María González
PartnerMaria is a lawyer specialising in regulatory compliance in technology environments, with experience in privacy, cybersecurity and IT compliance.
Since 2002, she has developed her professional career in firms, consulting firms and corporations, always focused on privacy, cybersecurity and regulatory compliance. She began her career with an entrepreneurial project at Manaca Consulting and later joined the legal consulting team at SIA, where, as a senior lawyer, she advised large public and private sector entities on security and compliance matters for almost five years. In 2012 she first joined ECIJA as a senior associate, and after a stint at Línea Directa Aseguradora as in-house counsel, she returned in 2018 to the firm, being promoted to partner in 2019. She currently leads the IT Compliance practice and
Related services
- Cybersecurity
- Regulatory Compliance
- Privacy and Data Protection
- Technology, Media and Telecommunications
Related insights

The State Agency for Tax Administration ("AEAT"), through its resolution published in April titled "Personal Use of Cl@ve and Prevention of Unauthorized Intermediation Practices", reinforces its position regarding the personal and non-transferable nature of the Cl@ve system and expressly questions models in which third parties intervene in the use of citizens' credentials to access public administration services.

This ruling is particularly significant from two perspectives — data protection and labour law — as it defines the limits of employers' control over personal devices and reinforces compliance requirements for companies with BYOD (Bring Your Own Device) policies.

The AEPD has fined a company for forcing employees to install applications on their personal mobile phones, thus violating the principles of data minimization, legal basis, and information to the employee.





