Country:西班牙 · Data Privacy
Spain · Data Privacy
Spain applies the EU GDPR, supplemented by the national LOPDGDD (Organic Law 3/2018), supervised by the AEPD. Fines reach up to 4% of global turnover or €20 million (whichever is higher). Cross-border transfers must be based on an adequacy decision or standard contractual clauses (SCC). Processors without an EU establishment must appoint an EU representative per GDPR Article 27. The AEPD 2025–2030 strategy shifts toward AI-priority and biometric enforcement; Chinese companies must also layer China's PIPL export compliance. In 2024, a Chinese company was fined €1.8 million for transferring EU user data to servers in China without proper grounds.
Key points
- Legal framework: GDPR + LOPDGDD (Organic Law 3/2018), supervised by the AEPD (exclusive jurisdiction over the private sector).
- Penalties: up to 4% of global turnover or €20 million (whichever is higher); AEPD issued over a thousand fines in 2024, ranking first in the EU.
- Cross-border transfers: require an adequacy decision for the receiving country, or SCC / binding corporate rules (BCR); transfers to China require a lawful mechanism and a transfer impact assessment (TIA).
- DPO: LOPDGDD lists 16 industry categories (insurance, telecom, finance, healthcare, schools, etc.) that must appoint a DPO, registered with the AEPD within 10 days of appointment.
- Digital rights (beyond GDPR): digital disconnection right (no work communications after hours), digital wills of the deceased, age of consent 14 (lower than the GDPR default of 16), employee monitoring must be explicit.
- AEPD 2025–2030 strategy: AI-priority enforcement, biometrics, eIDAS2 digital identity, cross-border transfer enforcement; the 2026 Yoti case confirmed fines can be imposed on companies without a Spanish establishment.
- Breach notification: report to the AEPD within 72 hours; notify data subjects in high-risk cases.
- China data export obligations (pkulaw verified 2026-07): transfers/return of data to China must choose one of security assessment (CAC Order No. 11), standard contract (Order No. 13), or certification (CAC·SAMR Order No. 20, effective 2025-10-14); the 2024–2025 regulatory stance has relaxed — the Provisions on Promoting and Regulating Cross-Border Data Flows (Order No. 16) and the Regulations on Network Data Security Administration (State Council Order No. 790) exempt some situations.
Procedure
- Inventory processing activities and establish a record of processing (ROPA).
- Determine the lawful basis (consent/contract/legal obligation) and publish a Spanish-language privacy policy.
- Without an EU establishment, appoint an EU representative per GDPR Article 27.
- For cross-border transfers to China, sign SCCs and conduct a TIA, linked to China's PIPL export mechanisms.
- Appoint a DPO (if industry triggers apply) and establish data subject request response and 72-hour breach emergency mechanisms.
- Camera/biometric processing requires a DPIA and disclosure.
Hard requirements
- Lawful basis and transparent notice (Spanish).
- Cross-border transfers based on adequacy/SCC plus TIA.
- EU representative (GDPR Article 27, when no local establishment).
- DPO registration and processing records.
Costs
Compliance consulting, DPO, and EU representative.DPIA and SCC costsExtremely high violation fine risk⏱ ⏱ Timeline:Compliance system building takes 1–2 months; DPO registration must be completed within 10 days.⚠ Common risks
- Returning EU user data to China without SCCs constitutes a violation (already a €1.8 million precedent)
- AEPD enforcement is the most active; companies of all sizes may be investigated
- AI and biometrics are priority enforcement areas for 2025–2030; failing to conduct a DPIA is high-risk
- GDPR and PIPL obligations intersect; a unified cross-border transfer plan is required
Handbook
📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)
Applies to:Chinese companies processing EU residents' personal data in Spain (EU), or providing goods/services to Spanish users and monitoring their behavior without a Spanish establishment, and transferring data back to China (subject to GDPR and LOPDGDD).
Prerequisites
- Determine whether GDPR extraterritorial application applies (services or monitoring of EU data subjects)
- Without an EU establishment, appoint an EU representative (GDPR Article 27)
- Assess whether DPO appointment obligations are triggered (16 industries listed by LOPDGDD)
| Step | Action | Owner | Timeline | Cost | Official form / system | Notes & penalties |
|---|---|---|---|---|---|---|
| 1 | Inventory processing activities and establish a ROPA. Map processing purposes, legal bases, data categories, and recipients; establish a record of processing (ROPA). | Legal/Compliance | 2–3 weeks | Internal cost | ROPA, data inventory | Required by GDPR Article 30. Penalty:Up to 4% of global turnover or €20 million. |
| 2 | Determine the lawful basis and publish a Spanish-language privacy policy. Determine the lawful basis under GDPR (consent/contract/legitimate interest, etc.) and publish a Spanish-language privacy policy and notice. | Legal | 1–2 weeks | Internal and translation costs | Spanish-language privacy policy | Age of consent is 14. Penalty:Same ceiling as step 1. |
| 3 | Without an EU establishment, appoint an EU representative (Article 27). Designate a representative in the EU, authorized in writing, as the contact point for regulators and data subjects. | Management/Legal | 1–2 weeks | Representative service fees | EU representative authorization | The 2026 Yoti case confirmed fines on companies without a Spanish establishment. Penalty:Missing representation can lead to rectification orders and fines. |
| 4 | Cross-border transfer to China: SCC + TIA. Sign standard contractual clauses (SCC) and conduct a transfer impact assessment (TIA); simultaneously handle China-side PIPL export mechanisms. | Legal | 3–6 weeks | Internal and lawyer fees | SCC, TIA, PIPL export documents | China has no adequacy determination. Penalty:Heavy fines without a lawful transfer mechanism (already a €1.8 million precedent). |
| 5 | Appoint a Data Protection Officer (DPO) and register with the AEPD. Triggering industries (insurance, telecom, finance, healthcare, schools, etc., 16 categories) must appoint a DPO and register with the AEPD within 10 days of appointment. | Management | Must register within 10 days | DPO staffing | DPO appointment and AEPD registration | Must perform duties independently. Penalty:Failure to appoint or late registration is penalized. |
| 6 | Report data breaches within 72 hours. Personal data breaches must be reported to the AEPD within 72 hours; data subjects must be notified in high-risk cases. | DPO/IT | Within 72 hours | Internal cost | AEPD breach report | AI/biometrics are priority enforcement areas for 2025–2030. Penalty:Concealment or late reporting is heavily penalized. |
| 7 | High-risk processing requires a DPIA and continuous compliance. High-risk processing such as cameras and biometrics requires a DPIA with disclosure, plus annual reviews and training. | Compliance | Annual | Internal cost | DPIA and annual audit | AEPD enforcement is the most active in the EU. Penalty:Continuous violations accumulate. |
✅ Self-check list
⚠ Common pitfalls
Returning EU user data to China without SCCs影响:Heavy fines (already a €1.8 million precedent)规避:Sign SCCs and conduct a TIA
Ignoring EU representative duty without a Spanish establishment影响:Rectification orders and fines规避:Appoint a representative per Article 27
DPO-triggering industries not registered within 10 days影响:Late registration penalized规避:Register with the AEPD upon appointment
Biometric/AI processing without a DPIA影响:Priority high-risk enforcement area for AEPD规避:Conduct a DPIA with disclosure in advance
Ignoring PIPL export when returning data to China影响:Double-violation situation规避:Handle China-side compliance mechanisms in parallel
Misusing the default age of consent of 16影响:Consent invalid规避:Spain's legal age is 14
📅 Ongoing post-incorporation obligations
- DPO registration and maintenance (where applicable)
- EU representative continues to serve
- Notify the AEPD of data breaches within 72 hours
- SCC/TIA and China PIPL export mechanisms remain effective
- Annual review, DPIA updates, and training
🔗 Official portals
📎 Source:EU GDPR (Reg. 2016/679); Spanish Organic Law 3/2018 LOPDGDD (Personal Data Protection and Digital Rights Guarantee); Spanish Data Protection Agency AEPD; Linklaters Data Protected Spain (2026-05); https://www.cac.gov.cn
Want to turn this into an actionable compliance workflow?
CompliGo · Outbound Compliance Automation
You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.
CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.