Back to glossary

AEPD

1 min read

The AEPD, the Agencia Española de Protección de Datos, is Spain’s independent data protection supervisory authority. It is the body a Spanish organisation notifies after a personal data breach, the body that investigates and sanctions, and the source of the technical guidance most often cited in a Spanish security report.

July 29, 2026
Compartir:

Its role follows from the regulation: it supervises, it receives notifications, it handles complaints from data subjects, and it can impose corrective measures and fines. For a technical team the relevant part is the clock. A breach involving personal data that is likely to present a risk has to be notified to the authority without undue delay and within seventy two hours of becoming aware of it, and where the risk to individuals is high they have to be told as well. Seventy two hours is not seventy two hours to finish the investigation: it is the deadline to notify with whatever is known, and to supplement afterwards.

The second reason it appears in engineering conversations is its published guidance. The authority issues technical material on risk management, on impact assessments and on specific technologies, and referencing it changes a discussion, because it is the position of the body that would carry out any inspection rather than a supplier’s opinion.

Where this touches our work directly is incident response readiness. The observation we record most often is an organisation with a competent technical response plan and no rehearsed answer to who decides that a notification is required, who signs it, and what evidence has to be preserved before systems are rebuilt. Working that out in advance is part of the data protection work where the notification path is prepared before it is needed.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.