EnglishEspañol
Spain flag

Spain

Spain Data Privacy Laws: GDPR, LOPDGDD & AEPD Enforcement Guide (2026)

By Recording Law Editorial TeamReviewed May 20, 202622 min read
Spain Data Privacy Laws: GDPR, LOPDGDD & AEPD Enforcement Guide (2026)

Frequently Asked Questions

How does Spain's LOPDGDD differ from the standard GDPR?

The LOPDGDD (Organic Law 3/2018) adapts the GDPR to Spain and adds provisions the GDPR leaves to member states. The most significant differences are: the age of digital consent is set at 14 (the GDPR default is 16, and proposed legislation would raise it back to 16); Data Protection Officers are mandatory for 16 specific sectors regardless of company size; Title X creates a charter of digital rights covering internet neutrality, the right to digital disconnection from work, digital wills, and the right to be forgotten on social networks; and deceased persons' data rights are codified in a way the GDPR excludes.

What is AESIA and how does it relate to the AEPD?

AESIA (Agencia Espanola de Supervision de la Inteligencia Artificial) is Spain's national AI supervisory authority, established in 2023 and operational since June 2024. It is the first dedicated national AI regulator in the EU. AESIA oversees compliance with the EU AI Act, runs regulatory sandboxes for high-risk AI systems, and publishes compliance guidance. The AEPD remains responsible for data protection under the GDPR and LOPDGDD. The two agencies coordinate on cases where AI systems process personal data, which includes most biometric, profiling, and decision-making AI applications.

What are the penalties for violating data privacy laws in Spain?

Spain classifies violations into three tiers. Minor infractions carry fines up to 40,000 euros with a one-year statute of limitations. Serious infractions carry fines between 40,001 and 300,000 euros with a two-year period. Very serious infractions can reach 20 million euros or 4% of global annual turnover (whichever is higher) with a three-year limitation. In 2025, the AEPD issued approximately 40 million euros in total fines across 299 sanctions, including a 10 million euro fine against Aena for biometric boarding systems at airports.

What is the right to digital disconnection in Spain?

Article 88 of the LOPDGDD gives workers in both the public and private sectors the legal right not to respond to work-related digital communications outside their contracted working hours. Employers must respect rest periods, holidays, and personal time. Organizations must develop an internal digital disconnection policy in consultation with employee representatives, specifying permissible contact channels and hours, and must provide training on the right. Failure to implement this policy can be treated as an aggravating factor in AEPD proceedings involving workplace monitoring.

How do I report a data breach to the AEPD?

Breaches likely to result in risk to individuals must be reported to the AEPD within 72 hours of discovery. Notifications are filed electronically through the AEPD's Electronic Office using the official breach notification form. The report must cover the nature of the breach, the number of affected individuals, likely consequences, and corrective measures taken or planned. The AEPD provides two free tools: ASESORA BRECHA for determining whether notification is required, and COMUNICA-BRECHA RGPD for evaluating whether affected individuals must also be notified directly. All breaches, including those below the notification threshold, must be documented internally.

Can employers use video surveillance to monitor employees in Spain?

Yes, with strict conditions under LOPDGDD Article 89. Employers must inform employees in advance, cameras are prohibited in rest areas, changing rooms, and dining areas, and audio surveillance is generally forbidden. Recorded footage may only be retained for one month unless it constitutes evidence of unlawful conduct. The surveillance must be proportionate to the purpose. In exceptional cases where there is well-founded suspicion of unlawful behavior, employers may proceed under a reduced notice obligation, but covert surveillance for routine monitoring is not permitted.

Does Spain's LOPDGDD apply to companies outside Spain?

Yes. The LOPDGDD applies to any organization established in Spain that processes personal data, and also to organizations established outside the EU that offer goods or services to people in Spain or monitor their behavior. This is the GDPR's territorial scope rule, which the LOPDGDD inherits. Non-EU companies must appoint an EU representative under GDPR Article 27 if they fall within the regulation's territorial scope. The AEPD has opened proceedings against organizations with no Spanish establishment based on GDPR territorial reach.

Updates

Full refresh: added AESIA and EU AI Act section, expanded enforcement case studies (Aena 10M euros, FC Barcelona 500K, Yoti 950K), updated AEPD 2025 statistics (40M euros, 299 sanctions), added AEPD Strategic Plan 2025-2030, added minors digital environment draft law, expanded cross-border transfers and ePrivacy sections, added internal links to EU data privacy and Spain recording laws.

Sources and References

  1. Boletin Oficial del Estado - Spanish Constitution (Article 18.4)(boe.es).gov
  2. Boletin Oficial del Estado - Ley Organica 3/2018, LOPDGDD(boe.es).gov
  3. Agencia Espanola de Proteccion de Datos (AEPD) - Official Website(aepd.es).gov
  4. AEPD - Notification of a Personal Data Breach to the Supervisory Authority(aepd.es).gov
  5. Agencia Espanola de Supervision de la Inteligencia Artificial (AESIA)(aesia.digital.gob.es).gov
  6. AESIA - Guidelines Published to Support Compliance with the AI Act (December 2025)(aesia.digital.gob.es).gov
  7. EU AI Act - Regulation 2024/1689(eur-lex.europa.eu).gov
  8. European Data Protection Board - AEPD Imposes Fine of 6,000,000 EUR on CaixaBank(edpb.europa.eu).gov
  9. European Data Protection Board - Spanish DPA Fines Vodafone Spain More Than 8 Million Euros(edpb.europa.eu).gov
  10. Biometric Update - Spanish Airport Operator Aena Fined Over Biometric Boarding Program(biometricupdate.com)
  11. Biometric Update - Spain AEPD Fines Yoti 950,000 Euros for Biometric Data Handling Violations(biometricupdate.com)
  12. PPC Land - Spain Fines FC Barcelona 500,000 Euros for Failing Biometric DPIA(ppc.land)
  13. Linklaters - The Spanish Data Watchdog Ramps Up Enforcement with Fines Totalling Over 35.5 Million in FY24(techinsights.linklaters.com)
  14. Linklaters - Spain 2025 Data Breach Landscape: 2,765 Notifications(techinsights.linklaters.com)
  15. ECIJA - More Sanctions and Higher Fines: The AEPD Raises the Level of Fines in 2025(ecija.com)
  16. Linklaters - Spain La Liga Fine for Microphone Access Upheld(linklaters.com)
  17. PPC Land - AEPD Orders Informa D&B to Delete 1.8 Million Worth of Records(ppc.land)
  18. activeMind.legal - Data Protection Officer Under Spanish Law(activemind.legal)
  19. GDPRhub - Data Protection in Spain(gdprhub.eu)
  20. Osborne Clarke - LOPDGDD Enters into Force in Spain(osborneclarke.com)
  21. LOPDGDD Full Text (English Translation) - Organic Law 3/2018(uspceu.com)
  22. Pinsent Masons - Spain Legislates for First EU AI Act Regulatory Sandbox(pinsentmasons.com)
Share: