Skip to main content

The Spanish Data Protection Authority (AEPD) issues a check-list on regulatory compliance


The Spanish DPA issued a check-list regarding regulatory compliance to facilitate the implementation of GDPR.

According to the DPA, this is a basic method that allows to identify and verify the requirements established in the GDPR. It includes useful aspects to verify the level of compliance, so that the necessary measures can be implemented.

This check-list complements other materials previously issued by the DPA like the Risk Analysis and Impact Assessment guidelines.

Those can be found here and These materials, which constitutes a tool to help reach compliance, complements the Risk Analysis and Impact Assessment guides and the road map made by the Agency for companies and private organizations.

The Regulation establishes that those who process data must apply a set of measures to comply - and be able to demonstrate that they comply - with the new principles and rights included in the new regulation. It also states that the risk analysis processes must be carried out objectively, consciously and verifiably by those responsible. In this task of identifying the risks for their subsequent management, the compliance risks associated with the regulatory framework must be taken into account. Thus, it includes the need to keep all the processes documented in order to demonstrate diligence in compliance and accountability. The analysis that could be carried out when completing this list can be incorporated into said document base, each organization having to interpret the obtained result and address the possible shortcomings that have been detected.

The regulatory compliance check-list is designed as a basic method that allows the controller   obtaining an overview of the degree of compliance to GDPR of a personal data processing, this overview being especially useful for both the risk analysis processes and the impact assessments. The check-list lists the items that should be analyzed to guarantee that the data processings are being carried out in accordance with the new regulations. The document is divided into 29 blocks among which are those related to transparency in the information to be provided to citizens, the exercise of rights, the registration of activities, security measures or international transfers.

The check-list can be found in the DPA website


Article provided by: Belén Arribas, Andersen Tax & Legal

Cloud Privacy Check (CPC). Data Privacy Compliance in the Cloud Made Easy

Understand Cloud and Data Protection Law in only 4 easy steps. Plus highly relevant legal information for 33 countries. Provided by EuroCloud and 53 European lawyers.


About Us

EuroCloud is an independent non-profit organization and consists of a two-tier setup where organisations form all European countries can apply to participate in as long as they respect the EuroCloud Statutes.

To act as a true European player, all programs that are developed are intended to be European activities. These European programs are the strength of EuroCloud as a whole. Respect to local cultures along with the will to promote a real European spirit.