Certix

Autónomos and GDPR: minimum obligations every self-employed professional must meet

Certix
Certix®
· 1 Jun 2026 · 7 min read

Informative article. It does not replace individualised professional advice.

An autónomo (self-employed professional in Spain) handles personal data from the very first client: name, tax ID, address, email, phone, bank account number, sometimes photographs or identity documents. Not having employees, an office or a formal legal structure does not reduce any obligation under the GDPR (Regulation (EU) 2016/679) or the LOPDGDD (Spain's Organic Law 3/2018). What does change is the proportional scope of the documentation: what in a company with a hundred employees becomes folders of protocols, for a self-employed professional fits into four or five well-written pages.

This guide summarises the minimum obligations of the freelancer under the GDPR, the LOPDGDD and the LSSICE (Spain's Law 34/2002 on Information Society Services) where the activity includes a web presence. It is aimed at the professional with no employees and at the micro-autónomo: consultant, commercial lawyer, physio renting a treatment room, digital freelancer, photographer, trainer, translator, independent sales agent.

The initial mistake: thinking the GDPR is only for big companies

The GDPR applies to any natural or legal person processing personal data in the context of a professional activity. The only exemption relevant to a self-employed professional —the so-called household exception (Art. 2(2)(c) GDPR)— is limited to purely personal or household activities. A private telephone book is outside scope; the autónomo's commercial address book is not.

The second frequent mistake is assuming that without a website or newsletter there are no obligations. But a self-employed professional processes personal data even if they only invoice: the client's name, tax ID and address appear on every invoice issued, in the VAT ledger, in the quarterly form 130 or 303 return, and in the copy kept by the gestoría. All of that falls within the GDPR.

The four typical processing operations of an autónomo

To design useful documentation without oversizing it, it helps first to identify what an average freelancer actually does. Almost any activity boils down to four operations:

Processing operation Data handled Legal basis
Client management Name or company name, tax ID, address, contact details, IBAN, correspondence. Performance of contract (6(1)(b))
Supplier management Details of the gestor, IT provider, coworking space, utilities. Performance of contract (6(1)(b))
Tax and accounting compliance Client data on invoices, forms 130/303/390/347/349, VAT and income ledgers. Legal obligation (6(1)(c))
Commercial communications Contact list for newsletters, mailings to clients with similar products. Consent or legitimate interest (6(1)(a)/6(1)(f)) + Art. 21 LSSICE

Identifying these four blocks helps to right-size the RoPA and to avoid inventing "processing activities" that do not actually exist. A self-employed professional with no active marketing should not document marketing as a processing operation; one without a website does not need a web privacy policy.

Minimum documentation for the autónomo

What follows is the proportional baseline any self-employed professional should have available. Done well, it fits in a digital folder with fewer than ten files.

  • Record of Processing Activities (RoPA): one page, three or four entries, with the information required by Art. 30(1) GDPR for each processing operation (controller, purpose, categories of data subjects, categories of data, recipients, retention period, security measures).
  • Information clause for clients: a paragraph or two in the first contact (welcome email, signed quote, contract) with the information required by Art. 13 GDPR.
  • Privacy and cookie policy on the website, if there is one. The privacy policy fulfils Art. 13 GDPR towards visitors; the cookie policy fulfils Art. 22(2) LSSICE.
  • Contract with the gestoría or advisory firm under Art. 28 GDPR, since the gestoría acts as processor of the data of the autónomo and their clients. The gestoría usually offers this contract as an annex to its engagement letter.
  • Art. 28 GDPR contracts with the relevant technology suppliers: invoicing software, email tool, cloud storage platform, CRM if any.
  • Basic security policy: one page setting out operational measures (individual strong passwords, two-factor authentication, backups, laptop encryption, automatic screen lock, up-to-date antivirus, physical or logical separation between professional and personal devices).
  • Breach protocol: two paragraphs setting out what to do if the laptop or work phone is lost, if a successful phishing attack occurs or if an incident is detected. Includes how to notify the AEPD (the Spanish Data Protection Authority) within 72 hours where there is a risk to data subjects (Art. 33 GDPR).

The information clause: the most useful and the least implemented

Of all the documentation, the information clause is probably the most useful because it is the only one the client actually reads. A professional autónomo includes it in their first quote email or in the contract. A reasonable version fits in three or four lines:

"Your personal data will be processed by [name of the self-employed professional], with tax ID [X], as controller, to manage the professional relationship, to comply with accounting and tax obligations, and to handle your enquiry. The legal basis is performance of the contract and compliance with legal obligations. Data will be retained for the duration of the professional relationship and the minimum statutory periods thereafter. Data may be disclosed to the external gestoría and to public authorities when required by law. You may exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to [email]. You may also lodge a complaint with the AEPD (www.aepd.es)."

This clause resolves 80% of the obligations under Art. 13 GDPR towards the client. The rest —specific recipients, international transfers, automated decisions— is only added when it applies to the case.

The gestoría: the processor almost nobody documents

Almost every autónomo in Spain works with an external gestoría (Spanish accountancy/advisory firm) for filing tax returns, bookkeeping and sometimes payroll if there are staff. When the freelancer hands over their invoices —containing clients' personal data— to the gestoría, they are disclosing that data so that the gestoría can process it on their behalf. The gestoría acts as a processor (Art. 28 GDPR) over that data.

This relationship requires a written contract containing the elements set out in Art. 28(3) GDPR: subject matter, duration, types of data, obligations, confidentiality, security measures, sub-processors, assistance, breach notification, return of data at termination. Most gestorías offer this contract as an annex to their service letter or engagement sheet. The autónomo must review, sign and file it.

"GDPR for an autónomo is a question of proportion, not quantity. Five well-thought-out pages cover 95% of compliance. The rest —the hundred-page templates floating around online— are noise that confuses and protects no one."

Mario P. Talamillo · Managing Partner, Certix®

Website and cookies for the self-employed

If the autónomo has a web presence —a personal page, contact form, professional blog, online booking, newsletter— two further obligations arise:

  • Privacy policy accessible from the footer of every page, with the information required by Art. 13 GDPR adapted to the actual use of the site. If there is only a contact form, the document is minimal; with online booking or a shop it becomes somewhat more elaborate.
  • Cookie policy and banner, if the site loads analytics cookies (Google Analytics, Matomo), marketing cookies (Meta pixel, retargeting) or social media cookies. Any cookie that is not strictly necessary for the service requested by the user requires prior consent under Art. 22(2) LSSICE, with three equally weighted options in the banner: accept, reject, configure.

Phone, WhatsApp and laptop: the autónomo's devices

A self-employed professional typically runs the business from one or two devices: a laptop and a phone. The reasonable security measures of Art. 32 GDPR, applied to this reality, are short but important:

  • Individual strong passwords, distinct for each critical service (email, banking, invoicing software, gestoría's platform). A password manager is strongly recommended.
  • Two-factor authentication enabled on email, banking and any platform that supports it.
  • Full-disk encryption of the laptop (BitLocker on Windows, FileVault on macOS) and password/PIN lock on the work phone.
  • Automatic screen lock after five minutes or less.
  • Up-to-date antivirus and operating system.
  • Regular backups to an encrypted service, with a restore test once a year.
  • Operational separation between professional and personal use: ideally separate devices; at minimum, separate profiles and separate accounts on the same device.
  • Professional WhatsApp: use a different line from personal, do not store long client lists in chats, do not share groups where clients can see each other's phone numbers.

Retention: how long to keep the data

Retention periods for the autónomo are governed by several coexisting rules:

  • Accounting obligation: Art. 30 of the Spanish Commercial Code sets a six-year retention period for books, correspondence, documentation and supporting records, counted from the last entry.
  • Tax obligation: the Spanish General Tax Act sets general limitation periods of four years for tax debts; keeping documentation for at least that period avoids problems in audits.
  • Ordinary civil actions: Art. 1964 of the Spanish Civil Code sets a general five-year limitation period for civil claims.
  • Specific actions (construction defects, service performance, professional liability): may have their own time limits.

The practical rule is to keep data linked to a client while any legal or tax risk is still open and to delete it once all relevant time limits have elapsed. The exception is marketing data, governed by the validity of the consent or of the prior contractual relationship; it is deleted when the client unsubscribes.

Minimum autónomo checklist

  • One-page RoPA covering the three or four real processing operations of the business.
  • Information clause ready to be included in every first quote email or contract.
  • Privacy and cookie policy on the website if any, with a properly configured LSSICE banner.
  • Art. 28 GDPR contract signed with the external gestoría and with the main technology suppliers.
  • Basic one-page security policy with operational measures for the laptop and the phone.
  • Two-paragraph breach protocol with the steps in case of device loss or incident.
  • Retention periods documented per block, with accounting, tax and civil references.
  • Annual review of the documentation: new clients, new suppliers, new tools.

Frequently asked questions

Does an autónomo with no employees have to comply with the GDPR?

Yes. The GDPR applies to any natural or legal person who processes personal data in the context of a professional activity. What changes compared to a company with employees is the proportional scope of the documentation: a short RoPA, security measures over one or two devices and one-page policies. The principles of lawfulness, transparency, minimisation and retention apply in the same way.

Does a self-employed professional need a Record of Processing Activities (RoPA)?

Art. 30(5) GDPR provides an exemption for controllers with fewer than 250 employees unless there is risk, non-occasional processing or special categories of data are involved. In practice, a self-employed professional invoicing and dealing with clients on a continuous basis carries out non-occasional processing and benefits from a RoPA even if it were not strictly mandatory. An autónomo's RoPA is a single page with three or four entries.

Is it lawful for an autónomo to store the client's bank account number for future invoices?

Yes. Keeping the client's IBAN to issue future invoices linked to an ongoing commercial relationship is supported by performance of the contract (Art. 6(1)(b) GDPR). The complementary obligation is to inform the client. It is not lawful to share that IBAN with third parties without an additional legal basis or to keep it for years after the relationship has ended without a legal obligation justifying it.

Does a self-employed professional have to have a privacy policy on their personal website, even if it is only one page?

Yes. Any professional website with a contact form, subscription or the autónomo's online presence processes or may process personal data and must comply with Art. 13 GDPR. A self-employed professional's privacy policy need not be long: one or two clear pages with controller, data, purpose, legal basis, recipients (typically the gestoría), retention and rights. If the site uses cookies, an LSSICE banner is also needed.

This content is for informational and educational purposes only and does not constitute legal advice. Applying the regulation to each specific case requires individual analysis. Regional sectoral regulations may extend or modify time limits and requirements.

Need to organise your GDPR compliance as a self-employed professional without overdoing it?

At Certix we assign you a compliance specialist for self-employed professionals. No commercial intermediaries, no generic templates.

Speak to a specialist

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →