The Spanish regulator, AEPD, has stated that preliminary steps to begin an official investigation are being conducted already: https://twitter.com/AEPD_es/status/1006115567227559936
For those who understand Spanish, here's a good technical analysis: https://reversecodes.wordpress.com/2018/06/12/analizando-la-...
The app uses rot(4) to obscure data, includes a debug link with the collected data, and has the Fluzo service api key hardcoded, among other gems.
Your hardcoded credential could then become a cryptographic key that you could rotate on app upfates.
I am not sure how many apps actually go through this trouble.
Now that they need your consent, they have named this feature "protect your team!" since the teams get royalties from bar licenses...
Edit: The official statement actually answers this
>The codes will not refer to your name, but to your IP address and the specific ID assigned by the PPP when you register.
However, that by itself doesn't mean you can't collect it, just that you need to have specifically asked for their informed consent and not hidden this purpose away in a changelog.
Does GDPR generally allow you or your apps to collect information that helps identify legal and moral transgressions around you?
What if you are watching the game at a friend's house? The collection is definitely going to have some false positives.
In that case the coordinates would identify your friend.
It seems like deputizing devices to spy on others. Regardless if those others may be doing something wrong or are caught up by accident, it seems like the sort of thing data protection would prevent.
This will be a good test of real competing interests. I don't know that privacy should win in the end here, but both sides actually have powerful prima facie cases to make.