ILP Abogados
Madrid · Internacional
=== mojibake pass === fixed 1 × em-dash —

INTELLIGENCE TOOL

Data

GDPR, AI Act and data governance with technology integration for companies processing data at scale.

Turn data protection compliance into a competitive advantage.

Companies processing data at scale need more than a DPO and a record of processing activities. They need real-time visibility over their risks. Our solution integrates GDPR, AI Act and governance into a single platform designed by lawyers.

These tools are free to use. If you are looking for advice on data protection, please see our Data Protection section.
sanciones-aepd.ilpabogados.com
aepd-edpb.ilpabogados.com
exposicion-asnef.ilpabogados.com
gestion-brecha.ilpabogados.com

Automated GDPR audits

Continuous compliance diagnostics with real-time risk dashboard.

AI Act classification

Automatic classification of your AI systems by risk level under the European regulation.

Data governance

Tailored frameworks: inventory of processing activities, legal basis, data flows, controllers.

Breach management

Automated response protocol: detection, assessment, notification to AEPD within the statutory deadline.

The AEPD Sanctions Dashboard allows users to explore the Spanish agency’s sanction decisions by period, including the number of sanctions, average amount, total amount, the most frequently breached article, quarterly trends, aggravating and mitigating factors, and the three largest fines for the period. The AEPD vs EDPB Comparator instantly compares the Spanish authority’s approach with that of the European Data Protection Board on any concept, GDPR article or subject matter, from cookies to data transfers or legitimate interests. These tools are designed for compliance officers, data protection officers and advisers; they provide data and guidance, not a ruling on your specific case.

Understand the result

What does the result mean?

Data on penalties and comparisons of criteria identify the risk; they do not assess it in your specific case.

Articles 5 and 6 of the GDPR
Principles and legal basis
The most frequently cited provisions. In the absence of a valid legal basis, all processing is unlawful.
Article 32 of the GDPR
Safety measures
Inadequate measures are penalised even if a breach does not actually occur.
72 hours
Notification of data breaches
Maximum time limit under Article 33 of the GDPR for notifying the AEPD of a data breach involving a risk.

The relevant legislation is Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD). The data protection impact assessment under Article 35 of the GDPR is mandatory where the processing is likely to result in a high risk to individuals, in particular in relation to profiling with legal effects, large-scale processing of special categories of data and the systematic monitoring of public areas; the AEPD also publishes the list of processing operations for which an impact assessment is required (Article 35(4)).

A high risk is not limited to the EIPD. It requires the measures set out in Article 32 to be strengthened, and consultation with the AEPD if the residual risk remains high (Article 36) and, in the event of a data breach, to report it within a maximum of 72 hours of becoming aware of it (Article 33) and to notify those affected if the risk to their rights is high (Article 34). Every breach, whether reported or not, must be documented.

Seek professional advice when the dashboard shows recurring penalties relating to a provision that affects your operations, when the comparison tool reveals discrepancies between the AEPD and the EDPB on the matter in question, or when you process data on a large scale, special categories of data or data flows outside the European Economic Area.

What should I do if the AEPD and the EDPB do not agree on a particular criterion?

The EDPB’s guidelines are not regulations, but they set out the common interpretation of the GDPR within the EU, and the AEPD applies them as a reference. Where there are differences in interpretation, the prudent course of action for a company operating in Spain is to follow the AEPD’s guidance – as it is the body responsible for investigating and imposing sanctions here – whilst keeping the EDPB’s guidance in mind if the data processing affects several Member States.

In practice, document the decision. The proactive accountability requirement under Article 5(2) of the GDPR means you must be able to demonstrate why a particular interpretation was chosen, which sources were used, and on what date; a dated analysis turns a grey area into a defensible position in the event of an inspection.

Tools assess risk; they do not design compliance measures. If you need to implement the system, manage a data breach or defend yourself before the AEPD, please see our Data Protection section.

Methodology and sources

What they rely on

The Dashboard is compiled from the penalty decisions published by the AEPD, categorised by date, amount, the provision breached (GDPR, Article 22 of the LSSI on cookies and Article 48 of the LOPDGDD on video surveillance) and the circumstances assessed; the indicators are recalculated for the selected period.

The Comparison Tool compares resolutions and reports from the AEPD with the EDPB’s guidelines and opinions on the same concept, article or subject matter. Both tools are updated using official sources; they are intended as a guide and do not replace direct consultation of the sources cited.

Frequently asked questions

What people ask on data protection

When is an impact assessment (EIPD) required?
Where processing may pose a high risk to individuals (Article 35 of the GDPR), and in all cases involving profiling with legal effects, large-scale processing of special categories of data, and the systematic monitoring of public areas. The AEPD publishes the list of processing operations for which this is required.
When is it mandatory to appoint a data protection officer?
Where required by Article 37 of the GDPR (routine and systematic monitoring on a large scale or processing of special categories of data on a large scale) and in the cases set out in Article 34 of the LOPDGDD, including healthcare centres, financial institutions and advertising companies that carry out profiling.
When does the 72-hour period for reporting a data breach begin?
From the moment the data controller becomes aware of the breach, not from the moment it occurred. If notification to the AEPD is made later, the reason for the delay must be explained. Breaches that do not pose a risk do not need to be reported, but all must be documented internally.
Can I transfer personal data outside the European Economic Area?
Only with a safeguard under Chapter V of the GDPR, an adequacy decision, standard contractual clauses with an assessment of the transfer, or binding corporate rules. Using a cloud provider with servers outside the EEA already constitutes an international transfer.
What legal basis do I need to process data?
One of the six grounds set out in Article 6 of the GDPR: consent, contract, legal obligation, vital interests, public interest or legitimate interests. Consent is not always the best option; most of a company’s data processing is based on a contract, a legal obligation or a balanced legitimate interest.
How much are the GDPR fines?
Article 83 of the GDPR sets out two bands: up to 10 million euros or 2 per cent of global annual turnover, and up to 20 million euros or 4 per cent for infringements relating to principles, rights and transfers. The dashboard shows the actual fines imposed by the AEPD for each article.
What is the difference between a data controller and a data processor?
The controller determines the purposes and means; the processor processes the data on the controller’s behalf, such as a payroll or hosting provider (Articles 4(7) and 4(8) of the GDPR). Their relationship requires a data processing agreement under Article 28, and each is accountable for its obligations to the AEPD.

Related analysis

On the blog

José Luis Cobo Aragoneses
Page reviewed by
The Data Protection Department at ILP Abogados, which is responsible for the legal content of this page and author of the blog’s Data Protection Series.
Updated August 2026

Processing personal data at scale? Let’s talk.

Request a personalised demo with no commitment.

Confidential
Response <24h
No commitment