Your cookie preferences

EDPB guidance · Art. 7 GDPR

We use technical cookies essential for the platform to work (login, security, sessions). We would also like to use analytics cookies to understand how to improve it.

You can accept all, reject all, or choose which categories to switch on.Your consent is valid for 6 months and you can withdraw it at any time from the footer.

You will find everything in our privacy notice.

All news
Regulation September 15, 2026 6 min

When a DPO is mandatory in Spain: the sixteen cases in Article 34

Art. 37(1) GDPR sets three general situations; Art. 34 of the Spanish LOPDGDD adds sixteen sector-specific ones. And a voluntary appointment, which many take to be free, brings the whole regime with it — plus a ten-day deadline

TL;DR

A DPO is mandatory in the three situations of Art. 37(1) GDPR and, in addition, in the sixteen cases of Art. 34(1) LOPDGDD. The voluntary appointment under Art. 34(2) still places the organisation under the same GDPR regime. In both cases — mandatory and voluntary — appointments and departures must be notified to the AEPD within ten days (Art. 34(3)), and the list of officers is public and electronically accessible (Art. 34(4)).

Two lists that add up, not two you choose between

Art. 37(1) GDPR requires a DPO in three situations: processing carried out by a public authority or body; core activities consisting of operations that require regular and systematic monitoring of data subjects on a large scale; and core activities consisting of large-scale processing of special categories under Art. 9 or of Art. 10 data. Art. 34(1) LOPDGDD refers back to that provision and adds “and, in any event, in the case of the following entities”. The conjunction matters: these are not sixteen cases instead of the three, they are sixteen on top of the three. An entity that appears in none of the letters may still be caught by Art. 37, and the reverse also holds.

The sixteen lettered items

  • a) Professional associations and their general councils. b) Educational establishments at any level, and public and private universities.
  • c) Operators of networks and providers of electronic communications services, where they process personal data regularly and systematically on a large scale. d) Information society service providers that build large-scale user profiles.
  • e) Entities under Art. 1 of Law 10/2014 (credit institutions). f) Credit financial establishments. g) Insurance and reinsurance undertakings. h) Investment firms.
  • i) Distributors and retailers of electricity and natural gas. j) Controllers of shared files on creditworthiness and credit, or on fraud prevention, including anti-money-laundering files.
  • k) Advertising and commercial prospecting businesses where they process preferences or build profiles. l) Healthcare centres legally required to keep patient records — with an express carve-out for the health professional practising individually.
  • m) Entities issuing commercial reports on natural persons. n) Gambling operators on electronic channels. ñ) Private security firms. o) Sports federations where they process data on minors.

A voluntary appointment is not a gesture of goodwill

Art. 34(2) provides that an organisation not otherwise caught “may voluntarily appoint” an officer, “who shall be subject to the regime laid down in Regulation (EU) 2016/679 and in this Organic Law”. That means: independence, no conflict of interest, resources, no penalising them for performing their tasks, and reporting to the highest management level. And Art. 34(3) requires the appointment to be notified to the AEPD within ten days “both where designation is mandatory and where it is voluntary”. Putting “DPO” in somebody's email signature without notifying it is a breach that takes a minute to establish.

Art. 34(4) should be read alongside it: the AEPD and the regional authorities maintain an up-to-date list of officers accessible by electronic means. The practical consequence is that the claim “we have a DPO” is checkable by anyone — including a prospective client running due diligence and a competitor preparing a complaint. It is not an internal register: it is public.

Finally, Art. 34(5) allows full-time or part-time commitment depending, among other criteria, on the volume of processing, the special categories handled and the risks to data subjects. This is not a general licence to do the minimum: it is a criterion to be reasoned and worth recording, because it is precisely what gets asked when an officer has not managed to deal with something in time.

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free