Spain issues more GDPR fines than any other country in the EU — and the body behind that volume is the AEPD. It is easy to confuse with Spain’s AI agency AESIA; they are different regulators with different jobs, and getting them mixed up is a common error. This is a profile of what the AEPD is, what it does, how it changed leadership in 2025, and how it differs from AESIA. Every fact is sourced.
Quick facts
- Full name: Agencia Española de Protección de Datos (AEPD) (AEPD)
- Role: Spain’s GDPR supervisory authority — the national body that enforces data-protection law in Spain and sits on the EDPB
- Legal status: an Autoridad Administrativa Independiente (independent administrative authority) (AEPD, Memoria 2025)
- Governing law: the Ley Orgánica 3/2018, de 5 de diciembre (LOPDGDD — the Spanish data-protection law that complements the GDPR) (AEPD, Memoria 2025)
- President: Lorenzo Cotino Hueso — appointed under Article 48 LOPDGDD, ratified by the Congress of Deputies on 19 February 2025, took office on 3 March 2025; five-year term, renewable once (AEPD — appointment; AEPD — toma de posesión)
- Deputy (Adjunto a la Presidencia): Francisco Pérez Bes — appointed alongside the President; the adjuntía is a newly introduced figure (AEPD, Memoria 2025)
- Headquarters: C/ Jorge Juan, 6, 28001 Madrid (AEPD)
- Website: aepd.es
What the AEPD is — and what it is not
The AEPD is Spain’s data protection authority (DPA — the independent national regulator that supervises and enforces data-protection law) and Spain’s GDPR supervisory authority. It is an Autoridad Administrativa Independiente (AEPD, Memoria 2025) — structurally independent of government — and one of the 27 national authorities on the EDPB. It applies the GDPR together with the Ley Orgánica 3/2018 (LOPDGDD), the Spanish law that complements the Regulation.
What it is not: it is not Spain’s AI Act authority. That is a separate body — AESIA — with a different mandate and a different legal nature (see the disambiguation below). The AEPD’s AI-relevant work, like every DPA’s, is GDPR enforcement, which is why it sits on the GDPR pillar.
What the AEPD actually does
Its job is the standard GDPR supervisory-authority remit — complaints, investigations, authorisations, corrective measures and fines. What stands out is volume: by number of GDPR fines, Spain has consistently been the EU’s most prolific enforcer (CMS GDPR Enforcement Tracker). That makes the AEPD a useful bellwether: trends often show up first in the sheer count of Spanish decisions, even where individual amounts are smaller than the headline Irish or Luxembourg cases.
It also runs an active programme on technology and rights — children’s data, biometrics, AI-driven processing — but always through the GDPR, not the AI Act.
AEPD vs AESIA — Spain’s two regulators, do not confuse
This is the single most common mistake about Spanish tech regulation. Spain has two distinct authorities:
- AEPD — data protection. An independent administrative authority, structurally separate from government, enforcing the GDPR (with the LOPDGDD). The subject of this profile.
- AESIA — artificial intelligence. A state agency attached to the ministry (via SEDIA), supervising the AI Act. Not an independent authority.
They are not the same body, do not have the same legal status, and do not enforce the same law. A privacy complaint goes to the AEPD; AI Act market-surveillance is AESIA. When a source says “Spain’s regulator fined an AI company”, it is almost always the AEPD acting under GDPR — not AESIA under the AI Act.
Leadership
The AEPD is led by a President and, since 2025, a Deputy (Adjunto a la Presidencia) — a newly introduced figure (AEPD, Memoria 2025). Both are selected through the procedure in Article 48 of the LOPDGDD and the AEPD Statute: a selection committee evaluation followed by ratification by the Congress of Deputies, for a five-year term renewable once (AEPD).
- President: Lorenzo Cotino Hueso. A Professor of Constitutional Law (University of Valencia). Ratified by the Congress of Deputies on 19 February 2025 and took office on 3 March 2025 (AEPD — appointment; AEPD — toma de posesión).
- Deputy (Adjunto a la Presidencia): Francisco Pérez Bes. Appointed alongside the President under the same procedure (AEPD, Memoria 2025).
If you have a memory of an earlier AEPD president, update it: the current leadership is Cotino Hueso (President) and Pérez Bes (Deputy), in post since 2025 under the LOPDGDD selection model.
What this means for you
- If you process personal data and reach Spanish users: the AEPD is your supervisory authority. Given Spain’s enforcement volume, the practical likelihood of a decision is real even for mid-sized matters — not only the headline cross-border cases.
- If your concern is an AI system in Spain (AI Act compliance): that is AESIA, not the AEPD. Mixing them up sends you to the wrong regulator.
- If you are tracking EU enforcement trends: watch the Spanish count, not just the euro totals — Spain leads the EU by number of GDPR fines (CMS Enforcement Tracker).
- If you are a journalist or researcher: “Spain’s privacy regulator” = the Agencia Española de Protección de Datos, an Autoridad Administrativa Independiente under Ley Orgánica 3/2018, seat C/ Jorge Juan 6, Madrid, led since 2025 by President Lorenzo Cotino Hueso and Deputy Francisco Pérez Bes — distinct from AESIA, Spain’s (ministry-attached) AI authority.
TL;DR
The AEPD (Agencia Española de Protección de Datos) is Spain’s GDPR supervisory authority and, by number of fines, the EU’s most prolific data-protection enforcer (CMS Enforcement Tracker). It is an Autoridad Administrativa Independiente governed by the Ley Orgánica 3/2018 (LOPDGDD), seated at C/ Jorge Juan 6, Madrid. It is not Spain’s AI Act body — that is the separate, ministry-attached AESIA. Leadership changed in 2025 under the LOPDGDD selection model: President Lorenzo Cotino Hueso and Deputy (Adjunto a la Presidencia) Francisco Pérez Bes, ratified by the Congress of Deputies on 19 February 2025, in office since 3 March 2025, five-year term renewable once. Its AI work, like every DPA’s, runs through the GDPR — see the GDPR pillar.
Sources
- AEPD — Presidencia (organigrama) — official name, current President, headquarters address (C/ Jorge Juan 6, 28001 Madrid)
- AEPD — Lorenzo Cotino Hueso and Francisco Pérez Bes appointed President and Deputy — Article 48 LOPDGDD procedure, Congress ratification 19 February 2025, five-year renewable term
- AEPD — Lorenzo Cotino Hueso and Francisco Pérez Bes take office (3 March 2025) — toma de posesión date
- AEPD — Memoria 2025 (official PDF) — Autoridad Administrativa Independiente, Ley Orgánica 3/2018 (LOPDGDD), the new adjuntía figure, President Lorenzo Cotino and Deputy Francisco Pérez Bes
- CMS GDPR Enforcement Tracker — Spain as the EU leader by number of GDPR fines
- GDPR — Regulation (EU) 2016/679 (EUR-Lex)
- GDPR pillar · EDPB profile · AESIA profile · aepd.es