Home › Knowledge Hub › Weekly Guidance Watch › AEPD — Data Protection in Employment Relations

Regulator guidance · surfaced resource

Data Protection in Employment Relations — the AEPD’s guide, updated December 2025

Agencia Española de Protección de Datos (Spain)Guidance — updated December 2025Spanish only

Most organisations’ largest and messiest personal-data estate is the one they built about their own people, and the hard questions in it are much the same everywhere: what you may ask a candidate, what you may look at online, what a person is entitled to see about how they were assessed, how long a rejected CV can sit in a folder, and where a clocking system stops being attendance and starts being surveillance. The AEPD has worked through those questions in a single document, drafted with the Spanish labour ministry, the employers’ confederations and the trade unions, and updated in December 2025. It is Spanish, non-binding, and decides nothing for a UK controller — but it is one of the fuller regulator-published treatments of the employment relationship we have come across, and we have found it unusually specific about the answers.

Published by
Agencia Española de Protección de Datos (AEPD) — the Spanish supervisory authority. The guide records that it was drafted with the participation of the Ministerio de Trabajo y Economía Social, the employers’ confederations (CEOE, CEPYME) and the trade unions (CCOO, UGT). We have no relationship with the AEPD and this is not an endorsement in either direction.
Type
Practical guide in seven chapters; six of them follow the arc of the employment relationship — general aspects · selection and recruitment · the relationship in progress · monitoring of working activity · workers’ unitary and union representation · health surveillance — behind an opening chapter that sets out the guide’s purpose. The guide states its own status expressly: «orientación de carácter práctico, no vinculante» — practical, non-binding orientation. It also notes the AEPD’s remit here is the private-sector employment context.
Versions & language
Spanish only. The cover reads “Guía actualizada en diciembre 2025”. The December 2025 text updates the AEPD’s GDPR-era guide of May 2021, which itself replaced a pre-GDPR guide of similar name. It is built on the GDPR and on Spain’s LOPDGDD (Ley Orgánica 3/2018), particularly its Title X digital-rights provisions. We could not locate an English edition on aepd.es. Two adjacent AEPD workplace documents are published in English and one is linked below.
Jurisdiction
Spain. Built on GDPR Art. 88, which lets Member States enact more specific employment rules, and on the LOPDGDD provisions Spain enacted under it. Not binding in the UK, and not merely a translation problem — several positions rest on Spanish statute with no UK counterpart. The UK reference points are the ICO’s employment guidance suite: Monitoring workers, Information about workers’ health, Keeping employment records (final version published 5 February 2025) and the draft Recruitment and selection guidance.
Primary audience
DPOs and privacy leads with HR in scope; HR and people-operations teams; employment lawyers; anyone specifying, buying or reviewing recruitment, monitoring or workforce-analytics technology. Directly operative for any group with a Spanish employing entity.
Topic tags
employment · HR data · recruitment · automated decision-making · profiling · biometrics · whistleblowing · working-time records · special category data · Art. 88
Availability
Free, no registration, direct PDF download from aepd.es.

Why it matters

The reason to read a Spanish guide about Spanish employment law is not the law. It is that somebody has taken the ordinary run of HR questions and answered each one on the record, with a stated basis, in one place — and that is unusual.

Where it lands hardest is recruitment. Four positions are worth having in front of you whatever jurisdiction you sit in.

Consent will not carry it. The starting point is that performance of the employment contract is the principal basis, “porque el consentimiento del afectado no es válido cuando se proporciona en un contexto de «desequilibro claro entre el interesado y el responsable del tratamiento»” — because consent is not valid where it is given in a context of clear imbalance between the data subject and the controller. It adds that a collective agreement cannot supply individual consent, and that the practical consequence is to keep consent requests out of the employment contract and in a separate document. The wording tracks Recital 43 GDPR; the guide’s stated authority is WP29 Opinion 2/2017. The reasoning holds under UK GDPR.

Social-media screening. “Las personas candidatas y las personas trabajadoras no están obligadas a permitir la indagación del empleador en sus perfiles de redes sociales, ni durante el proceso de selección ni durante la ejecución del contrato” — candidates and workers are under no obligation to allow the employer to look into their social-media profiles, during selection or during the contract. A public profile does not create a basis; the employer must show the processing is necessary and relevant to performing the job; and sending a “friend” request to obtain access is not legitimate.

Automated sifting. Where an algorithm sifts, the guide requires a DPIA at design and implementation, holds that a discriminatory outcome means the design must change, and sets a test for human review worth quoting in full: “Para ser considerada como intervención humana, el responsable del tratamiento debe garantizar que cualquier supervisión de la decisión sea significativa, en vez de ser únicamente un gesto simbólico. Debe llevarse a cabo por parte de una persona autorizada y competente para modificar la decisión” — the reviewer must be authorised and competent to change the decision, not merely present. The formula is the WP29’s, and UK law has now moved its scope test onto the same word. The Data (Use and Access) Act 2025 s. 80 replaced Art. 22 UK GDPR with Arts. 22A–22D, in force 5 February 2026; Art. 22A(1)(a) defines a decision as solely automated where there is “no meaningful human involvement”, and Art. 22A(2) requires the extent of profiling to be considered in judging that. The two tests do different jobs — the AEPD’s sits in the on-request intervention safeguard, the UK’s is applied at the outset to decide whether the safeguards bite at all — but they turn on the same idea, and a regulator has already written down what it thinks the idea means.

What happens to the CV of the person you did not hire. “Una vez concluido el proceso de selección, si la persona candidata no es contratada, desaparece la base jurídica para el tratamiento de datos” — once selection concludes and the candidate is not hired, the legal basis disappears; a talent-pool retention needs consent or a demonstrable legitimate interest, and otherwise the CV is destroyed. It also says consent is needed to pass a CV to another company even within the same group. Retention schedules tend not to answer this one cleanly.

Biometrics at work

The AEPD recommends verification over identification, and templates stored “en soportes que puedan ser conservados exclusivamente por las personas trabajadoras” — on media held by the workers themselves — with a DPIA compulsory if identification is chosen. The ICO arrived at a comparable place on comparable facts by enforcement rather than guidance: in February 2024 it ordered Serco Leisure and associated trusts to stop using facial recognition and fingerprint scanning for attendance checks across 38 leisure facilities, on the basis that less intrusive alternatives such as cards or fobs were available and no alternative had been offered. The AEPD also has an English-language document on exactly this — Guidelines: Clocking and attendance control processing using biometric systems, November 2023 — which is the obvious entry point for a reader who does not read Spanish. Note that those guidelines go materially further than the ICO has: the AEPD treats both biometric identification and verification as special-category processing and is sceptical that any Art. 9(2) condition is available for ordinary time-and-attendance absent a specific legal norm. Read them for the reasoning, and check the UK position separately.

A boundary, and it matters

Several positions here are Spanish statute, not European principle, and repeating them to a UK board would be wrong.

  • Criminal-records checks. The guide states a candidate cannot be required to produce a criminal-records certificate absent specific statutory authority, with a carve-out for work involving contact with minors. UK practice under the DBS framework, with Art. 10 UK GDPR and DPA 2018 Sch. 1, is materially different — the UK routinely permits basic checks the AEPD would want a specific norm to justify. Do not carry this one across.
  • Whistleblowing. The guide anchors its whistleblowing section on art. 24 LOPDGDD and on Art. 6(1)(e) public interest. Check that anchor before relying on it: art. 24 LOPDGDD was substituted by Ley 2/2023, and the three-month deletion default now sits at art. 32.4 of that law. Either way, a UK private-sector employer generally cannot rely on the public-task basis at all, and no UK three-month rule exists.
  • Working-time records. The universal clock-in duty with four-year retention is art. 34.9 of the Spanish Estatuto de los Trabajadores. The UK’s Working Time Regulations 1998 duty is narrower and shorter.
  • The bloqueo regime — mandatory blocking after erasure, art. 32 LOPDGDD — has no UK equivalent and should not be confused with Art. 18 restriction.
  • The structural point. The whole guide sits on Art. 88 GDPR. The UK retained Art. 88 UK GDPR but has nothing on the scale of LOPDGDD Title X; UK employment-specific provision sits in DPA 2018 Sch. 1 — Part 1 para. 1 (employment, social security and social protection, with an appropriate policy document) and Part 2 para. 12 (equality of opportunity) — and in ICO guidance, rather than in a statute of this shape. There is no UK document to compare this one to. That is why it is worth reading, and why it cannot be cited as authority.

The commercial line runs in two directions. The first is ordinary: employment data is where subject access requests concentrate, where they are most contested, and where the disclosure decisions are hardest — third-party data in a grievance file, another candidate’s assessment, an investigation report naming a reporter. A document that has already reasoned through those fact patterns shortens the argument and gives you something to cite that is neither your own view nor the other side’s. The second is worth saying plainly: the reason to get recruitment and monitoring right is not the fine. It is that these decisions are made about people who are not in the room when they are made, and often by a system chosen before anyone asked the question. Writing the basis down before the system goes in costs almost nothing; unpicking it afterwards is the expensive part, and by then somebody has already been sifted out. We hope you find it useful.

Read alongside the AEPD’s English-language biometric clocking guidelines (linked below); the EDPB Guidelines 01/2025 on Pseudonymisation where workforce analytics needs to be separated from identifiable HR records; and the AEPD Risk Management and DPIA Guide from issue #4, which is the method behind the DPIA this guide keeps requiring.

A Weekly Guidance Watch resource entry, curated by VulaPri. We summarise and link to the original; we do not reproduce or host it. Facts verified against the primary sources on 7 August 2026, edition re-checked 23 September 2026. Suggest a correction.