General Data Protection Regulation (GDPR)

🇪🇸General Data Protection Regulation in Spain

A comprehensive guide to General Data Protection Regulation compliance for organisations operating in Spain. Understand local enforcement, the national data protection authority, key focus areas, and notable enforcement actions.

About General Data Protection Regulation

The EU's landmark data protection law that governs how organisations collect, store, process, and transfer personal data of individuals in the European Economic Area.

Effective: 25 May 2018Max penalty: €20,000,000 or 4% of annual global turnover
Full General Data Protection Regulation overview

General Data Protection Regulation Enforcement in Spain

Spain's AEPD is one of Europe's most prolific enforcers by number of decisions, regularly issuing hundreds of sanctions per year across a wide range of sectors. The Spanish Organic Law 3/2018 (LOPDGDD) supplements the GDPR with provisions on the rights of the deceased's digital legacy, employee digital rights (including the right to digital disconnection), video surveillance in the workplace, and whistleblower channel management. The AEPD has been particularly active in sanctioning unlawful video surveillance (CCTV), unsolicited commercial communications, and inadequate data processing in healthcare. Spain sets the age of digital consent at 14. The AEPD publishes detailed guides on practical compliance and maintains an extensive publicly searchable sanctions database.

Data Protection Authority

Agencia Española de Protección de Datos (AEPD)

Key Enforcement Focus Areas in Spain

  • Video surveillance and CCTV compliance
  • Direct marketing and unsolicited communications
  • Healthcare data processing
  • Employee digital rights (right to disconnect)
  • Telecommunications sector compliance

Notable Enforcement Actions in Spain

CaixaBank S.A.

€6,000,000(2021)

Processing customer data for commercial communications without valid GDPR-compliant consent

Vodafone España S.A.U.

€8,150,000(2021)

Repeated unsolicited commercial calls and SMS messages, and failure to demonstrate valid consent

EDP Energía S.A.

€1,500,000(2022)

Switching customers' energy suppliers using personal data without authorisation or valid consent

Equifax Ibérica

€1,000,000(2023)

Maintaining inaccurate solvency data and failing to verify debt information accuracy

Check Your Compliance Status

Take our free assessment to evaluate your organisation's compliance posture. Get a personalised report with actionable recommendations in minutes — no sign-up required.

Start Free Assessment

Disclaimer: The information on this page is for educational purposes and does not constitute legal advice. For specific compliance guidance, consult a qualified legal professional in your jurisdiction.

Other Regulations Affecting Spain