Spain Spain

REAL SOCIEDAD DE FUTBOL S.A.D.

66,000 €

GDPR enforcement action by Spanish Data Protection Authority (aepd) on 2025-08-12.

Rank · Sector
#17
of 351 in Individuals and Private Associations
Rank · Spain
#167
of 1,075
Rank · All fines
#611
of 3,050

Case details

Authority
Spanish Data Protection Authority (aepd)
Date
2025-08-12
Controller / Processor
REAL SOCIEDAD DE FUTBOL S.A.D.
Sector
Individuals and Private Associations
Quoted Articles
Art. 5 (1) f) GDPR, Art. 32 GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Spanish DPA has imposed a fine of EUR 66,000 on REAL SOCIEDAD DE FUTBOL S.A.D. The controller suffered a ransomwareattack due to insufficient technical and organisational measures to ensure data security. The original fine of EUR 110,000 was reduced to EUR 66,000 due to immediate payment and admission of responsibility by the controller.

Open original source Links to the regulator's original publication or another source.

Related fines