An email or a notification from the Spanish Data Protection Agency (AEPD) usually causes concern in any company. The first reaction is to fear the worst. It is worth starting from the opposite: receiving a data protection complaint —what the rules precisely call a claim— is not a sanction, but the starting point of a procedure in which your organisation can explain itself and demonstrate how it processes data. This guide clarifies what it means, how it arrives, what phases it has and how to respond from the perspective of the company that receives it.
In 15 seconds
- "Complaint" is the colloquial term; the legal one is claim, a right of every data subject (art. 77 GDPR).
- The AEPD forwarding a claim to you is not a sanction and does not prejudge the outcome.
- The best position is to cooperate and demonstrate accountability (art. 5.2 GDPR).
- Having your documentation in order —RoPA, information notices, contracts, breach protocol— lets you respond with confidence.
"Complaint" or "claim": the correct term
In everyday language almost everyone says "I've been reported to the AEPD" or "I'm going to file a data protection complaint". It is an understandable expression, but legally imprecise. The term used by the General Data Protection Regulation is not complaint, but claim.
Art. 77 GDPR grants every data subject the right to lodge a claim with a supervisory authority —in Spain, the AEPD— when they consider that the processing of their personal data infringes the rules. That is the mechanism. It is not a criminal process nor an accusation in the strict sense: it is the exercise of a person's right within an administrative procedure.
The distinction matters because it changes the mindset with which the company should approach the matter. A claim does not presuppose fault. It is an expression that someone —a customer, an employee, a user, a former contact— believes that something in the processing of their data has not been correct, and conveys that perception to the authority. From there, a process opens in which the organisation has the opportunity to explain how it acts and to provide the documentation that supports it.
How a claim reaches your company
The data subject lodges their claim directly with the AEPD, normally through the Agency's electronic portal. Your company does not take part at that first moment: it finds out afterwards, when the supervisory authority decides to forward the matter.
That forwarding is the usual way an organisation discovers that a claim exists. The AEPD informs the company that a claim relating to its processing has been received and, frequently, offers it the possibility to make representations, provide information or respond to the question raised. In organisations that have a Data Protection Officer (DPO), the Agency may channel the communication through that figure, who acts as the point of contact.
It is worth emphasising a nuance that greatly reduces anxiety: receiving that communication does not mean that a sanction already exists or that the procedure will necessarily end in one. It is a phase of information exchange. In quite a few cases, when the company responds appropriately, with documentation and resolving the underlying situation, the matter can be redirected without major consequences.
The phases of the procedure before the AEPD
The procedure that follows a claim is governed by the Spanish data protection rules (LOPDGDD) and is structured, broadly, into several stages. Without going into technicalities, this is how it usually unfolds from the perspective of the company that receives the matter.
| Phase | What happens | What the company can do |
|---|---|---|
| Lodging | The data subject lodges their claim with the AEPD (art. 77 GDPR). The company is not yet involved. | — |
| Forwarding | The AEPD informs the company of the existence of the claim and, often, gives it the opportunity to respond. | Analyse the case, gather the documentation and give a clear, on-time response. |
| Assessment | The Agency assesses the claim and the information received to decide how to proceed. | Provide information that clarifies the facts and, if appropriate, remedy the underlying situation. |
| Preliminary investigation | The AEPD may gather information and require documentation in the exercise of its investigative powers (art. 58 GDPR). | Attend to the requirements within the indicated deadline and cooperate diligently. |
| Resolution | The Agency resolves. The procedure may end in different ways depending on what is evidenced. | Review the resolution and apply the measures or improvements that correspond. |
The duration and specific deadlines of each step are set by the administrative procedure rules and may vary depending on the complexity of the case. What matters for the company is not to memorise each stage, but to understand the underlying logic: there are several moments at which the organisation can intervene, explain itself and provide evidence. The procedure is designed precisely so that this happens.
What to review if you receive a claim
When the AEPD's communication arrives, the most useful reaction is orderly, not impulsive. Before responding, it is worth calmly reconstructing what happened and what documentation supports the company's actions. This checklist helps to prepare a solid response:
- Identify the processing affected. What activity does the claim refer to: a commercial communication, an unaddressed exercise of rights, a disclosure of data, a possible breach? Locate it in your Record of Processing Activities.
- Gather the legal basis. Check on which legal basis (art. 6 GDPR) that processing relies and whether it was correctly documented.
- Review the information provided to the data subject. Were they given the art. 13 GDPR information notice at first contact? Was it clear and accessible?
- Verify the contracts with third parties. If a provider or software was involved, confirm that the processing agreement (art. 28 GDPR) exists and what obligations it assumed.
- Check the history of the relationship. Emails, rights requests, responses given: reconstruct the trace of what happened, with dates.
- Consult the DPO if you have one. This is the figure that coordinates the response and acts as the interlocutor with the Agency.
- Respond on time and in writing. With a calm, factual tone supported by documentation. Never leave a requirement unattended.
The aim of this review is not to prepare a last-minute defence, but to check whether the company can evidence that it processes data in an orderly way. When the answer is yes —because the documentation exists and is consistent—, responding to the AEPD stops being a problem and becomes a manageable formality.
Documentation in order: your best position
The difference between facing a claim with confidence or with distress almost always comes down to one factor: whether or not the organisation has its data protection documentation up to date. It is not a formality. It is the tangible proof that the company takes the processing of data seriously.
The documents that underpin that position are the usual ones, and that is why it is worth keeping them alive before any communication arrives:
- The Record of Processing Activities (RoPA), which inventories what data the company handles, for what purpose and for how long (art. 30 GDPR).
- The information notices under art. 13, provided to customers, employees and users at first contact.
- The processor contracts (art. 28) that govern the relationship with providers and software.
- The security policy with the technical and organisational measures of art. 32.
- The breach management protocol, which evidences how the company acts in the event of a security incident.
When these documents exist, are up to date and reflect the actual activity, responding to the AEPD consists of providing what you already have. When they do not exist —or describe a company that is no longer the current one—, the response turns into a race against the clock to reconstruct after the fact what should have been done from the start. Documentation in order is not bureaucracy: it is what allows you to talk to the authority from an orderly position.
"A claim before the AEPD is not won with fear or with silence, it is faced with documentation. The company that can show its RoPA, its information notices and its contracts up to date has already answered half the questions before they are even asked."
Mario P. Talamillo · Managing Partner, Certix®
Cooperate and demonstrate accountability
The GDPR is built on the accountability principle of art. 5.2: it is not enough to comply with the rules, you have to be able to demonstrate it. A claim is, in essence, the moment when that principle is put to the test. And the company's attitude weighs as much as the documentation.
Cooperating with the supervisory authority is always the best position. The AEPD has investigative powers (art. 58 GDPR) to gather information and examine processing, and attending to its communications within the indicated deadlines is part of the duty of cooperation of any controller. Responding diligently, with transparency and providing what is requested, conveys exactly the message the GDPR expects from an organisation: that it processes data seriously and that it takes on its responsibility.
The opposite approach —ignoring requirements, responding late or evasively— never improves the situation; it makes it worse. By contrast, a company that acknowledges the problem when there is one, corrects it, documents the correction and communicates it clearly is doing the right thing and, moreover, demonstrating the accountability that the rule requires. That is the strongest position in which any organisation can place itself.
How Certix supports you
Receiving a claim is not pleasant, but it is perfectly manageable when the company has its house in order and has someone to guide it. At Certix we support organisations on both fronts: preparing in advance the documentation that underpins accountability —RoPA, information notices, contracts with providers, security policy and breach protocol— and helping to articulate an orderly response when the AEPD forwards a matter.
The approach is the same one we apply to all our work: a real analysis of the company's activity, with no generic templates, and direct dealings with a data protection expert. If you want to review where your organisation stands before any communication arrives, that is the best moment to do it.
Frequently asked questions
Does receiving a claim before the AEPD mean my company is already sanctioned?
No. A claim is simply the exercise of the right that art. 77 GDPR grants any person to address the supervisory authority. The AEPD forwarding a claim to your company does not amount to a sanction and does not prejudge the outcome: it opens a process in which the organisation can explain how it processes data and provide its documentation. Many procedures are resolved without a sanction when the company can show that it acts correctly and cooperates.
Is a complaint the same as a claim in data protection?
In everyday language people talk about a complaint, but the legal term in the GDPR is a claim. Art. 77 GDPR grants every data subject the right to lodge a claim with the supervisory authority (in Spain, the AEPD) when they consider that the processing of their data infringes the rules. The difference is not merely terminological: it frames the matter as a right of the data subject within an administrative procedure, not as a criminal process.
What documentation should be ready to respond well?
The documentation that underpins the accountability principle of art. 5.2 GDPR: the Record of Processing Activities (art. 30), the art. 13 information notices provided to data subjects, the processor contracts (art. 28), the security policy and the breach management protocol. Having this documentation up to date and consistent with the actual activity allows you to respond to the AEPD accurately and to demonstrate that the organisation processes data in an orderly way.
Should I cooperate with the AEPD or is it better not to respond?
Cooperating is the best position. The supervisory authority has investigative powers (art. 58 GDPR) to gather information, and attending to its communications within the indicated deadlines is part of the duty of cooperation. Responding calmly, with documentation and on time, providing the information requested, demonstrates accountability and places the company in the strongest position. Ignoring requirements never improves the situation.
In summary
A data protection complaint —a claim, in the terms of art. 77 GDPR— is not a verdict, but the start of a procedure in which your company has a voice. The AEPD forwarding a matter prejudges nothing: it opens the door to explaining yourself. The organisation that reaches that moment with its documentation in order and a willingness to cooperate demonstrates the accountability of art. 5.2 and places itself in the strongest possible position. The best moment to prepare that position is before the communication arrives.
Related reading
- Record of Processing Activities (RoPA) — the document that inventories all your processing.
- Security breach: what to do — how to act in the event of an incident affecting personal data.
- Certix data protection consultancy — direct dealings with an expert, with no generic templates.
This content is purely informational and educational; it does not constitute specialised legal advice. Applying the regulations to each specific case requires individual analysis.
Is your company ready to respond to a claim?
At Certix we bring your data protection documentation up to date and support you if the AEPD forwards a matter to your organisation.
Speak to a consultant