Posts

Frequency detectors in exams: they cheat with AI, and catching them has rules too
Of interest to youFrequency detectors in exams are lawful when they are passive, but the risk is not the device — it is how it is used. The law, the privacy limits and a six-step protocol.
Fingerprint time tracking in 2026: annulling the AEPD guidance did not make it legal
Of interest to youSpain's National Court annulled the AEPD biometrics guidance in June 2026. The instrument fell, not the rule: what your company must prove before keeping a fingerprint reader.

Twitter metadata is a privacy nightmare
Of interest to youTwitter/X metadata can reveal behavioural patterns and identify users even when the content of a post appears anonymous.

Data Processing Agreement under GDPR: when it is required and what it must include
Of interest to youLearn when a Data Processing Agreement is required under GDPR, what clauses it must include, and how to review processors, subprocessors, security, AI and international transfers.

Special Categories of Data Under the GDPR: Practical Guide
Of interest to youPractical guide to special categories of data under the GDPR: health, biometric, political, religious and sexual orientation data, Article 9 exceptions and safeguards.

Is the end of spam calls?
Of interest to youWhat does the General Telecommunications Law ("LGT") say about "spam" calls?
Is the end of spam calls? The General Communications Law ("LGT") was published on 28 June 2022.
In its article 66.1.b) it mentions that end users of interpersonal…

Property agency fined for exposing images of minors
Of interest to youThe fine imposed on a property agency for exposing images of minors has highlighted the importance of protecting the rights of minors.
An individual filed a complaint with the Spanish Data Protection Agency, with the aim of highlighting the…

Face recognition in exams: Is it proportionate?
Of interest to youThe Catalan Data Protection Authority (Autoritat Catalana de Protecció de Dades) has sanctioned the Universitat Oberta de Catalunya for collecting biometric data from its students through face recognition, in order to verify that they were…

Photographing Customer ID Documents: GDPR Risks and Data Minimisation
Of interest to youWhy photographing or copying customer ID documents may breach the GDPR and what less intrusive alternatives companies should assess.

Transborder data transfers
Of interest to youThe scope of transborder data transfers
The publication of the General Data Protection Regulation (GDPR) on May 25, 2016 in the European Union, served as inspiration worldwide for the implementation of data privacy laws.
Many countries,…

Sanction for recording underage soccer match
Of interest to youIn procedure PS/00313/2021, the Spanish Data Protection Agency (AEPD) has imposed a fine of €3,000 on a company specialized in recording soccer matches for capturing images of minors without prior consent from their parents.
Sanction for…

Lack of information on the processing of personal data
Of interest to youThe AEPD imposes penalties to real estate companies of up to 5,000 € for not informing the interested party of the processing of their personal data.
Several affected parties have filed complaints to the AEPD, in relation to the use of their…

Microsoft 365 in Schools: Privacy, Cloud Services and GDPR Lessons
Of interest to youLessons from the Microsoft 365 schools debate: cloud platforms, minors, contracts, international transfers and GDPR compliance.

Digital Markets Act DMA: key obligations
Of interest to youThe Digital Markets Act DMA regulates gatekeepers and core platform services. Key obligations and practical effects for digital businesses in the EU.

Digital Services Act DSA: key obligations
Of interest to youThe Digital Services Act DSA is now applicable, setting obligations for online platforms, marketplaces, search engines and intermediary services in the EU.

