GDPR and Data Protection Lawyer in Spain

The Spanish Data Protection Agency (AEPD) imposed EUR 48 million in fines in 2025. Does your company comply with the GDPR?

We help you comply with the GDPR and the Spanish Data Protection Act (LOPDGDD) before you receive a request from the AEPD. If your platform, app or digital service processes personal data at scale, you need a solid compliance plan.

Request a free initial assessment. We’ll give you an initial risk audit, an action plan and a quote tailored to your project.

No commitment · We reply the same day

    YEARS OF EXPERIENCE

    + 0

    CLIENTS ADVISED

    + 0

    PROJECTS COMPLETED

    + 0

    PRACTICE AREAS

    + 0

    WHAT SETS US APART

    We Understand Your Tech Stack, Not Just the Law

    We reply the same day

    DATA PROTECTION LEGAL SERVICES

    What Does Your Company Need?

    We anticipate and identify risks, providing focused legal advice to comply with the GDPR and the LOPDGDD in complex technology environments.

    We implement GDPR and LOPDGDD compliance programmes adapted to innovation environments: startups, SaaS platforms, apps and digital services that process personal data at scale. Records of processing activities, legal bases, impact assessments and technical documentation.

    We review your platform, app or digital service end to end: forms, cookies, third-party SDKs, API integrations and consent flows. We detect compliance gaps before the AEPD does.

    We map every supplier that accesses personal data in your value chain: hosting, analytics, CRMs, payment gateways and AI tools. We review data processing agreements and assess international data transfers.

    We advise on users’ digital rights in virtual environments, including digital identity, data portability, the right to be forgotten and the regulation of algorithmic profiling on platforms.

    We handle AEPD requests and inspections, design protocols to notify security breaches within 72 hours and represent you in penalty proceedings.

    SECTORS AND COMPANIES

    Does Your Company Process Personal Data at Scale?

    If your company operates in any of the following sectors, we can help you.

    SaaS and Platforms

    Large-scale processing of user data

    Fintech

    Financial data and credit scoring

    Digital Health

    Clinical and patient data

    eCommerce and Marketplaces

    Purchase and behavioural data

    Startups and Scaleups

    Scaling with data from day one

    PROCESS AND TIMELINES

    How We Work

    From the first call to compliance, in 4 steps

    1 –

    Initial assessment

    We audit your platform or digital service: what data you process, on what legal basis, which suppliers access it and where the compliance gaps are. Free of charge and with no commitment.

    2 –

    Risk assessment

    We identify specific risks: poorly configured consents, international transfers without safeguards, incomplete processor agreements and potential security breaches.

    3 –

    Compliance plan

    We design privacy policies, supplier contracts, data subject rights protocols, breach notification procedures and all the documentation the GDPR requires.

    4 –

    Ongoing support

    We monitor compliance on an ongoing basis and update the documentation whenever your processes, suppliers or the applicable regulations change.

    REVIEWS AND RATINGS

    What Our Clients Say

    Reviews from real clients and companies about our data protection and privacy services.

    Dimas Pérez
    1 review
    Marta combines impeccable professionalism with a remarkable ability to explain complex legal concepts in simple terms...
    Roberto Fernandez
    3 reviews
    Impeccable personal attention, availability and human touch. Broad knowledge and experience in the sector. Outstanding at solving problems. 100% recommended...
    Alina
    1 review
    I have no words to express my sincere gratitude. Marta is a very dedicated and empathetic professional. She also works fast...
    Gregorio Gigorro
    1 review
    Thank you so much, Marta, for your invaluable advice. Without your knowledge of NFT technology in the art market, a new and promising field but one exposed to a lot of fraud, I would have got myself into serious trouble. Marta …

    REGULATORY FRAMEWORK

    Data Protection Regulation in Spain and the European Union

    The General Data Protection Regulation (GDPR) is the EU law that has governed the processing of personal data since May 2018. In Spain, Organic Law 3/2018 on Data Protection and the Guarantee of Digital Rights (LOPDGDD) supplements and develops the GDPR.

    Every company that processes personal data must comply with both. This includes keeping a record of processing activities, appointing a Data Protection Officer where mandatory, carrying out impact assessments for high-risk processing, signing data processing agreements with every supplier that accesses data and notifying security breaches to the AEPD within 72 hours at most.

    Fines for non-compliance can reach EUR 20 million or 4% of total worldwide annual turnover. In 2025, the AEPD imposed fines totalling EUR 48.1 million, and security breaches accounted for 40% of that amount. Complaints received rose by 64% compared with 2024.

    The Spanish Data Protection Agency (AEPD) is the competent supervisory authority in Spain. It handles complaints, carries out inspections and exercises the power to impose penalties in data protection matters.

    FAQ

    Frequently Asked Questions on Data Protection and the GDPR

    Every company that processes personal data must comply with the GDPR and the LOPDGDD. The main obligations include: keeping a record of processing activities, informing data subjects about how their data is used, obtaining valid consent where it is the applicable legal basis, signing data processing agreements with suppliers, implementing appropriate technical and organisational security measures, and having a procedure to handle the exercise of rights (access, rectification, erasure, portability, objection and restriction).

    The GDPR sets two levels of fines. Up to EUR 10 million or 2% of total worldwide annual turnover for infringements such as not keeping a record of processing activities or not notifying a security breach (Article 83(4)), and up to EUR 20 million or 4% for infringements of the principles, the legal bases or data subjects’ rights (Article 83(5)). In both cases, whichever amount is higher applies. The Spanish LOPDGDD classifies infringements as very serious, serious and minor for limitation purposes. In 2025, the AEPD imposed fines totalling EUR 48.1 million.

    Appointing a DPO is mandatory in three cases: when the processing is carried out by a public authority or body, when the core activities require regular and systematic monitoring of data subjects on a large scale, or when special categories of data are processed on a large scale. In addition, the LOPDGDD extends the obligation to professional associations, schools, insurers, private security companies and other sectors listed in its Article 34. Even where it is not mandatory, having an external DPO is a sign of diligence that can mitigate penalties.

    A data protection impact assessment (DPIA) is a prior analysis that is mandatory when processing is likely to result in a high risk to people’s rights. It is required when new technologies are used, data is processed on a large scale, automated profiling is carried out or special categories of data are processed. The AEPD has published a list of processing operations that require a DPIA in Spain. Failing to carry out a mandatory DPIA is a serious infringement.

    Don’t ignore the request or let the response deadline pass. The first step is to identify what kind of procedure the AEPD has opened (preliminary investigation, penalty proceedings or rights protection procedure) and how long you have to respond. A lawyer can help you prepare the response, provide evidence of compliance and negotiate a reduction of the penalty. If you act diligently and show appropriate security measures, the AEPD may close the case or significantly reduce the fine.

    A compliance provider usually delivers standard, software-generated documentation for a low fixed monthly fee. A lawyer analyses your specific case, understands your technology and your data flows, designs a tailor-made compliance programme and defends you if you face an inspection or a penalty. If your company operates in a complex technology environment (platforms, apps, APIs, large-scale processing), you need a lawyer who understands both the law and your data architecture.

    REQUEST YOUR AUDIT

    Request a free initial assessment and receive an initial risk audit, an action plan and a tailored quote.