Last updated: 27 July 2026.
Quick answer. When you obtain personal data from a source other than the data subject (a third party, a public register, a data broker), Article 14 of the GDPR requires you to inform them: who you are, what data you process, for what purpose, the legal basis and where you obtained it. The deadline is one month at most (or sooner if you are going to disclose the data or contact the data subject). Only a few strictly defined exceptions release you from this duty. This guide brings together more than 70 questions with the doctrine of the AEPD and the EDPB. (Updated July 2026.)
Introduction
Data enrichment, scoring, profiling and marketing: a practical compliance guide for data controllers, DPOs and legal advisers 70 questions and answers on Article 14 of the GDPR for businesses that purchase, cross-reference and utilise data Methodological note on sources: This FAQ is based on: (i) the text of Article 14 of the GDPR and its recitals (60–62, and 47, 48 and 70), Article 12 of the GDPR, the LOPDGDD (Articles 11, 20, 72(1) and 74(a)) and the WP260 rev.01 Transparency Guidelines of the Article 29 Working Party/EDPS; (ii) the penalty decisions of the AEPD analysed — PS/00240/2019 ((***), SA, €1,000,000, in express breach of Article 14), PS/00070/2019, PS/00477/2019; PS/00021/2021, PS/00587/2021 ((***), Articles 5.1 and 32) and PS/00331/2022; and (iii) the three court rulings submitted and read in full: Supreme Court Judgment (Chamber 3) 1620/2020, dated 26 November 2020, Supreme Court Judgment (Chamber 1) 333/2026, dated 3 March 2026, and Supreme Administrative Court Judgment of 28 April 2022, Case No. 392/2021 (electronic service and finality). For the sake of completeness, it should be noted that decisions PS/00021/2021, PS/00587/2021 and PS/00331/2022 do not uphold Article 14: they are cited here for their doctrinal value in related matters (processing initiated without contact with the data subject, security and design).Section 1: General obligations regarding information and transparency
(Article 14)
Q1.1. When does Article 14 apply instead of Article 13?
Whenever the data has not been obtained from the data subject themselves: purchase or rental of databases, transfers between companies, collection of newsletters and registrations, web scraping, data communicated by a creditor, data provided by another person (a family member, an employer, an impersonator) and, in accordance with the transparency principle set out in WP260, data inferred or created by the data controller (profiles, scores). The practical rule: if the data subject did not provide the data, Article 14 applies.Q1.2. What information does Article 14 specifically require that Article 13 does not?
Three distinguishing elements: the categories of data processed (14.1.d — the data subject does not know what has been collected about them), the source from which the data originates and whether it is publicly available (14.2.f), and — common to Article 13 but critical here — the identification of the specific legitimate interests where the legal basis is Article 6(1)(f) (14.2.b). The AEPD fined XXX (PS/00070/2019) and YYY (PS/00477/2019) €2 million each, amongst other reasons, for providing generic and imprecise information on these points.Q1.3. Within what timeframe must information be provided?
Three time limits run concurrently, and the first to expire applies (Article 14(3)): (a) a reasonable period, not exceeding one month from the date of collection; (b) if the data is to be used to communicate with the data subject, no later than the first communication; (c) if the data is to be transferred, no later than the first communication to another recipient. In the EEA case (PS/00240/2019), data from the Judicial Incidents Register was accessed by banks without the data subject ever having been informed: a breach had taken place.Q1.4. What form should the information take: is it sufficient simply to publish a privacy policy on the website?
No. Article 12 requires information to be concise, transparent, intelligible, easily accessible and in plain language, and Article 14 requires that it be provided to the data subject, not merely made available in case they seek it out. Publication on the website is a supplementary measure (and a compensatory one in the exceptional case of Article 14(5)(b)), not the standard procedure. The standard procedure is a direct communication (letter, email, text message with a link to the full information).Q1.5. Is ‘layered’ information valid?
Yes: the first layer contains the basic information (identity of the data controller, purpose, exercise of rights, and —crucially under Article 14— the source and categories of data) and a reference to the full information (Article 11 of the LOPDGDD and WP260). The first layer must not omit anything essential nor contradict the second layer: the banking sector was criticised for inconsistencies across channels in the aforementioned rulings.Q1.6. If several companies are involved (transferor, transferee, platform), who is responsible for providing the information?
Each controller is responsible for its own processing. The data transferor must provide information (Art. 13 or 14, depending on how the data was obtained) regarding the transfer and the recipients; the transferee must provide information under Article 14 within its own timeframes, and cannot rely on the fact that ‘the party who sold the data to me has already provided the information’, unless it can be shown that the data subject already has all the required information regarding the new processing (14.5.a). If there is joint liability (Article 26), the agreement must specify who is responsible for providing the information, but both parties remain liable to the data subject.Q1.7. Can I delegate the obligation to provide information to my sales network, a data processor or the data provider?
You may delegate the practical implementation, but never the liability. The doctrine of non-delegability was strictly applied in the SIM fraud case: XXX was held liable for its distributors’ failure to carry out verification checks (PS/00021/2021, €900,000). Apply the standard: if your data provider “undertook to report” and failed to do so, the penalty will fall on you.Q1.8. How do I prove that I reported?
The burden of proof lies with you (Art. 5.2, proactive liability). Keep a record of: the list of recipients, the exact wording of each version of the clause, the channel used, the date of dispatch and proof of delivery. Without such a record, mounting a defence in disciplinary proceedings is practically impossible. Unlike security — where the Supreme Court has clarified that the obligation lies with the media — reporting is an obligation requiring a verifiable outcome. ⚠️High risk. Failing to provide information at all constitutes a very serious infringement (Article 72.1.h of the LOPDGDD, subject to a 3-year limitation period); incomplete reporting is a minor offence (74.a), but ‘minor’ does not mean cheap: the fines imposed on (***), SA and (***), SA for reporting deficiencies amounted to €2,000,000 each.Section 2: Sources of data and their impact on the duty to provide information
Q2.1. The data appeared in an official gazette or a public register: do I still have to provide information?
Yes, always. The fact that the source is publicly available does not constitute any of the four exceptions under Article 14.5; on the contrary, Article 14.2.f requires an express statement that the data originates from a publicly accessible source. This is the central principle of the ruling (***), SA (PS/00240/2019): a fine of €1 million, a prohibition on processing and an order to delete the data file. Under the 1999 Data Protection Act (LOPD), there was a more lenient regime for files based on public sources (Article 29(1)), which, according to Supreme Court Ruling 333/2026, still applies to older entries; that regime does not exist under the GDPR.Q2.2. What if the data was published by a public authority for a specific purpose (a public notice, a list of debtors)?
Worse still: in addition to the duty to inform, its reuse for another purpose (creditworthiness, marketing, business intelligence) must satisfy the compatibility test set out in Article 6(4) and comply with the purpose limitation principle (5.1(b)). The AEPD demonstrated that it was incompatible to convert public notices — the purpose of which is notification to ensure access to justice — into a creditworthiness file, compounded by inaccuracies (a ‘debt’ was recorded without specifying the amount, origin or status, Article 5(1)(d)).Q2.3. Can I purchase ‘commercial lists’ or databases from a data broker?
Only with documented due diligence: lawful origin of each record, the data provider’s legal basis, the information notice provided by the data provider (did it mention the transfer to companies such as yours, identified by name or by category?), date of collection and the channel for exercising rights. And even then, you must comply with your own Article 14: provide information within one month or before the first use. Buying the list does not guarantee compliance.Q2.4. Can I use data extracted from social media or the open web (scraping)?
The fact that a profile is public does not make the data freely reusable: you still require a legal basis (a legitimate interest that is unlikely to prevail in the case of mass data collection), proof of compatibility with the purpose for which the data was published, and compliance with Article 14 in respect of each data subject. At scale, this is almost always unfeasible: the exception for disproportionate effort is not granted on the basis of volume alone (Q9.3).Q2.5. What about data transfers within my business group?
Recital 48 recognises a possible legitimate interest in intra-group transfers for internal administrative purposes, but this does not provide any exemption: the receiving entity obtains data ‘not from the data subject’ and must comply with Article 14, and the transferring entity must disclose those recipients. The ‘single group customer’ approach, without any explanatory information to back it up, is precisely the model for which the banking sector has been penalised.Q2.6. Sector-specific example — pharmacy aggregator.
A platform that receives orders and forwards them to affiliated pharmacies generates two data flows under Article 14: the pharmacy receives data from a customer who does not recognise it (it must inform the customer upon the first dispensing or communication), and the aggregator may receive purchase histories from the pharmacies for analysis. If the history reveals medication, health data is present (Art. 9): the legal basis cannot be a mere legitimate interest; commercial exploitation is, in principle, prohibited without explicit consent, and the required security standard is the enhanced one set out in PS/00587/2021 for health data. Define by contract who is the controller, joint controller or processor for each data flow, and who reports what.Q2.7. Sector-specific example — gym using wearables.
A gym that receives customer metrics — heart rate, sleep, activity — from the device manufacturer (or its app) obtains data from a third party (Art. 14) as well as health data (Art. 9): it requires explicit consent for purposes that go beyond the contracted service, specific information on data categories, the source (the wearable device supplier) and the profiles it creates (‘fitness score’, risk of dropout). Using these metrics for marketing supplements or for insurance premiums outside the scope of the contract constitutes further processing, which requires a compatibility assessment and prior information (14.4) — and probably new consent.Q2.8. A third party contracted a service by providing another person’s data (or impersonating them). Which regime applies?
This is the exact opposite of Article 14: the data subject was never the source and was not informed. The AEPD sanctions such cases on the grounds of a lack of legal basis (Article 6(1)) or a failure to implement adequate identity verification measures (Article 5(1)(f)): (***), SA, €900,000 for duplicate SIM cards issued without sufficient verification (PS/00021/2021), as part of a series of fines running into millions against other operators. Implement enhanced identity verification for remote contracts and binding protocols with the distribution network. Checklist for onboarding a new data source Identify the source and classify it (data subject / private data provider / public source / inference / group). Verify the legal basis of both the organisation and the data provider; obtain contractual evidence of the information provided at source. Carry out the compatibility test (6.4) if the purpose differs from the original one. Schedule notification under Article 14 prior to first use or transfer and, in any event, within 30 days. Register the source in the Register of Activities and in the information clause (14.2.f).Block 3: Data enrichment and database merging
Q3.1. Does ‘enriching’ my CRM with external data constitute a new processing operation?
Yes, and in two respects: it is an indirect collection (Article 14) and, with regard to the purpose for which the source provided the data, it constitutes further processing (Articles 6(4) and 14(4)). It must pass the compatibility test, notification must be provided before carrying it out, the information clause must be updated (new categories and new source) and the accuracy of the imported data must be verified (5.1.d). Q3.2. What tends to go wrong in practice with data enrichment projects? Four patterns that have led to sanctions: (i) assuming that the generic website policy constitutes sufficient notification (XXX); (ii) assuming that public data does not require any action (XXX); (iii) enriching the data first and providing information afterwards ‘if anyone asks’ (in breach of 14.3 and 14.4); (iv) losing the context of the data when importing it (a ‘debt’ with no amount or status: inaccuracy under 5.1.d, criticised in PS/00240/2019 and also decisive in the civil proceedings of Supreme Court Ruling 333/2026).Q3.3. Can I merge the customer database of an acquired company with my own?
The corporate transaction will not transfer compliance obligations. A prior audit is required (what was disclosed, on what basis, for what purposes), notification under Article 14 of the new liability to all data subjects before using the data, and proof of compatibility if the purposes change. This is also the time to weed out unverifiable consents: remember that the burden of proving consent lies with the data controller (a well-established legal principle upheld by Supreme Court Judgment 26 November 2020).Q3.4. What about cross-referencing my own internal databases (customers + website + app + shop)?
If all data was collected from the data subject with information promoting the ‘single view of the customer’, Article 13 applies as amended. If any data flow originated from third parties (e.g. data from a gym wearable, orders via a pharmacy aggregator), that data flow falls under Article 14. Any cross-referencing that generates new inferred data (habits, propensities) must be declared as a data category and, if it feeds into automated decision-making, Article 14(2)(g) applies.Q3.5. What should I require contractually from my data enrichment provider?
The source and lawfulness of each field; a verbatim copy of the information clauses used during collection; a guarantee that your company was listed as a recipient (either identified or by an unambiguous category); a mechanism for synchronising erasures and objections (Article 19); and indemnity. And even once everything has been signed, plan your own notification under Article 14: the contract protects you financially, not administratively. ⚠️High risk. The corrective power under Article 58(2)(fyg) allows the AEPD to prohibit processing and order the deletion of the enriched dataset, as it did with the FIJ of (***), SA: the loss of the asset usually costs more than the fine.Block 4: Scoring and automated evaluation
Q4.1. Is the score you calculate for an individual ‘personal data’ that you are required to disclose?
Yes: it is data created by you, not obtained from the data subject, and must be included among the data categories in your clause (14.1.d) alongside the existence of profiling and the logic applied (14.2.g). Failing to disclose inferred data was one of the information shortcomings identified in the banking sector.Q4.2. When does a scoring system constitute an ‘automated decision’ under Article 22?
Following the CJEU judgment of 7 December 2023 (SCHUFA, C-634/21), when the score is communicated to a third party who relies on it decisively (to grant or refuse credit, a contract or a policy), the very process of calculating the score constitutes the decision: it requires a qualified legal basis (22.2), meaningful information on the logic, significance and consequences, and the right to human intervention.Q4.3. What further requirements does Spanish law impose on negative credit scoring?
Article 20 of the LOPDGDD: a certain, due and payable debt that is not disputed; a prior demand for payment; notification to the data subject of the possible inclusion in the database and notification of such inclusion within 30 days; and a maximum retention period of five years. Note the transitional regime: for entries prior to 2018, the First Chamber applies the 1999 LOPD and distinguishes between creditors’ files (Article 29(2), subject to all these requirements) and those from public sources (Article 29(1), not subject to them) — Supreme Court Judgements 434/2023 and 333/2026. For current inclusions, the standard is that of the GDPR plus Article 20 of the LOPDGDD, without the exemption provided for in Article 29.1.Q4.4. Can I carry out commercial analyses (purchase propensity, churn risk) using enriched data?
Only if: the external source was compatible (6.4), the data subject was informed that your company was the recipient, you complied with Article 14 before scoring, the clause states the profiling and its logic, and the data subject can object with a single click (Article 21; if the scoring feeds into marketing, unconditional right to object, Q6.2). Example: a gym’s ‘dropout rate’ calculated using data from a wearable device adds the layer of Article 9 — explicit consent.Q4.5. What does ‘meaningful information about the logic applied’ mean?
Not the formula or the code, but rather: the main variables used, their source, the nature of their influence, the score range and the practical consequences (which decisions they influence). ‘We use advanced algorithms’ is precisely the kind of vagueness penalised as a lack of transparency.Section 5: Profiling and automated decision-making
Q5.1. Is all profiling subject to Article 22?
No. Profiling (Article 4(4)) is lawful provided there is a legal basis, transparency and respect for rights; Article 22 applies only to decisions based solely on automated processing with legal or significant effects. However, all profiling, whether or not it falls under Article 22, must be disclosed (Article 14(2)(g), first part) and must comply with the right to object under Article 21(1) with balancing of interests, or under Article 21(2) without such balancing if it is used for marketing purposes.Q5.2. Does ‘human intervention’ exempt me from Article 22?
Only if it is genuine: someone with the competence and authority to change the outcome, who assesses factors other than the score itself. An employee who clicks ‘accept’ on the system’s recommendation does not constitute human intervention; and following the SCHUFA ruling, if the external score de facto determines the end customer’s decision, the liability under Article 22 extends to whoever compiles it.Q5.3. When do I need a DPIA for profiling?
Whenever there is systematic and comprehensive evaluation with significant effects, large-scale monitoring, sensitive data or cross-referencing of sources (Article 35(3) and the AEPD list): mass data enrichment + scoring almost always falls within this scope. The DPIA must specifically examine how Article 14 will be complied with (channel, time limit, evidence); failure to do so aggravates liability in a case.Q5.4. Example — pharmacy/data aggregator.
A ‘treatment adherence’ or ‘chronic patient’ profile constructed from dispensing records constitutes profiling using health data: explicit consent (9.2.a), enhanced information, a mandatory DPIA and a practical prohibition on its use for advertising purposes without such consent. The penalty imposed on (***) (PS/00587/2021) underscores the standard of protection required for health data, even against unauthorised access.Section 6: Direct marketing, advertising and segmentation
Q6.1. Can I carry out direct marketing on the basis of legitimate interest, without consent?
It depends on the channel and compliance with information requirements. The Supreme Court (STS 1620/2020, case (***), SL) established the legal principle: recital 47 does not create a presumption of lawfulness; legitimate interest requires a meticulous case-by-case assessment taking into account the data subject’s reasonable expectations, and only applies if the controller proves that it communicated the specific legitimate interests and the right to object explicitly, clearly and separately (recital 70, Articles 13, 14 and 21). Without such proof, the processing is unlawful — thus confirming the fine of €60,000 imposed on (***), SL and rejecting the favourable retroactive application of the GDPR.Q6.2. What is distinctive about the right to object in the context of marketing?
It is unconditional: once the right to object has been exercised, processing ceases without any possibility of balancing interests (Articles 21(2) and (3)), including any associated profiling. It must be offered free of charge, at any time, and communicated separately from any other information. Retain the minimum necessary data to comply with the opt-out (internal suppression list).Q6.3. What about advertising opt-out lists (such as ‘Robinson’ lists)?
Article 23 of the LOPDGDD requires that opt-out systems be checked before every campaign targeting non-customers. Failure to check them in itself invalidates the legitimate interest assessment.Q6.4. Email and SMS: is the GDPR sufficient?
No: Article 21 of the LSSI also applies — electronic commercial communications require prior consent, except for existing customers regarding products similar to those already purchased, provided there is always an unsubscribe option in every message. A list purchased for mass emailing simultaneously breaches the LSSI, Article 6 and Article 14: a three-pronged risk of penalties.Q6.5. I hired an agency for the campaign: who is liable?
Whoever sets the parameters for segmenting the target audience is the data controller; the advertiser commissioning the campaign must also ensure that the database used was lawfully collected. In the case of (***), SL, the National Court and the Supreme Court confirmed — on the basis of circumstantial evidence — that the alleged ‘data processor’ was in fact the data controller, lifting the veil on a network of companies. Contracts do not alter reality.Q6.6. Can I upload my customer database to a social media platform to create custom or lookalike audiences?
Only if your privacy notice disclosed that data would be shared with the platform (identified recipient), with an appropriate legal basis (for matching with email addresses, consent being the prudent standard) and a joint liability agreement with the platform. ‘Lookalike audiences’ also involve profiling third parties who have never provided you with data: require the platform to comply with Article 14 and document the sharing of data.Q6.7. Example — gym.
Sending former members an offer to rejoin: a defensible legitimate interest (pre-existing relationship, reasonable expectation) provided that, when the data was collected, they were informed of its commercial use, the LSSI is complied with (they were customers; similar product), the opt-out list is checked, and each mailing includes an option for immediate unsubscription. Sending them offers from a ‘partner’ insurance company using their activity data from a wearable device: data transfer + health data + new purpose = explicit consent or nothing.Section 7: Legal basis and its relationship with transparency
Q7.1. What is the relationship between the legal basis (Art. 6) and the duty to inform (Art. 14)?
These are separate and cumulative obligations: the AEPD imposed separate fines for an inadequate legal basis (Art. 6) and inadequate information (Arts. 13–14) on XXX (€3 million + €2 million) and ZZZ (€4 million + €2 million). Compliance with one does not remedy the other; furthermore, failure to comply with the duty to provide information undermines the legitimate interest (Q7.2).Q7.2. Why is the legitimate interest described as a ‘self-assessing’ legal basis?
Because its validity depends on the data subject being able to object, and they can only object if they have been informed. This is the core reasoning of the Supreme Court judgement of 26 November 2020: Article 6(1)(f), read in conjunction with recitals 47 and 70, requires the specific legitimate interests and the right to object to be communicated; without such proven communication, the balancing test fails and the processing becomes unlawful.Q7.3. Can I rely on the consent that the data subject gave to my data provider?
Only if that consent was given in an informed manner in relation to you: the source clause should have identified the assignees or unambiguous categories that include you, and you must retain evidence of this (text, date, method). A generic consent “to third-party collaborators” does not cover you. And in any case, Article 14 remains outstanding.Q7.4. Is legitimate interest sufficient grounds for processing data from public sources for creditworthiness or business intelligence purposes?
The CJEU ruling in ASNEF (C-468/10 and C-469/10) prevents the legislator from categorically requiring that the data appear in public sources in order to recognise a legitimate interest — but that does not make the public source a free pass: under the GDPR, the assessment is on a case-by-case basis, the original purpose is a limiting factor (Q2.2) and transparency is conditional (Q7.2). The combined outcome (***), SA (administrative) / STS 333/2026 (civil, under the old regime) marks the temporal boundary: what Article 29.1 of the LOPD tolerated is now subject to full disclosure and compatibility requirements under the GDPR.Section 8: Exercising rights in these contexts
Q8.1. How should I respond to a request for access (Art. 15) regarding data I have purchased?
Everything set out in Article 15(1), including subparagraph (g): the available information on the origin of the data. ‘Source unknown’ amounts to an admission of non-compliance with Article 14(2)(f) and the record of processing activities. Also include inferred data (scores, segments) — these are the data subject’s personal data.Q8.2. How do I handle an objection or erasure request when the data came from a broker and was transferred to others?
Cease processing (immediately if it is for marketing purposes, 21.2), erase the data if applicable (17) and notify each recipient to whom the data was disclosed of the rectification or erasure (Art. 19), informing the data subject of those recipients if they so request. Agree with the supplier on the two-way dissemination of unsubscriptions: this is the first thing the inspectorate checks.Q8.3. Can the data subject claim damages as well as lodging a complaint with the AEPD?
Yes: civil proceedings for infringement of honour (Organic Law 1/1982) are a separate matter and are extremely common in credit reference files (compensation for non-pecuniary damage). Supreme Court Ruling 333/2026 defines the scope of this under the 1999 Data Protection Act (LOPD) regime (files based on public sources: no obligation to notify inclusion and a presumption of the accuracy of the official publication — in that case (***), SA won), but for entries under the GDPR, the civil law framework will be governed by the strict standard (information, quality, Article 20 of the LOPDGDD): the dual penalty of a fine plus compensation is a real possibility.Q8.4. What time limits and procedures apply to responding to data subject rights?
One month, extendable by a further two months due to complexity (Article 12.3), free of charge, via accessible means, with proportionate identification of the data subject. Failure to respond on more than one occasion triggers an almost automatic investigation: rights are the route through which breaches of Article 14 come to light.Section 9: Exceptions to the duty to inform and practical limitations
Q9.1. “The data subject already has the information” (14.5.a): when can I invoke this?
Only if you can prove that you have all the information that can reasonably be expected regarding your data processing (data controller, fines, categories, source, retention periods, rights). The fact that the data provider informed you of the collection of your data does not imply that they informed you of how your data is being processed.Q9.2. Do the grounds of impossibility or disproportionate effort (14.5.b) apply if I have millions of records?
Almost never. The exception was designed primarily for archiving, research and statistical purposes (89.1); it requires a documented assessment of the balance between the effort involved and the impact on the data subject; it does not apply if you have — or can obtain from the data provider — contact details; and even if it does apply, it requires compensatory measures, notably making the information public. (***), SA invoked this provision and the AEPD rejected it: the cost of providing information on a large scale is a cost inherent to the business model.Q9.3. What is a ‘documented assessment’ under Article 14(5)(b)?
A previous, dated document that quantifies: the number of data subjects affected, available contact details, actual cost per channel, the impact of non-disclosure on their rights (will they be able to find out by other means? Are there decisions that affect them?), compensatory measures adopted, and periodic review. Without such a document, the exception is a defensive manoeuvre, not a genuine exception.Q9.4. What about the exceptions relating to statutory provisions (14.5.c) and professional secrecy (14.5.d)?
Point (c) covers information obtained or communications expressly established by law with safeguards (communications to the CIRBE, tax obligations or anti-money laundering obligations — the context of the AML/CFT documentation that underpinned the sanction against OOO, PS/00331/2022, although in that case the sanction was for the insecure design of the channel). Subparagraph (d) protects professionally regulated confidentiality (lawyers, healthcare professionals): the pharmacy cannot use it to justify its commercial practices, but only to avoid disclosing information covered by its duty of confidentiality.Q9.5. Is there an ‘information from a public source’ exception?
No. We emphasise this because it is the most costly mistake in the market: it is not included in Article 14.5, and invoking it has cost one million euros and an entire data file (PS/00240/2019).Section 10: Documentation, records, DPIA and compliance measures
Q10.1. What should my Record of Processing Activities (Art. 30) include in relation to processing from external sources?
For each activity: the source (with name), categories of data —including inferred data—, legal basis by purpose, recipients, retention periods, and a reference to the current privacy notice and the method of delivery. Inconsistencies between the Activity Log, privacy notices and actual operations are the very issues that the supervisory authority will focus on during an inspection.Q10.2. What additional documentation is required for legitimate interest?
The balancing test (LIA) for each processing operation: specific interest, necessity, balance with rights and expectations, safeguards (enhanced transparency, easy right to object). The Supreme Court ruling of 26 November 2020 makes the ‘meticulous assessment’ referred to in recital 47 an operational requirement; without a written LIA, the legal basis is presumed not to have been assessed.Q10.3. When is a DPIA mandatory and what must it state regarding Article 14?
Where profiling has significant effects, is carried out on a large scale, involves sensitive data or combines multiple data sources (Article 35 and the AEPD list). It must include the information plan: channels by data subject group, deadlines (matrix 14.3), text of the layers, proof of delivery, handling of undelivered data and exceptions invoked with their justification.Q10.4. What role does privacy by design play (Article 25)?
It is a standalone obligation — independent of the security provisions of Article 32, as emphasised in Resolution XXX (PS/00331/2022, €2.5 million) —: data enrichment flows must be designed with the information layer, traceability and the propagation of rights built in before the system is activated, not patched in afterwards.Q10.5. What contracts do I need?
With data processors, the full requirements of Article 28 (instructions, security, sub-processing, audit). With data providers, a data transfer agreement documenting the lawfulness of the data’s origin, information clauses regarding the origin, the inclusion of your company as a recipient, the synchronisation of rights and indemnities. With joint controllers (platforms, aggregators), the agreement under Article 26 with an express allocation of the duty to inform.Q10.6. How will legal proceedings affect me if a case is brought against me?
Keep an eye on your email inbox: legal persons (and entities without legal personality, such as communities) are obliged to communicate electronically; notification not accessed within ten days is deemed to have been rejected; time limits continue to run; the decision becomes final and the merits of the case are no longer open to challenge; the only remaining recourse is enforcement proceedings (Supreme Administrative Court ruling of 28 April 2022). Many cases are lost due to the calendar, not because of Article 14.Section 11: Penalties, real-life cases and lessons learnt
Q11.1. What penalty framework applies to non-compliance with Article 14?
Article 83(5)(b) of the GDPR (up to €20 million or 4 per cent of total annual global turnover, whichever is higher). The LOPDGDD classifies offences as follows: failure to fulfil the duty to inform = very serious (72.1.h); incomplete information = minor (74.a). The powers set out in Article 58.2 apply: requiring rectification, restricting or prohibiting processing, and erasure of data.Q11.2. Cases you need to be aware of.
| Case | Offence and measure | Lesson |
| PS/00240/2019 (26 April 2021) | Sections 5.1.ad, 6.1 and 14; €1,000,000 + prohibition of the FIJ + removal | The fact that the source is public does not exempt the organisation from reporting; the purpose of the publication imposes restrictions; the data set may disappear. |
| PS/00070/2019 (11 December 2020) | Art. 6 (€3 million) + Arts. 13–14 (€2 million) | A general failure to provide information constitutes a separate offence; categories, sources, interests and profiles must be declared. |
| PS/00477/2019 (13 January 2021) | Art. 6 (€4 million) + Arts. 13–14 (€2 million) | Consistency across channels and specificity by purpose/legal basis. |
| PS/00047/2016, upheld by Supreme Court Judgment 1620/2020 | Art. 6 LOPD; €60,000 | Legitimate interest does not justify marketing without proven information and opposition; circumstantial evidence is sufficient to identify the actual data controller. |
| PS/00021/2021 (1 February 2022) | Art. 5.1.f; €900,000 | Data processing arising from identity theft: identity verification cannot be delegated within the sales network. |
| PS/00587/2021 (18 November 2022) | Arts. 5.1.f and 32 | Enhanced standard for health data (relevant to pharmacies, aggregators and wearables). |
| PS/00331/2022 (28 July 2023) | Sections 25 and 32; €2,500,000 | Data flow design is a standalone obligation: privacy by design must be in place before operations commence. |
| Supreme Court Ruling 333/2026 | The appeal lodged by XXX is upheld (under the 1999 Data Protection Act, file 29.1) | Civil proceedings are available and widespread; their outcome depends on the applicable time limits and the type of data file. |
| Supreme Administrative Court 28 April 2022 | Confirms enforcement proceedings following final judgement | The management of electronic notifications forms part of compliance. |
Q11.3. What factors aggravate or mitigate the fine?
Article 83(2): nature, severity and duration; intent or negligence; mitigating measures; degree of cooperation; categories of data affected; manner in which the authority became aware of the breach; benefits obtained. In the cases cited, the duration, the structural nature (affecting the entire operation, not a one-off error), the number of data subjects affected and the link between the processing and the core business were considered significant factors.Q11.4. What is the ‘lesson of the lessons’?
That the regulator does not target the error itself but the business model: when opacity is the very basis of the business (no one informed = no one to object), the response combines the maximum fine, a ban and the removal of the data. Transparency is not a cost of the model: it is a prerequisite for its existence.Block 12: Best practice, drafting and checklists
Q12.1. Timeline matrix (Art. 14.3) — pin it to the project wall
| Milestone | Must report |
| Receipt of the dataset | No later than 30 days after |
| First scheduled contact with the affected party (email, SMS, letter, phone call) | At the time of that first contact, at the latest |
| First disclosure or access by a third party | Before that transfer/enquiry |
| Change of purpose (new use, new purpose) | Before commencing the new processing (14.4) |
Q12.2. Example of first-layer information (initial communication to a data subject who is not a customer)
Data protection. We hereby inform you that [DATA CONTROLLER, tax identification number, address, DPO contact details] processes your identifying and contact details obtained from [specific SOURCE; indicate whether publicly available] for the purpose of [specific PURPOSE], on the basis of [LEGAL BASIS; if legitimate interest: “our legitimate interest in…, which you may consult and to which you may object”]. Your data will [not] be disclosed to [RECIPIENTS]. We will retain it for [PERIOD/criterion]. You may access, rectify or erase your data, object — in particular, and in all cases, to its use for commercial purposes — and exercise your other rights via [a simple CHANNEL], as well as lodge a complaint with the AEPD (www.aepd.es). Full information: [URL/annex].Q12.3. Example of a profiling and scoring clause (layer 2)
We create a profile of you which may include [commercial segment / score for…], calculated on the basis of [key variables and their source]. This profile [is not] used to make automated decisions with significant effects; [if it is:] you may request human intervention, express your point of view and challenge the decision. You may object to profiling at any time via [CHANNEL].Q12.4. Checklist for marketing campaigns using third-party data
- Evidence of the source’s origin and information clause, with your company as the recipient.
- Documented LIA (or verifiable consent if required by the channel — LSSI for email/SMS to non-customers).
- Prior consultation of opt-out lists (Art. 23 LOPDGDD) with dated evidence.
- Notification of Article 14 included in the first mailing, with one-click opt-out.
- Record of deliveries, unsubscriptions and their dissemination to the data provider and recipients (Art. 19).
Q12.5. Data enrichment/merger project checklist
- Compatibility test 6.4 signed prior to upload.
- Update of the RAT, the DPIA and the clauses (new categories + source).
- Information plan: target groups, channel, timetable in accordance with matrix 14.3, approved text, proof of delivery.
- Accuracy check against source (documented sampling) and full context of the data (amount, status, age).
- Mechanism for complete deletion of the dataset if ordered by the AEPD (learn from (***), SA: design the ‘red button’).
Q12.6. Minimum annual audit programme
- Inventory of active external sources and associated contracts.
- Sampling of data subjects: is there a record of when and how they are informed?
- Rights test: simulated access (do the source and score appear?), simulated objection (is it propagated?).
- Review of exemptions under Article 14(5) invoked and their weightings.
- Verification of the electronic notification inbox and powers of attorney (SAN ruling 28 April 2022).
Q12.7. The five errors that account for the most penalties
- Confusing ‘accessible data’ with ‘usable data’.
- Providing generic information and only on the website.
- Acting first, then providing information (14.3/14.4).
- Treating legitimate interest as a tick-box exercise rather than as evidence + transparency (Supreme Court Ruling 26 November 2020).
- Delegating without oversight: suppliers, distributors, platforms (Art. 46 of the RLOPD previously, Arts. 26–28 currently).
Glossary
ARTICLE 14 GDPR:
The obligation to provide information applies whenever the data has not been obtained from the data subject themselves, as is the case with the purchase of databases, data transfers or data collection via the website. It requires disclosure of the categories of data being processed and the source from which they originate.DPIA (DATA PROTECTION IMPACT ASSESSMENT):
A preventive process designed to identify, assess and minimise the risks that a project may pose to individuals’ privacy and freedoms. It is mandatory in cases involving profiling with significant effects, large-scale monitoring, the use of sensitive data or the cross-referencing of data sources.DATA ENRICHMENT:
A process involving the addition of external data to in-house systems (such as a CRM). It constitutes indirect collection subject to the obligation to provide information, and further processing in relation to the purpose for which the original source collected the information.LEGITIMATE INTEREST:
A legal basis considered self-executing, as its validity depends entirely on the data subject having been explicitly informed so that they may exercise their right to object. It requires carrying out and documenting a meticulous assessment or data protection impact assessment (DPIA).PROFILING:
Data processing that must be disclosed in the first layer of information so that the data subject is aware of it. It must always be subject to the right to unconditional objection if used for marketing purposes.ACTIVITY REGISTER (RAT):
An internal document which must set out, for each activity, the source of the data, the categories of data processed (including inferred data), the applicable legal basis, the recipients, the retention periods and a reference to the current information notice.Do you process personal data you didn’t obtain directly from the individuals? Article 14 requires you to inform them, and failing to do so is punishable. We review your data-capture processes and your privacy notices. Write to us and let’s look at it.
Frequently asked questions
When the data is NOT obtained from the data subject, but from another source (a third party, a public register, a data broker). Article 13 applies when you collect it directly from the data subject.
Within a reasonable period, at most one month from obtaining the data; or at the first communication with the data subject; or before the first disclosure to a third party, whichever occurs first.
Yes. Even if the data comes from a data broker or a public source, Article 14 requires you to inform the data subject that you process their data, for what purpose and where you obtained it.
Not automatically. Being in a public source does not remove the Article 14 duty; there is an exemption only if informing would require disproportionate effort and alternative measures are adopted.
Scraping personal data without informing the data subject breaches Article 14 and usually lacks a valid legal basis; the AEPD and the EDPB have penalised these practices.
That the data subject already has the information, that informing is impossible or requires disproportionate effort, that a law provides for it, or that a duty of professional secrecy applies (Article 14(5) GDPR).
Contact
Don’t be left in doubt, get in touch. We’ll be happy to help and offer you solutions.

