Data Protection in Spain: The RGPD, the AEPD and Your Rights (2026)
Data protection in Spain runs on the European regime, applied by a Spanish authority. The rules are the EU's General Data Protection Regulation (the RGPD) and Spain's own law that completes it, and the body that enforces them is the AEPD. This section explains the rights you actually have and the free route to enforce them.
Information last verified on 23 July 2026. This page provides general legal information about Spanish law and does not constitute legal advice in an individual case.
Two laws, one system
Spain does not have a purely national data-protection code. It applies the RGPD, the EU regulation that is directly binding in every member state, together with the LOPDGDD (Ley Orgánica 3/2018), which fills in the areas the regulation leaves to national law. When you read about your data-protection rights in Spain, you are reading the RGPD as completed by the LOPDGDD. Because the general RGPD content is shared across the EU, the deeper explainers for it sit in the EU data privacy pages; these Spain pages focus on how it is applied here and how the AEPD works.
The AEPD: what it does and does not do
The Agencia Española de Protección de Datos is Spain's independent supervisory authority. It handles complaints, investigates, and can sanction a controller that breaks the rules. One point is worth stating clearly because it disappoints people who expect otherwise: the AEPD imposes fines that go to the public treasury, not compensation to you. If you have suffered actual damage, a claim for compensation is a separate matter for the civil courts under RGPD art. 82. The AEPD complaint page explains the reclamación route and this limit.
Your six rights
The RGPD gives you a set of rights you can exercise over your personal data (arts. 15 to 22):
- Access (acceso): to know what data an organisation holds about you.
- Rectification (rectificación): to correct inaccurate data.
- Erasure (supresión): to have data deleted, the "right to be forgotten", where the conditions apply.
- Restriction (limitación): to freeze the processing while a dispute is resolved.
- Portability (portabilidad): to receive your data in a portable format or have it transferred.
- Objection (oposición): to object to certain processing, including direct marketing.
You exercise these free of charge, and the organisation normally has one month to respond.
The route, and the fines behind it
The order matters. You first make your request to the controller, the company or public body holding your data. If it does not answer, or answers inadequately, you escalate to the AEPD with a free complaint.
Behind that sits real enforcement: under RGPD art. 83 the most serious infringements can be fined up to 20 million euros or 4% of a company's total worldwide annual turnover, whichever is higher, with a lower tier of 10 million euros or 2% for other breaches. That is what gives the rights their weight. The details of filing are on the AEPD complaint page.
This page is general legal information about Spanish data-protection law and does not constitute legal advice in an individual case. The controlling texts are the current versions in the BOE and the RGPD.
Frequently Asked Questions
What laws protect personal data in Spain?
Two apply together: the EU's General Data Protection Regulation (RGPD, Reglamento (UE) 2016/679), which is directly binding in Spain, and the Ley Orgánica 3/2018 (LOPDGDD), which completes it in national law. The supervisory authority that enforces them is the Agencia Española de Protección de Datos (AEPD).
What can I ask a company to do with my data?
You have six core rights under the RGPD (arts. 15 to 22): access to your data, rectification of errors, erasure, restriction of processing, portability, and objection to certain uses such as direct marketing. You exercise them free of charge, first with the organisation holding your data, which normally has one month to respond.
Does the AEPD pay compensation?
No. The AEPD investigates complaints and can impose fines, which go to the public treasury, not to you. If you have suffered actual damage from a data-protection breach, a claim for compensation is a separate matter for the civil courts under RGPD art. 82.
How big are data-protection fines in Spain?
Under RGPD art. 83, the most serious infringements can be fined up to 20 million euros or 4% of a company's total worldwide annual turnover, whichever is higher, with a lower tier of 10 million euros or 2% for other breaches. The AEPD applies these in Spain.