Even if you think not, you process personal data
You may think that, given the kind of business you run, you do not handle sensitive data on customers or suppliers. But at the very least you need their name, tax identification number and address to issue or receive invoices. That is already personal data, and holding it obliges you to protect it and to meet a series of duties towards the people concerned and the authorities.
Depending on your business, you may end up processing much more private information: health data, criminal records, family relationships, sexual orientation or religious beliefs. The law calls most of these special categories of data and requires greater care in processing them.
Which rules apply
This area is constantly evolving, always towards stricter requirements for the self-employed and businesses. Today the foundation is the General Data Protection Regulation (GDPR), a European Union regulation that has applied directly since May 2018 and replaced the regime of the old Spanish law of 1999. In Spain it is supplemented by Ley Orgánica 3/2018, de Protección de Datos Personales y garantía de los derechos digitales (LOPDGDD, the Spanish Data Protection and Digital Rights Act).
If you have a website or online shop, or send marketing by email or messaging apps, the Ley de Servicios de la Sociedad de la Información (LSSI, the Spanish Information Society Services Act) also applies. Among other things, it regulates cookies and advertising messages.
The obligations are not the same for everyone. They are stricter the larger the volume of data, the more sensitive it is, and depending on the channels through which you collect it and what you use it for.
The basic obligations
- Have a legal basis for each use of the data: a contract, a legal obligation, consent or a well-justified legitimate interest.
- Inform people of who processes their data, for what purpose, for how long and how to exercise their rights.
- Keep a record of processing activities. Small businesses have an exemption, but it does not apply when processing is regular, which in practice covers almost any business with customers or employees.
- Sign contracts with your processors, meaning the suppliers that access data on your behalf, such as your gestoría or IT service.
- Apply security measures appropriate to the risk and notify the Spanish Data Protection Agency of any breaches that pose a risk to individuals, within 72 hours.
- Respond to requests to exercise the rights of access, rectification, erasure, objection, restriction and portability, as a general rule within one month.
Do you need a data protection officer?
The data protection officer is the person who oversees compliance within the organisation. Whether you need one depends less on the size of the business than on its activity. The GDPR requires one, among other cases, when the core activity consists of processing special categories of data on a large scale or regularly and systematically monitoring individuals. The LOPDGDD adds a list of sectors that must appoint one, such as healthcare centres, schools, insurers, financial institutions and private security firms. I tell you whether this applies to you.
Situations with rules of their own
CCTV cameras, monitoring employees and their use of digital devices, and sending advertising all have specific rules. For example, camera footage must be deleted within one month at most, unless it is needed to prove a serious incident, and cameras must be signposted with an information sign.
If your collaborators access your customers’ data, also review your contracts with collaborators. And if you want me to keep everything up to date on an ongoing basis, I can include it in the comprehensive legal advice service.




