Skip to main content

Article 5 GDPR · Data accuracy principle

The disputed debt you registered is an adverse judgment in the making

Only debts that are certain, due, payable and beyond doubt may be reported to a credit default register. Everything else is paid for. So is complying without being able to prove it.

Your company registered a customer in a credit default register. The invoice was unpaid, yes. But the customer disputed it: they claimed the service was defective, denied part of the amount, had a complaint open. Months later a claim arrives for infringement of the right to honour. It is not signed by an imaginative lawyer: it rests on a settled line of case law, repeated by several Provincial Courts of Appeal (Audiencias Provinciales), which your company did not know about.

This article explains that line. First, what it costs. Then, why.

What is at stake: awards for improper registration in credit default registers run, as an indicative range, from 3,000 to 10,000 euros plus costs per person affected, with an indicative average award of around 4,500 euros. If your collections book registers dozens of debtors on the same defective criterion, multiply.

The rule: certain, due, payable and beyond doubt

Article 5 GDPR enshrines the data accuracy principle: the personal data processed must be accurate, truthful and up to date. Applied to credit information systems, the courts have turned it into a filter with four conditions. The debt you report must be:

  • Certain: it exists, it is documented and it does not depend on an interpretation that favours you.
  • Due: the payment deadline has passed. A future instalment cannot be registered.
  • Payable: you can demand it now, with no outstanding condition preventing it.
  • Beyond doubt: nobody is seriously disputing it. Not in court, not in a formal complaint, and not in an email in which your customer denies owing that amount.
SAP Orense 231/2026, of 10 April
The case law has been taking the view that failure to meet these requirements amounts to an infringement of the principle of accuracy of personal data enshrined in Article 5 of Regulation (EU) 2016/679. [translation]

The same court had already said so in SAP Orense 629/2021, of 29 December: anyone using an extraordinary means of pressure such as a credit default register must guarantee the accuracy of the data it registers. This is not a best-practice recommendation. It is the condition for the processing to be lawful.

"Disputed" means exactly that

This is where most companies fall. A disputed debt does not cease to be registrable only when the customer turns out to be right. It ceases to be registrable when there is a serious controversy about it, whoever is right. A credit default register is not an instrument for winning the argument: it is a record of established insolvency. Using it as a collection lever over a debt in dispute is, in the words of the courts, an unlawful act.

SAP Orense 385/2023, of 13 June, puts it plainly: the rules rest on the principles of prudence, balance and truthfulness, and any disclosure of information that does not meet the accuracy required by Article 5 is an unlawful act capable of also infringing the right to honour of the person affected. In other words: on top of the data protection breach comes the claim for damages to honour. Two fronts, one badly managed billing clause.

Accuracy is not a snapshot: it is a continuing obligation

Suppose the debt was impeccable when you registered it. The customer then pays, or pays part, or you agree to write part of it off. If the register still shows the old figure, your company is in breach again. Article 5(1)(d) GDPR requires the data to be kept accurate at all times, not only on the day of registration.

SAP Asturias 412/2024, of 3 October
Under Article 5(1)(d) GDPR, data shall be accurate and, where necessary, kept up to date, which obliges controllers to take every reasonable step to ensure that inaccurate data are erased or rectified without delay. [translation]

In operational terms: your collections process needs a mechanism that connects every payment, settlement or subsequent dispute with the immediate updating of the register. If that connection depends on somebody remembering, it does not exist.

Complying without being able to prove it is not complying

The second layer of the problem, and the most uncomfortable. Article 5(2) GDPR — accountability — reverses the burden: it is not for the person affected to show that their debt was disputed; it is for your company to show that it was certain, due, payable and beyond doubt, and that you acted diligently. In court, silence in the documents counts against you.

SAP Asturias 412/2024, of 3 October
And, under Article 5(2) GDPR, "the controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 («accountability»)". [translation]

SAP Madrid 123/2026 takes the same principle a step further: in relation to Article 6(4) GDPR, it is for the controller alone to determine and to demonstrate that the purpose for which it uses the data is compatible with the purpose for which it collected them. Determine and demonstrate. If your company decided to register but left no trace of how it verified the debt, it will have complied halfway. And halfway, before a judge, is not at all.

What you should be able to produce tomorrow morning

Think of the last entry your collections department ordered. If the claim arrived tomorrow, could you put this file on the table without improvising?

  • The contract and the invoices documenting that the debt is certain and has fallen due.
  • Evidence that, on the date of registration, there was no complaint or open dispute from the customer.
  • The written criterion your company uses to decide which debts are reported and which are not.
  • The record of updates: what happened in the register when the customer paid or disputed.

If any of those four pieces is missing, your exposure is not theoretical. It is the first of the five mistakes generating most adverse judgments in credit default registers, and the one that leaves the least room for defence, because the defect is written into the register itself.

The good news: it is a measurable risk. You can find out today, from your own answers, where your company stands before a claim tells you. The Exposure Test runs through exactly these points — data accuracy, information given to the customer, ability to prove — and gives you an immediate diagnosis.

Would your last entry pass this test?

Ten minutes, no confidential data. You will know which criteria a judge will apply to your entries and where you are falling short today.

Take the Exposure Test
articulos/art5-calidad-del-dato
Data accuracy: which debts you may register (Art. 5 GDPR) | ILP Abogados