🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
ES v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing35 sources retrieved model claude-sonnet-5 · 2026-08-03

Spain

ES schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 45 claims · 48 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
45Claimsbaseline..claims[]
31Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Spain's data protection enforcement environment shows a pronounced escalation around biometric data processing this cycle. The AEPD found that Yoti Ltd violated GDPR articles 5.1(e), 7 and 9, imposing combined fines of EUR950,000 across three distinct failures: EUR500,000 for unlawful biometric processing, EUR200,000 for invalid consent, and EUR250,000 for excessive retention. This sits alongside a broader pattern of AEPD action against inadequate biometric data protection impact assessments, most notably a EUR10,043,002 fine against Aena for deploying biometric-boarding facial recognition at eight airports without a DPIA that adequately assessed proportionality against less-intrusive alternatives, and a EUR500,000 fine against FC Barcelona in March 2026 for a deficient biometric DPIA covering approximately 143,000 club members.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Mature, fully operative omnibus regime with an active, well-resourced supervisory authority and clear statutory instruments.

Primary frameworkReglamento (UE) 2016/679 (RGPD/GDPR) + Ley Orgánica 3/2018 (LOPDGDD)
Traffic-light rationale — GreenMature, fully operative omnibus regime with an active, well-resourced supervisory authority and clear statutory instruments.

Sub-modules (5)

Regulator And AuthorityGreen

AEPD is the sole general-purpose national DPA for Spain; certain autonomous communities (Cataluña, País Vasco, Andalucía) maintain regional DPAs for public-sector processing within their territory, but AEPD retains general and private-sector competence.

Claims (1):

  • The Agencia Española de Protección de Datos (AEPD) is Spain's national data protection supervisory authority under GDPR and LOPDGDD.

Act And InstrumentsGreen

Core instruments are GDPR (directly applicable), LOPDGDD, LO 7/2021 (law-enforcement data), RD 389/2021 (AEPD Statute) and Ley 34/2002 LSSI for information-society services.

Claims (1):

  • Spain's data protection regime rests on GDPR (Regulation (EU) 2016/679) applied directly, LOPDGDD, LO 7/2021, RD 389/2021 (AEPD Statute) and Ley 34/2002 (LSSI) for e-commerce/electronic communications.

Material ScopeGreen

GDPR/LOPDGDD apply to any processing of personal data relating to an identified or identifiable natural person; data of legal persons is excluded.

Claims (1):

  • GDPR/LOPDGDD apply to the processing of personal data relating to identified or identifiable natural persons; data concerning legal persons is not covered.

Territorial ScopeGreen

Extraterritorial reach under GDPR Art 3(2) captures non-EU controllers/processors offering goods/services to, or monitoring the behaviour of, EU data subjects; such entities must designate an EU representative.

Claims (1):

  • Non-EU-established controllers/processors offering goods or services to, or monitoring the behaviour of, EU data subjects fall within GDPR's territorial scope and must appoint an EU representative as contact point for supervisory authorities and data subjects.

Regulator Registration And FilingAmber

General file-notification/registration with AEPD was abolished from 25 May 2018 and replaced by the internal, non-filed Registro de Actividades de Tratamiento (ROPA). The only affirmative filing duty remaining is communication of DPO appointments/removals to AEPD within 10 days.

Claims (2):

  • Since 25 May 2018, the obligation to register/notify processing files with AEPD has disappeared, both for public and private controllers, replaced by the internal Registro de Actividades de Tratamiento (ROPA).
  • Controllers/processors that designate a DPO (mandatorily or voluntarily) must communicate the appointment, and any subsequent removal, to AEPD within 10 days.
Category narrative74 words

Spain operates a fully-implemented GDPR omnibus regime. The Agencia Española de Protección de Datos (AEPD) is the national supervisory authority, operating under Ley Orgánica 3/2018 (LOPDGDD) alongside directly-applicable GDPR (Regulation (EU) 2016/679). The obligation to register files with AEPD was abolished on 25 May 2018 and replaced with internal accountability tools (ROPA). Territorial scope follows GDPR Art 3, extending to non-EU controllers targeting or monitoring EU-resident data subjects, who must appoint an EU representative.

Sources and claims (6)
  1. ConfirmedAgencia Española de Protección de Datos — The Agencia Española de Protección de Datos (AEPD) is Spain's national data protection supervisory authority under GDPR and LOPDGDD.observed
  2. ConfirmedAgencia Española de Protección de Datos — Spain's data protection regime rests on GDPR (Regulation (EU) 2016/679) applied directly, LOPDGDD, LO 7/2021, RD 389/2021 (AEPD Statute) and Ley 34/2002 (LSSI) for e-commerce/electronic communications.observed
  3. ConfirmedAgencia Española de Protección de Datos — GDPR/LOPDGDD apply to the processing of personal data relating to identified or identifiable natural persons; data concerning legal persons is not covered.observed
  4. ConfirmedAgencia Española de Protección de Datos — Non-EU-established controllers/processors offering goods or services to, or monitoring the behaviour of, EU data subjects fall within GDPR's territorial scope and must appoint an EU representative as contact point for supervisory authorities and data subjects.observed
  5. ConfirmedAgencia Española de Protección de Datos — Since 25 May 2018, the obligation to register/notify processing files with AEPD has disappeared, both for public and private controllers, replaced by the internal Registro de Actividades de Tratamiento (ROPA).observed
  6. ConfirmedAgencia Española de Protección de Datos — Controllers/processors that designate a DPO (mandatorily or voluntarily) must communicate the appointment, and any subsequent removal, to AEPD within 10 days.observed

#

Lawful basis and special-category framework is GDPR-aligned with clear, AEPD-published interpretive guidance; consent threshold for minors is well-documented.

Primary frameworkGDPR Arts 6-9 + LOPDGDD Arts 6-9
Traffic-light rationale — GreenLawful basis and special-category framework is GDPR-aligned with clear, AEPD-published interpretive guidance; consent threshold for minors is well-documented.

Sub-modules (4)

Lawful BasesGreen

GDPR Art 6 bases apply directly; LOPDGDD presumes legitimate interest for professional contact data of individuals acting for a legal person, absent proof to the contrary.

Claims (1):

  • LOPDGDD presumes, absent proof to the contrary, a legitimate interest under GDPR Art 6.1(f) for processing professional contact data and role/position data of individuals working for a legal entity.

Special CategoriesAmber

Facial recognition and other biometric identification technologies are classified as Art 9 special-category data, in principle prohibited absent an applicable exception; AEPD has repeatedly found that consent is an inadequate basis in imbalanced relationships (e.g. employment) and that an 'essential public interest' basis requires an appropriately-ranked statute that currently does not exist for many use-cases (e.g. biometric time/attendance control).

Claims (2):

  • The use of facial recognition in video-surveillance implies processing of biometric data classified as a special category under GDPR Art 9, in principle prohibited absent an applicable exception under Spanish law.
  • AEPD guidance holds that consent cannot lift the Art 9 prohibition for biometric presence/access-control systems in employment contexts due to the power imbalance between employer and employee, and that reliance on the 'essential public interest' exception requires a statute of appropriate legal rank that does not currently authorise biometric time-control.

Pseudonymisation And AnonymisationAmber

No AEPD-specific pseudonymisation/anonymisation safe-harbour instrument was surfaced in this research pass; GDPR's general pseudonymisation definition (Art 4(5)) applies directly as EU law.

Absence provenance: unavailable. Searched: AEPD anonymisation pseudonymisation guidance ES.

Category narrative87 words

Spain applies GDPR Art 6 lawful bases directly, supplemented by LOPDGDD presumptions (e.g. legitimate interest for professional contact data). Age of digital consent is set at 14 (LOPDGDD Art 7), below the GDPR default of 16, one of the lowest permitted under Art 8. Special-category data, notably biometric identifiers such as facial recognition, are treated as Art 9 data requiring an essential-public-interest legal basis grounded in a statute of appropriate rank; consent is treated by AEPD as an inadequate basis where a power imbalance exists (e.g. employer/employee).

Periodic update · new data 2026-09-28

Lawful Processing & Special Data

The AEPD found that Yoti Ltd violated GDPR articles 5.1(e), 7 and 9 in connection with its biometric data processing, imposing combined fines of EUR950,000 broken into three components: EUR500,000 for unlawful biometric processing, EUR200,000 for invalid consent, and EUR250,000 for excessive retention. The finding is understood to treat facial-match biometric data as special-category data under article 9 even where the operator claims immediate deletion after matching, a position that narrows the room for operators to argue that transient or non-retained biometric processing falls outside the special-category regime. The consent finding is understood to have turned on a pre-ticked-box mechanism used to obtain agreement for ancillary research-and-development use of the data, which the AEPD treated as invalid consent under article 7's standard for freely given, specific and unambiguous agreement.

This finding sits within a wider pattern this cycle of AEPD attention to biometric data specifically, rather than to special-category data generally, suggesting biometric processing has become a discrete enforcement priority rather than one example among many special-category categories. The retention component of the fine, EUR250,000 for excessive retention, indicates that even where initial collection and matching may have a lawful basis, the AEPD is scrutinising how long biometric data is actually held relative to the purpose for which it was collected.

Outlook

Yoti's appeal of the underlying sanction to the Spanish High Court, following the AEPD's rejection of its request for reconsideration on 2 March 2026, is the key item to watch for this module. Should the Audiencia Nacional narrow or overturn the AEPD's findings on the biometric special-category classification or the consent-validity analysis, that would materially affect the durability of the AEPD's current interpretive line on lawful processing of biometric data going forward.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (4)
  1. ConfirmedAgencia Española de Protección de Datos — LOPDGDD presumes, absent proof to the contrary, a legitimate interest under GDPR Art 6.1(f) for processing professional contact data and role/position data of individuals working for a legal entity.observed
  2. ConfirmedAgencia Española de Protección de Datos — Processing of a minor's personal data may only be based on the minor's own consent from age fourteen upward; below fourteen, consent must be given by parents or guardians.observed
  3. ConfirmedAgencia Española de Protección de Datos — The use of facial recognition in video-surveillance implies processing of biometric data classified as a special category under GDPR Art 9, in principle prohibited absent an applicable exception under Spanish law.observed
  4. ConfirmedAgencia Española de Protección de Datos — AEPD guidance holds that consent cannot lift the Art 9 prohibition for biometric presence/access-control systems in employment contexts due to the power imbalance between employer and employee, and that reliance on the 'essential public interest' exception requires a statute of appropriate legal rank that does not currently authorise biometric time-control.observed

#

Full GDPR rights catalogue in force; AEPD publishes accessible guidance confirming scope, including minors' rights from age 14.

Primary frameworkGDPR Arts 12-22 + LOPDGDD Arts 12-18
Traffic-light rationale — GreenFull GDPR rights catalogue in force; AEPD publishes accessible guidance confirming scope, including minors' rights from age 14.

Sub-modules (5)

Access RightGreen

Right of access under GDPR Art 15 applies; AEPD confirms minors over 14 may exercise it themselves.

Claims (1):

  • GDPR grants data subjects the rights of access, rectification, erasure, objection, portability, restriction of processing, and the right to object to automated decision-making including profiling; AEPD confirms these are exercisable by minors from age fourteen.

Rectification And ErasureGreen

Rights of rectification and erasure (Arts 16-17) form part of the standard rights catalogue confirmed by AEPD.

Claims (1):

  • GDPR grants data subjects the rights of access, rectification, erasure, objection, portability, restriction of processing, and the right to object to automated decision-making including profiling; AEPD confirms these are exercisable by minors from age fourteen.

Restriction And ObjectionGreen

Rights to restriction of processing and objection, including objection to automated decision-making/profiling, are confirmed in AEPD's minors-and-education guidance as part of the exercisable rights catalogue.

Claims (1):

  • GDPR grants data subjects the rights of access, rectification, erasure, objection, portability, restriction of processing, and the right to object to automated decision-making including profiling; AEPD confirms these are exercisable by minors from age fourteen.

Data PortabilityGreen

Portability right (Art 20) is included among the rights AEPD confirms as exercisable, including by minors from age 14.

Claims (1):

  • GDPR grants data subjects the rights of access, rectification, erasure, objection, portability, restriction of processing, and the right to object to automated decision-making including profiling; AEPD confirms these are exercisable by minors from age fourteen.

Deadlines And Response WindowsAmber

No ES-specific deviation from the GDPR Art 12(3) one-month (extendable to three) response window was located in this research pass; GDPR default applies directly.

Absence provenance: unavailable. Searched: AEPD plazo respuesta derechos RGPD un mes.

Category narrative34 words

GDPR Arts 15-22 rights (access, rectification, erasure, restriction, objection, portability, and objection to automated decision-making/profiling) apply directly in Spain and are reiterated in AEPD consumer-facing guidance, including specifically in the context of minors' data.

Sources and claims (1)
  1. ConfirmedAgencia Española de Protección de Datos — GDPR grants data subjects the rights of access, rectification, erasure, objection, portability, restriction of processing, and the right to object to automated decision-making including profiling; AEPD confirms these are exercisable by minors from age fourteen.observed

#

Comprehensive, actively-enforced accountability framework; breach and DPO statistics confirm real operative traction.

Primary frameworkGDPR Arts 5, 24-39 + LOPDGDD Arts 28, 31-37
Traffic-light rationale — GreenComprehensive, actively-enforced accountability framework; breach and DPO statistics confirm real operative traction.

Sub-modules (7)

Accountability And DpiaGreen

Accountability (Art 5(2)) is operationalised via ROPA construction, risk analysis, and DPIA (EIPD) execution as sequential compliance steps recommended by AEPD.

Claims (1):

  • AEPD's recommended RGPD-adaptation roadmap treats risk analysis and DPIA (EIPD) execution as core accountability tasks alongside ROPA construction and breach-notification mechanisms.

Dpo RequirementsGreen

GDPR Art 37.1 mandatory-DPO triggers (public authority, large-scale systematic monitoring, large-scale special-category processing) are extended by LOPDGDD Art 34 to additional categories of private entities (e.g. schools, sports federations processing minors' data). By end-2025, 126,176 DPOs were registered with AEPD.

Claims (2):

  • A DPO must be appointed where processing is carried out by a public authority, where core activities require regular and systematic large-scale monitoring of data subjects, or where core activities involve large-scale processing of special-category or criminal-conviction data; LOPDGDD Art 34 extends mandatory designation to further categories of entity.
  • By the close of 2025, 126,176 DPOs were registered with AEPD (116,007 private sector, 10,169 public sector), up from 119,803 in 2024.

Ropa RequirementsGreen

Art 30 ROPA obligation replaced the former file-registration regime; ROPA is an internal document made available to AEPD on request, not filed with the Agency.

Claims (1):

  • The Registro de Actividades de Tratamiento (ROPA) required by Art 30 GDPR is an internal document that must be made available to AEPD on request but does not need to be filed with or published to the Agency.

Joint Controller ArrangementsAmber

No ES-specific Art 26 joint-controller instrument beyond direct GDPR application and EDPB controller/processor guidance was located in this pass.

Absence provenance: unavailable. Searched: AEPD corresponsables tratamiento articulo 26.

Security MeasuresAmber

Art 32 security-of-processing obligations are actively enforced; AEPD's 2026 CaixaBank decision found repeated breaches attributable to systemic design and organisational deficiencies rather than isolated errors.

Claims (1):

  • AEPD confirmed a €500,000 fine (reduced to €400,000 on voluntary payment) against CaixaBank in March 2026 for repeated data breaches between 2022-2024 stemming from systemic design and organisational deficiencies rather than isolated human errors.

Breach NotificationAmber

Controllers must notify AEPD without undue delay and within 72 hours of becoming aware of a personal data breach (Art 33); breach-related sanctioning procedures rose sharply in 2025.

Claims (2):

  • Controllers must notify AEPD of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, per Art 33 GDPR.
  • AEPD's 2025 annual report recorded a 157% rise in breach-related sanctioning/reprimand procedures (30 in 2024 to 77 in 2025), yielding fines totalling approximately €19.8 million.

Retention And DisposalAmber

No ES-specific retention/disposal instrument beyond GDPR's storage-limitation principle (Art 5.1(e)) was surfaced in this research pass.

Absence provenance: unavailable. Searched: AEPD plazos conservacion supresion datos personales.

Category narrative51 words

GDPR accountability principle applies directly (Art 5(2)), operationalised through ROPA (Art 30), DPIA where risk criteria are met, DPO appointment where GDPR Art 37 / LOPDGDD Art 34 thresholds apply, and Art 32-34 security/breach-notification obligations. AEPD's 2025 annual report shows sharply increased breach-related sanctioning activity, evidencing active enforcement of these duties.

Periodic update · new data 2026-09-28

Controller/Processor Duties

Three substantial fines this cycle turn on the same underlying accountability failure: an inadequate data protection impact assessment for biometric processing. The AEPD fined Aena EUR10,043,002 for deploying biometric-boarding facial recognition at eight airports without a DPIA that adequately assessed proportionality against less-intrusive alternatives, the largest of the three penalties and the clearest signal that the AEPD expects controllers to demonstrate genuine consideration of alternatives before deploying biometric systems at scale. Separately, the AEPD fined FC Barcelona EUR500,000 in March 2026 for a deficient biometric DPIA, covering facial and voice data collection for approximately 143,000 club members, again turning on DPIA adequacy rather than on the underlying lawfulness of the processing itself.

Read together with the Yoti finding on unlawful biometric processing and invalid consent, these three actions establish DPIA adequacy for biometric systems as a distinct and currently very active enforcement front for the AEPD, spanning aviation, professional sport, and digital identity verification. The common thread across Aena and FC Barcelona is not that biometric processing itself was unlawful in principle, but that the controllers had not conducted or documented an assessment rigorous enough to justify the proportionality of the chosen approach against less intrusive alternatives.

Outlook

The pattern across three unrelated sectors this cycle suggests the AEPD is applying a consistent, elevated bar for DPIA adequacy specifically where biometric data is involved, and organisations deploying facial recognition, voice biometrics, or similar systems in Spain should expect continued scrutiny of their DPIA documentation. Whether this enforcement pattern extends into further sectors, and how the Yoti appeal to the Audiencia Nacional resolves, will indicate whether the current DPIA-adequacy standard for biometric systems is durable or subject to judicial narrowing.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (7)
  1. ConfirmedAgencia Española de Protección de Datos — AEPD's recommended RGPD-adaptation roadmap treats risk analysis and DPIA (EIPD) execution as core accountability tasks alongside ROPA construction and breach-notification mechanisms.observed
  2. ConfirmedAgencia Española de Protección de Datos — A DPO must be appointed where processing is carried out by a public authority, where core activities require regular and systematic large-scale monitoring of data subjects, or where core activities involve large-scale processing of special-category or criminal-conviction data; LOPDGDD Art 34 extends mandatory designation to further categories of entity.observed
  3. ConfirmedAgencia Española de Protección de Datos — By the close of 2025, 126,176 DPOs were registered with AEPD (116,007 private sector, 10,169 public sector), up from 119,803 in 2024.observed
  4. ConfirmedAgencia Española de Protección de Datos — The Registro de Actividades de Tratamiento (ROPA) required by Art 30 GDPR is an internal document that must be made available to AEPD on request but does not need to be filed with or published to the Agency.observed
  5. ConfirmedDataGuidance — AEPD confirmed a €500,000 fine (reduced to €400,000 on voluntary payment) against CaixaBank in March 2026 for repeated data breaches between 2022-2024 stemming from systemic design and organisational deficiencies rather than isolated human errors.observed
  6. ConfirmedAgencia Española de Protección de Datos — Controllers must notify AEPD of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, per Art 33 GDPR.observed
  7. ConfirmedAgencia Española de Protección de Datos — AEPD's 2025 annual report recorded a 157% rise in breach-related sanctioning/reprimand procedures (30 in 2024 to 77 in 2025), yielding fines totalling approximately €19.8 million.observed

#

Fully harmonised EU transfer regime in force with active AEPD guidance on mechanisms; TIA obligation confirmed via CJEU Schrems II jurisprudence.

Primary frameworkGDPR Arts 44-49 + Commission Implementing Decision (EU) 2021/914
Traffic-light rationale — GreenFully harmonised EU transfer regime in force with active AEPD guidance on mechanisms; TIA obligation confirmed via CJEU Schrems II jurisprudence.

Sub-modules (6)

Transfer MechanismsGreen

AEPD's international-transfers guidance confirms the availability of adequacy decisions, SCCs, BCRs, codes of conduct with binding commitments, certification mechanisms, and derogations for transfers outside the EEA.

Claims (1):

  • AEPD guidance confirms that, absent an adequacy decision, transfers outside the EEA may rely on Commission-adopted SCCs, controller-adopted SCCs approved by AEPD/the Commission, codes of conduct or certification mechanisms with binding commitments, or derogations for specific situations.

Adequacy ReceivedGreen

Not applicable in the conventional sense: as an EU Member State, Spain processes data under the GDPR directly and does not itself require an inbound adequacy decision from the European Commission.

Absence provenance: unavailable. Searched: Spain adequacy decision received EU Member State.

Adequacy GrantedGreen

The European Commission (binding EU-wide, applicable in Spain) has adopted adequacy decisions for a defined list of third countries and the EU-US Data Privacy Framework (10 July 2023), permitting transfers without further safeguards.

Claims (1):

  • European Commission adequacy decisions currently cover a defined set of third countries and the EU-US Data Privacy Framework (adopted 10 July 2023), permitting transfers from Spain without additional safeguards within their scope.

Sccs And BcrsGreen

Commission Implementing Decision (EU) 2021/914 SCCs (in force since June 2021, mandatory replacement of legacy clauses since December 2022) are the principal transfer safeguard mechanism referenced by AEPD.

Claims (1):

  • Commission Implementing Decision (EU) 2021/914 SCCs are considered to provide appropriate safeguards under GDPR Art 46(1)/(2)(c) for transfers from an EU data exporter to a non-EU importer; legacy pre-2001/2010-clause contracts ceased to be valid after 27 December 2022.

Transfer Impact AssessmentAmber

Following Schrems II (CJEU C-311/18), exporters relying on SCCs/BCRs must assess destination-country law/practice and adopt supplementary measures where needed — a transfer impact assessment obligation applicable to Spanish exporters.

Claims (1):

  • Following Schrems II, SCC-reliant exporters must carry out a transfer impact assessment documenting destination-country law/practice and any supplementary measures needed to protect transferred data.

Data LocalisationAmber

No Spain-specific data-localisation mandate (partial or absolute) was identified in this research pass beyond the general EU cross-border transfer regime.

Absence provenance: unavailable. Searched: Spain data localisation mandate personal data.

Category narrative54 words

As an EU Member State, Spain applies the GDPR Chapter V transfer regime uniformly: transfers rely on European Commission adequacy decisions, Commission Implementing Decision (EU) 2021/914 SCCs, BCRs, derogations, or ad hoc clauses authorised by AEPD. Post-Schrems II, a transfer impact assessment (TIA) is required for SCC-based transfers. No Spain-specific data-localisation mandate was identified.

Sources and claims (4)
  1. ConfirmedAgencia Española de Protección de Datos — AEPD guidance confirms that, absent an adequacy decision, transfers outside the EEA may rely on Commission-adopted SCCs, controller-adopted SCCs approved by AEPD/the Commission, codes of conduct or certification mechanisms with binding commitments, or derogations for specific situations.observed
  2. ConfirmedEUR-Lex — European Commission adequacy decisions currently cover a defined set of third countries and the EU-US Data Privacy Framework (adopted 10 July 2023), permitting transfers from Spain without additional safeguards within their scope.observed
  3. ConfirmedEUR-Lex — Commission Implementing Decision (EU) 2021/914 SCCs are considered to provide appropriate safeguards under GDPR Art 46(1)/(2)(c) for transfers from an EU data exporter to a non-EU importer; legacy pre-2001/2010-clause contracts ceased to be valid after 27 December 2022.observed
  4. ConfirmedEuropean Data Protection Board — Following Schrems II, SCC-reliant exporters must carry out a transfer impact assessment documenting destination-country law/practice and any supplementary measures needed to protect transferred data.observed

#

No separate sectoral statutes displace GDPR, but overlays exist and healthcare/financial sanctioning activity rose sharply in 2025, indicating active but uneven sectoral risk.

Primary frameworkGDPR/LOPDGDD + Ley 34/2002 (LSSI) + sector codes of conduct
Traffic-light rationale — AmberNo separate sectoral statutes displace GDPR, but overlays exist and healthcare/financial sanctioning activity rose sharply in 2025, indicating active but uneven sectoral risk.

Sub-modules (7)

Financial Sector OverlayAmber

No separate banking-secrecy statute displaces GDPR; AEPD actively enforces against financial institutions, e.g. the 2026 CaixaBank fine and 2026 Gesternova (energy-retail, financial data) fine.

Claims (1):

  • AEPD fined Gesternova, S.A. €220,000 in January 2026 for processing personal data without a valid legal basis and failing to provide mandatory transparency information at collection.

Health Sector OverlayAmber

Health data processing requires heightened DPO designation given its Art 9 special-category status; sanitary-sector sanctioning procedures rose 278% in 2025 (34 cases).

Claims (2):

  • AEPD has endorsed designating a single DPD for health-data processing bodies (e.g. within a defence-sector health inspectorate) given the special-category nature of health data and the scale of processing.
  • AEPD's 2025 annual figures show sanitary-sector sanctioning/reprimand procedures rose 278% year-on-year to 34 cases, among the six most active enforcement areas.

Telecoms And EprivacyGreen

Ley 34/2002 (LSSI) complements GDPR safeguards for information-society services, including the cookie-consent regime under its Art 22.2.

Claims (1):

  • Ley 34/2002 (LSSI) complements GDPR safeguards for information-society services in Spain, including the cookie/tracker consent regime under LSSI Art 22.2.

Employment DataAmber

Biometric access/presence-control systems in employment require a specific statutory basis; consent is deemed inadequate due to employer/employee power imbalance.

Claims (1):

  • AEPD guidance holds that consent cannot lift the Art 9 prohibition for biometric presence/access-control systems in employment contexts due to the power imbalance between employer and employee, and that reliance on the 'essential public interest' exception requires a statute of appropriate legal rank that does not currently authorise biometric time-control.

Credit And ScoringAmber

No ES-specific credit-scoring statute beyond GDPR Art 22 automated-decision safeguards was located in this research pass.

Absence provenance: unavailable. Searched: AEPD scoring crediticio normativa.

EducationGreen

Educational institutions offering any regulated level of teaching must designate a DPD, and online classes/exams do not require separate consent as they are legitimised by the educational mandate itself.

Claims (1):

  • Educational institutions are obliged to designate a DPD in the cases covered by GDPR Art 37 and, in all cases, when they offer teaching at any level established under regulating legislation; online classes/exams delivered as part of regulated education do not require separate student/parental consent.

InsuranceGreen

The insurance sector operates under a voluntary Art 40 GDPR code of conduct (UNESPA CC-0012-2019) supervised by an OCCC, supplementing but not displacing GDPR/LOPDGDD.

Claims (1):

  • The Spanish insurance sector operates under a voluntary Art 40 GDPR code of conduct (UNESPA CC-0012-2019), supervised by an OCCC, requiring adherent insurers to disclose their DPO identity and maintain ROPA compliance.
Category narrative54 words

GDPR/LOPDGDD apply horizontally, with sector overlays: Ley 34/2002 LSSI for electronic communications/cookies, DPO-mandatory designation for schools and sports federations processing minors' data, heightened biometric-data scrutiny in employment, and voluntary Art 40 sectoral codes of conduct (e.g. UNESPA insurance code). AEPD's strategic engagement covers health, education, telecoms, insurance, banking, and public administration as priority sectors.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (6)
  1. ConfirmedDataGuidance — AEPD fined Gesternova, S.A. €220,000 in January 2026 for processing personal data without a valid legal basis and failing to provide mandatory transparency information at collection.observed
  2. ConfirmedAgencia Española de Protección de Datos — AEPD has endorsed designating a single DPD for health-data processing bodies (e.g. within a defence-sector health inspectorate) given the special-category nature of health data and the scale of processing.observed
  3. ConfirmedAgencia Española de Protección de Datos — AEPD's 2025 annual figures show sanitary-sector sanctioning/reprimand procedures rose 278% year-on-year to 34 cases, among the six most active enforcement areas.observed
  4. ConfirmedAgencia Española de Protección de Datos — Ley 34/2002 (LSSI) complements GDPR safeguards for information-society services in Spain, including the cookie/tracker consent regime under LSSI Art 22.2.observed
  5. ConfirmedAgencia Española de Protección de Datos — Educational institutions are obliged to designate a DPD in the cases covered by GDPR Art 37 and, in all cases, when they offer teaching at any level established under regulating legislation; online classes/exams delivered as part of regulated education do not require separate student/parental consent.observed
  6. ProbableAEPD / UNESPA — The Spanish insurance sector operates under a voluntary Art 40 GDPR code of conduct (UNESPA CC-0012-2019), supervised by an OCCC, requiring adherent insurers to disclose their DPO identity and maintain ROPA compliance.observed

#

Cookie/dark-pattern regime is mature and AEPD-enforced; other sub-modules (opt-out signals, clean rooms, cross-context advertising) lack a direct EU/ES analogue and were not evidenced in this pass.

Primary frameworkLey 34/2002 (LSSI) Art 22.2 + GDPR + AEPD Guía sobre el uso de las cookies
Traffic-light rationale — AmberCookie/dark-pattern regime is mature and AEPD-enforced; other sub-modules (opt-out signals, clean rooms, cross-context advertising) lack a direct EU/ES analogue and were not evidenced in this pass.

Sub-modules (6)

Cookies And TrackersGreen

AEPD's cookie guide requires prior, informed, valid consent for non-exempt cookies, with accept/reject options presented with equal prominence and at the same level.

Claims (1):

  • For non-exempt cookies, valid consent must be obtained from the user, freely and informedly given, with the options to accept and reject cookies offered simultaneously, at the same level and with equal visibility.

Dark PatternsGreen

AEPD updated its cookie guide in 2023 to incorporate EDPB Guidelines 03/2022 on deceptive patterns, requiring accept/reject actions to be equally easy to select.

Claims (1):

  • AEPD updated its cookie guide in July 2023 to align with EDPB Guidelines 03/2022 on deceptive patterns, incorporating the criterion that accept/reject actions be presented in a prominent location and format at the same level, with rejection no more complicated than acceptance.

Opt Out SignalsAmber

No AEPD-specific recognition of a Global-Privacy-Control-equivalent browser signal was identified in this research pass.

Absence provenance: unavailable. Searched: AEPD Global Privacy Control señal navegador.

Clean Rooms And DcrAmber

No AEPD guidance on data clean rooms/data collaboration rooms was identified in this research pass.

Absence provenance: unavailable. Searched: AEPD clean room datos colaboración publicidad.

Cross Context AdvertisingAmber

The EU/ES consent-based ePrivacy model does not use the CPRA 'sale'/'share' framework; cross-context advertising is instead governed through the GDPR/LSSI cookie-consent regime.

Absence provenance: unavailable. Searched: AEPD publicidad cross-context venta datos.

Direct MarketingAmber

Electronic commercial communications are regulated via Ley 34/2002 (LSSI), which complements GDPR consent requirements for direct marketing by electronic means.

Claims (1):

  • Ley 34/2002 (LSSI) complements GDPR guarantees applicable to information-society services, including electronic direct-marketing communications.
Category narrative58 words

AEPD's Guía sobre el uso de las cookies (last major update aligning with EDPB Guidelines 03/2022 on deceptive patterns) governs cookie/tracker consent, mandating equal prominence for accept/reject options. No Spain-specific opt-out-signal (GPC-equivalent), clean-room, or CPRA-style 'sale/share' framework was identified — these concepts do not map directly onto the EU consent-based model, which instead relies on ePrivacy/LSSI consent requirements.

Sources and claims (3)
  1. ConfirmedAgencia Española de Protección de Datos — For non-exempt cookies, valid consent must be obtained from the user, freely and informedly given, with the options to accept and reject cookies offered simultaneously, at the same level and with equal visibility.observed
  2. ConfirmedAgencia Española de Protección de Datos — AEPD updated its cookie guide in July 2023 to align with EDPB Guidelines 03/2022 on deceptive patterns, incorporating the criterion that accept/reject actions be presented in a prominent location and format at the same level, with rejection no more complicated than acceptance.observed
  3. ProbableAgencia Española de Protección de Datos — Ley 34/2002 (LSSI) complements GDPR guarantees applicable to information-society services, including electronic direct-marketing communications.observed

#

AI governance is institutionally advanced (AESIA operative, 16 guidelines published) but the core Organic Law implementing AI Act governance domestically remains in draft/proposed stage as of mid-2026.

Primary frameworkGDPR Art 9, Art 22 + EU AI Act (Regulation (EU) 2024/1689) + draft Spanish Organic Law on AI governance
Traffic-light rationale — AmberAI governance is institutionally advanced (AESIA operative, 16 guidelines published) but the core Organic Law implementing AI Act governance domestically remains in draft/proposed stage as of mid-2026.

Sub-modules (6)

Profiling RestrictionsGreen

GDPR Art 22 grants data subjects the right to object to decisions based solely on automated processing, including profiling, applicable directly in Spain.

Claims (1):

  • GDPR grants data subjects the rights of access, rectification, erasure, objection, portability, restriction of processing, and the right to object to automated decision-making including profiling; AEPD confirms these are exercisable by minors from age fourteen.

Automated Decision Making TransparencyAmber

AEPD's AI-adaptation guidance ties automated processing to the GDPR information/transparency principle, requiring data subjects to be aware of how AI-driven processing uses their data.

Claims (1):

  • AEPD guidance on GDPR-compliant AI processing ties automated processing to the information/transparency principle, requiring affected data subjects to be made aware of how their data is used within AI-embedding treatments.

Ai Risk AssessmentsAmber

AESIA was created from scratch as Spain's dedicated national AI authority ahead of the EU AI Act's governance requirements, publishing 16 interpretive AI guidelines drawing on its regulatory sandbox; a draft Organic Law on AI governance, designating notifying/market-surveillance authorities and giving AESIA a single-point-of-contact role, was approved by Council of Ministers on 26 May 2026 and sent to Congress.

Claims (2):

  • Spain became the first EU Member State to establish a dedicated national AI supervisory authority, AESIA, which has published 16 interpretive AI guidelines developed within its AI regulatory sandbox to help translate EU AI Act principles into practical compliance steps.
  • On 26 May 2026, Spain's Council of Ministers approved a draft Organic Law on the proper use and governance of AI, designating notifying and market-surveillance authorities with AESIA as single point of contact, and sent it to Congress for parliamentary processing.

Biometric RegimeAmber

Facial-recognition and related biometric identification are treated as Art 9 special-category data requiring an essential-public-interest legal basis grounded in an appropriately-ranked statute; AEPD has rejected the argument that ordinary video-surveillance legitimation extends to facial/gait/voice recognition.

Claims (2):

  • The use of facial recognition in video-surveillance implies processing of biometric data classified as a special category under GDPR Art 9, in principle prohibited absent an applicable exception under Spanish law.
  • AEPD's 2020 legal report concluded that facial-recognition technology in private-security video-surveillance is, in principle, prohibited under GDPR as special-category biometric processing, and that the legitimation applicable to plain image/sound-capturing video-surveillance cannot be extended to facial, gait, or voice recognition.

Genetic DataAmber

No ES-specific genetic-data regime beyond GDPR Art 9's general special-category treatment was identified in this research pass.

Absence provenance: unavailable. Searched: AEPD datos geneticos regimen especial.

State Surveillance CarveoutsAmber

No ES-specific state-surveillance carveout beyond LO 7/2021 (law-enforcement-purpose data processing) was substantively evidenced in this research pass.

Claims (1):

  • Ley Orgánica 7/2021 provides a distinct data-protection regime for personal data processed for the prevention, detection, investigation and prosecution of criminal offences and execution of criminal penalties, operating alongside the general GDPR/LOPDGDD regime.
Category narrative81 words

Spain was the first EU Member State to create a dedicated AI supervisory authority, the Agencia Española de Supervisión de la Inteligencia Artificial (AESIA), operationalising EU AI Act oversight ahead of most peers, with a draft Organic Law on AI governance approved by the Council of Ministers in May 2026 and pending parliamentary processing. Biometric identification (facial recognition, gait, voice) is treated by AEPD as high-risk Art 9 special-category processing requiring reinforced safeguards. GDPR Art 22 profiling/automated-decision-making objection rights apply directly.

Periodic update · new data 2026-09-28

Algorithmic, Biometric & Surveillance Governance

Biometric enforcement is currently the AEPD's most active governance front, evidenced by three fines this cycle spanning digital identity verification (Yoti, EUR950,000 combined), aviation boarding systems (Aena, EUR10,043,002), and professional sports club membership management (FC Barcelona, EUR500,000). Each case turns on a different specific failure -- unlawful processing and invalid consent for Yoti, inadequate DPIA proportionality assessment for Aena and FC Barcelona -- but together they establish biometric data processing as a category receiving sustained, cross-sectoral AEPD attention rather than isolated sectoral scrutiny.

AESIA, Spain's national AI supervisory authority established under the national AI governance framework, is expected to coordinate with the AEPD to help ensure data-protection requirements are enforced alongside the EU AI Act's obligations, particularly for biometric and AI-driven systems where the two regulatory frameworks overlap. This coordination expectation reflects the structural reality that AI-driven biometric identification systems increasingly sit at the intersection of AI Act risk-classification obligations and GDPR's special-category data rules, though the operational form this AEPD-AESIA coordination will take has not been confirmed through a primary document this cycle.

Outlook

The coordination relationship between AESIA and the AEPD is the item to watch most closely, since formal confirmation of how the two authorities divide or share supervisory responsibility for AI-driven biometric systems would clarify whether Spain is developing an integrated AI-Act/GDPR enforcement posture for biometric technologies or maintaining largely separate regulatory tracks that happen to converge on the same underlying processing activities.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ProbableAgencia Española de Protección de Datos — AEPD guidance on GDPR-compliant AI processing ties automated processing to the information/transparency principle, requiring affected data subjects to be made aware of how their data is used within AI-embedding treatments.observed
  2. ConfirmedIAPP — Spain became the first EU Member State to establish a dedicated national AI supervisory authority, AESIA, which has published 16 interpretive AI guidelines developed within its AI regulatory sandbox to help translate EU AI Act principles into practical compliance steps.observed
  3. ConfirmedDataGuidance — On 26 May 2026, Spain's Council of Ministers approved a draft Organic Law on the proper use and governance of AI, designating notifying and market-surveillance authorities with AESIA as single point of contact, and sent it to Congress for parliamentary processing.observed
  4. ConfirmedAgencia Española de Protección de Datos — AEPD's 2020 legal report concluded that facial-recognition technology in private-security video-surveillance is, in principle, prohibited under GDPR as special-category biometric processing, and that the legitimation applicable to plain image/sound-capturing video-surveillance cannot be extended to facial, gait, or voice recognition.observed
  5. ConfirmedAgencia Española de Protección de Datos — Ley Orgánica 7/2021 provides a distinct data-protection regime for personal data processed for the prevention, detection, investigation and prosecution of criminal offences and execution of criminal penalties, operating alongside the general GDPR/LOPDGDD regime.observed

#

Consent-age and parental-consent framework is clear and GDPR-aligned; minor-specific profiling bans and dependent-adult protections beyond general GDPR safeguards were not evidenced in this pass.

Primary frameworkGDPR Art 8 + LOPDGDD Art 7 + LOPDGDD Art 34
Traffic-light rationale — AmberConsent-age and parental-consent framework is clear and GDPR-aligned; minor-specific profiling bans and dependent-adult protections beyond general GDPR safeguards were not evidenced in this pass.

Sub-modules (5)

Age VerificationAmber

AEPD's technical note on 'safe internet by default' for children stresses that age verification alone is insufficient and must be designed to meet all GDPR principles while avoiding new risks (e.g. enabling minors to be located).

Claims (1):

  • AEPD's technical note on a safe internet by default states that age verification, per se, is not sufficient and must be designed and implemented consistently with all GDPR principles while avoiding new risks such as enabling minors' location to be tracked.

Minor Profiling BansAmber

No explicit Spain-specific ban on profiling of minors beyond GDPR's general recitals/Art 22 objection right was identified in this research pass.

Absence provenance: unavailable. Searched: AEPD prohibicion perfilado menores.

Education SettingsGreen

Schools must designate a DPD when GDPR Art 37 criteria apply and, in all cases, when offering teaching at any level under regulating legislation; online classes/exams in regulated education are legitimised without requiring separate consent.

Claims (1):

  • Educational institutions are obliged to designate a DPD in the cases covered by GDPR Art 37 and, in all cases, when they offer teaching at any level established under regulating legislation; online classes/exams delivered as part of regulated education do not require separate student/parental consent.

Dependent AdultsAmber

No ES-specific dependent-adult (elderly/mentally incapacitated) data-protection instrument beyond general GDPR safeguards was identified in this research pass.

Absence provenance: unavailable. Searched: AEPD proteccion datos personas dependientes mayores.

Category narrative50 words

LOPDGDD sets the digital age of consent at fourteen, among the lowest permitted under GDPR Art 8's 13-16 range. AEPD publishes extensive guidance on age verification/age-appropriate design ('tudecideseninternet.es'), mandatory DPO designation for schools and youth-data-processing sports federations, and lawful processing of minors' data in regulated education without requiring separate consent.

Sources and claims (2)
  1. ProbableAgencia Española de Protección de Datos — AEPD's technical note on a safe internet by default states that age verification, per se, is not sufficient and must be designed and implemented consistently with all GDPR principles while avoiding new risks such as enabling minors' location to be tracked.observed
  2. ConfirmedAgencia Española de Protección de Datos — LOPDGDD Art 7 provides that processing of a minor's data may be based on the minor's own consent from age fourteen; below that age, parental or guardian consent is required, and consent must in all cases be express.observed

#

Enforcement activity is vigorous and well-documented, but AEPD's own reporting flags a capacity/resourcing strain relative to caseload growth.

Primary frameworkGDPR Arts 58, 77-84 + LOPDGDD Arts 48, 50, 63-72
Traffic-light rationale — AmberEnforcement activity is vigorous and well-documented, but AEPD's own reporting flags a capacity/resourcing strain relative to caseload growth.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

AEPD exercises Art 58 GDPR corrective powers (reprimand, corrective order, processing bans/limits, fines) through the LOPDGDD sanctioning procedure, governed subsidiarily by LPACAP; decisions are appealable via recurso de reposición or directly to the Audiencia Nacional.

Claims (2):

  • AEPD sanctioning procedures are governed by GDPR (Regulation (EU) 2016/679), LOPDGDD, its implementing regulatory provisions and, subsidiarily, general Spanish administrative procedure rules.
  • AEPD resolutions ending the administrative pathway may be challenged via a discretionary recurso de reposición before the AEPD Presidency/Director, or directly via recurso contencioso-administrativo before the Audiencia Nacional's Contentious-Administrative Chamber.

Enforcement Activity IndexAmber

2025 saw record enforcement activity: 30,931 complaints filed (+64% YoY), 77 breach-related sanctioning/reprimand procedures (+157% YoY, ≈€19.8m fines), plus headline 2026 fines against Gesternova (€220k) and CaixaBank (€500k/€400k).

Claims (4):

  • In 2025, AEPD received 30,931 complaints, the highest number in the Agency's history, a 64% increase over the prior year.
  • AEPD led 47 cross-border cases as lead authority in 2025 (+114% vs 2024) and cooperated as concerned authority in 419 cases (+20%); of 38 Audiencia Nacional judgments on AEPD-resolution appeals in 2025, 76% were dismissed or rejected, i.e. upheld the Agency's decisions.
  • AEPD fined Gesternova, S.A. €220,000 in January 2026 for processing personal data without a valid legal basis and failing to provide mandatory transparency information at collection.
  • AEPD confirmed a €500,000 fine (reduced to €400,000 on voluntary payment) against CaixaBank in March 2026 for repeated data breaches between 2022-2024 stemming from systemic design and organisational deficiencies rather than isolated human errors.

Regulator Funding And CapacityAmber

AEPD's own 2025 annual report states that growing workload across most subdirectorates has not been matched by proportional staffing growth, a constraint the Agency flags in its 2025-2030 Strategic Plan.

Claims (1):

  • AEPD's 2025 annual report states that the growing workload reflected across most of its subdirectorates and divisions has not been matched by a proportional increase in staffing, prompting a technology-supported, impact-prioritised supervision strategy under its 2025-2030 Strategic Plan.

Collective Redress And Class ActionsAmber

No ES-specific GDPR-related collective-redress/class-action mechanism beyond general Spanish civil procedure and EU Representative Actions Directive transposition was evidenced in this research pass.

Absence provenance: unavailable. Searched: AEPD accion colectiva proteccion datos demanda.

Private Right Of ActionAmber

Data subjects and controllers alike may challenge AEPD resolutions via recurso de reposición or directly via recurso contencioso-administrativo before the Audiencia Nacional's Contentious-Administrative Chamber.

Claims (1):

  • Any interested party may lodge a recurso contencioso-administrativo against a final AEPD resolution before the Audiencia Nacional's Contentious-Administrative Chamber within two months of notification.

Recent Developments 180DAmber

Within the last 180 days: AEPD published its 2025 annual report (May 2026) showing record complaint volumes and sanctioning activity; AEPD confirmed the €500k/€400k CaixaBank fine (March 2026); Spain's Council of Ministers approved a draft Organic Law on AI governance (May 2026); AESIA continued publishing AI guidelines through mid-2026.

Claims (3):

  • AEPD presented its Memoria de actuación 2025 on 6 May 2026, disclosing record complaint volumes, a 157% rise in breach-related sanctioning/reprimand procedures, and approximately €19.8 million in resulting fines.
  • AEPD confirmed a €500,000 fine (reduced to €400,000 on voluntary payment) against CaixaBank in March 2026 for repeated data breaches between 2022-2024 stemming from systemic design and organisational deficiencies rather than isolated human errors.
  • On 26 May 2026, Spain's Council of Ministers approved a draft Organic Law on the proper use and governance of AI, designating notifying and market-surveillance authorities with AESIA as single point of contact, and sent it to Congress for parliamentary processing.
Category narrative69 words

AEPD holds full Art 58 GDPR corrective powers (reprimand, order, ban, fine) exercised via LOPDGDD-specific sanctioning procedure (Art 63-65), with decisions appealable to the Audiencia Nacional. 2025 was a record enforcement year: 30,931 complaints (up 64%), breach-related sanctioning procedures up 157% to 77 (≈€19.8m in fines), and headline fines against Gesternova (€220k, Jan 2026) and CaixaBank (€500k/€400k, March 2026). AEPD explicitly flags that workload growth has outpaced staffing increases.

Periodic update · new data 2026-09-28

Enforcement & Redress

The AEPD's sanctioning powers remain grounded in GDPR article 83, permitting administrative fines of up to EUR20 million or 4% of global annual turnover, whichever is higher, and LOPDGDD article 77 mandates publication of final sanctioning resolutions once they become firm. This cycle's biometric enforcement wave -- the Yoti, Aena and FC Barcelona fines -- illustrates the AEPD exercising this authority at a range of scales, from EUR500,000 up to over EUR10 million, depending on the severity and sectoral context of the underlying violation.

Of particular note for the redress dimension is the active contestation of the Yoti sanction. The AEPD rejected Yoti's request for reconsideration on 2 March 2026, and Yoti has since escalated its challenge to a full appeal before the Spanish High Court, the Audiencia Nacional, disputing both the substantive findings and the adequacy of the AEPD's notification procedure. This is a live, unresolved legal proceeding rather than a settled enforcement outcome, and it represents the clearest current test of how far Spanish courts will support the AEPD's interpretive approach to biometric special-category data and consent validity under the current enforcement wave.

Outlook

The Audiencia Nacional's eventual ruling on Yoti's appeal is the single most consequential redress-related development to track, since it will either validate or narrow the AEPD's current enforcement approach to biometric data, with direct implications for how durable the accompanying Aena and FC Barcelona DPIA-adequacy findings prove to be if similarly challenged.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (7)
  1. ConfirmedAgencia Española de Protección de Datos — AEPD sanctioning procedures are governed by GDPR (Regulation (EU) 2016/679), LOPDGDD, its implementing regulatory provisions and, subsidiarily, general Spanish administrative procedure rules.observed
  2. ConfirmedAgencia Española de Protección de Datos — AEPD resolutions ending the administrative pathway may be challenged via a discretionary recurso de reposición before the AEPD Presidency/Director, or directly via recurso contencioso-administrativo before the Audiencia Nacional's Contentious-Administrative Chamber.observed
  3. ConfirmedAgencia Española de Protección de Datos — In 2025, AEPD received 30,931 complaints, the highest number in the Agency's history, a 64% increase over the prior year.observed
  4. ConfirmedAgencia Española de Protección de Datos — AEPD led 47 cross-border cases as lead authority in 2025 (+114% vs 2024) and cooperated as concerned authority in 419 cases (+20%); of 38 Audiencia Nacional judgments on AEPD-resolution appeals in 2025, 76% were dismissed or rejected, i.e. upheld the Agency's decisions.observed
  5. ConfirmedAgencia Española de Protección de Datos — AEPD's 2025 annual report states that the growing workload reflected across most of its subdirectorates and divisions has not been matched by a proportional increase in staffing, prompting a technology-supported, impact-prioritised supervision strategy under its 2025-2030 Strategic Plan.observed
  6. ConfirmedAgencia Española de Protección de Datos — Any interested party may lodge a recurso contencioso-administrativo against a final AEPD resolution before the Audiencia Nacional's Contentious-Administrative Chamber within two months of notification.observed
  7. ConfirmedAgencia Española de Protección de Datos — AEPD presented its Memoria de actuación 2025 on 6 May 2026, disclosing record complaint volumes, a 157% rise in breach-related sanctioning/reprimand procedures, and approximately €19.8 million in resulting fines.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct87.88
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Spain
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 45 claim(s) (45 category placement(s)), 48 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy granted
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redresscollective redress and class actions
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated with claims grounded primarily in T1 AEPD primary sources (regulation pages, FAQs, legal-office reports, published sanctioning resolutions, and the 2025 Memoria de actuación) plus T2 EDPB guidance and T3 DataGuidance/IAPP secondary reporting for the most recent 2026 enforcement and AI-governance developments. Sub-modules without located primary-source evidence (pseudonymisation/anonymisation safe-harbours, joint-controller arrangements, retention/disposal schedules, data localisation, opt-out signals, clean rooms, cross-context advertising framing, genetic data, minor-profiling bans, dependent-adult protections, credit-scoring rules, collective redress/class actions, and regulator funding specifics beyond the 2025 narrative) carry explicit absent_field_provenance rather than fabricated claims.

Unresolved questions (4):

  • Does any Spanish sectoral statute impose data-localisation requirements for specific data categories (e.g. health, government cloud) beyond the general EU transfer regime?
  • What is the current parliamentary status/timeline for the draft Organic Law on AI governance sent to Congress in May 2026?
  • Are there ES-specific collective-redress mechanisms for GDPR breaches beyond general civil procedure and any EU Representative Actions Directive transposition?
  • Does AEPD maintain any Spain-specific credit-scoring or genetic-data guidance not surfaced in this research pass?

Escalate to primary-source review: yes