GDPR Compliance and Data Protection Training
Build practical privacy governance knowledge and support stronger operational compliance practices.
The question sounds simple: does my business need a Data Protection Officer?
In most EU countries, the answer for small and medium-sized businesses is usually no — unless you carry out large-scale systematic monitoring or process sensitive data at scale. In Spain, it is considerably more complicated.
Spain has one of the broadest mandatory DPO appointment regimes in the entire EU. Article 34 of the LOPDGDD — Spain's national data protection law — requires DPO appointments across 16 specific sectors, regardless of company size or the scale of processing. A sole trader running a private language academy has the same DPO obligation as a national hospital. A three-person healthcare clinic faces the same requirement as a major insurance corporation.
Most businesses operating in these sectors are unaware of this. And the AEPD has been enforcing it.
This guide explains exactly who needs a DPO in Spain, what the proposed EU Digital Omnibus changes — and critically, what it does not change — and what your business should do depending on where you land.
For the full picture of how GDPR and the LOPDGDD interact for businesses in Spain, start with our pillar guide: EU GDPR Compliance for Businesses: The Complete Guide (2026).
A Data Protection Officer is an independent expert responsible for ensuring your organisation complies with GDPR and Spain's LOPDGDD. The role was created by the GDPR in 2018 and formalised in Spain through the LOPDGDD.
The DPO is not the person responsible for implementing GDPR — that remains the business owner or data controller. The DPO's role is to advise, monitor, and act as the bridge between your organisation, the people whose data you process, and the AEPD.
Under GDPR Article 39, a DPO's core tasks include:
A DPO must be independent — they cannot be instructed on how to perform their tasks, cannot be dismissed for performing them, and must report directly to the highest level of management. Under Spanish law, DPOs employed directly by the organisation receive elevated dismissal protection, except in cases of deliberate fraud or gross negligence.
Crucially, the DPO can be an internal employee or an external service provider. Under GDPR Article 37(6), businesses are explicitly permitted to fulfil the DPO role through an external provider via a service contract. For most Spanish SMEs, an outsourced DPO-as-a-service arrangement is the most practical and cost-effective option.

To determine whether your business needs a DPO in Spain, you need to check two separate legal frameworks — and both can independently trigger the obligation.
Under GDPR Article 37, a DPO is mandatory for any organisation that falls into one of three categories:
Public authorities and public bodies — all government entities, municipalities, and public institutions must appoint a DPO regardless of size.
Organisations whose core activities require large-scale, systematic monitoring of individuals — this includes companies whose primary business model relies on tracking, profiling, or monitoring people. The AEPD's 2020 fine against Glovo — the delivery platform — established clearly that processing thousands of customer profiles and geolocation data daily constitutes large-scale processing, even when the company did not consider itself large. The AEPD found that Glovo breached Article 37(1)(b) of the GDPR because its core activities consisted of processing operations that required regular and systematic monitoring of data subjects on a large scale, based on the number of customers and the personal identifiers processed daily.
Organisations whose core activities involve large-scale processing of special categories of data — this includes health data, biometric data, genetic data, data about criminal convictions, and data revealing racial or ethnic origin, political opinions, religious beliefs, or sexual orientation.
These GDPR thresholds are deliberately broad and intentionally undefined. Terms like "large scale" and "systematic monitoring" are not given precise numbers in the regulation. The EDPB guidelines identify relevant factors — number of individuals affected, volume of data, duration of processing, geographic scope — but the final determination requires legal analysis of your specific operations.

This is where Spain diverges sharply from the rest of the EU.
Article 34 of the LOPDGDD mandates DPO appointments across 16 specific sectors, regardless of company size or the scale of processing. If your organisation falls into any of the categories below, the DPO obligation applies to you automatically — no threshold analysis required, no "large scale" assessment needed.
The mandatory sectors under LOPDGDD Article 34 are:
Professional associations and their governing bodies — this includes medical associations, bar associations, engineering colleges, pharmacy councils, and any other officially recognised professional body.
Educational establishments at all levels, including public and private universities — this includes all schools, universities, and training centres. A small language academy with three teachers faces the same legal DPO requirement as a large hospital. Private tutoring academies, vocational training centres, driving schools that process student data, and language schools all fall within this category.
Telecommunications operators and electronic communications network providers — entities operating networks and providing electronic communications services when they regularly and systematically process personal data on a large scale.
Information society service providers that produce user profiles on a large scale — digital platforms, apps, and online services that build user profiles at scale. This is the category under which Glovo was sanctioned.
Credit institutions — banks, savings banks, credit cooperatives, and similar financial entities regulated under Spanish banking law.
Insurance and reinsurance companies — all licensed insurers and reinsurers, including brokers and intermediaries processing policyholder data.
Investment service companies and collective investment institutions — securities firms, fund managers, and similar financial entities.
Entities responsible for common solvency files — credit reference agencies and organisations that manage debt and solvency databases.
Private security companies — all private security and surveillance firms, including those operating CCTV systems as a core business function.
Sports federations — national and regional sports federations that process member, athlete, and competition data.
Gambling and gaming entities — companies holding gambling licences under Spanish gaming legislation.
Advertising and market research companies that carry out profiling — any organisation whose primary business involves building profiles of individuals for advertising, targeting, or research purposes.
Healthcare centres, establishments, and providers — hospitals, clinics, medical practices, dental clinics, pharmacies, physiotherapy centres, medical laboratories, and any healthcare entity processing patient data. This applies regardless of the number of patients or staff.
Entities managing large-scale mutual social security systems — entities administering occupational pension schemes and similar collective welfare arrangements.
Entities operating critical infrastructure — organisations designated as operators of critical national infrastructure under Spanish security legislation.
Energy distribution companies — electricity and natural gas distributors operating under sector-specific regulation.
This list is not exhaustive of all circumstances where a DPO may be legally required — it represents the sectors where the LOPDGDD creates an automatic, size-independent obligation. Organisations in other sectors may still require a DPO under the GDPR Article 37 criteria described above.

The EU Digital Omnibus, published in November 2025, has received significant attention for its proposed changes to GDPR compliance requirements for smaller businesses. Business owners have asked whether this proposal reduces the DPO obligation for SMEs.
The direct answer is no.
The Digital Omnibus proposals, if adopted, would result in administrative cost savings primarily through extended exemptions for GDPR records of processing activities and lighter compliance regimes for SMEs and small mid-cap companies. The DPO obligation under GDPR Article 37 is not among the provisions targeted for amendment.
More significantly for businesses in Spain, the Digital Omnibus does not propose any changes to national law. The LOPDGDD's 16-sector mandatory DPO list sits in Spanish national legislation — and EU-level proposals do not automatically modify national law. Even if the Digital Omnibus is adopted as proposed, Article 34 of the LOPDGDD will remain unchanged unless the Spanish government introduces separate domestic legislation to amend it.
The Digital Omnibus Package will make its way through the EU's trilogue legislative process, with adoption expected by mid-2026 — but its contents will likely change, and there is no requirement for organisations to implement any changes to their compliance frameworks yet.
For businesses in the 16 mandatory sectors, the DPO obligation is unchanged. For businesses outside those sectors, the GDPR Article 37 criteria are unchanged. The only change being proposed in this area is the ROPA exemption expansion — not DPO requirements.
Failing to appoint a mandatory DPO is a serious infringement under both GDPR and the LOPDGDD — and the AEPD enforces it.
Under Article 73 of the LOPDGDD, not having a DPO in accordance with the requirements of the GDPR may be considered a serious infringement, carrying an administrative penalty of up to €10 million or 2% of the total annual turnover, whichever is higher.
The AEPD's track record confirms this is not theoretical. In June 2020, the AEPD imposed a €25,000 fine on Glovo for failing to appoint a DPO. The AEPD proceedings were initiated following two complaints filed in May and November 2019. Although Glovo communicated the appointment of a DPO to the AEPD on 31 January 2020, the AEPD recognised the proactive action but found it was not sufficient to avoid the fine.
The Glovo case established several principles that remain relevant today:
Appointing a DPO after an investigation begins does not eliminate liability for prior non-compliance. The AEPD explicitly acknowledged Glovo's late appointment but fined the company regardless for the period during which no DPO existed.
An internal committee performing DPO-like functions is not a substitute for a formally appointed DPO. Glovo argued its Data Protection Committee fulfilled all DPO functions. The AEPD rejected this argument because no DPO was formally registered with the agency and no mention appeared in the company's public privacy policy.
The failure to notify the AEPD of the DPO appointment is itself a separate violation. Under Spanish law, controllers and processors must notify the AEPD within ten days of any DPO appointment, modification, or removal — both when the appointment is mandatory and when it is voluntary. Glovo was fined for the failure to appoint and for the failure to notify on time.
Being a repeat offender compounds risk substantially. Once a company has been sanctioned for any GDPR violation, subsequent violations are assessed with an aggravating circumstance that can materially increase fine amounts. A business fined for not having a DPO that later faces any other compliance issue enters the AEPD's process in a structurally worse position.

If you have determined that your business requires a DPO — or have decided to appoint one voluntarily — here is what the process involves.
Step 1 — Identify your DPO. Your DPO can be an existing employee, a newly hired specialist, or an external service provider. The DPO must have expert knowledge of data protection law — both GDPR and the LOPDGDD — and sufficient understanding of your business's processing activities. There is no mandatory certification in Spain, though the AEPD's voluntary Certification Scheme for DPOs (Esquema de Certificación de DPDs, v.1.4) is widely used as a benchmark.
Step 2 — Ensure independence. The DPO must not have a conflict of interest with their compliance oversight role. They cannot simultaneously hold a position that determines the purposes or means of data processing — for example, an IT director who makes decisions about what data to collect cannot also serve as DPO. The Belgian DPA fined a company €50,000 for appointing its Head of Compliance as DPO in a role that created a structural conflict of interest. Outsourcing the DPO role to an external provider is one effective way to guarantee independence.
Step 3 — Formalise the appointment. If using an internal employee, document the appointment formally. If using an external provider, execute a written service contract that defines the scope of the DPO's tasks and access rights.
Step 4 — Notify the AEPD within 10 days. The AEPD maintains an updated electronic register of DPOs, and controllers and processors are required to notify appointments, modifications, and removals within ten days — both for mandatory and voluntary appointments. This notification is made through the AEPD's online portal. Failure to notify is a standalone violation, separate from the obligation to appoint.
Step 5 — Publish the DPO's contact details. The DPO's contact information — typically a dedicated email address — must be published in your privacy policy and any other relevant communications. Individuals exercising their data subject rights may address requests to the DPO directly. The contact details do not need to include the DPO's personal name.
Step 6 — Resource the DPO properly. The DPO must have access to all relevant processing activities, receive adequate training, and be given the time and tools to perform their role. Appointing a DPO nominally but failing to resource them is not a compliance solution — and the AEPD assesses whether DPOs are genuinely functioning in their role when investigating complaints.

If your sector does not appear on the LOPDGDD Article 34 list, and your processing does not meet the GDPR Article 37 thresholds, you are not legally obligated to appoint a DPO. But that does not necessarily mean you should not have one.
Voluntary DPO appointment makes practical sense for businesses that:
If you choose to appoint a DPO voluntarily, you must complete the same steps as those who are obliged to appoint one — including notifying the AEPD — and the DPO must meet the same standards of expertise and independence.
A voluntary DPO appointment also cannot be reversed without notification. If you register a DPO with the AEPD and later remove them without appointing a replacement, that removal must itself be notified within ten days — and if the AEPD subsequently finds your processing actually required a mandatory DPO, the removal creates additional exposure.
For most small and medium-sized businesses in Spain that require a DPO — whether under the mandatory sector list or voluntarily — the outsourced DPO model has become the dominant approach.
An external DPO provides certified expertise, guaranteed independence from internal conflicts of interest, and scalable support without the cost of a full-time hire. The service contract specifies the scope of tasks — which typically includes maintaining the record of processing activities, advising on DPIAs, handling data subject rights requests, monitoring regulatory developments, liaising with the AEPD, and delivering annual compliance reports.
The cost of an outsourced DPO service varies based on the complexity of your processing activities and the level of support required. For a small business in a mandatory sector with straightforward processing, it is typically a fraction of the cost of a single compliance failure. For organisations managing healthcare records, student data, insurance portfolios, or financial data, the legal exposure from non-appointment makes the comparison straightforward.
Spain's approach to DPO obligations is different from the rest of Europe — and significantly broader than most business owners expect. The LOPDGDD's 16-sector mandatory list has no equivalent in most EU member states. And the AEPD has demonstrated, from the Glovo case onwards, that it will sanction organisations that assume exemption without properly assessing their position.
If your business operates in any of the 16 mandatory sectors — education, healthcare, financial services, insurance, private security, advertising that profiles individuals, or any of the others — you need a DPO today. Not when you grow larger. Not when the Digital Omnibus becomes law. Today.
If you are outside those sectors but process significant volumes of personal data, use AI or profiling tools, or handle sensitive data categories, a voluntary DPO appointment is the most effective risk management decision your business can make.
The EU GDPR Compliance and Data Protection for Businesses course from Spanish Compliance Institute covers the DPO obligation in detail — including the LOPDGDD sector requirements, what a DPO does in practice, how to assess whether your business needs one, and 18 downloadable compliance templates you can start using immediately.
Build practical privacy governance knowledge and support stronger operational compliance practices.