Spain AEPD Fines Aena EUR 10.04M for DPIA Failure on Biometrics

AI Regulation News › Spain

Spain's AEPD fined Aena 10,043,002 euros for skipping a valid impact assessment on airport facial recognition

By Anthony Guerriero, Founder and lead analyst, The Leveraged Years.
Dateline: Madrid, 24 November 2025. Last verified: 2026-07-25.

Spain's data protection authority, the Agencia Espanola de Proteccion de Datos (AEPD), has fined airport operator Aena 10,043,002 euros over facial recognition run on its own passengers, and the operative ground is a failure to carry out a valid data protection impact assessment, not the facial scan itself. The target is Aena, the state-controlled operator that runs 46 airports in Spain, including Madrid-Barajas and Barcelona-El Prat. The instrument is a sanctioning resolution, expediente EXP202304532, published as document PS-00431-2024 and signed by AEPD President Lorenzo Cotino Hueso.

What makes this one worth reading closely is not the headline number. It is the theory. The AEPD did not rule that scanning a passenger's face to board a plane is illegal. It fined Aena for a paperwork failure that sits at the center of the EU rulebook: the duty to carry out a proper data protection impact assessment before you switch on high-risk processing. For anyone building or buying AI systems that touch biometric data, that distinction is the entire lesson.

The 10.04 million euro fine, explained

Between 2019 and June 2024, Aena ran a series of biometric boarding pilots. It started at Menorca in 2019, then extended to Madrid and Barcelona. Passengers who opted in could pass through document and boarding checkpoints using a facial pattern instead of showing a document to a human agent. The resolution records that 62,054 people actually enrolled, against an initial planning figure of 17.39 million potential passengers.

A complaint filed on 22 March 2023 by an individual acting for the Fundacion Eticas Data Society set the case in motion. After an investigation, the AEPD landed on a single infringement and a single fine. The operative order reads:

"IMPONER a AENA, S.M.E., S.A., con NIF A86212420, por una infraccion del articulo 35 del RGPD, tipificada en el Articulo 83.4.a) del RGPD, una multa de DIEZ MILLONES CUARENTA Y TRES MIL DOS EUROS (10.043.002,00 EUR)."

English gloss: To impose on Aena, for an infringement of Article 35 of the GDPR, classified under Article 83.4.a) of the GDPR, a fine of ten million forty-three thousand two euros (10,043,002.00 EUR).

The math is deliberate. Article 83.4 of the GDPR caps this category of fine at 10 million euros or 2 percent of global annual turnover, whichever is higher. The resolution records Aena's 2024 turnover at 5,021,501,000 euros, so 2 percent is roughly 100 million euros. The AEPD did not go anywhere near that ceiling. It set the figure just above the flat 10 million euro floor, treating the missing impact assessment as serious but not catastrophic.

Key Facts

Instrument
AEPD Resolucion de Procedimiento Sancionador, expediente EXP202304532, document PS-00431-2024.
Issuer
Agencia Espanola de Proteccion de Datos (AEPD), signed by President Lorenzo Cotino Hueso.
Date
Resolution issued November 2025; Aena announced its intent to appeal on 25 November 2025.
Who is covered
Aena, S.M.E., S.A. (NIF A86212420), operator of 46 Spanish airports, for its biometric boarding program.
Penalty and consequence
Fine of 10,043,002 euros for a single Article 35 GDPR breach, plus a confirmed suspension of biometric processing until Aena completes a compliant impact assessment.
Status
Not final. Aena has said it will appeal to the courts.

What the AEPD actually found: an Article 35 impact-assessment failure

Article 35 of the GDPR requires a controller to run a data protection impact assessment, in Spanish an Evaluacion de Impacto relativa a la Proteccion de Datos (EIPD), before starting processing that is likely to result in a high risk to people's rights. Large-scale processing of biometric templates, which fall under the special-category rules of Article 9, is a textbook trigger.

Aena produced impact assessments. The AEPD found them inadequate. In the reasoning section the authority concludes that the assessment failed to justify the necessity and proportionality of the biometric system, given that a less invasive traditional check was already running alongside it. The resolution notes that the new system stored far more personal data than the old visual document check, that the biometric token was generated on the day of the flight and kept for up to 24 hours, and that other passenger data was retained by Aena for two years. In the AEPD's words, the extension of processing was "muy significativa," or very significant, and increased risk exponentially compared with the pre-existing method.

Crucially, the second operative order goes beyond money:

"CONFIRMAR la suspension temporal de todo tratamiento de datos biometricos [...] hasta que AENA lleve a cabo una EIPD en los terminos recogidos en el articulo 35 del RGPD."

English gloss: To confirm the temporary suspension of all biometric processing until Aena carries out an impact assessment in the terms set out in Article 35 of the GDPR.

So the enforcement is not purely retrospective. Aena cannot simply restart facial boarding after paying. It has to do the assessment properly first.

The largest EU facial-recognition fines, compared

The Aena penalty is among the larger EU fines tied to facial recognition. It is not the single largest in the bloc. That distinction still belongs to the Clearview AI cases, where regulators went after a vendor that scraped billions of face images. The useful split is deployer versus scraper: Aena stands out as a fine against an operator running facial recognition on its own consenting users, rather than against a scraper with no lawful basis.

Notable EU facial-recognition and biometric enforcement actions
AuthorityTargetAmountYearCore theory
Netherlands (AP)Clearview AIEUR 30.5M2024Unlawful biometric database, scraping
Italy (Garante)Clearview AIEUR 20M2022No lawful basis, special-category data
Greece (HDPA)Clearview AIEUR 20M2022No lawful basis, scraping
France (CNIL)Clearview AIEUR 20M2022No lawful basis, non-cooperation
Spain (AEPD)AenaEUR 10.043M2025Article 35 impact-assessment failure

Only the Aena figure is verified against a primary source in this piece. The Clearview figures are drawn from the public decisions of the respective authorities and are included for context. Notice the pattern. Every Clearview case rests on there being no lawful basis at all. The Aena case is different in kind. Aena had consent. The AEPD went after the governance step instead.

What this resolution does NOT do

A named expert on what it signals

The two named positions of record disagree sharply. Lorenzo Cotino Hueso, President of the AEPD, signed a resolution that treats the impact assessment as the decisive control for high-risk biometric AI, and confirms a processing suspension until that control is met.

Aena rejects the framing. In its official communique of 25 November 2025 the company wrote that the sanction "se fundamenta en la supuesta infraccion de una obligacion formal," that is, it rests on an alleged breach of a formal obligation, and added that it "discrepa respetuosamente" and will appeal on both substance and proportionality. The company stresses that it did prepare impact assessments before launch and that no data breach occurred.

Read together, the dispute is not about whether faces were scanned. It is about whether the paperwork that is supposed to govern the scan was good enough. That is a fight every EU AI deployer should expect to have.

For related enforcement we are tracking, see the Italian Garante's block of DeepSeek, the OLG Hamburg ruling in Kneschke v. LAION, and Hungary's national AI Act implementation law. The full index sits on the AI Regulation News hub.

Frequently asked questions

How much did the AEPD fine Aena, and for what?
A single fine of 10,043,002 euros for one infringement of Article 35 of the GDPR, the duty to run a valid impact assessment before high-risk processing. The order is resolution EXP202304532, document PS-00431-2024.

Did the AEPD rule that the facial recognition itself was unlawful?
No. The finding is an Article 35 impact-assessment failure. The resolution does not sanction the biometric processing as unlawful under Article 9 and accepts that passengers gave voluntary informed consent.

Is the fine final?
Not yet. Aena said on 25 November 2025 that it will appeal. There is an optional reconsideration request to the AEPD within one month, or a judicial appeal to the Audiencia Nacional within two months.

Why should companies outside Spain care?
An EU regulator used the impact-assessment duty, not a consent or transfer theory, as the lever against a large biometric AI rollout. Any organization deploying facial recognition or other high-risk AI in the EU faces the same Article 35 documentary standard.

Primary sources