Law / Spain

AEPD Enforcement, GDPR Article 82 and LOPDGDD Título IX

Regulation (EU) 2016/679, Arts. 82-83; LOPDGDD, Art. 47, Arts. 70-78

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 25 May 2018, effective 7 December 2018.

An enforcement supervision rule binding public and private bodies.

As of 2 September 2026.

What it requires

  • Expect the AEPD to sort a violation into a muy grave, grave, or leve infraction tied to a General Data Protection Regulation (GDPR) Article 83 fine tier when assessing exposure for processing personal data of a person in Spain.
  • Expect any person in Spain who suffered material or non-material damage from an infringement to have a direct GDPR Article 82 right to compensation from you as controller or processor.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Codigo Penal (Ley Organica 10/1995) Article 197, outside the LOPDGDD entirely, criminalises unauthorised interference with recorded personal data. Article 197(2) punishes, with the same penalty as paragraph 1 (imprisonment of one to four years and a fine of twelve to twenty-four months), a person who, without authorisation and to the detriment of a third party, seizes, uses, or modifies reserved personal or family data of another recorded in a computerised, electronic, or telematic file or medium, or in any other public or private archive or register, and imposes the same penalty on a person who accesses such data by any means without authorisation, or who alters or uses the data to the detriment of the data subject or a third party. Article 197(3) raises the penalty to two to five years' imprisonment where the data or discovered facts are disseminated, revealed, or transferred to third parties. Article 197(4) raises it further to three to five years where the offender is the person in charge of or responsible for the file, or where the offence is carried out through unauthorised use of the victim's personal data, with the upper half of the range applying if the data was also disseminated or transferred. Article 197(5) applies the upper half of the range where the data reveals ideology, religion, beliefs, health, racial origin, or sexual life, or where the victim is a minor or a person with a disability needing special protection, and Article 197(6) applies the upper half, or four to seven years where sensitive data under paragraph 5 is also involved, where the offence is committed for profit.

Penalty structure

GDPR Article 83(5) sets the higher administrative-fine tier the AEPD applies, up to EUR 20,000,000 or 4 percent of total worldwide annual turnover of the preceding financial year, whichever is higher; Article 83(4) sets the narrower EUR 10,000,000 or 2 percent tier. LOPDGDD (Ley Organica 3/2018) Title IX does not restate these figures with a different Spanish ceiling; instead its Article 71 defines an infraction as any conduct within GDPR Article 83(4) to (6) or the LOPDGDD itself, and Articles 72 to 74 classify infractions as very serious (muy graves, tied to Article 83(5)), serious (graves, tied to Article 83(4)), or minor (leves), a classification that under Article 78 sets the sanction's own limitation period (one year for a fine of EUR 40,000 or less, longer for larger fines) rather than a separate monetary cap.

Rule
Higher of
As of
2 September 2026
Currency
EUR
Fixed cap
20,000,000
Turnover percentage cap
4

Who enforces it

Enforcement body

Agencia Espanola de Proteccion de Datos (AEPD), Spain's national supervisory authority, exercising the GDPR Article 57 functions and Article 58 powers. Several autonomous communities (among them Catalonia, the Basque Country, and Andalusia) maintain their own regional data protection authorities with jurisdiction over their own regional and local public-sector bodies; LOPDGDD Article 47 recognises both the AEPD and these autoridades autonomicas as competent to approve binding corporate rules.

What it reaches

Obligation class

Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The AEPD is Spain's supervisory authority; LOPDGDD Titulo IX (Arts. 70-78) sorts infractions into muy graves, graves, and leves, each defined by direct cross-reference to a General Data Protection Regulation (GDPR) Article 83 tier rather than an independent Spanish fine scale, confirmed against the text. GDPR Article 82 arms an individual with a direct private right of action.

The specific Spanish instrument transposing the EU Representative Actions Directive for collective data-protection claims is not confirmed; LOPDGDD's own Disposicion final septima only modifies a narrow amicus provision, not a class-action mechanism.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • processes_voice
  • automated_outreach
  • high_risk_decisions

Read the law

GDPR Arts. 82-83
LOPDGDD Art. 47, Arts. 70-78

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app