•

Data Protection Officer in Spain: Who Needs a DPO (2026 Guide)

EV

Elena Vasquez-Moretti

Corporate Data Protection Officer (DPO) evaluating GDPR compliance documents and data charts for a business in Spain.

The question sounds simple: does my business need a Data Protection Officer?

In most EU countries, the answer for small and medium-sized businesses is usually no — unless you carry out large-scale systematic monitoring or process sensitive data at scale. In Spain, it is considerably more complicated.

Spain has one of the broadest mandatory DPO appointment regimes in the entire EU. Article 34 of the LOPDGDD — Spain's national data protection law — requires DPO appointments across 16 specific sectors, regardless of company size or the scale of processing. A sole trader running a private language academy has the same DPO obligation as a national hospital. A three-person healthcare clinic faces the same requirement as a major insurance corporation.

Most businesses operating in these sectors are unaware of this. And the AEPD has been enforcing it.

This guide explains exactly who needs a DPO in Spain, what the proposed EU Digital Omnibus changes — and critically, what it does not change — and what your business should do depending on where you land. 

For the full picture of how GDPR and the LOPDGDD interact for businesses in Spain, start with our pillar guide: EU GDPR Compliance for Businesses: The Complete Guide (2026).

What Is a Data Protection Officer — and What Do They Actually Do?


A Data Protection Officer is an independent expert responsible for ensuring your organisation complies with GDPR and Spain's LOPDGDD. The role was created by the GDPR in 2018 and formalised in Spain through the LOPDGDD.

The DPO is not the person responsible for implementing GDPR — that remains the business owner or data controller. The DPO's role is to advise, monitor, and act as the bridge between your organisation, the people whose data you process, and the AEPD.

Under GDPR Article 39, a DPO's core tasks include:

  • Informing and advising the business and its staff on data protection obligations
  • Monitoring ongoing compliance with GDPR, the LOPDGDD, and internal data protection policies
  • Advising on and monitoring Data Protection Impact Assessments (DPIAs) for high-risk processing
  • Acting as the point of contact with the AEPD for regulatory queries and investigations
  • Handling data subject rights requests directed to the organisation

A DPO must be independent — they cannot be instructed on how to perform their tasks, cannot be dismissed for performing them, and must report directly to the highest level of management. Under Spanish law, DPOs employed directly by the organisation receive elevated dismissal protection, except in cases of deliberate fraud or gross negligence.

Crucially, the DPO can be an internal employee or an external service provider. Under GDPR Article 37(6), businesses are explicitly permitted to fulfil the DPO role through an external provider via a service contract. For most Spanish SMEs, an outsourced DPO-as-a-service arrangement is the most practical and cost-effective option.

Data Protection Officer responsibilities infographic covering GDPR and LOPDGDD compliance duties

The Two Layers: GDPR First, Then the LOPDGDD

To determine whether your business needs a DPO in Spain, you need to check two separate legal frameworks — and both can independently trigger the obligation.

Layer 1: GDPR — The EU Baseline

Under GDPR Article 37, a DPO is mandatory for any organisation that falls into one of three categories:

Public authorities and public bodies — all government entities, municipalities, and public institutions must appoint a DPO regardless of size.

Organisations whose core activities require large-scale, systematic monitoring of individuals — this includes companies whose primary business model relies on tracking, profiling, or monitoring people. The AEPD's 2020 fine against Glovo — the delivery platform — established clearly that processing thousands of customer profiles and geolocation data daily constitutes large-scale processing, even when the company did not consider itself large. The AEPD found that Glovo breached Article 37(1)(b) of the GDPR because its core activities consisted of processing operations that required regular and systematic monitoring of data subjects on a large scale, based on the number of customers and the personal identifiers processed daily.

Organisations whose core activities involve large-scale processing of special categories of data — this includes health data, biometric data, genetic data, data about criminal convictions, and data revealing racial or ethnic origin, political opinions, religious beliefs, or sexual orientation.

These GDPR thresholds are deliberately broad and intentionally undefined. Terms like "large scale" and "systematic monitoring" are not given precise numbers in the regulation. The EDPB guidelines identify relevant factors — number of individuals affected, volume of data, duration of processing, geographic scope — but the final determination requires legal analysis of your specific operations.

GDPR and LOPDGDD decision tree infographic for determining DPO requirements in Spain

Layer 2: The LOPDGDD — Spain's Mandatory Sector List

This is where Spain diverges sharply from the rest of the EU.

Article 34 of the LOPDGDD mandates DPO appointments across 16 specific sectors, regardless of company size or the scale of processing. If your organisation falls into any of the categories below, the DPO obligation applies to you automatically — no threshold analysis required, no "large scale" assessment needed.

The mandatory sectors under LOPDGDD Article 34 are:

Professional associations and their governing bodies — this includes medical associations, bar associations, engineering colleges, pharmacy councils, and any other officially recognised professional body.

Educational establishments at all levels, including public and private universities — this includes all schools, universities, and training centres. A small language academy with three teachers faces the same legal DPO requirement as a large hospital. Private tutoring academies, vocational training centres, driving schools that process student data, and language schools all fall within this category.

Telecommunications operators and electronic communications network providers — entities operating networks and providing electronic communications services when they regularly and systematically process personal data on a large scale.

Information society service providers that produce user profiles on a large scale — digital platforms, apps, and online services that build user profiles at scale. This is the category under which Glovo was sanctioned.

Credit institutions — banks, savings banks, credit cooperatives, and similar financial entities regulated under Spanish banking law.

Insurance and reinsurance companies — all licensed insurers and reinsurers, including brokers and intermediaries processing policyholder data.

Investment service companies and collective investment institutions — securities firms, fund managers, and similar financial entities.

Entities responsible for common solvency files — credit reference agencies and organisations that manage debt and solvency databases.

Private security companies — all private security and surveillance firms, including those operating CCTV systems as a core business function.

Sports federations — national and regional sports federations that process member, athlete, and competition data.

Gambling and gaming entities — companies holding gambling licences under Spanish gaming legislation.

Advertising and market research companies that carry out profiling — any organisation whose primary business involves building profiles of individuals for advertising, targeting, or research purposes.

Healthcare centres, establishments, and providers — hospitals, clinics, medical practices, dental clinics, pharmacies, physiotherapy centres, medical laboratories, and any healthcare entity processing patient data. This applies regardless of the number of patients or staff.

Entities managing large-scale mutual social security systems — entities administering occupational pension schemes and similar collective welfare arrangements.

Entities operating critical infrastructure — organisations designated as operators of critical national infrastructure under Spanish security legislation.

Energy distribution companies — electricity and natural gas distributors operating under sector-specific regulation.

This list is not exhaustive of all circumstances where a DPO may be legally required — it represents the sectors where the LOPDGDD creates an automatic, size-independent obligation. Organisations in other sectors may still require a DPO under the GDPR Article 37 criteria described above.

Spain mandatory DPO sectors under LOPDGDD Article 34 including healthcare, finance, and education sectors

What the EU Digital Omnibus Proposes — and What It Does Not Touch

The EU Digital Omnibus, published in November 2025, has received significant attention for its proposed changes to GDPR compliance requirements for smaller businesses. Business owners have asked whether this proposal reduces the DPO obligation for SMEs.

The direct answer is no.

The Digital Omnibus proposals, if adopted, would result in administrative cost savings primarily through extended exemptions for GDPR records of processing activities and lighter compliance regimes for SMEs and small mid-cap companies. The DPO obligation under GDPR Article 37 is not among the provisions targeted for amendment.

More significantly for businesses in Spain, the Digital Omnibus does not propose any changes to national law. The LOPDGDD's 16-sector mandatory DPO list sits in Spanish national legislation — and EU-level proposals do not automatically modify national law. Even if the Digital Omnibus is adopted as proposed, Article 34 of the LOPDGDD will remain unchanged unless the Spanish government introduces separate domestic legislation to amend it.

The Digital Omnibus Package will make its way through the EU's trilogue legislative process, with adoption expected by mid-2026 — but its contents will likely change, and there is no requirement for organisations to implement any changes to their compliance frameworks yet.

For businesses in the 16 mandatory sectors, the DPO obligation is unchanged. For businesses outside those sectors, the GDPR Article 37 criteria are unchanged. The only change being proposed in this area is the ROPA exemption expansion — not DPO requirements.

What Happens If You Do Not Appoint a DPO When Required

Failing to appoint a mandatory DPO is a serious infringement under both GDPR and the LOPDGDD — and the AEPD enforces it.

Under Article 73 of the LOPDGDD, not having a DPO in accordance with the requirements of the GDPR may be considered a serious infringement, carrying an administrative penalty of up to €10 million or 2% of the total annual turnover, whichever is higher.

The AEPD's track record confirms this is not theoretical. In June 2020, the AEPD imposed a €25,000 fine on Glovo for failing to appoint a DPO. The AEPD proceedings were initiated following two complaints filed in May and November 2019. Although Glovo communicated the appointment of a DPO to the AEPD on 31 January 2020, the AEPD recognised the proactive action but found it was not sufficient to avoid the fine.

The Glovo case established several principles that remain relevant today:

Appointing a DPO after an investigation begins does not eliminate liability for prior non-compliance. The AEPD explicitly acknowledged Glovo's late appointment but fined the company regardless for the period during which no DPO existed.

An internal committee performing DPO-like functions is not a substitute for a formally appointed DPO. Glovo argued its Data Protection Committee fulfilled all DPO functions. The AEPD rejected this argument because no DPO was formally registered with the agency and no mention appeared in the company's public privacy policy.

The failure to notify the AEPD of the DPO appointment is itself a separate violation. Under Spanish law, controllers and processors must notify the AEPD within ten days of any DPO appointment, modification, or removal — both when the appointment is mandatory and when it is voluntary. Glovo was fined for the failure to appoint and for the failure to notify on time.

Being a repeat offender compounds risk substantially. Once a company has been sanctioned for any GDPR violation, subsequent violations are assessed with an aggravating circumstance that can materially increase fine amounts. A business fined for not having a DPO that later faces any other compliance issue enters the AEPD's process in a structurally worse position.

GDPR compliance team reviewing data protection risks, sanctions, and DPO appointment requirements in Spain

How to Appoint a DPO in Spain: The Practical Steps

If you have determined that your business requires a DPO — or have decided to appoint one voluntarily — here is what the process involves.

Step 1 — Identify your DPO. Your DPO can be an existing employee, a newly hired specialist, or an external service provider. The DPO must have expert knowledge of data protection law — both GDPR and the LOPDGDD — and sufficient understanding of your business's processing activities. There is no mandatory certification in Spain, though the AEPD's voluntary Certification Scheme for DPOs (Esquema de Certificación de DPDs, v.1.4) is widely used as a benchmark.

Step 2 — Ensure independence. The DPO must not have a conflict of interest with their compliance oversight role. They cannot simultaneously hold a position that determines the purposes or means of data processing — for example, an IT director who makes decisions about what data to collect cannot also serve as DPO. The Belgian DPA fined a company €50,000 for appointing its Head of Compliance as DPO in a role that created a structural conflict of interest. Outsourcing the DPO role to an external provider is one effective way to guarantee independence.

Step 3 — Formalise the appointment. If using an internal employee, document the appointment formally. If using an external provider, execute a written service contract that defines the scope of the DPO's tasks and access rights.

Step 4 — Notify the AEPD within 10 days. The AEPD maintains an updated electronic register of DPOs, and controllers and processors are required to notify appointments, modifications, and removals within ten days — both for mandatory and voluntary appointments. This notification is made through the AEPD's online portal. Failure to notify is a standalone violation, separate from the obligation to appoint.

Step 5 — Publish the DPO's contact details. The DPO's contact information — typically a dedicated email address — must be published in your privacy policy and any other relevant communications. Individuals exercising their data subject rights may address requests to the DPO directly. The contact details do not need to include the DPO's personal name.

Step 6 — Resource the DPO properly. The DPO must have access to all relevant processing activities, receive adequate training, and be given the time and tools to perform their role. Appointing a DPO nominally but failing to resource them is not a compliance solution — and the AEPD assesses whether DPOs are genuinely functioning in their role when investigating complaints.

Step-by-step checklist for appointing a Data Protection Officer in Spain under RGPD requirements

Should Your Business Appoint a DPO Voluntarily?

If your sector does not appear on the LOPDGDD Article 34 list, and your processing does not meet the GDPR Article 37 thresholds, you are not legally obligated to appoint a DPO. But that does not necessarily mean you should not have one.

Voluntary DPO appointment makes practical sense for businesses that:

  • Handle significant volumes of customer or employee personal data
  • Use AI tools, profiling systems, or automated decision-making in their operations
  • Operate in sectors where clients or partners contractually require evidence of robust data protection governance
  • Process any special categories of sensitive data — even if not at the scale that triggers a mandatory obligation
  • Are growing rapidly and expect their processing activities to evolve

If you choose to appoint a DPO voluntarily, you must complete the same steps as those who are obliged to appoint one — including notifying the AEPD — and the DPO must meet the same standards of expertise and independence.

A voluntary DPO appointment also cannot be reversed without notification. If you register a DPO with the AEPD and later remove them without appointing a replacement, that removal must itself be notified within ten days — and if the AEPD subsequently finds your processing actually required a mandatory DPO, the removal creates additional exposure.

The DPO-as-a-Service Model: What Spanish SMEs Are Choosing

For most small and medium-sized businesses in Spain that require a DPO — whether under the mandatory sector list or voluntarily — the outsourced DPO model has become the dominant approach.

An external DPO provides certified expertise, guaranteed independence from internal conflicts of interest, and scalable support without the cost of a full-time hire. The service contract specifies the scope of tasks — which typically includes maintaining the record of processing activities, advising on DPIAs, handling data subject rights requests, monitoring regulatory developments, liaising with the AEPD, and delivering annual compliance reports.

The cost of an outsourced DPO service varies based on the complexity of your processing activities and the level of support required. For a small business in a mandatory sector with straightforward processing, it is typically a fraction of the cost of a single compliance failure. For organisations managing healthcare records, student data, insurance portfolios, or financial data, the legal exposure from non-appointment makes the comparison straightforward.

Do Not Assume You Are Exempt

Spain's approach to DPO obligations is different from the rest of Europe — and significantly broader than most business owners expect. The LOPDGDD's 16-sector mandatory list has no equivalent in most EU member states. And the AEPD has demonstrated, from the Glovo case onwards, that it will sanction organisations that assume exemption without properly assessing their position.

If your business operates in any of the 16 mandatory sectors — education, healthcare, financial services, insurance, private security, advertising that profiles individuals, or any of the others — you need a DPO today. Not when you grow larger. Not when the Digital Omnibus becomes law. Today.

If you are outside those sectors but process significant volumes of personal data, use AI or profiling tools, or handle sensitive data categories, a voluntary DPO appointment is the most effective risk management decision your business can make.

The EU GDPR Compliance and Data Protection for Businesses course from Spanish Compliance Institute covers the DPO obligation in detail — including the LOPDGDD sector requirements, what a DPO does in practice, how to assess whether your business needs one, and 18 downloadable compliance templates you can start using immediately.

Also in this series:

Frequently Asked Questions

01 Does every business in Spain need a Data Protection Officer? +

No. A DPO is mandatory for organisations that meet the GDPR Article 37 criteria — public bodies, large-scale systematic monitoring, or large-scale processing of sensitive data — and for organisations included in the 16 sectors listed in Article 34 of the LOPDGDD. Businesses outside these categories are not legally required to designate a Data Protection Officer (DPO), although they may do so voluntarily.

02 Which sectors require a mandatory DPO in Spain, regardless of company size? +

Under Article 34 of the LOPDGDD, mandatory sectors include: professional associations, educational institutions at all levels — including private language academies and training centres —, telecommunications operators, information society service providers engaged in large-scale profiling, credit institutions, insurance companies, investment services firms, credit reference agencies, private security companies, sports federations, gambling entities, advertising and market research firms engaged in profiling, healthcare providers of all sizes, social welfare entities, critical infrastructure operators, and energy distribution companies.

03 Does a small language school or private academy need a DPO in Spain? +

Yes. Private educational centres — including small academies, language schools, and training centres — are expressly included in Article 34 of the LOPDGDD as organisations required to designate a Data Protection Officer (DPO), regardless of their size or number of employees. This is one of the most commonly overlooked obligations among SMEs in the education sector in Spain.

04 What is the fine for not having a DPO when it is mandatory? +

Failing to designate a mandatory Data Protection Officer is classified as a serious infringement under the LOPDGDD and can carry a fine of up to €10 million or 2% of total annual global turnover — whichever is higher. In practice, the AEPD has imposed five-figure fines for this infringement, including a €25,000 penalty against Glovo in 2020. Additionally, having been sanctioned creates an aggravating circumstance for any subsequent GDPR infringement by the same organisation.

05 Can I designate an employee as DPO, or must it be an external person? +

Both options are permitted under Article 37(6) of the GDPR and Spanish law. An internal employee can act as a Data Protection Officer (DPO) provided they have the necessary expertise, sufficient time dedicated to the role, and no conflict of interest. The conflict-of-interest test is critical: a person who determines the purposes or means of processing — such as a CTO, HR director, or in-house legal counsel with operational responsibilities — generally cannot also serve as DPO. Many Spanish SMEs opt for an external DPO-as-a-service provider to ensure independence and access to specialised knowledge.

06 How do I notify the AEPD of a DPO designation? +

DPO designations, modifications, and cessations must be notified to the AEPD within 10 days through the electronic notification system available on the agency's online portal. Notification applies whether the designation is mandatory or voluntary. The AEPD maintains a public register of registered Data Protection Officers. Failure to notify within the 10-day period constitutes a separate infringement, sanctionable independently from the failure to designate.

07 Does the EU Digital Omnibus reduce or eliminate the DPO obligation for SMEs? +

No. The Digital Omnibus proposals target GDPR documentation obligations — specifically the Records of Processing Activities exemption threshold — and do not propose changes to the Data Protection Officer (DPO) designation requirements under GDPR Article 37. More importantly, the LOPDGDD's 16-sector mandatory DPO list belongs to Spanish national law and would require a separate Spanish legislative process to amend. The Digital Omnibus does not automatically modify national legislation. For businesses in mandatory sectors, the DPO obligation remains fully in effect.

08 What qualifications does a DPO need in Spain? +

The GDPR requires Data Protection Officers to have expert knowledge of data protection law and practices, without specifying a mandatory qualification. In Spain, the AEPD has published a Data Protection Officer Certification Scheme that serves as a recognised benchmark of competence. While this certification is not legally mandatory, it is widely adopted in the market and demonstrates the level of knowledge the AEPD expects a DPO to possess.

09 Can a DPO be shared among several companies? +

Yes. Article 37(3) of the GDPR allows a single Data Protection Officer (DPO) to be designated for a group of undertakings, provided the DPO is easily accessible from each entity. This is a common model for holding companies, franchise groups, or owners with multiple legal entities in Spain. The accessibility requirement means a shared DPO cannot be so overburdened that individual entities cannot receive advice and support in a timely manner.

10 What happens after designating a DPO? What should they do first? +

Immediately after designation, a Data Protection Officer typically reviews the organisation's existing processing activities and identifies compliance gaps; assesses whether a Record of Processing Activities exists and is up to date; reviews privacy notices, consent mechanisms, and rights procedures; identifies processing operations that require a Data Protection Impact Assessment; and establishes a regular reporting cadence with management. The DPO then acts as an ongoing compliance supervisor, not a one-off adviser.

11 Is a voluntary DPO designation reversible? +

Technically yes, but with important caveats. If you voluntarily register a Data Protection Officer (DPO) with the AEPD, any subsequent cessation must be notified within 10 days. Additionally, if you decide to deregister your DPO, you must first reassess whether your current processing activities might actually require a mandatory DPO under GDPR Article 37 or LOPDGDD Article 34, as your processing may have evolved since the initial assessment. Withdrawing a registered DPO without a solid legal basis may attract regulatory scrutiny.