“Googling” a candidate before an interview is a widespread, almost automatic practice. But in Spain, doing so without clear criteria can turn innocent curiosity into a data-protection infringement.
What the AEPD guidance says
In its guide “Data Protection in Employment Relationships”, the Spanish Data Protection Agency establishes a very clear principle: a candidate is not required to allow a company to investigate their social media, even where the content is publicly accessible. The guidance adds that sending a “friend” request or similar request in order to view private content is not acceptable under any circumstances.
LinkedIn is not the same as Instagram
The key is not the platform itself, but its relationship to the role:
Professional networks (LinkedIn): because they are designed for professional visibility, candidates should expect recruiters to consult this information. Comparing stages of the CV with the LinkedIn profile is generally lawful, provided it is done in relation to the role and without taking into account “collateral findings” unrelated to the professional sphere.
Private networks (Instagram, Facebook, TikTok): even if the content is public, it usually serves a primarily private purpose. Reviewing it without a clear, documented and proportionate connection to the role can easily be disproportionate.
The risk almost nobody mentions: unconscious bias
Searching without a defined objective almost inevitably leads to information that is irrelevant to the role but legally protected: religion, sexual orientation, pregnancy or family planning (special categories under Article 9 of the GDPR). The problem is not only legal: once a recruiter has seen this information,
unconscious bias can influence the decision even where there is a firm intention to ignore it.
How to make it defensible
If an online investigation (OSINT) is justified by the role — for example, for a spokesperson or a position with high public exposure — it should be clearly defined and documented: what was searched, why, in which source and how it relates to the role. What is not defensible is a “let’s see what we can find” approach without predefined criteria.
See also: Human Risk and Background Checks in Spain: The 2026 Reference Guide and GDPR, LOPDGDD and AEPD: The Legal Framework for Background Checks in Spain
From