Country:西班牙 · Data Privacy
High confidenceUpdated 2026-08-03Handbook

Spain · Data Privacy

Spain applies the EU GDPR, supplemented by the national LOPDGDD (Organic Law 3/2018), supervised by the AEPD. Fines reach up to 4% of global turnover or €20 million (whichever is higher). Cross-border transfers must be based on an adequacy decision or standard contractual clauses (SCC). Processors without an EU establishment must appoint an EU representative per GDPR Article 27. The AEPD 2025–2030 strategy shifts toward AI-priority and biometric enforcement; Chinese companies must also layer China's PIPL export compliance. In 2024, a Chinese company was fined €1.8 million for transferring EU user data to servers in China without proper grounds.

Key points

Procedure

  1. Inventory processing activities and establish a record of processing (ROPA).
  2. Determine the lawful basis (consent/contract/legal obligation) and publish a Spanish-language privacy policy.
  3. Without an EU establishment, appoint an EU representative per GDPR Article 27.
  4. For cross-border transfers to China, sign SCCs and conduct a TIA, linked to China's PIPL export mechanisms.
  5. Appoint a DPO (if industry triggers apply) and establish data subject request response and 72-hour breach emergency mechanisms.
  6. Camera/biometric processing requires a DPIA and disclosure.

Hard requirements

Costs

Compliance consulting, DPO, and EU representative.DPIA and SCC costsExtremely high violation fine risk⏱ ⏱ Timeline:Compliance system building takes 1–2 months; DPO registration must be completed within 10 days.

⚠ Common risks

  • Returning EU user data to China without SCCs constitutes a violation (already a €1.8 million precedent)
  • AEPD enforcement is the most active; companies of all sizes may be investigated
  • AI and biometrics are priority enforcement areas for 2025–2030; failing to conduct a DPIA is high-risk
  • GDPR and PIPL obligations intersect; a unified cross-border transfer plan is required
Handbook

📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)

Applies to:Chinese companies processing EU residents' personal data in Spain (EU), or providing goods/services to Spanish users and monitoring their behavior without a Spanish establishment, and transferring data back to China (subject to GDPR and LOPDGDD).

Prerequisites

  • Determine whether GDPR extraterritorial application applies (services or monitoring of EU data subjects)
  • Without an EU establishment, appoint an EU representative (GDPR Article 27)
  • Assess whether DPO appointment obligations are triggered (16 industries listed by LOPDGDD)
StepActionOwnerTimelineCostOfficial form / systemNotes & penalties
1Inventory processing activities and establish a ROPA.
Map processing purposes, legal bases, data categories, and recipients; establish a record of processing (ROPA).
Legal/Compliance2–3 weeksInternal costROPA, data inventoryRequired by GDPR Article 30.
Penalty:Up to 4% of global turnover or €20 million.
2Determine the lawful basis and publish a Spanish-language privacy policy.
Determine the lawful basis under GDPR (consent/contract/legitimate interest, etc.) and publish a Spanish-language privacy policy and notice.
Legal1–2 weeksInternal and translation costsSpanish-language privacy policyAge of consent is 14.
Penalty:Same ceiling as step 1.
3Without an EU establishment, appoint an EU representative (Article 27).
Designate a representative in the EU, authorized in writing, as the contact point for regulators and data subjects.
Management/Legal1–2 weeksRepresentative service feesEU representative authorizationThe 2026 Yoti case confirmed fines on companies without a Spanish establishment.
Penalty:Missing representation can lead to rectification orders and fines.
4Cross-border transfer to China: SCC + TIA.
Sign standard contractual clauses (SCC) and conduct a transfer impact assessment (TIA); simultaneously handle China-side PIPL export mechanisms.
Legal3–6 weeksInternal and lawyer feesSCC, TIA, PIPL export documentsChina has no adequacy determination.
Penalty:Heavy fines without a lawful transfer mechanism (already a €1.8 million precedent).
5Appoint a Data Protection Officer (DPO) and register with the AEPD.
Triggering industries (insurance, telecom, finance, healthcare, schools, etc., 16 categories) must appoint a DPO and register with the AEPD within 10 days of appointment.
ManagementMust register within 10 daysDPO staffingDPO appointment and AEPD registrationMust perform duties independently.
Penalty:Failure to appoint or late registration is penalized.
6Report data breaches within 72 hours.
Personal data breaches must be reported to the AEPD within 72 hours; data subjects must be notified in high-risk cases.
DPO/ITWithin 72 hoursInternal costAEPD breach reportAI/biometrics are priority enforcement areas for 2025–2030.
Penalty:Concealment or late reporting is heavily penalized.
7High-risk processing requires a DPIA and continuous compliance.
High-risk processing such as cameras and biometrics requires a DPIA with disclosure, plus annual reviews and training.
ComplianceAnnualInternal costDPIA and annual auditAEPD enforcement is the most active in the EU.
Penalty:Continuous violations accumulate.

✅ Self-check list

⚠ Common pitfalls

Returning EU user data to China without SCCs影响:Heavy fines (already a €1.8 million precedent)规避:Sign SCCs and conduct a TIA
Ignoring EU representative duty without a Spanish establishment影响:Rectification orders and fines规避:Appoint a representative per Article 27
DPO-triggering industries not registered within 10 days影响:Late registration penalized规避:Register with the AEPD upon appointment
Biometric/AI processing without a DPIA影响:Priority high-risk enforcement area for AEPD规避:Conduct a DPIA with disclosure in advance
Ignoring PIPL export when returning data to China影响:Double-violation situation规避:Handle China-side compliance mechanisms in parallel
Misusing the default age of consent of 16影响:Consent invalid规避:Spain's legal age is 14

📅 Ongoing post-incorporation obligations

  • DPO registration and maintenance (where applicable)
  • EU representative continues to serve
  • Notify the AEPD of data breaches within 72 hours
  • SCC/TIA and China PIPL export mechanisms remain effective
  • Annual review, DPIA updates, and training

🔗 Official portals

📎 Source:EU GDPR (Reg. 2016/679); Spanish Organic Law 3/2018 LOPDGDD (Personal Data Protection and Digital Rights Guarantee); Spanish Data Protection Agency AEPD; Linklaters Data Protected Spain (2026-05); https://www.cac.gov.cn
Want to turn this into an actionable compliance workflow?

CompliGo · Outbound Compliance Automation

You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.

CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.