As it does every year, the Spanish Data Protection Agency (AEPD) has published its annual activity report. Among other matters, the document covers its participation in international forums, privacy challenges, the most relevant reports of the year and an analysis of regulatory trends.
With regard to its supervisory powers, the report shows that in 2025 a total of 30,931 complaints were submitted, representing a 64% increase compared with 2024 and the highest number of complaints in the history of the AEPD. This is not an isolated event, but rather a trend. The increase is due to greater public knowledge and awareness both of individuals’ rights and of the possibility of filing complaints.
In view of the increased complexity and scope of processing operations and, therefore, the impact of infringements on individuals’ rights and freedoms, the average amount of fines has increased by 17%, reaching €148,000 in 2025.
The six areas of activity with the highest number of sanctioning procedures and warnings are: (i) Internet services, (ii) video surveillance, (iii) personal data breaches, (iv) public administrations, (v) commerce, transport and hospitality, and (vi) healthcare.
The AEPD highlights that complaints which may initially appear to relate to isolated incidents often reveal a general way of operating that is not adapted to the regulations. Complaints show real and potential risks for all customers or users of the sanctioned controllers.
In addition, the AEPD notes that cases relating to security breaches have had a significant presence and highlight “the importance of safeguarding data security”.
Among the most relevant complaints and proceedings presented by the AEPD, particular attention should be paid to those cases involving poor management of relationships between controllers and processors, such as the absence of a contractual relationship or failure to establish the necessary security measures.
All of this demonstrates the importance of compliance by design and by default. To achieve this, it is essential to have a detailed understanding of the processing operations carried out in order to integrate the necessary safeguards.
At DATAX, we offer a 360-degree service that analyses the client’s data processing operations and organisational structure. This analysis enables us to identify the risks faced by the organisation and establish security measures to mitigate them.





