Spain's Royal Decree 723/2026, in force since 5 October, obliges companies to tell each worker in writing when automated systems help decide pay, hours, tasks, promotion, place of work or dismissal, according to a briefing dated today that also covers a related warning from the country's data protection agency.
In Short
Spain has made it a legal duty for companies to tell every worker, in writing, when automated software helps decide things like pay, hours or promotions. Workers already employed can ask for that information, and the company then has 30 working days to provide it. Separately, Spain's data protection agency has told one company that an AI tool for screening job applications needs risk checks and real human review before it is switched on.
What the decree requires
Royal Decree 723/2026 is dated 9 September 2026 and entered into force on 5 October 2026. It implements Article 8.5 of the Workers' Statute and partially transposes Directive (EU) 2019/1152, according to the briefing. The document frames the change in narrow terms: "What is new is not an authorization to use algorithms, but an additional duty to provide information about their existence and operation."
Who is covered
Chapter II applies, as a general rule, to employment relationships lasting more than four weeks, according to the briefing. Special employment relationships and public-sector employees also fall within it, subject to the particularities of their own regulations.
What must be disclosed
Article 3.2.k requires each employee to be informed in writing that algorithmic or automated decision-making systems exist. Where those systems feed into decisions on working hours, task allocation, pay, career progression, place of work, termination or other working conditions, the guidelines, criteria and operating rules must be explained as well. The existence of a system is therefore the floor; the explanation of its logic is triggered by its use in decisions that affect the worker.
Timing, format and existing contracts
The rules differ by situation. For new employment relationships, the information must arrive before the relationship begins. It can be delivered on paper or electronically, but it must be accessible, storable and printable, and the company must keep proof that it was transmitted or received. Any relevant change must be communicated as soon as possible and, at the latest, on the day it takes effect.
Existing staff are handled through a request mechanism. An employee who does not already hold the information may ask for it from the date of entry into force, and the company then has 30 working days from receipt of the request. Article 3.3 of the decree lets some items be satisfied by a simple reference to the law or to the collective bargaining agreement. The algorithmic information under Article 3.2.k is not among them, so it must be provided "in concrete terms", as the briefing puts it.
A template is due from the State Public Employment Service (SEPE). According to the briefing, it "may help document compliance, but its availability does not condition the enforceability of the obligation." In other words, the duty applies whether or not the template has been published.
Where data protection law enters
The decree does not stand alone. The briefing states that the employment-law duty does not displace the GDPR or Organic Law 3/2018. Where a system processes personal data, the company must at the same time satisfy the rules on lawfulness, transparency, accuracy, data minimization, data protection by design, risk management and, where applicable, automated decision-making.
Three disclosure tracks result, each with a different recipient, according to the briefing's summary table:
| Level | Recipient and legal basis | Main content |
|---|---|---|
| Individual employment | Each employee. Articles 3.2.k, 6 and 7 of Royal Decree 723/2026 | Existence of the system and, where it makes decisions on working conditions, its guidelines, criteria and operating rules |
| Collective employment | Legal representatives of the employees. Article 64.4.d of the Workers' Statute | Parameters, rules and instructions on which algorithms or AI systems are based that affect working conditions, access to and retention of employment, and profiling |
| Data protection | Affected candidates and employees. Articles 12 to 14, 15 and, where applicable, 22 of the GDPR | Purposes, legal basis, data, source, recipients, retention and rights; where there are relevant automated decisions, meaningful information about the logic involved, its significance and its consequences |
The briefing adds a practical limit. Information must be tailored to each stage and recipient, "without assuming that a collective communication satisfies the individual information obligation or the transparency required by the GDPR." A notice to a works council, in other words, does not settle what an individual candidate or employee is owed.
The AEPD warning on a screening tool
The second half of the briefing concerns warning AI-00009-2026, issued by the Spanish Data Protection Agency (AEPD). It examines a tool not yet deployed in Spain that would analyze résumés, assign scores according to fit for a position and prioritize applications in recruitment and internal mobility processes. The briefing notes that such a system "could therefore directly influence access to employment and career advancement."
Proceedings opened after the AEPD received information on 6 January 2026 about the possible deployment. The briefing does not name the company. In December 2025, according to the briefing, the entity had told employees' legal representatives that a person would make the final screening or rejection decision, that sensitive attributes would not be analyzed, and that the system would be subject to periodic audits.
The legal character of the document matters. The briefing describes the warning as "neither a finding of a completed infringement nor the imposition of a penalty." It is an exercise of the preventive power under Article 58.2.a of the GDPR, applied to processing operations that were likely to infringe the regulation. The AEPD has used that instrument before: PPC Land reported on 17 February 2026 that the agency issued a similar warning to Tools for Humanity, operator of an iris-scanning device, over impact assessment and transparency gaps ahead of a planned relaunch in Spain.
Requirements set out in the warning
The briefing says the organization must adopt, and be able to demonstrate, technical and organizational measures under Articles 24 to 35 of the GDPR, covering four areas:
- Risk and impact assessment. Risks to candidates and employees must be assessed, and a data protection impact assessment must be carried out before processing where a high risk is likely, under Article 35.
- Data protection by design and default. Design and minimization measures must be built in when the tool is selected, configured, tested and deployed, "rather than being added at the end."
- Security measures. These are determined according to the risk to individuals' rights, without prejudice to any security requirements of the system or the organization itself.
- Transparency and human intervention. The information must be clear, accessible and comprehensible.
On the last point the briefing is specific. "The formal presence of a person does not exclude the application of Article 22," it states, because the reviewer must be able to "critically assess the score and depart from it without being de facto conditioned by the automated result."
When Article 22 applies
Not every algorithm, and not all profiling, amounts to a decision under Article 22, according to the briefing. The regime applies where a decision rests solely on automated processing and produces legal effects or similarly significant effects for the individual. Where it applies, safeguards follow: the right to obtain human intervention, to express a point of view and to contest the decision. In employment, contractual necessity is read restrictively, and consent "will rarely be a secure basis if it cannot be shown that it was genuinely freely given."
A footnote cites two rulings of the Court of Justice of the European Union. In SCHUFA (7 December 2023, C-634/21), the court confirmed that an automated score may itself constitute an automated decision where the person who subsequently decides draws strongly on it. In Dun & Bradstreet Austria (27 February 2025, C-203/22), it added that meaningful information must explain, in a concise, transparent and intelligible manner, the procedure and principles actually applied, so that the data subject understands which data were used and how they influenced the outcome. Source code need not be disclosed, the briefing notes, "but neither does it accept generic or purely technical explanations."
Scores, inferences and monitoring
Protection does not stop at the data fed into a system. According to the briefing, scores, rankings, profiles, predictions and inferences associated with an identifiable person may themselves be personal data. That brings accuracy duties into play, including review of outdated information, proxy variables and outputs that could produce discrimination.
Where special categories of data are processed, Article 9 conditions must be met. A vendor's assurance does not close the question: "A statement that a tool does not use sensitive attributes is not sufficient on its own," the briefing says, since other variables might allow such attributes to be inferred or to act as proxies. Systems tied to digital devices, video surveillance, sound recording or geolocation also engage Articles 87 to 90 of the LOPDGDD, the Spanish data protection act, together with the corresponding employment safeguards.
Further points drawn from the warning
The briefing lists three issues beyond the core requirements.
First, responsibility stays local. A tool developed or assessed centrally by a corporate group does not relieve the entity that decides to use it in Spain. That entity must determine and document its position as controller, joint controller or user of a processor's service, the allocation of decisions, contractual safeguards, data location and international transfers, and its own conclusion on lawfulness, necessity and proportionality.
Second, audits need content. "A reference to periodic audits does not in itself demonstrate compliance," the briefing says. To be verifiable, an audit should record its purpose and scope, the version of the system examined, the data and variables tested, error rates, differentiated impacts, the effectiveness of human oversight, incidents and complaints detected, and corrective measures. It must also be established when the assessment will be repeated after changes to the model, data or purpose.
Third, human oversight is judged on substance. The reviewer must know the system's limitations, have access to the relevant factors, have the time and authority to change the result, and be able to consider additional information. The briefing calls it advisable to record disagreements with the automated recommendation, adding that "a systematic absence of disagreements may indicate practical dependence on the score and should prompt a review of the process."
Candidates who are never hired remain protected by the data protection regulation, the briefing adds, even though they are not recipients of the employment-law duties specific to an employment relationship. In internal mobility, the rights of the employee and of legal representatives both come into play.
The eight actions before deployment
The briefing sets out eight actions, with the caveat that "it is for the controller to analyze which actions (these or others) may be appropriate depending on the processing." They are: an inventory of systems that support or make decisions on applications, working hours, tasks, performance, remuneration, promotion, mobility, place of work or termination, including third-party services; a systematic description of the processing and its data lifecycle; documentation of purpose, controllers, input data and sources, inferences, main variables, decision rules, recipients, retention, transfers and the actual role of reviewers; a separate determination of legal basis, Article 22 applicability, risk level, the need for an impact assessment and the classification under the Artificial Intelligence Act; coordinated information for employees, candidates and legal representatives; validation, with representative examples, that the explanation is comprehensible "without disclosing trade secrets beyond what is necessary"; demonstrable human oversight; and retained evidence of delivery of information, tests, audits, model changes, incidents, complaints and corrective measures.
The conclusion is blunt. Royal Decree 723/2026, according to the briefing, "turns algorithmic transparency into a condition of the employment relationship, which must be communicated in advance, in writing and in a traceable manner." It adds that "providing information does not in itself legitimize the system."
Context: Spanish enforcement and the wider European picture
Spain is not a marginal jurisdiction for data protection enforcement. An analysis PPC Land published on 30 May 2026 counted 2,879 enforcement actions across Europe since May 2018 and €7.1 billion in announced fines, of which nearly 40% had been annulled or were being contested in court. Spain led on volume with 1,070 actions, although its €137 million total pointed to a lower average per case.
The AEPD's attention to impact assessments has a recent record. The agency fined FC Barcelona €500,000 on 4 March 2026 over a biometric assessment that did not systematically describe the data categories or genuinely evaluate proportionality. Six days later the European Data Protection Board released version 1.0 of its first impact assessment template, with a public consultation open until 9 June 2026. In February 2026, the AEPD's guidance on agentic AI had already flagged automation bias, the habit of accepting automated output without critical analysis, as a risk that grows with system autonomy. The point reappears in the new briefing as the test for whether a human reviewer is real.
Two EU-level moving parts sit alongside the Spanish decree. On the AI Act, European Parliament committees voted 101-9 in March 2026 to replace a discretionary mechanism with fixed dates. Under that text, obligations for high-risk systems covering employment screening, credit scoring and biometric identification would apply on 2 December 2027 rather than in August 2026, roughly 14 months after the Spanish decree took effect. The text's final status falls outside the briefing.
On the GDPR itself, a Council draft reported on 21 September 2026 restores language treating automated decisions as a right rather than a permission, and removes the Commission's phrase allowing such decisions for contracts regardless of whether another route was available. The same text keeps a proposed Article 88bis allowing processing for a legitimate interest in AI contexts, but moves the unconditional right to object and the explicit protections for children out of the operative articles and into non-binding recitals. Whether Article 22 is narrowed or kept intact will determine how far the Spanish reading of human intervention travels.
Why this matters to the marketing community
The briefing addresses recruitment and workforce management, not advertising. Its legal reasoning, however, rests on provisions that govern profiling in every sector. The statement that scores, rankings, predictions and inferences can be personal data is the same principle regulators apply to audience segments and propensity models. The SCHUFA reasoning, under which a score that a downstream human relies on heavily can count as the decision, bears on any pipeline where an automated rating feeds a nominally human choice. The Dun & Bradstreet Austria standard on explaining "the procedure and principles actually applied" sets a bar that generic privacy-notice wording does not meet.
There is also a direct operational overlap. Marketing and talent-acquisition teams increasingly share vendors, from résumé-parsing software to programmatic recruitment advertising. For companies operating in Spain, those tools now sit inside a framework with a written disclosure duty, a 30-working-day response window for existing staff, and a regulator that has signalled it will examine impact assessments, audit design and reviewer independence before launch rather than after complaints.
The briefing leaves several matters open. The SEPE template had not been published at the time of writing. The briefing records no enforcement under the decree, and the AEPD warning carries no penalty. The identity of the company behind the screening tool remains undisclosed.
Timeline
- 7 December 2023: the Court of Justice of the European Union rules in SCHUFA (C-634/21) that an automated score can itself be an automated decision where the person deciding draws strongly on it.
- 27 February 2025: the Court rules in Dun & Bradstreet Austria (C-203/22) that meaningful information must explain the procedure and principles actually applied.
- December 2025: an entity tells employees' legal representatives that a person would make the final screening decision and that sensitive attributes would not be analyzed.
- 6 January 2026: the AEPD receives information on the possible deployment of an AI screening tool for recruitment and internal mobility.
- 13 February 2026: the AEPD signs a warning to Tools for Humanity under Article 58.2(a), reported on 17 February.
- 4 March 2026: the AEPD publishes its €500,000 fine against FC Barcelona over a deficient impact assessment.
- 10 March 2026: the European Data Protection Board releases version 1.0 of its impact assessment template.
- 22 March 2026: European Parliament committees vote 101-9 to fix 2 December 2027 for high-risk AI systems listed in Annex III.
- 30 May 2026: PPC Land publishes an analysis of €7.1 billion in announced GDPR fines, nearly 40% annulled or contested.
- 9 September 2026: date of Royal Decree 723/2026.
- 21 September 2026: a Council draft on the Digital Omnibus restores Article 22 language and keeps Article 88bis.
- 5 October 2026: Royal Decree 723/2026 enters into force; existing employees can start requesting information, with 30 working days for the company to respond.
- 7 October 2026: date of the briefing on the decree and on AEPD warning AI-00009-2026.
- 2 December 2027: date proposed in the committee text for AI Act obligations on high-risk systems, including employment screening.
Related PPC Land coverage
- Eight years of GDPR: 40% of the EUR7.1B in fines annulled or under challenge - tallies 2,879 enforcement actions and shows where Spain sits by volume and total fines.
- Spain fines FC Barcelona EUR500,000 for failing biometric data protection assessment - covers the AEPD's decision on a deficient impact assessment.
- EDPB's first-ever DPIA template finally lands, but experts want more - details the minimum standard for impact assessments across EU supervisory authorities.
- Spain's data regulator warns World's iris-scan operator over GDPR risks - explains an earlier use of the AEPD's Article 58.2(a) warning power.
- Spain's data watchdog maps the hidden GDPR risks of agentic AI - sets out the AEPD's guidance on human oversight and automation bias.
- EU Parliament committee backs AI Act delay with fixed 2027 deadline - reports the 101-9 committee vote and the 2 December 2027 date for Annex III systems.
- EU Council draft drops unconditional opt-out from GDPR AI clause - describes the Council text on Article 22 and Article 88bis.
Summary
- Who: Spanish employers and public bodies subject to Royal Decree 723/2026; employees and job candidates in Spain; the Spanish Data Protection Agency (AEPD); an unnamed company planning an AI tool to screen applications.
- What: A decree requiring written information about automated decision-making systems that affect working conditions, alongside AEPD warning AI-00009-2026, which sets out risk assessment, explanation and human oversight requirements for a not-yet-deployed screening tool.
- When: The decree is dated 9 September 2026, entered into force on 5 October 2026, and the briefing is dated 7 October 2026. Existing employees can request information from entry into force, and companies have 30 working days from receipt to respond.
- Where: Spain, within the framework of EU law, including the data protection regulation and Directive (EU) 2019/1152.
- Why: The decree turns algorithmic transparency into a condition of the employment relationship, while the AEPD warning shows that disclosure must be backed by impact assessment, verifiable audits and real human review, according to the briefing.
Discussion