Certix

Client data on the self-employed professional's phone: WhatsApp, contacts and lawful handling

Certix
Certix®
· 1 Jun 2026 · 7 min read

Informative article. It does not replace individualised professional advice.

For most autónomos (self-employed professionals in Spain), the professional phone is the device where the business actually lives: the contacts list, chats with clients and suppliers, photos of completed work, invoices sent on the go and online banking. That concentration brings an enormous operational advantage and a very concrete cost from a data protection perspective: a single loss or theft affects practically the entire client base at once.

This guide summarises reasonable good practices for using the work phone without turning it into a compliance hole, under the framework of the GDPR (Regulation (EU) 2016/679) and the LOPDGDD (Spain's Organic Law 3/2018), with emphasis on what the average freelancer actually does: WhatsApp, contacts, service photos, backups, what to do in case of an incident.

Why the autónomo's phone is a unique device

Three features distinguish the self-employed professional's phone from the one used by an employee in a company:

  • Habitual mix of professional and personal use. The vast majority of freelancers use the same device to call clients, talk to family, do online shopping and keep photos of their last trip. That mix, acceptable in practical terms, makes it very hard to apply strict security policies unless separation is deliberately chosen.
  • Total concentration of the client base. The contacts list and chats bundle in a single device the data of every client the autónomo has ever had. A breach on the phone is a breach across the entire portfolio.
  • Mobility and physical risk exposure. A laptop usually stays on a desk; a phone goes in and out of a pocket, into public places, gets dropped, gets wet, gets left behind. The risk of loss or theft is structurally higher.

Separating professional from personal: the most profitable decision

The most effective way to reduce risk without overloading day-to-day work is to deliberately separate professional from personal activity on the phone. There are several reasonable options, ranked from strictest to lightest:

  • Two separate devices: a professional phone and a personal one. It is the cleanest separation, but also the most expensive and the least practical to keep up. It only makes sense if the activity generates many calls and messages per day.
  • One professional line and one personal line on the same phone (dual SIM or eSIM). Allows WhatsApp Business on one line and personal WhatsApp on the other, separates numbers from the client's point of view and makes professional hours clear.
  • Separate profiles on the same phone. Android supports work profiles; iOS does not, but allows the Professional Focus mode which hides personal apps during work hours.
  • At minimum, separation at app level: WhatsApp Business for clients, a professional Google account or Apple ID for email and contacts, a separate folder for work photos in the gallery.

Any of these options is better than none. What does not work is mixing everything in a single account and then trying to apply selective measures.

Professional WhatsApp: what is allowed and what is best avoided

WhatsApp is the dominant communication channel with clients in many Spanish professional sectors. It is lawful to use if it is done sensibly. These are the reasonable operational rules:

Allowed Best avoided
Answering operational queries from a client who has provided their number for that purpose. Sending copies of identity documents, medical reports or contracts with sensitive data without additional encryption.
Notifying changes to appointments or one-off contingencies. Creating groups with several clients where everyone can see each other's phone numbers.
Sending small photos of work in progress when the client has requested them. Using a personal WhatsApp mixed with professional clients.
Maintaining WhatsApp Business with a separate professional line and clearly stated hours. Retaining indefinitely conversations that no longer add anything.
Keeping encrypted backups of professional chats and archiving them when the relationship ends. Sharing screenshots containing a client's data with third parties without authorisation.

One point deserves attention: when several clients are gathered in the same professional WhatsApp group (group classes, workshops, community bookings), everyone sees the phone numbers of the rest. This turns the group into a cross-disclosure of personal data that would require a legal basis for all participants. The usual way to do it well is to inform group members beforehand and give them the option not to join, or to use a broadcast list where each conversation is bilateral.

The phone contacts list

The professional contacts list is a personal data file under the GDPR. Reasonable good practices are:

  • Label professional contacts to distinguish them from personal ones. The contacts apps on Android and iOS allow labels, groups or categories.
  • Minimise the fields of each card. Name, company, phone and email are enough for most cases. Adding personal details about the client to the notes (intimate preferences, sensitive situations) is disproportionate and increases the risk in the event of an incident.
  • Do not sync the professional contacts list with personal accounts (the family Google account, for example) or with platforms that scan contacts for their own purposes.
  • Delete contacts when the professional relationship ends and there is no legal obligation to keep them. The gestoría (Spanish accountancy/advisory firm) still holds the client's data for accounting and tax retention periods; the contacts list on the autónomo's phone does not need to keep them.
  • Encrypted backup of the contacts list to a professional service, not on the family computer.

Photos of completed work: the client's image rights

Many self-employed professionals share photos of completed work to attract new clients: the hairdresser's before-and-after, the architect's drawing and result, the renovator's finished living room, the photographer's sample session. The operational rule is simple:

  • If the photo only shows the result of the service with no identifiable persons or elements of the client, it may be shared without further requirement.
  • If the photo includes the client or people around them (photo session, hairdresser with client in the chair, before/after a cosmetic treatment), express, written, specific and revocable consent is required for each use (website, social media, messages to other clients).
  • If the photo shows the interior of the client's home (renovators, decorators, property photographers), it is advisable to obtain authorisation even if no people appear, because the home is part of the private sphere and the client may not want it publicly displayed.

Consent is collected once, when the service closes, with a simple signed form or a confirmation email that the freelancer files. If the client revokes it later, the autónomo must remove the photo from all channels within a reasonable period.

"The autónomo's phone is their business. If it falls and breaks, you lose a piece of metal and glass; if it is lost unencrypted, you lose the entire client portfolio. Encrypting the phone and enabling remote wipe takes five minutes and resolves 90% of the risk."

Mario P. Talamillo · Managing Partner, Certix®

Encryption, lock and remote wipe

Art. 32 GDPR requires the controller to apply technical and organisational measures appropriate to the risk. On the autónomo's phone, translated into concrete action:

  • Screen lock with a PIN, password or strong device passcode (not a simple pattern). Automatic lock after one or two minutes.
  • Encryption enabled by default on iOS and on most modern Android devices when a screen lock is set. Verify in settings.
  • Location and remote wipe enabled: Find my iPhone on iOS, Find My Device on Android. They allow locking or wiping the phone remotely from another device.
  • Encrypted backup to iCloud, Google One or a professional service, not on a home hard drive.
  • Automatic updates of the operating system and critical apps.
  • Apps only from the official store, without installing APKs from unknown sources on Android.

What to do if the phone is lost

The loss or theft of a phone containing professional data is a personal data breach. The reasonable protocol is:

  1. Lock the device remotely immediately from another device (Find my iPhone, Find My Device).
  2. Remote wipe of the device's data if it does not turn up within a few hours, especially if it was not encrypted.
  3. Change critical passwords: professional email, online banking, gestoría platforms, business social media.
  4. Police report in case of theft, including the device's IMEI.
  5. Risk assessment: what data was accessible, whether the phone was encrypted and locked, which clients might be affected.
  6. Internal record of the incident with all details and measures taken.
  7. Notification to the AEPD within 72 hours if the breach is likely to result in a risk to the rights and freedoms of data subjects (Art. 33 GDPR).
  8. Communication to affected clients where the risk is high (Art. 34 GDPR), explaining the situation, the measures taken and the precautions they can adopt.

Checklist for the autónomo's phone

  • Operational separation between professional and personal use (line, account or, ideally, device).
  • WhatsApp Business with a professional line, no groups with clients who see other clients' phone numbers.
  • Professional contacts list labelled and minimised, with encrypted backup and no syncing with personal accounts.
  • Strong screen lock, verified encryption and automatic lock within one or two minutes.
  • Location and remote wipe enabled.
  • Encrypted backup to a professional service with an annual restore test.
  • Clear policy on the use of client photos: express written consent before publishing.
  • Loss-or-theft protocol known and rehearsed.
  • Periodic review of old chats and files to remove data that no longer adds anything.

Frequently asked questions

Is it lawful for a self-employed professional to use WhatsApp to communicate with clients?

Yes, if done carefully. WhatsApp is valid when the client provides their number for that purpose or starts the conversation. Critical points: do not send sensitive documentation without encryption, do not include clients in groups where others see each other's phone numbers, do not mix personal and professional WhatsApp, and do not retain unnecessary conversations indefinitely. Recommended: WhatsApp Business with a separate line and encrypted backups.

Does the contacts list on the autónomo's phone fall within the GDPR?

Yes. The professional contacts list is a personal data file under Art. 4(6) GDPR. The household exception only covers purely personal or household activities. Good practice: separate professional from personal contacts, minimise fields, protect the phone with lock and encryption, and delete contacts when the professional relationship ends.

Can a freelancer send photos of completed work to other clients to attract new business?

It depends on the content. Photos of the service result with no identifiable persons or elements of the client may be shared without further requirement. If the photo includes identifiable persons or recognisable personal elements (interior of the home, intimate objects), express, written, specific and revocable consent is required, collected at the close of service.

What do I do if I lose the phone with my clients' data?

It is a breach under Art. 33 GDPR. Lock or wipe the device remotely, file a police report, assess the risk depending on encryption and accessible data, log the incident, notify the AEPD within 72 hours if there is risk and inform affected data subjects where the risk is high (Art. 34 GDPR). If the phone was encrypted and locked, the risk is significantly reduced.

This content is for informational and educational purposes only and does not constitute legal advice. Applying the regulation to each specific case requires individual analysis. Regional sectoral regulations may extend or modify time limits and requirements.

Would your work phone withstand loss or theft without compromising your clients?

At Certix we assign you a compliance specialist for self-employed professionals. No commercial intermediaries, no generic templates.

Speak to a specialist

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →