July 2026
The right to privacy undoubtedly forms the foundation upon which the protection of personal data in the employment context is built. However, recent regulatory developments emerging across the world of work, often pursuing different objectives and policy goals, are reshaping not only the way privacy rights and data protection are understood, but also the importance of identifying points of friction between overlapping legal obligations. Organisations must ensure that their actions adapt to an increasingly complex regulatory environment. The key lies in recognising potential areas of conflict, mitigating the risk of unforeseen non-compliance and adopting a case-by-case approach rather than relying on the automatic application of generic legal solutions. In this context, competitive advantage will favour those organisations best able to navigate and reconcile competing regulatory demands.
It is well established that an employment relationship does not entitle employers to process employee data without limitation. The legal bases most commonly relied upon are the performance of the employment contract (Article 6(1)(b) GDPR), compliance with legal obligations (Article 6(1)(c) GDPR) and, in certain monitoring activities, legitimate interests (Article 6(1)(f) GDPR). Employee consent, given the imbalance of power inherent in the employment relationship, must be used with particular caution. Yet despite these well-known principles, less attention has been paid to the challenges posed by other regulations that apply alongside the GDPR and which are equally significant in shaping employers’ obligations.
This became evident with Spain’s Remote Work Act (Law 10/2021), where various forms of employee monitoring technology highlighted the fine line between what is and what is not permissible from a data protection perspective. Monitoring measures may be deemed disproportionate if they fail to satisfy the requirements of necessity, proportionality and prior transparency. In this context, employers have had to strike a careful balance between complying with remote work obligations and avoiding practices that could undermine the fundamental principles of data protection.
Similarly, Royal Decree 902/2020 on equal pay introduced the risk of indirect identification of individual remuneration, particularly in highly specialised roles. Compliance already required measures such as data aggregation, access controls and strict purpose limitation, creating a clear intersection with data protection requirements. Today, as Spain moves towards the transposition of the EU Pay Transparency Directive (Directive 2023/970), the implications for employment relations are becoming increasingly apparent. The impact on data protection compliance, in particular, highlights the importance of identifying new risks within the existing legal framework. The challenge facing employers is no longer simply one of compliance, but of ensuring compliance with one set of obligations without inadvertently breaching another.
The European Pay Transparency Directive, whose objective is to promote equal pay through greater salary transparency, illustrates this tension particularly clearly. The Directive imposes obligations on employers to provide information regarding pay levels, gender pay gaps and job classification criteria. Inevitably, this requires the processing of employees’ personal data, including remuneration, job categories, length of service and compensation components.
Although the Directive has yet to be fully transposed into Spanish law, the adoption of implementing legislation is expected in the near future, and organisations are already preparing for a new employment relations landscape. The tension with the GDPR, Spain’s Organic Law on Personal Data Protection and even broader digital rights protections arises from the fact that pay transparency requires sufficient information to identify and address discrimination, while data protection rules require that personal data be adequate, relevant and limited to what is strictly necessary. At first glance, these objectives may appear to be in conflict. For this reason, it is essential that businesses are prepared for the forthcoming regulatory developments and adapt their governance and compliance frameworks accordingly.
Against this backdrop, understanding and complying with data protection obligations will be a fundamental starting point for organisations seeking to prepare for the future of work. Employment law has increasingly moved towards a landscape in which transparency plays a growing role, sometimes in ways that challenge established approaches to privacy and data governance. For businesses, understanding these evolving rules will be critical to ensuring that decisions remain reasonable, proportionate and fully aligned with the broader regulatory framework.
Companies that fail to adapt their practices or establish a clear roadmap for managing regulatory tension risk placing themselves at a competitive disadvantage. Success will depend on the ability to develop flexible and responsive management strategies grounded in a careful assessment of each individual case. In this new phase of the digital economy, context-specific analysis will become increasingly important, helping organisations create greater certainty in an environment characterised by complex and sometimes competing legal obligations.
Ultimately, this regulatory friction challenges organisations to become more agile, adaptable and capable of responding to a wide range of evolving scenarios. The convergence of employment, equality, prevention and data protection obligations means that Spanish businesses must now operate within a multi-layered compliance environment. In this setting, data protection is no longer an isolated legal requirement or an exception to other corporate obligations. Rather, it has become a cross-cutting framework that must be embedded in every significant business decision.
Selene Ricasoli
Associate at Bruchou & Funes de Rioja – Argentina
Member firm of Ius Laboris, the international alliance of employment law firms of which Sagardoy is a founding member.