Spain Data Protection Agency: All What You Need to Know

The Agencia Española de Protección de Datos (AEPD) is Spain's independent data protection authority, established in 1993 and the highest-volume EU DPA with 500+ sanctions per year. Complete 2026 reference covering role, powers, recent enforcement (BBVA €6M, Vodafone €8.15M), LSSI-CE cookie jurisdiction, LOPDGDD interplay, and how to file complaints.
Alaa
By Alaa
SMTPedia documents email infrastructure end to end: SMTP standards from the RFC archive, delivera...
7 min read Updated Jul 29, 2026 100 views

The Agencia Española de Protección de Datos (AEPD) is Spain’s independent data protection authority. Established in 1993 under the Spanish Data Protection Act, it enforces GDPR, the Organic Law on Data Protection and Digital Rights (LOPDGDD, 2018), and the Spanish ePrivacy transposition (LSSI-CE). The AEPD is the highest-volume DPA in the EU by number of decisions, issuing over 500 sanctions per year and disproportionately targeting SMEs for cookie consent, unsolicited marketing, and improper data retention.

Agencia Española de Protección de Datos (AEPD) · Established 15 January 1993 under the original Ley Orgánica 5/1992 · Presidencia held by Mar España Martí until 2023, transitional leadership through 2024, current presidencia active since 2025 · Based at C/ Jorge Juan 6, 28001 Madrid · Independent public authority under the Spanish Constitution Article 18 · Enforces GDPR, LOPDGDD (Organic Law 3/2018), LSSI-CE (Law 34/2002 on Information Society Services), Real Decreto-ley 13/2012 on cookies, and the Spanish Trust Services Act · Max fine: €20M or 4% of global annual turnover.

1993
Operational since January 1993 under the pre-GDPR Spanish Data Protection Act
500+
Sanctions issued per year: highest-volume EU DPA by decision count
€150M
Cumulative fines since 2018: heavy in volume, moderate in per-case ceiling
€6M
BBVA sanction: largest AEPD fine to date across multiple decisions

Role and powers

The AEPD is a public law entity with its own legal personality, funded by the Spanish state budget and reporting to Parliament through annual reports. Its structure combines a Presidencia (chief executive), a Consejo Consultivo (consultative board), and specialised sub-agencies for public sector, telecommunications, and digital rights. Its core mandates are:

  • Enforcement. Investigations, corrective measures, and administrative fines up to €20M or 4% of global annual turnover under GDPR Article 83, plus additional Spanish-specific sanctions under LOPDGDD for domestic infringements.
  • Guidance. The AEPD publishes practical guides and code of conduct approvals. Its cookie guide (2020, updated 2023) and email marketing recommendations are widely referenced across Spanish-speaking markets.
  • Individual redress. The AEPD is the highest-volume DPA in Europe for complaints, handling over 15,000 reclamaciones per year with a fast-track procedure that generally produces a decision within four to six months.
  • Right of exemption. Certain sensitive categories (health, financial, minors) get elevated scrutiny under the LOPDGDD, and the AEPD has issued binding opinions on scholl data processing and adolescent social media use.

Recent enforcement highlights

2020, 2024
BBVA €6M total
SMS marketing without consent (€5M, 2020) plus €1M for privacy policy transparency deficiencies. Both fines upheld on appeal by Spanish courts.
2021, 2023
Vodafone €8.15M
Multiple decisions across four years: unsolicited marketing calls, retention of data on deceased customers, unauthorised use of loyalty programme data.
Ongoing
SME sanctions volume
The AEPD issues hundreds of five-figure sanctions per year against SMEs for cookie consent violations, unsolicited email, and unauthorised data sharing with commercial partners.

Beyond the headline enterprise cases, the AEPD’s monthly bulletin routinely reports 30 to 50 new sanctions in the €1,000 to €30,000 range. Common triggers include cookie banners without a reject-all option, marketing email sent to purchased or scraped lists, WhatsApp Business messages without prior consent, and failure to honour access or erasure requests within one month.

2026 enforcement priorities

SME enforcement machine at full pace. The AEPD’s 2026 priorities target three areas: (1) minors’ privacy on social platforms, backed by the LOPDGDD Article 84 protections; (2) AI training data lawfulness, in coordination with the EU AI Act enforcement starting 2 August 2026; and (3) telecommunications and ISP data handling, particularly around data breach notifications. Ad-tech and cookie consent enforcement continues at pace. Marketing email violations remain the single most common trigger for AEPD action against SMEs, and the agency has publicly stated it will follow the CNIL’s April 2026 email pixel recommendation with equivalent Spanish guidance in H2 2026.

How to file a complaint

  • Submit a reclamación via the AEPD’s online sede electrónica (sedeagpd.gob.es) with the controller’s identifying information, a description of the alleged violation, and any supporting evidence.
  • Prior contact with the controller is not required for a reclamación, unlike Italy’s Garante. However, the AEPD encourages first raising the issue with the controller’s Data Protection Officer.
  • The fast-track procedure produces a decision within 4 to 6 months for standard complaints. Complex or cross-border cases go through the full procedure (up to 12 months).
  • Complaints against non-Spanish EU controllers are transferred to the lead supervisory authority under the GDPR one-stop-shop, though the AEPD retains competence over Spanish-territory-only infringements including LSSI-CE cookie rules.
  • Decisions are published on aepd.es (in Spanish, with English summaries for major cases). The searchable database at aepd.es/resoluciones is one of the most comprehensive DPA registers in the EU.

Common misconceptions

“AEPD only chases small fish.” No. BBVA (€5M then €1M), Vodafone (four separate decisions totalling €8.15M), and Google Spain have all faced multi-million-euro fines. What distinguishes the AEPD from other DPAs is the parallel high-volume SME pipeline, not exclusive focus on smaller organisations.

“LSSI-CE only applies to Spanish-registered companies.” No. LSSI-CE Article 21 applies to any information society service provider operating in Spain, including foreign senders reaching Spanish recipients. Cookie enforcement under LSSI-CE sits outside the GDPR one-stop-shop, giving the AEPD direct jurisdiction over foreign advertisers targeting Spanish users.

“Consent for one Spanish subsidiary covers the whole group.” No. The AEPD has repeatedly sanctioned corporate groups for sharing customer data between subsidiaries without granular consent for each purpose and recipient. Vodafone España €3.94M and Endesa €750,000 both involved improper intra-group data sharing.

“Deleting the record avoids liability for past sends.” No. Article 30 GDPR requires records of processing to be maintained even after individual subject data is deleted. The AEPD frequently penalises controllers for the sending activity itself, independent of whether the data survives to the investigation.

Frequently asked questions

Are there Spanish regional DPAs alongside the AEPD?

Yes, three: the Autoritat Catalana de Protecció de Dades (Catalonia), the Agencia Vasca de Protección de Datos (Basque Country), and the Consejo de Transparencia y Protección de Datos de Andalucía (Andalusia). Their competence is limited to the public sector within their respective autonomous communities. Private-sector processing across all Spanish territory is exclusively handled by the AEPD.

Does the AEPD accept English-language complaints?

Complaints must be submitted in Spanish (Castilian) or a co-official regional language (Catalan, Basque, Galician, Valencian) for the online procedure. The AEPD accepts supporting documents in English or French, but the reclamación itself must be filed in one of the accepted languages. Cross-border complaints from non-Spanish residents routed through the one-stop-shop mechanism can be filed in any EU language via the originating DPA.

What is the difference between LOPDGDD and GDPR?

LOPDGDD is the Spanish Organic Law that transposes and supplements GDPR with domestic rules. It adds seventeen “digital rights” in employment, education, and public services; sets the minimum age for consent at 14; and gives the AEPD additional sanctions competence over Spanish-only infringements. GDPR takes precedence in cases of conflict, but LOPDGDD adds substantive obligations in areas where GDPR left member states discretion.

How aggressive is the AEPD on cross-border cases?

Moderate through the one-stop-shop mechanism, aggressive on Spanish-only violations. The AEPD has repeatedly invoked its direct jurisdiction over LSSI-CE cookie violations to fine multinationals whose lead supervisory authority is elsewhere in the EU. Google (multiple decisions), Meta (Cambridge Analytica-linked complaints), and TikTok have all faced AEPD action independent of the Irish DPC one-stop-shop procedures.

Where can I find AEPD decisions in English?

The AEPD publishes English-language press releases and summaries for major cases at aepd.es/en. Full decision text is Spanish-only. The European Data Protection Board register (edpb.europa.eu) carries English summaries of cross-border decisions. Third-party aggregators including gdprhub.eu also translate selected AEPD decisions.

Where to go next

Sending marketing email into Spain? Pre-validating recipient addresses with SMTPing before you press send catches disposables, catch-alls, and dead mailboxes that generate AEPD complaints. Thirteen validation types, twenty-five free checks daily, no card required. Try SMTPing free.


About the Author

Alaa - SMTPedia author

Alaa · LinkedIn

Email infrastructure specialist with 8+ years of hands-on experience in SMTP, deliverability, and email verification. I’ve configured and troubleshot mail systems across Postfix, Exchange, and cloud relays, managed IP reputation and warmup campaigns, and built verification pipelines processing millions of addresses. My work spans DNS authentication (SPF, DKIM, DMARC, BIMI), bounce handling, blocklist monitoring, and compliance frameworks including CAN-SPAM and GDPR. I write every article on SMTPedia to give email professionals, developers, and marketers the accurate, RFC-grounded reference they need.


About SMTPedia

SMTPedia is an independent email industry reference covering SMTP, IMAP, POP3, email deliverability, marketing platforms, DNS authentication, and email verification. Every article is researched from official provider documentation, IETF RFCs, and industry best practices. Settings and configurations are verified quarterly.

We are cited as a source by ChatGPT, Microsoft Copilot, and thousands of email professionals worldwide. Learn more about our editorial process.