ILP Abogados
Madrid · Internacional
Mano señalando con un lápiz gráficos de barras impresos junto a un teléfono móvil y un portátil sobre una mesa de trabajo

The Price of Data: 15 Legal Commandments Every Business Owner Should Know to Avoid Penalties (Data Protection Series V)

Last updated: 30 July 2026.

Quick answer. The GDPR and Spain’s LOPDGDD do not protect files, they protect people: under Spanish law a company never owns a citizen’s data. These 15 rules, drawn from Supreme Court and Constitutional Court judgments and from AEPD penalty decisions, set out what every business owner must control: when processing begins, who bears the burden of proving consent, what separates a controller from a processor, when biometrics require an impact assessment, and why pseudonymisation is not anonymisation. Updated 30 July 2026.

Introduction

Essential knowledge of data processing for business owners

The management of personal data has become a critical asset and one of the main sources of legal liability for businesses. To navigate this environment safely and professionally, every business owner must master the following 15 essential concepts, underpinned by case law and rulings from the Spanish Data Protection Agency (AEPD).

1. The concept of ‘processing’ begins before the data is obtained

The GDPR does not require data to be stored or archived for a legal obligation to arise. The mere planned request for personal data already constitutes ‘processing’ of data, obliging the business owner to comply with the principles of lawfulness and data minimisation from that very moment.

  • Case law: Supreme Court, Contentious-Administrative Chamber, Judgment No. 390/2026, of 26 March 2026.

2. The company is not the ‘owner’ of personal data

Under Spanish law, there is no commercial ownership of natural persons’ data. The right to data protection is an autonomous fundamental right which grants solely and exclusively to the individual the power to dispose of and control their own information.

  • Case law: Constitutional Court, Plenary Session, Judgment No. 292/2000, of 30 November 2000.
  • AEPD: Decision R/01158/2013 (Case No. A/00072/2013).

3. The duty to provide prior information is inescapable

The data subject’s control over their data is guaranteed by means of express, precise and unambiguous information provided prior to collection. Information must be provided regarding the existence of the data file, the purposes for which it is used, the identity of the data controller and the possibility of exercising the so-called ARCO rights (access, rectification, cancellation and objection). Failure to fulfil this duty results in a ‘vitiated consent’ and undermines the user’s right to decide the fate of their data.

  • AEPD: Penalty Decision R/01580/2010 (Case PS/00102/2010), dated 26 July 2010.

4. The burden of proof regarding consent rests strictly with the company

The user’s consent must be unequivocal and demonstrable. The business is obliged to take diligent steps to verify the identity of the person giving consent (by checking their DNI/NIE), and in the event of a dispute, it is the company that must provide conclusive proof that it obtained such authorisation.

  • Case law: Supreme Court, Civil Chamber, Judgment No. 551/2023, of 19 April 2023.
  • AEPD: Penalty Decision R/03238/2015 (Case No. PS/00387/2015), penalty imposed in 2015.

5. Data minimisation: requesting more information than is necessary is punishable

The information requested must be adequate, relevant and limited to what is strictly necessary for the intended purpose. For example, when monitoring absenteeism, an employer may not demand to know an employee’s medical diagnosis if a simple certificate of attendance is sufficient.

  • Case law: Supreme Court, Contentious-Administrative Chamber, Judgment No. 390/2026, of 26 March 2026.

6. Obligation to maintain the quality and accuracy of data

Databases must accurately reflect the current situation of the data subject. Maintaining inaccurate data, false identities or including unjustified debts in debt registers constitutes a breach of the principle of data quality, for which the company operating or benefiting from the register is liable.

  • Case law: Supreme Court, Contentious-Administrative Chamber, Judgment No. 121/2019, of 5 February 2019.
  • AEPD: Penalty Decision R/02359/2015 (Case No. PS/00175/2015) and Decision R/03379/2015 (Case No. PS/00518/2015), penalties imposed in 2015.

7. Critical distinction between the ‘controller’ and the ‘processor’

A subcontractor (processor) may only process data in accordance with the documented instructions of the contracting company (controller) under a formal contract. If the subcontractor decides to use that data for its own purposes (for example, to create its own block list), it automatically becomes an independent “data controller” and assumes full responsibility for that infringement.

  • AEPD: Penalty Decision EXP202304148 (Case No. PS/00247/2024), dated 10 October 2025, and Decision EXP202407910 (Case No. PS/00248/2024), dated 30 September 2025.

8. Biometrics (fingerprints, facial recognition) constitutes ‘high-risk’ data processing

The creation of a ‘mathematical template’ to uniquely identify a person through facial recognition or fingerprinting constitutes the processing of special category data. Companies may not impose mandatory biometric systems without passing a three-part proportionality test and without offering less intrusive traditional alternatives to users or employees.

  • AEPD: Penalty Decision EXP202313347 (Case No. PS/00289/2024), dated 20 May 2025.

9. Data Protection Impact Assessments (DPIAs) must be carried out for invasive technologies

To implement invasive technological systems (such as biometrics), a company has an unavoidable obligation to carry out a Data Protection Impact Assessment (DPIA) prior to their implementation. Producing superficial formal documents that do not systematically describe operations, do not assess the actual risks, or do not specify mitigation measures constitutes a serious breach of that obligation.

  • AEPD: Penalty Decision EXP202313347 (Case No. PS/00289/2024), dated 20 May 2025.

10. Pseudonymisation does not exempt organisations from regulatory compliance

Replacing an employee’s or customer’s first name and surname with an alphanumeric code (pseudonymisation) does not render the database anonymous. If third parties can reasonably link that code to the individual, the information remains personal data and its processing or public disclosure must comply with the GDPR.

  • Case law: Supreme Court, Labour Chamber, Judgment No. 278/2026, of 12 March 2026.

11. The risk of ‘accidental discovery’ and security breaches due to a lack of due diligence

Companies are obliged to implement appropriate IT security measures (encryption, passwords, restrictions on shared folders). The dumping of files containing sensitive data or their scanning into shared folders accessible to any employee constitutes a breach of the principle of confidentiality, amounting to an unlawful intrusion into privacy, even where the access resulted from an accidental discovery.

  • Case law: Supreme Court, Civil Chamber (Plenary Session), Judgment No. 383/2025, of 13 March 2025.
  • AEPD: Penalty Decision EXP202414366 (Case No. PS/00190/2025), dated 26 March 2025.

12. Workplace monitoring, IT equipment and ‘reasonable expectation of privacy’

An employer may monitor the computer equipment assigned to its employees, but must satisfy the criteria set out in the Barbulescu case: the employee must be given prior, clear and sufficient information regarding the monitoring criteria, the methods to be used and the restrictions on personal use. If the employer fails to inform the employee of such monitoring, the employee retains a reasonable expectation of privacy.

  • Case law: Supreme Court, Contentious-Administrative Chamber, Judgment No. 1,565/2024, of 7 October 2024.

13. Full traceability of access to health data and special categories of data

In the case of extremely sensitive databases (such as medical records or patient histories), the employer or data controller must ensure enhanced transparency. The data subject is not only entitled to access their own records, but also to exercise their right of access to demand precise traceability of who, when and what has been accessed within their personal health information.

  • AEPD: Rights Decision PD-00068-2026 (Case No. EXP202518019), decision of 10 March 2026.

14. Sale and purchase of companies or portfolios: the duty to inform in the event of restructuring

The transfer of a customer database resulting from the purchase or transfer of a business does not, as a general rule, constitute an unlawful transfer requiring the customer’s new consent to be sought. However, the acquiring company is obliged to fulfil its duty to inform by contacting customers to disclose the change in ownership, who the new data controller is, and how to exercise their rights.

  • AEPD: Case Closure Decision E/02038/2015.

15. Predictive Big Data is a Trade Secret

Whilst individual data belongs to citizens, business intelligence, predictive reports and the large-scale cross-referencing of anonymised trends (Big Data) give rise to intellectual property and commercial rights in favour of the company making the technical investment. This aggregated information falls outside the scope of the GDPR and is protected under Law 1/2019 on Trade Secrets and the sui generis right under the Spanish Intellectual Property Law.

  • Legal Source: Legal Note ‘Data Processing and Ownership’ (ILP Abogados).

These fifteen principles are not merely theoretical: they are set out in clauses within data processing agreements, in activity logs, in impact assessments and in internal control policies, all of which must be reviewed individually. This work of review and defence before the AEPD forms the core of our legal advice on data protection for businesses.

Glossary

DATA PROCESSING

Any operation carried out on personal data. Legally, the concept ranges from the mere planned request for data to its deletion, requiring compliance with the principles of lawfulness and data minimisation even before the data is obtained.

UNAMBIGUOUS CONSENT

Clear and demonstrable authorisation granted by the data subject. The burden of proof lies with the company, which must take diligent steps (for example, identity verification) to establish this beyond doubt.

DATA MINIMISATION

A fundamental principle requiring the data controller to collect and process only information that is adequate, relevant and limited to what is strictly necessary for the intended purpose.

DATA CONTROLLER

The organisation or company that determines the purposes and means of personal data processing. It has a duty to provide information and is responsible for documenting the instructions for third-party subcontractors.

DATA PROCESSOR

A subcontractor that processes data under the formal instructions of the data controller. If it uses the information for its own purposes, it automatically becomes an independent data controller, assuming full legal responsibility.

DATA PROTECTION IMPACT ASSESSMENT (DPIA)

A mandatory analysis that a company must carry out before implementing intrusive technologies (such as biometric systems). It requires a systematic description of operations, an assessment of risks and the definition of specific mitigation measures.

PSEUDONYMISATION

The process of replacing directly identifying data with an alphanumeric code or alias. It does not render the data anonymous; therefore, its processing remains subject to the regulations if the data subject can be re-identified.

Do you know which of these fifteen points your company is breaching today? We review your processing activities, your data processing agreements and your internal controls to show you where you are exposed to an AEPD penalty: write to us and we will go through it with you.

Frequently asked questions

When does the processing of personal data legally begin?

Before the data is ever stored. The mere planned request for an item of personal data already amounts to processing, so the principles of lawfulness and data minimisation apply from the moment the form or the question is designed, not from the moment the information is filed.

Can a company consider itself the owner of its customers’ data?

No. Under Spanish law there is no commercial ownership of the data of natural persons: data protection is an autonomous fundamental right that grants the power of disposal and control to the individual alone. The company is the controller of the processing, never the owner of the information.

Who has to prove that the customer gave consent?

The company. Consent must be unequivocal and demonstrable, and in the event of a dispute it is for the company to prove conclusively that it obtained consent, having also taken diligent steps to verify the identity of the person giving it.

What is the difference between a controller and a processor?

The controller determines the purposes and means of the processing; the processor only handles the data in accordance with documented instructions set out in a formal contract. If the processor uses that data for its own purposes, it becomes an independent controller and assumes full responsibility for the infringement.

Can a company impose fingerprint or facial recognition clocking-in?

Not on a mandatory basis without more. A biometric template that uniquely identifies a person is special category data: it requires a three-part proportionality test, a prior data protection impact assessment and the offer of less intrusive alternatives to employees and users.

Is replacing names with a code enough to fall outside the GDPR?

No. Pseudonymisation is not anonymisation: if a third party can reasonably link that code to the individual, the information remains personal data and its processing or publication must comply with the GDPR.

Can an employer inspect an employee’s computer or email?

Yes, but only if it satisfies the Barbulescu test: prior, clear and sufficient information about the monitoring criteria, the methods used and the restrictions on personal use. Without that prior information, the employee retains a reasonable expectation of privacy.

When buying a company, must its customers be asked for consent again?

As a general rule no: the transfer of a customer base arising from the purchase of a business is not treated as an unlawful disclosure requiring fresh consent. The duty to inform does remain: the acquirer must communicate the change of ownership, who the new controller is and how to exercise data subject rights.



Contact
Don’t be left in doubt, get in touch. We’ll be happy to help and offer you solutions.

GUÍA GRATUITA

Regulación Financiera España 2026

DORA + MiCA + MiFID II + EMIR en un solo documento

Descargar gratis →

Videos relacionados

Cargando videos…

Discover more from ILP Abogados

Subscribe now to keep reading and get access to the full archive.

Continue reading