THE AEPD SETS OUT A ROADMAP TO STRENGTHEN COMPLIANCE WITHIN THE GENERAL STATE ADMINISTRATION
New guidance from the Spanish Data Protection Agency (AEPD): on 14 July 2026, the agency published a set of recommendations to strengthen compliance with data protection regulations within the General State Administration, following a series of consultations with the undersecretaries and data protection officers (DPOs) of ministries and agencies, which culminated in a meeting with more than seventy data protection officers at the National Institute of Public Administration. The document does not impose new organisational requirements nor does it limit the autonomy of each ministry; rather, it identifies best practices that can serve as a reference for strengthening the governance models already in place.
Among the main lines of action, the guide recommends: (i) structurally recognising the role of the DPO, preferably by including it in the list of posts and assigning it a high administrative grade (29–30, minimum 28); (ii) opting to designate a specific unit — such as a sub-directorate — or to establish a data protection committee or office, rather than entrusting the role solely to an individual, to ensure the continuity of functions, (iii) formalising, through internal policies, the DPO’s involvement in records of processing activities, impact assessments, public procurement and the drafting of regulations, and (iv) explicitly assessing the risks of conflicts of interest where the DPO combines their duties with another post.
In the regulatory sphere, the AEPD recommends incorporating the data protection perspective from the initial stages of the legislative process, using the regulatory impact assessment report and its own guidance on the matter, and including the DPO’s reasoned report with requests for mandatory reports submitted to the agency. With regard to training, the guidance emphasises that access to the role of DPO should be based on well-established knowledge combining legal, organisational and technological skills, given the increasing complexity of data processing operations.
The key new feature of the document is its treatment of artificial intelligence: the AEPD already has its own internal policy on generative AI, making it the first Spanish public administration body to have such a policy, and it offers this as a model for other organisations to follow. It recommends a phased roll-out — raising awareness amongst senior management, compulsory training prior to accessing AI tools, and internal collaboration networks — and suggests that the DPO should form part of any AI or security committees that are established, given their privileged position to detect risks to both personal and corporate data.
This document will be supplemented by future measures aimed at consolidating a stable framework for collaboration between the AEPD and the bodies of the General State Administration, including improvements to the management of conflicts of interest during the appointment, tenure and dismissal of Data Protection Officers (DPOs). Anticipating these guidelines not only facilitates a smoother relationship with the agency but also strengthens institutional trust and the quality of public administration in the field of data protection.
Other up to date
Our offices








