Certix

AEPD and DPO: complete guide to the Data Protection Officer

Certix
Certix®
· 12 Mar 2026 · 6 min read

Informative article. It does not replace individualised professional advice.

What is the DPO and what is its relationship with the AEPD?

The DPO (Data Protection Officer), also referred to by its Spanish acronym DPD (Delegado de Protección de Datos), is the person responsible for supervising GDPR compliance within an organisation. This role is regulated under articles 37 to 39 of the GDPR and further developed in Spain by Organic Law 3/2018 (LOPDGDD).

The AEPD (Agencia Española de Protección de Datos — Spain's data protection authority) is the public body responsible for supervising the application of privacy regulations in Spain. It acts as the official point of contact for the DPO, receives the mandatory registration, and may require the DPO's involvement in the event of an investigation or sanction.

Difference between internal and external DPO

The DPO may be an employee of the organisation itself (internal DPO) or an external professional or entity engaged on a contractual basis (external DPO).

Opting for an external DPO has clear advantages: greater independence and objectivity, up-to-date knowledge of the regulatory framework without the cost of ongoing training, and immediate coverage without the need to create a new in-house position.

"The AEPD does not sanction for the sake of sanctioning. It seeks to ensure that organisations take people's rights seriously. When they do, problems are avoided."

Mario P. Talamillo · Managing Partner, Certix®

When is it mandatory to appoint a DPO according to the AEPD?

The GDPR establishes three situations in which appointment is mandatory:

  1. Public authorities or bodies
  2. Organisations whose core activities involve large-scale processing of special categories of data: health data, biometric data, genetic data, ideology, religion, sexual orientation, etc.
  3. Organisations that carry out large-scale regular and systematic monitoring of individuals: mass video-surveillance companies, digital platforms, behavioural advertising, etc.

Article 34 of the LOPDGDD provides for additional cases for certain sectors in Spain — professional associations, educational institutions, credit institutions, insurance companies, securities firms, energy distributors, private security companies, sports federations when processing data of minors, among others — with the exception of healthcare professionals practising on an individual basis. The specific obligation depends on an individual analysis of each organisation; this information is for guidance purposes only and each case must be examined individually.

What if I do not fall into any of these cases?

If your organisation does not fall within any of the above situations, appointment is not mandatory, but it is highly advisable to have a DPO or specialist advisory support. The AEPD notes that proactive compliance significantly reduces the risk of sanctions.

DPO functions: what this professional actually does

Supervising regulatory compliance

The DPO analyses the data processing activities carried out by the organisation and verifies that they comply with the GDPR and the LOPDGDD. They review contracts with third parties, assess data processors, and audit internal procedures.

Advisory work and training

The DPO informs and advises the controller, employees, and all those involved in data processing. They ensure that staff receive adequate and up-to-date training.

Point of contact with the AEPD

The DPO acts as the official intermediary between the organisation and the Agencia Española de Protección de Datos in investigations or requests for information.

Data Protection Impact Assessments (DPIA)

Where high-risk processing activities are envisaged, the DPO supervises and advises on the preparation of Data Protection Impact Assessments.

Management of security breaches

In the event of a security breach, the DPO coordinates the response, assesses whether notification to the AEPD is required within the maximum period of 72 hours, and manages communication with affected individuals where appropriate.

How to register the DPO with the AEPD: step by step

Once the DPO has been appointed, the organisation must notify the AEPD via the dedicated service on its electronic office (sedeagpd.gob.es). This registration is mandatory and free of charge.

  1. Access the AEPD's electronic office
  2. Select the DPO notification procedure
  3. Identify yourself using a digital certificate, electronic identity document, or Cl@ve
  4. Complete the details of the controller and the designated DPO
  5. Submit the notification and retain the confirmation receipt

Sanctions for failing to comply with DPO obligations

Failing to designate a DPO when required, or failing to register one with the AEPD, are infringements that may result in significant sanctions:

  • Minor infringements: up to €40,000
  • Serious infringements: between €40,001 and €300,000
  • Very serious infringements: up to €20,000,000 or 4% of global annual turnover

The AEPD publishes sanctioning decisions that become indexed in search engines and are accessible to clients, suppliers, and partners. Compliance is not merely a legal obligation: it is a competitive advantage.

DPO and AEPD in Burgos: local service with national reach

At Certix, headquartered in Burgos, we have spent years helping organisations across Spain comply with data protection regulations. We act as external DPO, manage registration with the AEPD, and supervise ongoing compliance. No sales staff, no intermediaries: you will always speak directly with an expert.

This content is for informational purposes only and does not constitute legal advice. The application of regulations to each specific case requires individual analysis.

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →