ILP Abogados
Madrid · Internacional
Mazo de juez de madera sobre su base junto a un libro abierto en una mesa azul, símbolo del control judicial del artículo 14 del RGPD

Article 14 GDPR Before the Courts and the Supervisory Authorities (Data Protection Series IV)

Last updated: 30 July 2026.

Quick answer. Article 14 of the GDPR requires anyone who obtains personal data from a source other than the data subject to track them down and tell them, and it is now the provision that decides whether a business built on third-party data is viable at all. The courts and the AEPD have settled the rules: public availability does not remove the duty to inform, legitimate interest collapses without transparency, the first disclosure brings the deadline forward, and the burden of proving that information was given falls on the controller. Penalties reach 20 million euros or 4 % of worldwide annual turnover. Updated 30 July 2026.

1. Introduction: why Article 14 exists and what problem it addresses

The European data protection system is based on one premise: an individual can only control their data if they are aware that someone is processing it. When a company collects data directly from the data subject (via a form, a contract or an app), that awareness exists naturally and simply needs to be formalised (Article 13). But the data economy operates largely behind the data subject’s back: databases that are bought and sold, credit reference files fed by creditors or official gazettes, data transfers between companies within the same group, profiles and scores that are calculated and communicated to third parties, and contracts entered into by impostors using the victim’s data. In all these scenarios, the data subject is unaware that their data is being circulated, and this lack of awareness prevents them from exercising any rights: they cannot object to what they do not know about, nor rectify inaccurate data they have never seen, nor lodge a complaint with the supervisory authority regarding processing of which they have no knowledge. Article 14 of the GDPR is the answer to this blind spot. It imposes on the controller who obtains data from a source other than the data subject themselves the obligation to seek them out and inform them: who the controller is, what data they hold, where they obtained it from, what they will use it for, to whom they will pass it on, and what rights the data subject can exercise. It is, therefore, the provision that transforms transparency into an active duty rather than a mere courtesy, and the one that determines whether a business model based on third-party data (data enrichment, scoring, business intelligence) is legally viable or not. It is no coincidence that the most severe Spanish penalties for breaches of transparency ((SSS), S.A., (TTT), S.A., (VVV), S.A.) and a whole series of civil litigation cases concerning the right to honour revolve around this provision and its related provisions. The practical consequences of non-compliance are threefold: an administrative fine (up to 20 million euros or 4 per cent of global turnover), corrective measures that may extend to a ban on processing and the deletion of the data file – the destruction of the data asset, as occurred with the Judicial Incidents Register of (SSS), S.A.-, and civil liability for infringement of honour where the unreported data is, furthermore, harmful (typically, inclusion in a debtors’ register).

2. Exact wording of Article 14 of the GDPR

1. Where personal data have not been obtained from the data subject, the controller shall provide the data subject with the following information:

  • The identity and contact details of the controller and, where applicable, of their representative;
  • The contact details of the data protection officer, where applicable;
  • The purposes of the processing for which the personal data are intended, as well as the legal basis for the processing;
  • The categories of personal data concerned;
  • The recipients or categories of recipients of the personal data, where applicable;
  • Where applicable, the controller’s intention to transfer personal data to a recipient in a third country or an international organisation and the existence or absence of an adequacy decision by the Commission, or, in the case of transfers referred to in Articles 46 or 47 or Article 49, paragraph 1, second subparagraph, reference to the appropriate or suitable safeguards and the means of obtaining a copy of them, or to the fact that they have been provided.

2. In addition to the information referred to in paragraph 1, the controller shall provide the data subject with the following information necessary to ensure fair and transparent processing in relation to the data subject:

  • The period for which the personal data will be stored or, where that is not possible, the criteria used to determine that period;
  • Where the processing is based on Article 6(1)(f), the legitimate interests of the controller or of a third party;
  • The existence of the right to request from the controller access to personal data concerning the data subject, and the rectification or erasure of such data, or the restriction of its processing, and to object to the processing, as well as the right to data portability;
  • Where the processing is based on Article 6(1)(a) or Article 9(2)(a), the existence of the right to withdraw consent at any time, without this affecting the lawfulness of the processing based on consent prior to its withdrawal;
  • The right to lodge a complaint with a supervisory authority;
  • The source from which the personal data are derived and, where applicable, whether they are derived from publicly available sources;
  • The existence of automated decision-making, including profiling, as referred to in Article 22(1) and (4), and, at least in such cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.

3. The controller shall provide the information referred to in paragraphs 1 and 2:

  • Within a reasonable period of time after the personal data have been collected, and at the latest within one month, taking into account the specific circumstances in which the data are processed;
  • If the personal data are to be used for communication with the data subject, no later than at the time of the first communication to that data subject; or
  • If the data are to be disclosed to another recipient, no later than the time when the personal data are first disclosed.

4. Where the controller intends to carry out further processing of personal data for a purpose other than that for which it was collected, it shall provide the data subject, prior to such further processing, with information regarding that other purpose and any other relevant information referred to in paragraph 2.

5. The provisions of paragraphs 1 to 4 shall not apply where and to the extent that:

    • the data subject is already in possession of the information;
    • The provision of such information is impossible or would involve a disproportionate effort, in particular for processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, subject to the conditions and safeguards set out in Article 89, paragraph 1, or in so far as the obligation referred to in paragraph 1 of this Article would render impossible or seriously impede the achievement of the purposes of such processing. In such cases, the controller shall take appropriate measures to protect the data subject’s rights, freedoms and legitimate interests, including by making the information public;
    • the collection or disclosure is expressly laid down by Union or Member State law to which the controller is subject and which provides for appropriate measures to safeguard the data subject’s legitimate interests, or
    • Where the personal data must remain confidential on the basis of a professional secrecy obligation governed by Union or Member State law, including a statutory obligation of secrecy.
    • Quick reference points. Paragraph 1 sets out the core provisions; paragraph 2 adds the ‘fairness’ information (three points stand out which are either absent or less prominent in Article 13: point (b), specific legitimate interests; point (f), the source of the data; and point (g), the logic behind automated decisions). Paragraph 3 sets out three alternative time limits, with the one that expires first taking precedence. Paragraph 4 requires re-notification before changing the purpose of data processing. Paragraph 5 contains the only four exceptions, all of which are to be interpreted restrictively.

3. Related and concomitant provisions: what each one regulates and how it relates to Article 14

3.1. Within the GDPR itself

Recitals 60, 61 and 62. These are not provisions in the strict sense but interpretative criteria: they explain that transparency is a requirement of fairness, specify when information must be provided in the case of indirect collection (recital 61) and outline the exception relating to impossibility or disproportionate effort (recital 62). Recitals 47, 48 and 70 complete the picture regarding legitimate interests, intra-group data transfers and direct marketing. Article 12 (forms of transparency). This regulates the ‘how’: the information referred to in Articles 13 and 14 must be concise, transparent, intelligible, easily accessible, in clear and plain language, provided in writing or by electronic means, free of charge, and with specified response times. This is the provision that enables the ‘layered information’ approach and which renders a convoluted or inaccessible privacy policy non-compliant, even if it formally ‘says everything’. Article 13 (direct collection). This mirrors Article 14. Determining which of the two applies is the first practical point of contention: it defines who the ‘source’ is and what additional content is required (Article 14 also requires categories of data and their origin, because the data subject was not present at the time of collection). Article 5 (principles). Article 5.1(a) enshrines lawfulness, fairness and transparency – Article 14 elaborates on this -; Article 5.1(b) (purpose limitation) is the provision that prevents the reuse for creditworthiness purposes of information published for notification purposes; Article 5(1)(d) (accuracy) requires that data imported from the source be faithful to that source; and Article 5(2) (proactive accountability) places the burden of proof on the data controller to demonstrate that they have provided information: in the absence of traceability, a breach is presumed. Article 6 (lawfulness) and 6.4 (compatibility). Article 6.1 lists the legal bases; the one governing the processing of third-party data is subparagraph (f) (legitimate interest), which requires a case-by-case assessment. Article 6.4 governs the compatibility test when data is to be used for a purpose other than the original one: this is the threshold that Article 14.4 requires to be crossed by providing prior notice. Information and lawfulness are independent and cumulative obligations: compliance with one does not satisfy the other (this was the approach taken by the AEPD when it imposed separate penalties under Article 6 and Articles 13-14 on (TTT), S.A. and (VVV), S.A.). Articles 21 and 22 (objection and automated decisions). Article 21 grants the right to object – which is unconditional in the case of direct marketing (21.2 and 21.3) – and this right can only be exercised if the data subject has been informed: this is the functional rationale behind Article 14, as emphasised by the Supreme Court ruling of 26 November 2020. Article 22 regulates decisions based solely on automated processing with legal or significant effects (scoring, following the CJEU judgment in the SCHUFA case), and is linked to the duty to explain the logic set out in Article 14(2)(g). Articles 26 and 28 (joint controllers and data processors). These regulate the allocation of roles: who must provide information where there are several controllers (the agreement referred to in Article 26 must assign this responsibility) and why outsourcing to data processors or distributors does not exempt the controller from its duties, including the duty to provide information. Articles 58 and 83 (corrective powers and fines). Article 83(5)(b) classifies infringements of data subjects’ rights under Articles 12 to 22 as falling within the highest fine bracket. Article 58(2) grants the authority the powers to issue warnings, issue injunctions, restrict or prohibit processing (58(2)(f)) and order erasure (58(2)(g)): the latter two are what turn a case under Article 14 into an existential risk for a data business.

3.2. Spanish implementing legislation

LOPDGDD (Organic Law 3/2018). Three components: Article 11 legalises tiered information (immediate basic information + reference to the full information), setting out the minimum content of the first tier; Article 20 regulates credit information systems (debt status -valid, past due, enforceable-, prior demand for payment, five-year retention period, notification to the data subject within thirty days), an area where Article 14 gives rise to the highest level of litigation; and Articles 72(1)(h) and 74(a) classify the offence: failure to comply with the duty to provide information under Articles 13-14 is a very serious offence (three-year limitation period), whilst providing incomplete information is a minor offence (one-year limitation period) – hence why fines running into millions, such as those imposed on (TTT), S.A. or (VVV), S.A., were, paradoxically, classified as minor offences. The 1999 Data Protection Act (LOPD) (Organic Law 15/1999) and Royal Decree 1720/2007, now repealed but still applicable in legal proceedings. Article 29 distinguished between credit records compiled from publicly accessible sources (29.1) and those compiled by creditors (29.2, with requirements regarding quality, collection and notification set out in Articles 38-44 of the Regulations). That distinction lies at the heart of Supreme Court Judgment 333/2026 ((SSS), S.A.): the requirements of Articles 29.2 and 29.4 do not apply to the registers referred to in Article 29.1. This is significant because thousands of entries made prior to 2018 are still being adjudicated under that regime, and because the GDPR has superseded it: the category ‘publicly accessible source’ is no longer an independent legal basis nor does it exempt the data controller from the obligation to provide information (Article 14(2)(f)). Organic Law 1/1982 on the civil protection of honour. This regulates the concurrent civil remedy: the wrongful inclusion in a debtors’ register constitutes an unlawful infringement of honour (Article 7(7)) and gives rise to a claim for compensation (Article 9(3)). It is on this second front – running parallel to the administrative proceedings – that the failure to provide information under Article 14 is contested. Act 39/2015 (Common Administrative Procedure). This regulates relations with the Administration: its Article 14.2 (obligation to communicate electronically, which extends to entities without legal personality such as owners’ associations) and Articles 40-43 (electronic notifications, rejection within ten days) determine the finality of the AEPD’s decisions and access to judicial review – the procedural aspect illustrated by the Supreme Court ruling of 28 April 2022. It is important not to confuse this Article 14 with that of the GDPR: they regulate entirely different matters.

3.3. Harmonised European interpretation

Guidelines on Transparency WP260 rev.01 (WG29/EDPS). These guidelines set out the standard for the quality of information, the ‘layered approach’ and, above all, a restrictive interpretation of the ‘disproportionate effort’ exception in Article 14(5)(b) (documented assessment of effort versus impact and compensatory measures such as the publication of the information). EDPS Guidelines 07/2020 (data controller and data processor). They define who determines the purposes and means and, therefore, on whom the duty to inform rests; they uphold the doctrine of non-delegability applied in cases involving distributors (line (WWWW), S.A.). Case law of the CJEU. ASNEF and FECEMD (C-468/10 and C-469/10, 24 November 2011): direct effect of legitimate interest; the national legislator may not impose categorical requirements such as demanding that the data appear in public sources. Bara (C-201/14, 1 October 2015): the transfer of data between public authorities requires prior notification to the data subject – the direct precedent for the obligation under Article 14 in data transfers. SCHUFA (C-634/21, 7 December 2023): a credit score constitutes an automated decision under Article 22 where the recipient relies on it in a decisive manner. C-26/22 and C-64/22 (7 December 2023): time limits on the retention by private agencies of data derived from public insolvency registers.

4. Matters analysed, debated and resolved by judges and authorities

Each topic is presented using the same structure: what is being discussed, what opposing positions exist, and how it has been resolved (or what the current status is).

M1. The boundary between Article 13 and Article 14: who is the ‘source’?

What is under discussion. Whether the data was obtained ‘from the data subject’ or not, as this determines the applicable regime, the content of the information and the start of the time limit. Grey areas: observed data (browsing, telemetry), inferred data (profiles and scores created by the data controller), data provided by a third party claiming to act on behalf of the data subject, and data provided by an impersonator. Positions. Companies tend to treat inferred data as “their own” (not collected) and data provided by authorised third parties as having been obtained “from the data subject” via a representative. Authorities and legal doctrine (WP260) maintain that any data whose collection was not witnessed by the data subject merits the standard set out in Article 14, and that inferred data constitutes new personal data which must be disclosed. Ruling. The AEPD’s practice applies Article 14 to data transfers, public sources and shared profiles ((SSS), S.A., (TTT), S.A., (VVV), S.A.). In cases of identity theft, the Agency has opted to apply the lawfulness provision (Article 6(1)) or the security provision (Article 5(1)(f), in line with SIM swapping cases: (WWWW), S.A. PS/00021/2021 and similar cases) rather than Article 14, but the factual basis is identical: processing of which the victim was never informed because they were never the source.

M2. Publicly available sources: does the fact that information is public exempt the controller from the obligation to inform?

What is at issue. The most contentious issue: whether data obtained from official gazettes, registers and other open sources may be processed without informing the data subject, on the basis that it has already been made public. Positions. The credit information industry argued that the former Article 29.1 of the 1999 Data Protection Act (LOPD) authorised such files without the requirements applicable to files on defaulters and with a minimal information burden; that the data was already public and its reuse harmless. The AEPD maintained that the public nature of the source does not constitute any of the exceptions under Article 14(5), that Article 14(2)(f) specifically requires the source to be disclosed, and that under the GDPR the category ‘publicly available sources’ has ceased to be a valid legal basis. Decision . In administrative proceedings, Decision PS/00240/2019 ((SSS), S.A., 26 April 2021) is the leading case: a fine of one million euros for infringing, amongst other provisions, Article 14, with a prohibition on the processing of the FIJ and an order for its deletion. In civil proceedings, Supreme Court Judgment 333/2026 addresses the other side of the issue: for matters governed by the 1999 Data Protection Act (LOPD), the files referred to in Article 29(1) were not subject to the requirements of Article 29(2) (nature of the debt, demand for payment, notification) and official publication is presumed to be accurate; therefore, there was no infringement of honour. The overall result is a temporal boundary: a lenient regime for the past (under the 1999 LOPD), and a strict regime (always provide information) for the present (under the GDPR).

M3. Purpose limitation: the reuse of official publications

What is at issue. Whether data published in a gazette for a specific purpose (a public notice guaranteeing effective judicial protection under Article 24 of the Spanish Constitution) may be reused for a different purpose (assessing creditworthiness, feeding business intelligence). Positions. Re-users invoke publicity and the legitimate interest of economic transactions. The AEPD argues that the purpose of the publication exhausts its scope: re-using it for creditworthiness purposes constitutes incompatible further processing (Articles 5(1)(b) and 6(4)), exacerbated by the loss of context (in the (SSS) case, S.A. was recorded as having a ‘tax debt’ without any indication of the amount, origin or status, thereby also giving rise to inaccuracy under 5.1.d). Decision. Finalised through administrative channels (PS/00240/2019). This is the rule with the greatest impact on data enrichment: public origin does not confer a ‘right of re-use’, and a change of purpose requires a compatibility test and prior notification (14.4).

M4. Legitimate interest and transparency: does recital 47 provide an exemption?

What is under discussion is whether the reference at the end of Recital 47 (“the processing of personal data for direct marketing purposes may be considered to be carried out on the basis of a legitimate interest”) creates a presumption that exempts the data controller from carrying out a balancing test and, in practice, from providing information; and whether the GDPR has, as a result, retroactively decriminalised commercial communications sent without consent during the LOPD era. Positions. The sanctioned company ((XXX), S.L.) argued that Article 6(1)(f), read in conjunction with Recital 47, permits marketing without consent and without an individual balancing test, provided that the data subject has not objected. The AEPD and the National High Court countered that legitimate interest requires a meticulous case-by-case assessment, taking into account the data subject’s reasonable expectations, and that the system only works if the controller communicates the specific legitimate interests (13.1.d/14.2.b) and the right to object explicitly, clearly and separately (recital 70, Article 21). Decision. Supreme Court Ruling 1620/2020 of 26 November 2020 settles the matter: legitimate interest is not a free pass; without proven compliance with the information obligations that enable the right to object, the processing is not lawful, and there is no scope for favourable retroactive application. Practical implication: legitimate interest is a ground conditional upon transparency – it is null and void if not accompanied by information.

M5. Quality and content of information: vagueness as a breach

What is at issue. How specific must the information be: is a privacy policy that lists purposes and legal bases in the abstract sufficient? Positions. The organisations advocated single, generic texts (“commercial purposes”, “legitimate interest of the controller”) applicable to all their processing activities. The AEPD, relying on Article 12 and WP260, requires each purpose to be linked to its legal basis, specific legitimate interests to be identified, data categories (including inferred data) to be detailed, and unambiguous terminology to be used. Decision. PS/00070/2019 ((TTT), S.A., €5 million, of which €2 million under Articles 13-14) and PS/00477/2019 ((VVV), S.A., €6 million, of which €2 million relates to Articles 13-14): information that is imprecise, inconsistent across channels or which does not make it possible to ascertain which processing operations are covered by which legal basis constitutes an independent infringement, even if the information is “formally complete”. The layered approach set out in Article 11 of the LOPDGDD is valid, but the first layer must contain a minimum amount of information and the second must be consistent.

M6. The timing of notification: the three timeframes in Article 14.3 and the completion of the infringement

What is under discussion. When exactly does the obligation arise (calendar month? What if the data is transferred or the data subject is contacted earlier?) and when is the infringement deemed to have been committed for the purposes of sanctions and the limitation period? Positions. Data controllers generally calculate the period as one month. The supervisory authority and legal doctrine emphasise that subparagraphs (b) and (c) bring forward the expiry date: the first communication to the data subject and, above all, the first transfer to a recipient mark the cut-off point, even if the month has not yet elapsed. Decision. In the case of (SSS), S.A., the data was accessed by banking institutions without the data subject ever having been informed: the infringement was deemed to have taken place upon the first access. For models where the service consists of access by third parties (credit reference agencies, data brokers), the obligation applies, in practice, prior to the data being made available.

M7. The exception of impossibility or disproportionate effort (14.5.b)

What is at issue. Whether the scale (millions of records collected from external sources) or the cost of contacting each data subject allows for the exception to be invoked. Positions. The data controllers cite the cost and the lack of contact details. The AEPD and the EDPB (WP260) respond that the exception was intended primarily for archiving, research and statistical purposes; that it requires a documented assessment of the balance between the effort involved and the impact on the data subject; that it does not apply where contact details are available – or can reasonably be obtained from the data provider -; and that, even where it does apply, it requires compensatory measures, notably making the information public. Decision. Invoked by (SSS), S.A. and rejected by the AEPD: the volume of business does not render the cost of compliance disproportionate; it is a cost inherent to the business model. The exception remains a narrow remedy, with the burden of proof resting on the party invoking it.

M8. Burden of proof and accountability (5.2)

What is at issue. Who must prove that information was provided, what the content was, and on what date. Ruling. Undisputed in the AEPD’s practice: the burden lies with the data controller (accountability). Without a record of the notification (recipient, channel, date, version of the text), a defence is almost impossible. This ties in with the general evidential principle that the Supreme Court has clarified in the field of security (Supreme Court Judgment of 15 February 2022, cited in PS/00587/2021: obligation of means, not of result) – a nuance that does not apply to the duty to inform, which is indeed an obligation of verifiable result.

M9. Scoring, profiling and ‘applied logic’ (14.2.g and Art. 22)

What is at issue. Whether the score constitutes personal data that must be disclosed, what is meant by ‘meaningful information on the logic applied’ (formula? variables and weightings?) and when scoring constitutes an automated decision that is prohibited, subject to exceptions. Positions. Credit reference agencies argued that they merely ‘prepare’ the decision taken by another party. The CJEU (SCHUFA, C-634/21) ruled that the calculation of the score is in itself the decision referred to in Article 22 when a third party relies on it in a decisive manner, thereby triggering the qualified legal basis, the right to human intervention and the duty to explain the logic. In Spain, the AEPD imposed a fine on (TTT), S.A. for failing to provide information on profiling processing. Current situation: an open and expanding front (affecting credit scoring, fraud scoring, commercial risk scoring and AI systems that generate profiles): inferred data must be declared as a data category and explained.

M10. Processing operations initiated by third parties: fraudulent contracting and identity theft

What is under discussion. Liability of the data controller when a fraudster enters the victim’s data (duplicate SIM cards, contracts in another person’s name): lack of legal basis (6.1)?, security breach (5.1.f)?, liability if the deception was carried out by a third party or a distributor?, liability for the result? Positions. Operators argue that they exercised due diligence, that the fraudster or distributor bears sole fault, and that there is no link to the subsequent financial loss. The AEPD establishes a duty to verify identity as a measure under 5.1.f that cannot be delegated to the sales network, and has fluctuated in its classification (Art. 6.1 in previous cases; 5.1.f in the 2021-2022 wave), which the defence argues creates legal uncertainty. Decision. A firm and substantial line of sanctions ((WWWW), S.A. PS/00021/2021, €900,000; (YYY), S.A. PS/00001/2021, €3.94 million; (ZZZ), S.A. PS/00022/2021, €770,000), confirmed by the National High Court in 2024 in respect of (WWWW), S.A. For the victim, the situation is the reverse of Article 14: a complete data processing operation takes place without the data subject ever having been the source of the data or having been informed.

M11. Classification of the offence, concurrent offences and proportionality

What is at issue. Three fronts: (i) the Spanish grading system – total failure to fulfil a duty (72.1.h, very serious) versus incomplete information (74.a, minor) – and its consequences for the limitation period; (ii) the concurrence between the breach of lawfulness (Article 6) and the breach of disclosure (Articles 13-14): a single act or two separately punishable offences?; (iii) the grading of the fine (Art. 83.2: aggravating and mitigating circumstances) and the choice of corrective measures. Decision. The AEPD treats the infringements of lawfulness and information as separate and cumulative offences ((TTT), S.A. and (VVV), S.A. were each fined separately for each block). In the case of (SSS), S.A., the measures set out in Article 58(2)(f) and (g) were added – a sign that, in cases of structurally unfeasible processing, the response is not merely financial but involves the deletion of the data file. Arguments based on proportionality (few identified data subjects affected, negligible percentages, cooperation) have met with little success where the non-compliance is structural.

M12. Civil proceedings concerning reputation: concurrent claims and the time limit

What is at issue. Whether uninformed inclusion in a register infringes honour; what requirements (certainty of the debt, prior demand, notification) are enforceable depending on the type of register and the legislation in force on the date of inclusion; and the value of official publication as a source. Positions . Those affected invoke the First Chamber’s established case law on registers of defaulters (certain, due and payable debt; demand; notification of inclusion). The controllers of registers based on public sources argue that this standard falls under Article 29(2) of the 1999 Data Protection Act (LOPD) and not under the registers covered by Article 29(1). Decision. Supreme Court Judgment 333/2026 (following the precedent set by Supreme Court Judgment 434/2023) upholds the second argument regarding the previous regime: the requirements of Articles 29(2) and 29(4) and Articles 38-40 of Royal Decree 1720/2007 do not apply to files from public sources, and publication by an official body gives rise to a presumption of veracity (reinforced, in this case, because the claimant himself prevented the debt from being proven by refusing to give his consent for the local council to provide information). It is hereby established that, for inclusions under the GDPR, the criterion will be different: the strict standard set out in the administrative case law of S.A.

M13. The procedural dimension: notifications and finality

What is at issue. The validity of electronic notifications from the AEPD (decision to initiate proceedings, final decision) to data controllers required to communicate electronically, and their effects: the time-barred nature of appeals, finality, enforcement and which body reviews each act. Decision. The Supreme Administrative Court (SAN) judgment of 28 April 2022 (case no. 392/2021) is illustrative: owners’ associations, as entities without legal personality, have been obliged to communicate electronically since the entry into force of Law 39/2015; failure to access information made available within ten days constitutes a rejection; valid notification triggers the running of time limits and the penalty becomes final without the possibility of challenging the merits; and the enforcement order is challenged through the economic-administrative channels, not directly before the National High Court. Practical lesson: a significant proportion of data protection penalties are either dismissed or upheld before Article 14 is even discussed, due to issues relating to notifications and time limits.

5. Summary table

SubjectWho is debatingCurrent status
M1. Boundary between Articles 13 and 14 and the concept of ‘source’Companies v. AEPD/CEPDBroad interpretation of Article 14; data inferred and provided by third parties included within the logic of transparency.
M2. Public sources and the duty to informCredit bureaux v. AEPD; First Chamber of the Supreme CourtUnder the GDPR: always provide information ((SSS), S.A.). Under the 1999 LOPD: lenient regime under Article 29.1 (Supreme Court Judgment 333/2026).
M3. Reuse of official gazettesRe-users v. AEPDIncompatible purpose; requires Articles 6(4) and 14(4); established case law.
M4. Legitimate interest vs. transparencyDirect marketing vs. AEPD/AN/TSResolved (Supreme Court ruling of 26 November 2020): without information, there is no valid legitimate interest.
M5. Quality of informationBanking sector v. AEPDGeneric wording constitutes an independent infringement ((TTT), S.A., (VVV), S.A.).
M6. Timing of disclosureData brokers v. AEPDThe first transfer brings the deadline forward; this is a duty prior to processing.
M7. Disproportionate effortLarge data sets vs. AEPD/CEPDNarrow exception, documented assessment, compensatory measures.
M8. Proof of having provided informationData controllers vs. AEPDBurden on the controller (5.2); obligation to achieve a verifiable result.
M9. Scoring and applied logicScoring agencies v CJEU/AEPDAn expanding front (SCHUFA); the score is data and may constitute a decision under Article 22.
M10. Identity theft / third-party contractingOperators vs. AEPD/ANA firm line on sanctions (5.1.f, identity verification cannot be delegated).
M11. Classification, concurrence of offences and penaltyThose sanctioned vs. AEPDCumulative infringements relating to lawfulness and information; possible prohibition and removal.
M12. Civil claims for interference with honourAffected parties v. data controllers; First ChamberLimited by a time-limited regime (Supreme Court Judgements 434/2023 and 333/2026).
M13. Notifications and finalityThose sanctioned v. the AEPD; ANEstablished case law in favour of the Administration (SAN 28 April 2022).

Article 14 is not satisfied by a generic privacy policy: it requires identifying each source, documenting the balancing of legitimate interests, setting the timeframes in paragraph 3, and being able to subsequently demonstrate who was informed and when. This evidential framework, and the defence when the AEPD challenges it, forms the core of our data protection and GDPR compliance practice.

Glossary

ARTICLE 12 GDPR:

Provision governing the requirements for transparency, enabling the use of ‘layered information’ and requiring that information be concise, easily accessible and expressed in clear and plain language.

ARTICLE 13 GDPR:

Provision applicable when a company collects data directly from the data subject (via forms or contracts), acting as a regulatory counterpart to Article 14.

ARTICLE 14 GDPR:

A legal provision addressing processing carried out without the data subject’s knowledge, imposing on the controller an active obligation to inform the data subject of the controller’s identity, the data held, its source, the purpose of the processing and the recipients of the data.

UNLAWFUL INTERFERENCE WITH THE RIGHT TO HONOUR:

Civil liability governed by Organic Law 1/1982 arising from the improper and uninformed inclusion in a debtors’ register, giving rise to compensation.

LOPDGDD (Organic Law 3/2018):

Spanish Organic Law which legalises tiered information (Article 11) and classifies the failure to fulfil the duty to inform, as established in the GDPR, as a very serious infringement.

ACCOUNTABILITY (PROACTIVE RESPONSIBILITY):

A principle set out in Article 5(2) of the GDPR which places the obligation on the data controller to prove that they have informed the data subject, constituting a verifiable obligation of result rather than a mere obligation of means.

SCORING:

Inferred data created by the controller which, if relied upon decisively by a third party, constitutes an automated decision (Article 22) requiring human intervention and information on the logic applied.

WP260 REV.01:

European guidelines on transparency which require a very restrictive interpretation of the legal exception of ‘disproportionate effort’ when it comes to providing information, always requiring a documented assessment and compensatory measures such as public disclosures.

Could you prove tomorrow who you informed, when, and with what wording? We review your data sources, your legitimate interest assessments and the traceability of your privacy notices, which is precisely where the AEPD starts looking: tell us about your case.

Frequently asked questions

When does Article 14 GDPR apply instead of Article 13?

Article 14 applies whenever the data was not obtained from the data subject themselves: disclosures between companies, public registers and official gazettes, data brokers, or data inferred by the controller. Article 13 governs direct collection. Because the data subject did not witness the collection, Article 14 additionally requires disclosure of the categories of data and of their source.

What is the deadline to inform when data comes from a third party?

One month at most from obtaining the data, but that deadline is brought forward: if the data will be used to communicate with the data subject, the information must be given at the first communication; and if the data will be disclosed to another recipient, no later than that first disclosure. Whichever clock expires first prevails.

Does data published in an official gazette remove the duty to inform?

No. The public nature of the source is not among the exceptions in Article 14.5, and Article 14.2.f expressly requires the controller to state where the data came from. Under the GDPR, the category of publicly accessible sources has ceased to operate as an autonomous legal basis.

Can data from an official gazette be reused for credit scoring?

Not without first passing the compatibility test in Article 6.4 and giving prior information under Article 14.4. The purpose of an edictal publication is exhausted by the notification itself; using it for scoring or commercial intelligence is an incompatible further processing operation, aggravated where the data loses its original context.

Does legitimate interest allow third-party data to be processed without informing?

No. Legitimate interest requires a case-by-case balancing exercise and only works if the controller communicates the specific legitimate interests and the right to object in an explicit, clear and separate manner. Without prior information there can be no objection and therefore no lawful processing.

When can the disproportionate effort exception in Article 14.5.b be invoked?

It is a narrow route, designed above all for archiving, scientific or historical research and statistical purposes. It requires a documented balancing of the effort against the impact on the data subject, it does not apply where contact details are held or can reasonably be obtained from the discloser, and even then it requires compensatory measures such as making the information public.

Who has to prove that the data subject was informed?

The controller, under the accountability principle in Article 5.2. Without a record of the information notice (recipient, channel, date and version of the wording), a defence in enforcement proceedings is almost impossible: this is an obligation of result that must be verifiable, not merely an obligation of means.

What are the consequences of breaching the Article 14 duty to inform?

Fines of up to 20 million euros or 4 % of total worldwide annual turnover. In Spain, total failure to comply is classified as a very serious infringement and incomplete information as a minor one. The authority may also restrict or prohibit the processing and order erasure of the file, and civil liability for interference with the right to honour may arise.



Contact
Don’t be left in doubt, get in touch. We’ll be happy to help and offer you solutions.

GUÍA GRATUITA

Regulación Financiera España 2026

DORA + MiCA + MiFID II + EMIR en un solo documento

Descargar gratis →

Videos relacionados

Cargando videos…

Discover more from ILP Abogados

Subscribe now to keep reading and get access to the full archive.

Continue reading