{
 "jurisdiction_id": "ES",
 "jurisdiction": "Spain",
 "url": "https://dataprotection.gi/jurisdictions/spain/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 45,
  "sub_modules": 57,
  "source_register": 35
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/spain/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Mature, fully operative omnibus regime with an active, well-resourced supervisory authority and clear statutory instruments.",
   "claims": [
    {
     "statement": "The Agencia Española de Protección de Datos (AEPD) is Spain's national data protection supervisory authority under GDPR and LOPDGDD.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/en/about-aepd/welcome-aepd",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Spain's data protection regime rests on GDPR (Regulation (EU) 2016/679) applied directly, LOPDGDD, LO 7/2021, RD 389/2021 (AEPD Statute) and Ley 34/2002 (LSSI) for e-commerce/electronic communications.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/en/our-work-and-tools/regulation",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR/LOPDGDD apply to the processing of personal data relating to identified or identifiable natural persons; data concerning legal persons is not covered.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/preguntas-frecuentes/2-tus-obligaciones-como-responsable-del-tratamiento/2-aplicacion-de-la-normativa",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Non-EU-established controllers/processors offering goods or services to, or monitoring the behaviour of, EU data subjects fall within GDPR's territorial scope and must appoint an EU representative as contact point for supervisory authorities and data subjects.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/preguntas-frecuentes/2-tus-obligaciones-como-responsable-del-tratamiento/2-aplicacion-de-la-normativa/FAQ-0202-a-quien-se-aplica-el-RGPD",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Since 25 May 2018, the obligation to register/notify processing files with AEPD has disappeared, both for public and private controllers, replaced by the internal Registro de Actividades de Tratamiento (ROPA).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/preguntas-frecuentes/2-tus-obligaciones-como-responsable-del-tratamiento/2-aplicacion-de-la-normativa/FAQ-0205-sobre-la-obligatoriedad-de-la-inscripcion-de-ficheros",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Controllers/processors that designate a DPO (mandatorily or voluntarily) must communicate the appointment, and any subsequent removal, to AEPD within 10 days.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/en/rights-and-duties/fulfill-your-duties/measures-compliance/data-protection-officer",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/spain/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Lawful basis and special-category framework is GDPR-aligned with clear, AEPD-published interpretive guidance; consent threshold for minors is well-documented.",
   "claims": [
    {
     "statement": "LOPDGDD presumes, absent proof to the contrary, a legitimate interest under GDPR Art 6.1(f) for processing professional contact data and role/position data of individuals working for a legal entity.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/preguntas-frecuentes/2-tus-obligaciones-como-responsable-del-tratamiento/2-aplicacion-de-la-normativa",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Processing of a minor's personal data may only be based on the minor's own consent from age fourteen upward; below fourteen, consent must be given by parents or guardians.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/preguntas-frecuentes/10-menores-y-educacion/FAQ-1001-cual-es-la-edad-para-que-los-menores-puedan-prestar-consentimiento-para-tratar-sus-datos-personales",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The use of facial recognition in video-surveillance implies processing of biometric data classified as a special category under GDPR Art 9, in principle prohibited absent an applicable exception under Spanish law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/prensa-y-comunicacion/notas-de-prensa/AEPD-informe-sistemas-reconocimiento-facial-empresas-seguridad-privada",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AEPD guidance holds that consent cannot lift the Art 9 prohibition for biometric presence/access-control systems in employment contexts due to the power imbalance between employer and employee, and that reliance on the 'essential public interest' exception requires a statute of appropriate legal rank that does not currently authorise biometric time-control.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/guias/guia-control-presencia-biometrico.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/spain/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Full GDPR rights catalogue in force; AEPD publishes accessible guidance confirming scope, including minors' rights from age 14.",
   "claims": [
    {
     "statement": "GDPR grants data subjects the rights of access, rectification, erasure, objection, portability, restriction of processing, and the right to object to automated decision-making including profiling; AEPD confirms these are exercisable by minors from age fourteen.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/preguntas-frecuentes/10-menores-y-educacion",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/spain/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Comprehensive, actively-enforced accountability framework; breach and DPO statistics confirm real operative traction.",
   "claims": [
    {
     "statement": "AEPD's recommended RGPD-adaptation roadmap treats risk analysis and DPIA (EIPD) execution as core accountability tasks alongside ROPA construction and breach-notification mechanisms.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/documento/1-manuel-villaseca.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A DPO must be appointed where processing is carried out by a public authority, where core activities require regular and systematic large-scale monitoring of data subjects, or where core activities involve large-scale processing of special-category or criminal-conviction data; LOPDGDD Art 34 extends mandatory designation to further categories of entity.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/en/rights-and-duties/fulfill-your-duties/measures-compliance/data-protection-officer",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "By the close of 2025, 126,176 DPOs were registered with AEPD (116,007 private sector, 10,169 public sector), up from 119,803 in 2024.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/prensa-y-comunicacion/notas-de-prensa/la-agencia-recibio-mas-de-30.000-reclamaciones-en-2025-un-64-mas",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Registro de Actividades de Tratamiento (ROPA) required by Art 30 GDPR is an internal document that must be made available to AEPD on request but does not need to be filed with or published to the Agency.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/preguntas-frecuentes/2-tus-obligaciones-como-responsable-del-tratamiento/7-registro-de-actividades-de-tratamiento/FAQ-0220-que-es-el-registro-de-actividades-de-tratamiento",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AEPD confirmed a €500,000 fine (reduced to €400,000 on voluntary payment) against CaixaBank in March 2026 for repeated data breaches between 2022-2024 stemming from systemic design and organisational deficiencies rather than isolated human errors.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/spain-aepd-fines-caixabank-eur500000-data-protection",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Controllers must notify AEPD of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, per Art 33 GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/sites/default/files/2019-09/wp250rev01-es.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AEPD's 2025 annual report recorded a 157% rise in breach-related sanctioning/reprimand procedures (30 in 2024 to 77 in 2025), yielding fines totalling approximately €19.8 million.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/prensa-y-comunicacion/notas-de-prensa/la-agencia-recibio-mas-de-30.000-reclamaciones-en-2025-un-64-mas",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "green",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/spain/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Fully harmonised EU transfer regime in force with active AEPD guidance on mechanisms; TIA obligation confirmed via CJEU Schrems II jurisprudence.",
   "claims": [
    {
     "statement": "AEPD guidance confirms that, absent an adequacy decision, transfers outside the EEA may rely on Commission-adopted SCCs, controller-adopted SCCs approved by AEPD/the Commission, codes of conduct or certification mechanisms with binding commitments, or derogations for specific situations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/en/rights-and-duties/fulfill-your-duties/measures-compliance/international-data-flows",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "European Commission adequacy decisions currently cover a defined set of third countries and the EU-US Data Privacy Framework (adopted 10 July 2023), permitting transfers from Spain without additional safeguards within their scope.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj/eng/pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Commission Implementing Decision (EU) 2021/914 SCCs are considered to provide appropriate safeguards under GDPR Art 46(1)/(2)(c) for transfers from an EU data exporter to a non-EU importer; legacy pre-2001/2010-clause contracts ceased to be valid after 27 December 2022.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32021D0914",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Following Schrems II, SCC-reliant exporters must carry out a transfer impact assessment documenting destination-country law/practice and any supplementary measures needed to protect transferred data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/sme/be-compliant/international-data-transfers_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/spain/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "No separate sectoral statutes displace GDPR, but overlays exist and healthcare/financial sanctioning activity rose sharply in 2025, indicating active but uneven sectoral risk.",
   "claims": [
    {
     "statement": "AEPD fined Gesternova, S.A. €220,000 in January 2026 for processing personal data without a valid legal basis and failing to provide mandatory transparency information at collection.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/spain-aepd-fines-gesternova-eu220000-unlawful-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AEPD has endorsed designating a single DPD for health-data processing bodies (e.g. within a defence-sector health inspectorate) given the special-category nature of health data and the scale of processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/documento/2019-0100.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AEPD's 2025 annual figures show sanitary-sector sanctioning/reprimand procedures rose 278% year-on-year to 34 cases, among the six most active enforcement areas.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/prensa-y-comunicacion/notas-de-prensa/la-agencia-recibio-mas-de-30.000-reclamaciones-en-2025-un-64-mas",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Ley 34/2002 (LSSI) complements GDPR safeguards for information-society services in Spain, including the cookie/tracker consent regime under LSSI Art 22.2.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/guias/orientaciones-analitica-web-aapp.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Educational institutions are obliged to designate a DPD in the cases covered by GDPR Art 37 and, in all cases, when they offer teaching at any level established under regulating legislation; online classes/exams delivered as part of regulated education do not require separate student/parental consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/preguntas-frecuentes/10-menores-y-educacion",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Spanish insurance sector operates under a voluntary Art 40 GDPR code of conduct (UNESPA CC-0012-2019), supervised by an OCCC, requiring adherent insurers to disclose their DPO identity and maintain ROPA compliance.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "AEPD / UNESPA",
     "source_url": "https://www.aepd.es/documento/codigo-conducta-unespa-cc-0012-2019.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/spain/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Cookie/dark-pattern regime is mature and AEPD-enforced; other sub-modules (opt-out signals, clean rooms, cross-context advertising) lack a direct EU/ES analogue and were not evidenced in this pass.",
   "claims": [
    {
     "statement": "For non-exempt cookies, valid consent must be obtained from the user, freely and informedly given, with the options to accept and reject cookies offered simultaneously, at the same level and with equal visibility.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/preguntas-frecuentes/17-internet-y-redes-sociales/FAQ-1707-importancia-de-las-cookies-en-la-proteccion-de-datos",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AEPD updated its cookie guide in July 2023 to align with EDPB Guidelines 03/2022 on deceptive patterns, incorporating the criterion that accept/reject actions be presented in a prominent location and format at the same level, with rejection no more complicated than acceptance.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/prensa-y-comunicacion/notas-de-prensa/aepd-actualiza-guia-cookies-para-adaptarla-a-nuevas-directrices-cepd",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Ley 34/2002 (LSSI) complements GDPR guarantees applicable to information-society services, including electronic direct-marketing communications.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/guias/orientaciones-analitica-web-aapp.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/spain/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "AI governance is institutionally advanced (AESIA operative, 16 guidelines published) but the core Organic Law implementing AI Act governance domestically remains in draft/proposed stage as of mid-2026.",
   "claims": [
    {
     "statement": "AEPD guidance on GDPR-compliant AI processing ties automated processing to the information/transparency principle, requiring affected data subjects to be made aware of how their data is used within AI-embedding treatments.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/sites/default/files/2020-02/adecuacion-rgpd-ia.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Spain became the first EU Member State to establish a dedicated national AI supervisory authority, AESIA, which has published 16 interpretive AI guidelines developed within its AI regulatory sandbox to help translate EU AI Act principles into practical compliance steps.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/aesia-s-ai-guidelines-spain-steps-into-the-ai-spotlight",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 26 May 2026, Spain's Council of Ministers approved a draft Organic Law on the proper use and governance of AI, designating notifying and market-surveillance authorities with AESIA as single point of contact, and sent it to Congress for parliamentary processing.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/spain-council-ministers-approves-draft-organic-law-ai",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AEPD's 2020 legal report concluded that facial-recognition technology in private-security video-surveillance is, in principle, prohibited under GDPR as special-category biometric processing, and that the legitimation applicable to plain image/sound-capturing video-surveillance cannot be extended to facial, gait, or voice recognition.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/prensa-y-comunicacion/notas-de-prensa/AEPD-informe-sistemas-reconocimiento-facial-empresas-seguridad-privada",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Ley Orgánica 7/2021 provides a distinct data-protection regime for personal data processed for the prevention, detection, investigation and prosecution of criminal offences and execution of criminal penalties, operating alongside the general GDPR/LOPDGDD regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/en/our-work-and-tools/regulation",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/spain/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Consent-age and parental-consent framework is clear and GDPR-aligned; minor-specific profiling bans and dependent-adult protections beyond general GDPR safeguards were not evidenced in this pass.",
   "claims": [
    {
     "statement": "AEPD's technical note on a safe internet by default states that age verification, per se, is not sufficient and must be designed and implemented consistently with all GDPR principles while avoiding new risks such as enabling minors' location to be tracked.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/guides/technical-note-safe-internet-by-default-for-children.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "LOPDGDD Art 7 provides that processing of a minor's data may be based on the minor's own consent from age fourteen; below that age, parental or guardian consent is required, and consent must in all cases be express.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/preguntas-frecuentes/10-menores-y-educacion",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/spain/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement activity is vigorous and well-documented, but AEPD's own reporting flags a capacity/resourcing strain relative to caseload growth.",
   "claims": [
    {
     "statement": "AEPD sanctioning procedures are governed by GDPR (Regulation (EU) 2016/679), LOPDGDD, its implementing regulatory provisions and, subsidiarily, general Spanish administrative procedure rules.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/documento/ps-00253-2023.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AEPD resolutions ending the administrative pathway may be challenged via a discretionary recurso de reposición before the AEPD Presidency/Director, or directly via recurso contencioso-administrativo before the Audiencia Nacional's Contentious-Administrative Chamber.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/documento/pa-00023-2025.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In 2025, AEPD received 30,931 complaints, the highest number in the Agency's history, a 64% increase over the prior year.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/prensa-y-comunicacion/notas-de-prensa/la-agencia-recibio-mas-de-30.000-reclamaciones-en-2025-un-64-mas",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AEPD led 47 cross-border cases as lead authority in 2025 (+114% vs 2024) and cooperated as concerned authority in 419 cases (+20%); of 38 Audiencia Nacional judgments on AEPD-resolution appeals in 2025, 76% were dismissed or rejected, i.e. upheld the Agency's decisions.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/prensa-y-comunicacion/notas-de-prensa/la-agencia-recibio-mas-de-30.000-reclamaciones-en-2025-un-64-mas",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AEPD's 2025 annual report states that the growing workload reflected across most of its subdirectorates and divisions has not been matched by a proportional increase in staffing, prompting a technology-supported, impact-prioritised supervision strategy under its 2025-2030 Strategic Plan.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/prensa-y-comunicacion/notas-de-prensa/la-agencia-recibio-mas-de-30.000-reclamaciones-en-2025-un-64-mas",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Any interested party may lodge a recurso contencioso-administrativo against a final AEPD resolution before the Audiencia Nacional's Contentious-Administrative Chamber within two months of notification.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/documento/pa-00023-2025.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "AEPD presented its Memoria de actuación 2025 on 6 May 2026, disclosing record complaint volumes, a 157% rise in breach-related sanctioning/reprimand procedures, and approximately €19.8 million in resulting fines.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Agencia Española de Protección de Datos",
     "source_url": "https://www.aepd.es/prensa-y-comunicacion/notas-de-prensa/la-agencia-recibio-mas-de-30.000-reclamaciones-en-2025-un-64-mas",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}