The FAN ID case: a 42.8 million pesos lesson in how to manage personal data correctly
On 12 July 2026, the Secretariat for Anti-Corruption and Good Governance announced the imposition of a fine of 42,849,095 pesos on the Mexican Football Federation Association, A.C. (the “FMF”), as a result of various breaches identified by the authority in relation to the processing of personal data through the FAN ID system, used to identify supporters and grant access to Mexican football stadiums.
According to the administrative decision, the FMF is alleged to have committed two main infringements: on the one hand, failing to adequately inform supporters that the biometric data collected to generate the FAN ID constituted sensitive personal data; and, on the other hand, failing to obtain the data subjects’ express written consent in accordance with the required terms for the processing of this category of information.
In particular, the authority considered it insufficient for consent to be obtained simply by ticking a box on a website, as there was no handwritten signature, electronic signature or other authentication mechanism to unequivocally verify that it was the data subject themselves who had given their consent.
It also found breaches of the principles of accountability and lawfulness, as the necessary measures had not been taken to ensure the proper processing of the personal data in question.
The amount of the penalty was determined by taking into account, amongst other factors, the seriousness of the infringements, the sensitive nature of the biometric data processed and the FMF’s financial capacity.
Like any administrative decision of this nature, the penalty is subject to challenge through the appropriate legal channels.
A lesson that goes far beyond football
The significance of the case does not lie solely in the amount of the fine, nor should it be understood as an issue exclusive to the sports industry.
On the contrary, it raises a question that is relevant to virtually any organisation that uses technology to identify, authenticate, gather information about or interact with individuals: are our personal data processing procedures truly prepared to withstand scrutiny by a regulatory authority?
Digital transformation has led companies and organisations across all sectors to increasingly adopt solutions based on biometrics, facial recognition, video surveillance, mobile applications, artificial intelligence, access controls, profiling tools and identification or authentication systems.
These technologies may serve entirely legitimate purposes — ranging from improving security and preventing fraud to offering better experiences to customers and users — but their implementation neither eliminates nor reduces the obligations associated with the processing of personal data.
This is precisely where one of the key lessons from the FAN ID case lies: innovation, security and operational efficiency must be accompanied, right from the design stage, by an appropriate privacy architecture.
Compliance cannot be assessed only after a technology has been procured, a platform is already operational, or millions of data points have already been collected. Privacy must be integrated from the moment the project is conceived, when it is determined what information will be required, suppliers are selected, data flows are designed and the mechanisms by which data subjects will be informed – and, where appropriate, their consent obtained – are established.
In other words, the cost of prevention is usually considerably lower than that of rectifying the situation following a complaint, an investigation, a penalty or a reputational crisis.
Having a privacy notice is not the same as having a compliance programme.
Perhaps one of the most significant lessons to be learnt from this case is that, when it comes to personal data protection, compliance cannot be reduced to the mere formal existence of a privacy notice, an internal policy or a tick box.
These tools are important, but they are insufficient when they do not reflect the reality of an organisation’s operations or when they are not backed up by processes, controls, responsibilities and evidence that ensure — and demonstrate — the proper processing of information.
A genuine privacy compliance programme must be based on a precise understanding of the organisation’s processing of personal data.
This involves identifying what information is collected; from whom it is obtained; for what purposes it is used; with whom it is shared; which suppliers are involved; for how long it is retained; what risks it presents; and what measures have been taken to mitigate them.
Based on this assessment, compliance mechanisms must be designed to suit the organisation’s specific characteristics: privacy notices, procedures for obtaining and retaining consent, internal policies, protocols for addressing data subjects’ rights, contracts with suppliers, security measures, rules on data retention and disposal, training programmes, and clear frameworks for accountability and oversight.
But the work does not end there either. An effective programme must be implemented in practice, understood by those involved in data processing, and reviewed periodically to identify regulatory, technological or operational changes that may give rise to new compliance gaps.
Therefore, every organisation should be able to answer the following questions clearly, at the very least:
Do we know exactly what personal data we process and what we use it for?
Have we identified which processing operations pose the greatest risks to individuals and to our own organisation?
Do our privacy notices truly reflect what we do in practice?
Do we have an appropriate legal basis for each processing activity and, where consent is required, can we demonstrate that it was validly obtained?
Do we know what our technology providers do with the information we entrust to them?
Do we assess the risks before implementing biometrics, facial recognition, artificial intelligence or other high-impact technologies?
And, perhaps the most important question: do we have the necessary evidence to demonstrate our compliance to a regulatory authority?
Responsibility cannot be outsourced
Another aspect that deserves special attention is the growing involvement of third parties and technology providers in the processing of personal data.
Nowadays, an organisation may contract platforms, applications, cloud services, authentication tools, biometric solutions or systems developed entirely by third parties. However, outsourcing technology does not necessarily mean outsourcing responsibility.
Organisations must understand and assess the data flows generated by their suppliers, contractually define each party’s responsibilities, establish clear processing instructions, verify the applicable security measures and have adequate oversight mechanisms in place.
The technological sophistication of a tool does not replace the need to analyse how it operates from a legal perspective. Nor does the fact that a solution is widely used in the market mean, in itself, that its specific implementation complies with all the obligations applicable to a particular organisation.
Privacy, therefore, should not be viewed solely as a matter for the legal department or as an isolated review of documentation. It requires the coordinated involvement of legal, technology, commercial, security, human resources and management teams, depending on the nature of each data processing operation.
A particularly relevant issue for the sports industry
In professional sport, the volume and diversity of personal data processed have increased significantly as a result of the industry’s digitalisation.
Clubs, federations, leagues, event organisers and other participants in the sports ecosystem may process information relating to fans, season-ticket holders, players, underage athletes, employees, sponsors and suppliers, through ticketing systems, apps, loyalty programmes, marketing campaigns, video surveillance, access controls, performance-tracking devices, medical records and biometric solutions, amongst many others.
In this context, the FAN ID case serves as a particularly relevant wake-up call. The protection of personal data must be an integral part of the design of sports organisations’ strategies for innovation, security and digital transformation, especially when technologies capable of generating large-scale, continuous or particularly sensitive data processing are used.
However, this warning is not limited to sport. The same questions apply to financial institutions, fintech companies, retailers, hotels, airlines, insurers, educational establishments, hospitals, digital platforms and, in general, any company or organisation that uses personal data as part of its operations.
Prevention is better than cure
Financial penalties are just one of the possible consequences of a deficient personal data protection programme. These may be compounded by regulatory investigations, data subject complaints, operational disruptions, remediation costs and damage to the trust of customers, users, employees and business partners.
For this reason, privacy prevention should no longer be viewed as a purely administrative matter, but as an integral part of corporate governance, risk management and trust.
The FAN ID case offers an opportunity for companies and organisations to critically review their own processes before a regulatory authority does so.
It is not simply a matter of asking whether they have a privacy notice or specific policies in place, but of determining whether their compliance mechanisms truly reflect the way in which they use information and whether they can substantiate, with sufficient evidence, the decisions and measures taken.
Ultimately, the question is simple:
Would your organisation’s privacy programme stand up to scrutiny by a regulatory authority today?
Through its Sports Law practice , Data Protection and Compliance, ECIJA Mexico advises companies and organisations on identifying risks and on the design, review and implementation of preventive compliance models tailored to the reality of their operations, helping them to incorporate privacy by design and to anticipate regulatory contingencies before they materialise.
This article was jointly authored by Ricardo Chacón, Berenice Sagaón and Fernando Poo, members of the Sports Law, Data Protection and Compliance teams at ECIJA Mexico, who have combined their respective expertise to offer a comprehensive perspective on the implications for privacy and sports law arising from the FAN ID case.