The Agencia Española de Protección de Datos is Spain's independent data protection authority, operating under the GDPR and the Spanish implementing law, the LOPDGDD. It investigates complaints, issues sanctions, publishes guidance, and advises on legislation. It handles a very high caseload by European standards, which makes its published decisions an unusually detailed record of how the GDPR is applied in practice.
What the AEPD publishes
- Resolutions and sanction decisions, published in volume and with full reasoning
- Guides and criteria on recurring problem areas: video surveillance, cookies, employee monitoring, minors
- Technical tools for controllers, including breach notification and risk assessment aids
- Positions on emerging risks such as addictive design and artificial intelligence
- Reports from its legal service interpreting specific provisions
- Annual reports and enforcement statistics
Why it matters for compliance teams
Because the AEPD publishes so many decisions, it is often the fastest way to find out how a specific processing scenario is actually treated under the GDPR — where an abstract EDPB guideline leaves room for argument, an AEPD resolution on nearly identical facts frequently does not.
Seqlense DOC indexes AEPD resolutions and guidance in full text alongside EDPB material and the other national authorities, so a privacy team operating across Europe can compare enforcement postures rather than assuming they are the same.