Skip to content
EUMEDIUM coverage2 enforcement actions

Spain — AI Framework under GDPR (AEPD): AI Compliance Requirements

Spain's AEPD has published comprehensive AI-GDPR guidance including a 10-step AI adequacy methodology, algorithmic bias documentation requirements, and employee monitoring AI guidance. The AEPD is an active enforcement authority targeting AI systems without documented GDPR compliance frameworks — it opened 147 AI-related sanctioning proceedings between January 2025 and March 2026 (a reported 340% increase over the prior period), with roughly 46% of resolved proceedings ending in a fine (over €1.75M in fines in that 15-month window alone), and imposed its largest and most directly AI-relevant fine to date — €10,043,002 against AENA, the state airport operator, for biometric facial-recognition boarding without a valid DPIA (reported Nov 2025, under appeal — see enforcementActions) — alongside the earlier, smaller 2021 Mercadona retail-facial-recognition fine. (CYCLE 19, 2026-08-22: added the AENA fine and the AI-caseload statistics, both previously absent from this entry.)

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 1, 2023

Maximum Penalty

€20,000,000 or 4% of global annual turnover (GDPR fines applied by AEPD)

What Your Business Must Do

2 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

AI System GDPR Adequacy Assessment (AEPD Methodology)

High Priority

Conduct a formal AEPD 10-step AI adequacy assessment mapping each AI system's data flows, legal basis, and risks. Required before deploying AI in Spain.

GDPR (as applied by AEPD 10-step methodology)

Algorithmic Bias Documentation (Spain)

Medium Priority

AEPD requires documenting bias testing methodology and mitigation for AI systems making decisions about individuals in Spain.

GDPR Art. 5(1)(a), Art. 22 (fairness/non-discrimination, as applied by AEPD)

Who Does This Apply To?

Applies to any organisation deploying AI systems that process the personal data of individuals in Spain — the AEPD enforces GDPR against AI systems lacking a documented compliance framework. In scope: any business making AI-driven decisions about Spanish residents (must complete the AEPD 10-step AI adequacy assessment mapping each system's data flows, legal basis, and risks before deployment), operators of retail or workplace facial-recognition systems (the Mercadona €2.52M fine established that retail facial-recognition AI requires explicit consent and a DPIA — CYCLE 5, 2026-08-22: searched this cycle for an appeal outcome; none found reported either way, so the fine's current status is treated as the AEPD's original 2021 decision, not independently reconfirmed as final), and AI systems making decisions about individuals (algorithmic-bias testing and mitigation must be documented). Maximum exposure: €20M or 4% of global annual turnover.

Recent Enforcement Actions

2021-07-26Source verified· as of 2026-08-22

Against:

2025-11 (fine announced/reported); appeal pending as of 2026-08-22Source verified· as of 2026-08-22

Against:

Recent Regulatory Guidance

guidance2023-06

AEPD AI Adequacy Assessment — 10-Step Methodology (2023)

AEPD published a 10-step adequacy assessment for AI systems covering: purpose specification, legal basis, proportionality, data minimization, accuracy, security, transparency, individual rights, international transfers, and risk mitigation. Available as a self-assessment tool at aepd.es.

Industry Playbooks covering Spain — AI Framework under GDPR (AEPD)

These industry playbooks include jurisdiction-specific checklist items and guidance for Spain — AI Framework under GDPR (AEPD).

Frequently Asked Questions

Does Spain — AI Framework under GDPR (AEPD) apply to my business?

Spain's AEPD has published comprehensive AI-GDPR guidance including a 10-step AI adequacy methodology, algorithmic bias documentation requirements, and employee monitoring AI guidance. The AEPD is an active enforcement authority targeting AI systems… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Spain — AI Framework under GDPR (AEPD) is: €20,000,000 or 4% of global annual turnover (GDPR fines applied by AEPD). Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Spain — AI Framework under GDPR (AEPD)?

The 2 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.aepd.es/en/rights-and-duties/artificial-intelligence

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan