Data Protection & IT Lawyers in Spain

GDPR compliance, data protection, cybersecurity, IT contracts and technology law.

More coming firms being added · All firms offer English service · Free to be listed · Use the wizard →

Filter by specialisation

0 firms shown

🔍

No Data Protection & IT specialists listed yet for Spain

We're actively expanding our directory. In the meantime, use the lawyer wizard — it'll match you to the best available firm for your situation.

Use the Lawyer Wizard → Suggest a Firm

Pérez Llorca

English likely
Madrid English; Spanish
View Google Reviews →

Leading Spanish law firm specializing in corporate and M&A work with strong international capabilities

TaxCorporate MaBanking Finance

Garrigues

English likely
Madrid English; Spanish; French
View Google Reviews →

Major full-service law firm with extensive English-speaking team and international practice

Corporate MaBanking FinanceIntellectual PropertyEmployment

Gómez-Acebo & Pombo

English likely
Madrid English; Spanish
View Google Reviews →

Spanish law firm with strong corporate and tax practice serving multinational clients

Corporate MaBanking FinanceEmploymentReal Estate

Uría Menéndez

English likely
Madrid English; Spanish; French
View Google Reviews →

Leading Spanish firm with international corporate and finance expertise

TaxCorporate MaBanking Finance

Ashurst

English likely
Madrid English; Spanish
View Google Reviews →

International law firm with strong presence in Madrid for corporate and finance work

Corporate MaBanking Finance

DLA Piper

English likely
Madrid English; Spanish; Multiple
★★★★☆ 4.1 (44 reviews)

Global firm with comprehensive legal services in Madrid

Dispute ResolutionCorporate MaIntellectual PropertyEmployment

Frequently Asked Questions — Data Protection & IT in Spain

GDPR applies to any organisation that processes personal data of EU residents, regardless of where the organisation is based. A data protection lawyer can advise on compliance.

Fines can reach €20 million or 4% of global annual turnover (whichever is higher). A data protection lawyer can help implement compliant processes to minimise risk.

Need an English-Speaking Lawyer in Spain?

Browse our verified directory of law firms across Spain's major cities. All listed firms offer English-language legal services to expats and foreign nationals.

Find My Lawyer in 60 Seconds

Spanish Data Protection: RGPD & LOPDGDD — AEPD Fines & Compliance (2025)

Spain implements RGPD (GDPR) through the Ley Orgánica 3/2018 de Protección de Datos y garantía de los Derechos Digitales (LOPDGDD). The Spanish supervisory authority is the Agencia Española de Protección de Datos (AEPD).

AEPD Major Sanctions (Selected Cases)

CompanyFineYearViolation
Endesa Energía€3,000,0002022Illegal energy contract using third-party data without consent
Vodafone España€8,150,0002021Unlawful processing, inadequate security, spam
Caixabank€6,000,0002023RGPD art. 13/14 — inadequate information to clients
BBVA€5,000,0002021Insufficient transparency in data processing
Mercadona€2,520,0002021Illegal facial recognition system in stores (RGPD art. 9 biometric data)

LOPDGDD — Spanish-Specific Provisions

TopicSpanish Rule (LOPDGDD)
DPD (Data Protection Delegate)Mandatory for public bodies, colleges, teaching centres, credit institutions, insurance companies, ISPs, gambling companies, advertising platforms (art. 34 LOPDGDD — broader list than RGPD)
Age of consent (menores)14 years (LOPDGDD art. 7 — Spain chose 14, EU minimum is 13)
Derecho al olvido digitalSpecific right to request deletion from search engines, social networks (art. 93, 94 LOPDGDD)
Testamento digitalRight to designate a person to manage digital data after death (art. 96 LOPDGDD)
Derecho a la desconexión digitalEmployees' right to digital disconnection outside working hours (art. 88 LOPDGDD — ET art. 20 bis)
Videovigilancia laboralEmployer may monitor employees via CCTV but must notify — covert monitoring requires specific legal basis (art. 89 LOPDGDD)
🔍 TL;DR — RGPD/LOPDGDD for Businesses in Spain
  • AEPD fines up to €20M or 4% global turnover — has fined banks €5–8M in recent years
  • Age of digital consent: 14 in Spain (not 16 as in Germany/Austria)
  • DPD (DPO) mandatory for a wider list of sectors than RGPD minimum
  • Right to digital disconnection: employees cannot be required to be contactable 24/7
  • Facial recognition: biometric data is special category (RGPD art. 9) — Mercadona was fined €2.5M for unlawful store system