EU Regulation 2016/679 - Decision Register

SUPERVISORY AUTHORITY PROFILE / SPANISH AEPD

Spanish AEPD GDPR Fines, Enforcement Record

The highest-volume GDPR decision-maker in the EU. The Agencia Española de Protección de Datos issues hundreds of sanctioning decisions every year, dominated by small and mid-sized national fines on Spanish controllers.

Annual decisions

~400-600

Largest single fine

€10M (Google LLC 2022)

Complaints (2024)

~18,855

Active since

1993

EDUCATIONAL ONLY

This page is a reference summary of a published regulator decision. It is not legal advice. Consult a qualified data protection lawyer for advice on your specific situation. The UK GDPR is a separate regime from the EU GDPR following Brexit. Always read the source decision in full before relying on any figure or quote.

DIRECT ANSWER / SPANISH AEPD

What is the AEPD, and what is its largest GDPR fine?

The AEPD (Agencia Española de Protección de Datos) is Spain's national data protection authority. By volume it is the most active GDPR regulator in the EU, adopting several hundred sanctioning decisions (resoluciones) a year, the great majority of them small and mid-sized fines against Spanish controllers for cookie-consent, video-surveillance, employment-monitoring and direct-marketing breaches. It publishes its decisions on aepd.es, in Spanish, under references in the form PS/XX/YYYY.

Its largest fine to date is €10 million against Google LLC (18 May 2022), issued under Articles 6 and 17 for transferring users' content-removal data to the Lumen research project without a lawful basis and for an erasure process that defeated the right to be forgotten. Other landmark Spanish decisions include CaixaBank (€6M, 2021) and BBVA (€5M, 2020) on marketing consent, and Mercadona (€2.52M, 2021) for unlawful facial-recognition in its stores.

PROFILE

Mandate and constitution

The Agencia Española de Protección de Datos (AEPD) was established by Organic Law 5/1992 (the precursor to the current framework) and currently operates under Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD), which gives effect to the GDPR in Spanish law. The AEPD is designated as the supervisory authority under Article 51 GDPR for the territory of Spain, and as lead authority under Article 56 for any controller with its main EU establishment in Spain.

The AEPD is an independent public-law authority headquartered in Madrid, with statutory independence from the Spanish executive. The autonomous communities of Catalonia, the Basque Country and Andalusia have their own regional data protection authorities (APDCAT, AVPD, CTPDA) with competence over public-sector processing within their respective territories, but the AEPD remains the authority for the private sector throughout Spain and for public-sector processing in the remaining autonomous communities.

Fining philosophy

The AEPD's defining feature is volume. Where the Irish DPC concludes a handful of high-profile inquiries per year, the AEPD adopts hundreds of sanctioning decisions across the full range of GDPR provisions. The fining philosophy is necessarily different: rather than producing landmark precedents on novel questions, the AEPD's body of decisions provides a granular jurisprudence on how the GDPR applies to recurring SMB-level matters. Practical areas of concentration include video-surveillance compliance (Article 5 minimisation and signage requirements), cookie-consent banners (under Spanish implementation of ePrivacy), employment-monitoring (geolocation, email surveillance, biometric attendance), and direct-marketing breaches (consent and opt-out compliance).

Fine amounts reflect the SMB profile. The Article 83(2) factors of size of the undertaking and financial benefits flowing from the infringement consistently weigh against large fines for small Spanish controllers. The €1,000-€10,000 band is typical for first-offence SMB matters; €50,000-€500,000 for larger Spanish enterprises; €1M-€10M for the largest Spanish corporates (CaixaBank, BBVA, Vodafone España). The AEPD's top-end sanctions are well below the EU-wide highs, but the cumulative deterrent across the SMB base is substantial.

Headline Spanish decisions

Several AEPD decisions have set Spanish-market reference points. The largest to date is Google LLC (€10M, 18 May 2022), sanctioned under Articles 6 and 17 (€5M each) for transferring users' content-removal data to the Lumen research project in the United States without a lawful basis, and for an erasure process that removed content from search while still forwarding the personal data, defeating the right to be forgotten. CaixaBank S.A. (€6M, January 2021) addressed lawful-basis and transparency failures in consent-based marketing processing, applying the AEPD's standard analysis on what constitutes valid consent under the LOPDGDD. BBVA (€5M, December 2020) addressed similar marketing-consent failures plus inadequate response to data-subject access requests. Vodafone España has been the subject of multiple decisions reaching €8M in cumulative amount, addressing direct-marketing consent, contractual processing transparency and breach-notification timeliness.

The Mercadona supermarket-chain decision (€2.52M, July 2021) addressed the use of facial-recognition in supermarket entrance access control. The AEPD found that the processing of biometric data without an Article 9(2) basis was unlawful, and ordered the discontinuation of the technology. The decision is one of the leading early-stage authorities on retail biometrics in the EU.

Larger security cases include I-DE Redes Eléctricas Inteligentes, the Iberdrola Group distribution operator (€3M, April 2024), which the AEPD fined under Articles 5(1)(f) and 32 for failing to assess the security risk behind a 2022 attack on its GEA customer-connection portal that exposed the data of more than 1.5 million clients. Alongside these sit a large body of telemarketing decisions against energy retailers and telecoms providers, and an algorithmic-management line running parallel to the Italian Garante's Foodinho ruling on delivery platforms.

Procedural framework

The AEPD's sanctioning procedure is set out in the LOPDGDD and in the AEPD's Regulation 1/2020 on internal procedure. Decisions follow a structured sequence: admission of the complaint, preliminary investigation (during which the AEPD requests information from the controller), formal initiation of sanctioning proceedings, controller representations, draft decision, controller observations on the draft, and final resolution. Controllers can appeal final decisions to the Audiencia Nacional (the Spanish national court of administrative appeals) and onward to the Supreme Court of Spain.

The AEPD has a notable practice of offering reduced fines for early acknowledgement and remediation: a controller who admits the infringement and pays promptly can obtain reductions of up to 40% on the formally calculated fine. This procedural feature contributes to the high volume of resolved cases and to the SMB-affordable fine distribution.

Role in cross-border inquiries

For Big Tech matters where the lead authority is in Ireland, Luxembourg or France, the AEPD acts as a concerned supervisory authority. It has raised reasoned objections in several major DPC inquiries (including those that escalated to EDPB Article 65 binding decisions). The AEPD's comparative weight in the EDPB cooperation work is significant given the number of Spanish data subjects affected by Big Tech processing.

Recent enforcement trends

The AEPD's 2024-2026 enforcement programme covers AI systems (including a memorandum of understanding with the new Spanish AI Agency on AI Act implementation), employment biometrics (continuing the Mercadona line), telemarketing under the Spanish do-not-call list (Lista Robinson), connected vehicles, and the regulation of consent-management platforms operating in the Spanish market. The AEPD has also been notably active on micro-targeting in political campaigning under LOPDGDD provisions that go beyond the GDPR baseline.

FREQUENTLY ASKED

About the Spanish AEPD

Why does the AEPD issue so many decisions?
Spain's complaint system is unusually accessible: individuals can lodge complaints free of charge and without legal representation, and the AEPD is required to process every admissible complaint. This produces a complaint volume in the tens of thousands per year, which translates into hundreds of formal decisions annually. By decision count, the AEPD is by some margin the most active DPA in the EU.
Why are AEPD fines smaller than DPC fines?
The AEPD's caseload is dominated by national-only matters against Spanish controllers, often SMBs. The Article 83(5) cap (the higher of €20M or 4% of turnover) places a soft ceiling on Spanish SMB fines in the tens of thousands of euros, not the millions. The AEPD's largest fines, including the Mercadona (€2.5M) and CaixaBank decisions, are far below the Big-Tech-scale fines from Ireland and France.
What is the typical AEPD fine size?
The AEPD does not publish a median or 'typical' fine figure. Reading across its published sanctioning decisions (resoluciones), the bulk sit in the low thousands of euros, most often for cookie-consent failures, employment-monitoring infringements, video-surveillance issues and direct-marketing breaches against small businesses. The distribution is heavily right-skewed: a small number of decisions in the high hundreds of thousands or low millions, alongside many in the low thousands. Any single 'typical' figure is a characterisation of that spread, not an AEPD statistic.
Has the AEPD enforced against Big Tech?
Most major Big Tech GDPR matters route through the one-stop-shop to the lead authority (typically Ireland or Luxembourg). The AEPD acts as a concerned authority in those inquiries and has raised reasoned objections to lead-authority drafts (including the Article 65 escalations that led to the WhatsApp, Instagram and TikTok binding decisions). For local Spanish controllers and processors, the AEPD acts directly.
Who heads the AEPD?
The AEPD is led by a President appointed for a five-year term. Mar España Martí held the role from 2015 to 2024; the current President took office in 2024. The AEPD also has an Adjunct Director and a structured set of sub-directorates for enforcement, complaint processing, and international cooperation.
Where can I read AEPD decisions?
The AEPD publishes its decisions on aepd.es. The decisions are typically published in Spanish only, in PDF form, with case references following the format PS/XX/YYYY for sanctioning decisions and EXP/XX/YYYY for other decisions. Summary tables and statistical reporting are also published in the AEPD's annual reports.

CROSS-REFERENCES

Related references

PEER DPA

Irish DPC

Contrast: low decision count, high fine size. The AEPD is the inverse profile.

Open reference →

PEER DPA

French CNIL

Cookie enforcement leader; AEPD adopts similar standards for Spanish market.

Open reference →

PEER DPA

Italian Garante

AI specialism; AEPD parallel work on biometrics and AI.

Open reference →

ARTICLE 7

Consent & Cookies

Doctrinal framework applied across AEPD cookie enforcement.

Open reference →

RELATED

Clearview €20M (Italy)

Biometric processing case; AEPD has parallel work in retail biometrics.

Open reference →

REGISTER

Full Decision Register

Browse fines by country, year, violation type.

Open reference →

SOURCES & CITATIONS

Primary sources

Figures as of September 2026. Verified against published DPA decisions.

REGISTER UPDATED 2026-04-28