Last updated: 20 July 2026.
Quick answer. Under Spanish law, personal data is not merchandise a company can own outright: the only “owner” of the right is always the individual the data refers to. A business is the “file holder” and decides the purpose, but the power of disposal stays with the person. Aggregated, anonymised Big Data and predictive reports, however, can become a protectable business asset (sui generis database right, trade secrets). This guide sets out 10 keys backed by case law and the AEPD. (Updated July 2026.)
Strategic Document: The 10 Essential Points on “Data Ownership” in Business
There is a common misconception in the business world: believing that databases of clients, employees or users “belong” to the company. To avoid legal risks while protecting their technology investments, business owners must master the following 10 fundamental points on who the true owner of the data is, backed by legislation, case law and the Spanish Data Protection Agency (AEPD).
There is no “commercial ownership” of personal data
Under the Spanish legal system, personal data is not merchandise that can be bought, sold or owned absolutely by a company. The holder and sole “owner” of the right is always the individual from whom the data is collected.
- Case law: Constitutional Court, Plenary, Judgment No. 292/2000, of 30 November 2000.
Ownership translates into a “power of disposal and control”
Data protection is an autonomous fundamental right (distinct from the right to privacy) that does not grant a classic title of ownership, but a power of disposal and control over one’s own information. It is the citizen, and not the company, who retains absolute power to decide what is done with their data, being able to object to its use or demand that it cease.
- Case law: Supreme Court, First Chamber, Judgment No. 318/2022, of 20 April 2022.
- Case law: Supreme Court, First Chamber (Plenary), Judgment No. 383/2025, of 13 March 2025.
The company is the “file holder”, but not the owner of the information
There is a radical difference between managing a database and owning its content. The company establishes itself as the “owner of the file” (in management terms, as the Data Controller) and decides on its purpose, but the “power of disposal” over the data it holds belongs solely to the data subject.
- AEPD: Archiving Decision E/00250/2012, of 2012.
Omitting information usurps the user’s ownership (control)
Business owners cannot carry out processing without informing the citizen, regardless of whether the data originates from an official or public publication. Omitting prior information creates a “defect of consent” and frustrates the data subject’s ability to control (to exercise their ownership over) the fate of their data.
- AEPD: Penalty Decision R/01580/2010 (File PS/00102/2010), of 26 July 2010.
- AEPD: Penalty Decision R/01520/2010 (File PS/00730/2009), of 7 July 2010.
Structuring third-party data means assuming liability towards its owner
Even if a company receives data from another entity or a public source to provide a service (such as a pharmacy receiving health data from care homes), if the business owner carries out acts of structuring or organisation, it is causing a “loss of control and disposal” by the holder over their information. It therefore assumes direct liability towards the citizen.
- AEPD: Penalty Decisions EXP202414356 (File PS/00177/2025) and EXP202414366 (File PS/00190/2025), both of 26 March 2025.
For health data, the owner requires “full traceability”
In the case of extremely sensitive databases (such as medical records), the “owner” of the data enjoys a reinforced transparency standard. The right of access is configured as a “highly personal power of control” whereby the holder is entitled to know the exact traceability (identity of the professionals, date and reasons) of who has consulted their data within the company’s or administration’s system.
- AEPD: Decision PD-00068-2026 (File EXP202518019), agreement of 10 March 2026.
Invasive technologies (biometrics): physical identity cannot be expropriated
A company never acquires the right to impose or trade in the “mathematical templates” of its clients’ or employees’ fingerprints or faces. If a mandatory biometric system is imposed without a traditional alternative, the user’s control over their most intimate data is entirely nullified, constituting a serious infringement, since the citizen is the sole owner of their biometrics.
- AEPD: Penalty Decision EXP202313347 (File PS/00289/2024), of 20 May 2025.
The right to “data quality” as a manifestation of ownership
The control the holder exercises over their data requires that it be rigorously accurate. If a company keeps inaccurate information (for example, false identities on prepaid cards), it is breaching the quality principle and harming the citizen’s dominion over their public representation or their financial reputation.
- AEPD: Penalty Decision R/03379/2015 (File PS/00518/2015), penalty of 2015.
- Case law: Supreme Court, Contentious-Administrative Chamber, Judgments No. 121/2019 of 5 February 2019, and No. 1690/2019 of 10 December 2019.
Big Data and aggregation DO generate a commercial ownership right
Although the individual datum belongs to the individual, when a company massively aggregates thousands of data points and anonymises them (removing any link to the individual), that “macro” information falls outside personal data protection rules. The business intelligence and trends created generate a protectable asset in favour of the company that made the technical and financial investment.
- Legislation: Intellectual Property Law, Article 133 (Sui Generis right over databases).
- Source: Legal Note “Processing and Ownership of Data” (ILP Abogados).
Predictive reports are the company’s “Trade Secrets”
As a result of ownership over Big Data, the algorithms and predictive reports created through the massive analysis of user data (for example, on intermediary platforms) are the property of the platform that created them. Neither individual users nor collaborating entities (franchises, partners) can claim rights over the network’s global information.
- Legislation: Law 1/2019, of 20 February, on Trade Secrets.
- Source: Legal Note “Processing and Ownership of Data” (ILP Abogados).
Not sure whether your customer or employee databases are being handled lawfully? Getting data ownership wrong exposes you to AEPD fines. We review who controls your data and how you document it. Write to us and let’s look at it.
Frequently asked questions
The company is the “file holder” and decides its purpose, but it does not own the personal data. Under Spanish law the only “owner” of the right is each individual, who keeps the power of disposal and control over their data.
No. Personal data is not merchandise that can be owned absolutely (Constitutional Court 292/2000). What a company may commercialise are aggregated, anonymised datasets, not the personal data of identifiable individuals.
Yes. Once thousands of data points are massively aggregated and anonymised, that “macro” information falls outside data protection law and becomes a protectable business asset (sui generis database right, art. 133 of the IP Law).
Yes. Predictive reports and algorithms built from mass data analysis are the platform’s trade secrets (Law 1/2019). Individual users or partners cannot claim rights over the network’s global information.
Omitting the required information usurps the individual’s control over their data and creates a “defect of consent”; the AEPD has penalised it even when the data came from official or public sources.
Not without a real alternative. A company never acquires the right to trade in the “mathematical templates” of fingerprints or faces; imposing mandatory biometrics with no alternative is a serious infringement (AEPD PS/00289/2024).
Contact
Don’t be left in doubt, get in touch. We’ll be happy to help and offer you solutions.

