Part 1 of 3 | ANRO Privacy
Under Spain’s previous data protection regime, the Organic Law 15/1999 (LOPD), compliance was largely a matter of registration. Companies notified the authorities that they held personal data files, and for many that was the end of the exercise.
That model is gone. The General Data Protection Regulation (GDPR), together with Spain’s national adaptation, the Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (Ley Orgánica de Protección de Datos Personales y garantía de los derechos digitales, or LOPDGDD), replaced it with something far more demanding. The principle at the heart of the current framework is accountability (responsabilidad proactiva). In practical terms, this means that a company must not only comply with the rules but must be able to prove that it complies.
Documentation is that proof. If the Spanish Data Protection Authority (Agencia Española de Protección de Datos, or AEPD) opens an investigation or a data subject files a complaint, the first thing the regulator will ask for is evidence. A defensible compliance file is the difference between demonstrating responsible data management and scrambling to explain why no records exist.
This article covers the baseline documentation pack, the set of documents that virtually every company acting as a data controller (responsable del tratamiento) in Spain should have in place, regardless of size, sector, or specific risk profile. Part 2 of this series covers conditional documents triggered by risk, sector, or activity. Part 3 addresses the additional layer for companies with websites or online commercial activity.
Spain adds a number of specific requirements on top of standard GDPR obligations, including mandatory data blocking, an expanded list of sectors requiring a Data Protection Officer, and a suite of digital rights for employees. Those are addressed in Parts 2 and 3. The focus here is on the seven document categories that form the foundation of any compliance programme.
Watch the video overview
The Record of Processing Activities (Registro de Actividades de Tratamiento, commonly abbreviated as RAT) is the foundational compliance document. It is a structured record of every processing activity the company carries out involving personal data.
The RAT must describe, for each activity, what personal data is processed, the purpose of the processing, the legal basis relied upon, the categories of data subjects and recipients, any international transfers, the applicable retention periods, and a general description of the security measures in place. Both data controllers and data processors (encargados del tratamiento) are required to maintain one.
Legal basis: GDPR Article 30, LOPDGDD Article 31.
The GDPR formally requires a RAT only for organisations with 250 or more employees, or where processing is not occasional, involves special category data, or is likely to result in a risk to the rights and freedoms of individuals. In practice, almost every company processing employee or customer data falls within one of these conditions. The AEPD’s own compliance tools, Facilita RGPD for low-risk SMEs and Gestiona RGPD for more complex operations, both begin with the creation of a processing inventory.
Example: A small estate agency in Marbella would typically record processing activities for client property searches, marketing communications, employee records, and supplier contacts. Each activity gets its own entry in the RAT, with the legal basis, retention period, and security posture documented separately.

A privacy information notice (cláusula informativa) is the document that tells a data subject, at the point their data is collected, what will happen with their personal information. The LOPDGDD formalises a layered approach to these notices in Article 11.
The first layer must be concise, providing the essential information at the point of collection: the identity of the data controller, the purpose of the processing, and the data subject’s rights. The second layer, accessible via a direct link or a secondary medium, contains the full detailed information required by GDPR Articles 13 and 14, including retention periods, recipients, details of any international transfers, and the right to lodge a complaint with the AEPD.
Legal basis: GDPR Articles 13 and 14, LOPDGDD Article 11.
Companies typically need separate notices for each audience: customers, employees, job applicants, and suppliers. The AEPD provides model clauses (modelos de cláusulas informativas) and a dedicated guide on the duty to inform, both available on the AEPD website.
Example: A boutique hotel needs a notice on its booking form for guests, a separate clause in its employment contracts for staff, a notice in its job application process, and a clause in its supplier onboarding paperwork. The content differs for each because the purposes, legal bases, and retention periods are not the same.
Individuals have the right to request access to their personal data, rectification, erasure (supresión), restriction of processing, data portability, and to object to processing. These are sometimes grouped under the Spanish acronym ARSOPOL. A company must have a documented procedure for receiving, verifying, and responding to these requests (ejercicio de derechos).
Legal basis: GDPR Articles 15 to 22.
The procedure should define how requests are received, who within the company is responsible for handling them, how the identity of the requester is verified, the response deadlines (one calendar month, extendable by a further two months for complex requests), and how outcomes are recorded in an evidence log.
The AEPD has consistently sanctioned companies for responding late to rights requests, even where the eventual response was correct and complete. The delay itself constitutes a violation. A documented procedure reduces this risk by establishing clear internal ownership and timelines.
Example: An accountancy firm receives an access request from a former client. The procedure defines which team member acknowledges receipt, what data is gathered from the firm’s systems, how the one-month deadline is tracked, and where the response and supporting evidence are filed.

Whenever a company uses a third party that processes personal data on its behalf, a data processor agreement (contrato de encargado del tratamiento) must be in place. This applies to any external provider that handles personal data as part of the service it delivers: payroll providers, cloud software platforms, marketing agencies, IT support companies, and similar.
Legal basis: GDPR Article 28, LOPDGDD Article 33.
The agreement must set out the subject matter and duration of the processing, its nature and purpose, the types of personal data involved, and the obligations of the processor. Key clauses include the processor’s duty to implement appropriate security measures, to notify the controller without undue delay in the event of a breach, to obtain prior authorisation before engaging sub-processors, to support the controller in responding to data subject rights requests, and to return or destroy the data at the end of the contract.
The LOPDGDD adds a notable Spanish provision in Article 33.2: if a processor acts in its own name and establishes direct relationships with data subjects, it will be treated as a data controller regardless of what the contract says. This makes proper contractual boundaries especially important.
The AEPD publishes contract guidance and model clauses to assist with drafting.
Example: A restaurant chain using a cloud-based reservation system, an external payroll provider, and a digital marketing agency needs a separate processor agreement with each. If any of those providers uses sub-processors (for example, the payroll provider hosting data on a third-party cloud platform), that must also be documented and authorised.
The GDPR requires companies to implement technical and organisational security measures (medidas de seguridad) that are appropriate to the level of risk associated with their processing activities. Those measures must be documented.
Legal basis: GDPR Article 32.
This is not a one-size-fits-all exercise. What is “appropriate” depends on the nature of the data, the volume of processing, and the potential consequences of a breach. A small consultancy handling client contact details operates at a different risk level from a health clinic processing medical records.
Documentation should cover access controls, encryption practices, backup and recovery procedures, staff training records, physical security measures, and any policies governing the use of portable devices or remote working. The AEPD provides security guidance and risk management resources on its website.
Example: A professional services firm with eight staff might document the following measures: encrypted laptops, role-based access to client files, annual data protection training for all employees, a clean desk policy, and a locked filing cabinet for paper records containing personal data.

Every company must have an internal protocol for detecting, assessing, and responding to personal data breaches (brechas de seguridad de datos personales), together with a breach register (registro de brechas) that logs every breach, whether or not it is reported to the AEPD.
Legal basis: GDPR Articles 33 and 34.
Where a breach is likely to result in a risk to the rights and freedoms of individuals, the company must notify the AEPD within 72 hours. Where the risk is high, affected data subjects must also be informed. However, the obligation to record a breach in the register applies to all breaches, including those assessed as not requiring notification. The register serves as evidence that the company has a functioning breach management process.
The AEPD’s Comunica-Brecha RGPD tool provides a guided assessment to help companies determine whether a specific breach requires notification and to whom.
Example: An employee at an estate agency accidentally sends a client’s financial details to the wrong email address. The breach must be logged in the register immediately, even if the subsequent risk assessment concludes that notification to the AEPD is not required. The log should record what happened, when it was detected, the data affected, the assessment of risk, and any remedial action taken.
A retention and deletion policy (política de conservación y supresión) documents how long each category of personal data is kept and what happens when the retention period expires. In Spain, this document must also address a requirement that does not exist in the standard GDPR framework: data blocking (bloqueo de datos).
Legal basis: GDPR Article 5(1)(e) on storage limitation, LOPDGDD Article 32 on data blocking.
Under LOPDGDD Article 32, when a data controller rectifies or erases personal data, it must block that data rather than immediately destroying it. Blocking means that the data is identified, segregated, and technically locked so that it cannot be accessed by regular staff or used for any purpose other than being made available to judges, courts, the Public Prosecutor’s Office (Ministerio Fiscal), or competent public authorities in connection with potential liabilities arising from the processing.
The data remains in this blocked state for the statutory limitation period applicable to those liabilities, which typically ranges from three to six years depending on the type of obligation. Only once that period has expired must the data be physically destroyed.
If a company’s systems cannot support a blocking function, or if implementing one would require a disproportionate effort, LOPDGDD Article 32.4 permits an alternative: creating a secure copy of the data with digital evidence, or other evidence, that establishes its authenticity, the date of blocking, and the fact that the data has not been manipulated during the blocking period.
Failure to block data when rectification or erasure is carried out is classified as a serious infringement (infracción grave) under the LOPDGDD.
Example: A hotel guest exercises their right to erasure and requests deletion of their booking history. The hotel blocks the data so that it is inaccessible to reservations, marketing, or front-desk staff, but retains it in a locked state for the tax liability period (four years under Spanish tax law). After that period expires, the data is physically destroyed and the destruction is recorded.
These seven document categories, the Record of Processing Activities, privacy information notices, a data subject rights procedure, data processor agreements, security measures documentation, a breach procedure and breach register, and a retention and deletion policy with data blocking, form the minimum defensible compliance pack for a company operating in Spain.
Without them, a company cannot demonstrate the accountability that GDPR Article 5(2) requires. The AEPD’s enforcement record shows that procedural failings, such as missing documentation, late responses to rights requests, or the absence of a breach register, attract sanctions independently of whether any substantive harm to a data subject has occurred.
For companies that are building a compliance programme from scratch, a practical starting sequence is to begin with the RAT (establishing what processing exists), then address transparency through privacy notices, formalise vendor governance through processor agreements, build breach readiness, and document security measures and retention. The AEPD’s free tools, including Facilita RGPD for low-risk SMEs, Gestiona RGPD for more complex operations, and Comunica-Brecha RGPD for breach assessment, can support much of this process.
Part 2 of this series covers the conditional documents that become mandatory depending on a company’s specific risk profile, sector, or activities, including Data Protection Impact Assessments, DPO appointments, international transfer documentation, and workplace monitoring policies.
This article is published by ANRO Privacy for informational purposes only. It does not constitute legal advice and does not create a professional relationship between ANRO Privacy and the reader. Data protection compliance involves fact-specific assessments. Companies should consult a qualified Data Protection Officer or lawyer for advice tailored to their circumstances.
Key Takeaways
Most marketing still works by interruption. It shouts at people who never asked to be shouted at, then wonders why conversion rates stay flat and unsubscribe rates climb.
Seth Godin identified this problem back in 1999 when he introduced permission marketing: the idea that the most effective marketing only reaches people who have actually agreed to receive it. Remarkably, this aligns perfectly with a principle that European data protection law would later enshrine as a legal requirement: Privacy by Design.
Prefer to watch the overview on Privacy by Design & Marketing?
For businesses operating in Spain under both the GDPR and the LOPDGDD, this isn't just a philosophical alignment. It is a practical roadmap. When you build your marketing around genuine consent, you don't just satisfy regulators, you build a more engaged audience that actually wants to hear from you.
Permission marketing is the practice of sending marketing messages only to people who have explicitly agreed to receive them. Seth Godin defined it as the privilege, not the right, of delivering anticipated, personal, and relevant messages to people who want to get them.
This stands in contrast to interruption marketing, which relies on billboards, cold emails, and pop-up ads to grab attention by force. Godin’s framework rests on three core principles:
The result is a shift from broadcasting to everyone to cultivating an audience that actively chooses to listen.
Privacy by Design is a framework codified under Article 25 of the GDPR. It requires organisations to embed data protection into every stage of a business process rather than bolting it on as an afterthought.
Under the GDPR and Spain's LOPDGDD, Privacy by Design means your marketing must prioritise:
In Spain, the AEPD enforces these principles actively. Sanctions for non-compliance can reach €20 million or 4% of global annual turnover, making compliance a business-critical priority.
The overlap between Godin’s philosophy and legal requirements is striking. Both respect the individual’s autonomy over their own attention and data.

This isn't just about compliance, it is about performance. When someone has genuinely opted in, every key marketing metric improves:
Godin compares this to dating: you don't propose on the first meeting. You earn trust gradually, moving the person up the permission ladder from stranger to advocate.
In a market saturated with interruption tactics, trust is a competitive advantage. This is especially true in sectors like finance, legal services, and healthcare, where a Data Protection Officer is often required.
The businesses that thrive won't be the ones finding clever ways to skirt consent. They will be the ones that make consent the foundation of their growth. To learn more about how data protection works in Spain, explore our guides and articles.
Is permission marketing required by the LOPDGDD in Spain? Yes. The LOPDGDD and the GDPR strictly require informed, unambiguous consent before processing personal data for direct marketing purposes, effectively making permission marketing a legal mandate.
Does a pre-ticked box count as permission under the GDPR? No. Pre-ticked boxes do not constitute valid consent. Consent must be a freely given, specific, and affirmative action by the user.
How does data minimisation apply to email marketing?Data minimisation requires that you only collect the personal data strictly necessary for your marketing goal. For a newsletter, this typically means asking only for an email address, rather than demanding a phone number or physical address.
If you live in Spain, you have almost certainly received unwanted marketing calls, emails, or text messages (spam marketing) from companies you have never heard of. It is one of the most common complaints among residents, and especially among expats who find their phone numbers circulating among telemarketers shortly after signing a rental contract or opening a bank account.
Spain has specific, legally-backed tools to fight this. The best known is the Robinson List (Lista Robinson), but it is not the only one. A second service, Lista STOP Publicidad, operates under the same legal framework and offers some additional features. Whether you are an individual who wants to stop the spam, or a business that needs to understand its legal obligations before running marketing campaigns, this guide covers everything you need to know.
The Robinson List is Spain’s official advertising exclusion service (servicio de exclusión publicitaria). It is a free, voluntary registry where individuals can sign up to block unsolicited commercial communications from companies they have no prior relationship with.
The service is managed by Adigital (the Spanish Digital Economy Association) and covers four communication channels:
For a quick overview, watch our guide to The Robinson List in Spain
The name comes from Robinson Crusoe: the idea of being “isolated on an island” away from the flood of unwanted advertising. Similar opt-out registries exist across Europe, the UK has the Telephone Preference Service (TPS), Germany has the Robinsonliste, and the US has the Do Not Call Registry.
A second advertising exclusion service, Lista STOP Publicidad (listastoppublicidad.com), operates under the same legal framework as the Robinson List. It is a social initiative, completely free, and covers the same channels — phone calls, SMS, email, and postal addresses, with the addition of social media direct messages (DMs), which the Robinson List does not cover.
Key differences worth noting:
Businesses are equally obligated to check Lista STOP Publicidad before running campaigns, just as they are with the Robinson List. The legal obligation under Article 23 LOPDGDD applies to all recognised exclusion services, not just the Robinson List specifically.
Registration is free and takes about five minutes. Here is how to do it:
Step 1: Go to www.listarobinson.es
Step 2: Click “Apúntate en la lista” (Sign up for the list). The site is in Spanish, but you can use your browser’s translation feature.
Step 3: Register with your DNI/NIE number and personal details. You will need to provide the contact information you want to protect (phone number, email, postal address).
Step 4: Select the channels you want to block: phone, email, postal mail, and/or SMS.
Step 5: Confirm your registration via the verification email you receive.
Your registration becomes effective within a short period, but you should allow up to two months for the full effect, as companies are required to update their exclusion lists periodically.
The Robinson List does not block all marketing. It only blocks communications from companies with which you have no prior relationship. This means:
The Robinson List is not just a voluntary nicety. It has serious legal backing under both Spanish and European data protection law.
Spain’s Ley Orgánica 3/2018 de Protección de Datos y Garantía de los Derechos Digitales (LOPDGDD) explicitly regulates advertising exclusion systems in Article 23. The key provisions are:
Under the General Data Protection Regulation (GDPR), Article 21(2) gives every individual an unconditional right to object to the processing of their personal data for direct marketing purposes. When someone exercises this right, their data must cease to be processed for marketing immediately. The Robinson List is Spain’s practical implementation of this principle.
Spain’s 2022 General Telecommunications Law introduced stricter rules on commercial calls. Since June 2023, companies can no longer make unsolicited marketing calls to anyone who has not given prior consent, unless there is an existing contractual relationship. This significantly strengthened the protection provided by the Robinson List.
This is where the Robinson List becomes critically important for any company operating in Spain—and this is the section that will help you avoid fines from the AEPD.
If your company conducts direct marketing based on legitimate interest (Art. 6.1.f GDPR) rather than explicit consent, you are legally required to check the Robinson List before every campaign. This is not optional.
You should check the list:
Businesses can access the Robinson List through the Lista Robinson business portal. The system uses a privacy-preserving mechanism: you submit hashed versions of your contact data, and the system returns a yes/no result without exposing any personal data from the registry.
The AEPD has consistently sanctioned companies that fail to check the Robinson List. Penalties include:
| Infraction Level | Fine Range | Example |
|---|---|---|
| Minor | Up to €40,000 | Isolated failure to check |
| Serious | €40,001 – €300,000 | Systematic failure, repeated complaints |
| Very Serious | €300,001 – €20M or 4% turnover | Large-scale violations with GDPR breaches |
In practice, most Robinson List-related sanctions from the AEPD fall in the €1,000 to €70,000 range for individual companies. However, repeated offenders or large-scale operations face significantly higher penalties.
Under Article 21 of Spain’s LSSI-CE (Ley de Servicios de la Sociedad de la Información), there is an exception that allows businesses to send electronic marketing to existing customers without explicit consent, provided that:
This exception applies even if the person is on the Robinson List. However, the moment the customer opts out directly with you, you must stop immediately.
This is one of the most frequently asked questions, and the honest answer is: it helps significantly, but it is not a silver bullet.
What it does well:
What it does not do:
For additional protection, consider using call-blocking apps like Truecaller alongside your Robinson List registration. You can also file complaints directly with the AEPD at www.aepd.es if companies continue to contact you.
If your organisation has appointed a Data Protection Officer (DPO) (Delegado de Protección de Datos (DPD), they should ensure that Robinson List compliance is integrated into your marketing operations. Specifically, the DPO should:
Yes. Any person residing in Spain can register, whether you have a DNI (Spanish nationals) or a NIE (foreign residents). You need your identification number and the contact details you want protected.
No, Lista STOP Publicidad is a second recognised service operating under the same legal basis. Registering on one does not automatically register you on the other, so individuals who want maximum coverage should register on both.
The official website (listarobinson.es) is currently only in Spanish. However, the registration process is straightforward and your browser’s built-in translation should work well enough to complete it.
Registration is processed quickly, but companies are given a reasonable period to update their marketing lists. You should expect to see a reduction in unwanted communications within one to two months.
First, ask the company to stop and note down their details. If they continue, you can file a complaint with the AEPD. Your Robinson List registration serves as evidence that you opted out of unsolicited marketing.
The Robinson List primarily covers personal data. However, if your B2B marketing targets identifiable individuals (which it almost always does), the same rules apply. Marketing emails sent to name@company.com are still processing personal data.
Yes. There is no exemption based on company size. If you conduct direct marketing based on legitimate interest in Spain, you must check the list regardless of whether you are a sole trader or a multinational.
For individuals: Register on the Robinson List at listarobinson.es today. It is free, takes five minutes, and will meaningfully reduce the amount of unsolicited marketing you receive.
For businesses: Make Robinson List checks a standard part of your marketing workflow. Document your compliance. Train your team. The cost of a fine from the AEPD is far greater than the cost of implementing a proper checking process.
Disclaimer: This content is provided for informational purposes only and does not constitute legal advice. It does not create any professional relationship between the reader and ANRO Privacy. For specific compliance guidance tailored to your organization's circumstances, consult a qualified Data Protection Officer or legal professional specializing in Spanish data protection law.
The Agencia Española de Protección de Datos (AEPD) is Spain's independent data protection authority, responsible for enforcing data protection laws including the GDPR and Spain's national legislation, the LOPDGDD (Ley Orgánica de Protección de Datos y garantía de los derechos digitales). The AEPD ensures that organizations handle personal data lawfully, transparently, and securely while safeguarding individuals' fundamental rights to privacy and data protection.
As Spain's national Supervisory Authority, the AEPD wields extensive regulatory powers, including issuing substantial fines, conducting investigations, approving codes of conduct, and providing authoritative guidance to businesses, public bodies, and citizens across all sectors.
The AEPD plays a central role in Spain's data protection landscape by:
Organizations operating in Spain must follow AEPD requirements to ensure full compliance with both GDPR and LOPDGDD.
The AEPD plays a vital role in:
By aligning with AEPD regulations and understanding Spain's unique compliance requirements, businesses can ensure legal compliance, minimize enforcement risks, and demonstrate responsible data stewardship to Spanish customers, employees, and regulatory authorities.
Disclaimer: This content is provided for informational purposes only and does not constitute legal advice. It does not create any professional relationship between the reader and ANRO Privacy. For specific compliance guidance tailored to your organization's circumstances, consult a qualified Data Protection Officer or legal professional specializing in Spanish data protection law.
Essential privacy and data protection terminology for English-speaking businesses navigating Spain's regulatory framework
Last updated: January 2025
Understanding data protection terminology is crucial for businesses operating in Spain. This comprehensive glossary defines key privacy terms in both English and Spanish, helping you navigate Spain's dual regulatory framework under the GDPR and LOPDGDD (Spain's national data protection law).
Whether you're a UK company expanding to Spain, an expat running a Spanish business, or an international organisation with Spanish operations, this glossary provides the foundational terminology you need for compliance.
A formal request from a data subject to obtain confirmation of whether their personal data is being processed and, if so, to receive a copy of that data. In Spain, controllers must respond within one month under both GDPR Article 15 and LOPDGDD provisions.
Spain's independent supervisory authority responsible for enforcing GDPR and LOPDGDD, investigating complaints, imposing fines, and issuing binding guidance on data protection matters. The AEPD maintains a notably aggressive enforcement posture compared to many EU counterparts.
The process of rendering personal data irreversibly unidentifiable, ensuring individuals cannot be identified directly or indirectly through any means reasonably likely to be used. Properly anonymised data falls outside the scope of GDPR and LOPDGDD entirely.
The fundamental requirement that data controllers must demonstrate compliance with data protection principles through documented policies, procedures, and technical measures rather than merely claiming compliance. This represents the shift from "paper compliance" to proactive responsibility.
Personal data resulting from specific technical processing relating to physical, physiological, or behavioural characteristics (such as facial images or fingerprints) that allow unique identification of a natural person. Spain heavily restricts biometric processing, particularly in employment contexts, as demonstrated by the €10 million AENA fine.
A uniquely Spanish requirement under LOPDGDD Article 32 whereby data marked for deletion must first be placed in a restricted, offline state for a defined retention period (typically 4-5 years) before physical destruction. Data remains available only for legal claims, compliance obligations, or regulatory requests during the blocking period.
The mandatory obligation to report personal data breaches to the AEPD within 72 hours of discovery and, where high risk exists, to affected data subjects without undue delay. Controllers must maintain internal breach registers even when AEPD notification is not legally required.
A freely given, specific, informed, and unambiguous indication of a data subject's wishes by which they agree to the processing of their personal data through a clear affirmative action. In Spain, consent for children under 14 years requires parental or guardian authorisation, lower than the GDPR's default age of 16.
The natural or legal person, public authority, agency, or body which alone or jointly with others determines the purposes and means of processing personal data. Controllers bear primary legal responsibility for GDPR/LOPDGDD compliance including documentation, security measures, and rights fulfilment.
Regulated databases containing information about debts and payment behaviour, governed by strict rules under LOPDGDD Article 20. Debts under €50 cannot be registered, negative data must be removed after five years, and debtors must be notified before registration.
The movement of personal data from Spain or the EU to third countries outside the European Economic Area, which requires adequate safeguards such as Standard Contractual Clauses, Binding Corporate Rules, or an adequacy decision from the European Commission.
A security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored, or otherwise processed. Controllers must maintain breach registers and notify the AEPD within 72 hours where required.
The GDPR principle requiring that personal data collected must be adequate, relevant, and limited to what is strictly necessary for the specified processing purposes. Over-collection violates this fundamental principle even with valid consent.
The right of data subjects under GDPR Article 20 to receive their personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller without hindrance when processing is based on consent or contract.
A mandatory risk assessment required before implementing high-risk processing activities such as large-scale processing of special category data, systematic monitoring of public areas, or automated decision-making with legal effects. The AEPD maintains a specific list of processing operations requiring DPIAs.
An independent expert appointed to monitor GDPR/LOPDGDD compliance, advise on data protection obligations, cooperate with the AEPD, and serve as a contact point for data subjects. Under LOPDGDD Article 34, appointment is mandatory for 16 specific sectors regardless of organisation size—stricter than standard GDPR requirements.
An identified or identifiable natural living person whose personal data is being processed. Spanish law uniquely extends certain data protection rights to relatives and heirs of deceased persons under LOPDGDD Article 3.
A pioneering right enshrined in LOPDGDD Article 88 (Title X Digital Rights) requiring employers to establish policies and protocols limiting out-of-hours digital communications and respecting employees' rest periods, leave, personal time, and family privacy.
The right under LOPDGDD Article 96 for individuals to provide legally binding instructions regarding the access, use, rectification, or deletion of their online accounts, social media profiles, and digital content after death.
A technical security measure that transforms readable data into an encoded format requiring a decryption key for access, recognised under GDPR Article 32 as an appropriate safeguard for protecting personal data confidentiality and integrity.
The right of data subjects under GDPR Article 17 to obtain deletion of their personal data without undue delay when specific conditions are met (purpose achieved, consent withdrawn, unlawful processing). In Spain, erasure is closely linked to the mandatory blocking obligation under LOPDGDD Article 32.
The requirement under GDPR Article 5 that personal data be processed lawfully, fairly, and transparently in relation to the data subject, ensuring individuals can understand, challenge, and exercise control over how their information is used.
A free online compliance tool provided by the AEPD specifically designed to help Spanish small and medium-sized enterprises achieve GDPR compliance through guided questionnaires, automated documentation generation, and sector-specific templates.
Regulation (EU) 2016/679, the primary European legal framework for data protection that came into effect on 25 May 2018, establishing harmonised rules across all EU member states whilst allowing national adaptations through "opening clauses" that Spain exercised via LOPDGDD.
Special category data under GDPR Article 9 relating to physical or mental health of a natural person, including provision of healthcare services, which requires heightened protection. Processing generally requires explicit consent or must be necessary for healthcare provision, public health monitoring, or specific legal obligations.
See Data Protection Impact Assessment (DPIA)
The transparency obligations under GDPR Articles 13-14 requiring controllers to provide data subjects with clear information about processing purposes, legal basis, recipients, retention periods, and rights. LOPDGDD Article 11 endorses a layered approach for complex processing activities.
A core data protection principle under GDPR Article 5(1)(f) requiring that personal data be processed securely using appropriate technical and organisational measures to prevent unauthorised or unlawful processing, accidental loss, destruction, or damage.
Two or more controllers who jointly determine the purposes and means of processing personal data under GDPR Article 26, requiring a transparent written arrangement defining each party's respective compliance obligations and data subject rights procedures.
The fundamental GDPR Article 6 requirement that all personal data processing must be based on at least one of six legal bases: consent, contract necessity, legal obligation, vital interests, public task, or legitimate interests. Processing without a valid legal basis is unlawful.
The Spanish practice endorsed by LOPDGDD Article 11 and AEPD guidance of providing privacy information in progressive tiers: essential details provided immediately at point of collection, with additional comprehensive information accessible through clearly signposted links, documents, or QR codes.
A legal basis for processing under GDPR Article 6(1)(f) where the controller demonstrates compelling interests that do not override the fundamental rights and freedoms of data subjects. LOPDGDD Article 19 creates a rebuttable presumption of legitimate interest for business-to-business professional contact data.
Spain's Organic Law 3/2018 of 5 December on Protection of Personal Data and Guarantee of Digital Rights, which adapts and supplements the GDPR with stricter national requirements including lower age of consent (14 years), mandatory data blocking, expanded DPO obligations across 16 sectors, and pioneering digital rights provisions in Title X.
In Spain, individuals under 14 years of age are considered minors for data protection purposes and require verifiable parental or guardian authorisation to consent to processing of their personal data in information society services—notably lower than the GDPR's default age threshold of 16 years.
The right of data subjects under GDPR Article 21 to object to processing based on legitimate interests or public interest tasks, and an absolute right to object to direct marketing. Controllers must cease processing unless they can demonstrate compelling legitimate grounds that override the individual's interests.
Any information relating to an identified or identifiable natural person (data subject), including names, identification numbers, location data, online identifiers, or factors specific to physical, physiological, genetic, mental, economic, cultural, or social identity under GDPR Article 4(1).
A natural or legal person, public authority, agency, or body which processes personal data on behalf of and under the documented instructions of a controller, bound by written contracts specifying processing scope, security requirements, sub-processor authorisation, and assistance obligations.
Any form of automated processing of personal data used to evaluate, analyse, or predict aspects concerning an individual's performance, economic situation, health, personal preferences, interests, reliability, behaviour, location, or movements under GDPR Article 4(4).
Processing personal data in such a manner that it can no longer be attributed to a specific data subject without use of additional information kept separately under technical and organisational measures, reducing but not eliminating data protection obligations under GDPR Article 4(5).
The mandatory written documentation required under GDPR Article 30 describing all processing operations an organisation conducts, including purposes, legal basis, data categories, recipients, international transfers, retention periods, and security measures. Must be available to the AEPD upon request.
The right of data subjects under GDPR Article 16 to obtain correction of inaccurate personal data and completion of incomplete data without undue delay, with controllers obliged to communicate rectifications to all recipients unless impossible or requiring disproportionate effort.
The right under GDPR Article 18 to require controllers to mark stored personal data and limit its processing to storage only (except with data subject consent, for legal claims, or protecting another person's rights), applicable when accuracy is contested, processing is unlawful but deletion is opposed, or data is needed for legal claims.
Administrative fines imposed by the AEPD for GDPR/LOPDGDD violations, classified under Spanish law as minor infractions (up to €40,000), serious infractions (€40,001 to €300,000), or very serious infractions (up to €20 million or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher).
Technical and organisational safeguards required under GDPR Article 32 to ensure appropriate security of personal data, including confidentiality, integrity, availability, and resilience of processing systems through measures such as encryption, pseudonymisation, access controls, backup systems, and incident response procedures.
See Special Categories of Personal Data
Personal data under GDPR Article 9 revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for unique identification purposes, health data, or data concerning sex life or sexual orientation. Processing is generally prohibited without explicit consent or specific legal grounds.
An independent public authority established by an EU Member State responsible for monitoring GDPR application under Articles 51-59. In Spain, the primary authority is the AEPD, with regional supervisory authorities in Catalonia (Autoritat Catalana de Protecció de Dades), the Basque Country, and Andalusia holding competence for regional public sector processing.
A natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons who under the direct authority of the controller or processor are authorised to process personal data under GDPR Article 4(10).
The fundamental GDPR Article 5(1)(a) requirement that all information and communications relating to personal data processing be concise, easily accessible, clear, and written in plain language understandable to the intended audience, particularly when information is addressed to children.
The monitoring of spaces using camera systems, heavily regulated in Spain under LOPDGDD with strict requirements including mandatory yellow informative signage visible before entering monitored areas, prohibition on recording audio or filming public streets (unless authorised security forces), and significant limitations on workplace monitoring including prohibitions in break rooms and toilets.
A non-financial sanction available to the AEPD under LOPDGDD as an alternative to administrative fines for first-time, minor infringements particularly by public bodies, small organisations, or natural persons, imposing corrective obligations and future compliance requirements without immediate monetary penalty.
Internal reporting systems required under Spanish Law 2/2023 for companies with 50 or more employees, allowing anonymous reporting of irregularities, fraud, or legal violations whilst ensuring robust data protection for both whistleblowers and reported parties under strict AEPD oversight and specific retention limitations.
Spain operates under a dual regulatory framework combining the directly applicable EU GDPR with national specifications in the LOPDGDD. This creates compliance obligations that go significantly beyond baseline GDPR requirements familiar to UK and international businesses.
Key Spain-specific terminology to master includes:
For English-speaking businesses operating in Spain, understanding these terms isn't just academic—it's essential for avoiding substantial fines and ensuring genuine compliance with one of Europe's strictest data protection regimes.
This glossary provides foundational terminology, but navigating Spain's sophisticated dual GDPR/LOPDGDD framework requires specialised expertise. ANRO Privacy focuses exclusively on Spanish data protection compliance for English-speaking businesses and expats.
Disclaimer: This glossary is provided for informational and educational purposes only and does not constitute legal advice. It does not create a professional relationship between ANRO Privacy and the reader. For specific compliance guidance tailored to your business circumstances, consult a qualified Data Protection Officer or legal professional with expertise in Spanish data protection law.
© 2025 ANRO Privacy. All rights reserved.
TLDR: The LOPDGDD is Spain's data protection law that works alongside GDPR but adds stricter Spanish-specific requirements. It mandates Data Protection Officers for certain sectors, establishes unique "data blocking" obligations, and grants digital workplace rights. The Spanish Data Protection Agency (AEPD) actively enforces these rules with fines up to €20 million.
Operating in Spain means complying with both GDPR and the LOPDGDD, Spain's data protection law that adds requirements beyond baseline European rules.
The LOPDGDD (Ley Orgánica de Protección de Datos Personales y garantía de los derechos digitales) is Spain's Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights. It came into effect on 7 December 2018, shortly after GDPR's implementation.
Think of it as Spain's personalised version of GDPR. Whilst GDPR provides the baseline rules for all EU member states, the LOPDGDD fills in the gaps and adds Spanish-specific requirements. This creates a dual compliance framework: businesses in Spain must follow both GDPR and LOPDGDD.
The law does more than regulate data processing. It establishes a comprehensive "Digital Bill of Rights" for Spanish citizens, covering everything from the right to disconnect from work emails to how digital assets are handled after death. For businesses, this means your compliance obligations extend beyond traditional data security into areas like employee rights and digital legacy planning.
GDPR compliance alone isn't sufficient in Spain. The LOPDGDD introduces specific requirements that catch unprepared businesses by surprise:
Stricter Age Requirements: Spain sets the consent threshold at 14 years (not 16 as in many EU countries). Businesses collecting data from young people need age verification systems meeting Spain's lower threshold.
Mandatory Data Protection Officers: Specific sectors must appoint a DPO regardless of company size, including small language academies, private security firms, and local health clinics.
Data Blocking Obligations: Spanish law requires a "data blocking" phase before permanent deletion. Your IT systems must support this functionality.
The AEPD actively enforces these rules with substantial fines: €10 million against AENA for biometric processing violations, €8.15 million against Vodafone for security failures.
Article 34 of the LOPDGDD lists 16 sectors that must appoint a DPO regardless of company size. This includes:
If your business falls into any of these categories, appointing a DPO isn't optional, it's mandatory. The DPO must be registered with the AEPD and acts as an independent advisor and contact point for data protection matters.
The LOPDGDD's Title X establishes groundbreaking workplace rights. Your employees have the right to "digital disconnection", meaning they can refuse to respond to work communications outside working hours. Your business needs written policies addressing:
Video surveillance in the workplace has strict limitations. Cameras cannot record audio, cover break rooms, toilets or changing areas, or monitor areas beyond what's strictly necessary for security. The AEPD has repeatedly fined companies for excessive workplace surveillance.
If your business reports debts to credit reference agencies, the LOPDGDD sets specific thresholds. Debts under €50 cannot be reported to solvency files, and customers must be notified before their information is included. Data can only be retained whilst the debt remains unpaid, with a maximum period of five years from when the debt became due.
Spanish data subjects have enhanced rights compared to baseline GDPR:
Access and Portability: Request all personal data a company holds about you in a readable, transferable format.
Right to Erasure (with Blocking): Companies must first "block" your data, making it inaccessible whilst retaining it for legal obligations, befor permanent deletion.
Data Concerning Deceased Persons: Family members and heirs can request access to, correction of, or deletion of a deceased person's data (unless explicitly prohibited by the deceased).
Digital Disconnection: Employees can refuse to respond to work communications outside working hours.
Data Breach Notification: Companies must notify you directly if a breach poses high risk to your information.
The AEPD provides resources specifically for SMEs. Here's how to ensure compliance:
Document Your Processing Activities: Create a Record of Processing Activities (RAT) documenting what personal data you collect, why you need it, how you store it, and who has access.
Implement Appropriate Security: Use encryption for devices storing personal data, strong passwords with two-factor authentication, regular software updates, and staff training on data protection.
Review Your Legal Basis: Every piece of data must have a valid legal basis (consent, contractual necessity, or legitimate interest). Marketing requires explicit consent, pre-ticked boxes don't comply.
Create Clear Privacy Policies: Use a "layered approach" with a short summary followed by detailed information explaining what data you collect, why, retention periods, and how individuals exercise their rights.
Handle Requests Properly: Respond to data subject requests within one month, following Spain's unique requirements like data blocking.
Check DPO Requirements: Review Article 34's mandatory sectors list. If your business falls into any category, appointing a DPO is mandatory.
Prepare for Breaches: Notify the AEPD within 72 hours of breaches posing risk to individuals using the AEPD's "Comunica-Brecha RGPD" tool.
The LOPDGDD classifies violations into three tiers with corresponding penalties:
Minor Infractions: Fines up to €40,000 for issues like incomplete transparency notices or failure to register your DPO with the AEPD.
Serious Infractions: Fines from €40,001 to €300,000 for violations including inadequate security measures, processing children's data without proper consent, or failing to appoint a mandatory DPO.
Very Serious Infractions: Fines up to €20 million or 4% of global annual turnover (whichever is higher) for fundamental violations like processing without legal basis, unauthorised international data transfers, or violating data subjects' rights.
Recent enforcement actions demonstrate the AEPD's willingness to impose substantial penalties:
Small businesses aren't immune. The AEPD regularly fines SMEs thousands of euros for violations like improper video surveillance or inadequate cookie consent mechanisms.
Does LOPDGDD replace GDPR? No. LOPDGDD works alongside GDPR. You must comply with both regulations, GDPR as the European baseline and LOPDGDD as Spain's additional requirements.
I'm a sole trader with no employees. Do these rules apply? Yes. If you process personal data as part of your business, customer emails, client information, marketing lists, LOPDGDD applies regardless of size. The AEPD's Facilita RGPD tool provides free compliance guidance for small businesses.
What if my UK business serves Spanish customers? If you offer goods or services to people in Spain or monitor their behaviour, both GDPR and LOPDGDD apply regardless of your physical location.
Can I use pre-ticked consent boxes? No. Consent must be a clear, affirmative action. Pre-ticked boxes, assumed consent, or consent by silence don't meet Spanish requirements.
The LOPDGDD creates an active enforcement framework that shapes how businesses operate in Spain. Understanding Spain's requirements beyond baseline GDPR compliance protects your business from financial penalties and reputational damage.
Compliance with LOPDGDD should be a priority for any business in Spain handling personal data. The combination of mandatory DPOs for specific sectors, unique data blocking requirements, and the AEPD's enforcement stance creates a compliance environment demanding attention.
Don't wait for an AEPD investigation to address your obligations. Resources exist to help small businesses comply and take the first step toward ensuring your Spanish operations meet both GDPR and LOPDGDD requirements.
Disclaimer: This article provides general information about Spanish data protection law and should not be construed as legal advice. It does not create a professional relationship between the reader and ANRO Privacy. For specific compliance questions affecting your business, consult a qualified Data Protection Officer or legal professional specialising in Spanish data protection law.
TLDR: What is GDPR in simple terms? GDPR is EU law that treats personal data as "loaned" to businesses, not owned by them.
In Spain, businesses must comply with both GDPR and LOPDGDD, which is a stricter Spanish law that adds requirements like mandatory data blocking, lower age of consent (14), and compulsory Data Protection Officer (DPO) appointments for specific sectors.
Key principle: Organisations must prove they're protecting data properly, or they're holding it unlawfully.
What is GDPR in simple terms? This question matters more than ever for businesses operating in Spain, particularly English-speaking expat companies and British firms navigating the Spanish market. The answer isn't as straightforward as you might hope, because understanding GDPR in Spain means understanding two interconnected legal frameworks: the European Union's General Data Protection Regulation and Spain's own Ley Orgánica de Protección de Datos Personales y garantía de los derechos digitales (LOPDGDD).
If your business collects email addresses for newsletters, processes customer payments, tracks website visitors with cookies, or maintains employee records in Spain, you're subject to what is arguably Europe's strictest data protection regime. Unlike the UK or other EU countries that implemented GDPR with minimal additions, Spain went significantly further. The Spanish legislator didn't just transpose European requirements, it enhanced them, creating obligations that go beyond what the standard GDPR demands.
This isn't bureaucratic overreach. Data protection in Spain is anchored in Article 18.4 of the Spanish Constitution, which guarantees citizens' right to privacy against the misuse of technology. What began as a constitutional principle evolved into one of Europe's most rigorous enforcement environments, overseen by the notoriously active Agencia Española de Protección de Datos (AEPD).
In this article, you'll learn what GDPR means in practical terms, how Spain's LOPDGDD creates additional obligations, and what specific actions your business must take to operate lawfully in Spain.
At its heart, what is GDPR in simple terms? The General Data Protection Regulation operates on a principle of "loaned custody." This is the clearest way to understand the fundamental shift GDPR created: organisations do not own the personal data they hold about individuals, they are merely borrowing it.
Before GDPR, the European data protection landscape was fragmented. Each country had its own rules, and businesses largely operated on a "registration" model: tell the government you're keeping files, pay a fee, and carry on. GDPR replaced this with a unified European standard and, critically, shifted to an "accountability" model. Now, businesses don't just notify authorities, they must proactively prove they're managing data risks appropriately.
To lawfully borrow someone's personal data, organisations must meet four strict conditions:
If your organisation cannot prove it is meeting these four conditions for every piece of personal data it processes, you're not just non-compliant, you're holding that data unlawfully. This accountability burden is the defining characteristic of modern data protection law.
While GDPR provides a unified European baseline, the regulation contains "opening clauses" that allow Member States to specify certain aspects. Spain exercised this prerogative comprehensively through the LOPDGDD, which came into force alongside GDPR in May 2018.
The LOPDGDD accomplishes three critical objectives:
Adaptation: It harmonises Spanish law with GDPR, formally repealing the previous data protection law (LOPD 15/1999) that had governed since 1999.
Clarification: It resolves ambiguities in GDPR by setting specific national standards where the European regulation allowed flexibility.
Innovation: It introduces Title X, a pioneering "Bill of Digital Rights" that addresses labor relations, digital inheritance, and social issues in the internet era, topics the GDPR doesn't explicitly cover.
For businesses operating in Spain, several key divergences from standard GDPR implementation create unique obligations:
| Requirement | Standard EU GDPR | Spanish LOPDGDD | Impact on Your Business |
|---|---|---|---|
| Age of Digital Consent | 16 years (Member States can lower to 13) |
14 years | If your website or service targets teenagers, you need parental consent for users under 14, not under 16. Age verification systems must be calibrated accordingly. |
| Deceased Persons' Data | Generally does not apply to the deceased | Heirs have rights to access, rectify, and delete | Family members can request access to a deceased person's data unless the deceased explicitly prohibited it. Estate planning and data handling protocols must account for this. |
| Data Deletion | "Right to erasure" (delete the data) | "Bloqueo" (blocking) required first | You cannot immediately destroy data when deletion is requested. Data must first be placed in a restricted, archived state for 4-5 years to satisfy legal liability periods, then physically destroyed. |
| DPO Appointment | Required based on core activities and scale of processing | Mandatory for 16 specific sectors regardless of size | Schools, language academies, security firms, health services, and 12 other sectors must appoint a Data Protection Officer even if they're small operations. This catches many expat businesses by surprise. |
| Credit Reporting | General legitimate interest framework | €50 minimum debt threshold | You cannot include someone in credit default databases (like ASNEF) if the principal debt is less than €50. Strict notification requirements also apply. This prevents "blacklisting" for trivial amounts. |
| Digital Rights at Work | Not explicitly covered | Right to Digital Disconnection, device usage policies | Employers must negotiate protocols ensuring employees can disconnect from work communications outside working hours. Video surveillance cannot record audio or cover break rooms. |
To answer "what is GDPR in simple terms," you must understand the seven principles that underpin every lawful data processing activity. These aren't suggestions or best practices, they're legal requirements. Violating a principle is classified as a "Very Serious Infringement" under the LOPDGDD, carrying fines up to €20 million or 4% of global annual turnover, whichever is higher.
Every data processing activity must have a valid legal basis. The GDPR provides six lawful bases, but for most businesses, two dominate: consent and legitimate interest.
Consent in the GDPR era means affirmative action. The days of pre-ticked boxes or implied consent from silence are over. Consent must be:
Spain's enforcement history shows the AEPD scrutinises consent mechanisms closely. Businesses have been fined for using confusing double negatives in consent forms or bundling non-essential data processing with service access.
Transparency requires privacy policies written in plain, accessible language. In Spain, the preferred format is "layered" information:
This layered approach ensures people can quickly grasp the essentials without wading through pages of legalese.
Data collected for one purpose cannot be repurposed for another incompatible purpose without new legal basis (usually fresh consent).
This principle causes frequent violations. A common scenario: A Spanish language academy collects email addresses to send course enrollment confirmations (administrative purpose). Later, the academy starts sending promotional emails about new courses (marketing purpose). Without obtaining separate marketing consent, this constitutes unlawful repurposing.
The AEPD has consistently ruled that administrative and marketing purposes are distinct. Your initial legitimate interest or consent for one does not extend to the other.
You must only collect data that is strictly necessary for your stated purpose. This principle forces businesses to justify every data field they request.
Ask yourself: Does your contact form truly need the person's date of birth? Their postal address if you only communicate via email? Their gender for a newsletter subscription? If you cannot articulate a genuine, specific need for a data point, you shouldn't collect it.
The AEPD has issued significant fines for data minimisation violations, including a notable €10 million penalty to AENA (the Spanish airport operator) for excessive data collection from employees.
You must keep personal data accurate and up to date. When someone informs you of an error, you have an obligation to correct it promptly.
This ties to the Right to Rectification, one of the fundamental data subject rights. If a customer tells you their email address has changed, you cannot continue using (and potentially sharing with processors) the outdated address.
Data cannot be kept longer than necessary for the purpose it was collected. "Just in case we need it later" is not a valid retention justification.
Spain's unique requirement here is "bloqueo" (blocking). Unlike standard GDPR erasure, Spanish law requires a two-stage deletion process:
This means your systems need three data states: active, blocked, and destroyed. A simple "delete" button is insufficient for Spanish compliance.
You must implement appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, or damage.
"Appropriate" is risk-based. Processing health data or financial information requires stronger measures than processing newsletter subscriptions. At a minimum, Spanish businesses should implement:
Spain's LOPDGDD Article 5 extends the confidentiality obligation explicitly, noting that it persists even after someone's employment or contractual relationship ends. Former employees cannot disclose information they accessed during their work.
This is GDPR's most demanding principle. You must be able to prove compliance with all the other principles. Documentation is everything.
Accountability requires:
The burden of proof sits entirely with the organisation. If the AEPD investigates, "we thought we were compliant" means nothing without documentation to back it up.
Understanding what GDPR is in simple terms also means knowing what rights it grants to individuals. In Spain, these are often referred to as the ARCO-POL rights, an acronym covering the six fundamental rights:
Access: You can request to see what personal data an organisation holds about you, how it's being used, where it came from, and who it's been shared with. Organisations must respond within one month (extendable by two more months if the request is complex) and cannot charge a fee unless the request is manifestly unfounded or excessive.
Important Spanish clarification: The right of access applies to the personal data being processed, not necessarily to full copies of documents containing that data. Organisations can provide the data in summarised form, though providing document copies is often the most practical approach.
Rectification: You can require organisations to correct inaccurate personal data. If you've moved house, changed your name, or find errors in your records, organisations must update their systems when you notify them.
Cancellation/Erasure: Often called the "right to be forgotten," this allows you to request deletion of your personal data when it's no longer necessary for the purpose it was collected, when you withdraw consent, or when it was processed unlawfully.
In Spain, remember the blocking requirement: Organisations cannot immediately destroy your data. They must first place it in restricted storage for the applicable limitation period before physical destruction.
Objection: You can object to processing based on legitimate interest or for direct marketing purposes. When you object to marketing, organisations must stop immediately. Objections to legitimate interest processing require the organisation to demonstrate compelling grounds that override your interests. Find out about the Robinson list in and how to stop spam marketing in Spain.
Portability: You can request your personal data in a structured, commonly used, machine-readable format and transmit it to another organisation. This right only applies to data you provided directly and that is processed by automated means based on consent or contract.
Limitation: You can request that organisations restrict processing of your data in specific circumstances, for example, while they verify the accuracy of data you've challenged, or while determining whether legitimate grounds override your objection.
All these rights must be exercisable free of charge. Organisations cannot charge you for accessing your data or correcting errors (unless requests are clearly unreasonable or repetitive).
For English-speaking businesses operating in Spain, GDPR and LOPDGDD compliance requires specific, concrete actions. Here's what you must do:
Every website tracking visitors must obtain consent before placing non-essential cookies. Spain requires:
The AEPD has been particularly strict about cookie compliance, issuing fines to organisations that use "cookie walls" (blocking access unless visitors accept all cookies) or that place cookies before consent is obtained.
Your privacy policy must use the layered approach:
First layer (immediately visible): A concise table or statement covering:
Second layer (linked): The full legal policy with comprehensive details about legal bases, international transfers, security measures, and detailed rights information.
Spanish-specific disclosures should include:
You must have a system to handle requests for access, rectification, erasure, and other rights. This system should:
Many businesses establish a dedicated email address (e.g., dataprotection@yourcompany.es) and assign responsibility to a specific person or the DPO.
Spain's Article 34 of the LOPDGDD requires mandatory DPO appointments for 16 specific sectors, regardless of organisation size:
If your business falls into any of these categories, you must appoint a DPO. This catches many expat-run language schools and tutoring services by surprise, in Spain, educational services require a DPO regardless of size.
The DPO can be an employee or an external service provider, but must have expert knowledge of data protection law and cannot have conflicts of interest (e.g., the DPO cannot also be the CEO).
If your business reports unpaid debts to credit reference agencies or maintains customer solvency records, Spain's strict rules apply:
Spanish businesses must implement:
Digital disconnection protocols: Formal policies, ideally negotiated with employee representatives, establishing employees' right to disconnect from work communications outside working hours. This isn't merely a suggestion, it's a legally mandated right in Spain.
Video surveillance limitations: Workplace cameras cannot:
Device usage policies: Clear rules about personal use of company devices and company access to employee devices used for work purposes.
Assuming UK GDPR compliance equals Spanish compliance: The UK's post-Brexit GDPR implementation (UK GDPR) differs from LOPDGDD. Spain's stricter requirements around blocking, DPO appointments, and credit reporting won't be reflected in UK compliance frameworks.
Ignoring the age 14 threshold: UK businesses accustomed to the age 13 threshold may inadvertently process data from 13-year-olds without parental consent, which is unlawful in Spain.
Not implementing blocking systems: Simply deleting data when requested violates Spanish law. Your systems need the capability to archive data in a restricted state.
Missing mandatory DPO requirements: The biggest shock for small UK businesses is discovering their language school or tutoring service legally requires a DPO in Spain when no such requirement existed in the UK.
Repurposing Brexit-era international transfer mechanisms: Data transfers between Spain and the UK now require adequacy decisions or Standard Contractual Clauses, adding complexity not present when the UK was in the EU.
The AEPD is not a passive regulator. Spain's data protection authority issues thousands of sanctions annually and maintains one of Europe's highest enforcement rates.
Read our article and find out exactly what the AEPD is and what they do.
Fines operate on a tiered system:
Recent enforcement actions demonstrate the AEPD's willingness to act against all organisation sizes:
However, the AEPD also recognises the Spanish economy is dominated by SMEs and freelancers. The agency provides extensive free resources, including:
The message is clear: the law applies to everyone, but support is available for those making genuine efforts to comply.
So, what is GDPR in simple terms for a business operating in Spain? It's a fundamental reframing of the relationship between organisations and personal data. Data doesn't belong to the businesses that collect it, it belongs to individuals, and organisations are merely temporary custodians operating under strict conditions.
In Spain, those conditions extend beyond the baseline European requirements. The LOPDGDD creates a dual compliance environment where businesses must satisfy both GDPR's accountability model and Spain's additional specifications: lower age thresholds, mandatory data blocking, sector-specific DPO requirements, strict credit reporting rules, and pioneering digital workplace rights.
The practical implications are significant but manageable. Start with the basics:
For English-speaking businesses, particularly those expanding from the UK, don't assume your existing GDPR compliance translates directly to Spain. The LOPDGDD creates obligations that go beyond what you may have implemented under UK GDPR.
Data protection in Spain is not a one-time compliance exercise, it's an ongoing operational requirement. The AEPD's aggressive enforcement and Spain's constitutional protection of privacy mean that cutting corners carries real legal and financial risks. But for businesses willing to take the requirements seriously, compliance is achievable, and the free resources available from the AEPD provide substantial support.
The data privacy landscape has fundamentally shifted. In Spain more than perhaps anywhere else in Europe, that shift is enforced with rigor. Understanding what GDPR means in simple terms, and how the LOPDGDD builds upon it, is no longer optional for any business processing personal data in Spain.
Disclaimer: This article provides general informational guidance on GDPR and LOPDGDD requirements and should not be considered legal advice. Data protection compliance is complex and fact-specific. The information presented does not create a professional relationship between ANRO Privacy and readers. For specific compliance questions related to your business circumstances, consult a qualified Data Protection Officer or legal professional specialising in Spanish data protection law.