No, members could choose from three different options:

1- Complete the process in person at FCB facilities without creating a digital profile.

2- Through the FCB website, choosing not to create a digital profile.

3- Through the FCB website, choosing to create a digital voice profile.”

FCB states that the in-person census update process in no case required the creation of a digital profile. In fact, of the 12,249 members who completed the process in person, only 160 created a digital voice record.

Number of members who have updated their Census: 124,864

17- Explanation of whether it is possible for a member to complete the Census update process, either in person or online, without undergoing facial recognition or, therefore, without any processing of biometric data (facial and/or voice biometric vectors). If applicable, number of members who have updated their Census data without biometric data processing.


FC Barcelona responded that “The only way to skip the facial comparison process is to complete the procedure in person or through the OAB (Member Services Office). If the member chooses to complete the procedure digitally, they must still complete the facial comparison process, as, logically, this is the system that allows us to reliably identify the member.

A total of 12,704 members have completed the Census update process without biometric data processing.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 25/139

18- Regarding the processing activity “Census Update,” and specifically concerning biometric data, please indicate whether a report was requested from the Data Protection Officer prior to the start of the processing. If applicable, supporting documentation.


He responded that “The entire process of analyzing the tools to be used for the
census update process has been carried out in conjunction with the FCB Data Protection Officer and

the software provider.
In fact, our Data Protection Officer has actively participated in

all the meetings, drafted a preliminary report and a final report regarding the use
of biometrics, and collaborated on the RISK ASSESSMENT REPORT FOR THE FACIAL COMPARISON PROCESS.

He has also been present at the meetings with the software provider's legal team and has had access to the VOICE BIOMETRIC PROCESS IMPACT ASSESSMENT REPORT PREPARED BY A LAW FIRM AT THE PROVIDER'S REQUEST.”

Document 1, which is attached, includes:

-A document dated September 22, 2022, entitled: “PREVIOUS ANALYSIS OF THE

USE OF BIOMETRICS IN THE MEMBERSHIP CENSUS UPDATE PROCESS:

“We have been informed that, for the census update process, a biometric facial comparison system is being considered. This system compares two images of the same person in real time, allowing for reliable authentication of the member and guaranteeing the prevention of potential impersonation.”

In the explanation provided by the software vendors, they reiterate the facial comparison process, which involves “obtaining biometric vectors from the member during census verification.” “The biometric vectors are extracted from both images and compared to verify the member's authentication.”

“Once the images are compared, the ID card is removed, and the real-time photo is retained as the member's updated image for their membership card.”

“Once the images are compared, the ID card is removed, and the real-time photo is retained as the member's updated image for their membership card.” “This facial comparison is instantaneous, so the biometric data

is deleted and not stored in any database, since the
authentication is in real time and the biometric vectors are not needed
for any other purpose.

In short, the biometric authentication process will consist of a
comparison process between biometric data that compares a static image

(photograph of the ID card) with another image (selfie) taken of the member in
real time, and does not involve comparison with a database of a

group, which is commonly known as a one-to-one matching process.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 26/139

“Based on the information provided and lacking a more in-depth understanding of the entire process, FCB is urged to conduct, with our guidance, an analysis of the entire process that will allow us to determine:

The need for the use of biometric systems,

The legitimacy of processing biometric data,

The category of biometric data processed,

The need to conduct a risk assessment regarding the processing of biometric data, indicating:

-Risks inherent in the use of biometrics.

-Proportionality of the use of the biometric system compared to other authentication systems available on the market.

-The need or not to carry out a Data Protection Impact Assessment (DPIA) considering the specific characteristics of the system.

-A document, dated November 9, 2022, entitled: “CONCLUSIONS ON THE ANALYSIS OF THE PROCESSING OF BIOMETRIC DATA IN THE MEMBERSHIP CENSUS UPDATE,” states:

“In order to verify the feasibility and compliance with the General Data Protection Regulation (GDPR) of the entire procedure for updating the FC Barcelona members' census using a biometric system, FC Barcelona was asked to conduct an analysis of the entire procedure to verify its legality and effectiveness compared to other authentication systems, as well as to determine whether an impact assessment will be necessary.” ANALYSIS:

1- Regarding the need for biometrics in the membership update process, recommended due to its geographical dispersion,

to avoid requiring in-person visits to offices and to prevent fraud and
identity theft, the authentication system is effective and necessary,

pending a detailed analysis of the biometric process to verify its legality
with respect to the GDPR.

2- Regarding the legitimacy of processing biometric data, it notes that

since the purpose is to authenticate a person, distinct from a one-to-all process,

it is based on a simple facial comparison, comparing a static image,

a photo from the ID card, with another image, a selfie taken by the member in real time and

moving, and without “implying a one-to-one comparison of the member

with a database of a group.” They believe that the processing would not
be considered a special category of personal data, and could

be based on the legal grounds of Article 6.1.b) of the GDPR,

and does not require the consent of the data subjects. “However, in our
capacity as Data Protection Officer, we recommend that the biometric process be voluntary and at the
choice of your members.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 27/139

3-Need to carry out a risk assessment regarding the processing of
biometric data. From the conclusions of the risk assessment report,

which are copied below, the following can be deduced:

The processing is not included in Articles 35.1 and 2 of the GDPR as
processing that requires an impact assessment.

…

Although biometric data is processed, it cannot be considered
as a special category of data, according to the GDPR itself

and the reports prepared by the Spanish Data Protection Agency.

Regarding the purposes of the processing, it has been determined that no purposes that entail risks are carried out.

Regarding the context of the processing, despite the use of new technologies,
given their security, the type of biometric data processed, and the
facial comparison performed to authenticate the member, it is not considered
that the processing entails a risk for FCB members.

As for the technologies used, although biometric processing could be classified within the definition of technologies

considered immature, the software used has been tested and has been
determined to be completely secure. Furthermore, VERIDAS DIGITAL, the software owner, holds the most recognized certifications, therefore
we consider that its use does not pose any risks to FCB members.

No data transfers or international data transfers are carried out.

The data controller does not perceive that the main activity of the
processing involves a high risk, therefore, based on the three levels of
analysis and the questionnaire responses, it is concluded that the processing of

biometric facial comparison data for the FCB member census update process does not require an
impact assessment.

Once the various risks that may affect the processing of
data during the FCB member census update process have been analyzed, it is observed that the risk of the analyzed data processing is
minimal.

In CONCLUSIONS, it states:

“Based on the analysis of the various points examined and the results of the
risk assessment, we understand that the biometric update process

that FC Barcelona intends to use to update the
Club's membership census complies with the General Data Protection Regulation (GDPR).

However, we suggest that, taking into account the different characteristics
of the Club's membership and their lack of familiarity with
these technologies, the information provided to members regarding the process be as transparent as possible.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 28/139

Furthermore, although based on the statutory obligation to periodically update the census and
that, according to the conclusions of the process analysis, it would be possible to opt

for the biometric method to be mandatory, we consider

that the process Digital census updates must be voluntary,

Members may choose to complete the process in person.

- A written record of the main meetings held by the Data Protection Officer with the various internal and external stakeholders who participated in the census update process. This record covers the period from September 12, 2022, to April 28, 2023, and includes the following: “(Legal – IT – DPO – Indra – SIA – Veridas): Analysis of the suitability and legality of the biometric census update process, following the information request received from the Spanish Data Protection Agency.”


19- Regarding the processing of biometric data, security measures

implemented by the data controller and sub-processors involved in the digital process.

FCB responded that regarding “identity verification by voice recognition”

Regarding the operation of das-peak, it is a voice biometrics engine
capable of capturing the unique physical characteristics of the vocal apparatus and features such as frequency, speed, and accents, compiling them into a unique biometric voice vector.

This vector is irreversible; that is, it is impossible to return to the original audio
that generated it (not even the developer of the das-peak biometric engine would be

able to reverse the process). This means that even if the vector were lost or stolen, it would not be a loss of biometric data (the person's voice), but
only of the vector, which is simply a number that can only be used
in the engine that created it (it would not work in others). engines, not even in
other VERIDAS systems) and does not provide any personal data.

Regarding the recognition process, the registration of the person will depend exclusively on the VERIDAS Client. This solution can be integrated with various communication channels, requiring only a microphone for voice recording and a system to send that recording to the VERIDAS biometric engine (hosted in the cloud via an access point).

The system captures the unique characteristics of the voice from an audio recording and compiles them into a unique and irreversible biometric vector associated with the Client's ID.

VERIDAS does not store voiceprints under any circumstances. Once the biometric engine generates the vector, it will delete any information/data and return it to the Client, who will be responsible for storing these voiceprints on servers.

Once the registration process is complete, verification can be performed. This will require a new voice recording, which will be compared to the existing biometric vector. During this process, the following steps will be taken: Anti-fraud tests to prevent identity theft. Regarding the identity verification process,

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 29/139

This can be carried out through a 1:1 authentication model, in which the process acts as a two-factor authentication. Once the user has been previously identified and a vector associated with that person has been obtained, which is then linked to a phone number, ID card, password, etc., the double recording (the verification recording) will be compared with that associated vector. In short, a comparison is made between the biometric vectors of the two specific audio recordings to determine if there is a match.

20- Explanation of the procedures that members who have consented to the recording, registration, and use of their voice as biometric data can currently carry out.
Date from which these procedures can be carried out.


He responded that “To date, no procedure has been initiated that would allow the use of voice biometrics. This system was designed to allow members to securely complete procedures by telephone, and it was developed based on the reports and criteria being applied at that time by the Spanish Data Protection Agency and the European Commission's Article 29 Working Party. In other words, both the facial comparison and voice identification systems, being based on a simple (one-to-one) authentication system that does not generate a biometric database of Club members, were not considered special categories of personal data.

Following the latest reports on biometrics published by the Spanish Data Protection Agency, which radically changed its criteria, FC Barcelona has decided not to implement the voice authentication process and to review its legality and suitability. to the study by our
Data Protection Officer to determine whether or not we can use it.

If the conclusion is that we cannot use this system, we will take the appropriate action regarding the voice biometric data we have.

21- Explanation of whether the Census update process has been completed and the current status of the following initiatives related to the use of biometric data:

o Validation of member access to Club facilities.

o Remote/online procedures with FCB.

FCB responded that “The census update process was completed on November 30, 2023.

Initially, biometric data has not been collected to validate access to FCB facilities, and based on the criteria of the Spanish Data Protection Agency,

no procedures are planned in this regard.

Regarding remote/online procedures, as explained in the previous statement,

it is currently not possible to carry out any remote or online procedure
that involves the processing of biometric data.

22-As part of the investigation, on August 29, 2024, the official FC Barcelona website was consulted and the following was observed:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 30/139

In the "Become a Member" section of the "MEMBERS" tab,

https://www.fcbarcelona.es/es/socios/hacerse-socio, two
membership options are shown:

-Online Registration

-In-Person Registration: Membership can also be registered

in person at the FC Barcelona Supporters' Office (OAB) by scheduling an appointment.
       On the "Member Census" tab,

https://www.fcbarcelona.es/es/socios/censo-socios, the notice appears: "THE
CENSUS PROCESS ENDED ON NOVEMBER 30TH.
TO UPDATE YOUR INFORMATION, YOU MUST GO TO THE

SUBSCRIPTION OFFICE."

In "How to Register?",

https://www.fcbarcelona.es/es/ficha/3052130/como-
censarte, the "procedure for completing the census and creating your digital profile" is described, which can be done via the Club's website or the Socis App. This procedure is reproduced below:

"Each member can update their information personally without needing to go to the Submission Office. The entire process is done entirely digitally, from an electronic device with a camera and microphone."

" ... Creating your digital census profile should be done in a well-lit area with no screen glare or background noise.

[…] After accepting the privacy policy, you will proceed to digital identification. This will require you to photograph your ID card, NIE (Foreigner's Identity Number), or passport, take a full-face photo, and optionally record a short voice message.

Regarding the voice recording, you can freely and unconditionally choose whether or not to check the box "I accept the recording, registration, and use of my voice as biometric data," as it is optional, not mandatory.

If you choose not to check the box and therefore do not authorize voice recording, you can still continue with the census data update process and complete it successfully.

Once digital identification is complete, you will access the data update screen, which will already include the information that can be extracted from your photo. National Identity Document (DNI), Foreigner's Identity Number (NIE), and Passport already submitted. Once the required data is updated and completed, you will be included in the new FC Barcelona census.

[...] Census of Members Under 18

The process is the same as for adult members, with the difference that for members under 18, the parent or legal guardian must validate their information by declaring that they are the minor's representative

completing the census process.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 31/139

Members under 14 years of age must complete the process like adult members, photographing their National Identity Document (DNI) and taking a selfie.

Members under 14 years of age must upload a photograph and can add their National Identity Document (DNI) number.

[...] 23- As part of the investigation, on August 29, 2024, the FCB Privacy Policy was consulted and found to be consistent with the document in the second layer, as reflected in FACT TWO, point 5.

FIFTH: Receipt of two new complaints
While the investigation was underway, two additional complaints were received:

On December 3, 2023, a complaint was received from COMPLAINANT 2 (R2 - GENERAL ANNEX), who stated that they are a member of FCB and that on August 30, 2023, they received an email requesting their data to create a digital profile in order to update the Club's membership list. They stated that they did not comply with the request in the email because they believed their data were
updated.

He goes on to state that on October 2, 2023, he received another email
reminding him that he had to update his census data as a regulated obligation
in the Bylaws, Article 11.8, and he provides a copy of it. It is a newsletter that

informs:

“You have yet to complete the process of updating your census data as a

member. And that the Club initiated this process with the aim of updating the data it currently has
in order to improve and increase personalized communication between the
Club and its members.

“Creating your digital profile is absolutely necessary for the modernization the Club is undertaking, the reorganization of the capacity of the new Stadium, and will also allow you to enjoy the new services available at the new facilities in the very near future.

This process ends on October 31, 2023, and all members who have not updated their information in the census will not be able to renew their membership card for 2024, which will result in the loss of their season ticket status

when renewing their season ticket to the New Camp Nou.”

R 2 notes that the FCB Statutes do not provide for the creation of a digital profile

with the provision of biometric data. Furthermore, it considers that “expanding the number of data points required beyond those stipulated in the Statutes, and linking biometric data to unrelated issues such as capacity reorganization or the provision of unsolicited services, could cross certain red lines.”

It includes a copy of an email dated October 2, 2023: “Deadline for updating the membership census: October 31, 2023.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 32/139

On December 20, 2024, its complaint was accepted for processing by the Spanish Data Protection Agency (AEPD).

R2, dated December 27, 2023, expands upon his claim, stating that on December 19, 2023, an FC Barcelona employee contacted him by phone to update the membership census data, without the prior obligation to provide his biometric data—neither voice nor video recording—thus concluding the process.

On February 1, 2024, a claim was received from the person listed as CLAIMANT 3 in the GENERAL ANNEX (hereinafter R3). He states that, regarding the membership census update process, despite the public and private communications sent and the multiple extensions granted, he is aware that he has not yet completed the update, even though it is presented as a statutory obligation for members. He believes that the requirement for biometric data may contravene data protection regulations.

This claim was admitted for processing on February 14, 2024.

SIXTH: AXESOR Report
According to the report obtained from the AXESOR tool, the entity FÚTBOL
CLUB BARCELONA is an Association, within the activities of sports clubs, in the sports, recreational, and entertainment sector, classified as a "group parent company," with a turnover of €504,561,000 in the last available fiscal year, 2015, ending June 30, 2015.

On the other hand, the FCB website provides free and open access to the ANNUAL REPORTS, the latest being for 2023/2024. This is found in the "Economic Area" section (pp. 216-341).

In the section on FCB and Subsidiary Companies, the consolidated annual accounts for the fiscal year ending June 30, 2024, and the consolidated management report include the audit report of the consolidated annual accounts (p. 227 of 348), referring to FCB as the Club and its "subsidiaries," with the balance sheet as of June 30, 2024.




On page 237, the consolidated profit and loss account for the fiscal year ended June 30, 2024, is shown, with a net turnover for the 2023/2024 fiscal year of ***AMOUNT.1, compared to ***AMOUNT.2 for the preceding fiscal year. Note 18.1 details the structure of the net turnover.



SEVENTH: Commencement Agreement of 23/12/2024
On 23/12/2024, the Director of the Spanish Data Protection Agency (AEPD) agreed to initiate sanctioning proceedings against FC Barcelona, in accordance with the provisions of Articles 63 and 64 of the LPACAP (Law on the Common Administrative Procedure of Public Administrations), as follows:

“FIRST: TO INITIATE SANCTIONING PROCEEDINGS against FC Barcelona, with Tax Identification Number (NIF) G08266298, for the alleged infringement of the following articles of the GDPR:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 33/139

9 of the GDPR, in accordance with Article 83.5.a) of the GDPR, classified as very serious for the purposes of its statute of limitations in Article 72.1.e) of the LOPDGDD.

35 of the GDPR, in accordance with Article 83.4.a) of the GDPR, classified as serious
for the purposes of its statute of limitations in Article 73.t) of the LOPDGDD.

(…)

FOURTH: THAT for the purposes provided for in Article 64.2 b) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations, the applicable penalty would be €6,000,000, without prejudice to the outcome of the

investigation.”

As specified in legal basis VII:

“The assessment of the circumstances contemplated in Article 83.2 of the GDPR, with respect to the infringement committed by violating the provisions of Article 9 of the GDPR, allows for an initial administrative fine of €4,000,000, and

for the infringement of Article 35 of the GDPR, with an initial administrative fine of €2,000,000, without prejudice to the outcome of the investigation.”

EIGHTH: Allegations against the initiation agreement

Having been notified of the aforementioned initiation agreement in accordance with the rules established in the LPACAP, the respondent submitted a statement of allegations on January 24, 2025, in which it stated:

1- It reiterates the circumstances that led to the selection of the system for updating the census.

Provide a table showing the location of FC Barcelona members as of June 30, 2022, and the total percentage they represent.

Barcelona (city): 54,337, representing 38%

Barcelona metropolitan area: 24,379, representing 17%

Catalonia: 49,527, representing 34.6%

Spain: 7,143, representing 5%

Rest of the world: 7,700, representing 5.4%

Therefore, FC Barcelona believes it was necessary to find a system that would allow for

real verification of the identity of all Club members.

The online platform alternative (forms and attachments) was discarded because it does not
allow for authenticating members and verifying their identity in a real way, and

because it was insecure to establish a system that involved sending documents such as ID cards electronically,

while also having to temporarily store
copies of sensitive documents such as ID cards or passports.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 34/139

However, the method used for biometric authentication, comparing two images of the same person in real time—the ID card and the photograph—:

- “avoided sending copies of identification documents such as the ID card/passport.

- It ensured that the procedure was carried out by the member,

unlike the use of an online platform or form where there is no way to know the identity of the person carrying out the procedure or filling out the form,

and to verify if they are indeed the member.

- This system was deemed more suitable due to its reliability, security, and advantages, as it guaranteed the ability to verify the identity of members

without risk of fraud or impersonation, quickly and easily.

2- FCB reiterates its arguments regarding the differentiation between identification and Authentication,

the latter answering the question of “Is this person who they claim to be?”, and that in
identification, a person's biometric data is compared with that of a
set of users to determine the individual's identity. FCB considers that the
authentication process for both image and voice is one-to-one,

and not for the purpose of unambiguous identification. “Authentication is a comparison of the
person who must be in front of a camera with a previously

stored photograph of them. “

FCB points out that when FCB began its analysis of the processing and the system,
in the last half of 2022, from March 20th to November 30th, 2023, the Spanish Data Protection Agency (AEPD) maintained a
criterion that differentiated between authentication and identification, “primarily implying that authentication was not considered sensitive data or a special category data in accordance

with Article 9.1 of the GDPR.” Just days before the deadline set for the
conclusion of the process, the AEPD changed its criteria with the “guide on the processing of
attendance control data using biometric systems” of November 23rd, 2023, when almost
all of the processing had already been carried out. The “alleged breaches and
infringements of the regulations that FCB has supposedly committed are based on the application of the new criteria by the AEPD, which did not exist when

the data processing began or was being carried out.” In its initial agreement, the Spanish Data Protection Agency (AEPD) made an interpretation similar to that found in an interpretive guide that did not exist at the time the processing was analyzed and initiated.

Even so, FCB met all applicable requirements according to the new criteria (legitimate basis for the specific processing of biometric data and a report with the minimum content required for an impact assessment), both for the processing of images and voice, something the AEPD failed to consider in its initial agreement.

FCB states that, according to Article 9.1 of the GDPR, biometric data is defined as data used for identification purposes, but the term "authenticate" is never used, and although related concepts, they are not synonymous. Therefore,
initially a distinction is made between biometric data that can be used for

authentication or identification, and only data
used for identification will be considered sensitive, as stipulated in Article 9.1.


C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 35/139

FCB states that Opinion 3/2012 on the evolution of biometric technologies, dated April 27, 2012, from Working Party 29 (Opinion 3/2012), already made this distinction between authentication and identification before the GDPR came into force.

It also mentions that the European Commission's White Paper on Artificial Intelligence, dated December 19, 2020, reiterated this distinction.

It adds that the definition in Article 4.14 of the GDPR refers to data that "enables or confirms the unique identification of a person, such as facial images or fingerprint data," which it considers consistent with Article 9.1 of the GDPR, since biometric data can be used in different ways and for different purposes. purposes, which may or may not be of a special category, depending on their purpose. It considers that only the purpose of unique identification falls within Article 9.1 of the GDPR, with authentication falling outside that definition and the content of Article 9.1 of the GDPR. It believes that this was the criterion initially adopted by the Spanish Data Protection Agency (AEPD) until November 23, 2023.

FCB considers that if the authentication processing it carried out is not of a special category, it also does not pose a high risk, and therefore there was no need to lift the prohibition or conduct a Data Protection Impact Assessment (DPIA).

It adds that “Even so, and without it being necessary, at the time the processing was carried out,

for both the processing of biometric image and voice data, the consent of the data subjects was obtained and a report was available that complies with the requirements of Article 35.7 of the GDPR.”

FCB states that a criterion that did not exist at the time of the data processing is now being applied retroactively, when in reality FCB adhered to and acted at all times based on the guidelines and orientations of the Spanish Data Protection Agency (AEPD) in effect at that time.

“The initial agreement does not mention this prior and well-known criterion of the AEPD,” “it seems as if this criterion had never existed.”

“Before its change of criteria, the AEPD had acknowledged in its own guidelines and documentation that the processing of biometric data intended for authentication did not fall within Article 9 of the GDPR and, therefore, did not require an impact assessment.” Specifically, pages 30 to 32 of the guide “Data Protection in Employment Relationships” address the processing of biometric data, and the Spanish Data Protection Agency (AEPD) distinguishes between authentication and identification, concluding that certain aspects or safeguards must be considered in each case, and that an impact assessment is only necessary when using a biometric identification system.

“FCB has always acknowledged and transparently reported the use of biometric systems and biometric data from the outset, but made it clear that this was not biometric data as defined in Article 9.1 of the GDPR. In other words, it was biometric data not classified as special categories of data or sensitive data that does not pose a high risk.”

The Spanish Data Protection Agency (AEPD) is applying the new criteria to a previous processing activity and has reached a retroactive and unfavorable conclusion.

It states that the purpose of identification and authentication are not the same, although they are related, as they require different processes and actions. It points out that, unlike identification, which requires the data subject to provide prior biometric information (C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 36/139

to establish a database of biometric templates along with the rest of their personal information or with some data that reveals their identity), authentication does not involve obtaining prior biometrics or creating a database with biometric templates. There is no database with biometric templates.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 36/139 A biometric identification system requires a biometric database
previously stored, as we have indicated, since it will subsequently receive

new biometric data that does not carry any associated identity in order to
compare it with the entire database of biometric templates and uniquely identify the individual.

The system used by FCB, a biometric authentication system, does not perform any type of identification task by comparing received biometric data with
others to identify and obtain the person's identity. Here, an
identity is received; the member provides it. It is not necessary to identify them. What the

system does is simply compare two images provided at the same
moment by the member to validate that identity and prevent
impersonation or fraud. The system only verifies if the member's identity is real, but it is the member who identifies themselves.

And, in conclusion, during the authentication process, a photograph is taken of the member and a photograph of a document that allows them to prove their identity (ID card, passport). It adds that, since a biometric database has not been created from the image

for updating the census, there would be no risk of theft of said non-existent database, which is one of the risks mentioned in the initial agreement.

FCB states that Guidelines 5/2022 on the use of facial recognition technology

in the application of the Law, adopted on April 26, 2023 (Guidelines 5/2022), also refer to authentication as sensitive data, a criterion that the Spanish Data Protection Agency (AEPD) did not share at that time and did not acknowledge until the end of November 2023.

FCB believes that “the biometric template extracted from the face in the ID card photograph and the process used to compare it against the one extracted from the live photograph of the member cannot be considered a unique identification, since the system is not identifying the person.” The member was already indicating their identity from the outset, and the system did not perform any task of comparing the biometric template taken with multiple templates from different interested parties. Instead, it only compared two photographs of the same person who had previously identified themselves to verify if there was fraud or impersonation. The system does not identify or validate a credential presented by the member by comparing it with a photograph of their face.

Therefore, it cannot be concluded that the processing of biometric data initiated and completed before November 23, 2023, constitutes, under any circumstances, the processing of special categories of data, since, according to Article 9.1 and the criteria maintained by the Spanish Data Protection Agency (AEPD), the biometric data falls outside the scope of Article 9.1.

Furthermore, it should be added that, although the voice was stored for a period of time, its purpose was also for biometric authentication through a one-to-one process, which, until November 23, 2023, was not considered by the Spanish Data Protection Agency (AEPD) to be a special category or sensitive data. Moreover, for the processing of the voice data, the consent of all interested parties had been obtained, and a prior report was available

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 37/139

containing the content of Article 37 of the GDPR and a prior and positive impact assessment.

Finally, all biometric data related to the voice was deleted following the change in the AEPD's criteria, at the same time as the second information request was answered

on June 17, 2024.

The voice biometric data was obtained in accordance with the criteria of the Spanish Data Protection Agency (AEPD) and with all the guarantees required by the regulations. A reasonable period of time was maintained to allow the Data Protection Officer (DPO) to study the feasibility of its use, following the AEPD's unexpected change of criteria. “The purpose being to benefit members without any profit motive or risk to their privacy (in reality, the purpose of the processing was to safeguard the privacy and security of members in remote procedures).”

FCB lists a set of documents that reveal the previous criterion as of November 23, 2023:

- The Spanish Data Protection Agency's (AEPD) Guide to Data Protection in Labor Relations, dated May 18, 2021. A screenshot is provided, which expressly states that they are considered a special category of data.

- The sanctioning procedure ***PROCEDURE.1 (…), signed on June 1, 2022, states that on page 22, FCB assesses the identification and authentication in the processing of biometric data, indicating that: “Article 9.1, along with the prohibition of processing, indicates that those “aimed at uniquely identifying a natural person” are considered special categories of data, which indicates that the Biometric data, by its nature, is not sensitive; however, its sensitivity depends on the use or context in which it is used, the techniques employed for its processing, and the consequent interference with the right to data protection.

-Legal Report 36/2020, published on the AEPD website on May 8, 2020, on page 18, states that biometric data is only considered a special category of data if it is processed for identification purposes, and not for authentication (similar to the aforementioned Labor Guide).

-From the Catalan Data Protection Authority (ACPD), Opinion 21/2020, dated June 12, 2020, regarding a query from a Provincial Council, "on the consideration of certain biometric data as special category data," which mentions AEPD Report 36/2020 and the ACPD resolution. PS/00041/2022, dated December 5, 2020, which refers again to what was stated by the

Spanish Data Protection Agency (AEPD) in the aforementioned report 36/2020 of May 8, in which it is “considered that
biometric data will only be considered a special category in

cases where they are subjected to technical processing aimed at
identifying a natural person one-to-many, and not in cases of verifying
identity by searching for a one-to-one match.”

-Legal Report 98/2022, dated December 22, 2022, published on the AEPD website

on January 20, 2023, which mentions EDPB Guidelines 5/2022, “pending

final adoption at this time after the completion of the
public consultation process,” acknowledging in the report “that it follows a different criterion than
that of the European Data Protection Board, both considering: identification and
authentication as special categories of data,” and that if “the criterion is
maintained at the time of its final adoption, it will be

necessary to review it.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 38/139

It provides a series of press articles from November/December 2023, regarding the change
of the AEPD's criteria in the “guide on attendance control processing using

systems biometrics,” expressly mentioning the “Guide to Labor Relations and Data Protection,” and now, in line with Guidelines 5/2022, understands that both identification and authentication entail the processing of specially protected data, “that is, specially protected data cannot be processed unless there is a special legal basis under Article 9.2 of the GDPR.”

“In this regard, with the new criteria adopted by the Spanish Data Protection Agency (AEPD), companies, if

their systems are based on authentication, must seek a
legal basis under Article 9.2 of the GDPR.”

FCB points out that the initial agreement lacks sufficient justification in that
it fails to allow for understanding the essential legal criteria that
underpin the decision, which supports the attribution of the aforementioned infringements
to FCB, as it is based on conclusions not drawn from the operative part of the
applicable regulations and uses arguments inconsistent with the criteria that the AEPD held at that

time, causing a lack of due process.

The initial agreement uses recitals 51 and 75 of the GDPR to undermine the content of Article 9.1 of the GDPR as an additional requirement not included in
the operative part of the GDPR, when these are not substantive legal provisions and cannot

contradict the Article of the regulation.

FCB considers that the biometric data processed did not fall under the category of

special category at the time the data processing began and continued, and therefore, it cannot be argued that the technique used to authenticate the
member posed a high risk. It was not taken into account that the purpose of the SBRF processing
was to prevent impersonation and fraud in the various transactions with FCB, offering a
benefit for security and privacy, which did not involve any profit motive or

any benefit for FCB, despite the investment made in this technology.

3 - Regarding the lack of a second legal basis within those stipulated in Article 9.2 of the GDPR to lift the prohibition on the use of biometric data contained in Article 9.1 of the GDPR, both for the processing of facial image and voice data, it emphasizes that “this requirement was not applicable because the processing began before the Spanish Data Protection Agency's (AEPD) change of criteria on November 23, 2023.”

FCB states that the processing it carries out is not aimed at uniquely identifying a natural person, but rather at authentication, thus falling outside the concept of biometric data in Article 9.1 of the GDPR, and therefore none of the circumstances of Article 9.2 of the GDPR were required.

“But in any case, if we apply the new criteria, a biometric authentication system would constitute special category data processing, requiring

lifting the prohibition under Article 9.1 of the GDPR. The only exception to the

prohibition on processing special category data is when one of the circumstances specified in paragraph 2 of Article 9 of the GDPR applies. Legitimate interest, the performance of a contract, or pre-contractual measures are not among the listed circumstances.”

“FCB carried out both processing activities, offering alternative methods and obtaining the consent of its members to lift the prohibition on processing biometric data in accordance with Article 9 of the GDPR.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 39/139

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 39/139 It was taken into account that “many of FC Barcelona's members are elderly and not digital natives,

posing a problem for them to carry out procedures through digital tools or applications. FC Barcelona also understands that some members may prefer to visit the Club's offices in person or may be reluctant to use biometric authentication tools for whatever reason.

Therefore, regarding the processing of biometric image data to update the FC Barcelona membership register, there is a legal basis distinct from the processing of basic data for register updates, included in Article 9 of the GDPR, which would lift the prohibition imposed by said article: consent.

Explicit, prior, genuine, and freely given consent has been obtained from all members who provided their biometric data for the purposes indicated to them.”

FCB notes that the census update process was carried out through various means,
with remote updates using biometric data being one of them,

but not the only option, "as other alternatives existed for completing this procedure."
While FCB prioritized the use of the biometric authentication system for

security and management reasons, it offered the option of contacting members to arrange, if
possible, for the procedures to be carried out in person at the Club's offices, or to
find a personalized solution that did not require the individual to travel,
since this was not feasible in a significant number of cases, given the
geographical dispersion of the Club's members.

Consequently, members could update the census remotely
using a biometric update system, or alternatively, contact FCB
to explore the best option. Therefore, the use of the tool to update the

census by members was voluntary and based in their consent.

Furthermore, the information clause for this process did not include a box to obtain consent because the mere act of using the tool already constituted clear consent, as biometric authentication was the primary purpose of that processing and tool.

This purpose is reiterated in the initial FCB statement to members dated March 20, 2023, which has already been provided.

FCB adds that all communications informed members of other options for completing the procedures or how to request assistance. Furthermore, at the beginning of the process and on the website itself, members could consult the FAQs, which indicated that the census update procedure could be carried out in person at the OAB (Office of Bank Accounts), and that it was not mandatory to use the provided biometric authentication tool.

Please provide a printed copy of the FAQs again, which state that the process
ends on November 30, 2023 (the date these FAQs were published would be the date the end date was announced after the extension). A specific section asks, “Can I complete the census in person?”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 40/139 The process is digital and easy to complete, but if any member wants in-person assistance, they can come to the OAB (Office of Members) by appointment.

FCB states that, in the initial agreement, in section V regarding the infringement of Article 9 of the GDPR, the judgment of July 4, 2023, case C-252/21, is cited, which is subsequent to when the data processing began.

Regarding the information clause for the process of updating the processing of member data, FCB now states that, despite having two boxes to check—one for general acceptance of the privacy policy and another for acceptance of the specific privacy policy for obtaining voice consent—"consent for image is obtained simply by completing the process in this way—since it is its primary purpose and there are other alternatives—while consent for voice is obtained by specifically checking the box provided for this purpose."

"Once all the options, consent was inherent in the action of
carrying out the procedure through this digital channel, a channel that was optional and free, and that is why no
specific box appeared. For its part, the checkbox appeared to obtain
express and specific consent for voice recording because it was distinct and

accessory, since the main data processing was biometric authentication for
the census, and this was leveraged through a specific checkbox to request consent
for voice recording.

FCB believes that denying consent will not have adverse consequences for the
person. In this case, there is no negative consequence to denying
consent since it is genuine and voluntary, and members can use the proposed alternatives
without being penalized in any way for deciding not to provide it. Furthermore, there is no
imbalance between the parties: the members, who are the owners of FCB.

In conclusion, FCB states that “Updating the census was a
mandatory procedure for which different options were offered.”

“Although the majority of members voluntarily opted to complete the procedures
with the biometric authentication system, some members did not.” They gave their consent for this treatment and used another of the proposed options,

by going to the offices in person to do so,” reiterates the data, adding that

12,249 members completed the procedures in person at the Club's offices.”

It adds that, “regarding voice, it could be carried out remotely or in person at the offices using the proposed tools, with biometric data obtained in both cases with the express consent of the member.”

4- FCB states that although the risk assessment report concluded that an impact assessment was not necessary, it incorporated the basic points required to qualify as an impact assessment. Therefore, the report also analyzed each of the risks arising from the use of this biometric system, including a proportionality study of the processing.

It concluded that both the processing and the system intended for use were proportionate, as the legitimate basis was weighed against the potential infringement of the rights and freedoms of the data subjects. “The proportionality study of the processing was conducted from the perspective of necessity, effectiveness, and loss of the

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 41/139

Privacy and the existence of less invasive means, something that, according to the content of the
initial agreement, has not been taken into account by the Spanish Data Protection Agency (AEPD).

Regarding the Data Protection Impact Assessment (DPIA) required by the AEPD for the SBRF and SBRVOZ, FCB states that

since it was carried out before the AEPD's change of criteria on November 23, 2023,

this requirement was not applicable, as the biometric data was intended to authenticate
the member for census updates or for security in the management of
remote procedures.

FCB's processing was not aimed at identification but at authentication, falling outside the
concept of biometric data according to Article 9.1 of the GDPR, and not being considered
sensitive data or a special category at the time of processing and

in accordance with the criteria then held by the AEPD.

“According to the previous authentication criteria, a DPIA was not required based on the

lists of data processing types requiring a data protection impact assessment under Article 35.4 issued by the AEPD” on May 6, 2019, although
FCB states that “from this list, three criteria could be applicable to the processing carried out by FCB if this processing had been carried out after November 23, 2023.” But since this processing, it is emphasized, was analyzed, initiated, and practically

concluded before 23/11/2023, only one criterion could be applicable with
the old criteria of the Spanish Data Protection Agency (AEPD), and therefore there would be no obligation to carry out an
impact assessment,” specifically section 10 of the list (processing that
involves the use of new technologies…) not being applicable, according to FCB, sections

4 (processing that involves the use of special categories of Article 9.1 of the
GDPR…) nor 5 (processing that involves the use of biometrics for the purpose

of uniquely identifying a natural person”).

“As a demonstration of due diligence and proactive compliance with regulations, the company has, prior to processing biometric authentication data using image and voice, prepared two

reports containing the requirements of Article 35.7 of the GDPR, with a positive result for each of these processing activities.”

“The two pre-processing reports passed the triple test (suitability, necessity, and proportionality) and demonstrated a low or minimal risk.”

“In the case of the census update, the proposed alternatives to the processing of biometric data do not imply that it is unnecessary if another valid option that does not involve biometrics is already available. The reason for this is that, in addition to the remote process using biometric authentication, all members are informed that they can contact FC Barcelona to complete the process in another way,” by going in person to the Club's offices, “and thus the use of biometrics will not be necessary to validate their identity or as proof of life,” nor will they have to send any documents. In cases where distance and travel by the member make it unfeasible, FCB will seek a personalized alternative system

for updating the census…” These cases are residual and few in number, and are not the primary or secondary method for updating the census. “Even though there are two alternative ways to update the census, using remote biometric authentication is necessary, effective, and proportionate, since one of the alternatives (in-person) would only be valid for a few (those who can travel in person), and the other (finding a personalized method for each case) is not manageable for a large number of people.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 42/139

case) is not manageable for a large number of people. Furthermore, the most secure method, even more so than in-person, is through biometric authentication.”

FCB provides a table showing the distribution of members abroad (7,826),
compared to the majority in the city (55,837), the rest of Spain (6,136), and the metropolitan area (25,903),
out of a total of 146,808.

FCB states that the content of the preliminary report on biometric authentication of the census was already submitted in response to the "information requests,"

although it is not called a Data Protection Impact Assessment (DPIA), it contains the necessary information to be considered as such.

FCB provides a partial copy, again, of the REPORT DATED 11/20/2022,

which it indicates was already submitted in response to the Spanish Data Protection Agency's (AEPD) information requests (it does not specify whether this was in response to the transfer or in the API) or as referenced in the risk assessment report. The copy provided does not include the document title. The following sections are highlighted:

As part of the Article 35.7 a) of the GDPR:

“3. Purposes of processing: Updating the membership register/Facial comparison between ID card and selfie to verify the member's authenticity.” In processing categories, section 4, no biometric data of the face or ID card is listed, only “identifying information—name, surname, ID card—, membership number, image (photograph).” In “data lifecycle in processing activities,” it states:

- data processed. “Biometric features of the selfie for comparison with the ID card image.”

“5. Purpose of the risk assessment”: the analysis is carried out with the objective of “assessing the risk of using a biometric facial comparison system to authenticate members during the membership register update process.”

Section 6 outlines what may be included in the description of the
processing activities, stages of the processing activities,
data, parties involved, and technology.

As part of Article 35.7.b) of the GDPR:
Section 7: “analysis of the proportionality of the processing” “an assessment of the

necessity and proportionality of the processing operations with respect to their
purpose;”, “in which it has been considered necessary to carry out an analysis of the
proportionality of this system compared to others that might be less intrusive
for the data subjects.” Part of the problem of the limited number of seats in the stadium
in relation to the total number of members, the practice of not reporting deceased

members, with their relatives continuing to use the assigned seat irregularly, or even without having died, the irregular use of the transfer of the membership card and seat to a
third party. “Consequently, when evaluating the system for processing member updates, FC Barcelona had to consider a method that would allow it to authenticate members with greater security and certainty, without requiring their physical presence, given their geographical dispersion not only in Catalonia, but also in Spain and even abroad.”



Consequently, when evaluating the system for processing member updates,

FCB had to consider a method that would allow it to authenticate members with greater security and certainty, without requiring their physical presence,

given their geographical dispersion not only in Catalonia, but also in Spain and even abroad. Consequently, once the decision was made to update the census online, except for those members who contact the Club to do so in person, based on the characteristics of the process, the proportionality of the facial authentication system was analyzed in comparison to other more traditional systems.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 43/139

The conclusions were as follows:

The content of the response to the complaint, specifically point 3, regarding proportionality, is reiterated.

“In conclusion, the legitimacy is weighed against the possible infringement of the rights and freedoms of the interested parties, concluding that these rights are not at risk of being infringed due to the low impact, the fact that it only involves temporary, almost instantaneous biometric risks, and the balance is maintained as there is no significant intrusion into your privacy”
As part of Article 35.7.c) of the GDPR:

Regarding the minimum compliance with the content of Article 35.7.c) “risk assessment for the rights and freedoms of data subjects referred to in paragraph 1,” FCB indicates in said document, point 11: “Analysis of the risk assessment,” that “a series of questions were asked of the data controller in order to understand the risks that the processing of data may entail for the data subjects, based on the intended data processing.”

“The possible risks involved in the processing of personal data have been analyzed one by one, in order to define their characteristics and establish the measures planned to limit the likelihood of their occurrence.”

It reiterates the risks that have been taken into account and that are reflected in point

SECOND, 3.
This section 11 includes a table of the “data lifecycle in the activities of

"processing" for updating the census, which includes data capture through
"online collection and identification" using the "DAS-Face technology of the provider
VERIDAS," and links it to the process activities, the data processed,
participants, and technologies, listing only the data processor VERIDAS, without
SIA being mentioned.

In ANNEX B1, the table "Risk Assessment" of the processing operations appears: updating the census of members, accompanied by tables of
"associated risks," among others, the following categories:

- "to the protection of information," weighing the probability and impact,

it determines the risk in integrity, availability, and confidentiality, with a degree of

low risk.

-In "to regulatory compliance," type of risk: "guarantee of the legitimacy

relating to the processing." It rates the absence of a legitimacy basis

or the unlawful or unnecessary processing of personal data with a degree of low risk.

-In: “Data Quality” considers the risk of retaining personal data

for longer than necessary and the collection of inadequate, irrelevant, or excessive data, with a low risk level.

-In “Security,” the “risk typology” only includes: “incident management,”

“risk” “inability to detect and/or manage incidents that affect security, limited probability, limited impact,” “level: low risk,”

“control measures: Internal and external IT security audits.”
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 44/139

Next to the level, “control measures” are listed.

“Once each of the risks has been analyzed, it is observed that the risk of the analyzed data processing
process is minimal, and the small risk detected is
more than offset by the proposed control measures.”

FCB states that the report it prepared is a Data Protection Impact Assessment (DPIA), as it contains the minimum requirements and that the measures planned to address risks, in accordance with Article 35.7.d), are already included in the risk assessment table and are sufficient to ensure that the risk is acceptable/minimal.

Regarding the voice biometric authentication system, it indicates that: “this biometric template was obtained with consent and after a prior and passed impact assessment, with the aim of facilitating, in the future, the completion of any remote procedure (administrative, ticket purchase, use of a free seat) by members via telephone and preventing identity theft.”

“A risk assessment has been carried out using the same criteria as the report for facial biometrics and supported by a previous and positive Data Protection Impact Assessment (DPIA) report on the biometric authentication system/tool used.” The data processing

carried out is necessary for security reasons and due to the problems with impersonation and fraud that FC Barcelona, and therefore its members, have been experiencing. “There is no other non-biometric system that allows for the same objective, since this objective of offering an anti-fraud/impersonation system for remote transactions can only be achieved through biometrics, at least with this level of security and without risks in the storage of passwords.” “Any other method of identity verification for remote procedures that does not use biometrics would require each member to have passwords or security questions, which would pose a security risk, as well as a risk of losing the member and therefore the possibility of fraud or identity theft.”

FCB states that these obligations have been only partially fulfilled, as has been demonstrated.

FCB concludes by indicating that it has complied with the principles of the GDPR, such as transparency, by providing all the information about the processing of data and its members' rights. It has also ensured data accuracy, since the purpose of updating the membership list was to have up-to-date data “to prevent fraud and identity theft, and thanks to this process, an updated photo of the member has been obtained for the membership card.”

5- Regarding the classification of the conduct, FCB states that “As has been indicated in this document, both when conducting the “preliminary analysis on the use of biometrics in the process of updating the census of members” (report dated 09/22/2022 and conclusions document dated 11/09/2022) and

when reassessing compliance with its obligations when this party
prompted the census update process on its own initiative for this purpose
from 04/05/2023 until 05/04/2023, FCB took into account the interpretative criteria formulated and disseminated by the Spanish Data Protection Agency (AEPD) that was prevailing at that time and

which, in any case, was the prevailing interpretative approach.”
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 45/139

which, in any case, was the prevailing interpretation This supervisory authority,
prior to the publication date several months later (November 23, 2023), issued
a new guide in which the Spanish Data Protection Agency (AEPD) reformulated and modified its previous position.

FCB points out that, although in the press release regarding the publication of the new guide
on the use of biometric data for attendance and access control, the
AEPD stated and emphasized that “The Agency considers the processing of biometric data, both for identification and authentication, as high-risk processing that includes special categories of data,” this statement contradicts its

previous interpretation. It is public knowledge that this was not the interpretive criterion previously followed by the AEPD regarding the
consideration of biometric data as a special category of data. In fact,
statements and conclusions included in various legal reports and
guides published by the AEPD before November 23, 2023, show a different line of interpretation. which contradict the aforementioned statement and

consideration as a high-risk processing activity that includes special categories of
data, therefore this party understands that it was legitimate to adopt said interpretation
and take it into account in the assessment made of the processing.

FCB states that the EDPB Guidelines 5/2022 are dated April 26, 2023, just after the census update process had begun, with the AEPD's guide on monitoring
work attendance being dated November 23, 2023, the update of FCB's
members being completed, and therefore the processing of their data a few days later, on November
30, 2023, and assuming the interpretative shift of the attendance guide of November 23, 2023
regarding the categorization of biometric data for authentication/verification purposes
an interpretative application to a situation that arose before it, which is reflected
in the agreement of Initial.

FCB considers the principle of legitimate expectation and the classification of the
possible infringement to be breached, since there are previous and conclusive external pronouncements
from the Spanish Data Protection Agency (AEPD) contrary to the interpretation now followed in the initial agreement
and which largely led to the conclusion regarding the suitability of the

processing at the time it was analyzed.

FCB describes the initial agreement as surprising and creating legal uncertainty
by implementing a substantial change in interpretive criteria without any transitional measures
or adjustment period.

6- FCB states, regarding the severity of the sanction, in relation to the circumstances of
Article 83.2.a) of the GDPR, that the alleged infringement stems from a request by a

member who became confused during the census update process and believed that the only
option was to complete the procedure using the biometric authentication tool.

FCB acknowledges that the number of affected parties is considerable, but in no case It would be considered a large-scale matter. “No interested party has suffered any harm or damage; it all stems from a member's mistake.”

-FCB believes that the infringement should not be considered intentional or negligent, but rather a matter of compliance with the provisions of the GDPR, since:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 46/139

• The decision to initiate the processing was not made with the intention of infringing rights or generating economic benefit for the Club, but rather to provide members with a system that avoids the inconvenience of traveling, a secure system.

• Before initiating the processing, FCB took the appropriate measures to detect any potential risks, and the initial report included all the requirements stipulated by Article 35.7 of the GDPR.

• FCB was aware of the first complaint before the transfer. of

the complaint from the Spanish Data Protection Agency (AEPD) on April 21, 2023, and made the decision to
deactivate the service to conduct a new analysis of the legality and
security of the system.

The aforementioned elements demonstrate the absence of intent to

infringe rights and show due diligence by acting proactively
throughout the processing period, adopting
measures aimed at safeguarding the rights of data subjects.

-FCB believes that some of its actions should be considered mitigating factors

which would fall under Article:

• 83.2 c) of the GDPR: “any measures taken by the controller or processor to
remedy damages suffered by data subjects” based on:

-A Data Protection Impact Assessment (DPIA) was carried out despite not being mandatory, and a risk assessment report

prior to processing was prepared, which included all the requirements established in Article 35.7
of the GDPR.

-Adoption of security and cybersecurity measures described in the section:

“Conditions for the processing of special categories from November 23, 2023”.

-FCB established official channels for any member to “request assistance” from the
Member Support Office and the Member Ombudsman, as well as the Data Protection Officer (DPO), in order to
answer queries and address concerns, “and, where appropriate, offer interested parties

an alternative to the processing of their personal data, allowing them to opt out of

participating in the digital census update process”.

 83.2 d) “the degree of responsibility of the controller or processor, taking into account the technical and organizational measures they have implemented pursuant to Articles 25 and 32,” considering that FCB, both when determining the means of processing and during the processing itself, has implemented appropriate technical and organizational measures to effectively apply the principles of data protection and ensure that, by default, only personal data necessary for the intended purposes have been processed.

Special reference is made to the image, “since the processing was instantaneous and no database was stored,” and regarding the voice, the data was ultimately deleted “following the change in criteria by the Spanish Data Protection Agency (AEPD).”

Furthermore, “all technical and organizational measures have been taken to ensure an adequate level of security.” On the one hand, encryption systems have been used for

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 47/139

personal data (biometric templates and all data storage and transmission use encrypted means). A tool and provider have also been used that offer the highest guarantees in terms of confidentiality, integrity, availability, and permanent resilience of the systems, as shown by all the certifications and guarantees of the system provider.

83.2.e) “Any previous infringement committed by the controller or processor of the

processing,” FCB states that it has not committed any infringement, nor can resuming the census update process be understood as a reiteration or recidivism, since it is the same processing that FCB proactively stopped to review and strengthen it, which should serve as a mitigating factor.

 83.2 f) “the degree of cooperation with the supervisory authority in order to remedy the infringement and mitigate the possible adverse effects of the infringement;” which FCB considers to have been “total, since all communications received from it have been answered in detail.”

• 83.2.g) “the categories of personal data affected by the infringement;” FCB specifies that the categories of personal data processed are the “minimum and necessary; only identification data and biometric data were processed, which at the time of processing were not considered biometric data in accordance with Article 9.1 of the GDPR and therefore did not fall under special categories of data.”

• 83.2.h) “how the supervisory authority became aware of the infringement, in particular whether the controller or processor notified the infringement and, if so, to what extent.” FCB notes that the Spanish Data Protection Agency (AEPD) was informed directly by “the main complainant and partner who mistakenly believed that the census update could only be carried out using the biometric authentication tool.” “The complaints received previously from members did not involve any type of infraction and could be addressed and resolved by the member services department.”


 83.2.i) “When the measures indicated in Article 58.2 have been previously ordered against the controller or processor concerned in relation to the same matter, compliance with said measures

7-FCB alleges a lack of proportionality in the proposed fine, because:

-it takes into account criteria and guidelines for its calculation using business parameters.

The “net turnover” of a non-profit association in which no profits are distributed, and the Spanish Data Protection Agency (AEPD) should carry out an examination of the effectiveness, deterrent effect, and proportionality at the end of the calculation, also considering the financial and socio-economic circumstances, which in this case it believes have not been taken into account, given that it is a non-profit entity.

FCB points out that it is a non-profit association in which the profits obtained from the development of its economic activity are allocated to the fulfillment of its founding purposes and that, therefore, it cannot be classified as a large company. Nor are the financial circumstances taken into account, which are an accumulation of

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 48/139

losses/debts of €2,326,958,000 as of 30/06/2023 and €2,417,609,000 as of 30/06/2024, nor the economic consequences that could arise from the actual imposition of a sanction in the form of an administrative fine on

a sports association of this type. FCB believes that the amount would affect the interests of the individuals whose data protection rights it alleges have been violated, who would see this reflected in their membership fees.

FCB indicates that the supposed business volume used by the AEPD as a reference point for setting the amount is unclear.

FCB The fine, indicating two figures from different fiscal years

-the proposed amount in relation to the facts and the damages
allegedly caused.

If imposed, it would be among the highest ever imposed by the Spanish Data Protection Agency (AEPD). Higher fines have only been imposed in the case of very large companies, for-profit businesses, multinationals, or publicly traded companies with
turnovers exceeding, in some cases, twenty billion and one hundred billion
euros. FCB provides a list that it claims was published by the AEPD in the Official State Gazette (BOE) with companies and their fines, with GOOGLE leading the list with 10 million

euros, followed by VODAFONE with 8 million, and ENDESA ENERGIA and CAIXABANK with 6 million each.

FCB also provides another list from the GDPR Enforcement website.

FCB adds that the proposed fine amounts for the infringed articles, compared to other cases, use a specific criterion. surprising. It gives examples of the

files:

-***PROCEDURE.2, (…) “In this case, several fines were proposed for
infringements of Articles 6, 9, 12, 13, 25.1 and 35 of the GDPR, totaling
€3,150,000.” FC Barcelona stated that in its case there was

legitimacy and “obtained the prior, express and genuine consent of the
data subjects.” In this case, the affected parties were unaware that their data was being processed
to access the facilities, and the data processing was
against a database of biometric templates, “whereas FC Barcelona only collected biometric data from members who
freely chose that option and with their consent.” The

sanctioned entity was a large “retail” company, with a very high
turnover, more than 25 billion euros, 90,000 employees, and 1,636
stores open. In that case, the infringement of Articles 9 and 6 totaled 2
million euros; in this case, 4 million euros are proposed, and the sanction
for the infringement of Article 35 of the GDPR was 50,000 euros.

-At the regional level, it refers to the case of sanctioning procedure PS/0041/2022

of the Catalan Data Protection Agency (APCAT) against a non-profit foundation due to the similarity of the facts and
infringements committed, imposing a total sanction of 20,000 euros on a
non-profit entity. FCB states that in both cases there is agreement:

▪ that the purpose of the biometric data was to authenticate the
identity of a person, in order to prevent fraud, impersonation, and

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 49/139

without generating benefits but rather expenses to offer greater security
for personal data.

▪ The biometric system functioned similarly to that used in
the census update, capturing an image of the face to
compare it with the photo on the ID card and verify that the person is who they claim to be.

▪ The volume of data processed in the case being compared was
high.

▪ The Foundation attempted to use two legal bases, neither of which
was valid, while FCB “did use two legal bases, one of which was consent, which would lift the prohibition
of Article 9.1 of the GDPR.”

▪ In the Foundation's case, those affected could not freely choose
since, if they did not submit to the facial

recognition tool, their application would be considered not submitted.

It reiterates in its conclusions that “it all started with the need to update the FCB census due to fraudulent practices.” that affect the member, making it imperative

to have an updated, truthful, and reliable census and to combat fraudulent practices and remote impersonation, allowing verification that the person carrying out the procedure was indeed who they claimed to be. The same technology was also used

to voluntarily obtain voice data from members to manage
procedures remotely without risk of identity theft. For this, it was necessary

to find a system that allowed for real-time verification of the identity of all
Club members, and that, moreover, did not necessarily require their
physical presence at FCB offices, given the geographical dispersion.

NINTH: Start of the trial period: 4/08/2025
On 4/08/2025, it was agreed, for evidentiary purposes, to include the
filed claims and their documentation, the documents obtained and
generated during the claims admission phase, and the report of

preliminary investigative actions that form part of procedure
AI/00231/2023. Likewise, the
allegations against the agreement to initiate the disciplinary procedure were also included for evidentiary purposes. referenced,
submitted by FCB and the accompanying documentation.

Furthermore, it was decided to request that FCB provide the following information:

“1-1 Agreement of June 21, 2022, of the Board of Directors regarding the update of the census of
members associated with FCB, which should specify whether the

agreement included the method of said update (in this case, through the biometric facial recognition system SBRF).”

A written response was received on September 4, 2025, indicating:

Document 1, including the required Agreement, graphic and informational content, is provided.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 50/139

“Update of the membership census. Season tickets for the 22/23 season. Complete census for all
members.” Digital and mandatory for all members and season ticket holders. In the last census update (2012), 1,000 season tickets were recovered.

Benefits for the Club:

Database update, regularization of inactive members,

recovery of season tickets from the waiting list, promotion of the Club's digital transformation, joint project with the sustainability department, improved future communication with members, a defined timeframe for updating the system, and efforts to combat fraud.

Benefits for members:

Universal online access, process available regardless of location or time of day. Omnichannel experience (PC, mobile, iOS/Android, tablet, etc.). Members only need a computer, tablet, or mobile device with a camera.

The graphic section includes diagrams showing the process for online member identification with FC Barcelona through the Club's website. As steps for
completing the update process, although it mentions a video, the method was taking
a selfie. Figure:

“- access to the website with the member's username and password.

- Physical validation of your identity using your ID card and your device's camera.

Video ID technology will automatically analyze the document's authenticity and its match with the user.

- The user shows their face to the camera in a video of x seconds.

- Identity is verified through:

- The person's credentials

- The recorded video

- The ID document

- The person's face

"1-2 You must also inform us if the same agreement includes the incorporation of the member's image as part of its use in the member registry, and the reason why the processing of the member's image data is not mentioned in the FCB Statutes or in the data processing information (privacy policy), and whether this is or was the first time the member's image has been incorporated into the member registry."

" FCB responds that regarding the “member's image (photograph), it is personal data that

is requested from anyone” registering as a member. It was already requested
prior to the census update. It is incorporated into the “membership card, regardless of its format, digital or physical.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 51/139

FCB indicates that the member's image was not mentioned as data collected in the Board's
agreement, as it was not a new addition but rather an update of data that
was already held and whose purposes had already been communicated.

“Currently, the membership card is digital, except in the case of members aged 70 or older

who have a physical card. “Season tickets do not include any photograph of the
holder.”

“Therefore, since the image is not requested for a specific or distinct purpose that requires separate and particular information, and since all the data initially requested from the person to register as an FCB member, including the image, is for the purposes indicated in the registration procedure outlined in the Privacy Policy.”

“1-3 Indicate the regulations that empower the Board of Directors to

adopt said update of the membership census (Article 11.8 of the Statutes refers to
the electoral census, which has various purposes and is compiled by the Members' Auditor) and
to collect new data: image, which is not included in the membership register, and the role
played by the General Assembly and the representation of the members in affecting the individual rights of the members (also in the risk analysis or in the PPI).”

FCB responds regarding the Board's authority to update the membership census

that Article 11.8 of the FCB Statutes indicates that it is responsible for
"carrying out the procedures for updating the electoral census promoted by
the Club, either by requiring the member's presence or by providing the required data,
and that it is the member's obligation to comply with the census updates promoted by
the "Club" and doesn't quite understand what is meant when Article 11.8 is cited.

FCB adds that the Board of Directors, the Club's governing body, is

elected by the Club's members and not only has full powers but also the
obligation to carry out the census updates required by its Statutes,
by virtue of the provisions in Section 3, regarding the Board of Directors, and specifically Article 30 of the Statutes, with the function of promoting and directing the club's activities,
through acts of administration, management, representation, disposition, and execution that
are necessary for the fulfillment of FCB's objectives, the mandates of the

General Assembly, and the provisions of the Statutes. Furthermore, Article 31 grants the
Board powers not reserved by the Statutes to the General Assembly.

FCB states that, understanding that the statutes oblige FCB to maintain a register of members (Art. 61.1), that is, the census, and considering that this is not a power reserved for the General Assembly, they conclude that the Board of Directors would hold the power.

“2. For FCB, what did creating a digital profile include? Was it the updating of the membership census through the Biometric Facial Recognition System (SBRF), the creation of a voice profile with SBRVOZ, or both? Or was either of the aforementioned simply what FCB considered a ‘digital profile’?”

The response was that “digital profile” is a broad term used by FCB to refer to the credentials of individuals interested in the various digital and web environments through which they can operate and interact with the Club.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 52/139

The “digital profile” is a separate concept and has nothing to do with the census update process.

There are two distinct groups involved in registering for a digital profile and updating the census:

- Individuals who can only register a digital profile, requiring only an email address regardless of their membership status, in order to access, navigate, and interact within the FCB digital environment.

- On the other hand, there are FCB members who participated in the census data update process, and whose data FCB already possessed because it had been previously provided by the members.

The only point of connection between the two can occur when registering for the digital profile, and the person identifies themselves as an FCB member, in which case they expressly consent to linking the data already on file in their FCB membership record to said profile.

“Within the framework of the census update process and taking into account the
expansion of FCB's digital environment, voice recording was offered to those
who voluntarily wished to participate, in order to offer members
a feature in the future that would allow for more secure identification when
carrying out telephone transactions. The biometric use of voice, as
explained in the various documents included in this proceeding, was carried out

based on the considerations and guidelines published by the Spanish Data Protection Agency (AEPD) that at that time
permitted its use, but ultimately all voice recordings were deleted
when FCB decided against using voice as a verification element in
telephone transactions. It should be noted that this deletion measure was adopted by FCB even
before the AEPD published a new guide

related to biometrics, the content of which clearly prohibited its use.” Therefore, it is currently not possible to carry out any remote or online procedures using biometric data, nor is there any process that involves its use.


“3. In the first communication sent to members, dated March 20, 2023, members were invited to ask any questions they had about updating the membership list. Please provide copies of some sample emails received during the first month in which members inquired about alternative methods for updating the membership list, and the responses they received.

FCB responded that, in compliance with data protection regulations, all of those emails were deleted.

4. According to your responses to the transfer and the Preliminary Investigation Proceedings (API), the membership update process was interrupted due to complaints from FCB members, starting on April 5, 2023, and also upon receiving the transfer from the Spanish Data Protection Agency (AEPD) on April 21, 2023. Please clarify this alleged double suspension and the date until which it was extended.”

FCB responded that when the transfer from the Spanish Data Protection Agency (AEPD) was received on April 21, 2023, the
member update process had already been interrupted due to
an initial complaint from a member and FCB policy. There was only one suspension.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 53/139

extended until May 4, 2023. After responding to the member and confirming that
continuing the processing posed no risk, the process resumed.

“5 In their response to the transfer, dated May 22, 2023, they indicated that they had received “five complaints and the other four in writing” regarding the
census update.

They were

requested copies of these and the response given to each one.”

FCB responded that “these emails are not kept.”

“6. Please inform us whether only FCB members can purchase season tickets, and if any information other than membership details is required (image/photograph, etc.).
Please indicate whether the membership or season ticket card includes a photograph of the holder.

Please indicate whether any form of identification is required in addition to the membership/season ticket card for entry to official competition matches.

Please indicate whether, among the irregular uses of membership or season ticket cards, more instances of use by deceased individuals have been detected than by current members.”

FCB responded that to be a season ticket holder, one must be a member, although a member cannot be a season ticket holder. "Therefore, no additional information is required to obtain season ticket holder status."

They added that, at the entrances to official matches, security personnel may request, along with the membership card/season ticket holder's ID, solely to verify that the person holding the ID and the card are the same, given that the photo on the membership card is outdated.

Updating the census photographs has, among other objectives, the goal of facilitating identification and thus preserving and guaranteeing the security and thorough control of those accessing the Club's facilities, as well as facilitating the identification of those prohibited from entering the premises.

"7-1 Regarding how to complete the process for updating the membership census, as shown in images from the website—provided by claimant 1—'new membership census 2023 More digital, more personal' 'Create your digital BARÇA profile now, and access better services',

In the 8 steps contained therein, after recording your voice, step 7 states: 'enter the data form, complete it, and verify your Barça profile'." Please provide a copy

of this form, which you must complete, and specify whether this membership update
requires you to provide information that was already included when you registered as a member (email, address, phone number, etc.).

FCB responded that “In the final part of the process, members can access
their personal data registered by FCB (personal data, contact information,
bank details, tax information, preferences, and the groups and social media accounts of the

Club to which they belong), in order to update it, if necessary.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 54/139

You are providing, as DOCUMENT 2, a two-page membership data form,
subdivided into different tabs. Each tab contains various
types of data to be completed: mandatory, optional, or new mandatory data, new optional data.

In the first tab, “Personal Data,” facial biometrics, the photo of the

identification document and face are listed as mandatory. Voice recording is
optional in a separate section.

In the “Contact Data” tab, among other things, the telephone number is listed as optional, and the mobile phone number and email address are listed as mandatory for online operations.

“7-2 Please report if, at any time, all or any member has been asked for a full copy of their ID card before
this update of the member census, in what procedure, and
when?”

FCB responded that no, no copy of the ID card is requested in any FCB procedure.

Only perhaps in some processes might the in-person presentation of the document be required to verify the person's identity, as is the case with the management of
access to official competition matches, as explained previously.

“7-3 The same applies to the image (selfie photograph that remained in FCB's systems).”

FCB responded that all FCB members are required to submit an updated photograph to register and have it added to their membership card;
this photograph, as an identifying element, has always been requested in the registration process,

both in person and online.

“7-4 Please inform us whether the process of taking a selfie with movement involves video recording.”

FCB responded that no, at no point during the process was video recorded or
video images of members captured.

“8-1 Furthermore, please specify where and when the information clause regarding data protection (first layer) appeared when the member accessed the website or the member app to update the census.

FCB responded that it appeared on the FCB website, under the members tab, when accessing the census update, either via the direct link “member census” or through online procedures.
In all cases, the member must log in with their password and PIN and access their private area. Once logged in, they must click on “new member census,” and then “acceptance of privacy policy” appears.

It notes that the information clause appears before the button to accept the privacy policy.

It provides an image of “new member census 2023” next to the Club's crest.

“Welcome to the new Member census” identical to the graphic provided by R1
and stated in FACT 1, provides 2.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 55/139

“8-2-Indicate whether the aforementioned first-layer information clause underwent any modification
in its wording during the period in which the census data could be updated.

FCB responded that it did not.

“8-3-Report how the same information was provided to those who came in person to

offices to update the census.

FCB responded that they were informed in person by the staff in charge.

“8-4-The first layer states the purpose of using biometric data for
contacts with the Club and for member authentication and identification for
access to Club facilities in the case of express consent from the member.” Please detail which biometric data were used for contacts with the Club (those from
SBRF or SBRVOZ), which were used for member authentication (both types?), and

which biometric data was used for identification for access to Club facilities,
and where was express consent for this access completed?”

FCB responded that “the biometric data initially intended for contact with the
Club were the SBRVOZ data, which were intended to validate the identity of
members during telephone contacts to prevent fraud and impersonation.

The data for authentication were facial comparison data for the census update process.

The idea of access control was It was dismissed and never implemented.

The idea, which arose before the publication of the AEPD guide on biometrics on

November 23, 2023, was to inform that biometrics could be used for other
purposes in the future, without prejudice to the activation, when the time came, of the protocols for
requesting consent and collecting biometric data.

“8.5-Reason why, in the second layer, instead of only completing what relates to the
first layer (updating the membership census), all the information on all
processing activities is offered.”

FCB responded that it is the entity's policy to offer as much information

as possible on FCB's processing activities. Furthermore, it has an interactive index to
help find the information easily and quickly.

“8.6- Please also report whether the newsletter sent to complainant 1,
containing the data collection information, is sent to all members,
and If it is mandatory for members to receive it, or to be a season ticket holder. If it is not mandatory, how many members did not receive it?”

FCB responded that the newsletter was sent to all members, whether or not they were season ticket holders, and that it was an institutional communication.

“9-Final date or date until which the operational completion of the FCB member census was postponed, and total number of members who did not update their census by any means, and the consequences for them. Total count of members who updated their census with the SBRF, those who did so in person (and if their image is collected: photo, and for those who consented to their voice, a copy of the explicit consent for this data collection.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 56/139

[The following appears to be a separate, unrelated section: C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 56/139

] voice), as well as those who completed
the SBRF, as many as consented to provide the biometric voice recognition system profile (SBRVOZ).

FCB responded that the deadline for updating the census was extended to
November 30, 2023, and that the number of members who did not update their census was
14,433.

The consequences were the loss of membership, as detailed in
Article 15 of the Statutes. “Furthermore, the Club may terminate the membership of members who,
after two formal requests and three months having elapsed since the second, have not
completed the required census update procedures.”

“Once the census update process was completed, members who did not

update their information received an email warning them that if they did not
update it, they would lose their membership status.” Members. One month after the first email, they were sent another notification email, and finally, three months later, they received a third email confirming their removal as FCB members.

“The number of members who updated their membership with SBRF is 112,623. Of those who completed SBRF, 72,648 consented to provide their biometric voice recognition profile (SBRVOZ).

“The number of members who updated their membership in person is 12,249. Members had their photograph taken to update their information or, if necessary, were asked to provide an updated photograph.

The number of members who consented in person to having their voice recorded is 160. Minors were not allowed to complete the voice registration process.”

“10-In the FAQs for the process of the Census,

https://www.fcbarcelona.es/esficha/3052201/faqs): (attached FCB DOCUMENT 8).

On what date was this FAQ section implemented? And was it available before the start of the first mailing to members for the membership update on March 20, 2023? How can you verify this date?

FCB responded that the link to the FAQs had been on the website since the census update process was opened to the public.

“11-1 How the census update was carried out by
claimant 1, claimant 2, and claimant 3, providing accreditation, log, or trace of the
entry.

FCB responded that R1 performed it via computer. A computer log dated 11/28/2023 is attached. The log contains an entry for the ID card's expiration date,

issue date, support number, CAN (six-digit number), and a validation entry for the
selfie-proof-life verification.

Regarding R2, FCB responded that it was updated “manually remotely at the member's request,
due to unique and exceptional circumstances, this being, for the reasons given, a single extraordinary case.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 57/139

Regarding R3, FCB indicates that it was also carried out via computer, providing the computer log showing that it was performed on May 5, 2023, with a data set similar to that of R1. In this case, it seems strange because R3, in its claim of February 1, 2024, stated that it had not updated its data as of that date.

“11.2 Procedure for updating the census for members under the age of 18. Total number. Also in the SBRVOZ.”

FCB responded that the census update process could be done remotely or in person,
but they could not complete the process verbally. The total number of members under the age of 18
is 14,511.

“12. As a result of the membership census update process, how many
removals occurred due to delayed updates (death or resignation), broken down by
the number of each type? And how many removals occurred as a result of not

updating the census?”

FCB responded that, during the census update period, from March 21, 2023 to December 31, 2023 (in question 11, they responded that the update extended until November 30, 2023),
993 active membership cards belonging to deceased individuals were detected and subsequently deactivated.

They added that, as noted in response 11, 14,433 members who did not complete the census update were deactivated, with the process beginning on April 15, 2024. “Considering the time elapsed, almost two years, and the consequences of not updating the census (the loss of membership status and, where applicable, season ticket holder status), we can only conclude that either the cardholder has died, or the users of those cards were not the actual members, and therefore

they were unable to update their information.” The data.”

“13. Report the number of season ticket holders whose season tickets were revoked as a sanction for illegitimate use,
from 2020 to 2023, which is prompting the

update of the membership census. Also, indicate when the census was last updated before this update and what procedure was used then.

- How do you know that most illegal transfers of season tickets or membership cards may originate from deceased members? What investigations have been carried out?

Number of FC Barcelona members, and of those, how many also hold season ticket holder status. Provide statistics or data revealing the number of fraudulent uses of membership and season ticket cards, whether the use of membership cards corresponds to that of season ticket holders, and what other advantageous uses the use of a membership/season ticket card or simply a membership card might lead to.

If you have assessed or analyzed the different types of fraudulent or irregular uses of

membership/season ticket cards, please provide a brief summary of the number of cases involved, how you investigate them, and what methods you use to uncover these irregularities.


FCB responded by providing data on the number of cases of ticket and season ticket resale, as well as resale of membership cards at the entrances: 108.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 58/139

Depending on the various circumstances that may arise in the illegitimate use of membership cards, FCB breaks down the significance of the sanctions imposed by season, which include “resale of season tickets, ticket resale, and resale of season tickets and membership cards.”

Although the number of infractions is not specified, it is noteworthy that in the 2020/21 season,

75% were for resale of season tickets, compared to 33% in the previous season, and
25% for resale of season tickets and membership cards in the previous season. 23/24.

It also specifies as punishable conduct the transfer or rental of membership cards to third parties by some members.

FCB states that, upon reviewing the membership cards of several members, it observed that a significant number of them possess multiple membership cards, which is evidence that there are individuals who fraudulently manage multiple membership cards for their own benefit.

It has been verified that a total of 1,446 members have multiple membership cards.

14-1 Report whether FCB retains an updated photo of FCB members who physically appear at the offices to update the membership list (or through any other means or method, such as telephone verification) and who do not wish to provide data for the SBRF, or how the verification is carried out, including whether any note or mark is made, where it is made, and where it is stored. “

FCB responded that in this case, only one updated photograph is captured and used for the membership card and record, and is stored in the member's personal file in SERVICE 4 of the Club. Verification is carried out in person and without the use of biometrics.

They added that in cases where the update has not been carried out in person, mainly for members residing abroad, these individuals could opt for a telephone process, in which they were asked to send FCB an email with their information, including their photograph. The verification of the data was carried out by FCB staff. Once the verification was complete, the photograph was stored in the member's personal file.

“14-2 How is information provided to those who come to the offices in person or by telephone regarding compliance with Article 13 of the GDPR?
since, This option was not included in the information clause, first layer. Copy of the

information clause that was given to them on the spot.

FCB responded that, in those cases, their staff assisted the people who came
in person to update the census, proceeding as if it were the online process. Beforehand, they read Article 13 of the GDPR to them in order to comply with
the duty to inform so that the interested party could give their consent to

the procedures of the process.

“14-3 Confirm that none of those who came in person to update
the census provided biometric data for facial recognition.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 59/139

FCB responds: “No, as stated, members who visited FCB facilities could choose to complete the census update process using SBRF or manually.”

“14-4 Please confirm whether those who visited in person were offered the option of voice recording and how explicit consent was obtained. Provide informational documentation regarding this data collection. Include the total number of members whose voices were recorded in person.”

FCB responded that if a member wished to voluntarily record their voice in person, they were offered the option to complete the process in the same way as if they had done so online, but in this case with the assistance of FCB staff. Consequently, they would have had to accept the privacy policy and expressly consent by checking the same box on the form. As mentioned, 160 members consented to the recording of their voice in person.

“15. Reference to the spaces where the information is stored (…) (kept in (…)), whether it is the same location, and whether both pieces of information are part of the member registry mentioned in the FCB statutes.”

FCB responded that “the members’ images are stored in (…).

The voice data has not been stored, and therefore there is no voice file of any member.”

“16 In your response to the transfer, in point 8, regarding the adoption of measures to prevent similar incidents, you indicated that you had carried out a legal review during which you suspended the processing. In this regard, taking into account the publication by the European Data Protection Board (EDPB) of guidelines 5/2022 on the use of facial recognition technology in the application of the Law, version 26/04/2023 (points 6 to 12), what consideration did you give to this content, which states that both authentication and identification are distinct functions (it explains what authentication consists of beforehand) and concludes the interpretation that “both refer to the processing of biometric data relating to an identified or identifiable natural person, and therefore constitute the processing of personal data and, more specifically, the processing of special categories of personal data”? Please indicate what consideration you gave to your specific case of the collection of biometric data. facial and voice recognition.”

FCB responded that it had considered the suggestion, but they continued to abide by the interpretations of the supervisory authority, the Spanish Data Protection Agency (AEPD), as it is the competent body for interpreting these matters. “Furthermore, the existence of differing criteria adopted by other European supervisory authorities led us to recommend that we continue to act according to the AEPD’s interpretive criteria, as we are directly subject to its authority.”

It mentions that the AEPD report 0098/2022 of 22/12/2022 itself follows a different criterion than that established by the EDPB.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 60/139

“Although they took into account the EDPB's considerations, the criterion for action
for the processing was to apply all the interpretations and guidelines that the AEPD maintained up to that point, where, clearly and explicitly in its documents and

guidelines, as has already been demonstrated in previous submissions, it made a clear distinction
between authentication and identification and the implications that these entailed.”

“At the time of planning, initiating, and carrying out the processing, following the AEPD guidelines and
interpretations applicable at that time, it complied with the
data protection regulations and principles.”

FCB points out, regarding the suspension of the process, that it already indicated it occurred to
respond to the complaint they received, and was carried out primarily to verify whether the
information process had not been sufficiently clear and simple as

intended, “and not because of any doubts about the legality of the procedure adopted to
update the census, this being a point that was also ratified.”

“17-1 In their written response to the Preliminary Investigation Proceedings (API), they indicated
that they compared the image on the ID card with the selfie taken, and the software validates
that it is the same person. For this purpose, they are requested to clarify whether they compare each
of the images obtained: ID card with selfie, or if they compare each of the

extracted facial vectors, one from the ID card image and another from the selfie (this seems to be
inferred from a document dated 09/22/2022, entitled “Preliminary analysis on the
use of biometrics in the process of updating the census of members”),
it also appears in the RAT “biometric vectors facial comparison”, that “the
biometric vectors remain encrypted by SIA for seven days” and in the

transfer of the complaint they stated:

“VERIDAS does not retain either the user's personal data or the biometric vectors
that have been created and once the process is carried out For whom the service has been contracted and the relevant information sent to FCB, the provider automatically deletes all the information that has been on its servers.” In this phase, the analysis of the document's authenticity (processing the data it contains) and the person's identity will be carried out. For this purpose, two biometric vectors will be created: one from the photo contained in the document, and another from the selfie taken by the user at that moment. By comparing them (in a process known as 1:1 or one-to-one), it is possible to verify that a person is who they claim to be. After the verification, this data is sent to FCB and the VERIDAS systems are instantly deleted.

FCB responded that, in the process of comparing the ID card image with the selfie, biometric data was only taken from the face and the ID card photo to generate two patterns that were compared using a one-to-one system. 1:1. Once it was
verified that the person carrying out the procedure was who they claimed to be, the system
validated the process and the data was deleted from VERIDAS' systems.

“17-2 Furthermore, explain why you request an image of both sides of the ID card-“

FCB responded that it was for security reasons, to be able to verify that it was
an authentic document. No copies of ID cards were registered.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 61/139

“18 In its response to the transfer, FCB reported that

During the registration process, whether through an app or a website, a
photograph or video is taken of the user and of a document that allows them to prove their

identity. All the data contained in both the document and the image of the
face will be sent to the validation systems developed by VERIDAS.

Considering that the API states that

“Once the facial comparison process is completed, the ID card is deleted by
FC Barcelona and the biometric vectors remain encrypted by SIA,

for seven days on its own servers located within the European Economic Area. VERIDAS does not host any biometric data on its own or third-party servers.

Please explain what this means: “All data contained in both the document and the facial image will be sent to the validation systems developed by

VERIDAS?” And, if the software system is managed by INDRA SIA, why do they state that it is sent to VERIDAS? And explain why the facial biometric vectors remain encrypted for seven days on SIA's own servers (sub-processor).

-If VERIDAS uses the software and does not access any data, what is the reason

for signing a data processing sub-commissioning agreement? VERIDAS.”

FCB responds that “as indicated, VERIDAS, once the process was completed, did not store any data, since its function is to provide the application through which the document validation was performed, and then the vectors were automatically deleted from its systems.”

Regarding SIA, as a company belonging to the INDRA group and responsible for the facial comparison process, it kept the vectors encrypted for a period of seven days.

Under no circumstances did it store either the photos or the ID cards. This encrypted data was retained in case any incident was detected in the biometric process.

“The term ‘all data’ refers to the fact that both the biometric data obtained from the ID card photograph and the data obtained from the photograph taken in real time were processed by the biometric engine. The document data and the image are sent to the validation system developed by VERIDAS, since this process is not performed on a physical terminal that captures the data.” data and performs an on-site verification of the interested party's identity; it would not be a physical terminal that stores the information itself. Since the biometric procedure is carried out remotely, it requires that the information be sent to the system that will validate the requested data, verifying that the member is who they claim to be by comparing their image (selfie) with the photograph on their identity document. VERIDAS does not retain either the user's personal data or the biometric vectors that have been created: once the contracted process has been completed and the relevant information has been sent to the client, it automatically deletes all the information that was on its servers.

In this phase, the analysis of the document's authenticity (with the processing of the data contained therein) and the identity of the person will be carried out, for which two biometric vectors will be created: one from the photo contained in the document, and another with
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 62/139

The selfie taken by the user at that moment; by comparing them (in a process known as 1:1 or one-to-one), it is possible to verify that a person is who they claim to be.

After the verification, this data is deleted from the VERIDAS systems instantly.

FCB indicates that the data is sent to VERIDAS because it is sent to its validation system, as this is the provider subcontracted by INDRA/SIA that offers the service/system. INDRA is the company selected by FCB to implement all the software to carry out the census update process, which, in turn, subcontracts the part related to the facial comparison and voice recording process to SIA, which, in turn, subcontracts VERIDAS as the company. to
develop and design the software for the biometric facial comparison process and
voice recording, as it is a leading company in the biometrics sector,

for this reason VERIDAS acts as a sub-processor for INDRA-SIA.

“19-Regarding SBRVOZ, it is requested that they provide FCB's own DPIA.”

FCB responded that, as already stated in the allegations, similarly to the processing of
SBRF, “the risk assessment report indicates that it is not mandatory to
carry out a DPIA; however, taking into account the particularity of the system, it was
decided to further delve into the analysis and incorporate the

basic points of a DPIA into the risk assessment so that it would be considered as such, “so that the proportionality of the processing was also analyzed in the report from the
perspective of necessity.”

The document “RISK ASSESSMENT REPORT” is provided AND
PROPORTIONALITY OF THE PROCESSING OF PERSONAL DATA WITH
VOICE BIOMETRIC SYSTEMS. DATE: DECEMBER 22, 2022,

VERSION 1.” Its structure and composition are similar to the report of the same type, regarding
the SBRF (point 4 of the allegations to the agreement, fact eight).

It provides the document “RISK ASSESSMENT REPORT AND
PROPORTIONALITY OF THE PROCESSING OF PERSONAL DATA WITH
VOICE BIOMETRIC SYSTEMS. DATE: DECEMBER 22, 2022,
VERSION 1.” Its structure and composition are similar to the report of the same type, regarding

the SBRF (point 4 of the allegations to the agreement, fact eight).

The document was not included in the response to the transfer nor on the two occasions when information was requested in previous proceedings. FCB
expressly stated that the report contained elements that are typical of a
DPIA, although in the response to the transfer, second fact 3) stated that it has carried out
risk assessments of the processing activities and when their

need has been identified or detected in the risk assessment, the corresponding impact assessments
of certain processing activities

Purposes of the processing. Use of voice biometrics for verifying the identity of members when conducting telephone transactions with the Club

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 63/139

Data processing categories:

- Identification, name and surname

- Voice

For the purposes of risk assessment, this refers to the risk to the rights and freedoms of members to use a voice biometric system (DAS-PEAK) for identity verification when conducting telephone transactions with the Club.

Furthermore, considering the specific nature of the processing, it is deemed necessary to analyze the proportionality of the data processing system to determine its necessity.

In section 6, the description of the processing, the processing is divided into stages:
data capture/classification/storage-Use/processing-transfer/destruction,

with a simple description that fails to specify which stages involve voice recording.

In section 7, on proportionality, the issue of fraud in

ticket purchase or seat transfer services, fraudulent use of membership cards
in two forms: those of deceased members, where their cancellation is not reported and
the cards continue to be used, and those of members who illicitly transfer their season tickets or
cards. The section also considers the possibility of providing these services by telephone with an identification system, given that it is a more reliable and secure method

for the Club and its members.

Within the framework of proportionality, the concept of "necessity" is included, indicating that, regarding voice authentication, no non-biometric system exists that can achieve the same objective: preventing fraud or identity theft, which can only be accomplished through biometric technologies. These technologies allow for robust verification without compromising the security of password or key storage. The analysis considers that being a member of FC Barcelona, with the established legal and statutory rights and obligations, carries a high legal and institutional impact and establishes a legal burden that members assume. This makes verifying one's identity as a member with complete certainty an unavoidable necessity to confirm the rights and obligations derived from membership.

Regarding "effectiveness," the analysis indicates that the system is effective because it cannot be deceived, preventing members from impersonating each other, unlike any other system that carries risks of impersonation.

Regarding the "loss of privacy," it notes that the use of the voice processing software "das-peak" is less invasive of people's privacy, requiring only a

short recording without mentioning any specific pattern or phrase.

Regarding the existence of less invasive means, it was considered whether there were
less privacy-invading means that could achieve the same desired end, and
after analyzing the alternatives, it was found that they cannot achieve
the same end. "All the alternative systems analyzed lack

defense mechanisms against impersonation." Its speed stands out compared to other "knowledge-based verification" systems, or other non-biometric systems such as "phone-as-a-token" (OTP), which takes five seconds for registration and three seconds for verification.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 64/139

It uses technology with up to 99% reliability because the biometric vector created by the biometric engine generates a unique biometric vector for each person.

This section concludes by stating that "legitimacy is weighed against the potential

violation of the rights and freedoms of the data subjects, concluding that these rights are not
at risk of being violated for the reasons described above, and there is a
balance as there is no significant intrusion into their privacy."

This is followed by section 8, "Analysis of the Need for a Data Protection Impact Assessment (DPIA)," which must analyze whether the processing could pose a high risk to the rights and freedoms of individuals.

The assessments do not analyze the risks, but rather respond to assumptions contemplated in WP 248, such as whether large-scale processing is carried out, comparing it to the population level of the territory in Catalonia, and concluding that it is not. In the category of data processed, biometric data is not listed, with "special categories" of data unchecked, and below, in another box, the "extent of processing: international level" is checked.

In the same section, regarding the nature of the processing, it states that different datasets and various sources of information are not combined. It also indicates that it does not refer to individuals in vulnerable situations, and it does not mention processing biometric data in this section. In the context of the processing, the answer is "Yes" in the box for "use of new or emerging technologies," but "No" in "use of technologies that inherently add risks" or in "any other circumstance that may generate a relevant risk for individuals."

In scope, it indicates that no decisions with legal effects are made. In use of new or emerging technologies, the answer is "Yes." In use of technologies that inherently add risks, the answer is "No." In purposes, it indicates that no decisions are made, and it does not specify that biometric data is processed. Regarding the perception of a high risk by the data controller, it is indicated that it cannot lead to a loss or alteration of information. Based on the various negative notes present,

in addition to those already mentioned, such as the fact that special category biometric data is not processed, it concludes that the processing is not considered to pose a risk to FC members.

The “volume of data is minimal, since we are only processing the voice of the member, and the rest of the data was already in FCB's possession prior to this processing.”

In “Technologies used for processing”

- Are technologies that may be perceived as immature, recently created or launched on the market, whose scope cannot be clearly or reasonably foreseen by the data subject and which imply a high risk of unauthorized access, foreseen?

(combination of new technologies, use of smart devices) - YES

Could this processing lead to a loss or alteration of information? - NO, in the section on “perception of a high risk by the data controller.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 65/139

In section h, regarding the systems used for processing, it states that:

“The system captures the unique characteristics of the voice from an audio recording and compiles them into a unique and irreversible biometric vector associated with the client's ID.”

“Regarding the identity verification process, it is carried out through a
1:1 authentication model, in which the process acts as a two-factor authentication
where, once the user has been previously identified and
a vector associated with that person has been obtained and linked to a phone number,
ID number, password, etc., when a second

recording (the verification recording) is captured, it will be compared with that associated vector;
ultimately, a comparison is made between the biometric vectors extracted from two
specific audio recordings to determine if there is a match. Based on the result obtained from
this comparison between the biometric vectors extracted from both audio recordings,
identity verification will be obtained or the verification will be rejected due to a
non-match.”

It defines a biometric vector as “a way of representing a person's facial features, generated by the biometric engine, and sent to the client, who will store it in their own systems.”

The vector's defining characteristics are irreversibility and lack of interoperability.

“VERIDAS does not retain either the user's personal data or the biometric vectors that have been created: once the process for which we were contracted is completed and the relevant information has been sent to the client, all data stored on VERIDAS servers is automatically deleted.”

A table of “DAS-Peak software guarantees” and its certifications is included.

In section 10, “Conclusions on the need to carry out a

DPIA,” it indicates that the biometric data it processes cannot be considered as
special categories of data, is not included in Articles 35.1 and 2 of the GDPR,
is processed with the consent of the members, does not systematically evaluate
personal aspects, based on the number of members it may affect (143,000), it does not consider it large-scale processing, does not make

automated decisions that could have legal effects or prevent them from obtaining
services or benefits, despite the use of new technologies, given their security, it is not considered to pose a risk to the members, and although the
processing could be classified within technologies considered immature, the
software used is completely secure, and its owner has certifications, so

its use does not pose risks to the members.

“The controller does not perceive that the main activity of the
processing involves a High risk, therefore, based on the three levels of analysis and the questionnaire responses, it is concluded that the processing of voice biometric data for verifying the identity of members when they carry out telephone transactions does not require an impact assessment.

This is followed by section 11, "Risk Assessment Analysis," which contains a list of 19 risks that it indicates were taken into account for the assessment.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 66/139

This is followed by the data lifecycle in processing activities, with a brief explanation of the process at each stage, without a description of specific flows or operational periods, along with the stakeholders:

partnerships, and the technology used.

This is followed by a table listing the main key processes identified in the voice recording operation, verification process, and user deletion, including, among other information:

“A comparison process is carried out between the biometric vector

generated from the registration audio and a new biometric vector generated
from a new user audio recording (verification audio). A comparison is performed, searching for matches (noise and silences are removed, etc.), and a numerical match result is obtained. If this result exceeds the required levels, the process is completed.” As determined by the Client, identity verification will take place.

-The biometric vector is extracted from a voice recording of the person, taking into account the physical characteristics of the vocal apparatus and features such as frequency, speed, and accents, compiling them into a unique and irreversible biometric voice vector.

This continues with Annex B1, “Risk Assessment,” which includes the probability/impact matrix used, with four points in each direction.

Under “Default Risks,” it is divided into Risks associated with:

“Information Protection,” with the same content as in the SBRF and the same control measures (pages 26 and 48), with a “low risk” result, referring to “control measures.” These include:

-The probability values for the unintentional modification or alteration of personal data are 1, the probability is 2, the impact is 1, and the control measures are segregation of duties through profiles. Access. Such as monitoring controls, network threats, configuration logs of file access.

- Unintentional loss or deletion of personal data. Probability 1.

Impact 2. Control measures: backups.

Confidentiality, unauthorized access to personal data,
Probability 2. Impact 1. Control measures: Awareness of the duty of confidentiality.
Inventory of resources with data accessible through telecommunications networks.
Network and application segmentation. Policies. Need to know

to access information, the duty of confidentiality for employees who access data, and its consequences. Destruction of discarded media containing personal data.

- Confidentiality breaches, personal data by employees,
Probability 1. Impact 2. Employee training regarding

confidentiality. Establishment of deterrent sanctions.

“Regulatory Compliance”
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 67/139

Highlighting the lowest score, 1, in probability and impact for the absence or non-formalization of the legal basis for processing personal data or its transfer. Negligible degree, control measure; voice recording is not possible

without the prior consent of users without their participation in the recording. The same level is given to collecting data without providing the necessary information or difficulties in guaranteeing the legitimacy of personal data.

“Data Quality”

Underlining the lower value given to the collection of irrelevant or excessive data

for the intended purpose, measure: voice is the only data collected, as is the case with data retention for longer than necessary.

“ARCO Rights”

“Security, risk type: Incident management, risk: inability to detect or manage security incidents, degree: low risk. Control measure: “Internal and external IT security audits.”

In the conclusions section: “Once each of the risks was analyzed, it was observed that the risk of the analyzed data processing is minimal, and the low risk detected is more than offset by the proposed control measures.”

“20 Copy of the risk analysis of the SBRF processing for updating the member census and measures adopted to mitigate its effects, which, in its response to the transfer of the stated complaint, was carried out through a questionnaire or any other means.”

FCB responded as in the previous point regarding the preparation of the
risk assessment report for not being obligated to carry out a Data Protection Impact Assessment (DPIA), and it was
decided to incorporate the basic points of a DPIA into the analysis.

They provided a copy of the document “RISK ASSESSMENT REPORT AND
PROPORTIONALITY OF THE PROCESSING OF PERSONAL DATA WITH
FACIAL BIOMETRIC SYSTEM FOR THE CENSUS UPDATE PROCESS. Date:
22/11/2022, Version 1”.

The document matches the copy-pasted document that appears in fact eight,

allegations point 4.

“21. Provide a copy of the meeting that appeared in the DPO's meeting list, specifically
the meeting of 28/04/2023: “Analysis of the suitability and legality of the biometric process for
updating the census”.

FCB responded stating that they have no record of any meeting on the indicated date.

However, in API's second request for information, the response from FCB, under the "List of Meetings Held - FCB Member Census" from the Data Protection Officer (DPO), includes an "analysis of the suitability and legality of the biometric census update process," following the information request received from the Spanish Data Protection Agency (AEPD). This document was the one requested, and although the date did not match the request, the title did, and it was not submitted.

"22 In their arguments against the initial agreement, they submitted a report that they claim meets the requirements of the Data Protection Impact Assessment (DPIA). It has no title and is dated November 22, 2022. They are asked to indicate the purpose for which this report was completed and its title."

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 68/139

" Please indicate in what document and on what date it was previously submitted (in response to the transfer or in the prior actions).

In that document, you describe the stages that could generally occur in any processing activity. You must specify which stages would be fulfilled specifically for the census update and the processing or retention period for each stage, in your systems or in those of the data controller/sub-processor. Also, in the section on

"data lifecycle in processing activities," please indicate if contact information is requested again, what contact information is requested, and what this means in "systematic description of the processing operations and purposes - data flows between systems:
***SERVICE.4 of FCB and das-face software."

Given the option for members to voluntarily update the census by attending in person at the physical headquarters, and given that the aforementioned document

does not analyze the necessity of the data processing, considering that the number of members abroad and in Spain is only about seven thousand in each country, a small minority,

what judgment of necessity was made regarding the census update?

FCB responded that the report was completed for the purpose of conducting an initial risk assessment to identify and determine the risks associated with the use of biometrics in the census update process and, based on its conclusions, whether or not an impact assessment should be carried out and the risks of processing should be assessed for human rights and freedoms. This report was titled "RISK ASSESSMENT AND PROPORTIONALITY OF THE PROCESSING OF PERSONAL DATA WITH A FACIAL BIOMETRIC SYSTEM IN THE UPDATE PROCESS."

The essential content of this report was provided in the information request dated May 25, 2023.

In any case, it should be reiterated that this process does not foresee the request for contact information again (in any case, this information can be updated if it is incorrect).

Regarding the necessity test, this was analyzed and resolved in the previous report, which is referenced in [reference to previous report]. This point analyzes whether opting for the use of this system is essential to fulfill the identified purpose, which is the statutory obligation to update the FCB membership register. In other words, it analyzes whether the system was essential to achieve the intended purpose or whether it was chosen solely for its speed or cost-effectiveness. The conclusion and assessment are as follows:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 69/139

“For these purposes, it is concluded that this system is indeed proportionate, as it is necessary to fulfill the obligation required by the FCB Statutes to maintain an up-to-date membership register and because it is not simply the fastest or most economical system, but rather the most suitable, taking into account several aspects such as: the system's resilience and the number of members.” (143,000) who must update their information and the possibility that all members, regardless of their geographical location, can use it without having to travel to FCB's headquarters in Barcelona, as well as the security and authenticity guarantees it offers. Therefore, it is imperative to have a system that allows the census to be updated from different locations with the highest guarantees of reliability, something that can only be done, without the data being able to be manipulated, with a system of this type.

This report has concluded that, although other systems and possible alternatives exist, they are not equally valid, as they do not offer the same level of protection and accuracy. Therefore, these alternative mechanisms could lead to a failure to achieve the purpose that the census update intends to fulfill, and for this reason, they have been discarded, thus determining the need for the chosen system. “

“The risk analysis regarding the census update process was carried out
exclusively for the facial comparison option, since, for the other

scenarios, whether by phone or in person, no specific analysis is required because
no new personal data is requested and it is simply an update to comply
not only with the Club's Statutes, but also with the obligation to
keep the data updated as required by Article 5.1.d of the GDPR.

The assessment of the necessity of the facial comparison process adopted for the

2023 census update was based on the Club's awareness of
fraud in the use of membership cards and the fact that none of the previous
update processes (such as, for example, the use of forms) were able to resolve
this problem.” The clearest evidence that the adopted facial comparison system was necessary for an accurate and effective update process is the fact that 14,433 Club members have not completed the update process, consequently losing their membership status. This demonstrates that a large number of active membership cards were not being used by their actual holders, and therefore, with this system, they have had no way to update them and continue using them.It is true that the facial recognition system was not mandatory; however, for the reasons already explained, the Club prioritized its use by informing members, and given the results, it has proven effective, as members have used it extensively. Thousands of cases have been detected where members have chosen not to update their information, presumably due to misuse of their membership cards.

TENTH: Issuance of a proposed resolution dated November 4, 2025

On November 4, 2025, the Investigating Officer issued a proposed resolution with the following wording:

“That the Presidency of the Spanish Data Protection Agency sanction
FÚTBOL CLUB BARCELONA, with Tax Identification Number G08266298, for:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 70/139

- An infringement of Article 35 of the GDPR, in accordance with Article 83.4.a), classified as serious for the purposes of its statute of limitations under Article 73.t) of the LOPDGDD, with an administrative fine of €500,000

That the Presidency of the Spanish Data Protection Agency declare the case against FÚTBOL CLUB closed BARCELONA, with tax identification number G08266298, for:

- An infringement of Article 9 of the GDPR, pursuant to Article 83.5.a) of the GDPR.

ELEVENTH: Objections to the Proposal
On November 21, 2025, objections were received from FCB, stating the following:

FIRST: ON THE MANDATORY NATURE ATTRIBUTED TO THE DATA PROTECTION IMPACT ASSESSMENT (DPIA)


1. FCB states that the data processed was used for authentication purposes and was not considered a special category at the time it was processed, a criterion then in force by the Spanish Data Protection Agency (AEPD). It argues that if the data does not constitute a special category, a DPIA is unnecessary. Having acted in accordance with the criteria and guidelines in force at the time of the events, the principles of legal certainty and legitimate expectation are violated, and FCB cannot be held liable for such conduct.

2. Regarding the AEPD's classification of this biometric data as high-risk processing for the fundamental rights and freedoms of natural persons
used by FCB, considers that it must be taken into account in the interpretation of the
GDPR when assessing the need to carry out a DPIA, that the

Artificial Intelligence Regulation of 2/10/2024 expressly establishes that the processing of
biometric data in contexts whose sole purpose is to confirm that a specific natural person is the person they claim to be, does not generate a high risk, but is
considered to be of low or non-existent risk to the rights and freedoms of the
data subjects. It provides a copy-paste of ANNEX III, which indicates:

“High-risk AI systems pursuant to Article 6(2) are
AI systems that fall within any of the following areas:

1. Biometrics, to the extent that their use is permitted by applicable Union or
national law:

a) Remote biometric identification systems

AI systems intended to be used for purposes are excluded of
biometric verification whose sole purpose is to confirm that a specific natural person

is the person they claim to be.”

3-FCB appeals, on the grounds that the AEPD's consideration is not met, regarding the fact that the circumstances listed in the proposal as criteria

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 71/139

for classifying the two processing activities as high-risk, and which are contained
in guideline WP 248, are not present, with the following arguments:

-A-“2. Processing activities that involve automated decision-making or that
significantly contribute to such decision-making, including any type of

decision that prevents a data subject from exercising a right or accessing a good or
a service or becoming a party to a contract.”

FCB states that “no automated decisions with negative consequences were made.”

FC Barcelona states that, regarding the SBRF (Single Biometric Registry), the system does not automatically block or exclude members when the verification result is negative.

As this party has previously explained in its written submissions, the algorithm of VERIDAS' technical solution compared the biometric descriptors to grant validation based on the threshold established by the system. If this threshold was not met, a message appeared warning that the process could not continue and that the member should contact FC Barcelona to update the registry through other means.

Thus, the system did not automatically block or exclude members in case of failure; instead, the member was informed of the impossibility of continuing the process and offered human assistance to resolve the issue. Therefore, for individuals
initiating the census update process, the use of this system

did not, under any circumstances, imply automatic removal from the membership list.

“Regarding the SBRVOZ system, in the hypothetical case that the system could not
validate the voice, the only consequence was the issuance of an informational message
urging the interested party to contact the Club in order to offer them other ways to

complete the required procedure. Therefore, there was no automated decision
that directly produced legal effects for the member.”

-B- “5. Processing that involves the use of biometric data for the purpose of
uniquely identifying a natural person.”

FCB states that it does not understand how this criterion is applied, given that it has already dismissed the issue regarding the special or sensitive nature of biometric data for processing purposes, considered as authentication or identification on the dates (processing ended on November 30, 2023) when said processing was carried out, maintaining an unequivocal position on this matter,

even though the data is classified as biometric data outside the scope of Article 9.1 of the GDPR. Maintaining this position is inconsistent, according to FCB.

-C- “7. Processing involving the use of data on a large scale. To determine whether processing can be considered large-scale, the criteria established in the Article 29 Working Party's WP243 "Guidelines on Data Protection Officers (DPOs)" will be considered.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 72/139

FCB, on this point, notes the indeterminacy of its definition, which is not included in the GDPR or the LOPDGDD, including recital 91, which contains more indeterminate concepts. The Guidelines on Data Protection Officers

WP 243 indicate that "it is not possible to give an exact figure applicable to all situations, in relation to the amount of data or the number of people affected," only proposing indicative factors that are indeterminate, and their practical application is subjective. FCB considers that, faced with such indeterminacy, the AEPD maintains that The processing involves the use of data on a large scale without conducting an
analysis of the resulting insecurity or providing objective criteria to justify such a

classification.

Regarding the assertion that both processing activities encompass all members, FCB
believes that, in principle, the census update was applied to all members,
but questions whether this should therefore be classified as large-scale. FCB compares the number of its members to the
total national and global population, showing that the number of members in Spain,
139,220, represents 0.28% of the Spanish population, and the 143,000 members represent 0.0% of the global population.

FCB considers the assertion that the processing of voice data was intended to be

indefinite to be incorrect, as individuals could withdraw their consent or
cease being members.

It concludes by noting the existence of interested members in different countries, totaling
7,826 individuals. This cannot be considered a contributing factor to

defining it as large-scale.

FCB states that they ultimately did not complete the census update process with
SBRF for the 143,000 individuals listed, subtracting those who did not update at all:
14,433, plus those who did so in person: 12,249. In the SBRF, this reduces the figure to

72,808 people.

-D- “9. Processing of data of vulnerable individuals or those at risk of social exclusion, including data of minors under 14 years of age, adults with some degree of disability, disabled individuals, people accessing social services, and victims of gender-based violence, as well as their descendants and persons under their

guardianship and custody.”

FCB indicates that the process was not carried out independently by the minor, but rather
jointly with their legal guardian, father or mother, with the minor not providing
the data themselves, but rather their legal representative. who authorized the processing-

States that it recognizes that this criterion is met, but that it alone does not compel
the performance of a DPIA.

-E-“10. Processing that involves the use of new technologies or an
innovative use of established technologies, including the use of technologies on

a new scale, with a new objective, or combined with others, in such a way that
it involves new forms of data collection and use with a risk to the
rights and freedoms of individuals…”.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 73/139

The FCB points out that the assertion that it admitted the use of immature technologies is inaccurate, as these are not new technologies. Their use has been understood in areas such as identity verification for decades,

citing examples of their use in the 2001 Super Bowl or for locking and unlocking devices. Furthermore, biometrics has been the subject of "continuous analysis and regulation for more than two decades," citing as an example the 2003 Working Paper on Biometrics WP 80 and Opinion 3/2012, which cites biometrics as a mature technology. The FCB considers that these technologies, which could be categorized as emerging, have been implemented with sufficient security guarantees, being technically and legally consolidated technologies.

Furthermore, FCB does not believe that the processing involves an innovative use of technology that entails new forms of data collection or use that pose a risk to the rights and freedoms of individuals, given that the technology in question has been extensively regulated and well-established for decades.

Regarding the statement contained in the DPO report of 9/11/2022, “Conclusions on

the analysis of biometric data processing in the census update process,” that “Regarding the technologies employed, although the biometric processing could be classified as immature technologies, the software used has been tested and determined to be completely secure,” FCB points out that there is no risk to its members arising from the processing.

FCB indicates that it does not use such an absolute statement but rather uses it as a way of conveying that the system was secure within reasonable standards, synonymous with adequate.

SECOND.- CONSIDERATIONS REGARDING THE DEFECTS ATTRIBUTED TO

THE RISK ANALYSIS REPORTS
FCB expresses its disagreement with the proposal's assertion that the risk analyses were carried out after the signing of the contracts. The processing and service provision agreement effectively invalidates

any subsequent conclusion regarding the compliance of the processing with the GDPR. It states that
relevance is being given to the signing of contracts, which is not decisive in
determining the suitability or invalidity of the entire process. “Furthermore, it is not true that
none of the contracts were signed before carrying out the corresponding risk analyses.”

FCB explains that a risk analysis is a process that requires time,
needs to understand the technology to be used, the IT solutions,
data and information gathering; it cannot be done in a day. FCB states that after the
June 2022 decision to undertake the census update, they considered doing so
with biometric data and analyzed potential providers, initiating contact and

gathering information to determine which providers could carry it out,
since it was a new service. FCB believes that contacting providers to
learn about market options and The solutions offered and the risk analysis of the treatment, taking into account the possible solutions offered, proceed in parallel.

Once it was confirmed that the options offered by INDRA were the best fit, they were considered in the analysis that had already begun in the abstract. “The technical information and advice provided by the supplier during the risk assessment process are necessary to carry out the specific analysis and include it in the report.” On September 22, 2022, the Data Protection Officer (DPO) was informed of this process, requesting the issuance of a report, the conclusions of which were issued on November 8, 2022.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 74/139 “Having also had access to the technical information
previously provided by the supplier to whom the processing was to be entrusted,

corresponding to the final date of issuance and signing of the document, the date of the
formal closure of the process, which had necessarily begun and been carried out
earlier. The date reflects the assessment of a process that unfolds over
time. FCB adds that the contracts were signed after the analysis had already
begun, taking into account the DPO reports.

“It is clear that the risk analysis process had begun earlier.”

It adds that this was not an obstacle to having been able to introduce the review of the
measures and their update when necessary, introducing the necessary elements such as addenda or annexes if they had occurred in the interim.

FCB indicates that the assessment reports have different dates because the voice processing
was an additional treatment that was considered later, although
both were always prior to the start of the processing.

Regarding the content of the risk analyses of the defects shown by the
Spanish Data Protection Agency (AEPD), FCB believes that there is no pre-established or specific criterion for the
risk assessment, but rather guiding principles such as the “Practical Guide to Risk Analysis in the Processing of Personal Data Subject to the GDPR” prepared by the
AEPD, “which FCB followed.”

It considers that it complies with the aforementioned Guide in:

-The aforementioned Guide establishes a two-phase methodology to determine whether it is necessary to carry out a
DPIA. The first phase involves analyzing the lists of processing
provided for in the regulation, Articles 35.3, 4, and 5 of the GDPR. The second phase, “analysis of the

nature, scope, context, and purposes of the processing (Article 35.1 GDPR),” elements that
are contained in its two reports. It indicates that after carrying out the assessments, it is determined
that “it is not necessary to carry out a DPIA.”

Having ruled out the existence of a high risk and, consequently, the obligation to
carry out a DPIA, the following analysis is carried out, also following the methodology of

the Guide:

1. On the one hand, the description of the processing activities is documented, using as an example the same template provided in Annex II of
the Guide. Thus, the stages in which we classify the data lifecycle (capture,
classification/storage, processing, disclosures and international transfers, and

destruction) and the classification of the elements involved in each of these
stages (activities, data, parties involved, and technology) coincide with the stages and the
elements indicated in the Guide. Therefore, the statements made
regarding the description of the life cycle of the treatments in both reports are surprising,
when the truth is that the Guide does not establish the obligation to carry out such a

detailed description in the terms now required, nor is there any impediment
to treatments that rely on the same technology presenting similarities in
their life cycle. “In fact, the guide indicates that for processing activities
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 75/139

supported by the same technology, the exposure to the risks arising from its use
will be similar, and processing activities can be grouped under this criterion when
identifying, evaluating, and treating them.”

2. Regarding the risk analysis process, FCB specifies that it is documented
based on what is described in the Guide and that it was unaware that it was required and
essential for the validity of the reports. It adds that the Guide makes no mention of
documentary support for the conclusions reached or for any other
section, and that if it is necessary to clarify specific issues, as a

supervisory authority, it should provide guidelines and directives and have included them in the Guide so that
data controllers are aware of them.

“It is particularly striking that such an exhaustive level of detail is required—for example,
numerically justifying the probability and impact, explaining

our specific method for determining the probability and impact figures,
differentiating between inherent and residual risk, or explaining how the measures reduce risk—when such issues clearly exceed the methodological framework provided in the
Guide. Even more surprising is that the validity of the analysis is intended to be derived from this.

“This situation creates legal uncertainty and constitutes an expansive interpretation” and
exceeds the available methodological content and obligations of both the GDPR and

the LOPDGDD. “The failure to comply with the guidelines, which did not previously exist, cannot be considered sufficient grounds for invalidating the reports.”

THIRD.- ON THE MODIFICATION OF THE TERMS THAT LED TO THE

INITIATION OF THE DISCIPLINARY PROCEEDINGS AND THEIR NEW INTERPRETATION

FCB indicates that “while the initiation of the proceedings was based on the need for a Data Protection Impact Assessment (DPIA) due to the presence of special category data, once this argument was discarded,

the alleged infringement of Article 35 of the GDPR is now being maintained.”

“This reflection is based on the fact that the level of risk attributed to the update of the census, which was considered high by the Spanish Data Protection Agency (AEPD) due to its connection with the biometric nature of the data processed, as can be seen in the document initiating the sanctioning proceedings. In this regard, it can be concluded that biometrics was the determining factor for the Agency to consider the processing as high-risk, due to its potential impact on the rights and freedoms of the data subjects. If this element is eliminated, the processing is reduced to a mere census update, in compliance with a statutory and legal obligation, with a clearly lower risk, comparable to other ordinary processes that do not require a Data Protection Impact Assessment (DPIA).”

However, the processing of biometric data has been ruled out, and yet, the imposition of the sanction is now being justified on a different ground: the alleged lack of a comprehensive analysis of the processing activities, leading to a supposedly erroneous conclusion regarding the need for a Data Protection Impact Assessment (DPIA), as well as a series of alleged procedural and substantive defects in said activities.

Given that the resolution of the disciplinary proceedings depends on this, serious doubts arise as to whether this alteration respects the principle of congruity, considering that the imposition of the sanction is intended to be based on issues other than those that motivated the initiation of the disciplinary proceedings and, moreover, on alleged procedural and substantive defects in the risk analyses, a matter not regulated in the provision whose infringement now constitutes, after the partial dismissal, the sole basis of the proceedings (Art. 35 GDPR).

It cites several judgments that exemplify the principle, including those of the Supreme Court on this matter, set forth in its Judgment No. 570/2025, of May 14, and of the Constitutional Court. 138/1985 of October 18.

It should also be noted that the principle of consistency is equally
required in administrative proceedings, as recalled by the Judgment of July 13,

1995 (RJ 1995, 6238): “The procedural principle of consistency is more rigorous in the contentious-administrative jurisdiction and in administrative proceedings than in civil proceedings” (emphasis added).

In this regard, the above can be extrapolated to the present case, since the reason

for which this party was initially sanctioned—the lack of a Data Protection Impact Assessment (DPIA) for the
processing of biometric data—after being discarded, is being revived
by the Spanish Data Protection Agency (AEPD) in what appears to be an attempt to maintain a sanction that, in our
opinion, lacks grounds given the dismissal of the processing of
biometric data. But that's not all: when the existence of alleged defects
in form and substance in the risk analyses is invoked, the alteration of the foundations is such that

it bears no relation to what Article 35 of the GDPR—the provision on which the
sanction is based—actually regulates.

The foregoing leads to the conclusion that the actions are not being taken within the limits of the grounds
that justified initiating the proceedings, which is causing this party to be defenseless. Therefore, we respectfully request that the Spanish Data Protection Agency (AEPD) assess whether its

proposed sanction conforms to the limits and terms set forth at the beginning of the
proceedings, guaranteeing the consistency required of the Administration.

FOURTH.- REGARDING THE CIRCUMSTANCES INDICATED BY THE AEPD THAT

SUBJECT TO THE DETERMINATION AND IMPOSITION OF THE FINE
FCB does not agree with the following in the proposed sanction, specifically in legal basis VII:

- Regarding the content of Article 83.2.a) of the GDPR. As for the classification of
biometric technologies as immature, it has already been made clear that this is neither the meaning nor the definition given to the technology used in the risk analyses

carried out. Furthermore, it is stated that automated decisions were made, but
as has also been indicated in this document, neither the identification nor the collection
of data through the systems used in itself entails the
denial of any service or the making of a decision, since there was always the
possibility of contacting the Club in person or directly, and the second phase of providing telephone services was never carried out.

Regarding the seriousness of the infringement stemming from both the volume of data and its nature, it is considered that the data processed in the analyzed processes were limited, on the one hand, to two images of the associated person and, on the other hand, solely to their voice, since the remaining data, such as name, surname, date of birth, nationality, and signature, were already processed due to the associated person's status.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 77/139

Associated person. Regarding the nature of the data, it cannot be classified as a special category of data.



C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 77/139 “It is also surprising that the claim regarding the infringement of Article 35 is made that the “failure to comply
with said obligation before the actual commencement of the processing of this data

increases the risk that the data subjects may suffer in their rights and freedoms in the effective and high-volume processing carried out,” given that the processing did not actually commence until
March 20, 2023, and the assessment reports submitted are dated November 20, 2022, and
December 22, 2022, therefore, prior to the commencement of the processing.”

FC Barcelona reiterates that it must be considered a mitigating factor that no affected party has suffered, nor could suffer, any harm or damage. The reason given for this response is that "damage is not a determining factor, nor is it essential that it occur or be of a specific type, since causing harm within the framework of unlawful processing of personal data is only a potential, and not automatic, consequence of such processing. A violation of the GDPR does not necessarily entail harm," as it has been proven that the processing was not unlawful. The Spanish Data Protection Agency (AEPD) itself has indicated that there is a cause that would lift the prohibition, since the members have given their consent.


-Regarding “considering the special concurrence of the elements indicated in
Article 83.2.b)

FCB states that there is no special negligence because:

i) “The processing was suspended for barely a month and
was reactivated with the same assessments, without modifying the scenario or the point of
focus,” when the truth, according to FCB, is that if the conclusions were
the same, it was because as of May 4, 2023, nothing had changed regarding
the processing and the classification of the data that should not be

considered as a special category of data, since the Spanish Data Protection Agency (AEPD) had not yet
changed its criteria on that date.

Therefore, not only had FCB assessed the processing and analyzed the risks
before its commencement, but the circumstances and
measures adopted during the processing were also reviewed, without finding that it was necessary

to change the approach, beyond reinforcing the information for the
interested parties, thus complying with the provided for in Article 24.1

GDPR which states “(...), the controller shall implement appropriate technical and organizational measures to ensure and be able to demonstrate that the processing is in accordance with this Regulation. These measures will be

reviewed and updated as necessary.” (emphasis added).

Therefore, since neither the data categorization nor the
processing procedure nor any of the aspects analyzed for
its assessment (volume and category of data, nature, etc.) had changed, it was not necessary

to modify the conclusions of the assessments or update the measures
adopted. The only need identified was to add the relevant clarifications
to the explanation of the process.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 78/139

ii) Furthermore, the AEPD reaffirms that “FCB’s actions reveal
negligence in its conduct due to the absence of the required duty,” given that “FCB has a very high number of members, and despite being a sports association,
it frequently interacts with them, requiring it to exercise rigor and special care in its constant

data handling.” “Be careful with this type of data…”

“In this regard, it should be noted that of all the actions carried out throughout this entire procedure (which, let us remember, has lasted more than two and a half years, since the first prior request for information was received on April 21, 2023), FC Barcelona did comply with its obligations, effectively fulfilling the following obligations imposed by the GDPR, as already demonstrated in the proven facts:

1. Creation of a Record of Processing Activities (Article 30 GDPR).

2. Carrying out a specific risk analysis for each of the processing activities (dated November 20, 2022, and December 22, 2022, respectively) before their actual commencement on March 21, 2023, and implementing the appropriate technical and organizational measures according to the risks (Articles 24 and 25 (GDPR).

3. Selection of providers offering guarantees of compliance with data protection regulations and the application of appropriate security measures based on the risks, and signing of processing and sub-processing agreements with all parties involved (Article 28 GDPR).

4. Compliance with the duty to inform data subjects (Articles 12 and 13 GDPR) and, following the requirements of the LOPDGDD and the recommendations of the AEPD, layered information (Article 11 LOPDGDD and "Guide for compliance with the duty to inform").

5. Review of the measures adopted (Article 24 GDPR).

In addition to all of the above, FC Barcelona has appointed a Data Protection Officer (Article 37 GDPR).

Therefore, it is disconcerting that the Spanish Data Protection Agency (AEPD) reprimands FC Barcelona for suspending the processing for "barely a month when" the AEPD itself, neither in the two previous requests for information during the investigation phase nor in the agreement to initiate the sanctioning procedure, agreed to adopt any precautionary measures to safeguard the rights of the data subjects whose rights were allegedly being violated, as it had done in other cases. Thus, the AEPD disregarded the requests made by Complainant 1 and, furthermore, relied on the supposed "degree of intent, carelessness, or negligence (...)" indicating that the "justification for the assessment of the degree of fault" had been detailed. intervening party” to impose sanctions, when the reality is that

throughout the Proposed Resolution of the sanctioning procedure, the
AEPD itself not only details the obligations that FC Barcelona actually fulfilled
in relation to these data processing activities, but also fully accepts the
allegations made by FC Barcelona regarding the non-existence of a breach of

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 79/139

Article 9 GDPR and expressly indicates that “it is appropriate to accept its allegations
in relation to the culpability of the conduct” (emphasis added), dismissing this
infringement and thus recognizing that the data processed did not constitute

special categories of data. Therefore, throughout the entire procedure, it does not appear to have
seen sufficient evidence of a breach so serious as to make it
necessary to suspend the treatment or address the requests submitted to it by
the claimants, but instead it does consider and classify it as a
serious circumstance for setting the sanction. “

-Regarding the “systematic and teleological interpretation” made by the Spanish Data Protection Agency (AEPD) of the provisions of Article 83.2.g, concerning the categories of personal data affected by the infringement”

FCB states in this regard that the mention of the National Identity Document (DNI) as sensitive data without any prior mention of such consideration, nor in the initial agreement, which is brought up at this point, after the special category of the biometric data processed was ruled out, “after the AEPD acknowledged that they do not fall within the special categories of personal data,” these being the only data whose categorization as sensitive had been the subject of discussion and analysis throughout the entire procedure. FCB believes that the lack of justification for considering certain data as sensitive creates legal uncertainty, inconsistency, and a lack of due process, "since, after a lengthy process in which it was proven that the data that led to the opening of the disciplinary proceedings could not be considered sensitive, it is now surprisingly alleged, in order to determine the appropriate sanction, that there were other data that should also be considered sensitive, without any basis to support this assertion."

FIFTH.- ON THE PROPORTIONALITY OF THE SANCTION AND THE NON-EXISTENCE

OF COMPARATIVE GRIEVANCE WITH RESPECT TO OTHER PROCEEDINGS
FCB reiterates the comparison of the sanction in PROCEDURE 2, (…) that, being
the same type of infraction, in that case special category one-to-many data was used

in remote biometrics, and in the FCB case, special category data was not processed, the one-to-many system was not used, the processing was done with the knowledge of
the associated persons and in a controlled environment, citing the Guidelines on Facial Recognition of January 2021 from the “Consultative Committee of the Convention for the Protection of Individuals with regards to Automatic Processing of Personal Data

Convention 108”, which stated that private entities cannot develop facial recognition systems in uncontrolled environments such as shopping malls, especially to identify persons of interest for purposes of
security. Compare the business figures of ***COMPANY.1, 3,363 times greater than
that of FCB to affirm the disproportion between the fines imposed.

“On the other hand, the consideration that FCB is a non-profit

sports association is dismissed, and to magnify the economic circumstances, it is stated
that profits are obtained from a network of companies referred to by the AEPD as
“dependent companies” of the Group, when these companies are not part of the
proceedings, nor can FCB be classified as a large company.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 80/139

PROVEN FACTS

FIRST:
The FCB Board of Directors approved on 06/21/2022, among other measures, the promotion
of updating the FCB membership census during the 22/23 season. In the document provided during the testing period, FCB also indicates that it is: “digital and

mandatory for all members and season ticket holders,” stating the following objectives: to regularize inactive members, promote the Club's digital transformation, improve future communication with members, and combat fraud, thus benefiting members. It can be done from a computer or mobile device with a camera, via the website, by physically verifying identity using the ID card and the device's camera.

FCB states in its response to the complaint that it implemented the membership update process to ensure an accurate and reliable record and prevent the fraudulent use of membership cards and season tickets by third parties who are not the actual holders.

SECOND:

FCB is launching a membership update campaign from March 20th to November 30th, 2023.

FCB has decided to implement an online digital membership update process via the Club's app or website. Members will log in with their username and password. The process will utilize the

biometric facial recognition system (SBRF) to verify that they are still alive and that their information is correct and up-to-date.

FCB also offered members the option of visiting its offices in person to update their membership information, without needing to provide a digital sample.

Members could also opt to use the SBRVoz system if they wished.

In the same process, FCB offers, after verification of the SBRF process, the voluntary collection of voice samples (except for minors) using the Broz biometric voice recognition system.

Alternatively, FCB offered the SBRF the option of visiting its headquarters in person for this purpose, without having to provide a digital sample for census updates, and with the option to accept the use of the SBRVoz system if desired.

The SBRF for minors, aged 14 to 17, is the same as for adults.
Minors under 14 years of age must validate the system, with their parent or legal guardian declaring that they are the minor's representative completing the census process.

FCB has 14,511 members under the age of 18. (Fourth fact 22, API, 11.2 of ninth fact, evidence).

The updating of the census and the collection and use of the voices of the same category of
members associated with FC Barcelona, which implements the collection and use of a SBRF and

voluntarily, a SBRVoz, are both motivated by, and share a common factor: a
limited number of stadium seats in the face of high demand from members and
fans for season tickets to attend FC Barcelona matches, due to:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 81/139

-cases of members who die and whose families do not notify the Club,
allowing them to continue using their membership card or season ticket.

-the practice of illegitimately transferring membership cards of members of the Club, or
transferring season ticket holders' cards to third parties for a fee.

-fraud and identity theft in the purchase and sale of season tickets and
the transfer of seats.

The distinction between collecting facial and voice data from members, despite being done simultaneously on the website or app, is that the use and purpose of the voice data is unrelated to the membership census update process. Instead, it is for the future provision of telephone services for ticket sales, season tickets, and seat reservations.

FCB designed a system for updating the membership census and collecting voice data that would take into account the global distribution of members, eliminating the need for physical travel to the Club's offices and providing security, certainty, and real-time authentication. FCB provided data on the number of members, geographically distributed as follows:

- Abroad: 7,926, representing approximately 5.4%

- Barcelona city: 55,837, representing approximately 38%

- Barcelona metropolitan area: 25,903, representing approximately 17%

- Rest of Catalonia: 14,258, representing approximately 34.6%

- Rest of Spain: 6,136, representing approximately 5%

This information is in accordance with the statements provided by FCB in point eight, allegations, 4, the evidence-gathering period, in point nine, 9), and FCB provides in document 10, a table showing the geographical distribution of FCB members as of November 8, 2023, supplemented by point 1 of the allegations in point eight.

The previous process for updating the FCB membership census, which took place in 2012, consisted of an online system of forms for FCB members registered outside the city of Barcelona. The rest had to appear in person at the headquarters, according to response 1 of point two provided in response to FCB's claim. In that process, 1,000 season tickets were recovered, as per point nine 1.1.

THIRD: To carry out the online digital census update with SBRF, to which SBRVoz voluntarily added its own, information on data collection and common use was provided for both. It was listed on the FCB website,

https://www.fcbarcelona.es/es/ficha/3052130/como-censarte, according to the screenshot

provided by R1 in fact one (point 2), and in,

https://www.fcbarcelona.es/es/ficha/3052130/como-censarte, fact four, API, 22).

The information regarding the process is also reiterated in the responses at

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 82/139

API, fact four, point 2, through the communication sent on 20/03/2023 to the members, in point 5 of the FAQs. It consists of 8 steps:

1- Through the Club's website or members' app, go to "New Member Census" and log in with your password and personal code (PIN) to access the private area.
2- Go to the "New Member Census Procedures" section.

At this point, you were informed about the data collection and its purpose (information clause, first layer) displayed on the screen, and you were asked to accept the privacy policy, according to FCB's response in testing, section 10.1, point nine.

3- Select your country and the type of official identity document.
4- Show your official identity document to the camera, and it will be scanned automatically.

5- Take a selfie.

6- Record your voice for 5 seconds.

7- Finally, access the data form, complete it, and verify your Barça profile.
To clarify the content Regarding step 7, in testing, FCB indicated that it involves:

displaying the personal data of the member performing the process on screen, so they can update any outdated information.

8- The process will end with certification that it has been completed correctly.

This process was also reported in the first communication sent by FCB to its members on March 20, 2023, as stated in the preliminary investigation proceedings, Fact 4, 2.

FOURTH:
The information clause regarding data collection and processing displayed on the screen appears before the facial biometric capture process of the members and is indicated by FCB in its response to the transfer, Fact 2,
response to transfer 5, providing a screenshot that matches the one

provided by R1 in Fact 1, 2, indicating it as "new census 2023".

This notice informs you of:

“Purposes: management, relationship building, and identification with the member. Procedures and
management related to season tickets. Right to use the seat, use of biometric data for
contact with the Club and for member authentication and identification for
access to Club facilities with the member's express consent, sending communications related to FC Barcelona, electronic sending of
commercial information from FC Barcelona, and/or affiliated/subsidiaries,

as well as from its sponsors or partners.

Rights: You may object to receiving commercial communications and exercise your

right of access, rectification, erasure, portability, and restriction of processing,” including an email address and further information via a link.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 83/139

In the test procedure, section 8.4, FCB clarifies that the authentication of the
data referred to the facial comparison process for updating the census
of members, subsequently dismissing the purpose of using it for access control,

and that the voice data was intended to validate the identity of members in telephone contacts to prevent fraud and impersonation.

Two checkboxes follow.

The first, “I accept the Privacy Policy,” with a link when clicked.

The second, “I accept the recording, registration, and use of my voice as biometric data in accordance with the Privacy Policy I have accepted.”

The clause under analysis also provides information on various means of
contacting FCB if questions arise regarding the process, but it does not expressly state that
the alternative of completing the membership census update or the voice survey in person at FCB headquarters is also applicable,

although this may appear in other sections of the website, in communications, or with a
later date.

This initial layer, according to the information provided by FCB, remained
unchanged during the update process.

Clicking on the "I accept the privacy policy" link, according to

the information provided by FCB in response to the transfer, point 5,
leads to information on all the data processing activities carried out by FCB—up to 10—
as indicated in point 8.5, point 9: to provide the most comprehensive information possible on
the data processing activities. In this case, it is worth noting that it further specifies the
differences between SBRF and SBRVoz processing, classifying them according to their

purposes of use.

Both are listed in “Purposes, legal basis and retention of data processing carried out by FC Barcelona.

1. Management of the relationship with the member and procedures arising from membership status,” with the following distinctions:

a) “Application for membership and management of related procedures”

Purpose: To register you as a member, issue membership cards and duplicates, manage
the payment of dues, manage season tickets for the use of available seats,

maintain the relationship and apply the disciplinary code;

carry out administrative tasks arising from the relationship; manage the
election of delegates and convene information sessions;

convene assemblies and referendums; manage voting and, where applicable,
process postal votes; convene and hold

electoral processes. Use of biometric data for member authentication and

validation of member access to the Club's facilities or in Remote/online procedures with FC Barcelona, providing you with a Barça ID number so you can interact with FC Barcelona through a single username and/or code and enjoy all the benefits and services offered by FC Barcelona with a single ID and username. Sending communications by any means, including electronic, regarding the Club's activities and events; sending commercial information via electronic means and social media, applications, or websites of which the member is a user, from FC Barcelona entities, its sponsors, and/or entities related to the Club's activities.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 84/139

Legal basis: Membership registration and compliance with the FC Barcelona Statutes, rules, and policies. Consent for the use of biometric data. Legitimate interest in keeping the member commercially informed.

Retention: While you are registered and maintain your FC Barcelona membership status. and once this is completed, for the legal periods to address any potential liabilities. Until you withdraw your consent for the processing of your biometric data.

b. “Member Census Update”

Purpose: Procedures for updating and validating member data to update the FCB member census.

Legal Basis: Compliance with the FCB Statutes, rules, and policies.

Retention: While you are registered and maintain your FCB member status.

In the response to API dated 11/29/2023, point 3), FCB indicated that the use of voice biometrics was postponed until the census update process was completed, while

in response 20 to API, dated 07/17/2024, point 4, FCB indicated that “to date, no procedure has been initiated in which voice biometrics could be used, and it has been decided not to implement the process while…” "Analyzes," while the voice data is stored in the member's personal file within the Club's management program.

In the arguments against the agreement and in the evidence

FIFTH:
In point 11 of the fourth fact, it is stated that FCB submitted the RAT "census update" to API on November 29, 2023, highlighting the following aspects:

"Purpose:

-Updating the Club's member census through facial recognition processes," "Access to Club facilities via facial recognition systems" in the same API response, point 10, with FCB adding that consent would be requested for this, given that they already have the "updated image of the members."

-“Authentication of the member by voice for carrying out telephone procedures with the Club, ticket sales, use of free seats, renewal,
any procedure requiring member authentication, online procedures with
FCB.”

As the legal basis for the processing, without differentiating between the use of SBRF and SBRVoz, it indicates:

-6.1.a) of the GDPR,

-6.1.b) of the GDPR in relation to Article 11.8 of the FCB statutes.

Data categories:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 85/139

“Identification data: name and surnames; date of birth; nationality; ID/Passport; expiry date; sex; language. Signature. Identification data of legal guardians.

Contact data: postal address; telephone; email address.
Financial and tax data: bank details (account number) and tax information.
Social data: sports preferences and membership in Club groups. Contact on social media.
Image: Member's photograph; photograph of ID card.
Biometric data: facial and voice biometric vectors,” although some data were already

previously included because they were necessary for acquiring membership or because FC Barcelona stated that it already had them, such as the photograph on the membership card.

SIXTH:
FCB acknowledged in its response to the transfer and in its arguments that it had prioritized

updating the membership census online, considering it the most suitable, convenient, efficient, and secure method.

It is established that the information regarding the option to update the membership census in person was not included in the first information sent by

FCB to members on March 20, 2023 (fact four, API 2), but it did refer to that option in the announcement of the first extension, until October 31, 2023, and in the announcement of the second extension, until November 30, 2023. It was also included in the "More Information" section of the Club's website, under the Membership Census area, FAQs. Nor was it included in the extension notices or reminders to members who had not yet updated their census data.

The census update extension notices, such as the one sent to R2 on October 2, 2023 (newsletter), added that the census update was being carried out to improve and personalize communication between the Club and its members and season ticket holders, and that it is an obligation regulated in Article 11.8 of the FCB Statutes, requiring the creation of a digital profile.

It warned of the consequences of not updating: inability to renew membership cards and the consequent loss of season ticket holder status. The in-person option was not mentioned.

SEVENTH:
In summary, for both scenarios, the purpose of processing biometric personal data is to:

-update the membership list by any member from any geographical location without the need for travel, using a reliable and guaranteed system, as FCB argues that alternatives do not offer the same level of accuracy. There are cases where member deaths are not reported, and the membership card, along with the season ticket (if the deceased held one), continues to be used by third parties, given that season tickets are automatically renewed each season. The updating of the census by individuals
associated with FC Barcelona is considered by the club to be an obligation, in accordance with the
information available on the website and the letters sent to members.

-The use of voice recognition is intended to facilitate telephone services

by preventing identity theft among members through authentication, at

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 86/139

in cases where the fraudulent use mentioned above also occurs,

as well as in the "seat transfer" service, but from active members to
third parties, and for a fee, considering that the system provides greater certainty and

security to the Club.

The relative weight of these uses by their fictitious owners is not quantified in

cases of deceased members or in cases by active members.

EIGHTH:

The legal and contractual relationship between FCB and VERIDAS for updating the census,
with whom it contracted the technical solutions for SBRF and SBRVoz, was formalized
through INDRA SOLUCIONES TECNOLOGICAS DE LA INFORMACION SLU
(INDRA), which, according to the attached service provision contract dated October 24, 2022, acted as the data processor for FCB in its capacity as the main provider
of the applications for updating the membership census

through electronic digital identification and the integration of the data into
***SERVICE.2 of the Social area (Clause One - Subject Matter, Section Four of API, 7, 12).

Clause Eight and Annex II relate to the protection of data that is
owned by FCB, and the provider is authorized to collect and use the data
within the framework of the provision of services. The aforementioned annex, "processing agreement,"

addresses the requirements of Article 28 et seq. of the GDPR, dated November 17, 2022, and indicates
that the processor may access, among other information, facial and voice biometric data. Section 4 states that "the processor must implement appropriate security and organizational measures to guarantee the protection of personal data held by the controller, as described in Article 32," and Addendum I contains the corresponding technical and organizational measures,

according to the type of data processed. It includes a table
with the measures described that the processor declares to have implemented.

Annex I also included "access to the VERIDAS digital onboarding service."

INDRA subcontracted on November 14, 2022, with SISTEMAS INFORMÁTICOS ABIERTOS, S.A.

(SIA), an “intragroup processing agreement” for the provision of services for

implementation of product licenses for digital identity verification.

In clause 6, Subcontracting, the subcontracting of the digital identity verification service for FCB members is expressly authorized
with VERIDAS Digital Authentication Solutions S.L. through the use of VERIDAS licenses, and
according to the scope of activities included in the offer sent to the client FCB, on behalf of
INDRA SOLUCIONES. The processing description indicates

“identification of FCB members with VERIDAS licenses for updating the member census, biometric data for identification purposes—image and voice—and of an
identifying nature,” in categories of data subjects and data types, with data stored
on proprietary servers within the EEA.

SIA has a contract for the use of facial comparison and voice authentication software with VERIDAS, dated March 4, 2021, with addenda dated June 30, 2021, and June 23, 2023. The provided agreement indicates that biometric data is processed for identification purposes—image and voice—and is of an identifying nature. Point 4 establishes, among VERIDAS's obligations, the use of the data it accesses for the purposes of the agreement and the processing of said data in accordance with the instructions received, including the obligation to provide a general description of the technical and organizational security measures relating to:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 87/139

the pseudonymization and encryption of personal data.


[The following appears to be a separate, unrelated section:]

- The pseudonymization and encryption of personal data. -The ability to guarantee the confidentiality, integrity,

ongoing availability, and resilience of processing systems and services.

-The ability to quickly restore the availability of and access to personal data in the event of a physical or technical incident.

-The process of regularly verifying, evaluating, and assessing the effectiveness of the technical and organizational measures to ensure the security of the processing.

NINTH:

The facial comparison software used by FCB in its SBRF for census updates is a technological solution from the supplier VERIDAS DIGITAL AUTHENTICACTION SOLUTIONS SL (VERIDAS). This solution, operated by VERIDAS, captures unique features and characteristics (whether from a photographic image, such as an ID card, or a selfie), generating an irreversible (it is not possible to reconstruct the original facial image), non-interoperable (it cannot be used in other systems), and uniquely characterizing the individual. The solution allows the entire identity verification process to be carried out remotely. Both the document image and the photo are first sent to the validation systems of the solution developed by VERIDAS. The facial capture (biometric characteristic), whether from the document or the photo, is processed by the biometric engine, which generates biometric vectors: one for the ID card photo and another for the selfie photo. The algorithm of the VERIDAS technical solution compares these biometric descriptors and, based on the threshold established by the solution, grants validation if it passes or fails.

The images (photographs) generated during the FCB member update process are stored in ***SERVICIO.5, linked to each member, along with the documents related to their contact and procedures.

Simultaneously, the images are saved as images in (…) ***SERVICE.2.

VERIDAS, once it processes the comparison of the facial biometric vectors
in its solution (comparison of vectors exceeding the established threshold, and

a favorable result), removes the photograph from the ID card (second fact 1, fourth fact 5,
ninth fact 17.1) and sends the information to FCB, leaving no trace in its systems.

Once FCB received these references from VERIDAS, FCB stated that
the biometric vectors remain on SIA's servers for seven days

(FOURTH fact, API 7) (NINTH fact 18) encrypted in case any

incident was detected in the biometric process.

In the event that the aforementioned threshold for updating the
census with the SBRF was not met, with a negative result according to what FCB stated in

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 88/139

(API, FOURTH fact 8), a message appears warning that the process cannot continue
and that in-person visits to FCB offices are required.

Once the facial comparison process is completed between, on the one hand, the facial biometric vector extracted through the software's biometric engine from the photo on the

identity document or passport, and on the other hand, the facial vector from the selfie photo,
VERIDAS automatically deletes the information from its systems. VERIDAS does not
retain either the user's personal data or the biometric vectors that
were created: once the contracted process is completed and the relevant information is sent to the Client, it automatically deletes all the information that was on its

servers (fact NINTH, evidence, 20). FCB states that
once the comparison is made, any biometric trait is eliminated, retaining
only the real-time photograph as an updated image of the member, and
it is not possible to recover the biometric traits used for the
facial comparison.

Regarding the preservation of the image captured from both sides of the National Identity Document (DNI), obtained
during the online digital process of updating associated individuals (in API, fact
FOURTH. 7), FCB indicated that it deletes the DNI when VERIDAS compares the vectors in its
solution. However, while it is not proven that it preserves said image, it is proven that it retains references contained in the same DNI in the logs of the

associated individuals who completed the process. This is demonstrated in the evidence presented, fact nine 7), which shows that for R1 and R3, the following DNI data is recorded:

- validity date, issue date, support number, CAN (six-digit number).

In evidence presented, fact nine 9-2, FCB stated that it has never before requested a copy
of the complete DNI from associated individuals, and that it requested the complete DNI in the process
because it was necessary to verify that it was an authentic document.

TENTH:
Regarding the SBRVoz process, which involves collecting the voices of members, FCB indicates that it is not used for updating the census, but rather to carry out certain procedures by telephone, such as purchasing tickets and season passes, and using the "free seat" option, in order to prevent impersonation of the member. It should be added that this voice recording process is also included within the data collection process for updating the census,
with FCB projecting its use for after the aforementioned update,
which, according to its arguments against the agreement, was ultimately not implemented and was eliminated. However, in API, fact 14, 20, on the date of the response

July 17, 2024, it was stated that the only digital profile FCB has of its members is voice, fact 14, and that it was suspending its use, “following the latest reports on biometrics published by the Spanish Data Protection Agency (AEPD), which radically changed its criteria, it was decided not to implement the process and to submit its legality and suitability to a study to determine whether or not we can use it” fact 20,

it being understood that as of this date, July 17, 2024, it had not yet been eliminated the voice vector of FC Barcelona, which implies that its processing continued at least until this date.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 89/139

In the data collection process, as FCB explains in API, fact four 3), the member records their voice, extracting biometric vectors that are stored in the member's personal file in the Club's management program. When the member, after this registration, contacts the Club by phone and identifies themselves, their voice is compared with the recorded voice. If their voice is registered, it will allow comparison with the stored voice traits and identification, enabling them to carry out certain procedures by phone.

FCB also points out that the biometric vector extracted from the voice is unique, irreversible, and
non-interoperable (it can only be used with the biometric engine of that solution) and that

it stores the collected data as a recording in the cloud via an access point. FCB
reported that VERIDAS does not store any data, since upon generating the vector, it returns it
to the client, who will be responsible for storing it on their servers. The vector is
stored in the associated person's record, which includes attributes such as phone number and
ID number. During a call, the voice is captured, and this capture is compared with
the existing biometric vector. The biometric vectors of the two

audio recordings are compared to determine if there is a match (Fact 4, API 19).

In point 2 of its allegations, fact 8, and in point 9 of evidence 2), FCB adds
in its information that it decided on “the deletion of all biometric data from the
voice.”

TWELFTH:

As of September 4, 2025, when FCB responded to the requested evidence, points 12 to 14, ninth fact, it states that:

A total of 124,872 members completed the census update process.

- 112,623 members chose to do so online, and of these, 72,648 agreed to have their voice recorded.

- 12,249 members updated their census in person, and 160 of these expressly agreed to have their voice recorded.

- The online census update system was also available for minors, as was the in-person system. It only indicates that the total number of members under the age of 18 is 14,511, without specifying how many minors used each method.

- 14,433 members did not update their information in the FCB membership census.

“-993 membership cards of deceased members were detected,” without FCB providing details as to whether these are among the 14,433 or how this figure was determined.

ELEVENTH:

In the response provided by FCB in section 16.1, it is stated that members who came to FCB headquarters in person to update their information in the membership census underwent identity verification without the use of facial recognition. An updated photograph was taken and used for the membership card, which was stored in the member's personal file in the Club's ***SERVICE.4 system (
***SERVICE.4 being a software system that involves a centralized database).

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 90/139

Furthermore, it indicates that, exceptionally, members residing abroad were offered the option of a telephone process, requesting that they submit their information and a photograph via email, with verification carried out by FCB staff.

Members could also grant consent for voice processing during in-person updates. Point 11 of the testing practices states, according to FCB, that 12,249 members updated their information in person, and of these, 160 gave consent for SBRVOZ.

Following the resumption of the process, on May 5, 2023, FCB reinforced the information regarding the SBRF census update process, adding further explanations to the FAQs on its website and mentioning that the procedure must be completed in person, as indicated in its response to API, point 4, 5. However, the informational text of the privacy policy was not modified.

THIRTEENTH: The image (photograph) of members, as stated by FCB in its response to the testing request, point NINE 1-2), is associated with the membership card, both in its physical and digital formats. This photo does not appear on season tickets. It should be noted that only members, as reported by FCB during the testing period, are eligible for season tickets. With the incorporation of the
photographs taken by members during the online
membership renewal process, as well as in person, FCB also stored them

in (…) considering them up-to-date. FCB stated in evidence that members may be required to present their membership card along with their ID card at the entrance to the Club's facilities to verify their identity, and that this photograph was required for both in-person and online membership registration.

FOURTEENTH:
According to the report obtained from the AXESOR tool, FC BARCELONA is an Association, within the activities of

sports clubs, specifically in the sports, recreational, and entertainment sector, and is classified as a "group parent company." On the other hand, on the FCB website, in the ANNUAL REPORTS, the latest 2023/2024 and in its "economic area" section (pp. 216-341) in the section on FCB and Dependent Companies, as of 06/30/2024, on page 237, the net amount of turnover for the 2023/2024 financial year is listed as ***AMOUNT.1.

FIFTEENTH:
In the transfer of the complaint, FCB was required to provide the Data Protection Impact Assessment (DPIA). In its response regarding the SBRF, FCB stated that it had assessed the risks and concluded that a DPIA was not necessary, as its processing did not present a probable high risk. It mentioned its risk analysis, without providing it,

and mentioned a report, which was not provided but only partially reproduced (fact 2, 4).

Following the initial agreement, in its allegations, it submitted fact 8, 4, and in its evidence, fact 9, 19, two reports (the first from the SBRF, the second from the SBRVoz) which

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 91/139

it claims contain the essential elements of Article 35 of the GDPR, even though they are not called DPIAs. In the aforementioned reports entitled: RISK ASSESSMENT AND PROPORTIONALITY REPORT FOR THE PROCESSING OF PERSONAL DATA

WITH BIOMETRIC SYSTEMS, dated November 22, 2022 (SBRF) and December 22, 2022 (SBRVoz)

(one for each biometric recognition system):
- The processing activities, their operations, the software used, and the

lifecycle of the processing are described.

- Regarding proportionality in biometric recognition systems, the focus is on the

online digital approach because the deaths of individuals are not reported to the Club, and other

problems with irregular practices related to membership and season ticket cards, not
exclusively concerning deceased individuals, which involve fraud in the sale and transfer of
season tickets and seat assignments.

The need to use the SBRF (Single Registry of Members) is linked to the statutory obligation and is
proportional to the necessity of fulfilling that obligation, considering that of the
143,000 members, almost 8,000 reside abroad and about 6,000 outside the Autonomous Community of Catalonia.

This allows all members to complete the process without having to
visit the headquarters in person. Therefore, a system is needed that allows updating
the membership list from different locations, something that can only be done without
the data being manipulated using a system of this type.

Regarding SBRVoz (Single Registry of Members Voice), it is based on the fact that no other non-biometric system is capable of
achieving the same objective: guaranteeing security and preventing fraud.

Regarding the effectiveness of both systems, a key factor is the high level of certainty in identity verification.


Regarding risk assessment, the following are mentioned: “security” (incident management), “data quality,” “access, rectification, erasure, and objection rights,” “international data transfers,” “legal basis for processing,” and “risks associated with data protection.”

It is concluded that, with respect to both systems, the identified risk is minimal and is offset by the implemented measures.

SIXTEENTH:
FCB provided a copy of the document entitled “Conclusions on the analysis of the
processing of biometric data in the member census update process”

carried out by FCB's Data Protection Officer (DPO) on November 9, 2022, prior to the alleged Data Protection Impact Assessments (DPIAs) of November 22 and December 22, 2022, regarding SBRF and SBRVoz, respectively, fact four, 18. In the
“Conclusions on…”, referring only to SBRF, it states that “From the conclusions of the
risk assessment report, the conclusions of which are copied here…”, knowing that the
only risk analyses are those contained in the aforementioned DPIAs of those two

dates, and that:

-no purposes that entail risks are carried out,

-Despite the use of new technologies, given their security, the
processing is not considered to entail risks for FCB members.

-The data controller does not perceive that the main processing activity involves a high risk; therefore, there is no need to carry out a Data Protection Impact Assessment (DPIA).

LEGAL BASIS
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 92/139

I. Jurisdiction
In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679

(General Data Protection Regulation, hereinafter GDPR), and as established in Articles 47, 48.1, 64.2 and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter LOPDGDD), the Presidency of the Spanish Data Protection Agency is competent to resolve this procedure.


Likewise, Article 63.2 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights) stipulates that: "The procedures
processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, by this Organic Law, by the implementing regulations issued thereunder and, insofar as they do not contradict them,

subsidiarily, by the general rules on administrative procedures."

II. Preliminary Issues
It must be noted that Recital 1 of the GDPR states that: “The protection of natural persons with regard to the processing of personal data is a fundamental right.” Article 8, paragraph 1, of the Charter of Fundamental Rights of the European Union (“the Charter”) and Article 16 [TFEU], paragraph 1,
[…] establish that everyone has the right to the protection of personal data concerning him or her.

According to Art. 4.1 GDPR defines “personal data” as: any information
relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name,

an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

The GDPR “lays down rules concerning the protection of natural persons with regard to the processing of personal data,” Article 1, and its purpose, according to Article 1.2, is: “to protect the fundamental rights and freedoms of natural persons and, in particular, their right to the protection of personal data.”

Finally, it is worth mentioning the sector-specific regulation applicable to the data of individuals
associated with FCB, which addresses the updating of the FCB membership census. This is the primary, though not the sole, subject of the three complaints received, which will be analyzed in

legal basis III.

The data affected by the processing activities that are the subject of the complaints relate
to those defined in Article 4.14 of the GDPR as: “biometric data”:

personal data obtained from specific technical processing relating to the
physical, physiological, or behavioral characteristics of a natural person, which allow

or confirm the unique identification of that person, such as facial images or
fingerprint data;”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 93/139

Thus, the provision establishes that, through specific technical processes,
starting from physical characteristics such as the face, or physiological characteristics such as the voice of a
natural person, that person can be identified among several, using these

biometric techniques that result in biometric data, which can confirm or allow something
that is unknown.

For its part, Article 4.2 of the GDPR defines processing as “any operation

or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording,
organization, structuring, storage, adaptation or alteration, retrieval,
consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.”

The legal definition of biometric data includes physical biometric characteristics (examples: fingerprints, facial features), physiological characteristics (e.g., voice), and even psychological or behavioral characteristics, such as keystroke analysis or a handwritten signature.

These characteristics are distinctive enough to identify a person. Once captured and transformed into biometric data through technical processes, they can be measured and compared. This recognition process is divided into several technical stages during which biometric data is generated. It's important to understand that biometric recognition is not intended to determine a person's identity, but rather to compare data sets generated by a biometric system to determine if they match.

The measurement is performed by comparing biometric data sets. This results in a statistical similarity score between different sets of biometric data, which are compared to establish the probability that they belong to the same individual.
... This comparison determines the percentage probability that the data originates from the same person.

While traditional authentication methods such as passwords

require a 100% match to allow the user to access, for example,
an account or application (deterministic methods), biometric methods are
called “probabilistic” because they are probabilistic technologies. In the use of
biometric systems, it is difficult to obtain 0% error results when comparing
the captured biometric references with the reference or stored data. This can result in

margins of error, measured by the false rejection rate (legitimate user is rejected) and the false acceptance rate (unauthorized user is accepted), as
explained in Opinion 3/2012, “.2 Definitions.”

If the probability of a match exceeds a certain threshold, the system considers

it is the same person and validates it; otherwise, it rejects it. At the same time, if a system is to be implemented, for example, for identification purposes
for law enforcement, it is advisable to implement biometric identifiers
characterized by low rejection rates.

In this case, the summary of the census update process would be that
members of FC Barcelona access the FC Barcelona website or app with their
password and key in a specific section to update the census. There, they find
data protection information with two checkboxes to select. Next,

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 94/139

they upload a scanned copy of both sides of their national identity card and then take a
selfie, in that order.

Then, in the same census update process, checking the second box: “I accept the recording, registration, and use of my voice as biometric data in accordance with the privacy policy I have accepted” led to more information about the second layer, which is reproduced in proven fact 3. Once the voice was captured, it led to a personal data update form that offered information about the person interacting with the system.

Personal data that is proven to have been collected and processed is referred to the
responsible for its implementation, under the definition provided in Article 4.7 of the

GDPR of the “controller” or “controller”: “the natural or legal person,
public authority, agency or other body which, alone or jointly with others, determines the
purposes and means of the processing of personal data,” a status that corresponds to FCB, as
it also acknowledges, regardless of whether it uses the figures of data processor and sub-processor for its functions of
processing data for SBRF and SBRVoz. This is defined in Article 4.8 of the GDPR: “processor or

processor: the natural or legal person, public authority, agency or other body
which processes personal data on behalf of the controller;”.

In light of the foregoing, in the present case and in accordance with the provisions of the aforementioned articles, there is evidence of two distinct types of biometric personal data processing carried out by FCB as the data controller, comprising various processing operations not limited exclusively to the collection and use of said data. These processing operations are specified in response to the three complaints filed regarding the update of the Club's membership census, which, according to FCB, they were obligated to perform under the Club's Statutes. Furthermore, the FCB Board of Directors, acting in the interest and on behalf of FCB, agreed, serving its own interests and decision, to carry out the update using a biometric facial recognition system (SBRF) or in person, with a warning of expulsion from membership if the data was not updated. Additionally, regarding the processing of

the voices of the same members (excluding minors), FCB is the
data controller for the provision of services as part of creating and
enhancing their digital profile with future service offers, as planned
after completing the membership census, for example, to facilitate ticket purchases and the use of
free seats, preventing the impersonation of members that has been occurring.

Biometric data is collected by FCB at the same time and using the
same tool on the FCB website or app through a biometric system of

facial recognition (SBRF), along with a second, separate processing method, of
biometric voice recognition data (SBRVOZ), in this case, as stated by
FCB, with the member's consent.

As a third type of data processed, there have also been
processing activities related to updating the membership census data,

specifically, an updated photograph, both for those who completed the
census update process online and those who visited
the Club offices in person. According to FCB, this photograph forms part of the
membership card that may be requested by its staff upon entry to its

sports facilities.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 95/139

It can be concluded that there are several biometric personal data processing operations carried out during the same act of updating the
membership census, using two different technical solutions under the same service provider,

VERIDAS, the sub-processor.

Furthermore, according to the initial response to the transfer, the data was processed for different purposes and legal bases, with only one common information clause regarding data collection.

The processing period must be considered in relation to the processing operations performed on the data, from March 20, 2023, to November 30, 2023, as the possible collection period. However, it is also understood that processing occurs while the data is retained, stored, or used, and even its deletion would constitute a processing operation. To this end, it should be noted that FCB monitored the process for members who had not yet updated their membership list, sending them reminders about their obligation and the adverse consequences of failing to do so.

The SBRF process demonstrates that FCB still maintains logs containing records of the process, including data from said update, such as the ID card, which was compared to the selfie.

In summary, FC Barcelona carries out this personal data processing activity in its

capacity as data controller, since it is the entity that determines the purposes and
means of such activity, pursuant to Article 4.7 of the GDPR.

III. Obligation to Update and Ensure the Accuracy of FC Barcelona Members' Data

The purpose of updating the FC Barcelona members' register is that
since 2012, the data controller has not conducted a unilateral campaign

to update members' data. The main reason for
conducting this update in 2023 is to clean up the register, as retaining membership cards
for deceased individuals can reduce available seats and lead to
fraudulent practices within the Club. This is part of the solution, since these
irregularities do not solely depend on the use of deceased members' cards. FCB reported

that this update was mandatory for members and stated
that there are two possible legal grounds for processing this data: the need for the
performance of the contract, as per Article 6.1.b) of the GDPR, or the grounds provided for in Article 6.1.c):

“processing is necessary for compliance with a legal obligation on the part of the
controller.”

To understand the processing activities carried out by FCB, it is important to
first determine, in general terms, what the obligation and principle of maintaining
accurate and up-to-date data entails.


The FCB Statutes stipulate:

“Article 12. Acquisition of Membership

The admission of new members to the Club is the prerogative of the Board of Directors, which may
establish at any time temporary limitations on the maximum number of
members, or general conditions for admission.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 96/139

Membership must be requested in person or electronically with a
digital signature or similar security element from the applicant, or from their
legal representatives if they are minors or incapacitated.

The admission of new members must be recorded in the register governed by
Article 61.1.”

Article 33.3 of the Statutes, as functions of the Secretary, establishes that of “being responsible for the register of members provided for in Article 61.1 and keeping

the data and entries that must be made up to date.”

Article 11 of the FCB Statutes establishes the obligation of members (11.8):

"to complete the procedures for updating the electoral register promoted by the Club, either by requiring the member's presence or by providing the required information."

Article 10 of the aforementioned Statutes stipulates that membership is personal and non-transferable. "Each member is only entitled to one season ticket" (access pass to sporting events) (Art. 10.4), and: "The transfer of the right to attend sporting events in the seats covered by the season tickets by season ticket holders is expressly prohibited, except when the transfer is made through or in favor of the Club itself" (Art. 10.4, end).

Article 10.9 of the Statutes considers the right to respect for the privacy and dignity of members, while Article 14, in section 1, indicates, among other things, that death is a cause for the loss of membership status, without establishing any time limit for the loss of membership status, as long as the member fulfills the obligations of their membership.

Regarding the loss of membership and the consequences of failing to update the membership register for members who do not do so, FCB considers applicable the provisions of Article 15 of the Statutes, which states:

“The loss of membership can only occur individually and for

the following reasons:

…

-by disciplinary decision agreed upon in cases of very serious infractions
related to membership conduct as provided for in Article 75…”

“The Club may terminate the membership of members who, after two formal requests and
three months having elapsed since the second, have not completed the required registration update procedures.”

In its response to the evidence, point 11, FCB reported that 14,433 members

did not update their membership census, thus losing their membership status, and that 993 membership cards belonging to deceased members were detected, without providing details of how this was done. In the last update in 2012, which did not use biometric data, they recovered 1,000 memberships.

Among the processing principles that data controllers must respect is Article 5 of the GDPR, which states:

“1. Personal data shall be:

(d) accurate and, where necessary, kept up to date; every reasonable step shall be taken to ensure that personal data which are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’);

The judgment in Case C-247/23 of the CJEU states:

“26 In this respect, it should be noted that, according to the case law of the Court of Justice, the accuracy and completeness of personal data must be assessed in light of the purposes for which they were collected (see, by analogy, the judgment of 20 December 2017, Nowak, C-434/16, EU:C:2017:994,
paragraph 53).

The enduring nature of the relationship and status of
the individuals associated with FCB must be taken into account. Furthermore, it should be noted that the obligation to
keep personal data updated and accurate rests primarily with the

data controller, who must ensure that the information is accurate and
up-to-date, as established by the GDPR's principle of proactive responsibility.

However, the associated individual also has the right and the responsibility to
inform the data controller of any changes to their
personal data, so that the controller can fulfill its obligation to rectify it. In the event of the death of a person associated with FC Barcelona,

unless the family members, if any, voluntarily report the death, updating the data would be complicated, and requesting their cooperation in doing so would be highly uncertain.

The data controller is responsible for taking measures to ensure the accuracy of the data and being able to demonstrate it, according to Article 5.2 of the GDPR.

This means that the controller must not only respond to requests from data subjects for rectification or correction of their data, but must also have processes in place to keep the data up to date.

The primary responsibility lies with the data controller, but it is a collaborative process. Individuals must provide their current data, and the controller must have mechanisms in place to ensure its accuracy and respond to requests for correction.


The primary obligation lies with the data controller. The processing of inaccurate personal data can have significant negative effects on the individual,

not to mention the allocation of resources that could be used by other members. Accurate data ensures a correct representation of the individual at all levels and in all contexts.

In this case, FC Barcelona's problems do not stem, for example, from

an inability to communicate with members or a lack of data to process and achieve the objectives of the membership relationship. Rather, they arise from
deaths that occur but are not reported, while the club continues to use membership cards or season tickets linked to membership status, or, alternatively, without releasing the

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 98/139

membership and season ticket status when a waiting list may exist.


This is part, but not all, of the fraudulent uses that occur with the limited number of seats at FCB's stadium in relation to the high demand. Other problems

of fraud are committed by active members who resell or transfer their seats,
and there may even be organized groups for this purpose, as seems to be revealed by the
fact presented by FCB in the evidence (...), encompassing a total of 1,446
members, which may suggest that the actions of
updating the membership census should be directed at specific individuals rather than at the entire

group.

To this end, FCB established a SBRF process using the National Identity Document (DNI), operating with the
result of the technical processing of the photo of the DNI (static image) compared
with the result of the technical processing performed on a selfie, to

determine if they exceeded the software's match threshold for a

unique identification of the associated person.

IV. Unfulfilled Obligation. Article 9 GDPR
Article 9 of the GDPR, concerning the processing of special categories of personal data, states that:

“1. The processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person’s sex life or sexual orientation, shall be prohibited.

2. Paragraph 1 shall not apply where one of the following grounds applies:

(a) the data subject has given explicit consent to the processing of such personal data for one or more of the specified purposes, except where Union or Member State law provides that the prohibition referred to in paragraph 1 cannot be overridden by the data subject;

(b) processing is necessary for the performance of a task for which the personal data are processed.” of obligations and the
exercise of specific rights of the controller or the
data subject in the field of labor law and social security and protection

insofar as authorized by Union law or a collective agreement pursuant to Member State law which provides for appropriate safeguards for the
fundamental rights and interests of the data subject;

c) the processing is necessary to protect the vital interests of the data subject or
of another natural person, where the data subject is physically
unable to give consent;

d) the processing is carried out, in the course of its legitimate activities and
with appropriate safeguards, by a foundation, association or other
non-profit body with political, philosophical, religious or

trade union purposes, provided that the processing relates exclusively to the members of that foundation, association or other non-profit

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 99/139

current or former data subjects of such bodies or persons who maintain
regular contact with them in relation to their purposes, provided that the personal data
are not disclosed outside of them without the consent of the

data subjects;

e) the processing relates to personal data which the data subject has manifestly made public;

f) the processing is necessary for the establishment, exercise or defense of legal claims or when courts are acting in the exercise of their judicial

function;

g) the processing is necessary for reasons of substantial public interest,
on the basis of Union or Member State law, which must

be proportionate to the objective pursued, respect the substance of the right to data protection and lay down appropriate and specific measures to safeguard the interests and fundamental rights of the data subject;

h) the processing is necessary for the purposes of preventive or occupational medicine,
assessment of the worker's fitness for work, medical diagnosis,
provision of health or social care assistance or treatment, or management of
health and social care systems and services, regarding the basis of

Union or Member State law or pursuant to a contract with
a healthcare professional and without prejudice to the conditions and safeguards
referred to in paragraph 3;

(i) the processing is necessary for reasons of public interest in the area of
public health, such as protection against serious cross-border threats
to health, or to ensure high standards of quality and safety of
healthcare and of medicinal products or medical devices, on the basis of
Union or Member State law which lays down

appropriate and specific measures to safeguard the rights and freedoms of the
data subject, in particular professional secrecy,

(j) the processing is necessary for archiving purposes in the public interest, for
scientific or historical research purposes or for statistical purposes, in accordance with
Article 89(1), on the basis of Union or Member State law, which must be proportionate to the objective pursued, respect in substance the right to data protection and lay down appropriate and
specific measures to safeguard the interests and fundamental rights of the

       interested.

3. The personal data referred to in paragraph 1 may be processed for the

purposes referred to in paragraph 2(h), where such processing is carried out by
a professional bound by professional secrecy, or under their
responsibility, in accordance with Union or Member State law or with rules established by competent national bodies,
or by any other person also bound by the obligation of

secrecy in accordance with Union or Member State law or

with rules established by competent national bodies.

4. Member States may maintain or introduce additional conditions, including limitations, regarding the processing of genetic, biometric, or health-related data.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 100/139

According to the information in the file and reflected in the background section, FCB does not consider the personal data processed (RF and voice) to constitute special categories of data during the period it carried out the processing. Therefore, it did not determine that any of the circumstances provided for in Article 9.2 of the GDPR existed that would lift the prohibition on the processing of RF and voice data, interpreting that it did not process special category data. As a second consequence, it argues in its two submissions that, because it does not belong to the same category, a Data Protection Impact Assessment (DPIA) is not required.

For this reason, it was agreed to initiate proceedings. The Spanish Data Protection Agency (AEPD) has issued a sanction against FC Barcelona for an infringement of Article 9 of the GDPR, despite the AEPD's initial findings.

FC Barcelona has submitted several arguments in this regard, pointing out that, while the Guide to Labor Relations published by the AEPD in May 2021 analyzed this issue, applying the criteria contained in Opinion 3/2012 of the Article 29 Working Party, it expressly stated that:

"However, the GDPR does not consider all processing of biometric data as processing of special categories of data, since Article 9.1 refers to 'biometric data for the purpose of uniquely identifying a natural person.' Therefore, a joint interpretation of both provisions leads to the conclusion that biometric data would only constitute a special category of data if it undergoes specific technical processing aimed at uniquely identifying a person." physical.(...)”,

The processing activities carried out by FCB were conceived and implemented before the EDPB issued its opinion on the matter, specifically in EDPB Guidelines 05/2022,
when it established its position regarding the new regulation contained in Article

9 of the GDPR. This position was adopted by this Agency on November 23, 2023, when the Guide on attendance control processing using biometric systems, to which FCB refers, was published. Therefore, and based on the above, it is appropriate to uphold its allegations regarding the culpability of the conduct.

V. On the need to carry out and pass a prior and appropriate data protection impact assessment (DPIA) for the processing

Article 35 GDPR - Data Protection Impact Assessment - states the following (emphasis added):

1. Where it is likely that a type of processing, in particular if it uses new technologies, by its nature, scope, context or purposes, entails a
high risk to the rights and freedoms of natural persons, the

controller shall, prior to processing, carry out an assessment of the
impact of the processing operations on the protection of personal data.

A single assessment may address a number of similar
processing operations that entail similar high risks.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 101/139

2. The controller shall seek the advice of the data protection officer, if one has been appointed, when carrying out the data protection impact assessment.


3. The data protection impact assessment referred to in paragraph 1 shall be required in particular in the case of:

a) systematic and extensive evaluation of personal aspects of natural persons

based on automated processing, such as profiling, and on the basis of which decisions are taken that produce legal effects concerning natural persons or significantly affect them in a similar manner;

(b) large-scale processing of the special categories of data referred to in Article 9(1) or of personal data relating to criminal convictions and offenses referred to in Article 10, or

(c) large-scale systematic monitoring of a publicly accessible area.

4. The supervisory authority shall establish and publish a list of the types of processing operations that require a data protection impact assessment in accordance with paragraph 1. The supervisory authority shall communicate these lists to the Committee referred to in Article 68.

5. The supervisory authority may also establish and publish a list of the types of processing that do not require data protection impact assessments. The supervisory authority shall communicate these lists to the Committee.

6. Before adopting the lists referred to in paragraphs 4 and 5, the competent supervisory authority shall apply the consistency mechanism provided for in Article 63 if those lists include processing activities that

related to the offer of goods or services to data subjects or to the observation
of their behavior in several Member States, or processing activities
that may substantially affect the free movement of personal data
within the Union.

7. The assessment shall include at least:

(a) a systematic description of the envisaged processing operations and
the purposes of the processing, including, where appropriate, the legitimate interest
pursued by the controller;

(b) an assessment of the necessity and proportionality of the processing operations

in relation to their purpose;

(c) an assessment of the risks to the rights and freedoms of the data subjects referred to in paragraph 1; and

(d) the measures envisaged to address the risks, including safeguards, security measures
and mechanisms to ensure the protection of personal data,

and demonstrate compliance with this Regulation, taking into account
the rights and legitimate interests of data subjects and other affected persons.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 102/139

8. Compliance with the approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be duly taken into account when assessing the impact of processing operations carried out by those controllers or processors, in particular for the purposes of a data protection impact assessment.

9. Where appropriate, the controller shall seek the views of data subjects or their representatives concerning the envisaged processing, without prejudice to the protection of public or commercial interests or the security of processing operations.

10. Where processing pursuant to Article 6(1)(c) or (e) is based on Union law or the law of the Member State to which the controller is subject, that law governs the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment. In the context of adopting this legal basis, paragraphs 1 to 7 shall not apply unless Member States consider it necessary to carry out such an assessment prior to processing activities.

11. Where necessary, the controller shall examine whether the processing is in accordance with the data protection impact assessment, at least where there is a change in the risk posed by the processing operations.

The GDPR requires controllers to implement appropriate measures to ensure and be able to demonstrate compliance with the regulation, taking into account, among other things, “the risks of varying likelihood and severity for the rights and freedoms of natural persons” (Article 24, paragraph 1).

The GDPR does not require a DPIA for every processing of personal data, but it does stipulate that it is mandatory when there is a high likelihood of a high risk. The existence of a

reasonable degree of presumption that the treatment may entail a high risk makes
conducting a DPIA essential.

The GDPR does not define DPIA, which is developed in the Guidelines on Data Protection Impact Assessments (DPIAs) and for determining whether processing is likely to result in a high risk for the purposes of Regulation (EU) 2016/679, adopted on 4 April 2017, last revised and adopted on 4 October 2017 (hereinafter WP 248), as:

“…a process designed to describe the processing, assess its necessity and proportionality, and help manage the risks to the rights and freedoms of natural persons arising from the processing of personal data by assessing them and determining measures to address them.”

The EDPB considers DPIA to be a process, and therefore:

- “DPIAs must be documented, but they are more than just the report that reflects their findings.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 103/139

-The DPIA must assess risks, determining the measures to address them. It obliges the controller to act and has a greater dimension than a mere formality embodied in a document; it is a process of analyzing a processing activity

that extends over time throughout the entire lifecycle of that processing.

The analysis of the obligation to carry out a DPIA is part of the risk assessment process
for rights and freedoms. The obligation of data controllers

to carry out a DPIA in certain circumstances must be understood within the context of their general obligation to adequately manage the risks arising from the processing of personal data. The high risk to the rights and freedoms of data subjects primarily concerns the rights to data protection and privacy, but can also involve other fundamental rights,

such as human dignity, especially when there is no objection to the processing, which should be differentiated in the proportionality and necessity analyses of these processing activities, as was the case here, where no such analysis was conducted with respect to children under 14 years of age.


Recital 90 of the GDPR establishes the obligation to carry out a data protection impact assessment before processing in order to assess the particular severity and likelihood of a high risk to the rights and freedoms of the data subject, taking into account the nature, scope, context, and purposes of the processing and the origins of the risk, including the type of processing operations that involve new technologies or are of a new kind, according to Recital 89. This assessment must set out the measures, safeguards, and mechanisms provided for mitigating the risk, ensuring the protection of personal data, and demonstrating compliance with the GDPR.

Recital 76 of the GDPR establishes general principles for determining the likelihood and severity of the risk to the rights and freedoms of the data subject, in accordance with the nature, scope, context, and purposes of the data processing. It specifies that the risk must be weighed on the basis of an objective assessment to determine whether the data processing operations pose a risk or whether the The risk is high.

Article 35(1) of the GDPR establishes, in general terms, the obligation
for data controllers to carry out a Data Protection Impact Assessment (DPIA)

before implementing such processing when it is
likely that, by its nature, scope, context, or purposes, it entails a high
risk to the rights and freedoms of natural persons. This high risk, according to the
Regulation itself, is increased when processing is carried out
using “new technologies.”

Given that biometrics is not just another information technology, but rather one that irrevocably changes the relationship between the body and identity,
in that it allows a machine to read the characteristics of the human body, which are then subject to subsequent use, it offers a distinctive character

almost absolute, meaning that each person possesses a unique biometric that almost never
changes throughout their life, giving permanence to these characteristics. It also has a dimension of universality because we all share the same elements Physical.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 104/139

Furthermore, as in this case, the biometric information obtained is linked from the outset to the individuals associated with the membership registry, along with other data such as the use of the ID card.

The technical processes to which the images of the ID card (photo of the ID card) and the face (with its selfie), or the voice, are subjected are all aimed at carrying out technical comparisons that imply the existence of biometric data that are compared: the selfie photo with the ID card photo, the voice with the registered template. Both processes are or include biometric recognition purposes. It must be understood that the photograph of the ID card is susceptible to being used to obtain biometric data, since it was subjected to technical processing, and this was not by chance, but rather that this processing was intended to uniquely identify an individual. person. If only

a selfie had been taken, and its template extracted, there would be no one to compare against to obtain the person's identity.

FCB decided in June 2022 that it would update the membership census.

To that end, and as stated in the eighth proven fact, dated October 24, 2022,
FCB entered into a service agreement with INDRA SOLUCIONES TECNOLOGÍAS DE LA INFORMACIÓN
S.L.U., the purpose of which was the

“Updating the membership census of the entity, through digital identification and the integration of the data into SERVICE 2 of the Social area.” The details

of all these SERVICES, as well as the specific conditions for their execution, are
established both in the body of this Contract and in the technical and
economic offer that the SUPPLIER may have submitted, which are attached as
Annex I, forming an integral part of this Contract and binding on the
parties for all purposes.” (emphasis added)

The data processing agreement is included as Annex II of the aforementioned contract, and was

signed on November 17, 2022.

In the aforementioned data processing agreement, and in relation to the
security measures, it includes generic provisions, referring to Addendum I, which
sets out, in just two pages, a series of measures related to the specific
processing, but very general, without describing what they consist of or how they should be
implemented.

FCB requested a preliminary analysis from its Data Protection Officer (DPO) on September 22, 2022, regarding the use of the Biometrics
in the process of updating the membership census, the conclusions of which are contained in the document “Conclusions on the Analysis of the Processing of Biometric Data in the Member Census Update Process” dated November 9, 2022.

This document, issued after the signing of the service agreement, presents the conclusions reached, without any additional supporting documentation or legal justification beyond the mere assertions made. It concludes that a Data Protection Impact Assessment (DPIA) is not necessary, detailing the reasons why a DPIA is not required (and not the reasons why it might be necessary) and that such processing is compliant with the GDPR.

Subsequently, on November 20, 2022, FCB issued the “Report on the Assessment of Risks and Proportionality of the Processing of Personal Data with a Facial Biometric System in the Census Update Process,” which identifies in its allegations the fact that

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 105/139

eighth 4, as a presumed material DPIA of the SBRF, again submitted as evidence, ninth fact, 20.

And on 22/12/2022, the “Risk and Proportionality Assessment Report
of the processing of personal data with a voice biometrics system” was issued, requested and

submitted as evidence by FCB, ninth fact 19, also categorized as a material DPIA, with the same structure and content as the previous one of 20/11/2022.

It should also be noted that neither in the responses to the transfer nor in the previous investigative actions had FCB stated that it had documents with the aforementioned content, presumably adapted to the formal content of DPIAs, despite being expressly requested

for the document; rather, it stated at all times that it was not It was necessary to conduct a Data Protection Impact Assessment (DPIA), and this was stated regarding the SBRF even in the aforementioned document dated November 9, 2022, from the Data Protection Officer (DPO) entitled “Conclusions on the analysis of the processing of biometric data in the member census update process,” with arguments such as:

- “The processing is not included in Articles 35.1 and 2 of the GDPR.”

- “Although biometric data is processed, it cannot be classified as a special category.”

- “Based on the three levels of analysis” (referred to in the response to the transfer, point 4).

Both reports were issued after the signing of the aforementioned service provision contract and data processing agreement.

FCB considered both in the document of conclusions on the analysis of the processing of biometric data in the member census update process. As of 9/11/2022, and in the reports of 20/11/2022 and 22/12/2022, FCB indicated that it was not necessary to conduct an EIPD for any of the referenced treatments.

On this point, it should be noted, firstly, that a Data Protection Impact Assessment (DPIA) was indeed required for both processing activities.

In this regard, we must refer to the lists of types of data processing

that require a data protection impact assessment (Article 35.4)
prepared by the Spanish Data Protection Agency (AEPD) and approved by the European Data Protection Board (EDPB).

This list is indicative and not restrictive, as the AEPD explains, since,
generally speaking, there is an obligation to carry out a DPIA
whenever the processing involves a high risk to the rights and freedoms of
natural persons. In this sense, the focus must be on the processing itself

examined as a whole, “particularly if it uses new technologies, due to its
nature, scope, context, or purposes,” and not on isolated elements of it, such as
simply whether we are dealing with special categories of personal data or
whether a processing activity involves authentication or identification of data subjects.

The list published for this purpose aims to guide data controllers so that they

are aware of and can identify when processing poses a high risk to the
rights and freedoms of natural persons.


C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 106/139

Thus, the list indicates, with regard to what is relevant to this procedure, that:

“When analyzing data processing, it will be necessary to carry out a
DPIA in most cases where said processing meets two
or more criteria from the list below, unless the processing is

included in the list of processing activities that do not require a DPIA referred to
in Article 35.5 of the GDPR. The more criteria the processing activity in question meets, the greater the risk it entails and the greater the
certainty of the need to carry out a DPIA.

This list is based on the criteria established by the Working Party on

Article 29 in guidance WP248 “Guidelines on data protection impact assessments (DPIAs) and to determine whether the processing
“is likely to have a high “risk” for the purposes of the GDPR,” complements them

and should be understood as a non-exhaustive list:

…

2. Processing that involves automated decision-making or that
significantly contributes to such decision-making, including any

type of decision that prevents a data subject from exercising a right or
accessing goods or services or entering into a contract. …

5. Processing that involves the use of biometric data for the purpose of
uniquely identifying a natural person.

…

7. Processing that involves the use of data on a large scale. To determine

whether processing can be considered on a large scale, the criteria established in the Article 29 Working Party’s WP243 “Guidelines on Data Protection Officers (DPOs)” will be considered.

…

9. Processing of data of vulnerable individuals or those at risk of social exclusion,
including data of children under 14 years of age and older individuals with some degree of of

disabled persons, persons with disabilities, persons accessing social services, and
victims of gender-based violence, as well as their descendants and persons
under their guardianship and custody.

10. Processing that involves the use of new technologies or an
innovative use of established technologies, including the use of technologies
on a new scale, with a new objective, or combined with others, in a way

that entails new forms of data collection and use with risk to
the rights and freedoms of individuals.

…”. (emphasis added)

Well, each and every one of these highlighted sections is present in the two
personal data processing activities now under review.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 107/139

We are dealing with processing activities that involve
automated decision-making. Thus, the processing of personal data for census updates,
based on facial recognition, occurs automatically without human intervention
through the application of algorithms that process a series of data,
providing a result (positive or negative). The decision is based

solely on the processing of the required data, without prejudice to the fact that, if the
decision is negative regarding the member's identification, the member has the possibility of an
in-person review. This positive or negative identification decision has direct
legal effects on the members, allowing the census to be updated if it is positive, and leaving it unupdated if it is
negative, to the point that, if such a subsequent review does not occur, the member may lose their status as indicated in the FCB statutes.

We can determine the same provision for the processing of voice data by members in relation to the provision of various services by the Club and the identification of members through their voice, since this processing also includes automated decisions when the member is identified by their voice for the provision of the service.

However, both risk analyses conclude that no decisions are made

with legal effects for members, nor that they have direct or indirect effects that could affect individuals.

On this point, the CJEU judgment of 7 December 2023, in case C-634/21, stated: “45 The broad scope of the concept of decision, confirmed in recital 71 of the GDPR, “according to which a decision involving the assessment of personal aspects relating to a data subject, to which that data subject has the right not to be subject, ‘may include a measure’ that either produces legal effects concerning him or ‘significantly affects him in a similar way.’ According to this recital, the term ‘decision’ includes, by way of example, the automatic rejection of an online loan application or online contracting services where there is no human intervention.”

“46 The concept of “decision”…can include various acts with the potential to affect
the data subject in multiple ways, as it is broad enough to encompass

the result of calculating a person’s creditworthiness in the form of a probability value
relative to their ability to meet their payment obligations in
the future,” and indicating that, when it comes to automated decisions, there are
specific risks that affect the rights and freedoms of data subjects, which
impose additional obligations and safeguards.

The FCB has not assessed whether the processing involved

automated individual decisions.

On the other hand, we are dealing with processing that, contrary to the FCB’s determination, involves the use of data on a large scale.

In this regard, the Guidelines on Data Protection Officers (adopted
on 13/12/2016, last revised and adopted on 5/04/2017) and the Guidelines WP
248, establishes various factors to determine it, including “the number of
interested parties affected, either as a specific figure or as a proportion of the

corresponding population; the volume of data or the variety of data elements that are

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 108/139

the subject of processing; the duration, or permanence, of the data processing activity; the geographical scope of the processing activity.”

Well, regarding FCB's assertion in its document of November 9, 2022, that “After
analyzing whether it should be considered large-scale processing, it has been concluded that,
based on the number of FCB members affected (currently 143,000),

in proportion to the corresponding population, as well as the volume of data processed,
the duration of the processing, and its geographical scope, it is not a large-scale data processing activity,” it must be pointed out that:

• The two personal data processing activities encompass all FCB members, that is, all 143,000, considered as a specific figure. While

this is by no means a negligible number of people, they do not explain

the impact of the number of data subjects as a proportion of what “corresponding population” (global, national, regional, or local) and how such a
provision affects the conclusion that It is not on a large scale.

• As FCB explicitly states, it has members all over the world, so the

geographic scope of the processing activity is also broad and is not
limited to the Autonomous Community of Catalonia, as asserted in the risk analyses of both processing activities.

• The volume of data processed is high, affecting various

personal data of the 143,000 members, in addition to the special sensitivity of
some of them, such as the National Identity Document (it processes all the personal data contained in
the National Identity Document, not just an image), voice, or biometric data.

• The processing of voice biometric data was intended to remain

indefinitely, without prejudice to the eventual revocation by the
data subject, in order to provide the services referred to by FCB to its members.

They also process data of minors, including children under 14, who
are recognized as having special protection status under the GDPR due to their
vulnerability.

They also carry out processing activities involving the use of new technologies,
with an innovative application within FCB, with a new objective and combining, under the guise of

updating the census, two processing activities that are combined,
increasing the risk.


FC Barcelona acknowledges this in its document of November 9, 2022, stating that “Regarding the technologies used, although biometric processing could be considered immature, the software used has been tested and determined to be completely secure. Furthermore,

Veridas Digital Authentication Solutions S.L., the software owner, hereinafter Veridas, holds the most recognized certifications, so we believe that its use poses no risk to FC Barcelona members.” (emphasis added).

Similarly, in the risk analyses presented for both data processing activities, the agency considers the technologies immature, although “completely secure,” and

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 109/139

confirms that there is no risk to its members arising from the processing. Regarding facial recognition, it also indicates that it is a particularly invasive technology.

And all this, besides the fact that, by definition, nothing is completely secure (especially the use of a probabilistic system), nor is it possible that the use of such technologies in the various processing operations involved, many of them technical, does not entail risks for FC Barcelona members.

For all the reasons explained, FC Barcelona should have carried out a Data Protection Impact Assessment (DPIA) for each of these personal data processing activities.

Secondly, regarding the review of FCB's risk analyses, it should be noted that:

Based on proactive responsibility and from the perspective of
privacy by design, any analysis of the
necessity and proportionality of personal data processing, as well as any
risk assessment (identification, evaluation, and assessment) of the rights and
freedoms of data subjects arising from the processing of personal data, and the

determination of all types of technical and organizational measures to prevent their
materialization, among other issues, must, by definition, take place before the
material commencement of personal data processing.

This must include, as it should, if the controller decides to
materially carry out the processing through a third party (data processor), the service provision agreement and the data processing agreement signed for that purpose. This is because it is neither possible, logical, nor in accordance with the GDPR to instruct the data processor on matters relating to the processing of personal data, or to establish processing conditions in the service agreement and the data processing agreement (such as the scope of the processing or the security measures), when such matters have not even been examined and the controller lacks the conclusions of such an examination and cannot determine whether the processing complies with the GDPR. Signing the service agreement and the data processing agreement before conducting risk analyses effectively invalidates any subsequent conclusions regarding the compliance of the processing with the GDPR.

Therefore, the risk analyses presented by FCB, which FCB argues are true Data Protection Impact Assessments (DPIAs) based on their content, serve neither as

risk analyses nor as DPIAs, and have no legal standing, since they were submitted after the signing
of the service provision and data processing agreements and can hardly
be incorporated into or considered in the signed contracts.

They appear to be merely a formal endorsement of a decision already made.

Data protection risk analyses are not a mere document, not a
mere formality. As established by Article 24 of the GDPR, they constitute true

substantive obligations to fulfill proactive responsibility and provide coverage
for the risk-based approach pillar of the GDPR. Without these analyses, including DPIAs,
being conducted beforehand, it is impossible to determine the risks, decide on the measures, and
even whether processing can be carried out.

In conclusion, the actions carried out by FC Barcelona in relation to the risk analyses

do not comply with the obligations established in the GDPR.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 110/139

To the above, we must add that these risk analyses suffer from significant
fundamental flaws that invalidate the analysis.

As we have indicated previously, the risk analyses are presented without any
documentary support regarding the conclusions obtained therein. The

risk analysis summary document must be accompanied by prior work
with supporting documentation, reflecting the proactive responsibility involved in complying
with the GDPR and demonstrating compliance.

We must also highlight some issues that reveal, among
others, the flaws in the risk analyses of both

processing activities.

On the one hand, the Data Protection Officer (DPO) himself recommends, regarding the processing related to the
census update, that “the digital census update process should be
voluntary, with members having the option to complete the process
in person.” This statement highlights the existence of other equally valid means for carrying out the census update. In fact, both

methods coexist, as stated in the “Risk Assessment and Proportionality Report for the Processing of Personal Data with a Facial Biometric System for the Census Update Process” dated November 20, 2022.

It is undeniable that in-person census updates are clearly less intrusive
for members, and that the majority of members reside in the city of
Barcelona, the metropolitan area, and, exceptionally, within the same Autonomous Community. The exception and

therefore the actual geographical dispersion linked to the difficulties of travel
to carry it out could be explained for a small proportion of the staff
associated, along with the convenience of not having to travel to perform it. These are
issues related to necessity and proportionality that were not considered in the
processing and are not justified.

However, the FCB is inconsistent in its statements, since it indicates in the

cited analysis that: “when evaluating the processing system for the
updating of members, the FCB has had to take into account a means that allows it to
authenticate the interested party with greater security and certainty, without the
physical presence of the members being necessary”... Existence of less
invasive means: As a fourth aspect to evaluate the suitability of the biometric system

analyzed, consideration has been given to whether there are less invasive means of
privacy that could achieve the same desired end. After analyzing the alternatives, it has been found that they cannot achieve the same goal.” (emphasis added).

Besides not examining what these alternatives are, the fact is that facial recognition is coexisting de facto with the in-person census update, which is less invasive. Furthermore, when facial recognition yields a negative result, the member is instructed to go to the FC Barcelona member services offices, despite the fact that in-person updates have been carried out for this purpose.

All of this demonstrates a clear inconsistency and a deficient examination of the necessity and proportionality of the data processing.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 111/139

It also states that “it is a system that cannot be deceived, so members cannot impersonate each other, unlike any other system.” It entails
risks of identity theft (whether through ID cards, codes, paper forms,

online forms...).” (emphasis added).

However, it does not foresee the possibility that, through the facial recognition system,
a manipulated ID card could be presented, with a photograph that corresponds to the person taking the photo
and not to its true holder. They do not mention this risk nor do they specify measures
to mitigate it.

Regarding the risk analysis related to voice authentication:

Likewise, this section also indicates that “Need: With respect to

voice authentication, there is currently no non-biometric system capable of
achieving the same objective: guaranteeing security in remote procedures by
preventing fraud or identity theft. … Effectiveness: …it is a system that cannot be deceived, so members cannot impersonate each other. Any other system carries risks of impersonation (whether through

cards, codes, paper forms, online forms, etc.). In short, there is currently no non-biometric system that can achieve the same objective with an equivalent level of security and without compromising the protection of keys or passwords. The purpose of this processing is to implement an effective mechanism for authentication and prevention of fraud or identity theft in procedures carried out remotely, through voice recognition of the member. Therefore, any non-biometric alternative would not achieve this purpose in an equivalent manner. Existence of less invasive means: As a fourth aspect to evaluate the suitability of the analyzed biometric system, consideration was given to whether there are less invasive means of privacy that could achieve the same desired goal. After analyzing the alternatives, it has been found that they cannot

achieve the same goal. All the alternative systems analyzed lack
defense mechanisms against impersonation (it is very easy to impersonate another person if you have their codes, ID number, membership number, etc.)” (emphasis added).

However, as previously stated, it is a probabilistic system, not
free from errors. Therefore, we must emphasize that, given that member identification is achieved through an automated decision (comparing the member's voice

with the stored biometric data), if the automatic result were, for whatever reason
to be negative, it should at least be subject to the possibility, among others,
of human intervention. It is not foreseen what happens in that scenario
and whether it is necessary to request other data from members in order to identify them and
provide the service.

Furthermore, given that this system is voluntary for members, coexisting
with other systems for purchasing tickets or season passes, it is entirely incongruous to state
that "any non-biometric alternative would not achieve this purpose
in an equivalent manner."

Moreover, it is not specified which other non-biometric systems
are being compared with. It must be demonstrated that alternative treatments have been considered and

evaluated which, using less intrusive means,
achieve at least the same effectiveness. The reports argue that there is no

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 112/139

non-biometric system that achieves the same level of security, but a DPIA
should formally detail this comparative analysis.

Regarding both risk analyses, the data lifecycle described in
those analyses is so generic that it could apply to any processing activity. In fact, the

lifecycle contained in both analyses is practically identical. For example, in
the SBRF, it appears in “lifecycle in processing activities,” “processing:
Updating member data,” or in “classification/storage:
updating the member's record with the data provided.” In this case, an online application is involved in the data collection, through two sub-processors.

Biometric data passes through these sub-processors, with the facial vector being stored on SIA's servers for seven days.

It is vital to describe the data lifecycle in detail, specifying exactly what happens to the data, for how long, who has access to it, through what means, whether it can be modified, deleted, etc., what types of processes it undergoes within the framework of which processing operations, etc., in order to

determine in detail, within the data lifecycle, what the risks are to the rights and freedoms of the specific data subjects at each processing operation, at each stage, and with what impact and probability.

For example, there may be a risk of confidentiality loss in the processing of personal data, but this risk is not identical at all stages of the processing. It can vary in terms of its impact on the personal data, the likelihood of its occurrence, and its overall impact. This will determine its specific categorization and the appropriate technical and organizational measures for each risk.

This means that without such a detailed description, it will be difficult to determine all the risks, their probability and impact, the level of risk associated with the processing, and the adoption and implementation of appropriate technical and organizational measures.

Thus, risk analyses examine the risks associated with the protection of information.

For example, and so on for the rest, regarding the integrity of personal data, both processing activities mention, identically, that there is a risk of

"unintentional modification or alteration of personal data," with a probability of

1 and an impact of 2, concluding that there is "little risk" and indicating a series of
control measures. The interpretation of the probability and impact thresholds for the
risks used in both risk analyses lacks explanation,
despite the fact that the GDPR establishes that the use of new technologies and biometrics,
even for verification purposes, are factors that increase risk. For example, the risk of unintentional modification or alteration of personal data

has a Probability of 1 (Negligible) and an Impact of 2 (Limited). The risk of
inability to detect and/or manage incidents is Low Risk (P=2, I=2).

According to the Spanish Data Protection Agency (AEPD) Guide, the complexity of the risk management process should be adjusted to the potential impact of the activity, and intrinsic risk should be considered before implementing mitigation measures. Assigning such low risks to a process that aims for maximum security (preventing fraud) seems like an optimistic assessment that could underestimate the actual risk before controls are implemented (inherent risk).

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 113/139


underestimate the actual risk before controls are implemented.

However, (i) it is not explained where this risk is present in the data lifecycle,
(ii) at each stage of processing, with what probability of impact, (iii) where they

obtained the figures for probability 1 and impact 2 and what that implies, (iv) what the
actual impact is, on which rights and freedoms of data subjects, how a
materialization of the integrity risk affects them, (v) they determine “little risk” without knowing if it is the
inherent risk of the processing or the residual risk after applying the measures, (vi) we do not know how
the measures are applied and implemented and how they reduce the risk, and whether they reduce its

probability, its impact, or both, and how.

It is curious that they do not foresee the very real risk of unintentional modification or alteration of personal data
clearly present in the processing, which can impact
the rights and freedoms of data subjects.

In addition to the fact that there is never zero risk to the rights and freedoms of data subjects, as the FCB asserts, the aforementioned analyses fail to identify the

inherent risk of the processing and the residual risk once the appropriate measures have been applied.

Furthermore, 19 types of existing risks are mentioned, but the risk analyses do not examine all of them, as can be seen. Similarly, although the reports conclude that the residual risk is minimal, in a DPIA, this analysis must be more granular and explicit, leading to a determination of the final

feasibility of the processing. It also lacks an analysis of the interaction of the different risk factors with each other—the cumulative risk factor.

The alleged DPIAs also fail to:

- indicate that the opinions of FCB members or their representatives were sought, an explicit requirement in the content of the DPIA. In the documents

related to the treatments, there is no record or mention that such an opinion was obtained, which is even more relevant given that they are also owners of the Club, as stated by the Club. The objective would be to make stakeholders aware that the treatment is high-risk, detailing the factors that attest to this and the potential impacts, while also indicating alternatives to achieve the same objectives in a less intrusive way for their collective interests.

- An action and follow-up plan is not defined. The position of the signatory is not listed.


In conclusion, on the one hand, FCB should have carried out two DPIAs on the
processing activities, and on the other hand, the referenced risk analyses are invalid and
do not comply with the GDPR because they were carried out after

FCB signed the service provision and data processing agreements and because they suffer from serious flaws in their design and execution that
prevent them from complying with the provisions of the GDPR. Furthermore, these risk analyses
cannot be considered, as FCB claims, as DPIAs for the same
reasons, since for a DPIA to be valid and comply with the GDPR, it is not enough for it to be
formally carried out; it must be substantively and successfully completed. In short, the content

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 114/139

material that FCB referred to as two DPIAs lacks essential elements to be considered as such.

VI. Response to the allegations

Regarding the allegations made by FCB to the initial agreement, concerning the fact that it processes biometric authentication data, which does not constitute its classification as a special category of personal data, and that there is a cause that would lift such prohibition since the consent of the members has been given, in relation to Article 9 of the GDPR, its response is pointless since it is proposed to archive the matter for these purposes in accordance with the provisions of the preceding legal grounds. Consequently, there is no second ruling on the conformity and lawfulness of the aforementioned consent.

Regarding the responses to the allegations made by FCB against the
proposed resolution, it must begin by indicating, in relation to the filing of

Article 9 of the GDPR, that it refers to the two processing activities, SBRF and SBRVoz, during the
period in which they took place, specifying the circumstances that existed
reflected in legal basis IV, and concluding with the assumption of the lack of
culpability of FCB for the reasons stated.

Turning into the specifics of the objections raised against the infringement alleged under Article 35

regarding the processing of said data, which was carried out during that period and
as detailed in the eleventh fact, the following should be noted:

FIRST-1

It must be clarified that not only the processing of personal data of special categories, including biometric data contained in Article 9.1 of the GDPR, would be subject to the obligation of a data protection impact assessment, due to

posing a likely high risk to the rights and freedoms of data subjects.

The fact that they might not fall into that category would not in itself imply that
the risk assessment for the rights, freedoms, and interests of individuals cannot be considered a likely high risk.


As previously stated, what triggers a Data Protection Impact Assessment (DPIA) is

that a data controller is faced with a type of processing that
is likely (probability is sufficient; it is not even necessary for the high risk to be
confirmed) to pose a high risk to the rights and freedoms of natural persons. This may be due to various elements inherent to the processing, such as
the technologies used, the nature, scope, context, and purposes of the processing, which

must be analyzed in the specific case. Evidence of this is that the list of
types of data processing requiring a data protection impact assessment (Article 35.4) drawn up by the Spanish Data Protection Agency (AEPD) and approved by the European Data Protection Board (EDPB) does not
include closed scenarios or fixed cases.

Therefore, it cannot be argued, as FCB attempts, that a Data Protection Impact Assessment (DPIA) should not be carried out simply because we are not dealing with special categories of personal data, without examining the processing as a whole, from the perspective of the risks to the rights and freedoms of natural persons, as mandated by the GDPR.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 115/139

GDPR

Regarding the tool used by FCB for risk assessment, it refers to the "Practical Guide to Risk Analysis in the Processing of Personal Data Subject to the GDPR," published on February 28, 2018. It should be noted that this Guide was superseded on June 29, 2021, with the publication on the website of the Guide to "Risk Management and Impact Assessment in the Processing of Personal Data" (hereinafter, GGR).


C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 115/139

The introduction states that it is “a guide for risk management

for the rights and freedoms of data subjects, applicable to any
processing, regardless of its risk level. Furthermore, for cases of
high-risk processing, it incorporates the necessary guidance for carrying out a
Data Protection Impact Assessment (DPIA).”

This June 2021 Risk Management Guide is more comprehensive and detailed than the 2018 version. While
it does not mandate any specific model for risk assessment, it is
considered a guide to ensure a minimum level of quality in its analysis.

In Section 1, III, under “Identification of Risk Factors,” the “Basic Methodology
for the Application of Risk Management for Rights and Freedoms” describes,

in section VI, the “identification and analysis of risk factors,” which is the step
prior to assessing the level of risk of the processing. As a principle, it points out that it is in the GDPR, the LOPDGDD, special regulations, guides, and directives approved by the data protection authorities where a set of risk factors are identified, constituting a minimum list.

The documents of Working Party 29 (WP29) issued up to the date of the FCB biometric data collection process, from March to November 2023, and since the 2003 Working Party 29 "Working Document on Biometrics," adopted on August 1, 2003, indicate that the risks to the protection of fundamental rights and freedoms must be taken into account, and contain various examples of risks associated with the different processing operations that characterize them.

A similar emphasis on various risks is found in Opinion 3/2012 on the evolution of biometric technologies, and is also highlighted in Guidelines 3/2019 on the processing of personal data using video devices, adopted on January 29, 2020.

Risk assessment involves the form and extent of compliance with processing regulations that every data controller must carry out in order to determine which measures to apply and how to do so. Part of FC Barcelona's arguments focus on asserting that they consider the system to have been secure (and therefore not posing any risk to members). However, the processing of personal data is not only affected by the security of the personal data itself, but can also affect the rights, freedoms, and interests of natural persons, even if there has not been a deficiency strictly related to security. And that—the rights and freedoms of natural persons—is what the GDPR protects.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 116/139

The likely high risk in the treatments analyzed in this procedure, and the
compliance with criteria established as such, for guidance purposes in WP 248, are
what is being discussed in this procedure, therefore the allegation must be

dismissed.


FIRST-2

Regarding FCB's assertion that, for the purposes of interpreting the GDPR, biometric authentication in remote facial recognition systems is considered low-risk, as a consequence of the provisions of the aforementioned ANNEX of Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024, laying down harmonised rules in the field of artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No
168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives
2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Regulation, hereinafter referred to as the RIA), it should be noted that:

- The RIA does not apply to the case under examination, not even

comparatively, considering only the provisions of Article 2
thereof regarding the scope of application of said Regulation, as well as

its objective scope, and furthermore, in this case examined in the present
disciplinary proceedings, FCB has not used artificial intelligence.

Furthermore, it is also inapplicable since, in accordance with the provisions of Article 113 thereof, both its entry into force (August 1, 2024) and its application (from February 2, 2025, August 2, 2025, August 2, 2026, and August 2, 2027) are clearly subsequent to the completion of the FCB census update procedure (November 30, 2023), as established in the proven facts.

At this point, it must be noted that FCB, in defense of its interests, is citing regulations, guidelines, and recommendations that were in effect prior to the processing of personal data, and at the same time, subsequent regulations, such as the RIA, which are neither objectively nor subjectively applicable and were not even in force or applicable when the processing was carried out. This technique of gleaning regulations cannot be considered
when assessing their claims.

- Notwithstanding the foregoing, and for the sake of clarity, recital 6 of the RIA

provides: “The concept of a ‘remote biometric identification system’ referred to
in this Regulation should be functionally defined
as an AI system designed to identify natural persons without
their active participation, generally remotely, by comparing their biometric data
with data contained in a reference database,

regardless of the specific technology, processes, or types of biometric data
used.”

As we have indicated, it has not been demonstrated that the tools used
through the sub-processor VERIDAS to process the biometric data for
updating the census used artificial intelligence in their technology.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 117/139

If used, it would further reinforce the need to

conduct a Data Protection Impact Assessment (DPIA), as it would affect the processing

processing carried out by FCB as an additional risk due to its novel nature.

The fact that AI systems are not used does not mean that there cannot be a
high-probability risk in this type of processing, which, as can be seen, is not
solely due to the presence of biometric data.

-It is based on the assumptions that its use is permitted by EU law or the law of the Member States, which would refer to the requirements for its
processing set out in the GDPR and the LOPDGDD, as well as the
opinions and guidelines.

In this case, remote data collection does not occur in

either of the two treatments, but rather once logged into the FCB website
using their username and password. The definition of real-time remote biometric identification referred to in the RIA is not the one analyzed
in the census update with SBRF.

For all the reasons stated above, the legal reasoning and the allegation made by FCB must be

dismissed.

FIRST.3-A

Regarding the allegations that we are not dealing with “2…
automated decisions…”, it should be noted that, according to Article 22 of the GDPR,
individuals have the right not to be subject to decisions based solely on automated processing (including profiling) if such processing has legal

effects or a significant effect, unless:

-It is necessary for the performance of a contract between the data subject and the controller.

-It is authorized by Union or Member State law.

-The data subject has given explicit consent.

In cases where an automated individual decision is made within the framework of the conclusion or execution of a contract or with the consent of the data subject, the latter will enjoy a series of guarantees and will always, at a minimum, have the right to obtain human intervention from the controller, to express their point of view, and to challenge the decision.

In fact, the adoption of automated individual decisions is one thing, and subsequent human intervention (precisely because the system has decided automatically) is another. This intervention is a guarantee that the data subject must have as a minimum.

The existence of subsequent human intervention does not invalidate the prior automated individual decision (especially given the broad concept of decision established by the CJEU).

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 118/139

These automated individual decisions can only use special categories of data if there is explicit consent from the data subject or if the processing is necessary to protect the vital interests of the data subject or another person.

It is not disputed whether the system automatically excludes or blocks the member from updating the census, even though there is an option to continue the census process (guarantee of human intervention). Rather, it is evident that automated individual decisions are being made.

Thus, as already indicated, the processing of personal data for updating the census, based on facial recognition, occurs automatically without human intervention through the application of algorithms that process a series of data points, providing a result (positive or negative).

The decision is based solely on the processing of the required data, without prejudice to the possibility of an in-person review should the decision be negative regarding the member's identification.

This is not only due to the template comparison resulting from the technical configuration that must be implemented in the systems for vector comparison, considering potential false rejections and false acceptances, but also because the SBRF verification result does not automatically detect the lack of a match and prompt direct action by FCB. Instead, the member must report it to FCB, in which case a review will be initiated using other methods deemed appropriate by the entity (by telephone or email).

Therefore, the fact that subsequent human intervention is required in the event of a negative result, in order to complete the processes and avoid negative consequences, does not mean that these are not automated individual decisions that produce legal effects or significantly affect the interested party in a similar way. As already noted, this
positive or negative identification decision has direct legal effects on
the members, allowing, if positive, the census to be updated, and if negative, leaving it unupdated, to the point that, if such a subsequent review does not occur at the request of the
member, the member may lose their status, as indicated in the FCB

statistics.

Similarly, according to SBRVoz, there is no record that, as a result of the lack of
matching, any mechanism was implemented directly and at that

time to resolve the potential discrepancy, and

there is no record of whether a specific protocol existed outlining the measures that FCB would take.

Therefore, the allegation made must be dismissed.

FIRST.3-B

Regarding the allegations made by FCB that we are not subject to the mandatory Data Protection Impact Assessment (DPIA) for: “5. processing involving the use of biometric data for the purpose of uniquely identifying a natural person,”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 119/139

it must be noted that, despite the dismissal of the infringement of Article 9 of the GDPR, there is a difference in relation to the reference to “a high probability of risk” among the many and varied risks mentioned in Recital 75 of the GDPR, which would apply in this case, as argued, among other circumstances; and this is because, in this case, it must be considered that combined data is processed in the procedures carried out in both the SBRF and the SBRVoz.

In the first processing activity, the SBRF, along with the official and public identification document (national identity card or passport, in the case of non-nationals), is governed as personal data by Article 87 of the GDPR as a specific situation for its processing, referred to as "national identification numbers," and has, for all purposes, the value of proving the identity and personal data of its holder as recorded therein.


It should be noted that the biometric comparison is based on the valid National Identity Document (DNI), first obtaining the vector from the scanned DNI and then the selfie photo, extracting its vector, and comparing it with the vector from the DNI. Therefore, despite FCB understanding that this authentication lacks special status at the time, the comparison is made with a unique identity data point, and the templates being compared are based on the technical extraction of the face in both cases (template or vector). This implies risks inherent to this set of sensitive data, given that, as mentioned, biometric data without adjectives is data inherent to the person because it refers to their biological characteristics.

On the other hand, in the processing of SBRVoz, the person is linked to their own voice. The identifying vector is saved and stored by FCB in the cloud through the associated person's record, which also contains other personal data: telephone number, national identity document number.

The Voice Data Protection Impact Assessment (DPIA) states that, regarding the nature of the processing, different data sets are not combined. However, the data associated with the member's record is combined and used or added. In both cases, the processing is carried out entirely by a sub-processor, VERIDAS, which in turn processes another sub-processor, SIA.

Therefore, given that the processing was indeed carried out to uniquely identify a person using biometric data, even if through authentication rather than identification, the claim must be dismissed.

FIRST.3-C

Regarding FCB's claim that we are not dealing with
“7. large-scale data…”, it must be reiterated that the purpose of the data processing, specifically the census update, is for all members to complete it.

Intrinsically, those residing outside the city of Barcelona will be more likely to complete the process digitally, although this does not preclude residents of Barcelona from also using the system. However, ultimately, the established processing "aims to process a considerable amount of personal data," not only locally: 54,337 members have a residence in the city of Barcelona, but also regionally: 24,379 in the metropolitan area, and 49,527 in the rest of Catalonia, within the Autonomous Community of Catalonia, also in Spain: 7,143, and in the rest of the world: 7,700. The potential target population is the total number of members, although a smaller number may have chosen other methods.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 120/139

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 120/139 Similarly, in the SBRVoz.

The detail provided is consistent with the criteria indicated in WP 248.

The Article 29 Working Party recommends that the following factors be taken into account, in particular, when determining whether the processing is carried out on a large scale:

a. the number of data subjects affected, either as a specific figure or as a proportion of the corresponding population;

b. the volume of data or the variety of different data elements being processed;

c. the duration, or permanence, of the data processing activity;

d. the geographical scope of the processing activity.

The counter-argument comparing the number of members in Spain with the population in Spain and the number of members outside our country in relation to the world population does not diminish the fact that we are dealing with large-scale processing when it includes all the members of the entity, as a specific figure, in the terms established by Article 29 Working Party.

As indicated in previous sections, the factors present in this

case warrant its being considered large-scale, and the
allegation made must be dismissed.


FIRST.3-D

Regarding the claim concerning the processing of biometric facial recognition data
of children under 14 years of age, as included in point 9 of the list of data subject activity under Article 35.4 of the GDPR, which was approved by the EDPB at the request of the Spanish Data Protection Agency (AEPD), it should be noted that the claim is made by the legal guardian or the

person or persons holding parental authority, and FCB acknowledges that the case exists.

It should be added that the fact that the processing of data of children under 14 years of age is carried out through their guardians or those holding parental authority, due to their lack of capacity regarding their personal data, does not preclude the processing of data of children under 14 years of age. Therefore, one of the elements

listed by the Spanish Data Protection Agency (AEPD) is met, classifying these minors as vulnerable subjects,
regardless of the data processed or the type of processing, as long as
they are under 14 years of age.


FIRST.3-E

Regarding the allegation that we are dealing with “10.data processing that
involves the use of new technologies…”, and with respect to the SBRF, FCB acknowledges
in its document of 9/11/2022 that “As for the technologies used, although

biometric processing could be classified within the definition of
technologies considered immature, the software used has been tested and it has been

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 121/139

determined to be completely secure. Furthermore, Veridas Digital Authentication
Solutions S.L., the software owner, hereinafter Veridas, has the most
recognized certifications, so we consider that its use does not entail any risks

for FCB members.” (emphasis added).

It should be noted that the SBRVoz Data Protection Impact Assessment (DPIA) is included in response to the question: “Is the use of technologies that may be perceived as immature, recently created or launched on the market, whose scope cannot be clearly or reasonably foreseen by the data subject and which implies a high risk of unauthorized access, foreseen?

(combination of new technologies, use of smart devices) - YES.”

Similarly, in the risk analyses presented for both processing activities, the DPO considers the technologies immature, although they are “completely safe,” and confirms that there is no risk to its members arising from the processing. Regarding facial recognition, it also indicates that it is a particularly invasive technology.

We must remember, in this regard, that two processing activities were combined in the same process of updating the FCB member census.

The DPO also refers to technologies considered immature in the DPO report of

November 9, 2022. Furthermore, in its objections to the agreement, point eight, four,
FCB refers to the fact that, based on the list in Article 35.4 of the GDPR, this criterion could be applicable to it.


Regarding the claim that biometric data is sufficiently

regulated and consolidated at a technical and legal level, being a mature technology, or
that its processing does not involve new forms of data collection or use that pose a risk
to the rights and freedoms of individuals, it should be noted that since the
specific consideration of personal biometric data in the GDPR, and those
considered as special cases, no
jurisprudential assessment has yet been issued on legitimacy, principles, or differentiation between

biometric functions. However, the inherent risk of biometric data, based on data that forms part of the physical identity of
individuals by which they can be recognized, and which is permanent data not
susceptible to change over time, has been publicly addressed in all guidelines,
opinions, and reports, from Working Party 29 and the European Data Protection Supervisor to the current EDPB.

This risk stems from data that forms part of the physical identity of
individuals, data that can be recognized, and which is permanent and not
susceptible to change over time.

FCB did not consider any aspect of these guidelines and opinions published prior to the aforementioned processing activities when deciding whether or not to carry out a Data Protection Impact Assessment (DPIA) as high-risk processing activities, focusing primarily on the criteria that, in its opinion, were not met.

In any case, Article 35 of the GDPR stipulates that, when assessing whether processing entails a high risk to the rights and freedoms of natural persons, "in particular if it uses new technologies" must be taken into account, indicating further factors that demonstrate that the processing must be examined as a whole; however, this does not mean that consideration should not be given to the use of technologies that are not new or technologies being used for the first time by a controller (as is the case here).

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 122/139

novel or technologies being used for the first time by a controller (as is the case here).

Therefore, this allegation must be dismissed.

SECOND

It should be noted that risk management measures for the processing of the rights and freedoms of natural persons have two objectives. The first is to optimize efforts to identify, assess, and evaluate risks, to mitigate and manage them proportionately, preventing them from resulting in harm to the rights and freedoms of natural persons; and the second is to determine whether the level of risk requires compliance with the provisions of Articles 35 and 36 of the GDPR (cases of probable high risk to the rights and freedoms of natural persons arising from the processing of personal data).

Regarding the chronology of the commissioning agreement, first sub-commission, and second sub-commission, it should be noted that the service provision contract

between FCB and INDRA is dated October 24, 2022, to which is added the data processing commission
of November 17, 2022, and the sub-commission between INDRA and SIA, dated November 14, 2022, while SIA
had a contract for the use of VERIDAS software dated March 4, 2021, with annexes
dated June 30, 2021, as reflected in the eighth proven fact.

However, the date on the risk assessment report for the SBRF is later, specifically November 22, 2022, and December 22, 2022, for the SBRVoz. This means that the potential results obtained and the measures to mitigate the risks, if any, could not be included in the previously signed engagement and sub-engagement agreements.

FCB adds that the agreements were signed after the analysis had already begun, taking into account the DPO reports. It further states that this did not preclude the review and updating of the measures as needed, incorporating the necessary elements such as addenda or annexes, if applicable.

Therefore, the risk analyses should have been completed before the corresponding engagement and sub-engagement agreements were signed.

This is because a risk analysis can determine that the residual risk of a

processing, once all technical and organizational measures have been implemented,
is unacceptable and makes it impossible to complete the processing.

And this cannot be known until a risk analysis has been completed.

It is not a matter of adding or introducing other elements later, as

the FCB argues, since this would also violate the privacy by design
imposed by the GDPR, which prohibits data protection from being an added layer
to a product or system, as stated in the AEPD's Privacy by Design Guide.


C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 123/139

Regarding the role of the Data Protection Officer (DPO) in the risk assessment and therefore in the
Data Protection Impact Assessment (DPIA) material provided, it is noted that the document of 22/09/2022: “Preliminary Analysis on the Use of Biometrics in the Member Census Update Process” and its conclusions of 9/11/2022, only refers to the
processing of the SBRF in the census update; no mention is made of
the DPO's role in the processing of the SBRVoz.


Based on the dates of these reports, it is clear that on November 9, 2022, FCB already had a risk analysis for updating the census, which reached the aforementioned conclusions regarding the processing of data with SBRF. This conclusion was based on risk analyses dating from a later date, and FCB, in addition to assessing their sufficiency, intends to validate them as a Data Protection Impact Assessment (DPIA), despite concluding that such a data processing guarantee instrument was not required. The DPO's action of reproducing the findings of the risk analysis does not imply their participation in its preparation or in supervising its application, in accordance with Article 39.1 c) of the GDPR, which must be documented. Simply echoing the content of said risk analysis does not serve as documentation, as there is no record of any suggestion from the DPO regarding the need to carry out a DPIA or their involvement in the methodology used or in the assessment of the quality of the risks.

Regarding the risk analysis dating process, FCB states that it actually
began earlier due to, among other things, the collection of the necessary information
and the possibility of modifying the risk assessment, as it is
a documentary obligation for which compliance must be demonstrated. However, in this case, it is not proven that such action took place, as only the reports are provided, the rest being mere statements without any documentary evidence.

It is unknown whether the analysis referred to in the report of November 9, 2022,
was the only and complete one, or if it varied, and why the dates are in versions 1,
the SBRF report of November 22, 2022, and the report of December 22, 2022.

In response to FCB's claim, it cannot be asserted that the data processing

carried out by FCB for SBRF and SBRVoz has a similar lifecycle, since
one is instantaneous in duration and persistence, with virtually no storage time
for the biometric vectors, using the ID card data and photo as the primary contrast, while the other stores the voice template
along with other member data on FCB's own servers. In addition to the way their

processing is implemented, the inherent risks of fingerprinting—the capture requires physical contact with
a sensor, it is static as it does not change over time, and it is vulnerable to
physical replication—compared to personal voice data: variable due to health status,
emotions, noisy environments, and AI-generated voice cloning, are entirely different. Therefore,
the descriptions of the processing operations from which to begin
analyzing their various risks must necessarily be different.

Describing the treatment requires understanding it, and to do so, it needs to be analyzed. This involves examining each part in detail, separating and considering it independently, to understand its characteristics, qualities, restrictions, and limitations. The depth—or granularity—of this analysis must be sufficient to draw conclusions regarding the risk it poses to rights and freedoms.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 124/139

In the systematic descriptions of the processing activities and purposes of Article 35.7.a) of the GDPR, the enumeration and description of the personal data affected, the stages at which the data is processed by the processors/sub-processors, and the data flows cannot be omitted, otherwise the management will not be effective. In this case, neither of the two descriptions of the processing activities contains anything other than mere references. The descriptions of the data processing activities break them down into phases, although they do not detail the components of each phase. For example, they do not mention the website from which the SBRF (Single-Party Data File) is collected, the technological asset of the ID card scanning, or the data transfers from VERIDAS to the FCB (Financial Communications Board). In other words, they do not achieve a complete analysis of the data lifecycle.

In the assessments of the need to conduct a Data Protection Impact Assessment (DPIA) for the SBRVoz (Voice Data Processing System) contained in point 8 of the report, the risks are not analyzed. Instead, the report responds to assumptions contemplated in WP 248, such as whether large-scale processing is carried out. A comparison is made at the population level in Catalonia, and biometric data is not included in the data processing category. Therefore, the report concludes that this is not large-scale data processing.

In the same section, regarding the nature of the processing, different

data sets and various sources of information are not combined, although it is true that they are combined

and the data associated with the member's record are used or added, as in the entry linked to the member's profile,
whose membership registration has other purposes, or the data from the National Identity Document (DNI), also retaining
the photo from the DNI.

Finally, it should be noted that this procedure is not discussing the
compliance of the risk analyses with data protection regulations, but rather the
need to conduct a Data Protection Impact Assessment (DPIA). The risk analyses
conducted by FC Barcelona are examined solely to demonstrate that they are not DPIAs, nor
do they contain the necessary elements, in light of the arguments made by FC Barcelona in this regard

(that the risk analyses carried out are true DPIAs because they contain

all the necessary elements). Therefore, it is curious that FCB indicates it is
surprised that the Spanish Data Protection Agency (AEPD) is thoroughly examining the data lifecycle,
given that, they say, the Guide does not establish the obligation to provide such a
detailed description in the terms now required. All of this is being
examined precisely because FCB intends for the risk analyses to serve as a

Data Protection Impact Assessment (DPIA).

For all these reasons, this claim is dismissed.

THIRD

Regarding the allegation that the motivation and justification have been altered

in the proposal for the initial agreement to assess and interpret the

correction of the deficiency in the risk analysis assessment, the original
understanding of the initial agreement being the presence of special category data,
an element no longer in dispute in the proposal due to the dismissal of Article 9 of the
GDPR, the following should be noted:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 125/139

-When drafting the initial agreement, it was taken into consideration that,
after the request was made to include the DPIA in the response to the complaint on
21/04/23, the response stated that it had concluded that it was not necessary, without

indicating the existence of the document dated 22/11/2022. The document itself was
submitted as part of the initial agreement, while SBRVoz's document, lacking

the conclusions regarding the need for a Data Protection Impact Assessment (DPIA), was not
obtained except during the testing phase.

-It should be noted that each of the minimum elements that a

DPIA must contain, as indicated in Article 35.7 of the GDPR, must be assessed

not for its merely formal compliance or whatever it may be called, but for its
substantive content and effectiveness in fulfilling the purposes of what a
true DPIA should be. Starting with the risk analysis developed by FCB,

whose conclusions, in the case of SBRF, were adopted by the Data Protection Officer (DPO) on November 9, 2022,

concluding that a DPIA was not necessary after analyzing the risks,

without, on the other hand, any conclusion on the same matter regarding the use of
SBRVoz.

-The proposal is not considered inconsistent because biometric processing is not considered special, since the probability of high risk is not limited to special categories of data; it can be applied to any type of data that, when processed, presents a significant risk to the rights and freedoms of individuals. The classification of data into "special categories," however, refers to data that, by its nature (health, ethnic origin, opinions, etc.), is inherently more sensitive and has a stricter processing prohibition, which could increase the probability of high risk if managed inadequately.

-The DPIA must not only be a nominal description but must meet a minimum quality standard in its drafting, implementation, reassessment, and follow-up.

Similarly, the assessment of the conditions for determining whether the controller is obligated to carry out a DPIA must be based on the description of the processing and the risk factors identified in the risk analysis process for rights and freedoms.

-The DPIA must be supported by documentation that distinguishes between the

process and the way it is presented, and the data controller must provide proof
that it supports it. Documentation does not imply creating a single
document, but rather recording the actions, analyses, and decisions
of the DPIA. For example, the criteria used to determine certain
probability or impact values for data subjects, the reasons why

a particular measure reduces the probability or
impact, etc. In accordance with guidelines WP248, the following would be included:

“even if a processing operation corresponds to the cases
mentioned above, a controller may not consider that
such processing is likely to entail a high risk. In these cases, the

controller must justify and document the reasons why a DPIA is not carried out,
and include and record the opinions of the Data Protection Officer. Likewise, the justification and the decision not to carry out a DPIA

made within the framework of risk management must also be

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 126/139

adequately documented. Failure to carry out documentation activities
in relation to the proactive responsibility activities carried out, or failure to
adequately and with justification document the controller's decisions,

will prevent the controller from demonstrating compliance with its obligations.”

-Similarly, the chronological order of completing a DPIA is important for understanding and avoiding potentially fruitless procedures. Opinion WP

248 establishes in section D, "How should a DPIA be carried out?"

section C, the basic methodology that meets the minimum requirements and the iterative order to follow.

- “description [...] of the planned processing operations and
the purposes of the processing”;

- “an assessment of the necessity and proportionality” of the
processing;

- “an assessment of the risks to the rights and freedoms
of the data subjects”;

- “the measures envisaged to:

- address the risks

- “demonstrate compliance with this Regulation”

- In the sanctioning procedure, the act of imputation can only be

the proposed resolution, since it contains all the necessary elements of the charge
for the competent body to issue the administrative resolution, without generating any defenselessness for the accused,

since after its issuance the party against whom the complaint is filed can use the procedure for submitting allegations
conferred in Article 89.2 of the LPACAP.


       In this regard, Constitutional Court Judgment 14/1999, of February 22, indicates that, “5. The appellant

considers his right to a fair trial violated as a consequence of the manner in which, at its various stages, the content of the disciplinary proceedings was made known to him

. He complains, firstly,
of the Investigating Officer's refusal to provide him with a copy of the proceedings

containing the file, a request that had been made in order to formulate the
response to the statement of charges (Art. 40 L.O.R.D.F.A.). He also complains about the
manner in which he was given access to the file so that he could submit whatever he
deemed appropriate regarding the proposed resolution (Art. 41
L.O.R.D.F.A.): this access procedure was carried out by providing
a simple copy, not duly certified, of the file, some pages of which were,

moreover, illegible (although, he has If necessary, those that corresponded to

writings from the interested party himself). In this sense, we have said that "without any
doubt, the right to know the proposed resolution of a
disciplinary proceeding, clearly stipulated in the rules of the
administrative procedure, forms part of the guarantees established by art.

24.2 C.E., since without it there are no real possibilities of defense within the scope of the

procedure" (Constitutional Court Judgment 29/1989, legal basis 6. This doctrine, with a
similar formulation, is reiterated in Constitutional Court Judgment 145/1993, legal basis 3,

referring, on this point, to Constitutional Court Judgments 192/1987, legal basis 2, and
98/1989, legal basis 7), and extends to the possibility of the accused to
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 127/139

access knowledge of the incriminating testimonies that substantiate
the charges contained in the statement of charges (Constitutional Court Judgment 64/1994, although
referring to criminal proceedings). The exposition of both complaints thus highlights

their relationship with The exercise of the right to defense in its aspect of

the right to be informed of the charges.”

Therefore, in this case, the data processing operations of FCB del SBRF and
SBRVoz, in addition to meeting the conditions of entailing not one, but several probable
high risks to the rights and freedoms of natural persons, due to the nature,

scope, context, and purposes of the processing, were predisposed to such risks, as they
met more than two of the requirements set forth in Article 35.3 of the GDPR and in the
list of Article 35.4 of the GDPR (list of types of data processing that require
a data protection impact assessment (Art. 35.4) drawn up by the
Spanish Data Protection Agency (AEPD), approved by the EDPB). It is concluded that the submitted DPIAs are
insufficient in several of their essential elements, which have been specified in this and the

previous legal basis.

The allegations regarding the components of the penalty assessment and its amount are addressed in Legal Basis VIII.

VII. Classification of the Infringement

As explained in the Legal Basis above, it is considered that
the facts presented could infringe the provisions of Article 35 of the GDPR, which
could constitute an administrative infringement classified under Article

83.4(a) of the GDPR, which states that:

“Infringements of the following provisions shall be subject, in accordance with
paragraph 2, to administrative fines of up to EUR 10,000,000 or,
in the case of an undertaking, up to 2% of its
total worldwide annual turnover of the preceding financial year, whichever is higher:



(a) The obligations of the controller and the processor pursuant to Articles 8, 11,
25 to 39, 42 and 43.”

For the purposes of the statute of limitations, the LOPDGDD (Spanish Organic Law on the Protection of Personal Data and Guarantee of Digital Rights) establishes in its Article 73.t) that: “In accordance with the provisions of Article 83.4 of Regulation (EU) 2016/679, the following infringements are considered serious and shall be subject to a two-year statute of limitations:

t) The processing of personal data without having carried out an assessment of the impact of the processing operations on the protection of personal data in cases where such an assessment is required.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 128/139

VIII Proposed Sanction

In order to determine the administrative fine to be imposed, the provisions of Articles 83.1 and 83.2 of the GDPR must be observed. These articles state the following:
“1. Each supervisory authority shall ensure that the imposition of administrative fines under this Article for infringements of this Regulation referred to in paragraphs 4, 9 and 6 is, in each individual case, effective, proportionate and dissuasive.

2. Administrative fines shall be imposed, depending on the circumstances of each individual case, as an additional measure to, or in lieu of, the measures provided for in Article 58(2)(a) to (h) and (j). When deciding on the imposition of an administrative fine and its amount in each individual case The following shall be duly taken into account:

(a) the nature, seriousness, and duration of the infringement, taking into account the

nature, scope, or purpose of the processing operation concerned, as well as

the number of data subjects affected and the level of damage suffered by them;

(b) whether the infringement was intentional or negligent;

(c) any measures taken by the controller or processor to
remedy the damage suffered by data subjects;

(d) the degree of responsibility of the controller or processor,
taking into account the technical and organizational measures implemented pursuant to
Articles 25 and 32;

(e) any previous infringements committed by the controller or processor;

(f) the degree of cooperation with the supervisory authority in order to remedy the
infringement and mitigate its possible adverse effects;

(g) the categories of personal data affected by the infringement;

(h) how the supervisory authority became aware of the infringement, in
in particular whether The controller or processor notified the infringement and, if so, to what extent;

(i) where the measures referred to in Article 58(2) have been previously ordered against the controller or processor concerned in relation to the same matter, compliance with those measures;

(j) adherence to codes of conduct pursuant to Article 40 or to approved certification mechanisms pursuant to Article 42; and

(k) any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement.

For its part, Article 76, “Sanctions and Corrective Measures,” of the LOPDGDD (Spanish Data Protection Law)

stipulates:

“1. The sanctions provided for in paragraphs 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679 shall be applied taking into account the criteria for determining the severity of the sanction

established in paragraph 2 of the aforementioned article.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 129/139

2. In accordance with the provisions of Article 83.2.k) of Regulation (EU) 2016/679, the following may also be taken into account:

a) The continuing nature of the infringement.

b) The connection between the infringer's activity and the processing of personal data.

c) The benefits obtained as a result of committing the infringement.

d) The possibility that the affected party's conduct could have inducing the commission of the infringement.

e) The existence of a merger by acquisition subsequent to the commission of the infringement, which cannot be attributed to the acquiring entity.

f) The impact on the rights of minors.

g) Having a data protection officer, when not mandatory.

h) The voluntary submission by the controller or processor to alternative dispute resolution mechanisms in cases where disputes arise between them and any interested party.

Recital 146 states that: “In order to strengthen the application of the rules of this Regulation, any infringement thereof should be punished with sanctions, including administrative fines, in addition to, or instead of, appropriate measures imposed by the supervisory authority under this Regulation. In the case of a minor infringement, or if the fine likely to be imposed would constitute a disproportionate burden for a natural person, a warning may be issued instead of a fine. However, special attention should be paid to the nature, seriousness and duration of the infringement, its intentional character, the measures taken to mitigate the damage suffered, the degree of responsibility or any relevant prior infringements, the manner in which the supervisory authority became aware of the infringement, compliance with measures ordered against the controller or processor, adherence to codes of conduct, and any other aggravating or mitigating circumstances.”

In this case, the alleged infringement is that of Article 35 of the GDPR, as defined in Article 83.4 of the GDPR, where the maximum fine is €10,000,000 or, in the case of a company, 2% of its total global annual turnover for the preceding financial year, whichever is higher.

Therefore, the fine to be imposed would range from €0 to €14,866,260 (net turnover for the 2023/2024 financial year).

The initial agreement stated, insofar as it applies to the alleged infringement of Article 35 of the GDPR, that:

“In this case, considering the seriousness of the potential infringements,

paying particular attention to the consequences of their commission on the affected parties,

and the circumstances of this case,

a fine would be appropriate.

As a common factor, the figures provided by

FCB must be considered, which refer to:

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 130/139

In total, 124,872 members out of a total of 143,000 members

completed the census update process.

- 112,623 members chose to do so online,

and of these, 72,648 consented to the recording of their voice.

- 12,249 members updated their membership in person, and

160 of them expressly consented to having their voice recorded.

Minors also used the online membership update system, as well as the in-person system.

-14,433 members did not update their information in the FCB membership register.

-993 membership cards belonging to deceased members were detected.

Therefore, the following circumstances must be noted:

-Considering Article 83.2.a) of the GDPR:

"the nature, seriousness, and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation concerned, as well as the number of data subjects affected and the level of damage suffered."

Two types of biometric data processing have been carried out—for facial comparison, as a system for updating the social census, and for voice recognition for future service provision—which, due to their nature and the different techniques used in each, have a more incisive impact on the fundamental rights to data protection directed at the same categories of affected parties, all FCB members, and not only because the data originates from physical parts of the individuals and the unique nature of biometric data, being carried out through automated processing; The processing begins with registration in an online environment through the established census update process, using different technologies, including the integration of voice recognition software, to digitally identify the individual in both cases using two different methods. Each processing activity has distinct purposes, encompassing all FCB members worldwide, representing a large-scale operation involving 143,000 individuals.

The seriousness of the infringement stems from both the volume of personal data—for facial comparison as a system for updating the social census, and for voice data for future service provision—and its nature. In the first case, the geographical dispersion of members in the census plays a role, while in the case of voice data, it is used for sales purposes. The failure to comply with the mandatory DPIA due to
insufficiency of its components resulted in the processing of data with
these characteristics without a valid DPIA having been carried out.

This processing continued until November 30, 2023, for the SBRF and until the
SBRVoz, increasing the various risks to which all
processing is subject, which is more intrusive in the case of biometric data, with the consequent
potential impact on its consequences.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 131/139

It should be noted that the alleged infringement falls under Chapter IV of the
GDPR: “Data Controller and Data Processor,” which begins its
Section 1 with the general obligations aimed at ensuring and being able to demonstrate that

the processing is compliant with the GDPR. In section 3, entitled “Data Protection Impact Assessment and Prior Consultation,” preceded by section 2, “Personal Data Security.”

In short, it can be concluded that the infringement prevented the effective application of the provision and the achievement of the objective it sought to protect.

-The specific concurrence of the elements indicated in Article 83.2.b) must be considered: “intent or negligence in the infringement.”

Despite some complaints raised by members to whom the obligation to provide their data was directed, FCB suspended the processing for barely a month. The Club opted to deactivate the service on April 5, 2023, despite the potential harm this could cause to FCB, while the entire process was re-analyzed with the help of the Club's Data Protection Officer, external lawyers, and the software provider, thus reaffirming its legality and the system's compliance with data protection regulations. The service was reactivated on May 4, 2023, with the same conclusions reached for not carrying out the EIDP, without changing the scenario or the point of focus. Nor did the

publication of EDPB Guidelines 5/2022 on the use of facial recognition technology in the application of the Law, adopted on April 26, 2023,
almost a month after the start of the data collection process for both types of data, which also
emphasized the high risk in this type of processing due to the nature of the data,
lead FCB to reconsider its position of considering both biometric data processed

as non-special data, one considered necessary for the execution of the contract of
persons associated with FCB: facial recognition, and the other, voice, for the
provision of services collected based on consent.


It must be considered that FC Barcelona has a very high number of members, and despite being a

sports association, its interactions with members are not uncommon. Therefore, it is required
to exercise rigor and special care with this type of data in its constant handling of it,
also because it is part of the Club, especially when creating a digital profile
that was added and included with the census update. FC Barcelona's actions reveal
negligence in its conduct due to the absence of the required duty.

-Regarding the provision of Article 83.2.g) of the GDPR, a systematic

and teleological interpretation of this GDPR precept connects it with other classifications
offered by the GDPR text, which, moreover, better reflect the purpose of the
regulation: to determine the appropriate administrative fine in each individual case,
respecting in all cases the principles of proportionality and effectiveness, taking into account
the presence of sensitive data.

In this regard, recitals 51 and 75 of the GDPR distinguish a group of personal data that, by their nature, are particularly sensitive due to the significant risk they may pose, in the context of their processing, to fundamental rights and freedoms. The common denominator among all of them is that their processing entails a high and significant risk to fundamental rights and freedoms, as it can lead to physical, material, or immaterial harm.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 132/139

This group or category of particularly sensitive data includes the categories of specially protected data regulated by Article 9 of the GDPR (recital 51) and, in addition, many other data not regulated by that provision. Recital 75 details the personal data whose processing may pose a risk, of varying severity and likelihood, to the rights and freedoms of natural persons because it may cause physical, material, or immaterial harm. Among these, it mentions:

data whose processing “may lead to discrimination, identity theft or fraud, financial losses, reputational damage, loss of confidentiality of data subject to professional secrecy, unauthorized reversal of pseudonymization, or any other significant economic or social harm.”

Thus, we can highlight, among sensitive data, the National Identity Document (DNI), which in this case has been processed not only with regard to its number, but also with regard to all the data contained therein.

According to its regulatory framework, Royal Decree 255/2025 of April 1, which governs the National Identity Document (DNI), the DNI allows for the direct and unequivocal identification of a natural person, as established by the aforementioned Royal Decree, because it is a general personal numerical identifier with sufficient value to prove both the identity and nationality of the holder, making it a particularly sensitive element within the personal data ecosystem. Furthermore, its misuse carries a high risk of identity theft, financial losses, or infringement of the right to honor, risks expressly contemplated in recital 75 of the GDPR. Therefore, a systematic and purposive interpretation of the GDPR—in accordance with recitals 51 and 75—allows the DNI to be considered a particularly sensitive piece of data, given its capacity to cause significant harm in the event of unauthorized use.

Regarding the allegation made against FCB's proposal that the reference to this data is only now being brought up,

potentially creating legal uncertainty, it must be clarified that it is not an inopportune moment to assess what was outlined in the initial agreement in the
proposed resolution, given that more details of the processing activities and the
risk assessment carried out by FCB have become known. It should be noted that the two risk analyses that FCB considers "presumed"

DPIAs were only submitted in the allegations and
evidence.

Likewise, the interpretation of Constitutional Court Judgment 14/1999, of February 22, set out in legal basis VI, must be reiterated.

Having said that, we now turn to the allegations made in relation to
Article 35 of the GDPR, the only article on which the charge is based:

Regarding FCB's allegations as a mitigating factor to be considered within Article

83.2.a) of the GDPR, that no data subject has suffered or could suffer harm or injury, considering that the processing itself has not been declared unlawful, since the
Spanish Data Protection Agency (AEPD) itself has indicated that there is a cause that would lift such a prohibition,
since the members have given their consent, also because the
processing ended more than a year ago, and consequently,

precautionary measures had not been adopted to safeguard the rights of the affected individuals, whose rights were allegedly being violated, this
authority must point out that the The damage—whether material or immaterial—is not a determining factor or essential condition that it
occur or be of a specific type, since “the causation of damage in the context of unlawful processing of personal data is only a potential and not automatic consequence of such processing, and the infringement of the GDPR does not necessarily entail damage” (CJEU Judgment 27/10/24, Case C-507/23).

However, it is clear from the three complaints that members,
including minors, are being forced to update the census digitally or
in person to rectify a situation in which most members already had their

data updated in order to identify deceased members (whose status is still being used by others). It is observed that the same procedure is applied to all members, without differentiating the scope
and extent of the data processed based on the geographical origins of the members
for data minimization purposes. Furthermore, the proposed
resolution does not indicate that the processing of the analyzed data was lawful, but rather that

there is a lack of culpability in the infringement attributed to FCB under Article 9 of the GDPR,

without assessing the consents obtained.

Regarding the allegation related to the circumstances to be considered within Article 83.2.a) of the GDPR, that the complaint stems from a misunderstanding by R1, and that the complaints previously received from members did not involve any type of infringement,

being resolved by the member services department, it should be noted that there are three complaints that make up this file, and that FC Barcelona does not consider that they also raise other questions about the processing carried out.

In addition, there are those that, according to FC Barcelona's response to the transfer on May 22, 2023, stated that, regarding complaints received, "five have been received to date, and another four" of which it did not provide copies because it considered they should have been deleted.


Also, of the complaints received, before responding to the transfer of the claim,

one led to the suspension of the procedure to assess the legitimacy of the processing,

resuming it a month later on May 5, 2023.

However, in its obligation to proactively process data

aimed at demonstrating compliance with the GDPR processing principles
as outlined in Article 5.2 of the GDPR, it has neither provided a copy of any complaint to
examine its nature and the type of incident it alleged, nor did it provide the report
recommending the continuation of the suspended processing, which it claimed in evidence

to have prepared in connection with the suspension, responding in evidence regarding
the cause of the suspension, stating that the procedure was clearly legal, corroborating
informational aspects of the processing, and expanding the information on the website.

On the other hand, the terms in which the complaints are formulated do not bind the
development of the actions to be carried out by the Spanish Data Protection Agency (AEPD), since, based on the
powers and functions established in the GDPR, it can assess the processing operations, with special consideration given to those that may affect a large group

of people and where the infringements may stem from a systematic pattern of action that
could harm the entire group, which has regulated conditions in its
Statute and whose Board of Directors makes and implements decisions, as is the case here.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 134/139

In consideration of Article 83.2.b) “the intent or negligence in the infringement;”

It must be considered that FC Barcelona has a very high number of members, and despite being a sports association, it is not uncommon to have relationships with them that hold rights and obligations within the framework of their relationship, within the context of private relationships derived from their status as consumers, and in which the fundamental rights of the members must be duly considered, especially, and as far as this concerns us, the fundamental right to the protection of personal data. The initial complaint was filed with the Spanish Data Protection Agency (AEPD) one month after the processing began, and it had to be suspended to add clarifications to the information, without modifying the initial data collection clause.


Therefore, given that FCB is required to exercise rigor and special care with this type of data in its ongoing data handling, especially when creating a digital profile that was added and included with the census update, FCB's actions reveal negligence in its conduct due to a failure to fulfill the required duty of care mandated by the regulations.

Special importance must be given to the extensive data protection measures FCB provides, including professionals dedicated to privacy and data protection,

responsible for continuous compliance verification, an external law firm,

and a Data Protection Officer (DPO) with over 20 years of experience in privacy and data protection, presented as a guarantee of proper processing. These individuals should have been familiar with the application and implementation of the regulations, given the requirement to conduct a Data Protection Impact Assessment (DPIA).

Regarding the claim that intent or negligence cannot be considered present because the risks were analyzed and a Data Protection Impact Assessment (DPIA) was in place, and because the decision took into account providing a service that avoided travel, without any intention of infringing rights or obtaining economic benefit, we would like to point out that the risk analyses carried out do not comply with the GDPR, much less be considered DPIAs. Regarding geographical dispersion, it should be noted that a minority of members are located in various countries abroad or in the rest of Catalonia, with the majority concentrated in the city and metropolitan area. Therefore, while ease of use benefits everyone, it is not a decisive factor.

Regarding the lack of intention to infringe rights, this is why it is not considered intent, but rather negligence. Providing convenience through the implementation of the system does not negate its compliance with the article and its accompanying regulations, which have been violated, as it can fulfill both purposes. The fact that
no economic benefit was obtained or that no funds had to be invested to implement
the system does not negate the fact that the census update was carried out with the results
desired by FCB, as membership cards for deceased individuals were released, and that
such elements cannot be considered either as a lack of intent or

as a mitigating factor.

FCB alleges in its defense that it halted the procedure before receiving

the transfer of the claim, on April 26, 2023, and analyzed whether the information was adequate,
reactivating the process on May 4, 2023. Regarding this, it is estimated that it reached the same
conclusions that were initially taken for the establishment and reasons for the
processing, without modifying the scenario or the point of focus with respect to the EIPDs.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 135/139

Regarding FC Barcelona's objection to the proposal concerning the application of this circumstance, specifically that, for the census update and voice recording, it had complied with a series of obligations stipulated by the GDPR in relation to the alleged infringement,

these are merely obligations established in the GDPR and the LOPDGDD, which must be fulfilled concurrently with the DPIA. Furthermore, the meager assessment and level assigned to the risks of biometric data processing lacks the necessary practical application to project a residual risk map, which is essential for gaining a comprehensive understanding of the risks associated with both types of processing and for serving as an effective management tool. The inclusion of the National Identity Document (DNI) as sensitive data in this

section of the proposal does not infringe any rights of FC Barcelona, as it conforms to what was
already included in the initial agreement and is made clear in the proposal.

FCB requests that the following be considered mitigating factors:

Regarding the consideration that carrying out the Data Protection Impact Assessments (DPIAs) on
the two processing activities, and the risk assessment report, which is inherent in them,

constitute measures taken to mitigate damages suffered (Article 83.2.c of the GDPR),
this contradicts FCB's own assertion in its allegations that there were no damages to the data subjects. Complying with a legal obligation is not, nor does it constitute, any measure
of any kind, but simply fulfilling the obligation imposed by the law, and cannot
serve as an excuse for the imputed conduct.

In any case, completing a DPIA is not connected to reactive measures, not only
because it must be available before processing, being a mandatory

preventive measure, intended, among other things, precisely to reduce any
damages that may arise.

In any case, its insufficient content cannot be considered a mitigating factor,

since these are mandatory measures, expressly stipulated as obligations of the
data controller in all cases, and before the commencement of processing (preventive purpose), and specifically in the case of two different types of biometric data combined
with ID cards, in one instance, and voice data, as was the case here. As indicated, the risk analyses were clearly flawed and not in accordance with the GDPR and could not be

considered a Data Protection Impact Assessment (DPIA) simply because they merely had the formal content required by the
GDPR.

The same applies to the adoption of security measures in the
processing, which FCB claims. Their application merely ensures
that the processing applies the measures necessary to comply with the GDPR, as indicated in
Article 24.1 of the GDPR, given that it processes the data of its members and
encourages them to update their information or voluntarily provide their voice data. These measures
aim to guarantee effective and comprehensive protection of the right advocated by the

GDPR, which is owed to and belongs to the data subject. The active and effective implementation
of security measures is simply compliance with the general
obligations imposed by the GDPR on all data controllers, and cannot serve to mitigate what is legally required.

Regarding cooperation with the Spanish Data Protection Agency (AEPD) to remedy the
infringement and mitigate adverse effects, responding to the questions
raised is simply the duty of cooperation stipulated by the GDPR and further developed by

the Spanish Data Protection Act (LOPDGDD).

Regarding FCB's allegations concerning the proportionality of the fine in the initial agreement, contained in point eight, 7, it should be noted that there is a lack of certainty

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 136/139

regarding the turnover figure used by the Spanish Data Protection Agency (AEPD) as a reference for the calculation,
since two different financial years are mentioned, firstly, it should be noted that Article 83.4
of the GDPR, which establishes the application of the maximum penalty amount,

for infringements of Article 35 of the GDPR, states that: “…Infringements of the following provisions shall be sanctioned, in accordance with paragraph 2, by administrative fines of no more than EUR 10,000,000 or, in the case of an undertaking, no more than 2% of the total annual turnover for the financial year.” previous financial, opting for the one with the highest amount: a) the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39,

42 and 43.”
Secondly, Recital 150 of the GDPR, second paragraph, states: “This

Regulation should specify the infringements as well as the maximum limit and the
criteria for setting the corresponding administrative fines, which the competent supervisory authority should determine in each individual case taking into account all
the circumstances involved, paying particular attention to the nature,
seriousness and duration of the infringement and its consequences and to the measures taken
to ensure compliance with the obligations imposed by this

Regulation and to prevent or mitigate the consequences of the infringement.”

Article 4 of the GDPR, in its definitions, states: “18) ‘undertaking’: a natural or legal person, regardless of its legal form, including companies or associations regularly engaged in an economic activity;” “19) ‘group of undertakings’: a group consisting of a controlling undertaking and its controlled undertakings;”. This latter concept is used primarily in Chapter V of the GDPR, in the expression “group of undertakings engaged in a joint economic activity.”

Third, it is a fact that FC Barcelona is a non-profit sports association, but this does not prevent it from developing different roles in the field of business management.

Fourth, the financial section of the 2023/2024 annual report includes the balance sheet as of June 30, 2024, of FC Barcelona and its subsidiaries (the Group), some of which are operating to generate returns on investment and are subject to commercial law for the preparation of their financial statements. The net revenue figures include €390 million from marketing and advertising and €215 million from television rights broadcasting, while income from subscribers and members amounts to €65 million.

Finally, Recital 150 of the GDPR states: “If administrative fines are imposed on an undertaking, that undertaking shall be understood to mean an undertaking as defined in Articles 101 and 102 of the GDPR.” TFEU...”

Given that the initial agreement, as stated in the established facts, shows a
net turnover for the 2023/2024 financial year of ***AMOUNT.1, while
the figure for the preceding year was ***AMOUNT.2, attributed to FCB and its

subsidiaries (the Group, as referred to in its 23/24 Annual Report), the
penalty of the initial agreement of €2,000,000 for Article 35 of the GDPR would
fall within the maximum range of the aforementioned figure, considering either of

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 137/139

both figures, noting that the one updated to the total annual turnover
of the previous financial year is that of 2023/2024, that is, the first figure.

The objection to the proposal, which contemplated a sanction for infringement of Article 35 of the GDPR regarding proportionality, stating that it includes companies within its group that are not parties to the proceedings, stems from considering the application of the maximum sanction amount for proportionality in the aforementioned articles. Considering the turnover published in the FC's 2023/2024 Annual Report in relation to the circumstances, it is not entirely disproportionate.

Furthermore, sanction proportionality is understood as the appropriateness, according to criteria of justice and equity, between the facts constituting the infringement and the determination of the applicable sanction, taking into account the degree of fault involved, that is, the level of intent, carelessness, or negligence revealed by the conduct. And, of course, a justification for the assessment of the degree of fault involved is required, which in this case has has been detailed.

On the other hand, regarding the sanction affecting the members of the Club and the potential impact on membership fees, it should be noted that it has already been determined that no information was provided regarding the EIPD (Environmental Impact Assessment). The impact on the members of the social body, as a sports association, is inherent to any type of organization, whose financing includes supporting its members. Therefore, the argument presented cannot be considered contrary to the proportionality of the sanction resulting from the commission of the infraction by an agreement adopted by its governing body in this case.

Finally, regarding the alleged comparative disadvantage in the sanction contained in the initial agreement compared to other procedures involving companies and their business volumes, or the circumstances involved, it should be noted that comparisons are not possible in terms of illegality, and the comparative figures provided by FCB offer only a partial view of the issues, without considering, for example, that in the case From ***COMPANY.1, the
processing was only carried out in 22 establishments in Palma de Mallorca without
containing how many people were being searched for in the biometric facial

recognition system that had the aforementioned restraining orders or access prohibitions. Moreover, each case is different, as are the circumstances surrounding it.

Notwithstanding the above, it should be considered, with regard to the processing of the member's voice, that this could be subdivided into two phases. The first aimed at the

collection of the biometric data, its registration, and its storage, carried out in the same census update process, and the second in the provision of the
services by telephone by FCB. Well, the first phase was carried out, but
the second was not, and was initially suspended, with FCB stating on
July 17, 2024, that "FCB has opted not to implement the process." of
voice authentication and submit the legality and suitability of this process to review

by our data protection officer to determine whether
we can use it or not. Should the conclusion be that we cannot use
this system, we will take the appropriate action regarding the voice biometric data we hold… Regarding remote/online procedures, as
explained in the previous statement, it is currently not possible to carry out any

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 138/139

remote or online procedure that involves the processing of biometric data.”Furthermore, in its arguments against the initial agreement, it states that subsequently,
all voice recordings were deleted: “ultimately, all voice recordings

were deleted after FCB decided against using voice as a verification tool
in telephone transactions.”

Thus, the assessment of the circumstances contemplated in Article 83.2 of the GDPR, with respect to
the infringement committed by violating the provisions of Article 35 of the GDPR,
leads to the imposition of an administrative fine of €500,000.

Therefore, in accordance with applicable legislation and having assessed the criteria for determining the severity of the sanctions, the existence of which has been proven,

the Presidency of the Spanish Data Protection Agency RESOLVES:

FIRST: To IMPOSE on FÚTBOL CLUB BARCELONA, with Tax Identification Number G08266298, for an infringement of Article 35 of the GDPR, classified under Article 83.4.a) of the GDPR, an administrative fine of €500,000.

SECOND: To declare the dismissal of the case concerning the infringement of Article 9 of the GDPR attributed to FÚTBOL CLUB BARCELONA.

THIRD: To notify FÚTBOL CLUB BARCELONA of this resolution, with the submission of the GENERAL ANNEX.

FOURTH: This resolution will become enforceable once the deadline for filing the optional appeal for reconsideration (one month from the day following notification of this resolution) has expired without the interested party having exercised this right.

The sanctioned party is advised that they must pay the imposed sanction once this resolution becomes enforceable, in accordance with the provisions of Article 98.1.b)

of the LPACAP, within the voluntary payment period established in Article 68 of the General Collection Regulations, approved by Royal Decree 939/2005, of July 29, in relation to Article 68. 62 of Law 58/2003, of December 17, by depositing the amount, indicating the Tax Identification Number (NIF) of the sanctioned party and the procedure number shown in the heading of this document, into restricted account IBAN: ES00-0000-0000-0000-0000-0000

(BIC/SWIFT Code: CAIXESBBXXX), held in the name of the Spanish Data Protection Agency at CAIXABANK, S.A.

Otherwise, collection will be pursued during the enforcement period.

Once the notification has been received and is enforceable, if the enforceability date falls between the 1st and 15th of each month, inclusive, the deadline for making the voluntary payment will be the 20th of the following month or the next business day thereafter. If the date falls between the 16th and the last day of each month, inclusive, the payment deadline will be the 5th of the second following month or the next business day thereafter.

In accordance with Article 50 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights), this Resolution will be made public. Publication will take place once the interested parties have been notified.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 139/139

This resolution, which concludes the administrative process pursuant to Article 50 of the LOPDGDD, may be appealed. 48.6 of the
LOPDGDD, and in accordance with the provisions of Article 123 of the LPACAP, the

interested parties may, optionally, file an appeal for reconsideration with the
Presidency of the Spanish Data Protection Agency within one month from the day following notification of this resolution, or directly file an
contentious-administrative appeal with the Contentious-Administrative Chamber of the
National Court, pursuant to the provisions of Article 25 and paragraph 5 of

the fourth additional provision of Law 29/1998, of July 13, regulating the
Contentious-Administrative Jurisdiction, within two months from the day following notification of this act, as provided for in Article 46.1 of the
said Law.

Finally, it is noted that, in accordance with the provisions of Article 90.3 a) of the LPACAP, a
final administrative decision may be provisionally suspended if the
interested party expresses their intention to file an appeal with the Administrative Court.

If this is the case, the interested party must formally communicate this fact by means of a
written notice addressed to the Spanish Data Protection Agency, submitting it through

the Agency's Electronic Registry [https://sedeaepd.gob.es/sede-electronica-
web/], or through one of the other registries provided for in Article 16.4 of the
aforementioned LPACAP. They must also provide the Agency with documentation proving the
effective filing of the appeal with the Administrative Court. If the Agency does not receive
notice of the filing of the appeal with the Administrative Court within

two months from the day following notification of this resolution, it will consider the
provisional suspension terminated.

938-101025

Lorenzo Cotino Hueso
President of the Spanish Data Protection Agency

6 Jorge Juan Street www.aepd.es
28001 – Madrid sedeaepd.gob.es