Sanctioning Powers of the Spanish Data Protection Agency

As it does every year, the Spanish Data Protection Agency (AEPD) has published its annual activity report. Among other matters, the document covers its participation in international forums, privacy challenges, the most relevant reports of the year and an analysis of regulatory trends.

With regard to its supervisory powers, the report shows that in 2025 a total of 30,931 complaints were submitted, representing a 64% increase compared with 2024 and the highest number of complaints in the history of the AEPD. This is not an isolated event, but rather a trend. The increase is due to greater public knowledge and awareness both of individuals’ rights and of the possibility of filing complaints.

In view of the increased complexity and scope of processing operations and, therefore, the impact of infringements on individuals’ rights and freedoms, the average amount of fines has increased by 17%, reaching €148,000 in 2025.

The six areas of activity with the highest number of sanctioning procedures and warnings are: (i) Internet services, (ii) video surveillance, (iii) personal data breaches, (iv) public administrations, (v) commerce, transport and hospitality, and (vi) healthcare.

The AEPD highlights that complaints which may initially appear to relate to isolated incidents often reveal a general way of operating that is not adapted to the regulations. Complaints show real and potential risks for all customers or users of the sanctioned controllers.

In addition, the AEPD notes that cases relating to security breaches have had a significant presence and highlight “the importance of safeguarding data security”.

Among the most relevant complaints and proceedings presented by the AEPD, particular attention should be paid to those cases involving poor management of relationships between controllers and processors, such as the absence of a contractual relationship or failure to establish the necessary security measures.

All of this demonstrates the importance of compliance by design and by default. To achieve this, it is essential to have a detailed understanding of the processing operations carried out in order to integrate the necessary safeguards.

At DATAX, we offer a 360-degree service that analyses the client’s data processing operations and organisational structure. This analysis enables us to identify the risks faced by the organisation and establish security measures to mitigate them.

Datax - Soluciones legales a medida para tu negocio

Barcelona 
Rambla Catalunya 66, 2ªC.
08007 Barcelona
T 93 754 06 88
info@datax.es

Mataró
Edificio Blaumar
C/ de la Bobinadora,  Nº 1-5.
Planta 1, Locales 15 y 17
08302 Mataró
T 93 754 06 88
info@datax.es

Latest Data Protection Updates

Subscribe to Our Newsletter


    PROTECCIÓN DE DATOS DATAX, SLU, as the data controller, will process your data for the purpose of managing your subscription to our newsletter and sending you informative and commercial communications regarding our services. You may access, rectify, and erase your data, as well as exercise other rights, by consulting the additional and detailed data protection information in our Privacy Policy


    Solicitar infoSolicitar info
    Call us
    Contact us
    Datax
    Privacy Overview

    This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.