Traffic-light rationale — GreenMature, fully operative omnibus regime with an active, well-resourced supervisory authority and clear statutory instruments.
Sub-modules (5)
Regulator And AuthorityGreen
AEPD is the sole general-purpose national DPA for Spain; certain autonomous communities (Cataluña, País Vasco, Andalucía) maintain regional DPAs for public-sector processing within their territory, but AEPD retains general and private-sector competence.
Claims: CLM-ES-a1b2c301
Act And InstrumentsGreen
Core instruments are GDPR (directly applicable), LOPDGDD, LO 7/2021 (law-enforcement data), RD 389/2021 (AEPD Statute) and Ley 34/2002 LSSI for information-society services.
Claims: CLM-ES-b2c3d402
Material ScopeGreen
GDPR/LOPDGDD apply to any processing of personal data relating to an identified or identifiable natural person; data of legal persons is excluded.
Claims: CLM-ES-c3d4e503
Territorial ScopeGreen
Extraterritorial reach under GDPR Art 3(2) captures non-EU controllers/processors offering goods/services to, or monitoring the behaviour of, EU data subjects; such entities must designate an EU representative.
Claims: CLM-ES-d4e5f604
Regulator Registration And FilingAmber
General file-notification/registration with AEPD was abolished from 25 May 2018 and replaced by the internal, non-filed Registro de Actividades de Tratamiento (ROPA). The only affirmative filing duty remaining is communication of DPO appointments/removals to AEPD within 10 days.
Claims: CLM-ES-e5f6a705, CLM-ES-f6a7b806
Category narrative74 words
Spain operates a fully-implemented GDPR omnibus regime. The Agencia Española de Protección de Datos (AEPD) is the national supervisory authority, operating under Ley Orgánica 3/2018 (LOPDGDD) alongside directly-applicable GDPR (Regulation (EU) 2016/679). The obligation to register files with AEPD was abolished on 25 May 2018 and replaced with internal accountability tools (ROPA). Territorial scope follows GDPR Art 3, extending to non-EU controllers targeting or monitoring EU-resident data subjects, who must appoint an EU representative.
Sources and claims (6)
ConfirmedAgencia Española de Protección de Datos — The Agencia Española de Protección de Datos (AEPD) is Spain's national data protection supervisory authority under GDPR and LOPDGDD.
ConfirmedAgencia Española de Protección de Datos — Spain's data protection regime rests on GDPR (Regulation (EU) 2016/679) applied directly, LOPDGDD, LO 7/2021, RD 389/2021 (AEPD Statute) and Ley 34/2002 (LSSI) for e-commerce/electronic communications.
ConfirmedAgencia Española de Protección de Datos — GDPR/LOPDGDD apply to the processing of personal data relating to identified or identifiable natural persons; data concerning legal persons is not covered.
ConfirmedAgencia Española de Protección de Datos — Non-EU-established controllers/processors offering goods or services to, or monitoring the behaviour of, EU data subjects fall within GDPR's territorial scope and must appoint an EU representative as contact point for supervisory authorities and data subjects.
ConfirmedAgencia Española de Protección de Datos — Since 25 May 2018, the obligation to register/notify processing files with AEPD has disappeared, both for public and private controllers, replaced by the internal Registro de Actividades de Tratamiento (ROPA).
ConfirmedAgencia Española de Protección de Datos — Controllers/processors that designate a DPO (mandatorily or voluntarily) must communicate the appointment, and any subsequent removal, to AEPD within 10 days.
Lawful basis and special-category framework is GDPR-aligned with clear, AEPD-published interpretive guidance; consent threshold for minors is well-documented.
Traffic-light rationale — GreenLawful basis and special-category framework is GDPR-aligned with clear, AEPD-published interpretive guidance; consent threshold for minors is well-documented.
Sub-modules (4)
Lawful BasesGreen
GDPR Art 6 bases apply directly; LOPDGDD presumes legitimate interest for professional contact data of individuals acting for a legal person, absent proof to the contrary.
Claims: CLM-ES-a7b8c907
Consent ThresholdsGreen
LOPDGDD Art 7 sets the age of valid data-processing consent at 14; below that age, parental/guardian consent is required.
Claims: CLM-ES-b8c9d008
Special CategoriesAmber
Facial recognition and other biometric identification technologies are classified as Art 9 special-category data, in principle prohibited absent an applicable exception; AEPD has repeatedly found that consent is an inadequate basis in imbalanced relationships (e.g. employment) and that an 'essential public interest' basis requires an appropriately-ranked statute that currently does not exist for many use-cases (e.g. biometric time/attendance control).
Claims: CLM-ES-c9d0e109, CLM-ES-d0e1f210
Pseudonymisation And AnonymisationAmber
No AEPD-specific pseudonymisation/anonymisation safe-harbour instrument was surfaced in this research pass; GDPR's general pseudonymisation definition (Art 4(5)) applies directly as EU law.
Absence provenance: not recorded. Searched: AEPD anonymisation pseudonymisation guidance ES.
Category narrative87 words
Spain applies GDPR Art 6 lawful bases directly, supplemented by LOPDGDD presumptions (e.g. legitimate interest for professional contact data). Age of digital consent is set at 14 (LOPDGDD Art 7), below the GDPR default of 16, one of the lowest permitted under Art 8. Special-category data, notably biometric identifiers such as facial recognition, are treated as Art 9 data requiring an essential-public-interest legal basis grounded in a statute of appropriate rank; consent is treated by AEPD as an inadequate basis where a power imbalance exists (e.g. employer/employee).
Sources and claims (4)
ConfirmedAgencia Española de Protección de Datos — LOPDGDD presumes, absent proof to the contrary, a legitimate interest under GDPR Art 6.1(f) for processing professional contact data and role/position data of individuals working for a legal entity.
ConfirmedAgencia Española de Protección de Datos — Processing of a minor's personal data may only be based on the minor's own consent from age fourteen upward; below fourteen, consent must be given by parents or guardians.
ConfirmedAgencia Española de Protección de Datos — The use of facial recognition in video-surveillance implies processing of biometric data classified as a special category under GDPR Art 9, in principle prohibited absent an applicable exception under Spanish law.
ConfirmedAgencia Española de Protección de Datos — AEPD guidance holds that consent cannot lift the Art 9 prohibition for biometric presence/access-control systems in employment contexts due to the power imbalance between employer and employee, and that reliance on the 'essential public interest' exception requires a statute of appropriate legal rank that does not currently authorise biometric time-control.
Traffic-light rationale — GreenFull GDPR rights catalogue in force; AEPD publishes accessible guidance confirming scope, including minors' rights from age 14.
Sub-modules (5)
Access RightGreen
Right of access under GDPR Art 15 applies; AEPD confirms minors over 14 may exercise it themselves.
Claims: CLM-ES-e1f2a311
Rectification And ErasureGreen
Rights of rectification and erasure (Arts 16-17) form part of the standard rights catalogue confirmed by AEPD.
Claims: CLM-ES-e1f2a311
Restriction And ObjectionGreen
Rights to restriction of processing and objection, including objection to automated decision-making/profiling, are confirmed in AEPD's minors-and-education guidance as part of the exercisable rights catalogue.
Claims: CLM-ES-e1f2a311
Data PortabilityGreen
Portability right (Art 20) is included among the rights AEPD confirms as exercisable, including by minors from age 14.
Claims: CLM-ES-e1f2a311
Deadlines And Response WindowsAmber
No ES-specific deviation from the GDPR Art 12(3) one-month (extendable to three) response window was located in this research pass; GDPR default applies directly.
Absence provenance: not recorded. Searched: AEPD plazo respuesta derechos RGPD un mes.
Category narrative34 words
GDPR Arts 15-22 rights (access, rectification, erasure, restriction, objection, portability, and objection to automated decision-making/profiling) apply directly in Spain and are reiterated in AEPD consumer-facing guidance, including specifically in the context of minors' data.
Sources and claims (1)
ConfirmedAgencia Española de Protección de Datos — GDPR grants data subjects the rights of access, rectification, erasure, objection, portability, restriction of processing, and the right to object to automated decision-making including profiling; AEPD confirms these are exercisable by minors from age fourteen.
Traffic-light rationale — GreenComprehensive, actively-enforced accountability framework; breach and DPO statistics confirm real operative traction.
Sub-modules (7)
Accountability And DpiaGreen
Accountability (Art 5(2)) is operationalised via ROPA construction, risk analysis, and DPIA (EIPD) execution as sequential compliance steps recommended by AEPD.
Claims: CLM-ES-f2a3b412
Dpo RequirementsGreen
GDPR Art 37.1 mandatory-DPO triggers (public authority, large-scale systematic monitoring, large-scale special-category processing) are extended by LOPDGDD Art 34 to additional categories of private entities (e.g. schools, sports federations processing minors' data). By end-2025, 126,176 DPOs were registered with AEPD.
Claims: CLM-ES-a3b4c513, CLM-ES-b4c5d614
Ropa RequirementsGreen
Art 30 ROPA obligation replaced the former file-registration regime; ROPA is an internal document made available to AEPD on request, not filed with the Agency.
Claims: CLM-ES-c5d6e715
Joint Controller ArrangementsAmber
No ES-specific Art 26 joint-controller instrument beyond direct GDPR application and EDPB controller/processor guidance was located in this pass.
Absence provenance: not recorded. Searched: AEPD corresponsables tratamiento articulo 26.
Security MeasuresAmber
Art 32 security-of-processing obligations are actively enforced; AEPD's 2026 CaixaBank decision found repeated breaches attributable to systemic design and organisational deficiencies rather than isolated errors.
Claims: CLM-ES-d6e7f816
Breach NotificationAmber
Controllers must notify AEPD without undue delay and within 72 hours of becoming aware of a personal data breach (Art 33); breach-related sanctioning procedures rose sharply in 2025.
Claims: CLM-ES-e7f8a917, CLM-ES-f8a9b018
Retention And DisposalAmber
No ES-specific retention/disposal instrument beyond GDPR's storage-limitation principle (Art 5.1(e)) was surfaced in this research pass.
Absence provenance: not recorded. Searched: AEPD plazos conservacion supresion datos personales.
Category narrative51 words
GDPR accountability principle applies directly (Art 5(2)), operationalised through ROPA (Art 30), DPIA where risk criteria are met, DPO appointment where GDPR Art 37 / LOPDGDD Art 34 thresholds apply, and Art 32-34 security/breach-notification obligations. AEPD's 2025 annual report shows sharply increased breach-related sanctioning activity, evidencing active enforcement of these duties.
Sources and claims (7)
ConfirmedAgencia Española de Protección de Datos — AEPD's recommended RGPD-adaptation roadmap treats risk analysis and DPIA (EIPD) execution as core accountability tasks alongside ROPA construction and breach-notification mechanisms.
ConfirmedAgencia Española de Protección de Datos — A DPO must be appointed where processing is carried out by a public authority, where core activities require regular and systematic large-scale monitoring of data subjects, or where core activities involve large-scale processing of special-category or criminal-conviction data; LOPDGDD Art 34 extends mandatory designation to further categories of entity.
ConfirmedAgencia Española de Protección de Datos — By the close of 2025, 126,176 DPOs were registered with AEPD (116,007 private sector, 10,169 public sector), up from 119,803 in 2024.
ConfirmedAgencia Española de Protección de Datos — The Registro de Actividades de Tratamiento (ROPA) required by Art 30 GDPR is an internal document that must be made available to AEPD on request but does not need to be filed with or published to the Agency.
ConfirmedDataGuidance — AEPD confirmed a €500,000 fine (reduced to €400,000 on voluntary payment) against CaixaBank in March 2026 for repeated data breaches between 2022-2024 stemming from systemic design and organisational deficiencies rather than isolated human errors.
ConfirmedAgencia Española de Protección de Datos — Controllers must notify AEPD of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, per Art 33 GDPR.
ConfirmedAgencia Española de Protección de Datos — AEPD's 2025 annual report recorded a 157% rise in breach-related sanctioning/reprimand procedures (30 in 2024 to 77 in 2025), yielding fines totalling approximately €19.8 million.
Traffic-light rationale — GreenFully harmonised EU transfer regime in force with active AEPD guidance on mechanisms; TIA obligation confirmed via CJEU Schrems II jurisprudence.
Sub-modules (6)
Transfer MechanismsGreen
AEPD's international-transfers guidance confirms the availability of adequacy decisions, SCCs, BCRs, codes of conduct with binding commitments, certification mechanisms, and derogations for transfers outside the EEA.
Claims: CLM-ES-a9b0c119
Adequacy ReceivedGreen
Not applicable in the conventional sense: as an EU Member State, Spain processes data under the GDPR directly and does not itself require an inbound adequacy decision from the European Commission.
Absence provenance: not recorded. Searched: Spain adequacy decision received EU Member State.
Adequacy GrantedGreen
The European Commission (binding EU-wide, applicable in Spain) has adopted adequacy decisions for a defined list of third countries and the EU-US Data Privacy Framework (10 July 2023), permitting transfers without further safeguards.
Claims: CLM-ES-b0c1d220
Sccs And BcrsGreen
Commission Implementing Decision (EU) 2021/914 SCCs (in force since June 2021, mandatory replacement of legacy clauses since December 2022) are the principal transfer safeguard mechanism referenced by AEPD.
Claims: CLM-ES-c1d2e321
Transfer Impact AssessmentAmber
Following Schrems II (CJEU C-311/18), exporters relying on SCCs/BCRs must assess destination-country law/practice and adopt supplementary measures where needed — a transfer impact assessment obligation applicable to Spanish exporters.
Claims: CLM-ES-d2e3f422
Data LocalisationAmber
No Spain-specific data-localisation mandate (partial or absolute) was identified in this research pass beyond the general EU cross-border transfer regime.
Absence provenance: not recorded. Searched: Spain data localisation mandate personal data.
Category narrative54 words
As an EU Member State, Spain applies the GDPR Chapter V transfer regime uniformly: transfers rely on European Commission adequacy decisions, Commission Implementing Decision (EU) 2021/914 SCCs, BCRs, derogations, or ad hoc clauses authorised by AEPD. Post-Schrems II, a transfer impact assessment (TIA) is required for SCC-based transfers. No Spain-specific data-localisation mandate was identified.
Sources and claims (4)
ConfirmedAgencia Española de Protección de Datos — AEPD guidance confirms that, absent an adequacy decision, transfers outside the EEA may rely on Commission-adopted SCCs, controller-adopted SCCs approved by AEPD/the Commission, codes of conduct or certification mechanisms with binding commitments, or derogations for specific situations.
ConfirmedEUR-Lex — European Commission adequacy decisions currently cover a defined set of third countries and the EU-US Data Privacy Framework (adopted 10 July 2023), permitting transfers from Spain without additional safeguards within their scope.
ConfirmedEUR-Lex — Commission Implementing Decision (EU) 2021/914 SCCs are considered to provide appropriate safeguards under GDPR Art 46(1)/(2)(c) for transfers from an EU data exporter to a non-EU importer; legacy pre-2001/2010-clause contracts ceased to be valid after 27 December 2022.
ConfirmedEuropean Data Protection Board — Following Schrems II, SCC-reliant exporters must carry out a transfer impact assessment documenting destination-country law/practice and any supplementary measures needed to protect transferred data.
No separate sectoral statutes displace GDPR, but overlays exist and healthcare/financial sanctioning activity rose sharply in 2025, indicating active but uneven sectoral risk.
Traffic-light rationale — AmberNo separate sectoral statutes displace GDPR, but overlays exist and healthcare/financial sanctioning activity rose sharply in 2025, indicating active but uneven sectoral risk.
Sub-modules (7)
Financial Sector OverlayAmber
No separate banking-secrecy statute displaces GDPR; AEPD actively enforces against financial institutions, e.g. the 2026 CaixaBank fine and 2026 Gesternova (energy-retail, financial data) fine.
Claims: CLM-ES-e3f4a523
Health Sector OverlayAmber
Health data processing requires heightened DPO designation given its Art 9 special-category status; sanitary-sector sanctioning procedures rose 278% in 2025 (34 cases).
Claims: CLM-ES-f4a5b624, CLM-ES-a5b6c725
Telecoms And EprivacyGreen
Ley 34/2002 (LSSI) complements GDPR safeguards for information-society services, including the cookie-consent regime under its Art 22.2.
Claims: CLM-ES-b6c7d826
Employment DataAmber
Biometric access/presence-control systems in employment require a specific statutory basis; consent is deemed inadequate due to employer/employee power imbalance.
Claims: CLM-ES-d0e1f210
Credit And ScoringAmber
No ES-specific credit-scoring statute beyond GDPR Art 22 automated-decision safeguards was located in this research pass.
Absence provenance: not recorded. Searched: AEPD scoring crediticio normativa.
EducationGreen
Educational institutions offering any regulated level of teaching must designate a DPD, and online classes/exams do not require separate consent as they are legitimised by the educational mandate itself.
Claims: CLM-ES-c7d8e927
InsuranceGreen
The insurance sector operates under a voluntary Art 40 GDPR code of conduct (UNESPA CC-0012-2019) supervised by an OCCC, supplementing but not displacing GDPR/LOPDGDD.
Claims: CLM-ES-d8e9f028
Category narrative54 words
GDPR/LOPDGDD apply horizontally, with sector overlays: Ley 34/2002 LSSI for electronic communications/cookies, DPO-mandatory designation for schools and sports federations processing minors' data, heightened biometric-data scrutiny in employment, and voluntary Art 40 sectoral codes of conduct (e.g. UNESPA insurance code). AEPD's strategic engagement covers health, education, telecoms, insurance, banking, and public administration as priority sectors.
Sources and claims (6)
ConfirmedDataGuidance — AEPD fined Gesternova, S.A. €220,000 in January 2026 for processing personal data without a valid legal basis and failing to provide mandatory transparency information at collection.
ConfirmedAgencia Española de Protección de Datos — AEPD has endorsed designating a single DPD for health-data processing bodies (e.g. within a defence-sector health inspectorate) given the special-category nature of health data and the scale of processing.
ConfirmedAgencia Española de Protección de Datos — AEPD's 2025 annual figures show sanitary-sector sanctioning/reprimand procedures rose 278% year-on-year to 34 cases, among the six most active enforcement areas.
ConfirmedAgencia Española de Protección de Datos — Ley 34/2002 (LSSI) complements GDPR safeguards for information-society services in Spain, including the cookie/tracker consent regime under LSSI Art 22.2.
ConfirmedAgencia Española de Protección de Datos — Educational institutions are obliged to designate a DPD in the cases covered by GDPR Art 37 and, in all cases, when they offer teaching at any level established under regulating legislation; online classes/exams delivered as part of regulated education do not require separate student/parental consent.
ProbableAEPD / UNESPA — The Spanish insurance sector operates under a voluntary Art 40 GDPR code of conduct (UNESPA CC-0012-2019), supervised by an OCCC, requiring adherent insurers to disclose their DPO identity and maintain ROPA compliance.
Cookie/dark-pattern regime is mature and AEPD-enforced; other sub-modules (opt-out signals, clean rooms, cross-context advertising) lack a direct EU/ES analogue and were not evidenced in this pass.
Primary frameworkLey 34/2002 (LSSI) Art 22.2 + GDPR + AEPD Guía sobre el uso de las cookies
Traffic-light rationale — AmberCookie/dark-pattern regime is mature and AEPD-enforced; other sub-modules (opt-out signals, clean rooms, cross-context advertising) lack a direct EU/ES analogue and were not evidenced in this pass.
Sub-modules (6)
Cookies And TrackersGreen
AEPD's cookie guide requires prior, informed, valid consent for non-exempt cookies, with accept/reject options presented with equal prominence and at the same level.
Claims: CLM-ES-e9f0a129
Dark PatternsGreen
AEPD updated its cookie guide in 2023 to incorporate EDPB Guidelines 03/2022 on deceptive patterns, requiring accept/reject actions to be equally easy to select.
Claims: CLM-ES-f0a1b230
Opt Out SignalsAmber
No AEPD-specific recognition of a Global-Privacy-Control-equivalent browser signal was identified in this research pass.
Absence provenance: not recorded. Searched: AEPD Global Privacy Control señal navegador.
Clean Rooms And DcrAmber
No AEPD guidance on data clean rooms/data collaboration rooms was identified in this research pass.
Absence provenance: not recorded. Searched: AEPD clean room datos colaboración publicidad.
Cross Context AdvertisingAmber
The EU/ES consent-based ePrivacy model does not use the CPRA 'sale'/'share' framework; cross-context advertising is instead governed through the GDPR/LSSI cookie-consent regime.
Absence provenance: not recorded. Searched: AEPD publicidad cross-context venta datos.
Direct MarketingAmber
Electronic commercial communications are regulated via Ley 34/2002 (LSSI), which complements GDPR consent requirements for direct marketing by electronic means.
Claims: CLM-ES-a1b2c331
Category narrative58 words
AEPD's Guía sobre el uso de las cookies (last major update aligning with EDPB Guidelines 03/2022 on deceptive patterns) governs cookie/tracker consent, mandating equal prominence for accept/reject options. No Spain-specific opt-out-signal (GPC-equivalent), clean-room, or CPRA-style 'sale/share' framework was identified — these concepts do not map directly onto the EU consent-based model, which instead relies on ePrivacy/LSSI consent requirements.
Sources and claims (3)
ConfirmedAgencia Española de Protección de Datos — For non-exempt cookies, valid consent must be obtained from the user, freely and informedly given, with the options to accept and reject cookies offered simultaneously, at the same level and with equal visibility.
ConfirmedAgencia Española de Protección de Datos — AEPD updated its cookie guide in July 2023 to align with EDPB Guidelines 03/2022 on deceptive patterns, incorporating the criterion that accept/reject actions be presented in a prominent location and format at the same level, with rejection no more complicated than acceptance.
ProbableAgencia Española de Protección de Datos — Ley 34/2002 (LSSI) complements GDPR guarantees applicable to information-society services, including electronic direct-marketing communications.
AI governance is institutionally advanced (AESIA operative, 16 guidelines published) but the core Organic Law implementing AI Act governance domestically remains in draft/proposed stage as of mid-2026.
Primary frameworkGDPR Art 9, Art 22 + EU AI Act (Regulation (EU) 2024/1689) + draft Spanish Organic Law on AI governance
Traffic-light rationale — AmberAI governance is institutionally advanced (AESIA operative, 16 guidelines published) but the core Organic Law implementing AI Act governance domestically remains in draft/proposed stage as of mid-2026.
Sub-modules (6)
Profiling RestrictionsGreen
GDPR Art 22 grants data subjects the right to object to decisions based solely on automated processing, including profiling, applicable directly in Spain.
Claims: CLM-ES-e1f2a311
Automated Decision Making TransparencyAmber
AEPD's AI-adaptation guidance ties automated processing to the GDPR information/transparency principle, requiring data subjects to be aware of how AI-driven processing uses their data.
Claims: CLM-ES-b2c3d432
Ai Risk AssessmentsAmber
AESIA was created from scratch as Spain's dedicated national AI authority ahead of the EU AI Act's governance requirements, publishing 16 interpretive AI guidelines drawing on its regulatory sandbox; a draft Organic Law on AI governance, designating notifying/market-surveillance authorities and giving AESIA a single-point-of-contact role, was approved by Council of Ministers on 26 May 2026 and sent to Congress.
Claims: CLM-ES-c3d4e533, CLM-ES-d4e5f634
Biometric RegimeAmber
Facial-recognition and related biometric identification are treated as Art 9 special-category data requiring an essential-public-interest legal basis grounded in an appropriately-ranked statute; AEPD has rejected the argument that ordinary video-surveillance legitimation extends to facial/gait/voice recognition.
Claims: CLM-ES-c9d0e109, CLM-ES-e5f6a735
Genetic DataAmber
No ES-specific genetic-data regime beyond GDPR Art 9's general special-category treatment was identified in this research pass.
Absence provenance: not recorded. Searched: AEPD datos geneticos regimen especial.
State Surveillance CarveoutsAmber
No ES-specific state-surveillance carveout beyond LO 7/2021 (law-enforcement-purpose data processing) was substantively evidenced in this research pass.
Claims: CLM-ES-f6a7b836
Category narrative81 words
Spain was the first EU Member State to create a dedicated AI supervisory authority, the Agencia Española de Supervisión de la Inteligencia Artificial (AESIA), operationalising EU AI Act oversight ahead of most peers, with a draft Organic Law on AI governance approved by the Council of Ministers in May 2026 and pending parliamentary processing. Biometric identification (facial recognition, gait, voice) is treated by AEPD as high-risk Art 9 special-category processing requiring reinforced safeguards. GDPR Art 22 profiling/automated-decision-making objection rights apply directly.
Sources and claims (5)
ProbableAgencia Española de Protección de Datos — AEPD guidance on GDPR-compliant AI processing ties automated processing to the information/transparency principle, requiring affected data subjects to be made aware of how their data is used within AI-embedding treatments.
ConfirmedIAPP — Spain became the first EU Member State to establish a dedicated national AI supervisory authority, AESIA, which has published 16 interpretive AI guidelines developed within its AI regulatory sandbox to help translate EU AI Act principles into practical compliance steps.
ConfirmedDataGuidance — On 26 May 2026, Spain's Council of Ministers approved a draft Organic Law on the proper use and governance of AI, designating notifying and market-surveillance authorities with AESIA as single point of contact, and sent it to Congress for parliamentary processing.
ConfirmedAgencia Española de Protección de Datos — AEPD's 2020 legal report concluded that facial-recognition technology in private-security video-surveillance is, in principle, prohibited under GDPR as special-category biometric processing, and that the legitimation applicable to plain image/sound-capturing video-surveillance cannot be extended to facial, gait, or voice recognition.
ConfirmedAgencia Española de Protección de Datos — Ley Orgánica 7/2021 provides a distinct data-protection regime for personal data processed for the prevention, detection, investigation and prosecution of criminal offences and execution of criminal penalties, operating alongside the general GDPR/LOPDGDD regime.
Consent-age and parental-consent framework is clear and GDPR-aligned; minor-specific profiling bans and dependent-adult protections beyond general GDPR safeguards were not evidenced in this pass.
Primary frameworkGDPR Art 8 + LOPDGDD Art 7 + LOPDGDD Art 34
Traffic-light rationale — AmberConsent-age and parental-consent framework is clear and GDPR-aligned; minor-specific profiling bans and dependent-adult protections beyond general GDPR safeguards were not evidenced in this pass.
Sub-modules (5)
Age VerificationAmber
AEPD's technical note on 'safe internet by default' for children stresses that age verification alone is insufficient and must be designed to meet all GDPR principles while avoiding new risks (e.g. enabling minors to be located).
Claims: CLM-ES-a7b8c937
Parental ConsentGreen
LOPDGDD Art 7 requires express consent, given by parents/guardians for children under fourteen; those fourteen and above may consent themselves absent a specific rule requiring parental assistance.
Claims: CLM-ES-b8c9d038
Minor Profiling BansAmber
No explicit Spain-specific ban on profiling of minors beyond GDPR's general recitals/Art 22 objection right was identified in this research pass.
Absence provenance: not recorded. Searched: AEPD prohibicion perfilado menores.
Education SettingsGreen
Schools must designate a DPD when GDPR Art 37 criteria apply and, in all cases, when offering teaching at any level under regulating legislation; online classes/exams in regulated education are legitimised without requiring separate consent.
Claims: CLM-ES-c7d8e927
Dependent AdultsAmber
No ES-specific dependent-adult (elderly/mentally incapacitated) data-protection instrument beyond general GDPR safeguards was identified in this research pass.
Absence provenance: not recorded. Searched: AEPD proteccion datos personas dependientes mayores.
Category narrative50 words
LOPDGDD sets the digital age of consent at fourteen, among the lowest permitted under GDPR Art 8's 13-16 range. AEPD publishes extensive guidance on age verification/age-appropriate design ('tudecideseninternet.es'), mandatory DPO designation for schools and youth-data-processing sports federations, and lawful processing of minors' data in regulated education without requiring separate consent.
Sources and claims (2)
ProbableAgencia Española de Protección de Datos — AEPD's technical note on a safe internet by default states that age verification, per se, is not sufficient and must be designed and implemented consistently with all GDPR principles while avoiding new risks such as enabling minors' location to be tracked.
ConfirmedAgencia Española de Protección de Datos — LOPDGDD Art 7 provides that processing of a minor's data may be based on the minor's own consent from age fourteen; below that age, parental or guardian consent is required, and consent must in all cases be express.
Traffic-light rationale — AmberEnforcement activity is vigorous and well-documented, but AEPD's own reporting flags a capacity/resourcing strain relative to caseload growth.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
AEPD exercises Art 58 GDPR corrective powers (reprimand, corrective order, processing bans/limits, fines) through the LOPDGDD sanctioning procedure, governed subsidiarily by LPACAP; decisions are appealable via recurso de reposición or directly to the Audiencia Nacional.
Claims: CLM-ES-d0e1f239, CLM-ES-e1f2a340
Enforcement Activity IndexAmber
2025 saw record enforcement activity: 30,931 complaints filed (+64% YoY), 77 breach-related sanctioning/reprimand procedures (+157% YoY, ≈€19.8m fines), plus headline 2026 fines against Gesternova (€220k) and CaixaBank (€500k/€400k).
AEPD's own 2025 annual report states that growing workload across most subdirectorates has not been matched by proportional staffing growth, a constraint the Agency flags in its 2025-2030 Strategic Plan.
Claims: CLM-ES-b4c5d643
Collective Redress And Class ActionsAmber
No ES-specific GDPR-related collective-redress/class-action mechanism beyond general Spanish civil procedure and EU Representative Actions Directive transposition was evidenced in this research pass.
Absence provenance: not recorded. Searched: AEPD accion colectiva proteccion datos demanda.
Private Right Of ActionAmber
Data subjects and controllers alike may challenge AEPD resolutions via recurso de reposición or directly via recurso contencioso-administrativo before the Audiencia Nacional's Contentious-Administrative Chamber.
Claims: CLM-ES-c4d5e644
Recent Developments 180DAmber
Within the last 180 days: AEPD published its 2025 annual report (May 2026) showing record complaint volumes and sanctioning activity; AEPD confirmed the €500k/€400k CaixaBank fine (March 2026); Spain's Council of Ministers approved a draft Organic Law on AI governance (May 2026); AESIA continued publishing AI guidelines through mid-2026.
AEPD holds full Art 58 GDPR corrective powers (reprimand, order, ban, fine) exercised via LOPDGDD-specific sanctioning procedure (Art 63-65), with decisions appealable to the Audiencia Nacional. 2025 was a record enforcement year: 30,931 complaints (up 64%), breach-related sanctioning procedures up 157% to 77 (≈€19.8m in fines), and headline fines against Gesternova (€220k, Jan 2026) and CaixaBank (€500k/€400k, March 2026). AEPD explicitly flags that workload growth has outpaced staffing increases.
Sources and claims (7)
ConfirmedAgencia Española de Protección de Datos — AEPD sanctioning procedures are governed by GDPR (Regulation (EU) 2016/679), LOPDGDD, its implementing regulatory provisions and, subsidiarily, general Spanish administrative procedure rules.
ConfirmedAgencia Española de Protección de Datos — AEPD resolutions ending the administrative pathway may be challenged via a discretionary recurso de reposición before the AEPD Presidency/Director, or directly via recurso contencioso-administrativo before the Audiencia Nacional's Contentious-Administrative Chamber.
ConfirmedAgencia Española de Protección de Datos — In 2025, AEPD received 30,931 complaints, the highest number in the Agency's history, a 64% increase over the prior year.
ConfirmedAgencia Española de Protección de Datos — AEPD led 47 cross-border cases as lead authority in 2025 (+114% vs 2024) and cooperated as concerned authority in 419 cases (+20%); of 38 Audiencia Nacional judgments on AEPD-resolution appeals in 2025, 76% were dismissed or rejected, i.e. upheld the Agency's decisions.
ConfirmedAgencia Española de Protección de Datos — AEPD's 2025 annual report states that the growing workload reflected across most of its subdirectorates and divisions has not been matched by a proportional increase in staffing, prompting a technology-supported, impact-prioritised supervision strategy under its 2025-2030 Strategic Plan.
ConfirmedAgencia Española de Protección de Datos — Any interested party may lodge a recurso contencioso-administrativo against a final AEPD resolution before the Audiencia Nacional's Contentious-Administrative Chamber within two months of notification.
ConfirmedAgencia Española de Protección de Datos — AEPD presented its Memoria de actuación 2025 on 6 May 2026, disclosing record complaint volumes, a 157% rise in breach-related sanctioning/reprimand procedures, and approximately €19.8 million in resulting fines.
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Spain
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 45 claim(s), 35 source(s) in the cumulative register.