"Legal basis: the controller's legitimate interests." That line appears in thousands of records of processing activities and privacy policies as if it were a formality already settled. It is not. When the registration of a debtor ends up in court — and it does so more and more often — the judge does not check whether you ticked the box. The judge checks whether your company passed, and can prove that it passed, a test with three parts. Failing any one of the three turns the entry into unlawful processing, and unlawful processing into an award that, as an indicative range, runs from 3,000 to 10,000 euros plus costs per person affected.
The three parts of Article 6(1)(f)
Your company's interest in getting paid is legitimate; nobody disputes that. The question is a different one: whether that interest justifies the reputational harm caused by an entry in a credit information system (CIS). The courts resolve it with three cumulative tests. Cumulative means all three have to be passed; there is no averaging.
1. Necessity
Was there a less intrusive alternative for obtaining payment? A formal demand, a documented negotiation, court proceedings to recover the debt. If there was one and it was not exhausted, the entry was not necessary: it was convenient. And convenience is not a legal basis.
2. Suitability
Does the entry genuinely serve the purpose you invoke? Reporting the debt to a register that your debtor and their lenders will never consult protects nobody's credit: it merely punishes. The measure has to be effective for the stated objective, not a general instrument of pressure.
3. Proportionality in the strict sense
Weighing your company's commercial interest against the rights of the person affected, does yours weigh more? With small, doubtful or old debts, the courts tend to answer no. The balance is assessed case by case, and the one who has to have assessed it before registering is you.
The application of Article 6(1)(f) GDPR requires that there be a legitimate interest of the controller or of a third party; that the processing be necessary for the satisfaction of the legitimate interest pursued; and that, in balancing that legitimate interest... against the impact on the interests..., the former prevail. [translation]
SAP Madrid 148/2026 adds the point that hurts most in practice: the controller's interest prevails only if the impact on the person affected is proportionate and there were no more moderate measures available to achieve the same purpose. In other words, the judge will actively look for the alternative you did not use.
"In writing" is not a metaphor
This is where most cases are lost. A company may in fact have made reasonable use of the register and still be found liable, because it cannot reconstruct before the judge the balancing exercise it says it carried out. SAP Madrid 123/2026 links this to the accountability duty in Article 5(2): it is for the controller alone to determine — and to demonstrate — the lawfulness and compatibility of the processing. Without a dated document setting out what was assessed, which alternatives were discarded and why, your legitimate interests are an assertion, not evidence.
And assertions without evidence have a poor record in the case law. As long ago as SAP Barcelona 72/2021, of 15 February, the courts warned that invoking an interest — even a public one — does not exempt the processing from the principles of Article 5:
The existence of a public interest does not legitimise any and every kind of processing of personal data; regard must be had... to the principles of Article 5 GDPR already cited, in particular purpose limitation and data minimisation. [translation]
If not even a public interest is a free pass, the commercial interest in collecting an invoice is even less so.
The surprise question: identity impersonation
There is one situation in which the test becomes harder: when the contract giving rise to the debt was signed by an impostor. Your company registers the holder of the identity document used, who never contracted anything, and that person sues. The instinctive reaction — "we were victims of the fraud too" — does not work as a defence. Article 82(3) GDPR presumes the controller to be at fault: to be relieved of liability, your company must show that it applied appropriate diligence measures to prevent precisely that error of identity. SAP Madrid 273/2024 states this clearly, and adds that processing inaccurate data which gives a misleading picture of the data subject's situation is itself a breach of the rules.
Article 20 LOPDP, "Credit information systems", is contained in Title IV, "Provisions applicable to specific processing operations", under the power conferred on Member States by Article 6(2) and (3) GDPR. [translation]
In business terms: your identity verification controls when onboarding customers are not an abstract compliance matter. They are the only evidence that will relieve you of liability on the day an impersonated person appears in your collections book. If you cannot describe those controls on a single sheet of paper today, you do not have them.
What to decide this week
Three specific tasks for your team: document the legitimate interests balancing exercise applicable to your collections process, set out in writing which prior steps are exhausted before registering, and review your identity controls at the contracting stage. A failure in the legal basis is also one of the five mistakes generating most adverse judgments in credit default registers: it rarely comes alone, because a company that does not document the balancing exercise usually does not document the rest either.
Before you commission anything, measure. The Exposure Test puts you, in ten minutes, in front of the same criteria a judge will apply: legal basis, data accuracy, information given to the customer and ability to prove.
Would your company pass the three-part test today?
Check it with your own answers, no confidential data. Immediate, prioritised result.
Take the Exposure Test