Article · Compliance

GDPR for Spanish law firms: 7 obligations most get wrong

Where AEPD fines actually come from and what your firm needs to fix: processors, records, WhatsApp, retention and breaches. With articles and deadlines.

7 min read
Glass facades of an office building seen from below.

The Spanish data protection authority’s 2025 annual report contains three figures worth reading in sequence: 30,931 complaints — up 64% on the previous year, the highest in the AEPD’s history — €48.1 million in fines, and an average fine of €148,000 per procedure. Twelve cases closed above the million-euro mark.

None of those record fines went to a law firm. Which is precisely the problem: the comfortable reading (“this is about airlines and telecoms”) is what keeps most firms where they are — with a “GDPR pack” a consultant sold them in 2018, a folder nobody has opened since, and the conviction that the matter is settled.

It is not. A law firm routinely processes what article 9 of the GDPR calls special categories of data — health in a workplace accident, criminal records in a defence brief, family circumstances in a divorce — and does so with the infrastructure of an ordinary small business. The AEPD has already sanctioned law firms for missing privacy clauses in their engagement letters, for passing data to third parties without a legal basis, and for the absence of basic security measures. And here is the only opinion in this article: firms don’t breach the GDPR in the privacy policy on their website; they breach it in how case files move around inside the firm. The first problem is fixed with a template. The second is not.

These are the seven obligations where the real non-compliance concentrates, each with its article and with what meeting it actually looks like.

1. The record of processing activities (art. 30)

The widespread belief is that the record is for large companies. For a law firm it is false: the article 30.5 exemption for organisations under 250 employees falls away when the processing includes special categories of data — and in a law firm it nearly always does.

The record is not a filing with the AEPD — the old register of ficheros disappeared in 2018 — but an internal document: what data you process, for what purpose, on what legal basis, who receives it, how long you keep it and how you protect it. It is the first thing an inspector asks for, because its absence proves nothing else can be in order. The AEPD offers a free tool, Facilita RGPD, that produces a basic record in an afternoon.

2. A processing agreement with every vendor (art. 28)

Every third party that touches your clients’ data on the firm’s behalf is a processor, and article 28 requires a specific contract with each one: the practice management software, the cloud email, the gestoría that runs payroll, the IT contractor, the AI tool that transcribes meetings.

The test is simple and almost no firm passes it: ask today for the signed data processing agreement with your three main vendors. If it doesn’t surface in ten minutes, it doesn’t exist. Signing with a vendor that offers no such contract — or that cannot say where the data is hosted — means adopting their non-compliance as your own, because choosing processors with adequate guarantees is the controller’s responsibility: the firm’s.

3. Actually informing the client (arts. 13 and 14)

The client must know, at the moment of engagement, who the controller is, what their data is used for, on what legal basis, how long it will be kept, who it will be disclosed to and what rights they have. That belongs in the engagement letter, not behind a link in the website footer.

Disclosures are the classic blind spot. An ordinary matter means passing data to the procurador, the court, the opposing party, sometimes an expert or an insurer. All of that is processing and all of it must be disclosed. So are the channels: if the firm communicates with clients over WhatsApp — and it does — that channel has to appear in the privacy information. A channel that exists in fact but in no clause is exactly the kind of inconsistency that surfaces at the worst possible moment.

4. Security proportionate to what you hold (art. 32)

Article 32 imposes no specific measures: it imposes measures “appropriate to the risk”. For criminal defence files, health data or minors, the bar is high — and common practice sits far below it: one shared password for the case management system, no second factor, unencrypted backups on an office drive, and everyone able to open everything.

Appropriate to a law firm’s risk, today: encrypted devices and backups, two-factor authentication on anything that touches case files, and access control by role and by matter — the clerk who does the invoicing cannot open the criminal file, and there is a trail of who opened what. That access log is also the only way to demonstrate diligence when something goes wrong.

5. Getting matters out of personal channels

The case file that leaves the firm through a partner’s personal phone is the quietest breach there is: client messages mixed in with the family group chat, photos of court documents in a personal camera roll, an unencrypted handset lost in a taxi. None of it passes through the record of processing activities, or the article 32 measures, and none of it survives the partner leaving the firm.

The answer is not banning WhatsApp — the client has already decided that is their channel — but institutionalising it: a firm-owned number, archiving, and a mention in the privacy information. How to do that, with the three models and their professional-conduct fit, is in the WhatsApp Business guide for law firms.

6. Retention with a deadline, not forever

“We keep everything just in case” breaches the storage limitation principle (art. 5.1.e), and in a law firm “everything” includes especially sensitive data. Erasure is not optional: it is an active obligation that requires knowing when liability actually expires for each type of matter.

There is no single correct period. Due diligence documentation under Ley 10/2010 must be kept ten years; tax records for as long as Hacienda can audit; the case file for as long as professional liability can be claimed. What is demanded of you is a retention schedule by matter type, applied — restrict first, erase after. A 2009 divorce file on an accessible server is not an archive: it is a liability.

7. A breach protocol somebody actually knows (arts. 33 and 34)

The 2025 numbers speak plainly: sanction procedures for security breaches grew 157% — from 30 to 77 cases — and produced almost €20 million in fines, 40% of everything the AEPD imposed that year. The dominant pattern is ransomware with data exfiltration.

When it happens, the firm has 72 hours from becoming aware to notify the AEPD, and must inform the affected clients if the risk is high. That deadline leaves no room for improvising: it requires knowing in advance who decides, who notifies and where the actions taken are documented. Breaches you decide not to notify must be recorded too, with the reasoning why. A lost laptop with unencrypted case files is a breach; pretending otherwise turns an incident into an infringement.

What about a data protection officer?

Here the surprise runs the other way: most law firms are not required to appoint a DPO. The article 37 obligation is triggered by large-scale processing of special categories or systematic monitoring — not by being a law firm. Spain closed 2025 with 126,176 DPOs registered with the AEPD; for a mid-sized firm, a voluntary external DPO is good practice and an early-resolution channel the regulator itself prioritises — but it is a decision, not a requirement. What you must be able to show is that you took it deliberately, in writing.

What to demand from your tools

Five of the seven obligations depend directly on the software the firm runs on. A serious case management system has to offer an article 28 processing agreement, EU hosting, encryption, access control by role and by matter, an access log and configurable retention periods. That is the list we applied when building Mandato, and it is the list you should put to any vendor before signing — the price of one that fails it is yours to pay, at an average of €148,000 per fine.

Where to start this week

Not with the privacy policy. Ask your three main software vendors for their data processing agreements and put them in a folder you can find in ten minutes. If one doesn’t exist, demand it from the vendor: drafting it is their obligation. With that you will have met article 28 where it hurts most — and discovered, along the way, which of your vendors take your firm seriously.

Less admin. More law.

Mandato brings matters, communications, billing and compliance into one platform built for firms in Spain.

Start free 14-day trial14 days. No card.
Start free 14-day trial