PROFILE
Mandate and constitution
The Agencia Española de Protección de Datos (AEPD) was established by Organic Law 5/1992 (the precursor to the current framework) and currently operates under Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD), which gives effect to the GDPR in Spanish law. The AEPD is designated as the supervisory authority under Article 51 GDPR for the territory of Spain, and as lead authority under Article 56 for any controller with its main EU establishment in Spain.
The AEPD is an independent public-law authority headquartered in Madrid, with statutory independence from the Spanish executive. The autonomous communities of Catalonia, the Basque Country and Andalusia have their own regional data protection authorities (APDCAT, AVPD, CTPDA) with competence over public-sector processing within their respective territories, but the AEPD remains the authority for the private sector throughout Spain and for public-sector processing in the remaining autonomous communities.
Fining philosophy
The AEPD's defining feature is volume. Where the Irish DPC concludes a handful of high-profile inquiries per year, the AEPD adopts hundreds of sanctioning decisions across the full range of GDPR provisions. The fining philosophy is necessarily different: rather than producing landmark precedents on novel questions, the AEPD's body of decisions provides a granular jurisprudence on how the GDPR applies to recurring SMB-level matters. Practical areas of concentration include video-surveillance compliance (Article 5 minimisation and signage requirements), cookie-consent banners (under Spanish implementation of ePrivacy), employment-monitoring (geolocation, email surveillance, biometric attendance), and direct-marketing breaches (consent and opt-out compliance).
Fine amounts reflect the SMB profile. The Article 83(2) factors of size of the undertaking and financial benefits flowing from the infringement consistently weigh against large fines for small Spanish controllers. The AEPD publishes two figures that bound this directly: in 2024 it adopted 281 resolutions carrying a monetary penalty, with those penalties totalling €35,592,200. Dividing one by the other gives an average of roughly €127,000 per fining decision, which is our own arithmetic on the AEPD's two published numbers rather than an AEPD statistic.
That average should be read with care, because it is pulled upwards by a small number of large decisions and the AEPD does not publish a median or a distribution of fine sizes. Its own 2024 sector breakdown shows where the money actually landed: energy and water €11,680,600, financial and credit entities €5,356,900, internet services €4,547,380, telecommunications €3,330,000 and fraudulent contracting €2,538,200. Personal-data-breach matters accounted for €13,179,600, some 37% of the annual total, across 30 procedures. The AEPD's top-end sanctions are well below the EU-wide highs, but the cumulative deterrent across the Spanish controller base is substantial.
Headline Spanish decisions
Several AEPD decisions have set Spanish-market reference points. The largest to date is Google LLC (€10M, 18 May 2022), sanctioned under Articles 6 and 17 (€5M each) for transferring users' content-removal data to the Lumen research project in the United States without a lawful basis, and for an erasure process that removed content from search while still forwarding the personal data, defeating the right to be forgotten. CaixaBank S.A. (€6M, January 2021) addressed lawful-basis and transparency failures in consent-based marketing processing, applying the AEPD's standard analysis on what constitutes valid consent under the LOPDGDD. BBVA (€5M, December 2020) was two linked penalties, one on the transparency of the bank's data protection policy and one on consent for commercial communications. That case then took the longest route of any Spanish decision: the Audiencia Nacional annulled both fines on 23 December 2022 on procedural grounds, holding that the AEPD had strayed beyond the individual complaints that opened the file. The Spanish Supreme Court revoked that ruling and reinstated the fines, holding that where individual complaints share a common origin in a controller's privacy policy, the AEPD may and indeed should bring that document itself within the sanctioning procedure. Vodafone España has been the subject of multiple decisions reaching €8M in cumulative amount, addressing direct-marketing consent, contractual processing transparency and breach-notification timeliness.
The Mercadona supermarket-chain decision (€2.52M, July 2021) addressed the use of facial-recognition in supermarket entrance access control. The AEPD found that the processing of biometric data without an Article 9(2) basis was unlawful, and ordered the discontinuation of the technology. The decision is one of the leading early-stage authorities on retail biometrics in the EU.
Larger security cases include I-DE Redes Eléctricas Inteligentes, the Iberdrola Group distribution operator (€3M, April 2024), which the AEPD fined under Articles 5(1)(f) and 32 for failing to assess the security risk behind a 2022 attack on its GEA customer-connection portal that exposed the data of more than 1.5 million clients. Alongside these sit a large body of telemarketing decisions against energy retailers and telecoms providers, and an algorithmic-management line running parallel to the Italian Garante's Foodinho ruling on delivery platforms.
Procedural framework
The AEPD's sanctioning procedure is set out in the LOPDGDD and in the AEPD's Regulation 1/2020 on internal procedure. Decisions follow a structured sequence: admission of the complaint, preliminary investigation (during which the AEPD requests information from the controller), formal initiation of sanctioning proceedings, controller representations, draft decision, controller observations on the draft, and final resolution. Controllers can appeal final decisions to the Audiencia Nacional (the Spanish national court of administrative appeals) and onward to the Supreme Court of Spain.
The AEPD has a notable practice of offering reduced fines for early acknowledgement and remediation: a controller who admits the infringement and pays promptly can obtain reductions of up to 40% on the formally calculated fine. This procedural feature contributes to the high volume of resolved cases and to the SMB-affordable fine distribution.
Role in cross-border inquiries
For Big Tech matters where the lead authority is in Ireland, Luxembourg or France, the AEPD acts as a concerned supervisory authority. It has raised reasoned objections in several major DPC inquiries (including those that escalated to EDPB Article 65 binding decisions). The AEPD's comparative weight in the EDPB cooperation work is significant given the number of Spanish data subjects affected by Big Tech processing.
Recent enforcement trends
The AEPD's 2024-2026 enforcement programme covers AI systems (including a memorandum of understanding with the new Spanish AI Agency on AI Act implementation), employment biometrics (continuing the Mercadona line), telemarketing under the Spanish do-not-call list (Lista Robinson), connected vehicles, and the regulation of consent-management platforms operating in the Spanish market. The AEPD has also been notably active on micro-targeting in political campaigning under LOPDGDD provisions that go beyond the GDPR baseline.