Spain's LOPDGDD (Organic Law 3/2018) has three articles that decide what an employer can do on employees' mobile devices: Article 87 on privacy, Article 88 on digital disconnection, Article 90 on geolocation. If you manage a fleet with users in Spain, they shape your MDM configuration, your device usage policy, and who you have to talk to before the first phone is enrolled.
What the LOPDGDD says about mobile devices at work
Title X of Ley Orgánica 3/2018 of December 5, 2018 (the law that complements the GDPR in Spain) sets out a list of "digital rights". Three of them land directly on the MDM admin's desk.
Article 87: privacy in the use of digital devices
Workers and public employees have a right to privacy when using the digital devices their employer makes available to them. The employer may access content derived from that use, but only for two purposes: checking that work obligations are met, and guaranteeing the integrity of the devices. That's the whole list.
Paragraph 3 is the one people forget. The employer must establish usage criteria for the devices, and workers' representatives must take part in drawing them up. Where private use is allowed, accessing device content requires that the authorized uses are precisely specified and that privacy safeguards exist, such as defining the periods when the device may be used for private purposes. Workers must be informed of these criteria.
Article 88: the right to digital disconnection
Outside working time, employees are entitled to have their rest, leave and holidays respected. After hearing the workers' representatives, the employer must write an internal policy defining how the right is exercised, plus training and awareness actions to avoid what the law calls "IT fatigue". Managers are explicitly included. So is remote work.
Article 90: geolocation
Employers may process geolocation data to exercise the monitoring functions of Article 20.3 of the Workers' Statute, within their legal framework and limits. One condition comes first: they must inform workers and, where applicable, their representatives "expressly, clearly and unequivocally" about the existence and characteristics of these systems, and about the rights of access, rectification, restriction of processing and erasure.
The link with the Workers' Statute and the GDPR
The thirteenth final provision of the LOPDGDD inserted Article 20 bis into the Estatuto de los Trabajadores: a right to privacy in the use of employer-provided digital devices, to digital disconnection, and to privacy against video surveillance and geolocation. The same Statute, in Article 64.5 f), gives the works council the right to issue a report before the employer implements or revises systems for organizing and monitoring work. An MDM with location features is hard to file anywhere else.
The GDPR still applies in full: data minimization, purpose limitation, proportionality. The most useful reading for an admin is the AEPD's guide "La protección de datos en las relaciones laborales" (data protection in employment relationships), published on May 18, 2021 by the Spanish data protection authority. On geolocation it says several things worth keeping next to your console:
- Proportionality means limiting these systems to situations where no less intrusive means exists.
- Employers can't lawfully require workers to supply personal equipment, such as their own mobile phone, to be geolocated. The guide cites the Audiencia Nacional ruling 136/2019 of February 6, 2019.
- Tracking can be designed so that location data is only available when the device is reported lost or stolen. That is the design we recommend below.
Do you need a DPIA? The AEPD's list of processing types that require a DPIA (GDPR Article 35.4) says one is needed in most cases where processing meets two or more criteria on the list. One criterion is "systematic and exhaustive" observation, monitoring, supervision, geolocation or control of the data subject. A device inventory with enforced passcodes and encryption rarely gets there. Continuous tracking of your field sales team does. Document the reasoning either way, with your DPO.
What an MDM sees and doesn't see: BYOD vs. company-owned
A legal nuance first. Article 87 covers devices "made available by the employer". On a personal phone (BYOD), the hardware belongs to the worker, so the privacy expectation is even higher and the GDPR applies with nothing to soften it. That's why the technical architecture matters so much.
Android BYOD: the work profile. Android Enterprise creates a separate, encrypted container. IT sees and manages what's inside it: work apps, corporate accounts, the profile's compliance state. Everything outside (personal apps, photos, messages, browsing history) is invisible to the console. A wipe removes the work profile and leaves the rest of the phone alone.
iOS BYOD: enrollment link. On a personal iPhone, enrollment goes through a link, with managed apps and managed accounts. IT distributes and removes corporate apps along with their data. Apple's MDM protocol never exposes messages, photos, personal mail or browsing history, whatever the enrollment type. And in the Appaloosa console, the actions available on a BYOD device come down to wipe and remote assistance. There's no locate button.
Company-owned devices. Here the MDM manages everything: full app inventory, restrictions, OS updates, lock, lost mode, full wipe. In Appaloosa, location is limited to lost mode, on managed devices only and never on BYOD. Real-time geolocation of managed devices is only activated on request, once the customer has provided evidence such as user consent or the relevant employment contract clause. It can do more, which is exactly why Article 87.3 wants written criteria. If you tolerate private use of those phones (nearly every company does, admitted or not), say so and define the safeguards. On Android, the best fit is COPE: a corporate device with a work profile, so the personal side stays out of IT's reach.
Book a demo
See Appaloosa run on your fleet
A 20-minute call on your real setup. Enrollment, private apps, security.
Book a demo →Configuring the MDM to respect Articles 87 and 90
An MDM doesn't make you compliant with the LOPDGDD. It lets you apply, in a verifiable way, the decisions you wrote into your policy. These are the settings we recommend for mobile device management in Spain.
Four decisions carry most of the weight. Location stays off by default and is only turned on for groups with a justified purpose (delivery handhelds, shared warehouse devices), after the Article 90.2 notice has gone out. For everyone else, it is kept for lost mode after a loss or theft report. On BYOD there is no personal app inventory and wipes are selective: a full wipe of a personal phone destroys data that isn't yours. And console access is limited to a few admins with defined roles and SSO, because Article 87.2 restricts why you may access content and you should be able to show who did what.
| LOPDGDD article | Obligation | MDM setting |
|---|---|---|
| Art. 87.1 and 87.2 | Protect privacy. Access only to check work obligations and guarantee device integrity | Work profile on Android BYOD, managed apps and accounts on iOS BYOD, limited admin roles |
| Art. 87.3 | Usage criteria drawn up with workers' representatives. Authorized private uses and safeguards | COPE on corporate devices with personal use. Inventory limited to managed apps |
| Art. 88 | Internal digital disconnection policy | An MDM doesn't solve this alone. Avoid forced notifications outside working hours, and don't use the console to check activity during rest periods |
| Art. 90.1 | Geolocation only within the monitoring functions of Art. 20.3 of the Workers' Statute, with proportionality | Location off by default. Enabled per group and per purpose. Lost mode after a loss report |
| Art. 90.2 | Prior, express, clear and unequivocal information to workers and representatives | No location feature is switched on before the notice date. Keep the acknowledgment |
What the internal device usage policy must contain
Article 87.3 asks for "usage criteria". In practice, four or five pages a worker understands on first read beat twenty pages of clauses. If you already have an acceptable use policy for mobile devices, use it as the base and add the Spanish specifics. At minimum:
- Scope: corporate, COPE and BYOD devices, and which enrollment mode goes with each.
- Whether private use is allowed, which uses, under what conditions.
- The data the MDM collects and the data it doesn't. Be concrete: model, OS version, work apps, encryption status. Then state plainly what IT cannot see.
- For which purposes the company may access content, who may do it, and through what procedure.
- Geolocation: whether it exists, on which devices, for what purpose, during which hours, how long data is kept, and how to exercise the Article 90.2 rights.
- Loss, theft and offboarding: selective or full wipe depending on the device type.
My advice: write the "what IT can't see" section before any other. It's the one employees actually read, and it decides whether a BYOD program gets adopted or quietly sabotaged.
A five-step rollout sequence
- Inventory and purposes. List device types, user groups and, for each intrusive feature (location, app inventory), the specific purpose. No purpose, no feature.
- Proportionality analysis and, where relevant, a DPIA. Done with the DPO. Update the record of processing activities.
- Workers' representatives. Share the draft usage criteria with them (Art. 87.3), hear them on the disconnection policy (Art. 88.3), and inform them of any geolocation system (Art. 90.2). Do it before you configure, not after. A works council that discovers the MDM through an enrollment prompt on a phone is a dispute waiting to happen.
- Group-based MDM configuration. Work profile for Android BYOD, enrollment link for iOS BYOD, automated enrollment (zero-touch, Apple Business Manager) for corporate devices.
- Individual notice. Every worker gets the policy before enrolling. Keep the proof, and revisit the policy every year or whenever an MDM feature or the collective agreement changes.
This article is for information only and is not legal advice. Have your policy validated by your DPO or employment counsel in Spain.
Appaloosa is a European MDM, hosted in France, that manages iOS, iPadOS, Android, Windows and macOS from one console, with the Android work profile and iOS managed apps for BYOD. To see what these settings look like in practice, book a demo or try it free for 14 days.
FAQ
Can an employer in Spain track the location of an employee's mobile phone?
Yes, under strict conditions. Article 90 of Spain's LOPDGDD (Organic Law 3/2018) allows employers to process geolocation data for the monitoring functions of Article 20.3 of the Workers' Statute, provided they first inform workers and their representatives expressly, clearly and unequivocally about the existence and characteristics of the system and about their rights of access, rectification, restriction and erasure. The Spanish data protection authority (AEPD) adds that the measure must be proportionate and that an employer cannot lawfully require workers to supply their personal phone to be geolocated.
What does Article 87 of the LOPDGDD require from employers who provide mobile devices?
Article 87 of the LOPDGDD requires employers to establish usage criteria for digital devices, drawn up with the participation of workers' representatives, and to inform workers of them. The employer may access content derived from the use of those devices only to check that work obligations are met and to guarantee device integrity. If private use is allowed, the authorized uses must be precisely specified and privacy safeguards defined, such as the periods when private use is permitted.
What can IT see on a personal phone enrolled in an MDM?
On a correctly configured personal phone, IT sees only the work side. On Android, the Android Enterprise work profile separates the data: the console sees corporate apps and accounts, while personal apps, photos and messages stay invisible. On iOS with Appaloosa, BYOD enrollment goes through a link with managed apps and accounts, and Apple's MDM protocol gives no access to messages, photos or browsing history. Wipes should be selective: work data only.
Is a DPIA mandatory before deploying an MDM in Spain?
Not always. According to the list the AEPD published under GDPR Article 35.4, a DPIA is needed in most cases where processing meets two or more criteria on that list, including systematic and exhaustive observation, monitoring, geolocation or control of the data subject. An MDM limited to inventory and security rules usually doesn't meet them. An MDM that continuously geolocates workers probably does. In both cases, document the analysis with your data protection officer.
Ready to try Appaloosa? Start free