gdpr hub

GDPR Hub: your resource centre on the General Data Protection Regulation

Everything you need to comply with the GDPR (Regulation (EU) 2016/679) and the LOPDGDD: legal bases, data subject rights, international transfers, fines, glossary, compliance checker and sector guides.

GDPR · Data protection · LOPDGDD · AEPD · DPO · DPIA · International transfers

We help you adapt your data processing to the GDPR and the LOPDGDD.

TL;DR — The essentials of the GDPR

The General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) is the European regulation governing the processing of personal data. It applies to any controller or processor established in the EU, or offering services to data subjects in the EU. It requires six legal bases (Art. 6), guarantees eight rights to data subjects, mandates security measures (Art. 32), regulates international transfers (Arts. 44-49) and provides for fines of up to €20 million or 4% of global turnover. In Spain it is complemented by the LOPDGDD (Organic Law 3/2018) and the AEPD is the supervisory authority.

Key milestones timeline

The GDPR and its regulatory environment have evolved since 2018. These are the relevant milestones:

25 May 2018 GDPR direct application in all EU Member States
5 Dec 2018 Spanish LOPDGDD (Organic Law 3/2018): Spanish adaptation to the GDPR
16 Jul 2020 CJEU Schrems II ruling: Privacy Shield for US transfers invalidated
10 Jul 2023 EU-US Data Privacy Framework (replaces Privacy Shield)
27 Dec 2023 CJEU Schufa ruling: credit scoring = automated decision (Art. 22 GDPR)

For details on each milestone, see the GDPR glossary and the AI Act vs GDPR comparison.

Key areas of the GDPR

The Regulation is structured around six fundamental areas. Obligations are proportional to the risk of the processing:

Legal bases

Six bases under Art. 6 (consent, contract, legal obligation, vital interests, public task, legitimate interests) plus Art. 9 bases for special data.

Examples: Explicit consent, legitimate interest, contract

Data subject rights

Eight rights: access, rectification, erasure, restriction, portability, objection, no automated decision and complaint to the AEPD.

Examples: Right to be forgotten, portability, objection

Security and breaches

Technical and organisational measures (Art. 32). Breach notification within 72 hours (Art. 33).

Examples: Encryption, pseudonymisation, breach register

International transfers

Countries with adequacy decision or appropriate safeguards: SCCs, BCRs, codes of conduct, certifications.

Examples: SCCs 2021, BCRs, EU-US Framework

DPO and DPIA

Data Protection Officer mandatory in Art. 37 cases. Data Protection Impact Assessment mandatory in Art. 35 cases.

Examples: Internal or external DPO, DPIA

Fines

Up to €20 million or 4% of global turnover (upper level). Up to €10 million or 2% (lower level).

Examples: CaixaBank €6M, BBVA €5M, Vodafone €8M

GDPR resources

Glossary, tools, services and training for Regulation compliance:

Sector GDPR guides

Vertical-specific analyses with use cases, applicable legal bases, rulings and AEPD fines:

Related articles

Frequently asked questions

What is the GDPR and who does it apply to?

The General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) is the European regulation governing the processing of personal data. It applies to any controller or processor established in the EU that processes personal data, or to anyone not established in the EU who offers goods or services to data subjects in the EU or monitors their behaviour. In Spain it is complemented by the LOPDGDD (Organic Law 3/2018).

What is the difference between controller and processor?

The controller (Art. 4(7)) is the entity that determines the purposes and means of processing (e.g. a company collecting customer data). The processor (Art. 4(8)) is the entity that processes data on behalf of the controller (e.g. a cloud provider, a CRM, a marketing agency). The relationship between them is governed by a data processing agreement (Art. 28) that sets out security, confidentiality and sub-processor obligations.

When is a DPO mandatory?

The Data Protection Officer (DPO) is mandatory (Art. 37) when: (a) the processing is carried out by a public authority or body; (b) the controller's core activities consist of processing operations requiring systematic and large-scale assessment (e.g. credit scoring, monitoring); or (c) large-scale processing of special categories of data (health, biometrics) or criminal conviction data. It may be internal or external (DPO as a Service).

When is a Data Protection Impact Assessment (DPIA) mandatory?

A DPIA is mandatory (Art. 35) for high-risk processing, including: systematic and extensive evaluation of personal aspects (scoring), large-scale processing of special categories of data, systematic large-scale monitoring of public areas, or where required by the AEPD. It must document the risk analysis, mitigation measures and residual assessment. It is a prerequisite before starting the processing.

What fines does the GDPR provide for?

The GDPR sets two levels: upper level (up to €20 million or 4% of global annual turnover, whichever is higher) for breaches of basic principles, data subject rights and transfers; lower level (up to €10 million or 2%) for breaches of technical obligations, DPO, breach notification and cooperation with the authority. The AEPD has imposed fines of up to €6 million (CaixaBank, 2021) and €5 million (BBVA, 2020).

How are international data transfers made?

Transfers to countries with an adequacy decision (Japan, Switzerland, United Kingdom, EU-US Framework) require no authorisation. For the rest, appropriate safeguards are needed: Standard Contractual Clauses (SCCs 2021), Binding Corporate Rules (BCRs), codes of conduct or certifications. In addition, a Transfer Impact Assessment (TIA) must be carried out to verify that the country offers an essentially equivalent level of protection (EDPB Recommendations 01/2020).

What is the right not to be subject to automated decisions?

Art. 22 GDPR grants the data subject the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects or similarly significantly affects them. The CJEU confirmed in the Schufa case (2023) that credit scoring constitutes an automated decision under Art. 22. Exceptions: contract, legal authorisation, explicit consent, with additional safeguards.

Which authority supervises the GDPR in Spain?

The Spanish Data Protection Agency (AEPD) is the competent supervisory authority in Spain. At the European level, the European Data Protection Board (EDPB) coordinates enforcement between Member States through the one-stop-shop mechanism (Art. 56). The AEPD publishes sectoral guidance, infringement decisions and maintains a register of fines above €1 million.

Shall we talk?

Tell us about your project and we will help you find the best legal solution for your company.

Let's talk
Contact us