The coronavirus outbreak is set to test the limits of institutions and organisations the world over – including data watchdogs.
As the coronavirus crisis rapidly escalated over the last few days, data protection authorities have sprung into action. The EDPB published guidance for organisations yesterday on data processing rules – particularly those relating to health data – while authorities try to mitigate the Covid-19 outbreak.The statement came after several national authorities published data protection advice. The EU’s own data watchdog, the European Data Protection Supervisor, has been working remotely as of last Friday.
Observers – some working from home themselves – have said the lack of EU-wide guidance has led to member states’ regulators offering diverging guidance, creating confusion for organisations across the bloc. Many also said the virus and its impact on society will stress-test the regulators, particularly as many authorities have limited resources.
Regarding the processing of electronic communication data, such as mobile location data, additional rules apply, the regulator said. The ePrivacy Directive – which ensures location data can only be used when anonymised or with consent – can allow member states to introduce legislation pursuant to national security and public safety that allows them to process data that has not been made anonymous.
Jesús Yáñez, a partner at ECIJA in Madrid, told GDR that Spain’s state of emergency – effective from 14 March – means all administrative deadlines are suspended, allowing some breathing space for any ongoing investigations the Spanish AEPD must carry out, and also to companies that must provide documentation to the regulator.
As Spanish citizens liaise with their authorities using digital channels, Yáñez said this novel situation should not have a “great impact” on the AEPD’s operations, but the main issue is that not all administrative workplaces are ready for remote working, “which is a very different thing”.
“I’m sure the internal effectiveness inside the AEPD will be impacted. The implementation of the GDPR back in May 2018 already showed that more resources were needed, and of course these needs are going to become even more obvious over the coming days and weeks, Yáñez said.

LATEST FROM #ECIJA

Resolution 277/2026, which came into force on 29 June 2026, establishes SIGIM, a platform that will forward notifications of compulsory pre-litigation mediation to ARCA’s electronic tax address.

In Mexico, international arbitration has become a common means of resolving complex disputes relating to investments, long-term contracts and strategic projects.

ECIJA Ecuador analyses the main provisions of the Free Trade Agreement between Ecuador and Canada.

The historic agreement between Michael Jackson and Pepsi marked a turning point in the commercial exploitation of image rights, laying the foundations for modern sponsorship contracts. Today, in a world dominated by social media and artificial intelligence, these agreements are more complex and strategic than ever.

It sets out new rules for the processing of personal data in debt collection procedures and communications with third parties.

Two out of three days fall at the weekend

ECIJA’s TMT department analyses the ‘Digital Omnibus’, the reform approved by the European Union that streamlines the Artificial Intelligence Regulation (AIR). It extends deadlines, reduces the burden on SMEs and strengthens the powers of the European AI Office, without compromising the level of protection of rights and security.

A comparative analysis of the regulation, functions and requirements of the Data Protection Officer (DPO) in Chile and Spain, highlighting their strategic role in governance and compliance in the field of personal data protection.

In light of the rise in online scams and fraud, SUTEL is calling for changes.





