Regulation
Data protection for companies: GDPR duties and how to comply
Every company that collects, stores or uses personal data — from clients, employees or suppliers — must comply with the General Data Protection Regulation (GDPR) and with Spain's LOPDGDD, the Ley Orgánica de Protección de Datos y Garantía de los Derechos Digitales (the Spanish data protection act). It makes no difference whether you are a self-employed professional with a mailing list or a company with thousands of records: the obligation is the same.
Penalties for non-compliance can reach €20 million or 4% of annual global turnover. The Agencia Española de Protección de Datos (AEPD), the Spanish data protection authority, has imposed fines of between €10,000 and €50,000 on SMEs for breaches that proper adaptation would have avoided.
What data protection obligations does your company have?
The GDPR and the LOPDGDD set out a group of obligations that every company must meet:
Basic obligations (every company)
- Record of processing activities: document what data is collected, for what purpose, for how long and who has access
- A legal basis for each processing operation: consent, performance of a contract, legitimate interest or another basis under Article 6 GDPR
- Information for the data subject: a clear, accessible and up-to-date privacy policy on the website and in forms
- Contracts with processors: a formal agreement with any supplier that accesses personal data (accountancy firm, hosting, CRM and so on)
- Security measures: protect the data with technical and organisational measures appropriate to the risk
- Breach notification: report any security breach to the AEPD within a maximum of 72 hours
Additional obligations by size and activity
- Data Protection Officer (DPO): mandatory for companies that process data on a large scale, process sensitive data or carry out systematic profiling. Also mandatory for security firms, schools, insurers and the other entities listed in Article 34 LOPDGDD.
- Data protection impact assessment (DPIA): required where the processing entails a high risk to the rights of data subjects
- Whistleblowing channel: from April 2026, companies in Spain with more than 50 employees must have a whistleblowing channel with a designated officer
Not sure whether your company complies? Our consultancy team can run a quick compliance audit.
What are the GDPR and the LOPDGDD?
They are two complementary sets of rules:
| GDPR | LOPDGDD | |
|---|---|---|
| Scope | The whole EU | Spain only |
| Rank | European regulation (directly applicable) | Spanish organic law |
| Adopted | 2016, applicable from 2018 | 2018 (Ley Orgánica 3/2018) |
| Function | General data protection framework | Adapts the GDPR to Spanish law and adds digital rights |
The LOPDGDD does not replace the GDPR; it complements it. It adds Spanish specifics such as the list of entities required to appoint a DPO, the digital rights of employees and the rules on video surveillance and credit information systems.
Penalties: what non-compliance can cost
The AEPD classifies infringements at three levels:
| Type | Maximum fine | Examples |
|---|---|---|
| Minor | Up to €40,000 | No record of processing activities, inadequate information |
| Serious | Up to €300,000 | No DPO where one is required, failure to report breaches within 72h |
| Very serious | Up to €20,000,000 or 4% of turnover | Processing data with no legal basis, unlawful international transfers |
In practice, penalties on SMEs in Spain tend to run between €1,000 and €100,000, depending on the seriousness and the volume of data affected. The cost of adapting to the GDPR is far lower than the cost of a fine.
How to adapt your company to the GDPR step by step
A 6-step adaptation plan
- Take an inventory of your processing operations: list all the personal data the company handles (clients, employees, suppliers, marketing)
- Check the legal basis: confirm that every processing operation has a legitimate basis (consent, contract, legitimate interest)
- Update the information given to data subjects: review the privacy policy, legal notice and cookie policy
- Formalise contracts with processors: make sure every supplier with access to data has a processor agreement
- Put security measures in place: encryption, access control, backups, breach protocols
- Appoint a DPO if required: assess whether the company is obliged to have a Data Protection Officer
Free AEPD tools
The Spanish data protection authority offers free tools to make compliance easier:
- Facilita RGPD: an online questionnaire for low-risk companies
- Gestiona EIPD: a tool for impact assessments
- Comunica Brecha RGPD: a channel for reporting security breaches
Data protection and digital transformation
Data protection is not only a legal obligation — it is an essential part of your company's digital transformation. Any digitalisation project that involves personal data must build in data protection from the outset (privacy by design).
This connects directly with other regulatory obligations your company may have:
- Mandatory electronic invoicing: invoicing data includes personal data
- The NIS2 Directive: cybersecurity measures also protect personal data
- Corporate compliance: the GDPR forms part of the regulatory compliance programme
The investment in adapting to the GDPR can be partly funded with grants for digitalisation in Spain such as Kit Digital (the cybersecurity category) or Kit Consulting.
When is a Data Protection Officer (DPO) mandatory?
A DPO is mandatory for companies that process data on a large scale, process sensitive data or carry out systematic profiling, and for security firms, schools, insurers and the other entities in Article 34 of the LOPDGDD. If your company falls into any of these categories, appointing a DPO is not optional.
What penalties can the AEPD impose for breaching the GDPR?
The AEPD classifies infringements as minor (up to €40,000), serious (up to €300,000) and very serious (up to €20 million or 4% of annual turnover). In practice, fines on SMEs tend to run between €1,000 and €100,000 depending on the seriousness and the volume of data affected.
Next step
GDPR compliance is neither optional nor something to postpone. If your company has not yet fully adapted, the risk of a penalty grows by the day. At Tecnocim Innova we can help you assess your level of compliance, identify the gaps and design an adaptation plan proportionate to the size and risk of your company.
Get in touch for an initial data protection audit.
Related service
Free assessment for companies with revenue above €500,000
Get grant and tax deduction updates by email
Calls, deadlines and regulatory changes, once a month.
Related articles
Regulation
Regulation

