The GDPR —General Data Protection Regulation, officially Regulation (EU) 2016/679— is the European regulation governing how organisations must handle the personal data of any individual in the European Union. Published on 4 May 2016 and applicable from 25 May 2018, it replaced the former Directive 95/46/EC and completely transformed the compliance landscape in Europe.
Unlike a directive, the GDPR is a directly applicable regulation: it requires no national transposition to be binding. This means it imposes equal obligations on a company in Spain, Germany or Poland, without any Member State being able to lower its requirements.
This guide distils its 99 articles and 11 chapters into an accessible format, with tables and examples, so that any business decision-maker can understand what the regulation demands and what consequences non-compliance entails.
GDPR and LOPDGDD: two regulations that go hand in hand
In Spain, the GDPR coexists with the LOPDGDD (Organic Law 3/2018). They are not alternatives: they are complementary. The GDPR sets the European framework; the LOPDGDD develops and adapts it to the Spanish legal system.
| Feature | GDPR (EU 2016/679) | LOPDGDD (LO 3/2018) |
|---|---|---|
| Nature | European regulation (directly applicable) | Spanish Organic Law |
| In force since | 25 May 2018 | 7 December 2018 |
| Scope | All EU Member States | Spain only |
| Role | General European framework | Adapts and develops the GDPR in Spain |
| Minors | 16 years (reference age) | 14 years (Art. 7 LOPDGDD) |
| Digital rights | Not covered | Title X: 22 new digital rights |
| Sectoral DPO | Art. 37: general criteria | Art. 34: Spanish sector-specific list |
| Supervisory authority | National authorities + EDPB | AEPD (Spanish Data Protection Agency) |
Structure of the GDPR: 11 Chapters and 99 articles
The GDPR is organised into 11 Chapters ranging from basic definitions to final provisions. Its 173 recitals do not carry direct legal force but are essential for correctly interpreting the articles.
| Chapter | Content | Key articles |
|---|---|---|
| Ch. I | General provisions | Art. 1–4 · Subject matter, scope, definitions |
| Ch. II | Principles | Art. 5–11 · Lawfulness, purpose limitation, minimisation, accuracy, storage limitation, integrity |
| Ch. III | Rights of the data subject | Art. 12–23 · Access, rectification, erasure, portability… |
| Ch. IV | Controller and processor | Art. 24–43 · RoPA, privacy by design, contracts, DPO, DPIA |
| Ch. V | Transfers to third countries | Art. 44–49 · Adequacy decisions, safeguards, DPF |
| Ch. VI | Independent supervisory authorities | Art. 51–59 · AEPD and equivalent bodies in each Member State |
| Ch. VII | Cooperation and consistency | Art. 60–76 · One-stop-shop, EDPB, consistency mechanism |
| Ch. VIII | Remedies, liability and penalties | Art. 77–84 · Complaints, compensation, fines |
| Ch. IX | Specific processing situations | Art. 85–91 · Journalism, archives, health, churches… |
| Ch. X | Delegated and implementing acts | Art. 92–93 |
| Ch. XI | Final provisions | Art. 94–99 · Repeal of Directive 95/46/EC, entry into force |
Scope of application: who is bound by the GDPR?
The GDPR has an extraordinarily broad territorial scope (Art. 3). It does not only apply to organisations established in the EU: it also applies to any organisation outside the EU that offers goods or services to individuals in the EU, or that monitors their behaviour.
- Material scope (Art. 2): any processing of personal data wholly or partly by automated means, and also non-automated processing where the data form part of a filing system.
- Excluded activities: activities outside the scope of EU law, national security, and activities of a purely personal or household nature.
- Who is the data controller: the entity that determines the purposes and means of processing (Art. 4.7).
- Who is the data processor: the entity that processes personal data on behalf of the controller (Art. 4.8).
The principles of processing (Art. 5): the backbone of the GDPR
Article 5 sets out the 7 principles governing any processing of personal data. They are the starting point of any compliance analysis: if a processing activity cannot be framed within these principles, it must not take place.
| Principle | What it requires |
|---|---|
| Lawfulness, fairness and transparency | Data must be processed lawfully (with a legal basis), fairly (without deception) and transparently (the data subject must know what is being done with their data). |
| Purpose limitation | Data are collected for specified, explicit and legitimate purposes and may not be used for purposes incompatible with the original one. |
| Data minimisation | Only data that are adequate, relevant and limited to what is necessary in relation to the purposes may be processed. |
| Accuracy | Data must be accurate and kept up to date. Inaccurate data must be erased or rectified without delay. |
| Storage limitation | Data may not be kept in a form that permits identification for longer than necessary. Once the retention period expires, data must be erased or anonymised. |
| Integrity and confidentiality | Data must be processed with appropriate technical and organisational measures to ensure security against unauthorised access, loss or destruction. |
| Accountability | The controller must be able to actively demonstrate compliance with all the above principles. The burden of proof rests with the controller. |
Legal bases for processing (Art. 6)
For processing to be lawful, it must rest on at least one of the six legal bases in Article 6. Choosing the correct basis is not a formality: it determines the rights available to the data subject, the information obligations, and the possibility of continuing to process data if that basis ceases to apply.
| Basis | When it applies | Practical example |
|---|---|---|
| Art. 6.1.a — Consent | The data subject has given freely given, specific, informed and unambiguous consent. | Marketing newsletter |
| Art. 6.1.b — Contract | Processing necessary for the performance of a contract or for pre-contractual steps at the data subject's request. | Employee data, customer data for invoicing |
| Art. 6.1.c — Legal obligation | Processing necessary for compliance with a legal obligation to which the controller is subject. | Retention of accounting data under tax legislation |
| Art. 6.1.d — Vital interests | Protecting the vital interests of the data subject or another natural person. | Medical emergency situation |
| Art. 6.1.e — Public task | Processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority. | Public authorities, regulatory bodies |
| Art. 6.1.f — Legitimate interests | Legitimate interests of the controller or a third party, provided they are not overridden by the interests or rights of the data subject (balancing test). | Network security, fraud prevention, B2B marketing |
Important note on consent (Art. 7): it must be freely given, specific, informed and unambiguous. Pre-ticked boxes, silence and blanket consent are not valid. Furthermore, the data subject may withdraw consent at any time with the same ease with which it was given.
Special categories of data: the highest level of protection (Art. 9)
As a general rule, the GDPR prohibits the processing of certain data due to their particular sensitivity. They may only be processed if one of the enumerated exceptions in Art. 9.2 applies, and enhanced safeguards must be applied in all cases.
- Data revealing racial or ethnic origin
- Political opinions, religious or philosophical beliefs
- Trade union membership
- Genetic and biometric data processed for the purpose of uniquely identifying a natural person
- Data concerning health
- Data concerning a person's sex life or sexual orientation
Biometric data in the workplace deserve particular attention: their processing is subject to severe restrictions. According to the AEPD (Spanish Data Protection Agency) in Report 0023/2023, the use of biometric systems — such as fingerprint-based access control — lacks an express legal basis in ordinary employment settings and therefore requires individual legal analysis before any implementation.
"The GDPR is not bureaucracy: it is architecture. Those who understand it that way stop asking what documents they need and start asking how they handle their customers' data. That shift in approach is what separates companies that truly comply from those that merely appear to."
Mario P. Talamillo · Managing Partner, Certix®
Data subject rights (Arts. 12–23)
Chapter III of the GDPR recognises a broad catalogue of rights that any individual may exercise against the data controller. The general response deadline is 1 month, extendable to 3 months in complex cases (with prior notice to the data subject).
| Right | Article | What it entitles the data subject to |
|---|---|---|
| Access | Art. 15 | Obtain confirmation as to whether their data are being processed, and to access them along with full information about the processing. |
| Rectification | Art. 16 | Correct inaccurate data or complete incomplete data. |
| Erasure ("right to be forgotten") | Art. 17 | Obtain the deletion of their data when they are no longer necessary, consent has been withdrawn, or processing is unlawful, among other grounds. |
| Restriction | Art. 18 | Suspend processing while a dispute about accuracy or lawfulness is resolved, with the data remaining blocked in the meantime. |
| Portability | Art. 20 | Receive their data in a structured, commonly used and machine-readable format and transmit it to another controller. Applies only when the legal basis is consent or contract and processing is carried out by automated means. |
| Objection | Art. 21 | Object to processing where the legal basis is legitimate interests or public task. The controller must cease processing unless it can demonstrate compelling legitimate grounds. |
| No automated decision-making | Art. 22 | Not be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect them. |
Obligations of the data controller (Ch. IV)
Chapter IV is the most extensive and generates the greatest volume of practical work. It sets out the specific obligations that the data controller — and, where applicable, the data processor — must fulfil.
| Obligation | Article | What it entails |
|---|---|---|
| Accountability | Art. 24 | Implement appropriate technical and organisational measures and be able to demonstrate that processing complies with the GDPR. |
| Privacy by design and by default | Art. 25 | Integrate data protection from the design stage of any system and configure the most privacy-friendly settings as the default. |
| Contracts with processors | Art. 28 | Formalise a data processing agreement with all vendors that access personal data on behalf of the controller (mandatory minimum clauses required). |
| Record of Processing Activities (RoPA) | Art. 30 | Maintain a written record of all processing activities: purposes, categories of data, retention periods, security measures. Mandatory for the vast majority of organisations. |
| Security measures | Art. 32 | Implement technical and organisational measures appropriate to the risk: encryption, pseudonymisation, access controls, business continuity plans, audits… |
| Breach notification to the authority | Art. 33 | Notify the AEPD within 72 hours of any security breach that poses a risk to the rights and freedoms of individuals. |
| Communication of breaches to data subjects | Art. 34 | Where the breach is likely to result in a high risk to data subjects, communicate it to them without undue delay in clear and plain language. |
| Data Protection Impact Assessment (DPIA) | Art. 35 | Mandatory where processing is likely to result in a high risk: new technologies, automated decisions with legal effects, large-scale processing of sensitive data, surveillance of public areas… |
| Prior consultation | Art. 36 | If the DPIA concludes that the residual risk is high and cannot be mitigated, the controller must consult the supervisory authority before commencing the processing. |
The Data Protection Officer (DPO): Arts. 37–39
The GDPR establishes in Article 37 the general criteria that determine the obligation to appoint a Data Protection Officer (DPO). In Spain, Article 34 of the LOPDGDD expands and specifies this list for particular sectors of the Spanish business landscape.
When is a DPO mandatory under Art. 37 GDPR?
- Where the processing is carried out by a public authority or body (with certain exceptions).
- Where the core activities of the controller or processor require regular and systematic monitoring of data subjects on a large scale.
- Where the core activities consist of large-scale processing of special categories of data (Art. 9) or data relating to criminal convictions (Art. 10).
Determining whether an organisation is subject to this obligation depends on a concrete analysis of its processing activities: scale, frequency, categories of data and nature of the activity. This is indicative information; each case requires individual analysis.
What does the DPO do? (Art. 39)
- Inform and advise the controller, the processor and employees of their obligations under the GDPR.
- Monitor compliance with the GDPR and with internal policies.
- Provide advice on Data Protection Impact Assessments (DPIAs).
- Act as the point of contact with the supervisory authority (AEPD).
- Handle queries from data subjects regarding the exercise of their rights.
The DPO may be an employee (internal) or an external service provider. In either case, they must possess expert knowledge of data protection law and practice and must act with full independence (Art. 38): they may not receive instructions as to how to perform their tasks and may not be dismissed or penalised for doing so.
The Data Protection Impact Assessment (DPIA): Art. 35
The DPIA (Data Protection Impact Assessment) is the GDPR's instrument for managing high-risk processing activities before they begin. It is not a documentary formality: it is an analytical process that must lead to real decisions about whether the processing can proceed and under what conditions.
When is it mandatory:
- Systematic and extensive profiling of natural persons based on automated processing, including profiling, that produces legal or similarly significant effects.
- Large-scale processing of special categories of data (Art. 9) or criminal data (Art. 10).
- Systematic large-scale monitoring of a publicly accessible area (e.g. CCTV).
- Processing included in the AEPD's lists of operations requiring a DPIA.
Minimum content of the DPIA (Art. 35.7):
- A systematic description of the processing operations and their purposes.
- An assessment of the necessity and proportionality of the processing.
- An assessment of the risks to the rights and freedoms of data subjects.
- The measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data.
International transfers of personal data (Ch. V)
When personal data of individuals in the EU are transferred to a third country outside the EEA (European Economic Area), the GDPR requires that the level of protection is not diminished. Articles 44 to 49 establish the mechanisms to ensure this.
| Mechanism | What it consists of | Countries / Examples |
|---|---|---|
| Adequacy decision (Art. 45) | The European Commission has recognised that the third country offers an adequate level of protection. No additional safeguards are required. | United Kingdom, Japan, Switzerland, Canada, Israel, New Zealand… |
| Standard Contractual Clauses (SCCs) (Art. 46) | Standard contracts approved by the Commission that bind the recipient to provide GDPR-equivalent safeguards. | Used with vendors outside the EEA without an adequacy decision |
| Data Privacy Framework — DPF (Art. 45) | Adequacy decision specific to the United States (in effect since July 2023). US companies enrolled in the DPF may receive data without additional SCCs. | Google, Microsoft, Meta, Salesforce, AWS and thousands of DPF-certified companies |
| Binding Corporate Rules (BCRs) (Art. 47) | Internal data protection policies approved by the supervisory authority, for intra-group transfers within a multinational organisation. | Corporate groups with subsidiaries in countries without an adequacy decision |
| Derogations (Art. 49) | In the absence of the above mechanisms, transfers are only permitted in specific circumstances: explicit consent of the data subject, performance of a contract, important public interest… | Occasional use only — not for large-scale or routine transfers |
Note on SaaS and cloud tools from US providers: if the provider is enrolled in the Data Privacy Framework (DPF), the transfer is valid without further formalities. Before using any SaaS tool that processes personal data, verify whether the provider is listed on the public DPF registry (dataprivacyframework.gov). If not, SCCs or another Art. 46 mechanism will be required.
The GDPR sanctions regime (Art. 83)
The GDPR established an administrative fines regime that marked a turning point compared to previous legislation. Sanctions are proportionate, effective and dissuasive, and are determined on a case-by-case basis taking into account criteria such as the nature, gravity and duration of the infringement, the number of data subjects affected, the damage suffered and the conduct of the infringer.
| Tier | Maximum fine | Infringements |
|---|---|---|
| Tier 1 (Art. 83.4) | €10,000,000 or 2% of total worldwide annual turnover | Breach of obligations of controllers/processors (Arts. 8, 11, 25–39, 42–43), or certification conditions. |
| Tier 2 (Art. 83.5) | €20,000,000 or 4% of total worldwide annual turnover | Infringement of the basic principles (Art. 5), legal bases for processing (Art. 6), conditions for consent (Arts. 7 and 9), data subject rights (Arts. 12–22), international transfers (Arts. 44–49). |
In Spain, the LOPDGDD adapts and supplements this sanctions regime with its own grading system (minor, serious, very serious) that the AEPD applies in its enforcement proceedings.
The AEPD and the EDPB: the supervisory architecture
The GDPR creates a decentralised yet coordinated supervisory architecture. Each Member State designates one or more independent supervisory authorities. In Spain, that authority is the AEPD (Agencia Española de Protección de Datos — Spanish Data Protection Agency).
Above the national authorities, the GDPR establishes the EDPB (European Data Protection Board), composed of the heads of all national supervisory authorities and the European Data Protection Supervisor. The EDPB adopts guidelines, recommendations and best practices that controllers must take into account.
The one-stop-shop mechanism (Art. 56) allows organisations engaged in cross-border processing within the EU to be supervised primarily by the authority of the Member State where their main establishment is located.
GDPR compliance checklist
This is an operational summary of the elements that every organisation processing personal data should have in place:
| ✓ | Element | Reference |
|---|---|---|
| □ | Record of Processing Activities (RoPA) | Art. 30 GDPR |
| □ | Up-to-date information clauses and privacy policy | Arts. 13–14 GDPR |
| □ | Data processing agreements with all vendors | Art. 28 GDPR |
| □ | Documented security policy and measures | Art. 32 GDPR |
| □ | Security breach management protocol | Arts. 33–34 GDPR |
| □ | Procedure for handling data subject rights requests | Arts. 12–22 GDPR |
| □ | Analysis and legal basis documented for each processing activity | Art. 6 GDPR |
| □ | Assessment of DPO obligation | Art. 37 GDPR · Art. 34 LOPDGDD |
| □ | DPIA for high-risk processing activities | Art. 35 GDPR |
| □ | Verification of international transfers (DPF / SCCs / adequacy) | Arts. 44–49 GDPR |
| □ | Training for staff with access to personal data | Art. 24 GDPR · Recital 39 |
| □ | Review and update when processing activities change | Art. 24 GDPR (ongoing risk-based review) |
Frequently asked questions about the GDPR
Does the GDPR only apply to large companies?
No. The GDPR applies to any organisation — regardless of size — that processes personal data of individuals in the EU in the course of a professional or business activity. Size-based differences exist only in narrow exceptions (for example, the RoPA obligation may be waived for certain micro-enterprises where processing is not habitual and does not involve sensitive data), but the obligation to comply with the principles and protect data subject rights is universal.
What is the difference between a data controller and a data processor?
The data controller determines the purposes and means of processing (your company when it processes the data of its customers or employees). The data processor processes personal data on behalf of the controller and following its instructions (the payroll provider that manages salaries, the CRM software vendor, the courier company that delivers parcels using customer data). The relationship between both must always be formalised in a written contract containing the minimum content required by Art. 28 GDPR.
What is the RoPA and who must maintain one?
The Record of Processing Activities (RoPA) is the documented inventory of all processing activities carried out by an organisation: what data are processed, for what purpose, who the processors are, how long the data are retained and what security measures are applied. Art. 30.5 GDPR allows an exception for organisations with fewer than 250 employees whose processing is not habitual, does not affect special categories of data and poses no risk to individuals' rights. In practice, the vast majority of companies must maintain a RoPA.
When must I notify the AEPD of a security breach?
When you suffer a security breach that poses a risk to the rights and freedoms of the affected individuals, you have 72 hours from the moment you become aware of it to notify the AEPD (Art. 33 GDPR). If you do not yet have all the information, you may notify in phases. If the breach is likely to result in a high risk to data subjects, you must also communicate it to them directly (Art. 34).
Is consent always the safest legal basis?
It is a common mistake to assume that consent is the preferred legal basis. In fact, using it when another basis is more appropriate can work against the controller: if the data subject withdraws consent, processing must cease — even if it was necessary for the contractual relationship. Consent is the correct basis for optional processing (marketing, non-essential cookies). For the performance of a contract, legal obligations or legitimate interests, the corresponding bases must be used instead.
Does the GDPR require periodic audits?
The GDPR does not set a fixed frequency for data protection audits. The controller's obligation is to maintain an ongoing risk-based review (Art. 24) and to adapt its measures whenever processing activities, technology or the regulatory context change. The specific frequency of a formal review depends on the nature of each organisation and its processing activities.
This content is for informational and educational purposes only; it does not constitute legal advice in any case. The application of regulations to each specific case requires individual analysis.