Data protection: GDPR rights and claiming before the AEPD
Last updated 16 July 2026 · Reviewed by Jaime Piñeira Pardo, lawyer registered with the ICAM bar, no. 138826 · English version of our Spanish guide.
The GDPR and Ley Orgánica 3/2018 (the Spanish Data Protection Act) grant you rights over your personal data: access, rectification, erasure (right to be forgotten), objection, restriction and portability. The company must assist you within 1 month. If they do not respond or misuse your data, you can claim for free before the AEPD. Managora prepares your request and submits the claim for you.
We handle the whole procedure for you, from start to finish.
You describe your case in a chat and sign; we file it with the Spanish authorities. Fixed price from €157.00 (21% VAT included), plus the tasa (official fee) where there is one.
What is new, and the law that applies
- Current regulation: Regulation (EU) 2016/679 (GDPR), applicable since 25 May 2018, and Ley Orgánica 3/2018, of 5 December (LOPDGDD), in force since 7 December 2018. As of 17 July 2026, they remain the current framework, with no structural changes.
- The claim procedure before the AEPD is governed by the LOPDGDD and Ley 39/2015. The AEPD maintains a general form and several specific forms depending on the reason (rights, advertising, defaulters, video surveillance).
- Claiming before the AEPD is free: there is no tasa (official fee) for submitting a claim or for exercising your rights before a company.
What rights does the GDPR give you over your personal data?
The General Data Protection Regulation (GDPR, EU Regulation 2016/679) and Ley Orgánica 3/2018 (the Spanish Data Protection Act) grant you a set of rights that you can exercise against any company or organisation processing your data. They are free and personal: you exercise them yourself or through an authorised representative.
The main ones are: access (knowing what data they have about you and what for), rectification (correcting inaccurate data), erasure or right to be forgotten (having them deleted), objection (stopping them from using them for a purpose, for example advertising), restriction of processing (keeping them but not using them while a discrepancy is resolved) and portability (receiving your data in a reusable format and taking them to another company).
You must direct the request to the data controller (the company). As a general rule, it does not need to be motivated: the objection to processing for direct marketing or advertising purposes is unconditional and does not require stating any reason (article 21.2 GDPR), whereas the objection based on the legitimate interest of the controller or a public interest mission does require you to express reasons related to your particular situation (article 21.1 GDPR). The company is obliged to answer you and cannot charge you, unless the request is manifestly unfounded or excessive (article 12.5 GDPR).
How to claim before the AEPD if a company does not respond or misuses your data?
If you have exercised a right and the company does not answer you within the deadline, or the response is unsatisfactory, you can submit a claim for failure to attend to the exercise of your rights before the Spanish Data Protection Agency (AEPD), which the Agency processes as a rights procedure. You can also claim for an improper use of your data: unwanted advertising, transfer without consent, inclusion in a defaulters file or video surveillance.
The claim is preferably submitted online, filling in the form on the AEPD electronic headquarters (sedeaepd.gob.es), identifying yourself with a digital certificate, DNIe or Cl@ve (the Spanish electronic identity system). It can also be done on paper in accordance with Ley 39/2015 (the Spanish Administrative Procedure Act). Claiming before the AEPD is free.
You must provide evidence or indications of the infringement: in the claim for unattended rights, the copy of the request you sent to the company and the response received (or proof that there was none). The AEPD examines the admission for processing and, where appropriate, opens investigation proceedings against the company.
Managora drafts your claim, gathers the evidence and submits it for you at the AEPD headquarters. You can see the updated amount in the reclamacion_aepd procedure file.
What is the right to be forgotten and how is it exercised?
The right to be forgotten is the digital aspect of the right to erasure: it allows you to request that your personal data be deleted when they are no longer necessary, when you have withdrawn consent, when you object and there is no prevailing legitimate reason, or when they have been processed unlawfully (article 17 GDPR).
On search engines, you can request the removal of results associated with your name when the information is inadequate, irrelevant or excessive. The search engine must assess your request and, if it denies it or does not respond, you can claim before the AEPD. Erasure is not absolute: it can yield to freedom of information, legal conservation obligations or public interest.
Managora prepares the erasure request before the company or the search engine and, if they do not attend to it, the claim before the AEPD. You can see the amount in the derecho_olvido_aepd file.
What happens if there is a data security breach?
A security breach is any incident that causes the destruction, loss, alteration or unauthorised access or communication of personal data: a cyberattack, sending data to the wrong recipients, losing a device or the theft of a database.
The company (data controller) must notify the breach to the AEPD without undue delay and, at the latest, within 72 hours of becoming aware of it, unless it is unlikely to pose a risk to people's rights (article 33 GDPR). If the breach entails a high risk, it must also communicate it without delay to those affected (article 34 GDPR).
Failing to notify on time is a punishable offence. If you are the affected company, Managora prepares and submits the breach notification at the AEPD headquarters within 72 hours. You can see the amount in the denuncia_aepd_brecha_seguridad file. If you are an individual affected by a breach, you can claim before the AEPD for the improper use of your data.
When must a company appoint a Data Protection Officer (DPO)?
The Data Protection Officer (DPO, or DPD in Spanish) is the person who supervises GDPR compliance in the organisation. It is mandatory in 3 cases under article 37 GDPR: when the processing is carried out by a public authority or body; when the core activity requires regular and systematic monitoring of individuals on a large scale; and when special categories of data (health, ideology, biometrics) or criminal data are processed on a large scale.
The LOPDGDD (article 34) extends the obligation to numerous sectors: professional associations, educational centres and universities, credit and financial institutions, insurance companies, investment firms, energy distributors, information society service providers that profile on a large scale, healthcare centres, advertising and commercial prospecting companies, private security companies and gambling operators, among others.
Once appointed, their contact details must be communicated to the AEPD within 10 days (article 34.3 LOPDGDD). Managora communicates and registers your DPO with the AEPD. You can see the amount in the aepd_inscripcion_dpd file.
How much does it cost and how long does it take?
Exercising your rights before a company is free and submitting a claim before the AEPD is too: the Agency does not charge a tasa (official fee). Managora's cost for preparing and submitting the procedure appears in each file (reclamacion_aepd, derecho_olvido_aepd, denuncia_aepd_brecha_seguridad, aepd_inscripcion_dpd): you can see the updated amount there.
The legal deadlines are clear: the company has 1 month to respond to your request (extendable by 2 more months if it is complex); the notification of a breach to the AEPD is 72 hours; and the communication of the DPO is 10 days. The subsequent processing by the AEPD after a claim depends on each case.
Step by step
- 1
Exercise your right before the company first(The company must respond within 1 month (extendable by 2 more months if it is complex))
Send the request in writing to the data controller (access, rectification, erasure, objection, restriction or portability). Identify yourself and keep a copy and proof of sending. This preliminary step is mandatory to be able to claim later for failure to attend to the exercise of rights.
- 2
Wait for the response or the end of the deadline
If the company does not answer within 1 month or gives you an unsatisfactory response, the avenue for claiming before the AEPD is open.
- 3
Gather the evidence
Prepare the copy of the request you sent to the company and the response received (or proof that there was no response), plus any other evidence of the misuse of your data.
- 4
Access the AEPD electronic headquarters and identify yourself
Enter sedeaepd.gob.es and identify yourself with a digital certificate, DNIe or Cl@ve. You can also submit it on paper in accordance with Ley 39/2015.
- 5
Fill in the claim form
Choose the form according to the reason (unattended rights, advertising, defaulters, video surveillance or others), describe the facts and attach the evidence. Submission is free.
- 6
Submit the claim and keep the receipt(The subsequent processing by the AEPD depends on the case)
Register the claim and keep the receipt. The AEPD will study its admission for processing and, where appropriate, will open proceedings against the company.
GDPR rights and the company's response deadline
| Right | What it allows you | Company deadline |
|---|---|---|
| Access | Knowing what data they have about you, what they use them for and who they transfer them to | 1 month (+2 months if complex) |
| Rectification | Correcting inaccurate data or completing incomplete ones | 1 month (+2 months if complex) |
| Erasure (right to be forgotten) | Having your data deleted when they are no longer necessary or the processing is unlawful | 1 month (+2 months if complex) |
| Objection | Stopping them from processing your data for a purpose (for example, advertising) | 1 month (+2 months if complex) |
| Restriction | Keeping but not using your data while a discrepancy is resolved | 1 month (+2 months if complex) |
| Portability | Receiving your data in a reusable format and transmitting them to another company | 1 month (+2 months if complex) |
Key deadlines in data protection
| Action | Who | Legal deadline | Regulation |
|---|---|---|---|
| Responding to your rights request | The company (controller) | 1 month, extendable to 3 in total | Art. 12.3 GDPR |
| Notifying a security breach to the AEPD | The company (controller) | 72 hours from knowing about it | Art. 33 GDPR |
| Communicating the breach to those affected (high risk) | The company (controller) | Without undue delay | Art. 34 GDPR |
| Communicating the DPO's contact details to the AEPD | Controller or processor | 10 days from appointment | Art. 34.3 LOPDGDD |
| Submitting a claim before the AEPD | The affected citizen | No strict deadline (recommended soon) | LOPDGDD / Ley 39/2015 |
Who is obliged to appoint a DPO?
| Legal basis | Cases |
|---|---|
| Art. 37 GDPR | Public authorities and bodies; regular and systematic monitoring on a large scale; large-scale processing of special categories or criminal data |
| Art. 34 LOPDGDD | Professional associations, educational centres and universities, credit and financial institutions, insurance companies, investment firms, energy distributors, providers profiling on a large scale, healthcare centres, advertising and commercial prospecting, private security and gambling operators, among others |
Claim for unattended rights vs. claim for infringement
| Unattended rights | Claim for infringement | |
|---|---|---|
| When it is used | The company did not attend to your request for access, erasure, rectification, objection, restriction or portability | The company misused your data: spam, transfer without consent, defaulters, video surveillance, breach |
| Mandatory preliminary step | Yes: having previously exercised the right before the company | It is not essential, but it is advisable to provide evidence of the misuse |
| What to provide | Copy of your request and the response (or its absence) | Evidence or indications of the infringement (emails, screenshots, contracts) |
| Cost before the AEPD | Free | Free |
| Possible outcome | The AEPD orders your right to be attended to | The AEPD can investigate and penalise the company |
Official forms and where it is filed
- Claim form before the AEPD (unattended rights, advertising, defaulters, video surveillance or others) ↗
- Templates for requesting the exercise of rights before the controller (access, rectification, erasure, objection, restriction, portability) ↗
- Security breach notification form (art. 33 GDPR) ↗
- Communication of the Data Protection Officer's contact details (art. 34.3 LOPDGDD) ↗
Frequently asked questions
How long does a company take to answer my request?
1 month from receiving your request. If it is complex or there are many requests, it can extend the deadline by 2 more months, but it must notify you within the first month. If it does not respond, you can claim before the AEPD.
How much does it cost to claim before the AEPD?
The AEPD does not charge a tasa (official fee): claiming is free, just like exercising your rights before a company. The cost for Managora to prepare and submit it for you appears in the procedure file.
What do I do if a website does not delete my data (right to be forgotten)?
First request it in writing to the company or the search engine. If they deny it or do not respond within 1 month, you can claim before the AEPD providing the copy of your request. Managora prepares and submits the claim for you.
As a company, can I be fined if I do not notify a breach within 72 hours?
Yes. Article 33 of the GDPR obliges you to notify the breach to the AEPD within a maximum of 72 hours from when it is known, unless it is unlikely to pose a risk. Failing to do so is a punishable offence.
Does my small business need a Data Protection Officer?
Not always. It is only mandatory in the cases of article 37 GDPR (large-scale processing, systematic monitoring or sensitive data) and in the sectors of article 34 LOPDGDD. Many SMEs are not obliged, although they can appoint one voluntarily.
Can I claim before the AEPD and also ask for compensation?
Yes. The claim before the AEPD is administrative and seeks to correct or penalise the infringement. Compensation for damages is claimed through civil proceedings before the courts, and both avenues are compatible.
We handle the whole procedure for you, from start to finish.
You describe your case in a chat and sign; we file it with the Spanish authorities. Fixed price from €157.00 (21% VAT included), plus the tasa (official fee) where there is one.
Related procedures
The price, the tasa (official fee) and the current deadlines are on each procedure page.
- Complaint to the AEPD (Spanish Data Protection Agency) over misuse of your personal dataWe file a complaint before the Agencia Española de Protección de Datos (Spanish Data Protection Agency) ove...
- Right to erasure / right to be forgotten (GDPR art. 17)We draft the request to the data controller so that you can exercise your right to erasure, also known as t...
- Notification / complaint to the AEPD (Spanish data protection authority) over a personal data breach (GDPR art. 33)We draft the notification of a personal data breach to the AEPD (Spanish data protection authority) within ...
- AEPD: registration / notification of the Data Protection Officer (DPD)We handle the initial registration, amendment, replacement or removal of your Data Protection Officer (DPD)...
- Recurso de reposición (administrative appeal) before the AEPD (Spanish Data Protection Agency) (LO 3/2018 + Ley 39/2015)We draft and file with the AEPD (Spanish Data Protection Agency) the optional recurso de reposición (admini...