Algorithmic transparency clauses in your software vendor contract

An algorithmic transparency clause is the commitment by which a software vendor gives its client what the client needs to explain the system to its staff. Since 5 October 2026, Spain’s Royal Decree 723/2026 has required employers to inform each worker in writing about the algorithmic or automated systems that decide on their working conditions, including their guidelines, criteria and rules. The duty falls on the employer, but knowledge of the system usually sits with a third party. Spain’s Public Employment Service (SEPE) published its model information document on 1 October, with a section of its own for these systems. Filling it in requires data that only the vendor holds, and the contract is the only place where the vendor can be required to hand it over.

Table of contents

Why Royal Decree 723/2026 ends up in your vendor contract

Article 3.2.k of Royal Decree 723/2026 (in Spanish) binds the employer, not the vendor. It is the employer who must report the existence of algorithmic or automated decision-making systems and, where they decide on working conditions, their guidelines, criteria and operating rules. The vendor does not appear in the rule. If the information is missing or incomplete, the minor offence in article 6.4 of the Spanish Law on Social Order Offences and Penalties (LISOS) is attributed to the employer, with a fine of 70 to 750 euros.

The problem is practical. In many technology companies, shift scheduling, performance reviews and incentives run on third-party software, used as a service or under licence. The company knows what the system does, but not always how it decides. The variables, their weighting and the rules that turn data into a decision sit in the vendor’s internal documentation.

The SEPE model makes this visible. Its section I, on the «existence of algorithmic or automated decision-making systems», is a free-text box. To fill it with more than the name of the program, the company needs an explanation from the vendor that it can pass on. What to tell staff, to whom and when is explained in our guide on algorithmic transparency for workers in Spain.

Six clauses worth negotiating with your vendor

Six commitments cover what a company needs to comply with Royal Decree 723/2026 and the rules around it. A new contract is not required. They fit in the service or licence agreement, in the service level agreement or in an addendum.

A description of the system that can be passed on to staff

The vendor undertakes to deliver, and keep up to date, a description of how the system works in plain language. It should state which decisions it supports or takes, what data it uses, how it weights each variable, which rules it applies and what human intervention it allows. The clause must specify that the description is meant to be shared with workers and their representatives. A technical document written for the IT department does not serve that purpose.

It is also worth setting the format and the deadline. An annex of two or three pages, delivered shortly after signature, is enough for most scheduling, evaluation or incentive systems.

Advance notice of changes to the model or its parameters

The vendor undertakes to give advance notice of any change that alters the variables, their weighting or the decision rules. The reason lies in article 7.3 of the Royal Decree, which requires changes to be communicated to workers as soon as possible and, at the latest, on the day they take effect. A vendor that updates its model without warning leaves the company in breach without knowing it.

The clause works if it defines what counts as a relevant change and sets a notice period. Thirty calendar days is a reasonable starting point for planned changes. For urgent fixes, same-day notice describing the effect is enough.

Cooperation with workers, the works council and the Labour Inspectorate

The vendor undertakes to help the company answer three kinds of request. Workers hired before 5 October 2026 may ask for the information, and the company has thirty working days to provide it under the sole transitional provision. The works council is entitled to know the parameters, rules and instructions of the algorithms under article 64.4.d of the Spanish Workers’ Statute. And the Labour Inspectorate may request the documentation at any time.

The contract should give the vendor a shorter response time than the company’s. If the company has thirty working days, the vendor should answer within ten.

Documentation of testing, bias controls and human oversight

The company needs to know more than how the system decides. It also needs to know what controls it has. The vendor should provide a summary of the tests carried out before release, the bias controls and the human review options it offers. This helps answer staff questions and feeds the data protection impact assessment under article 35 of the GDPR where the processing requires one.

For high-risk artificial intelligence systems used in employment, this documentation will stop depending on negotiation on 2 December 2027. From that date, the AI Act will require their provider to supply instructions for use containing that information.

Confidentiality and trade secrets without leaving the company in the dark

Explaining an algorithm does not mean revealing its code. The Spanish Ministry of Labour’s guide of May 2022 already made this clear for the information right in the Workers’ Statute, and letter k uses equivalent language. The vendor can protect its source code and training data as a trade secret under Spain’s Trade Secrets Act 1/2019 (in Spanish).

The clause balances both interests. The vendor identifies which information it considers secret, and the company undertakes not to disclose it beyond what the law requires. In return, the vendor cannot rely on secrecy to refuse an understandable description of how the system decides, which is exactly what the company must pass on.

Liability, indemnity and exit

The liability clause closes the loop. If the company is fined because the vendor did not provide the information or did not announce a change, the contract should allow it to recover that cost. Software-as-a-service agreements often cap the vendor’s liability at one year of fees and exclude fines. The breach of these obligations should fall outside that cap or have a cap of its own.

The exit also needs to be planned. If the vendor repeatedly fails to comply, the company must be able to terminate the contract and recover its data without penalty.

Which obligation each clause covers

Each clause answers a specific rule. The table helps check whether a contract covers all the rules that apply to a system deciding on staff.

ClauseRule that makes it necessaryApplicable since
Understandable description of the systemRoyal Decree 723/2026, article 3.2.k5 October 2026
Advance notice of changesRoyal Decree 723/2026, articles 5 and 7.35 October 2026
Cooperation with requestsRoyal Decree 723/2026, sole transitional provision · Workers’ Statute, article 64.4.d · GDPR, article 28.3.e2026 · 2021 · 2018
Documentation of testing and human oversightGDPR, article 35 · AI Act, article 13, for high-risk AI2018 · 2 December 2027
ConfidentialityTrade Secrets Act 1/20192019
Liability and indemnityLISOS, article 6.4, which penalises the employer5 October 2026

Contracts already signed and vendors with standard terms

Contracts signed before 5 October do not include these clauses, and the obligation is already in force. The quickest route is an algorithmic transparency addendum of one or two pages, signed without reopening the rest of the contract. If the contract expires soon, it can be negotiated at renewal.

Large vendors rarely negotiate their terms. In that case, ask in writing for product documentation describing the system and check whether it is enough to fill in section I of the SEPE model. If it is not, the company must decide whether to complete the information itself, which requires understanding the system, or to change vendor.

Example: a clinic chain with scheduling software

The case is fictitious. Clínicas Vereda, S.L. runs six physiotherapy clinics in Valencia with 85 professionals. Since 2024 it has used cloud software that assigns each week’s shifts based on appointment demand, declared availability and seniority. The contract is the vendor’s standard one and does not mention the algorithms.

In October 2026 the company prepares the information document for three new hires. While filling in section I, it realises it does not know how much seniority weighs against availability. It asks the vendor for an addendum with four commitments, namely a descriptive annex within fifteen days, thirty days’ notice of changes, a response within ten days to any staff request and the exclusion of these obligations from the liability cap.

The vendor accepts the first three and offers, for the fourth, a separate cap of twice the annual fee. With the annex, Clínicas Vereda completes the document before the new hires start and files the addendum for the next works council review.

How it fits with the GDPR processing agreement and the AI Act

Almost every HR software vendor processes staff personal data on behalf of the company and has already signed a processing agreement under article 28 of the GDPR. That agreement requires it to help the company respond to data subjects’ rights, under article 28.3.e. These include the right to meaningful information about the logic involved under article 15.1.h, which the GDPR recognises at least for decisions based solely on automated processing under article 22.

Royal Decree 723/2026 goes further than the GDPR. It covers any system involved in a decision on working conditions, even if a person has the final say. That is why the processing agreement is not enough and the algorithmic transparency clause belongs in the main contract or in the service level agreement. In practice, it pays to review both documents together.

The AI Act will take over part of this work from 2 December 2027. AI systems intended to make decisions on the terms of employment, promotion or dismissal, to allocate tasks based on behaviour or personal traits, or to evaluate performance are high-risk under its Annex III. Their provider will have to supply instructions for use describing their capabilities, limitations and human oversight measures. Each party’s obligations are explained in our AI Act compliance guide for businesses. Systems that are not AI, or not high-risk, will continue to depend on the contract alone.

Is the software vendor bound by Royal Decree 723/2026?

No. The duty to inform falls on the employer, and the vendor is only bound by what it agrees in the contract. That is why the company needs clauses requiring the vendor to provide the system description, announce changes and cooperate when a worker or the Labour Inspectorate requests information. Without them, the penalty for inadequate information falls on the company even if the vendor is at fault.

There is no need, and the vendor may refuse. Royal Decree 723/2026 requires explaining the system’s guidelines, criteria and operating rules, not its programming. Source code and training data can be protected as trade secrets. What the company should demand is an understandable description of what data the system uses, how it weights it and what it decides.

Ask for it in writing and keep a record of the refusal. Then there are three options, namely completing the information with the product’s public documentation and your own testing, negotiating an addendum at the next renewal, or changing vendor. The vendor’s refusal does not release the company from informing its staff, because the duty under Royal Decree 723/2026 is the company’s.

Sometimes. It is enough if it explains which decisions the system supports, which variables it uses, how it weights them and what human intervention it allows. User manuals usually describe how to configure the program, not how it decides. The practical test is to try to fill in section I of the SEPE model information document with it. If that is not possible, you need an annex from the vendor.

It is not mandatory, but it is advisable for systems that decide on staff. The duty to inform has been in force since 5 October 2026 and also covers workers hired earlier if they ask. A short addendum with the system description, notice of changes and cooperation with requests solves the problem without reopening the rest of the contract.

Royal Decree 723/2026 turns a technical issue into a contractual obligation. The company answers to its staff and to the Labour Inspectorate for something it does not control, and only the vendor contract allocates that risk. Reviewing now the contracts for systems that decide shifts, evaluations or incentives costs less than doing it after an inspection request. At Innovatech we review and negotiate software contracts as part of our software contracts service in Spain. Write to us for a free initial assessment.

Managing Partner at Innovatech Legal | Website | + posts

Marta Suárez-Mansilla is Managing Partner of Innovatech Legal and a Spanish lawyer (abogada), Madrid Bar (ICAM), working in technology law. She completed Harvard Law School's Copyright course and BerkeleyX's Blockchain programme, and has advised technology companies for more than eight years.