Open one of your standard contracts. Find the data protection clause. You will almost certainly find a sentence like this: "in the event of non-payment, your data may be reported to credit default registers or solvency registers". Somebody drafted that sentence a decade ago, it has survived several revisions untouched, and today it is, literally, the reason your company would lose the case if a registered debtor sued you. Not because the clause is missing. Because the clause says nothing.
The rule: either you name the register, or you demand payment before registering
Reading Article 13 GDPR together with Article 20 of the LOPDGDD (the Spanish Data Protection Act) leaves the creditor two routes, and only two. Either the contract giving rise to the debt tells the customer the specific credit information system (CIS) to which their data will be reported — together with the rest of the Article 13 information, in particular paragraphs 1(e) and 2 — or, before registering, you send a prior payment demand warning of possible registration. Without the first, the second is compulsory. Without either, the entry is unlawful and defective from minute one.
This allows the interpretation that the prior demand will only be necessary where the contract has not informed the person concerned of the specific CIS in which the creditor participates and of the other requirements laid down in Article 13 of Regulation (EU) 2016/679. [translation]
Note the word that decides everything: specific. It is not enough to warn that credit default registers exist. You have to say which one: the system your company participates in and to which it will actually report the non-payment.
Generic clauses do not work. None of them.
"Credit default registers". "Solvency registers". "The credit information systems provided for by law". All those formulas — the ones in the vast majority of Spanish contracts in circulation — have been examined by the courts and all of them have failed. The reasoning is simple: a warning that does not name the register does not allow the customer to know where they will appear or to exercise their rights against that register. It is the appearance of information, not information.
Clause 11 of the contract neither sets out nor makes any mention of the systems in which it participates. That is to say, it does not set out the identification of the registers (...) and the mere generic reference (...) is not sufficient for the alternative condition to the prior payment demand to be regarded as satisfied. [translation]
Note the end of the quotation: the contractual information is the "alternative condition" to the demand. If the clause is generic, it is not that your company has a minor formal defect: it is that the prior payment demand, which you thought was optional, was compulsory and was not made.
This is not an isolated judgment: it is case law in series
The Provincial Court of Appeal of Vizcaya (Audiencia Provincial de Vizcaya) alone has repeated it six times in a single year: judgments 136/2022, of 27 May; 265/2022, of 15 June; 292/2022, of 7 July; 197/2022, of 12 July; 225/2022, of 8 September; and 319/2022, of 7 September. To these must be added SAP Orense 629/2021 cited above. The wording is almost identical in all of them:
Creditors must send the prior payment demand where the contract has not indicated the specific CIS in which that creditor participates, in addition to the rest of the information set out in Article 13 GDPR. [translation]
For a company director, this uniformity has a very practical reading: predictability works against you. The debtor's lawyer does not need to build a novel argument; it is enough to photocopy your clause, cite six judgments saying the same thing and wait. When the judicial criterion is this settled, litigation is not a risk: it is an outcome.
The prior payment demand cannot be improvised either
If your current contracts do not name the CIS — and until you correct them — your whole registration process depends on the prior payment demand. That requires a protocol, not a habit: what is sent, when, with what content and, above all, with what proof of dispatch. Remember that the accountability duty in Article 5(2) GDPR places on your company the burden of demonstrating that the processing was diligent (SAP Asturias 412/2024, of 3 October): a demand that cannot be proved before the judge is worth the same as a demand that was never sent.
What to do with your contracts, in order
- Today: find the credit default clause in every contract template in use and check whether it names the specific CIS. It is a five-minute read per contract.
- This week: until the clause is corrected, freeze any entry without a documented prior payment demand. Every one that goes out is a winnable claim against you.
- This month: correct the templates — naming the system, Article 13 information — and formalise the demand protocol for the older book, which will continue to be governed by the old contracts for years.
This contractual defect is the most widespread of the five mistakes generating most adverse judgments in credit default registers, and the only one that is inherited: every contract signed with the old clause carries the problem for its whole life.
If you want to know where your company stands before you touch anything, the Exposure Test examines in ten minutes your clause, your demand protocol and the rest of the criteria a judge would use to assess your entries.
Does your clause name the register, or only appear to?
Check it now against the same criteria the Provincial Courts of Appeal apply. Ten minutes, no confidential data, immediate result.
Take the Exposure Test