What constitutes non-compliance with the LOPDGDD and GDPR?
Non-compliance means failing to respect the obligations established by the Spanish and European data protection regulatory framework. The most common infringements include: absence of a privacy policy, lack of contracts with suppliers who process data, no Record of Processing Activities, insufficient information provided to users, failure to respond to rights requests within the required timeframe, sending commercial communications without consent, and inadequate security measures.
Any affected individual may file a complaint with the AEPD, which may also investigate on its own initiative or following complaints from competitors.
Types of infringements and sanctions for LOPDGDD non-compliance
To understand the amounts at stake, it is important to distinguish between two coexisting frameworks: the Spanish framework, which defines the usual tiers, and the European framework, which sets the absolute ceilings for the most serious cases.
The sanctions scale in Spain (LOPDGDD)
Minor infringements (up to €40,000): Formal or procedural errors, such as having an incomplete privacy policy on a website or failing to respond to a simple user request in time.
Serious infringements (from €40,001 to €300,000): Significant non-compliance: lacking a Record of Processing Activities, sending commercial communications without consent, or failing to apply basic security measures.
Very serious infringements (from €300,001 upwards): Fundamental violations: processing sensitive data — health, ideology, racial origin — without explicit authorisation, or unlawfully disclosing databases to third parties.
The European maximum thresholds (GDPR)
For larger-scale infringements or those affecting major corporations, the GDPR raises the limits to substantial figures:
Up to €10,000,000 or 2% of global annual turnover (whichever is higher): security failures, absence of a DPO when mandatory, or failure to notify a breach within the required timeframe.
Up to €20,000,000 or 4% of global annual turnover (whichever is higher): violation of basic privacy principles, failure to uphold individuals' rights, or unlawful international data transfers.
In addition to financial penalties, the AEPD may issue public warnings, orders to cease processing, temporary restrictions, and orders to notify those affected.
"Fines do not fall from the sky. There are almost always warning signs that nobody attended to. That is why ongoing support is not a luxury: it is what makes the difference."
Mario P. Talamillo · Managing Partner, Certix®
Real-world consequences of failing to comply with data protection regulations
Reputational damage: The AEPD's sanctioning decisions are public and become indexed in search engines. This deters potential clients and damages existing relationships.
Commercial restrictions: An increasing number of companies require GDPR compliance as a prerequisite before signing contracts with suppliers and partners.
Personal liability: Company directors may incur personal liability if they deliberately ignored compliance obligations.
How to prevent LOPDGDD non-compliance in your business
- Carry out an audit of the data you process and its legal basis
- Keep your Record of Processing Activities up to date
- Create and regularly update a privacy policy tailored to your actual activities
- Sign data processing agreements with all suppliers that access personal data
- Establish clear procedures for handling rights requests
- Develop a security breach response protocol
For organisations that are required to do so, appointing an external Data Protection Officer is an efficient solution for supervising ongoing compliance without the need for dedicated internal resources.
Staff training significantly reduces the risks arising from human error or lack of awareness of obligations.
This content is for informational purposes only and does not constitute legal advice. The application of regulations to each specific case requires individual analysis.