I'll have to look that up, but as someone else said it's only enforced at EU member state level, however there is another central oversight to ensure it's enforced.
I'll have to look that up, but as someone else said it's only enforced at EU member state level, however there is another central oversight to ensure it's enforced.
This is almost certainly a thought experiment though, the amount of engineering effort required to ensure no logs of any kind could result in deriving the IP address of the user would be high, and they’re probably not doing it (even if they are actually not sending any identifying information directly).
You might also find that you have to take special care to avoid creating circumstances that allow inference of personal information. For example, sampling every night at 11pm, you’re very likely to be able to determine an address or approximate location of the subscribers home.
Specific Permissions and Uses
Personal Information:
The app collects your personal data, such as your email, to allow you to log in, register for services, and provide you with content and information about your favorite teams.
Device or other IDs:
This type of ID is used to facilitate your registration and access to the app.
Location Data:
The app may use your phone's location to identify establishments showing football matches, potentially for a piracy detection feature.
Audio/Microphone Access:
In the past, La Liga has used the official app to remotely activate the microphone to detect audio from football matches, particularly in bars.
What I'm saying is that it is possible to build a system where the app dispatches some kind of event to a server which does not have any identifying information associated with it.
I have worked as an enterprise integratation architect in highly regulated environments. Sometimes you reuse interfaces that give you tons of info you are not supposed to have access to. You sign contracts that you will never look at this (dump it at the interface layer). This is acceptible in compliance.
Chances that in this case the app does not hover up all it can? 0%
What matters in terms of processing is how much of it gets sent to LALIGA (or their provider).
On a separate note, I am surprised you think you can just promise not to look at something. You can’t, it’s not “acceptable in compliance”, and I’m not even sure what that means—there’s no body that certifies GDPR compliance.
But there’s plenty of evidence suggesting you would be wrong. The biggest fines under GDPR have been for Meta, Amazon, TikTok, Uber, LinkedIn.
Even outside of tech you don’t have to look too far down the list to find H&M, British Airways, Marriott Hotels, Vodafone…
https://www.enforcementtracker.com
This example specifically refers to failure to adequately secure systems against unauthorised use: https://www.enforcementtracker.com/ETid-2306
This one is even closer to what you’re saying—Vodafone didn’t do enough to monitor third parties working for them: https://www.enforcementtracker.com/ETid-2646