Data protection for companies: GDPR duties and how to comply
Regulation

Data protection for companies: GDPR duties and how to comply

BY TECNOCIM INNOVA   PUBLISHED ON 3 MAY 2026

Every company that collects, stores or uses personal data — from clients, employees or suppliers — must comply with the General Data Protection Regulation (GDPR) and with Spain's LOPDGDD, the Ley Orgánica de Protección de Datos y Garantía de los Derechos Digitales (the Spanish data protection act). It makes no difference whether you are a self-employed professional with a mailing list or a company with thousands of records: the obligation is the same.

Penalties for non-compliance can reach €20 million or 4% of annual global turnover. The Agencia Española de Protección de Datos (AEPD), the Spanish data protection authority, has imposed fines of between €10,000 and €50,000 on SMEs for breaches that proper adaptation would have avoided.

What data protection obligations does your company have?

The GDPR and the LOPDGDD set out a group of obligations that every company must meet:

Basic obligations (every company)

Additional obligations by size and activity

Not sure whether your company complies? Our consultancy team can run a quick compliance audit.

What are the GDPR and the LOPDGDD?

They are two complementary sets of rules:

GDPRLOPDGDD
ScopeThe whole EUSpain only
RankEuropean regulation (directly applicable)Spanish organic law
Adopted2016, applicable from 20182018 (Ley Orgánica 3/2018)
FunctionGeneral data protection frameworkAdapts the GDPR to Spanish law and adds digital rights

The LOPDGDD does not replace the GDPR; it complements it. It adds Spanish specifics such as the list of entities required to appoint a DPO, the digital rights of employees and the rules on video surveillance and credit information systems.

Penalties: what non-compliance can cost

The AEPD classifies infringements at three levels:

TypeMaximum fineExamples
MinorUp to €40,000No record of processing activities, inadequate information
SeriousUp to €300,000No DPO where one is required, failure to report breaches within 72h
Very seriousUp to €20,000,000 or 4% of turnoverProcessing data with no legal basis, unlawful international transfers

In practice, penalties on SMEs in Spain tend to run between €1,000 and €100,000, depending on the seriousness and the volume of data affected. The cost of adapting to the GDPR is far lower than the cost of a fine.

How to adapt your company to the GDPR step by step

A 6-step adaptation plan

  1. Take an inventory of your processing operations: list all the personal data the company handles (clients, employees, suppliers, marketing)
  2. Check the legal basis: confirm that every processing operation has a legitimate basis (consent, contract, legitimate interest)
  3. Update the information given to data subjects: review the privacy policy, legal notice and cookie policy
  4. Formalise contracts with processors: make sure every supplier with access to data has a processor agreement
  5. Put security measures in place: encryption, access control, backups, breach protocols
  6. Appoint a DPO if required: assess whether the company is obliged to have a Data Protection Officer

Free AEPD tools

The Spanish data protection authority offers free tools to make compliance easier:

Data protection and digital transformation

Data protection is not only a legal obligation — it is an essential part of your company's digital transformation. Any digitalisation project that involves personal data must build in data protection from the outset (privacy by design).

This connects directly with other regulatory obligations your company may have:

The investment in adapting to the GDPR can be partly funded with grants for digitalisation in Spain such as Kit Digital (the cybersecurity category) or Kit Consulting.

When is a Data Protection Officer (DPO) mandatory?

A DPO is mandatory for companies that process data on a large scale, process sensitive data or carry out systematic profiling, and for security firms, schools, insurers and the other entities in Article 34 of the LOPDGDD. If your company falls into any of these categories, appointing a DPO is not optional.

What penalties can the AEPD impose for breaching the GDPR?

The AEPD classifies infringements as minor (up to €40,000), serious (up to €300,000) and very serious (up to €20 million or 4% of annual turnover). In practice, fines on SMEs tend to run between €1,000 and €100,000 depending on the seriousness and the volume of data affected.

Next step

GDPR compliance is neither optional nor something to postpone. If your company has not yet fully adapted, the risk of a penalty grows by the day. At Tecnocim Innova we can help you assess your level of compliance, identify the gaps and design an adaptation plan proportionate to the size and risk of your company.

Get in touch for an initial data protection audit.

Related service

Request a free assessment

Free assessment for companies with revenue above €500,000

Get grant and tax deduction updates by email

Calls, deadlines and regulatory changes, once a month.

Get our latest updates

We respect your privacy. No spam.

company data protectionGDPR for companiesLOPDGDDdata protection officer
PreviousDocument management for companies: digitalisation and grants
NextMandatory e-invoicing in Spain: deadlines and requirements

Related articles

Financiado por la Unión Europea - Gobierno de España, Ministerio de Industria y Turismo - Plan de Recuperación, Transformación y Resiliencia - EOI Escuela de Organización Industrial
Programa Activa Industria 4.0Industria Conectada 4.0