The RGPD in Spain: How GDPR Applies and How to Use Your Rights (2026)
The RGPD is the same regulation across the European Union, but readers in Spain want to know two practical things: how it applies here, and how to actually use it against a company that is holding or misusing their data. This page focuses on the doing, not the theory.
Information last verified on 23 July 2026. This page provides general legal information about Spanish law and does not constitute legal advice in an individual case.
How the RGPD applies in Spain
The RGPD is an EU regulation, so it applies in Spain directly, without needing to be copied into Spanish law. The LOPDGDD completes it where the regulation left room for national rules, and it went further, adding a catalogue of derechos digitales in its Título X, from disconnection outside working hours to rules on data after death. For the general mechanics of the GDPR that are shared across the EU, the EU data privacy explainers go into the concepts; this page is about exercising them in Spain.
Exercising a right: the practical steps
Using a data-protection right is more approachable than people expect. There is no official form and it is free. In practice you:
- Write to the controller, the company or public body holding your data. Their privacy notice must say how to contact them or their data protection officer.
- Identify yourself and state clearly which right you are exercising, for example access to your data or erasure.
- Keep proof that you sent it and when, because the clock and any later complaint depend on it.
You do not have to explain why, except for the right to object, where you point to your particular situation.
The one-month clock
Timing is where most disputes start. Under RGPD art. 12 the controller must respond without undue delay and within one month of your request. It can extend that by a further two months for particularly complex or numerous requests, but only if it tells you within the first month and explains why.
Silence is not a lawful answer, and a refusal has to be reasoned. If either happens, you have grounds to escalate.
What each right gets you
The rights map onto real problems:
- Getting a copy of what a company knows about you: access.
- Fixing a wrong address, name or record: rectification.
- Having data deleted once there is no lawful reason to keep it: erasure.
- Stopping marketing or profiling you did not want: objection.
- Freezing use of contested data while you argue about it: restriction.
- Moving your data to another provider: portability.
When it does not work: the AEPD
If the controller ignores your request, misses the deadline, or refuses without a good reason, the enforcement route is a free complaint to the AEPD. It is the same authority described in the data protection overview, and the mechanics of filing are on the AEPD complaint page. The right and the remedy are both free, which is the point worth remembering.
This page is general legal information about Spanish data-protection law and does not constitute legal advice in an individual case. The controlling texts are the current versions in the BOE and the RGPD.
Frequently Asked Questions
Is the GDPR the same in Spain?
Yes, the RGPD is an EU regulation and applies directly in Spain. What Spain adds is the LOPDGDD (Ley Orgánica 3/2018), which completes the regulation and introduces a set of digital rights in its Título X. So the core rules are the shared EU ones, applied here by the AEPD.
How do I make a data access request in Spain?
Write to the company or public body holding your data, identify yourself, and state that you are exercising your right of access under the RGPD. There is no official form and it is free. Keep proof of when you sent it, because the one-month response deadline and any later complaint to the AEPD depend on it.
How long does a company have to answer?
One month from your request, under RGPD art. 12. It can extend that by up to two further months for particularly complex or numerous requests, but only if it tells you within the first month and explains why. Silence or an unreasoned refusal are not lawful responses and let you complain to the AEPD.
What is the LOPDGDD?
It is the Ley Orgánica 3/2018 de Protección de Datos Personales y garantía de los derechos digitales, Spain's national law that completes the RGPD. Alongside implementing the regulation, it added a catalogue of digital rights in its Título X, such as the right to disconnect outside working hours and rules on data after a person's death.