{"id":20083,"date":"2026-03-09T08:00:45","date_gmt":"2026-03-09T08:00:45","guid":{"rendered":"https:\/\/letslaw.es\/cuidado-con-lo-que-le-confias-aepd\/"},"modified":"2026-03-06T12:13:36","modified_gmt":"2026-03-06T12:13:36","slug":"commandments-aepd","status":"publish","type":"post","link":"https:\/\/letslaw.es\/en\/commandments-aepd\/","title":{"rendered":"\u201cCuidado con lo que le confIAs\u201d, the new AEPD ten-point guide"},"content":{"rendered":"<p>On 27 January 2026, the day before International Data Protection Day (28 January), the Spanish Data Protection Agency (AEPD) published the \u201c<a title=\"Cuidado con lo que le confIAs\" href=\"https:\/\/www.aepd.es\/guias\/recomendaciones-ia-aepd.pdf\" target=\"_blank\" rel=\"noopener\">Cuidado con lo que le confIAs<\/a>\u201d ten-point guide, with practical recommendations to reduce privacy risks when we interact with AI systems.<\/p>\n<h2>Objectives of the AEPD ten-point guide<\/h2>\n<p>Aware of the growing use ofand the already tangible potential of Artificial Intelligence systems, the Agency considers it important to provide a set of <strong>tips to help people understand and prevent privacy risks<\/strong> arising from the improper use of these tools.<\/p>\n<p>In the Agency\u2019s own words, this ten-point guide \u201caims to offer the public key pointers to promote a safe, responsible and informed use of artificial intelligence and to foster a digital environment that respects people\u2019s fundamental rights.\u201d<\/p>\n<p>In addition, this initiative follows the direction set out by the AEPD in its <a title=\"2025-2030 Strategic Plan\" href=\"https:\/\/www.aepd.es\/documento\/plan-estrategico-aepd-2025-2030.pdf\" target=\"_blank\" rel=\"noopener\">2025-2030 Strategic Plan<\/a> on <strong>Responsible Innovation and the defence of dignity in the digital era<\/strong>, where it reaffirmed its commitment to promoting a culture of privacy and <a title=\"data protection\" href=\"https:\/\/letslaw.es\/en\/privacy-data-protection-lawyers\/\">data protection<\/a> among both citizens and organisations, as well as supporting technological innovation with safeguards.<\/p>\n<h2>Responsible use of artificial intelligence<\/h2>\n<p>Talking about \u201cresponsible use\u201d is not only an ethical matter; it is also a practical one. In day-to-day use of generative AI, there are four ideas worth keeping in mind:<\/p>\n<h3>1. Your prompt is not always \u201cjust text\u201d<\/h3>\n<p>When you write a query, it is not only the content of the message that travels. In many services, use may involve technical and contextual data (browsing data, identifiers, metadata, etc.). In other words, even if your question is harmless, the surrounding ecosystem might not be.<\/p>\n<h3>2. Privacy is not breached only by sharing your name and surname<\/h3>\n<p>Some data may not look personal at first, but can become personal through accumulation: habits, frequent locations, routines, concerns, or preferences. With enough repetition, small clues add up to a profile.<\/p>\n<h3>3.AI doesn\u2019t \u201cunderstand\u201d like a professional<\/h3>\n<p>These tools can sound convincing even when they are wrong. And in sensitive matters (health, legal advice, psychological support), the risk is not only privacy-related: it can also lead to poorly informed decisions.<\/p>\n<h3>4. It\u2019s not only your privacy: you are also responsible for other people\u2019s data<\/h3>\n<p>A common mistake is to think \u201cthis isn\u2019t mine\u201d and let your guard down: a client\u2019s data, a candidate\u2019s details, a supplier\u2019s information, a colleague, a minor, a screenshot with names, a forwarded email\u2026 If you input these into an AI tool, you are processing personal data and may be exposing third-party information without a legal basis, without necessity, and without control.<\/p>\n<h2>The good practices recommended by the AEPD<\/h2>\n<p>The value of the ten-point guide lies precisely in the fact that it does not stay at generalities: it proposes concrete habits. These are the 10 recommendations set out by the Agency:<\/p>\n<h3>1. Don\u2019t upload your personal information to AI<\/h3>\n<p>Avoid including information that directly identifies you (e.g., contact details, documents, personal images). If you need to describe a case, anonymise it or use a fictional scenario.<\/p>\n<h3>2. Be especially careful not to upload sensitive or delicate information<\/h3>\n<p>Some categories are best kept out by default: health data, financial information, contractual matters, locations or stays. These are high-impact data if exposed.<\/p>\n<h3>3. Respect the privacy of third parties<\/h3>\n<p>If your query involves other people, remove any element that could identify them. And as a rule of thumb: don\u2019t upload images of third parties to generate new content, especially when minors are involved.<\/p>\n<h3>4. Don\u2019t include professional information<\/h3>\n<p>If you use AI in a professional context, apply the \u201cas if you were going to paste it into a public channel\u201d standard (because, in practice, the risk of exposure exists). No contracts, reports, strategies, client data, or employee information.<\/p>\n<h3>5. Review the AI service\u2019s terms before using it and choose the safest options<\/h3>\n<p>Before using a tool, check what happens to your information (retention, use for improvement, privacy settings, permissions). Prioritise solutions that collect only what is strictly necessary and provide clear controls.<\/p>\n<h3>6. If you need specialised professional advice, emotional support or psychological help, go to a professional rather than AI<\/h3>\n<p>If you need a diagnosis, clinical guidance, legal advice, or psychological support, don\u2019t replace it with a conversation with AI. You can use AI as support, but not as \u201cthe professional\u201d.<\/p>\n<h3>7. Don\u2019t believe everything an AI says: keep a critical stance towards its answers<\/h3>\n<p>Maintain a critical mindset. Don\u2019t delegate important decisions without verification, and cross-check against reliable sources (especially for matters with legal, financial, or personal impact).<\/p>\n<h3>8. Advise and guide the minors in your care<\/h3>\n<p>Explain what risks exist, what types of data should not be shared, and encourage critical thinking. Here, prevention means practical digital education.<\/p>\n<h3>9. Use different accounts and delete your history<\/h3>\n<p>If you are \u201ctesting\u201d tools, avoid mixing them with your personal or professional email. Use separate accounts, review deletion options, and remove conversations regularly when the service allows it.<\/p>\n<h3>10. Your questions can define you<\/h3>\n<p>You don\u2019t need to type \u201cmy ID number\u201d to leave a trail. Repeated questions about habits, fears, likes or routines can build a very precise profile. Practise the \u201cminimum necessary\u201d principle in what you ask as well.<\/p>\n<div class=\"cyp_post_formulario\"><h2>Contact Us<\/h2>\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f3074-o1\" lang=\"es-ES\" dir=\"ltr\" data-wpcf7-id=\"3074\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/en\/wp-json\/wp\/v2\/posts\/20083#wpcf7-f3074-o1\" method=\"post\" class=\"wpcf7-form init wpcf7-acceptance-as-validation\" aria-label=\"Formulario de contacto\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"3074\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.5\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"es_ES\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f3074-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/><input type=\"hidden\" name=\"_wpcf7_recaptcha_response\" value=\"\" \/>\n<\/fieldset>\n<div class=\"campo_nombre\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-name\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Name\" value=\"\" type=\"text\" name=\"your-name\" \/><\/span><\/div>\n<div class=\"campo_telefono\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-phone\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-tel wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-tel datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Phone\" value=\"\" type=\"tel\" name=\"your-phone\" \/><\/span><\/div>\n<div class=\"campo_email\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Email\" value=\"\" type=\"email\" name=\"your-email\" \/><\/span><\/div>\n<div class=\"campo_asunto\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-asunto\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Subject\" value=\"\" type=\"text\" name=\"your-asunto\" \/><\/span><\/div>\n<div class=\"campo_mensaje\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-mensaje\"><textarea cols=\"40\" rows=\"10\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Message\" name=\"your-mensaje\"><\/textarea><\/span><\/div>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"\" type=\"hidden\" name=\"cyp_form_url\" \/>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"cyp_zonaweb\" type=\"hidden\" name=\"zonaweb\" \/>\n<span class=\"wpcf7-form-control-wrap recaptcha\" data-name=\"recaptcha\"><span data-sitekey=\"6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" class=\"wpcf7-form-control wpcf7-recaptcha g-recaptcha\"><\/span>\r\n<noscript>\r\n\t<div class=\"grecaptcha-noscript\">\r\n\t\t<iframe loading=\"lazy\" src=\"https:\/\/www.google.com\/recaptcha\/api\/fallback?k=6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" frameborder=\"0\" scrolling=\"no\" width=\"310\" height=\"430\">\r\n\t\t<\/iframe>\r\n\t\t<textarea name=\"g-recaptcha-response\" rows=\"3\" cols=\"40\" placeholder=\"Aqu\u00ed la respuesta de reCAPTCHA\">\r\n\t\t<\/textarea>\r\n\t<\/div>\r\n<\/noscript>\r\n<\/span>\n<div style=\"width:100%\">\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important;margin-bottom:15px !important\">\nBy clicking on \"Send\" you accept our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup_ingles\">+ Info<\/a>\n<\/p>\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important\">\n<span class=\"wpcf7-form-control-wrap\" data-name=\"checkbox-173\"><span class=\"wpcf7-form-control wpcf7-checkbox wpcf7-exclusive-checkbox\"><span class=\"wpcf7-list-item first last\"><label><input type=\"checkbox\" name=\"checkbox-173\" value=\"\" \/><span class=\"wpcf7-list-item-label\"><\/span><\/label><\/span><\/span><\/span> I agree to receive outlined commercial communications from LETSLAW, S.L. in accordance with the provisions of our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup\">+ Info<\/a>\n<\/p>\n<\/div>\n<div class=\"vc_col-sm-12 botton-datos-contacto\"><input class=\"wpcf7-form-control wpcf7-submit has-spinner\" type=\"submit\" value=\"Send\" \/><\/div><input type='hidden' class='wpcf7-pum' value='{\"closepopup\":false,\"closedelay\":0,\"openpopup\":false,\"openpopup_id\":0}' \/><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<div>","protected":false},"excerpt":{"rendered":"<p>We analyse the AEPD&#8217;s ten-point guide, \u2018Cuidado con lo que le confIAs\u2019 with recommendations for reducing privacy risks in AI systems.<\/p>\n","protected":false},"author":2,"featured_media":20085,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[243],"tags":[],"class_list":["post-20083","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection"],"_links":{"self":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/20083","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/comments?post=20083"}],"version-history":[{"count":4,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/20083\/revisions"}],"predecessor-version":[{"id":20084,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/20083\/revisions\/20084"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media\/20085"}],"wp:attachment":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media?parent=20083"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/categories?post=20083"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/tags?post=20083"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}