Spain - The taxpayer's protected digital domicile: a missing legal framework
Gonzalo Rincón de Pablo and Beatriz Moroy Arambarri, partner and principal associate, respectively, in Garrigues' Tax practice.
The growing digitalisation of taxpayers' personal and professional activity raises new challenges for the protection of privacy and calls for the recognition and regulation of a genuine “protected digital domicile”, distinct from the physical domicile and from the fiscal domicile, to which the constitutional, legal and procedural guarantees applicable to particularly intense interferences with private, professional and economic life should apply, adapted to the technical particularities of the digital environment.
Digitalisation has reached the personal and professional sphere of the taxpayer, transforming, among many other things, the way in which tax-relevant information is generated, stored and accessed. A significant part of that information no longer resides in physical spaces but in devices, cloud services, digital platforms and electronic communications, blurring the boundaries between the personal and professional spheres and requiring a specific concept of a “protected digital domicile” as the most private core of the taxpayer's digital sphere. This is a legislative and functional proposal, not a claim that an autonomous fundamental right bearing that name currently exists.
In the tax field, this reality makes it necessary to put forward a specific protection for what may be termed the taxpayer's protected digital domicile, seeking to reconcile the constitutional guarantees at stake -privacy, the inviolability of the home, the secrecy of communications, data protection, effective judicial protection, legality, proportionality and judicial control of administrative action- with the role of the Spanish tax authorities in ensuring compliance with tax obligations and combating fraud.
The taxpayer cannot claim to remain outside the scope of tax control merely because the information is stored in digital form rather than on paper. What is at stake is not immunity from inspection, but the manner, scope and safeguards under which that inspection may reach the taxpayer's digital sphere.
In practical terms, the debate is not about creating a zone immune from tax control, but about applying the principle inherent to the rule of law whereby a more intense interference requires a clearer legal basis, justification and control.
Constitutional protection was designed for physical reality
The domicile constitutionally protected under Article 18.2 of the Spanish Constitution has traditionally operated as a guarantee against administrative or judicial entry and search of physical spaces. Article 113 of the Spanish General Tax Act (Ley 58/2003) requires the taxpayer's consent or judicial authorisation to enter a constitutionally protected domicile, while Article 142 of the General Tax Act regulates the powers of the Tax Inspectorate, including the examination of books, accounting records, files, databases, computer programs, records and computer archives relating to economic activities.
In the same vein, Article 18.4 of the Spanish Constitution, in requiring that the law limit the use of computing to guarantee privacy, already anticipated the need to adapt constitutional protection to new technological realities.
In this area, the Constitutional Court, in its judgment 173/2011, of November 7, already warned that data stored on a personal computer falls within the constitutionally protected sphere of privacy. In that case, however, the Court found no violation, given the justified and proportionate nature of police access at issue.
An insufficient legal framework to guarantee taxpayers' rights in a digital environment
The problem is that this framework, built around the physical domicile, does not fully respond to the current digital reality, particularly in view of the advances in artificial intelligence. Tax-relevant information for a taxpayer is now increasingly found on laptops, mobile phones, email accounts, messaging applications, collaborative platforms, ERP and CRM systems, document repositories and cloud storage accessible from multiple devices, without being tied to an office or a physical archive. In these digital spaces there coexist accounting documentation, personal data, internal communications, third-party information, trade secrets, legal strategy, communications with advisors, family documentation, personal records, metadata, access logs and location data.
For this reason, in our view, the law should recognise the existence of a genuine “protected digital domicile,” distinct from the “physical” tax domicile under Article 48 of the General Tax Act, to which the constitutional, legal and procedural guarantees applicable to particularly intense interferences with private, professional and economic life should apply, adapted to the technical particularities of the digital environment.
The Supreme Court demands specific guarantees
In the absence of express legal regulation, the Supreme Court has required specific guarantees whenever an action seeks to access, control or process information stored on computers, mobile phones, tablets or other digital media. The Supreme Court judgment of September 29, 2023, establishes that the requirements of necessity, suitability and proportionality must govern any such action. The Supreme Court held that the rules governing authorisation to enter a domicile do not, by themselves, constitute an adequate channel for capturing or using data from a computer located outside the domicile when other fundamental rights are affected. Authorisation to enter the domicile does not, on its own, legitimise indiscriminate access to digital content.
This approach was reaffirmed by the Supreme Court judgment of June 25, 2024, which insists on the need for reasoned judicial authorisation whenever access is sought to a taxpayer's digital environment. Access to digital content may be authorized in the same order as entry into the domicile, without requiring a separate judicial decision, but the Spanish tax authorities must justify -and the judge must specifically weigh- the suitability, necessity, proportionality and scope of access to devices, repositories or electronic information. In that case, although the Supreme Court set aside the lower court's judgment for having departed from this doctrine, it ultimately dismissed the administrative appeal, finding that the authorisation order had in fact carried out the required balancing exercise.
European courts confirm the need for effective limits
At the international level, the European Court of Human Rights has also had occasion to examine cases concerning access to and copying of data stored on shared servers during tax inspections. In Bernh Larsen Holding AS and Others v. Norway, application no. 24117/08, of March 14, 2013, the Court found, under Article 8 of the Convention, that such measures may interfere with private life, the home or correspondence, although no violation was found in that case in view of the predictability, scope and administrative and judicial safeguards available.
This judgment forms part of a broader body of case law rendered in legal systems like the Spanish one. Already in Ravon and Others v. France, application no. 18497/03, of February 21, 2008, the Court found a violation of Article 6.1 of the Convention on account of insufficient judicial review of tax search and seizure visits. Likewise, in Vinci Construction et GTM Génie Civil et Services v. France, applications nos. 63629/10 and 60567/10, of April 2, 2015, although not strictly a tax case, the Court found a violation of Article 8 owing to the lack of concrete and effective control over the seizure of numerous digital documents and electronic communications, some of which were covered by attorney-client privilege.
The most recent pronouncements confirm that the question remains open. Thus, in Italgomme Pneumatici S.r.l. and Others v. Italy, applications nos. 36617/18 and others, of February 6, 2025, the Court found a violation of Article 8 in the course of tax inspections of business and professional premises, on the ground that the domestic legal framework lacked the required “quality of law,” granting the tax authorities unlimited discretion without effective safeguards or remedies -a systemic problem within Italy's regulatory framework, reiterated in Agrisud 2014 S.r.l. Semplificata and Others v. Italy, application no. 32539/18 and others, of December 11, 2025-. Likewise, in Ferrieri and Bonassisa v. Italy, applications nos. 40607/19 and 34583/20, of January 8, 2026, the Court reiterated this reasoning regarding access by the tax authorities to taxpayers' banking data, finding a lack of precise legal conditions, reasoned decision-making, and effective judicial or independent control.
European Union law points in the same direction. In the WebMindLicenses judgment, of December 17, 2015, Case C-419/14, ECLI:EU:C:2015:832, the Court of Justice allowed the tax authorities to make use of evidence obtained in a parallel criminal proceeding, but conditioned its collection and use on respect for Articles 7, 47 and 52.1 of the Charter of Fundamental Rights, leaving it to the national court to review the legality of that evidence and to exclude it, where obtained or used in violation of those rights, if the assessment cannot stand without it.
This consequence connects, in Spanish domestic law, with Article 11.1 of the Organic Law on the Judiciary, under which evidence obtained, directly or indirectly, in violation of fundamental rights has no effect.
Need for reinforced guarantees in accessing digital tax information
In Spain, the question remains open and has once again become topical. An order of the Supreme Court of March 5, 2026, issued in connection with entry into a physician's professional practice as part of a tax investigation, once again raises the question of whether Article 8.6 of the Law on Contentious-Administrative Jurisdiction provides an adequate statutory basis to authorize actions that, together with entry into the domicile, may affect the secrecy of communications, privacy and data protection -particularly where access is sought to third-party information or to categories of especially sensitive data-. As an admission order, it does not yet settle the doctrine on the merits. The question is not whether the Spanish tax authorities may access tax-relevant information stored in digital form, but with what scope, under what conditions, and with what guarantees.
Insofar as access to the taxpayer's digital sphere entails the processing of personal data, the principles of purpose limitation and data minimization under Regulation (EU) 2016/679 (the General Data Protection Regulation) must also be respected, and the Spanish tax authorities should be confined to processing data that are adequate, relevant and strictly necessary for the specific tax action concerned. Article 95 of the General Tax Act likewise imposes an obligation of confidentiality and purpose-limited use of tax-relevant data, although this guarantee does not replace the limits applicable to the way such data is obtained.
This difficulty is especially evident in remote environments, such as corporate or personal clouds, where the information available may far exceed what would be found in a specific physical space -including mailboxes, global repositories, version histories, backups, internal communications, documentation belonging to subsidiaries, third-party information, data relating to tax years not under review, and especially sensitive personal information that is difficult to separate from the rest-.
For this reason, access to the taxpayer's digital sphere should be subject to reinforced guarantees and, where appropriate, specific judicial authorisation, with effective prior control to avoid disproportionate interference. Any such authorisation should precisely limit the repositories to be examined, the time periods covered, the relevant categories of documents, and the information excluded from access -in particular, material covered by legal professional privilege, the right of defence, or unrelated to the tax purpose of the action-. Minimization rules, prior filtering procedures and safeguards should also be established to avoid the processing of personal or third-party information that is not relevant.
Protection of legal professional privilege and attorney-client communications
Effective protection of legal professional privileges and of communications between lawyers and clients must likewise be guaranteed. Article 16 of Organic Law 5/2024, of November 11, on the Right of Defence, declares such communications confidential and protects documents linked to the exercise of the right of defence. Digital environments may contain legal reports, defence drafts, tax risk analyses, procedural strategy and communications with lawyers or advisors. Access to devices or repositories should therefore be accompanied by filtering or segregation mechanisms that prevent the examination of material covered by the right of defence. Along these lines, the European Court of Human Rights, in Saber v. Norway, application no. 459/18, of December 17, 2020, found a violation of Article 8 of the Convention owing to insufficient safeguards applicable to the examination of a mirror copy of a mobile phone; although not a tax proceeding, its reasoning on the filtering of protected communications is relevant here. Technological advances cannot reduce existing guarantees or serve as cover for generic access to an environment that reveals very broad aspects of a taxpayer's life.
In the tax field itself, Article 93.5 of the General Tax Act reinforces this caution with regard to the duty of professionals to provide information about third parties, excluding certain private data unrelated to property matters and confidential data known in connection with advisory or defence services -although this does not create a general privilege against any inspection action, nor does it prevent verification of the professional's own tax situation-.
Possible solutions
Despite the progress made by case law, the General Tax Act should expressly regulate tax access to protected digital environments. One possible solution would be to incorporate specific regulation into the rules governing verification and investigation powers, with a regulatory referral for technical aspects. This regulation should operate as a cross-cutting guarantee for the digital taxpayer, and not merely as a technical rule to be followed in the course of a tax audit, and should include, at a minimum: a functional definition of the protected digital domicile; a subsidiarity rule; the requirement of specific judicial authorisation where appropriate; minimization criteria; filtering protocols; chain of custody; traceability of searches; mechanisms to segregate protected material; and limited retention with destruction or blocking of irrelevant data. In short, the same guarantees provided for the constitutionally protected domicile and for tax entries and searches should be adapted to the digital environment.
Among these guarantees, subsidiarity occupies a central place. Mass or forensic access to devices, clouds or repositories should only be admitted when the Spanish tax authorities justify that the information cannot be obtained through less intrusive means, such as individualized requests, selective submission of documents, third-party information, or data already available in its own databases. The power of verification should not permit, without reinforced justification, the general capture of a taxpayer's digital environment.
This proposal has, moreover, a precedent in Spanish law. Articles 588 sexies a, 588 sexies b and 588 sexies c of the Criminal Procedure Act, introduced by Organic Law 13/2015, have, since 2015, regulated the search of mass storage devices and require individualized reasoning for the grounds justifying access. The Supreme Court judgment of September 29, 2023, itself invoked this regulation to reason that an inspected taxpayer cannot be placed in a worse position than a person under investigation in criminal proceedings. It is anomalous that this guarantee should exist in criminal jurisdiction but not in the tax field.
A good opportunity would be to make use of the parliamentary processing of the draft Organic Law on the good use and governance of artificial intelligence, submitted to Congress on May 28, 2026, and published in the Official Gazette of the Cortes Generales on June 12, 2026 (initiative 121/000096), to introduce specific regulation of taxpayer guarantees in the digital environment. Alternatively, a dedicated, general-purpose law on taxpayer rights and guarantees in the digital sphere could be promoted, rather than addressing the issue through piecemeal reforms. Such regulation should address, among other matters: the concept of the protected digital domicile; its coordination with the fiscal domicile and with the constitutionally protected domicile; the conditions under which the Spanish tax authorities may access devices, repositories and cloud environments; and taxpayers' rights regarding the use of automated systems, mass data analysis and artificial intelligence in tax proceedings.
Montesquieu warned in The Spirit of the Laws that “every man who has power is inclined to abuse it” and that, to prevent this, “power must check power.” A tax system respectful of the Constitution requires clearly defining the powers of the Spanish tax authorities and the limits on their exercise, including when the information at issue is found in the digital environment. Regulating the protected digital domicile would convert a protection that is currently built mainly through case law into some concrete, legally enforceable guarantee for the benefit of all.