INTELLIGENCE TOOL
Data
GDPR, AI Act and data governance with technology integration for companies processing data at scale.
Turn data protection compliance into a competitive advantage.
Companies processing data at scale need more than a DPO and a record of processing activities. They need real-time visibility over their risks. Our solution integrates GDPR, AI Act and governance into a single platform designed by lawyers.
Automated GDPR audits
Continuous compliance diagnostics with real-time risk dashboard.
AI Act classification
Automatic classification of your AI systems by risk level under the European regulation.
Data governance
Tailored frameworks: inventory of processing activities, legal basis, data flows, controllers.
Breach management
Automated response protocol: detection, assessment, notification to AEPD within the statutory deadline.
The AEPD Sanctions Dashboard allows users to explore the Spanish agency’s sanction decisions by period, including the number of sanctions, average amount, total amount, the most frequently breached article, quarterly trends, aggravating and mitigating factors, and the three largest fines for the period. The AEPD vs EDPB Comparator instantly compares the Spanish authority’s approach with that of the European Data Protection Board on any concept, GDPR article or subject matter, from cookies to data transfers or legitimate interests. These tools are designed for compliance officers, data protection officers and advisers; they provide data and guidance, not a ruling on your specific case.
Understand the result
What does the result mean?
Data on penalties and comparisons of criteria identify the risk; they do not assess it in your specific case.
The relevant legislation is Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD). The data protection impact assessment under Article 35 of the GDPR is mandatory where the processing is likely to result in a high risk to individuals, in particular in relation to profiling with legal effects, large-scale processing of special categories of data and the systematic monitoring of public areas; the AEPD also publishes the list of processing operations for which an impact assessment is required (Article 35(4)).
A high risk is not limited to the EIPD. It requires the measures set out in Article 32 to be strengthened, and consultation with the AEPD if the residual risk remains high (Article 36) and, in the event of a data breach, to report it within a maximum of 72 hours of becoming aware of it (Article 33) and to notify those affected if the risk to their rights is high (Article 34). Every breach, whether reported or not, must be documented.
Seek professional advice when the dashboard shows recurring penalties relating to a provision that affects your operations, when the comparison tool reveals discrepancies between the AEPD and the EDPB on the matter in question, or when you process data on a large scale, special categories of data or data flows outside the European Economic Area.
What should I do if the AEPD and the EDPB do not agree on a particular criterion?
The EDPB’s guidelines are not regulations, but they set out the common interpretation of the GDPR within the EU, and the AEPD applies them as a reference. Where there are differences in interpretation, the prudent course of action for a company operating in Spain is to follow the AEPD’s guidance – as it is the body responsible for investigating and imposing sanctions here – whilst keeping the EDPB’s guidance in mind if the data processing affects several Member States.
In practice, document the decision. The proactive accountability requirement under Article 5(2) of the GDPR means you must be able to demonstrate why a particular interpretation was chosen, which sources were used, and on what date; a dated analysis turns a grey area into a defensible position in the event of an inspection.
Tools assess risk; they do not design compliance measures. If you need to implement the system, manage a data breach or defend yourself before the AEPD, please see our Data Protection section.
Methodology and sources
What they rely on
The Dashboard is compiled from the penalty decisions published by the AEPD, categorised by date, amount, the provision breached (GDPR, Article 22 of the LSSI on cookies and Article 48 of the LOPDGDD on video surveillance) and the circumstances assessed; the indicators are recalculated for the selected period.
The Comparison Tool compares resolutions and reports from the AEPD with the EDPB’s guidelines and opinions on the same concept, article or subject matter. Both tools are updated using official sources; they are intended as a guide and do not replace direct consultation of the sources cited.
Frequently asked questions
What people ask on data protection
When is an impact assessment (EIPD) required?
When is it mandatory to appoint a data protection officer?
When does the 72-hour period for reporting a data breach begin?
Can I transfer personal data outside the European Economic Area?
What legal basis do I need to process data?
How much are the GDPR fines?
What is the difference between a data controller and a data processor?
Related analysis
On the blog
Processing personal data at scale? Let’s talk.
Request a personalised demo with no commitment.
