Any company wishing to verify a candidate’s background in Spain needs to understand three elements of the legal framework: the European regulation that applies directly, the Spanish law that supplements it, and the authority that enforces it.
The GDPR: direct application
As a Member State of the European Union, Spain directly applies the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679). Its principles of lawfulness, data minimisation, purpose limitation and transparency form the basis of any recruitment process: only information that is strictly necessary to assess a candidate’s suitability for the specific role may be collected.
The LOPDGDD: Spain’s supplementary legislation
Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD) supplements the GDPR with rules specific to the Spanish context, including the restriction on access to creditworthiness databases (Article 20.1(e)) already mentioned in connection with ASNEF and RAI.
The AEPD: the authority that supervises and sanctions
The Spanish Data Protection Agency (AEPD) is the authority that supervises compliance with both rules in the employment context. It does not merely publish guidance: it investigates complaints and actively imposes sanctions. The two cases most frequently cited in the sector — the EUR 2,000,000 fine imposed on Amazon Road Transport Spain for requiring criminal records without a legal basis, and the EUR 42,000 fine for consulting ASNEF in relation to a candidate — are not isolated cases, but examples of the rules being actively enforced in the Spanish market.
How much can non-compliance cost?
Article 83 of the GDPR establishes two levels of fines: up to EUR 10 million or 2% of the company’s total worldwide annual turnover for serious infringements, and up to EUR 20 million or 4% of total worldwide annual turnover for the most serious infringements, with the higher amount applying in each case. Title IX of the LOPDGDD in turn classifies infringements as minor, serious and very serious within these limits.
The principle that summarises the entire framework: proportionality
If there is one criterion that an HR manager should remember from this entire legal framework, it is proportionality: every piece of information collected must have a direct, justifiable and documented relationship with the specific role. Anything that does not meet this criterion is, at the very least, a risk; and, as the AEPD cases demonstrate, often also grounds for a sanction.
See also: Human Risk and Background Checks in Spain: The 2026 Reference Guide, Criminal Record Certificates in Spain: What an Employer May (and May Not) Require and AEPD Sanctions for Unlawful Background Checks: Real Cases in Spain
From