Personal Data in Company Records: What Fuentio Keeps, What It Drops, and Why

Personal data in company records: what Fuentio keeps about officers in France and Spain (names and roles), what it drops, and how removals are handled.

· By the Fuentio team · 7 min read

Share image: "Personal Data in Company Records: What Fuentio Keeps, What It Drops, and Why" on Fuentio's paper background, with the Guide label.

Company registers are public, and they name people: directors, managers, sole traders. If you put a company data provider into your stack, your data protection officer will ask what personal data comes with it, on what basis, and how a removal request is handled. This page answers those questions for Fuentio, precisely, for France and Spain.

Method as of 10 October 2026. Reuse conditions link to their official texts.

Short answer: Fuentio keeps officers' names and roles only, as the official register publishes them, marked personal_data: "officially_public". We drop birth dates, nationality, home addresses, ID numbers and civil status, even when the source shows them. We don't offer search by person. For Spain, when the BOE starts excluding a document, we hide the officers and act texts we took from it, and keep only company-level facts.

What you'll learn

  • What the official reuse conditions say about personal data
  • Exactly which fields we keep and drop, per country
  • Why we don't offer search by person
  • How removals and exclusions are handled
  • What this means for your own processing

What do the reuse conditions say?

  • France, officers from INPI's national company register (RNE): the RNE reuse licence allows commercial reuse, and says personal data may be reused only within the legal framework on personal data (GDPR and French data protection law). It also requires respecting the restrictions on search criteria set by the Commercial Code.
  • Spain, BORME from the BOE: the BOE's reuse conditions require full respect of the GDPR when documents contain personal data.

Both allow reuse; both put the responsibility for lawful handling on the reuser. Our choices below go beyond the minimum on purpose.

What do we keep and drop?

FranceSpain
Officer nameKept, as publishedKept, as published
Officer roleKept, with the original wording and a normalised roleKept, with the original wording and a normalised role
Birth date or yearDroppedReplaced before storage
NationalityDroppedReplaced before storage
ID numbers (DNI, NIE)—Replaced before storage
Home address, civil status, birth place—Replaced before storage
Sole trader as "officer"Not added: the name is already the business nameSame rule
Company officers (a company as director)Kept with a link to that companyKept

Each officer entry is marked personal_data: "officially_public", so your systems can tell it apart from data you collect yourselves. Here's how an officer looks in a real record (name hidden on this site):

{"name": "[not shown]", "role_original": "Administrateur", "role": "director", "personal_data": "officially_public"}

This blog and our demo never show people's names.

Why no search by person?

Searching companies by an individual's name turns a company register into a register of people. In France, the Commercial Code restricts search criteria on register data, and the RNE licence asks reusers to respect those restrictions. So Fuentio searches by company name, postcode and town only. Any search-by-person feature would need a legal review first, and isn't offered.

How are removals handled?

Spain. The BOE's robots.txt excludes some BORME documents and whole days, which look like individual removal requests. We re-read it every day and skip excluded documents. When a document we already used becomes excluded, we treat it as a removal request: the officers and act texts from that document are hidden, while company-level facts (name, status, acts) stay. Stored history is redacted the same way.

France. We return what the source returns. Individual entrepreneurs who opted out of publication aren't in the State's public API at all, and we never fill that gap from another source. See non-diffusible companies.

Requests to us. Anyone can write to [email protected] about data concerning them. Our privacy page explains how we handle personal data.

Questions your DPO will ask, answered

  • Where does officer data come from? France: INPI's national company register, via the State's company API. Spain: section A of the BORME.
  • Is it public? Yes, officially published by law. We mark it officially_public so you can document that.
  • What's the purpose limitation on our side? We use officer data to describe the company record, nothing else. We don't build profiles of people and don't sell data.
  • How long do you keep it? As long as the company record exists, with redaction when a removal applies.
  • Do you search by person? No.
  • What about search logs? We count units per key per day for quota and billing; our technical logs keep the time, status and address of each call, which for a lookup includes the company number, but never your search text.

Why we go beyond the minimum

The official reuse conditions allow commercial reuse of officer data, and the registers publish more than names: French sources can include birth years, Spanish act texts can include ID numbers and home addresses. We could pass all of it through. We don't, for three reasons:

  • Most products don't need it. Checking who can sign for a company needs a name and a role, not a birth date.
  • Every field you receive is a field you must protect. Fewer personal fields means a smaller risk for you and for us.
  • Removal requests should be easy to honour. Data we never stored is data nobody has to find and erase.

Data minimisation isn't only a legal principle; it's a design choice that makes our product easier for your DPO to approve.

How this looks in an API answer

An officer entry has exactly four fields: name, role_original (the register's wording, such as "Administrateur" or "Adm. Solid."), role (a normalised role such as director or manager) and personal_data. A company that sits as an officer of another gets a company_ref pointing to its own record, never a person's.

What this means for your processing

  • You still need a legal basis for your own use of officer data, for example checking who can sign for a customer. Our marking helps you document where it came from.
  • Keep only what you need. If your process only needs the company's status, don't store officer names.
  • Keep the provenance with any officer data you store: source, licence and check date. See provenance on every answer.

For how officer data feeds signing checks, see who runs a French company.

Fuentio's API isn't open yet. Become an early tester and review these rules with your DPO before launch.

See what we cover in France and Spain.

Frequently asked questions

Does Fuentio return directors' personal data?

Names and roles only, as the official register publishes them. Birth dates, nationality, ID numbers and addresses are dropped.

Can I search companies by a person's name?

No. Search runs on company name, postcode and town only.

What happens when a BORME document is excluded by the BOE?

We hide the officers and act texts taken from it, and keep company-level facts.

Who do I contact about data concerning me?

Write to [email protected].

Sources

← All articles · RSS feed