Spain Data Removal Guide (2026)
Spanish residents may exercise GDPR and LOPDGDD rights against covered controllers, including requests to access, correct, erase, restrict, or object where the legal conditions apply. Public registers, business records, advertising systems, and international providers have separate scope and exceptions.
Research status: sources last checked 2026-09-07.
This page is educational orientation, not legal advice. The legal fields below are a research snapshot; eligibility, exemptions, deadlines, penalty rules and broker routes can change. Verify the current statute and regulator guidance before relying on a right or filing a complaint.
At a glance
- Governing law
- EU GDPR / LOPDGDD
- Response deadline
- GDPR rights requests: within 1 month; a 2-month extension may apply for complexity or request volume with notice
- Regulator
- Agencia Española de Protección de Datos (AEPD)
- Private right of action
- Potential: GDPR Article 82 compensation and other judicial remedies where the claim and applicable conditions are satisfied
EU General Data Protection Regulation (GDPR) + Ley Orgánica 3/2018 (LOPDGDD)
Spain applies the EU GDPR alongside the Ley Orgánica 3/2018 de Protección de Datos Personales y garantía de los derechos digitales (LOPDGDD). The AEPD supervises data protection, while LOPDGDD Article 23 recognises advertising-exclusion systems. GDPR rights remain subject to legal bases, identification, retention, public-register rules, and other exceptions. Controllers generally respond within one month and may extend by two months for complex or numerous requests with notice; the AEPD complaint route is available when a rights request is unanswered or unsatisfactory.
Read the full EU GDPR / LOPDGDDexplainer →Scope, penalties, private right of action, enforcement history.
What rights do Spain residents have?
- →Right of access to personal information (Article 15 GDPR / Art. 13 LOPDGDD)
- →Right to rectification (Article 16 GDPR / Art. 14 LOPDGDD)
- →Right to erasure / "Derecho de Supresión" where Article 17 conditions apply (Article 17 GDPR / Art. 15 LOPDGDD)
- →Right to object to direct marketing; objections to other processing are conditional (Article 21 GDPR / Art. 18 LOPDGDD)
- →Digital-disconnection and post-mortem digital-rights provisions under the LOPDGDD, within their statutory scope
- →Right to submit a formal complaint (reclamación) to the AEPD
Who holds your data in Spain?
A Spain request may involve mercantile and other public registers, official gazettes, business or credit-information providers, telephone directories, telemarketing systems, professional profiles, or international data services. Identify the controller, exact listing, natural-person versus legal-entity record, source, legal basis, and retention or publication rule before assuming that a provider can change the data.
Public-record sources brokers scrape
- Mercantile and other official/public registries: source-specific disclosure and correction rules
- Boletín Oficial del Estado (BOE) and provincial official gazettes: publication and source-record rules
- Commercial, credit, and business-information providers: provider-specific privacy and accuracy routes
- Telephone directories and telemarketing lead lists: separate listing and advertising-opposition routes
How to remove your data in Spain
- 1Register the relevant phone, postal, email, or SMS/MMS channels with the free Lista Robinson. The service says registration can take up to two months to become fully effective; direct consent, an existing relationship, or a company-level objection can affect the result.
- 2Identify the controller and exact listing, then send a written GDPR access, correction, objection, or Article 17 erasure request using the current privacy contact or DPO route. Provide only proportionate identity information if needed.
- 3For mercantile, gazette, directory, credit, or other source records, contact the relevant custodian separately about correction, disclosure, retention, and publication rules; a provider request does not necessarily amend the underlying source.
- 4If the controller does not respond within the applicable period or the response is unsatisfactory, preserve the request and response and use the current AEPD rights-complaint route. A complaint does not guarantee deletion or a particular enforcement outcome.
Generate requests in under 60 seconds
Generate requests for 1,034 US/global broker workflows for $9
What if a company ignores your request?
Consider the Agencia Española de Protección de Datos (AEPD) information or complaint route above if the controller does not respond or the response is unsatisfactory. This guide records the following penalty orientation: Up to €20M or 4% of worldwide annual turnover, whichever is higher, for specified GDPR infringements. The private-action note is: Potential: GDPR Article 82 compensation and other judicial remedies where the claim and applicable conditions are satisfied. Neither field is an individual award or a promise of enforcement.
Open the Agencia Española de Protección de Datos (AEPD) information or complaint route ↗FAQ: Spain data removal
What is the Lista Robinson in Spain?+
The Lista Robinson is a free advertising-exclusion service managed by Adigital and recognised under LOPDGDD Article 23. It supports phone, postal, email, and SMS/MMS preferences; the service says full effectiveness can take up to two months, and consent, an existing relationship, the channel, and a direct objection can change the result. It is not a universal deletion mechanism for public records or broker copies.
How do I exercise my "Derecho de Supresión" in Spain?+
Send a written Article 17 request to the controller's current privacy contact or DPO, identifying the data and the basis for the request without oversharing. The AEPD states that rights requests generally receive a response within one month, with a possible two-month extension for complexity or request volume; exceptions may permit retention, and a response is not a guaranteed deletion.