LSSI-CE vs LOPDGDD: Mandatory transparency or unnecessary exposure?

Law 34/2002 on Information Society Services and Electronic Commerce (LSSI-CE) requires any online service provider to display clear identifying information in an accessible manner: name or corporate name, tax ID number, address and contact details.

So far, the objective seems legitimate because in theory it guarantees transparency and user trust. However, in practice — especially for freelancers and small businesses — this obligation creates an evident tension with the right to personal data protection.

The clash with the LOPDGDD is not theoretical

Organic Law 3/2018 strengthens the right to privacy and establishes principles such as data minimisation and protection against misuse. And here friction appears: while one regulation pushes to expose personal data openly, the other insists that such data must be limited to the necessary minimum.

Freelancers: the most vulnerable link

In the case of freelancers — who make up that 99.8% of the Spanish business fabric composed of SMEs — the contradiction is especially visible because we are not talking about a company as an abstract entity, we are talking about a person. The same person who works is forced to publish their full name, ID number, address and phone number on the internet, accessible to anyone.

Another issue arises: the proportionality of the current obligation. In 2002, when the LSSI-CE was approved, the internet was nothing like today. The current level of automation, massive scraping, or the volume of digital fraud we see daily did not exist then. That completely changes the context.

Publishing personal data openly is no longer simply "informing". It is exposing information that can be reused, cross-referenced and exploited. Identity theft, targeted phishing, databases fed by bots… these are not hypothetical scenarios; they are very real and sadly normalised due to the legislator's inconsistency in applying the basic principle of internet security: common sense.

Normative hierarchy: organic vs. ordinary law

This also brings up the debate about normative hierarchy. The LOPDGDD is an organic law and the LSSI-CE is an ordinary law, but in practice there is no substitution of one for the other, but rather an uncomfortable coexistence. The result is that the obligation to display data remains in force, even though it fits increasingly poorly with the current data protection approach.

And perhaps the problem is not transparency itself, but how it is being implemented.

Technical alternatives for secure transparency

If the goal is for users to verify who is behind a website, there are technical alternatives much more in line with today's environment. For example, an indirect identification system: when registering as a freelancer for digital activities, a unique public identifier is generated, and that identifier is displayed on the website.

The user could consult the real data through an official government platform, accessing with a digital certificate, Cl@ve or another secure system. In this way, the information would remain accessible, but would no longer be exposed massively and without control.

This would maintain trust, guarantee traceability, and at the same time reduce risk for those — let us not forget — who are putting their own personal data at stake.

Because for commercial companies this is not a real problem

But for freelancers, it is. And it affects the vast majority of the Spanish business fabric.

Conclusion

The LSSI-CE was a necessary law at the time, but today it is hard to argue that transparency should imply the total exposure of personal data on the internet. In an environment where Europe rightly prides itself on leading data protection, maintaining this model creates, at the very least, a contradiction that is difficult to justify.

In the end, the issue is not whether we need to identify ourselves. It is whether it makes sense to keep doing it the same way as more than twenty years ago.