🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
ES · run data-protection-2026-08-03 v13-gdpri-1.0.0
content: ai_generated 35 sources retrieved model claude-sonnet-5 ·

Spain

ES schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 45 claims · 35 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
45Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Mature, fully operative omnibus regime with an active, well-resourced supervisory authority and clear statutory instruments.

Primary frameworkReglamento (UE) 2016/679 (RGPD/GDPR) + Ley Orgánica 3/2018 (LOPDGDD)
Traffic-light rationale — GreenMature, fully operative omnibus regime with an active, well-resourced supervisory authority and clear statutory instruments.

Sub-modules (5)

Regulator And AuthorityGreen

AEPD is the sole general-purpose national DPA for Spain; certain autonomous communities (Cataluña, País Vasco, Andalucía) maintain regional DPAs for public-sector processing within their territory, but AEPD retains general and private-sector competence.

Claims: CLM-ES-a1b2c301

Act And InstrumentsGreen

Core instruments are GDPR (directly applicable), LOPDGDD, LO 7/2021 (law-enforcement data), RD 389/2021 (AEPD Statute) and Ley 34/2002 LSSI for information-society services.

Claims: CLM-ES-b2c3d402

Material ScopeGreen

GDPR/LOPDGDD apply to any processing of personal data relating to an identified or identifiable natural person; data of legal persons is excluded.

Claims: CLM-ES-c3d4e503

Territorial ScopeGreen

Extraterritorial reach under GDPR Art 3(2) captures non-EU controllers/processors offering goods/services to, or monitoring the behaviour of, EU data subjects; such entities must designate an EU representative.

Claims: CLM-ES-d4e5f604

Regulator Registration And FilingAmber

General file-notification/registration with AEPD was abolished from 25 May 2018 and replaced by the internal, non-filed Registro de Actividades de Tratamiento (ROPA). The only affirmative filing duty remaining is communication of DPO appointments/removals to AEPD within 10 days.

Claims: CLM-ES-e5f6a705, CLM-ES-f6a7b806

Category narrative74 words

Spain operates a fully-implemented GDPR omnibus regime. The Agencia Española de Protección de Datos (AEPD) is the national supervisory authority, operating under Ley Orgánica 3/2018 (LOPDGDD) alongside directly-applicable GDPR (Regulation (EU) 2016/679). The obligation to register files with AEPD was abolished on 25 May 2018 and replaced with internal accountability tools (ROPA). Territorial scope follows GDPR Art 3, extending to non-EU controllers targeting or monitoring EU-resident data subjects, who must appoint an EU representative.

Sources and claims (6)
  1. ConfirmedAgencia Española de Protección de DatosThe Agencia Española de Protección de Datos (AEPD) is Spain's national data protection supervisory authority under GDPR and LOPDGDD.
  2. ConfirmedAgencia Española de Protección de DatosSpain's data protection regime rests on GDPR (Regulation (EU) 2016/679) applied directly, LOPDGDD, LO 7/2021, RD 389/2021 (AEPD Statute) and Ley 34/2002 (LSSI) for e-commerce/electronic communications.
  3. ConfirmedAgencia Española de Protección de DatosGDPR/LOPDGDD apply to the processing of personal data relating to identified or identifiable natural persons; data concerning legal persons is not covered.
  4. ConfirmedAgencia Española de Protección de DatosNon-EU-established controllers/processors offering goods or services to, or monitoring the behaviour of, EU data subjects fall within GDPR's territorial scope and must appoint an EU representative as contact point for supervisory authorities and data subjects.
  5. ConfirmedAgencia Española de Protección de DatosSince 25 May 2018, the obligation to register/notify processing files with AEPD has disappeared, both for public and private controllers, replaced by the internal Registro de Actividades de Tratamiento (ROPA).
  6. ConfirmedAgencia Española de Protección de DatosControllers/processors that designate a DPO (mandatorily or voluntarily) must communicate the appointment, and any subsequent removal, to AEPD within 10 days.

#

Lawful basis and special-category framework is GDPR-aligned with clear, AEPD-published interpretive guidance; consent threshold for minors is well-documented.

Primary frameworkGDPR Arts 6-9 + LOPDGDD Arts 6-9
Traffic-light rationale — GreenLawful basis and special-category framework is GDPR-aligned with clear, AEPD-published interpretive guidance; consent threshold for minors is well-documented.

Sub-modules (4)

Lawful BasesGreen

GDPR Art 6 bases apply directly; LOPDGDD presumes legitimate interest for professional contact data of individuals acting for a legal person, absent proof to the contrary.

Claims: CLM-ES-a7b8c907

Special CategoriesAmber

Facial recognition and other biometric identification technologies are classified as Art 9 special-category data, in principle prohibited absent an applicable exception; AEPD has repeatedly found that consent is an inadequate basis in imbalanced relationships (e.g. employment) and that an 'essential public interest' basis requires an appropriately-ranked statute that currently does not exist for many use-cases (e.g. biometric time/attendance control).

Claims: CLM-ES-c9d0e109, CLM-ES-d0e1f210

Pseudonymisation And AnonymisationAmber

No AEPD-specific pseudonymisation/anonymisation safe-harbour instrument was surfaced in this research pass; GDPR's general pseudonymisation definition (Art 4(5)) applies directly as EU law.

Absence provenance: not recorded. Searched: AEPD anonymisation pseudonymisation guidance ES.

Category narrative87 words

Spain applies GDPR Art 6 lawful bases directly, supplemented by LOPDGDD presumptions (e.g. legitimate interest for professional contact data). Age of digital consent is set at 14 (LOPDGDD Art 7), below the GDPR default of 16, one of the lowest permitted under Art 8. Special-category data, notably biometric identifiers such as facial recognition, are treated as Art 9 data requiring an essential-public-interest legal basis grounded in a statute of appropriate rank; consent is treated by AEPD as an inadequate basis where a power imbalance exists (e.g. employer/employee).

Sources and claims (4)
  1. ConfirmedAgencia Española de Protección de DatosLOPDGDD presumes, absent proof to the contrary, a legitimate interest under GDPR Art 6.1(f) for processing professional contact data and role/position data of individuals working for a legal entity.
  2. ConfirmedAgencia Española de Protección de DatosProcessing of a minor's personal data may only be based on the minor's own consent from age fourteen upward; below fourteen, consent must be given by parents or guardians.
  3. ConfirmedAgencia Española de Protección de DatosThe use of facial recognition in video-surveillance implies processing of biometric data classified as a special category under GDPR Art 9, in principle prohibited absent an applicable exception under Spanish law.
  4. ConfirmedAgencia Española de Protección de DatosAEPD guidance holds that consent cannot lift the Art 9 prohibition for biometric presence/access-control systems in employment contexts due to the power imbalance between employer and employee, and that reliance on the 'essential public interest' exception requires a statute of appropriate legal rank that does not currently authorise biometric time-control.

#

Full GDPR rights catalogue in force; AEPD publishes accessible guidance confirming scope, including minors' rights from age 14.

Primary frameworkGDPR Arts 12-22 + LOPDGDD Arts 12-18
Traffic-light rationale — GreenFull GDPR rights catalogue in force; AEPD publishes accessible guidance confirming scope, including minors' rights from age 14.

Sub-modules (5)

Access RightGreen

Right of access under GDPR Art 15 applies; AEPD confirms minors over 14 may exercise it themselves.

Claims: CLM-ES-e1f2a311

Rectification And ErasureGreen

Rights of rectification and erasure (Arts 16-17) form part of the standard rights catalogue confirmed by AEPD.

Claims: CLM-ES-e1f2a311

Restriction And ObjectionGreen

Rights to restriction of processing and objection, including objection to automated decision-making/profiling, are confirmed in AEPD's minors-and-education guidance as part of the exercisable rights catalogue.

Claims: CLM-ES-e1f2a311

Data PortabilityGreen

Portability right (Art 20) is included among the rights AEPD confirms as exercisable, including by minors from age 14.

Claims: CLM-ES-e1f2a311

Deadlines And Response WindowsAmber

No ES-specific deviation from the GDPR Art 12(3) one-month (extendable to three) response window was located in this research pass; GDPR default applies directly.

Absence provenance: not recorded. Searched: AEPD plazo respuesta derechos RGPD un mes.

Category narrative34 words

GDPR Arts 15-22 rights (access, rectification, erasure, restriction, objection, portability, and objection to automated decision-making/profiling) apply directly in Spain and are reiterated in AEPD consumer-facing guidance, including specifically in the context of minors' data.

Sources and claims (1)
  1. ConfirmedAgencia Española de Protección de DatosGDPR grants data subjects the rights of access, rectification, erasure, objection, portability, restriction of processing, and the right to object to automated decision-making including profiling; AEPD confirms these are exercisable by minors from age fourteen.

#

Comprehensive, actively-enforced accountability framework; breach and DPO statistics confirm real operative traction.

Primary frameworkGDPR Arts 5, 24-39 + LOPDGDD Arts 28, 31-37
Traffic-light rationale — GreenComprehensive, actively-enforced accountability framework; breach and DPO statistics confirm real operative traction.

Sub-modules (7)

Accountability And DpiaGreen

Accountability (Art 5(2)) is operationalised via ROPA construction, risk analysis, and DPIA (EIPD) execution as sequential compliance steps recommended by AEPD.

Claims: CLM-ES-f2a3b412

Dpo RequirementsGreen

GDPR Art 37.1 mandatory-DPO triggers (public authority, large-scale systematic monitoring, large-scale special-category processing) are extended by LOPDGDD Art 34 to additional categories of private entities (e.g. schools, sports federations processing minors' data). By end-2025, 126,176 DPOs were registered with AEPD.

Claims: CLM-ES-a3b4c513, CLM-ES-b4c5d614

Ropa RequirementsGreen

Art 30 ROPA obligation replaced the former file-registration regime; ROPA is an internal document made available to AEPD on request, not filed with the Agency.

Claims: CLM-ES-c5d6e715

Joint Controller ArrangementsAmber

No ES-specific Art 26 joint-controller instrument beyond direct GDPR application and EDPB controller/processor guidance was located in this pass.

Absence provenance: not recorded. Searched: AEPD corresponsables tratamiento articulo 26.

Security MeasuresAmber

Art 32 security-of-processing obligations are actively enforced; AEPD's 2026 CaixaBank decision found repeated breaches attributable to systemic design and organisational deficiencies rather than isolated errors.

Claims: CLM-ES-d6e7f816

Breach NotificationAmber

Controllers must notify AEPD without undue delay and within 72 hours of becoming aware of a personal data breach (Art 33); breach-related sanctioning procedures rose sharply in 2025.

Claims: CLM-ES-e7f8a917, CLM-ES-f8a9b018

Retention And DisposalAmber

No ES-specific retention/disposal instrument beyond GDPR's storage-limitation principle (Art 5.1(e)) was surfaced in this research pass.

Absence provenance: not recorded. Searched: AEPD plazos conservacion supresion datos personales.

Category narrative51 words

GDPR accountability principle applies directly (Art 5(2)), operationalised through ROPA (Art 30), DPIA where risk criteria are met, DPO appointment where GDPR Art 37 / LOPDGDD Art 34 thresholds apply, and Art 32-34 security/breach-notification obligations. AEPD's 2025 annual report shows sharply increased breach-related sanctioning activity, evidencing active enforcement of these duties.

Sources and claims (7)
  1. ConfirmedAgencia Española de Protección de DatosAEPD's recommended RGPD-adaptation roadmap treats risk analysis and DPIA (EIPD) execution as core accountability tasks alongside ROPA construction and breach-notification mechanisms.
  2. ConfirmedAgencia Española de Protección de DatosA DPO must be appointed where processing is carried out by a public authority, where core activities require regular and systematic large-scale monitoring of data subjects, or where core activities involve large-scale processing of special-category or criminal-conviction data; LOPDGDD Art 34 extends mandatory designation to further categories of entity.
  3. ConfirmedAgencia Española de Protección de DatosBy the close of 2025, 126,176 DPOs were registered with AEPD (116,007 private sector, 10,169 public sector), up from 119,803 in 2024.
  4. ConfirmedAgencia Española de Protección de DatosThe Registro de Actividades de Tratamiento (ROPA) required by Art 30 GDPR is an internal document that must be made available to AEPD on request but does not need to be filed with or published to the Agency.
  5. ConfirmedDataGuidanceAEPD confirmed a €500,000 fine (reduced to €400,000 on voluntary payment) against CaixaBank in March 2026 for repeated data breaches between 2022-2024 stemming from systemic design and organisational deficiencies rather than isolated human errors.
  6. ConfirmedAgencia Española de Protección de DatosControllers must notify AEPD of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, per Art 33 GDPR.
  7. ConfirmedAgencia Española de Protección de DatosAEPD's 2025 annual report recorded a 157% rise in breach-related sanctioning/reprimand procedures (30 in 2024 to 77 in 2025), yielding fines totalling approximately €19.8 million.

#

Fully harmonised EU transfer regime in force with active AEPD guidance on mechanisms; TIA obligation confirmed via CJEU Schrems II jurisprudence.

Primary frameworkGDPR Arts 44-49 + Commission Implementing Decision (EU) 2021/914
Traffic-light rationale — GreenFully harmonised EU transfer regime in force with active AEPD guidance on mechanisms; TIA obligation confirmed via CJEU Schrems II jurisprudence.

Sub-modules (6)

Transfer MechanismsGreen

AEPD's international-transfers guidance confirms the availability of adequacy decisions, SCCs, BCRs, codes of conduct with binding commitments, certification mechanisms, and derogations for transfers outside the EEA.

Claims: CLM-ES-a9b0c119

Adequacy ReceivedGreen

Not applicable in the conventional sense: as an EU Member State, Spain processes data under the GDPR directly and does not itself require an inbound adequacy decision from the European Commission.

Absence provenance: not recorded. Searched: Spain adequacy decision received EU Member State.

Adequacy GrantedGreen

The European Commission (binding EU-wide, applicable in Spain) has adopted adequacy decisions for a defined list of third countries and the EU-US Data Privacy Framework (10 July 2023), permitting transfers without further safeguards.

Claims: CLM-ES-b0c1d220

Sccs And BcrsGreen

Commission Implementing Decision (EU) 2021/914 SCCs (in force since June 2021, mandatory replacement of legacy clauses since December 2022) are the principal transfer safeguard mechanism referenced by AEPD.

Claims: CLM-ES-c1d2e321

Transfer Impact AssessmentAmber

Following Schrems II (CJEU C-311/18), exporters relying on SCCs/BCRs must assess destination-country law/practice and adopt supplementary measures where needed — a transfer impact assessment obligation applicable to Spanish exporters.

Claims: CLM-ES-d2e3f422

Data LocalisationAmber

No Spain-specific data-localisation mandate (partial or absolute) was identified in this research pass beyond the general EU cross-border transfer regime.

Absence provenance: not recorded. Searched: Spain data localisation mandate personal data.

Category narrative54 words

As an EU Member State, Spain applies the GDPR Chapter V transfer regime uniformly: transfers rely on European Commission adequacy decisions, Commission Implementing Decision (EU) 2021/914 SCCs, BCRs, derogations, or ad hoc clauses authorised by AEPD. Post-Schrems II, a transfer impact assessment (TIA) is required for SCC-based transfers. No Spain-specific data-localisation mandate was identified.

Sources and claims (4)
  1. ConfirmedAgencia Española de Protección de DatosAEPD guidance confirms that, absent an adequacy decision, transfers outside the EEA may rely on Commission-adopted SCCs, controller-adopted SCCs approved by AEPD/the Commission, codes of conduct or certification mechanisms with binding commitments, or derogations for specific situations.
  2. ConfirmedEUR-LexEuropean Commission adequacy decisions currently cover a defined set of third countries and the EU-US Data Privacy Framework (adopted 10 July 2023), permitting transfers from Spain without additional safeguards within their scope.
  3. ConfirmedEUR-LexCommission Implementing Decision (EU) 2021/914 SCCs are considered to provide appropriate safeguards under GDPR Art 46(1)/(2)(c) for transfers from an EU data exporter to a non-EU importer; legacy pre-2001/2010-clause contracts ceased to be valid after 27 December 2022.
  4. ConfirmedEuropean Data Protection BoardFollowing Schrems II, SCC-reliant exporters must carry out a transfer impact assessment documenting destination-country law/practice and any supplementary measures needed to protect transferred data.

#

No separate sectoral statutes displace GDPR, but overlays exist and healthcare/financial sanctioning activity rose sharply in 2025, indicating active but uneven sectoral risk.

Primary frameworkGDPR/LOPDGDD + Ley 34/2002 (LSSI) + sector codes of conduct
Traffic-light rationale — AmberNo separate sectoral statutes displace GDPR, but overlays exist and healthcare/financial sanctioning activity rose sharply in 2025, indicating active but uneven sectoral risk.

Sub-modules (7)

Financial Sector OverlayAmber

No separate banking-secrecy statute displaces GDPR; AEPD actively enforces against financial institutions, e.g. the 2026 CaixaBank fine and 2026 Gesternova (energy-retail, financial data) fine.

Claims: CLM-ES-e3f4a523

Health Sector OverlayAmber

Health data processing requires heightened DPO designation given its Art 9 special-category status; sanitary-sector sanctioning procedures rose 278% in 2025 (34 cases).

Claims: CLM-ES-f4a5b624, CLM-ES-a5b6c725

Telecoms And EprivacyGreen

Ley 34/2002 (LSSI) complements GDPR safeguards for information-society services, including the cookie-consent regime under its Art 22.2.

Claims: CLM-ES-b6c7d826

Employment DataAmber

Biometric access/presence-control systems in employment require a specific statutory basis; consent is deemed inadequate due to employer/employee power imbalance.

Claims: CLM-ES-d0e1f210

Credit And ScoringAmber

No ES-specific credit-scoring statute beyond GDPR Art 22 automated-decision safeguards was located in this research pass.

Absence provenance: not recorded. Searched: AEPD scoring crediticio normativa.

EducationGreen

Educational institutions offering any regulated level of teaching must designate a DPD, and online classes/exams do not require separate consent as they are legitimised by the educational mandate itself.

Claims: CLM-ES-c7d8e927

InsuranceGreen

The insurance sector operates under a voluntary Art 40 GDPR code of conduct (UNESPA CC-0012-2019) supervised by an OCCC, supplementing but not displacing GDPR/LOPDGDD.

Claims: CLM-ES-d8e9f028

Category narrative54 words

GDPR/LOPDGDD apply horizontally, with sector overlays: Ley 34/2002 LSSI for electronic communications/cookies, DPO-mandatory designation for schools and sports federations processing minors' data, heightened biometric-data scrutiny in employment, and voluntary Art 40 sectoral codes of conduct (e.g. UNESPA insurance code). AEPD's strategic engagement covers health, education, telecoms, insurance, banking, and public administration as priority sectors.

Sources and claims (6)
  1. ConfirmedDataGuidanceAEPD fined Gesternova, S.A. €220,000 in January 2026 for processing personal data without a valid legal basis and failing to provide mandatory transparency information at collection.
  2. ConfirmedAgencia Española de Protección de DatosAEPD has endorsed designating a single DPD for health-data processing bodies (e.g. within a defence-sector health inspectorate) given the special-category nature of health data and the scale of processing.
  3. ConfirmedAgencia Española de Protección de DatosAEPD's 2025 annual figures show sanitary-sector sanctioning/reprimand procedures rose 278% year-on-year to 34 cases, among the six most active enforcement areas.
  4. ConfirmedAgencia Española de Protección de DatosLey 34/2002 (LSSI) complements GDPR safeguards for information-society services in Spain, including the cookie/tracker consent regime under LSSI Art 22.2.
  5. ConfirmedAgencia Española de Protección de DatosEducational institutions are obliged to designate a DPD in the cases covered by GDPR Art 37 and, in all cases, when they offer teaching at any level established under regulating legislation; online classes/exams delivered as part of regulated education do not require separate student/parental consent.
  6. ProbableAEPD / UNESPAThe Spanish insurance sector operates under a voluntary Art 40 GDPR code of conduct (UNESPA CC-0012-2019), supervised by an OCCC, requiring adherent insurers to disclose their DPO identity and maintain ROPA compliance.

#

Cookie/dark-pattern regime is mature and AEPD-enforced; other sub-modules (opt-out signals, clean rooms, cross-context advertising) lack a direct EU/ES analogue and were not evidenced in this pass.

Primary frameworkLey 34/2002 (LSSI) Art 22.2 + GDPR + AEPD Guía sobre el uso de las cookies
Traffic-light rationale — AmberCookie/dark-pattern regime is mature and AEPD-enforced; other sub-modules (opt-out signals, clean rooms, cross-context advertising) lack a direct EU/ES analogue and were not evidenced in this pass.

Sub-modules (6)

Cookies And TrackersGreen

AEPD's cookie guide requires prior, informed, valid consent for non-exempt cookies, with accept/reject options presented with equal prominence and at the same level.

Claims: CLM-ES-e9f0a129

Dark PatternsGreen

AEPD updated its cookie guide in 2023 to incorporate EDPB Guidelines 03/2022 on deceptive patterns, requiring accept/reject actions to be equally easy to select.

Claims: CLM-ES-f0a1b230

Opt Out SignalsAmber

No AEPD-specific recognition of a Global-Privacy-Control-equivalent browser signal was identified in this research pass.

Absence provenance: not recorded. Searched: AEPD Global Privacy Control señal navegador.

Clean Rooms And DcrAmber

No AEPD guidance on data clean rooms/data collaboration rooms was identified in this research pass.

Absence provenance: not recorded. Searched: AEPD clean room datos colaboración publicidad.

Cross Context AdvertisingAmber

The EU/ES consent-based ePrivacy model does not use the CPRA 'sale'/'share' framework; cross-context advertising is instead governed through the GDPR/LSSI cookie-consent regime.

Absence provenance: not recorded. Searched: AEPD publicidad cross-context venta datos.

Direct MarketingAmber

Electronic commercial communications are regulated via Ley 34/2002 (LSSI), which complements GDPR consent requirements for direct marketing by electronic means.

Claims: CLM-ES-a1b2c331

Category narrative58 words

AEPD's Guía sobre el uso de las cookies (last major update aligning with EDPB Guidelines 03/2022 on deceptive patterns) governs cookie/tracker consent, mandating equal prominence for accept/reject options. No Spain-specific opt-out-signal (GPC-equivalent), clean-room, or CPRA-style 'sale/share' framework was identified — these concepts do not map directly onto the EU consent-based model, which instead relies on ePrivacy/LSSI consent requirements.

Sources and claims (3)
  1. ConfirmedAgencia Española de Protección de DatosFor non-exempt cookies, valid consent must be obtained from the user, freely and informedly given, with the options to accept and reject cookies offered simultaneously, at the same level and with equal visibility.
  2. ConfirmedAgencia Española de Protección de DatosAEPD updated its cookie guide in July 2023 to align with EDPB Guidelines 03/2022 on deceptive patterns, incorporating the criterion that accept/reject actions be presented in a prominent location and format at the same level, with rejection no more complicated than acceptance.
  3. ProbableAgencia Española de Protección de DatosLey 34/2002 (LSSI) complements GDPR guarantees applicable to information-society services, including electronic direct-marketing communications.

#

AI governance is institutionally advanced (AESIA operative, 16 guidelines published) but the core Organic Law implementing AI Act governance domestically remains in draft/proposed stage as of mid-2026.

Primary frameworkGDPR Art 9, Art 22 + EU AI Act (Regulation (EU) 2024/1689) + draft Spanish Organic Law on AI governance
Traffic-light rationale — AmberAI governance is institutionally advanced (AESIA operative, 16 guidelines published) but the core Organic Law implementing AI Act governance domestically remains in draft/proposed stage as of mid-2026.

Sub-modules (6)

Profiling RestrictionsGreen

GDPR Art 22 grants data subjects the right to object to decisions based solely on automated processing, including profiling, applicable directly in Spain.

Claims: CLM-ES-e1f2a311

Automated Decision Making TransparencyAmber

AEPD's AI-adaptation guidance ties automated processing to the GDPR information/transparency principle, requiring data subjects to be aware of how AI-driven processing uses their data.

Claims: CLM-ES-b2c3d432

Ai Risk AssessmentsAmber

AESIA was created from scratch as Spain's dedicated national AI authority ahead of the EU AI Act's governance requirements, publishing 16 interpretive AI guidelines drawing on its regulatory sandbox; a draft Organic Law on AI governance, designating notifying/market-surveillance authorities and giving AESIA a single-point-of-contact role, was approved by Council of Ministers on 26 May 2026 and sent to Congress.

Claims: CLM-ES-c3d4e533, CLM-ES-d4e5f634

Biometric RegimeAmber

Facial-recognition and related biometric identification are treated as Art 9 special-category data requiring an essential-public-interest legal basis grounded in an appropriately-ranked statute; AEPD has rejected the argument that ordinary video-surveillance legitimation extends to facial/gait/voice recognition.

Claims: CLM-ES-c9d0e109, CLM-ES-e5f6a735

Genetic DataAmber

No ES-specific genetic-data regime beyond GDPR Art 9's general special-category treatment was identified in this research pass.

Absence provenance: not recorded. Searched: AEPD datos geneticos regimen especial.

State Surveillance CarveoutsAmber

No ES-specific state-surveillance carveout beyond LO 7/2021 (law-enforcement-purpose data processing) was substantively evidenced in this research pass.

Claims: CLM-ES-f6a7b836

Category narrative81 words

Spain was the first EU Member State to create a dedicated AI supervisory authority, the Agencia Española de Supervisión de la Inteligencia Artificial (AESIA), operationalising EU AI Act oversight ahead of most peers, with a draft Organic Law on AI governance approved by the Council of Ministers in May 2026 and pending parliamentary processing. Biometric identification (facial recognition, gait, voice) is treated by AEPD as high-risk Art 9 special-category processing requiring reinforced safeguards. GDPR Art 22 profiling/automated-decision-making objection rights apply directly.

Sources and claims (5)
  1. ProbableAgencia Española de Protección de DatosAEPD guidance on GDPR-compliant AI processing ties automated processing to the information/transparency principle, requiring affected data subjects to be made aware of how their data is used within AI-embedding treatments.
  2. ConfirmedIAPPSpain became the first EU Member State to establish a dedicated national AI supervisory authority, AESIA, which has published 16 interpretive AI guidelines developed within its AI regulatory sandbox to help translate EU AI Act principles into practical compliance steps.
  3. ConfirmedDataGuidanceOn 26 May 2026, Spain's Council of Ministers approved a draft Organic Law on the proper use and governance of AI, designating notifying and market-surveillance authorities with AESIA as single point of contact, and sent it to Congress for parliamentary processing.
  4. ConfirmedAgencia Española de Protección de DatosAEPD's 2020 legal report concluded that facial-recognition technology in private-security video-surveillance is, in principle, prohibited under GDPR as special-category biometric processing, and that the legitimation applicable to plain image/sound-capturing video-surveillance cannot be extended to facial, gait, or voice recognition.
  5. ConfirmedAgencia Española de Protección de DatosLey Orgánica 7/2021 provides a distinct data-protection regime for personal data processed for the prevention, detection, investigation and prosecution of criminal offences and execution of criminal penalties, operating alongside the general GDPR/LOPDGDD regime.

#

Consent-age and parental-consent framework is clear and GDPR-aligned; minor-specific profiling bans and dependent-adult protections beyond general GDPR safeguards were not evidenced in this pass.

Primary frameworkGDPR Art 8 + LOPDGDD Art 7 + LOPDGDD Art 34
Traffic-light rationale — AmberConsent-age and parental-consent framework is clear and GDPR-aligned; minor-specific profiling bans and dependent-adult protections beyond general GDPR safeguards were not evidenced in this pass.

Sub-modules (5)

Age VerificationAmber

AEPD's technical note on 'safe internet by default' for children stresses that age verification alone is insufficient and must be designed to meet all GDPR principles while avoiding new risks (e.g. enabling minors to be located).

Claims: CLM-ES-a7b8c937

Minor Profiling BansAmber

No explicit Spain-specific ban on profiling of minors beyond GDPR's general recitals/Art 22 objection right was identified in this research pass.

Absence provenance: not recorded. Searched: AEPD prohibicion perfilado menores.

Education SettingsGreen

Schools must designate a DPD when GDPR Art 37 criteria apply and, in all cases, when offering teaching at any level under regulating legislation; online classes/exams in regulated education are legitimised without requiring separate consent.

Claims: CLM-ES-c7d8e927

Dependent AdultsAmber

No ES-specific dependent-adult (elderly/mentally incapacitated) data-protection instrument beyond general GDPR safeguards was identified in this research pass.

Absence provenance: not recorded. Searched: AEPD proteccion datos personas dependientes mayores.

Category narrative50 words

LOPDGDD sets the digital age of consent at fourteen, among the lowest permitted under GDPR Art 8's 13-16 range. AEPD publishes extensive guidance on age verification/age-appropriate design ('tudecideseninternet.es'), mandatory DPO designation for schools and youth-data-processing sports federations, and lawful processing of minors' data in regulated education without requiring separate consent.

Sources and claims (2)
  1. ProbableAgencia Española de Protección de DatosAEPD's technical note on a safe internet by default states that age verification, per se, is not sufficient and must be designed and implemented consistently with all GDPR principles while avoiding new risks such as enabling minors' location to be tracked.
  2. ConfirmedAgencia Española de Protección de DatosLOPDGDD Art 7 provides that processing of a minor's data may be based on the minor's own consent from age fourteen; below that age, parental or guardian consent is required, and consent must in all cases be express.

#

Enforcement activity is vigorous and well-documented, but AEPD's own reporting flags a capacity/resourcing strain relative to caseload growth.

Primary frameworkGDPR Arts 58, 77-84 + LOPDGDD Arts 48, 50, 63-72
Traffic-light rationale — AmberEnforcement activity is vigorous and well-documented, but AEPD's own reporting flags a capacity/resourcing strain relative to caseload growth.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

AEPD exercises Art 58 GDPR corrective powers (reprimand, corrective order, processing bans/limits, fines) through the LOPDGDD sanctioning procedure, governed subsidiarily by LPACAP; decisions are appealable via recurso de reposición or directly to the Audiencia Nacional.

Claims: CLM-ES-d0e1f239, CLM-ES-e1f2a340

Enforcement Activity IndexAmber

2025 saw record enforcement activity: 30,931 complaints filed (+64% YoY), 77 breach-related sanctioning/reprimand procedures (+157% YoY, ≈€19.8m fines), plus headline 2026 fines against Gesternova (€220k) and CaixaBank (€500k/€400k).

Claims: CLM-ES-f2a3b441, CLM-ES-a3b4c542, CLM-ES-e3f4a523, CLM-ES-d6e7f816

Regulator Funding And CapacityAmber

AEPD's own 2025 annual report states that growing workload across most subdirectorates has not been matched by proportional staffing growth, a constraint the Agency flags in its 2025-2030 Strategic Plan.

Claims: CLM-ES-b4c5d643

Collective Redress And Class ActionsAmber

No ES-specific GDPR-related collective-redress/class-action mechanism beyond general Spanish civil procedure and EU Representative Actions Directive transposition was evidenced in this research pass.

Absence provenance: not recorded. Searched: AEPD accion colectiva proteccion datos demanda.

Private Right Of ActionAmber

Data subjects and controllers alike may challenge AEPD resolutions via recurso de reposición or directly via recurso contencioso-administrativo before the Audiencia Nacional's Contentious-Administrative Chamber.

Claims: CLM-ES-c4d5e644

Recent Developments 180DAmber

Within the last 180 days: AEPD published its 2025 annual report (May 2026) showing record complaint volumes and sanctioning activity; AEPD confirmed the €500k/€400k CaixaBank fine (March 2026); Spain's Council of Ministers approved a draft Organic Law on AI governance (May 2026); AESIA continued publishing AI guidelines through mid-2026.

Claims: CLM-ES-f4a5b645, CLM-ES-d6e7f816, CLM-ES-d4e5f634

Category narrative69 words

AEPD holds full Art 58 GDPR corrective powers (reprimand, order, ban, fine) exercised via LOPDGDD-specific sanctioning procedure (Art 63-65), with decisions appealable to the Audiencia Nacional. 2025 was a record enforcement year: 30,931 complaints (up 64%), breach-related sanctioning procedures up 157% to 77 (≈€19.8m in fines), and headline fines against Gesternova (€220k, Jan 2026) and CaixaBank (€500k/€400k, March 2026). AEPD explicitly flags that workload growth has outpaced staffing increases.

Sources and claims (7)
  1. ConfirmedAgencia Española de Protección de DatosAEPD sanctioning procedures are governed by GDPR (Regulation (EU) 2016/679), LOPDGDD, its implementing regulatory provisions and, subsidiarily, general Spanish administrative procedure rules.
  2. ConfirmedAgencia Española de Protección de DatosAEPD resolutions ending the administrative pathway may be challenged via a discretionary recurso de reposición before the AEPD Presidency/Director, or directly via recurso contencioso-administrativo before the Audiencia Nacional's Contentious-Administrative Chamber.
  3. ConfirmedAgencia Española de Protección de DatosIn 2025, AEPD received 30,931 complaints, the highest number in the Agency's history, a 64% increase over the prior year.
  4. ConfirmedAgencia Española de Protección de DatosAEPD led 47 cross-border cases as lead authority in 2025 (+114% vs 2024) and cooperated as concerned authority in 419 cases (+20%); of 38 Audiencia Nacional judgments on AEPD-resolution appeals in 2025, 76% were dismissed or rejected, i.e. upheld the Agency's decisions.
  5. ConfirmedAgencia Española de Protección de DatosAEPD's 2025 annual report states that the growing workload reflected across most of its subdirectorates and divisions has not been matched by a proportional increase in staffing, prompting a technology-supported, impact-prioritised supervision strategy under its 2025-2030 Strategic Plan.
  6. ConfirmedAgencia Española de Protección de DatosAny interested party may lodge a recurso contencioso-administrativo against a final AEPD resolution before the Audiencia Nacional's Contentious-Administrative Chamber within two months of notification.
  7. ConfirmedAgencia Española de Protección de DatosAEPD presented its Memoria de actuación 2025 on 6 May 2026, disclosing record complaint volumes, a 157% rise in breach-related sanctioning/reprimand procedures, and approximately €19.8 million in resulting fines.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Spain
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 45 claim(s), 35 source(s) in the cumulative register.