Data privacy and data protection in Spain

ECIJA

The IT, privacy and data protection practice at ECIJA remains a dominant force in the market, providing a comprehensive service to major multinational financial institutions and corporates on a broad span of issues. Such matters include the implementation of large data transfers and protection systems, regulatory compliance, litigation and sanctioning procedures, software rights and licensing issues. The team’s client portfolio includes household names including McDonald’s, Mercedes, Coca-Cola, Microsoft and Uber, and spans the retail, sport, technology, food and beverage, automotive, banking, IT and tourism sectors. In Madrid, managing partner Alejandro Touriño brings TMT expertise to the group, Daniel López advises on data security, and recently promoted partner Cristina Villasante specialises in digital transformation projects. Teresa Pereyra, an experienced data protection expert, and former associate at the firm, joined the team in September 2021.

Testimonials

They are just brilliant. The know-how they have and the methodology is excellent. They are always available to help.’

‘I think it is the best team in Privacy and Technology, at least in Spain. They always anticipate our needs and are highly responsive to any unforeseen event.’

‘It is a perfectly coordinated team adapted to the day-to-day needs of the company. They stand out for their availability and for their knowledge of the internal functioning of a company, offering realistic and truly applicable solutions within the business.’

‘In-depth and up-to-date knowledge of the subject. They are people with a very marked vocation and it shows. Their contributions to complex problems are essential to provide realistic responses adapted to the needs of the company.’

Key clients

McDonald’s

Santander Bank

Segurcaixa Adeslas

Bupa Group (Sanitas)

AXA

Roche

Odeon & UCI cinemas group

H&M

Vodafone

Telefónica

Huawei

Dentsu Aegis Network

Mercedes

BNP Paribas

Liberty

Ferrovial

LG

Microsoft

LVMH

Hawkers

Orange

Loewe

Mediapro

Red Eléctrica

Enagás

Reale Seguros

Havaianas

Desigual

La Liga

Uber

Porsche

Renault

Schweppes

Coca-Cola

Work highlights

  • Advised Inditex (a global retailer, which operates in 216 markets through its online platform) on information technology, privacy, new cookies requirements for websites and e-commerce, among other matters.
  • Advising Mercadona Supermarkets on the implementation of the first European facial recognition system for the detection of persons with a final sentence and restraining order in its shops.
  • Advised the Bank of Spain on the process of adaptation and compliance with the European and Spanish regulations on data protection, as well as its interrelation with other own economic, labour, tax and security regulations, providing support to the DPO in the issues that arise on a daily basis.

Garrigues

The data protection, privacy, cybersecurity and technology practice at Garrigues continues to lead, leveraging the experience of its team and the strength of its global network to advise multinational corporates and financial institutions on a wide range of issues across the practice area. Areas of strength for the practice include data collection, blockchain analysis, GDPR adaptation, contractual relations, database integrations, and e-commerce and cybersecurity advisory services. Headed by data protection specialist Alejandro Padín in Madrid, the group’s client base includes major names such as Volvo, Philip Morris, Samsung and AIG, across the banking and finance, tobacco, automotive, e-commerce, telecoms, aerospace, insurance and fintech sectors. The team is backed by senior associate Sandra López in Barcelona, and senior associate Katiana Otero and associate Álvaro Blanco in Madrid.

Practice head(s):

Alejandro Padín

Testimonials

‘Technical excellence and vast experience in innovative projects. Working with the Garrigues team is a guarantee that the technical part of the projects will be well covered given its technical solidity.’

‘Special mention to Katiana Otero, for her ability to understand business needs, provide solutions and “business-friendly” alternatives with her extensive knowledge and technical capacity.’

Key clients

JP Morgan

Volvo

AIG

Estée Lauder

Philip Morris

Bip & Drive

Samsung

Fundación 29

Advent

FCC Group

Bankia

Evonik Peroxide Spain, S.L.U.

Akulaku

Deutsche Bank, S.A.

Squareup International Ltd

Work highlights

  • Providing advice to AIG on its insurance programme Cyber-Edge, including 24/7 response in case of cyberattacks or security incidents covered by the policy.
  • Providing continuous advice on Fundación 29’s HealthData 29 project, an open data project using health data to promote research, mainly related to rare diseases.
  • Advising on innovative technology projects such as mobile payments, personalised publicity over smart TVs, blockchain analysis, telecommunications, etc.

Hogan Lovells International LLP

The intellectual property, media and technology group at Hogan Lovells International LLP remains a key player in the market, providing bespoke solutions to advise major multinationals, insurance companies and financial institutions across a broad spectrum of matters. These include data governance plans, data mining, GDPR compliance, international transfers of personal data, IP/IT contractual matters, e-licensing and online marketing. Spearheaded by international data protection expert Gonzalo F. Gállego, the team’s client portfolio contains household names Google and Salesforce, and covers such sectors as energy, insurance, tech, finance, aerospace, fashion, banking and finance, defence, software and entertainment. The practice is supported by a team of associates, including pharmaceutical industry data protection expert Juan Ramón Robles, GDPR implementation specialist Santiago de Ampuero and Clara Regalado Ramirez, an experienced data protection litigator who has acted in proceedings before both the Spanish High Court and Supreme Court.

Practice head(s):

Gonzalo Gállego

Other key lawyers:

Juan Ramón Robles; Santiago de Ampuero; Clara Regalado Ramirez; Clara Lázaro; Graciela Martin

Testimonials

‘This team sets itself apart by its ability to understand client needs and seek solutions that go beyond simply applying the law.’

‘Gonzalo Gallego and his team stand out for their prompt response and high academic content and knowledge of the topics. His friendliness and personal treatment make him and his team of absolute excellence.’

‘Young, dynamic and well-prepared team in the field. They study issues in depth and offer solutions tailored to specific cases.’

‘Gonzalo Gallego, Santiago de Ampuero and Graciela Martin form a very close and dynamic team. They go deep into the matter proposed by the client to offer fully adapted solutions.’

‘The level of knowledge of all the attorneys that serve me is excellent. I would like to draw attention to the great facility that Gonzalo Gállego has in transmitting his needs to the client, as well as the best way to implement the solutions he provides.’

‘Especially good at cross-jurisdictional and complex data and privacy issues.’

‘Excellent lawyers. The partners get involved in the issues and report very closely and on time. They are additional members of our team.’

‘Gonzalo Gallego: technical ability, flexibility, practicality. Gonzalo is always able to adapt to what the client needs, in a way that perfectly matches the in-house lawyers and the client’s style.’

Key clients

Clarity AI

Repsol

Salesforce

Fomento de Construcciones y Contratas (FCC)

Google

Cabify

Applus+

Caixabank

Endesa

Applied Therapeutics

Work highlights

  • Advising Spanish multinational FCC on the implementation and approval of controller and processor Binding Corporate Rules (BCRs) for the international transfer of personal data.
  • Providing ongoing global support to the Applus+ group on data protection matters in Spain and other countries, including on GDPR compliance and other local data protection and e-privacy requirements.
  • Advising Repsol on a wide variety of IP/IT contractual matters.

Baker McKenzie

The IP and technology team at Baker McKenzie continues to advise multinationals and financial institutions on a diverse range of data privacy, data security and information management matters. These include corporate governance, regulatory compliance, personal data protection, online freedom of speech and content moderation and financial institution privacy issues. Headed by media and technology expert José María Méndez and supported by associate Patricia Perez, the group’s client portfolio encompasses the telecoms, IT, education and retail sectors, among others.

Practice head(s):

José María Méndez

Other key lawyers:

Patricia Perez

Ramón y Cajal Abogados

The TMT department at Ramón y Cajal Abogados assists major multinationals and financial institutions involved in a diverse range of data protection and data privacy matters. These include electronic signatures, cloud computing, project outsourcing, IT contracts, GDPR compliance programmes, cookies implementation programmes and mobility start-ups. The team is led by Norman Heckh, a specialist in data protection, and is backed by senior associates María Luisa González and Antonio Borjas. The group’s client base spans the automotive, real estate, energy, transport, TMT and infrastructure sectors, and features household name companies, including WarnerMedia, Ericsson and BMW.

Practice head(s):

Norman Heckh

Key clients

Repsol

Naturgy

WarnerMedia

BMW

Ericsson

Sonae Sierra

The Spanish Agency for Cooperation and Development (AECID)

The Madrid Public Transport Corporation (EMT)

Suez

Iberia Express

General Optica

Vueling

Lamberts

Econocom

Redexis

Gesternova

Siemens Healthcare

Seppelec

Fraternidad-Muprespa

Unibail-Rodamco

Work highlights

  • Advising WarnerMedia on privacy and health and safety matters related to Covid-19 protective measures in the various productions of TV shows and movies around Spain.
  • Advising the Spanish Agency for Cooperation and Development (AECD) on a data protection audit and implementation project for the update and improvement of its GDPR compliance programme.
  • Supporting Repsol in a large and complex cookies implementation project for its entire group.

Uría Menéndez

With offices across the Iberian Peninsula in Madrid, Barcelona, Valencia, Bilbao, Lisbon and Porto, the privacy and digital law group at Uría Menéndez leverages the strength of its network to advise major global corporates and financial institutions on a broad range of data protection and data privacy issues. Areas of strength include cybersecurity strategy, augmented reality and AI, data protection class actions, international transfers of personal data, risk assessments, global business policies and GDPR compliance matters. Headed by data privacy expert Leticia López-Lapuente in Madrid, the group represents household names Facebook, Amazon, Microsoft, Twitter, Instagram and Deliveroo, across the automotive, technology, e-commerce, banking and pharmaceuticals sectors. The team is supported by managing associate Reyes Bermejo Bosch.

Practice head(s):

Leticia López-Lapuente

Other key lawyers:

Reyes Bermejo Bosch; Laia Reyes

Testimonials

‘The Data Privacy & Data Protection team at Uría Menendez is a very reliable team, with very clear criteria and high-quality advice.’

‘Dynamism and availability, which together with great professional solvency, make Uría Menendez’s team a benchmark in the field.’

Key clients

Facebook

Microsoft

Twitter

Instagram

Telefónica

WhatsApp

Glovo

Deliveroo

Amazon

Toyota

Banco Santander

BBVA

Repsol

Unidad Editorial

PRISA

Experian

Johnson & Johnson

CaixaBank

Teka

Morgan Stanley

Campofrío

TherapyChat

National Nederlanden

Igenomix

Work highlights

  • Provided privacy advice on the design and launching of Telefónica’s new e-health business named Movistar Salud, a digital platform that offers on a B2B and B2B2C basis e-health services by digital means.
  • Provided privacy advice to Facebook in connection with significant cases such as the launch of disruptive AI and augmented reality products.
  • Advising on Banco Santander Group’s global strategy on international transfers of personal data for its businesses worldwide and review of main global tech partnerships on this matter.

Andersen

Part of a global network with 280 locations worldwide and with offices in Madrid, Barcelona, Valencia and Seville, the privacy, IT and digital business group at Andersen assists national clients and major multinationals on the full range of data privacy and protection issues. Led by recently promoted partner, national coordinator and data privacy expert Isabel Martínez Moriel, the group’s comprehensive services cover: data protection impact assessments, international data transfers, data breaches and cybersecurity, GDPR compliance and proceedings before data protection authorities. Supported by associate and data compliance specialist María Zarzalejos, the team’s client base covers the food and beverage, insurance, marketing and financial services sectors.

Practice head(s):

Isabel Martínez Moriel

Other key lawyers:

María Zarzalejos

Testimonials

‘Client service and detection of client needs. Absolute knowledge on the subject. They have unique professionalism and qualification.’

‘The collaboration of the Andersen team at all times, personalized attention and quick solutions. They focus on the client’s needs and their daily practice.’

‘Its best qualities are the availability and attention to the client and to detail, specifically Isabel Martinez Moriel.’

Key clients

Encore Capital Group

Insud Pharma Group

Medinsa and Aristo Pharma Iberia

Heineken Spain

Headspring

Europ Assistance

Unicskin

Smart4ads

Inveravante

Cedro

Ambilamp

Work highlights

  • Advised Insud Pharma, an international pharmaceutical corporate group, on data protection and GDPR compliance projects, the development and application of digital solutions, the international adaptation of its processes to GDPR standards and data protection accountability.
  • Advised Heineken on data protection compliance taking into consideration data protection aspects worldwide as well as local aspects, support the data protection officer’s team in Spain, and advises on the launching of P2B and P2C projects.
  • Advised Cabot Financial, a credit management provider in Europe, on GDPR compliance, the launching of new services, data protection impact assessments and the exercise of data subjects’ rights.

Audens

With offices in Madrid and Bilbao, the data protection team at boutique firm Audens devises solutions for multinational corporates, banks and insurance companies on a wide range of data protection and data privacy matters. These include regulatory audits and compliance reviews, GDPR adaptive measures, blockchain, internal privacy governance systems, contract reviews, impact statements and personal data protection matters. The group is led in Madrid by data protection experts and founding partners Marcos Judel and Leandro Núñez, and is supported by senior associates Héctor Oliver Almeida in Madrid and Jon Vicuña Sanabria in Bilbao. The team’s client base includes Avanza and GMV Innovating Solutions, and covers such sectors as telecoms, technology, consumer electronics, finance, software, legal services, marketing and entertainment.

Practice head(s):

Marcos Judel; Leandro Núñez

Testimonials

‘Audens’ technical quality is exceptional.’

‘In my opinion, Leandro Núñez García is probably one of the best lawyers specialised in data privacy in Spain. He is a benchmark and with technical and communication skills that place him among the best lawyers in the sector in our jurisdiction.’

‘Leandro Núñez has solved many problems for me on a day-to-day basis and has faced very complex national and international cases. In addition, the proximity and treatment is excellent.’

‘I have worked mainly with Marcos Judel and Leandro Nuñez and I can highlight from them, in addition to their professional value, their dealings with colleagues and with the client, and their good sense and closeness. It is very difficult to find colleagues who combine the legal and technological aspects and all of the above aspects so well.’

‘I have had the opportunity to work with several firms, well-known firms on many occasions, but what is a differentiating element of Audens is its client orientation, rigour, closeness and above all the dedication and adaptation of the entire team on occasions with very little margin of time to complex situations in which they accompany the client to the end.’

‘Audens is one of the best law firms that I have worked with in data protection due to proximity, knowledge, speed of response and quality.’

Key clients

GMV Innovating Solutions

Vorwerk España

MásMóvil

Avanza

Cobas Asset Management

Bird & Bird

Leveraging the strength of its team and its access to a network of 30 offices across Europe, Africa, the Middle East, Asia Pacific and North America, the privacy and data protection practice at Bird & Bird advises national and multinational corporates on regulatory compliance and safeguarding their businesses against cybersecurity threats. A group of experienced professionals led by recently promoted partner and personal data protection expert Joaquin Muñoz, the team’s full service covers GDPR adaptation, Binding Corporate Rules, compliance audits and personal data processing. Senior associate Ester Vidal brings to the group expertise with GDPR and local data protection legislation, and associate Paula Garralón specialises in data breach management. The team’s client roster includes key names in the software, financial services, life sciences and healthcare and technology sectors.

Practice head(s):

Joaquin Muñoz

Other key lawyers:

Ester Vidal; Paula Garralón

Testimonials

‘Bird & Bird gives us complete advice on this complex matter and complements it with privacy and data transmission issues, which in my company are very sensitive issues. Its agility and adaptability to our needs stands out.’

‘What makes Joaquín Muñoz and Paula Garralón special is their ability to find innovative approaches and never give no for an answer. Their approach is based on the risk appetite of the client, meaning that they always offer a range of alternatives depending on each situation.’

‘High technical knowledge, business-oriented advice and a good international network.’

‘Good technical knowledge and a lot of communication skills.’

Key clients

Colt Telecom

Job & Talent

Hocelot

Amrest

Artistas, Intérpretes y Ejecutantes, Entidad de Gestión

Exevi

Work highlights

  • Carried out the submission and approval procedure of a major telecommunication group’s Binding Corporate Rules (BCRs), before the Spanish Data Protection Authority.

CMS Albiñana y Suárez de Lezo

Drawing on the combined bench strength of 70 offices across 40 countries, the team at the Madrid office of global firm CMS Albiñana y Suárez de Lezo develops data protection, privacy and cybersecurity programmes for multinationals involved in complex cross-border projects. Headed by regulatory telecoms expert Javier Torre de Silva and of counsel and privacy and personal data protection specialist José Luis Piñar, the group counsels key players such as British Telecom and eBay. Aided by associate and e-commerce specialist Miguel Recio, the team’s client portfolio spans such sectors as banking, telecoms, software and insurance.

Other key lawyers:

Miguel Recio

Testimonials

‘The professionals assigned to the company I represent are highly efficient and accessible, as well as of recognised prestige, which makes them highly-qualified “partners” for my company.’

‘It is a team that includes the necessary disciplines at all times and that, in all of them, are among the best specialists in the field.’

Key clients

eBay

Ferrovial (Wondo)

Banco Sabadell

The World Bank

Software One

Area Sur Shopping

British Telecom

Work highlights

  • Providing representation to CaixaBank in court proceedings initiated to challenge the Spanish Data Protection Authority’s decision imposing a fine of €6m and the obligation to adapt its internal procedures and protocols.
  • Provided advice on the partnership between Israeli firm Moovit and Spanish Ferrovial group (Wondo) to launch a mobility service platform, which involved complex data protection issues.
  • Provided advice to the World Bank in relation to the existing legal framework in Bolivia regarding digital identity (including data protection, cybercrime, cybersecurity, social inclusion and digital signatures).

Cuatrecasas

The experienced intellectual and industrial property, media and data protection team at Cuatrecasas provides a comprehensive service to multinational corporates on a wide spectrum of data protection issues across the practice area. Such matters include outsourcing and software licensing, technology transfers, drone usage, the international transfer of personal data, the use of AI for marketing purposes, GDPR compliance and data protection privacy agreements. Headed by new technologies expert Albert Agustinoy in Barcelona, the group’s client portfolio features household names Facebook and Airbnb, and spans the technology, energy, automotive, luxury goods, hospitality, music and retail sectors. The team is backed by counsel Alejandro Negro in Madrid and the Barcelona-based Jorge Monclús, who was promoted to counsel in January 2021.

Practice head(s):

Albert Agustinoy

Other key lawyers:

Alejandro Negro; Jorge Monclús

Key clients

Feat

Airbnb

Facebook Spain

EDP

Total

Hi Partners

Schneider Electric

Pernod Ricard

Adevinta

Orange

Work highlights

  • Providing ongoing advice to Seat Volkswagen Audi on data protection and its adaptation of its policies and procedures to the GDPR, as well as issues connected with an app for facial recognition, the use of drones for moving spare parts, and other matters.
  • Providing Facebook with ongoing legal advice on data protection issues.
  • Advising Adevinta on use of IA tools for marketing purposes from a data protection perspective, and coordinated the advice in different jurisdictions in M&A transactions involving databases.

Gómez-Acebo & Pombo

The privacy and cybersecurity practice at Gómez-Acebo & Pombo utilises the experience of its multidisciplinary team to assist international corporates on a diverse range of data protection and data privacy matters. These include protection of personal data, the holding of databases, data processing contracts, data disclosure agreements, data protection audits, the implementation of whistleblowing systems, cookie policies, sanctioning procedures before the Spanish Data Protection Agency and the management of data breaches. The group is led by associate and data protection officer Isabela Crespo and supported by associate and IP and technology specialist Bárbara Sainz de Vicuña. The team’s client base covers the retail, automotive, entertainment, life sciences, technology, infrastructure, finance and insurance sectors, and features Pandora and Carrefour.

Practice head(s):

Isabela Crespo

Other key lawyers:

Bárbara Sainz De Vicuña

Testimonials

‘It is a very dedicated team and always available.’

I would highlight Isabela Crespo and Bárbara Sainz.’

Key clients

Centros Comerciales Carrefour, S.A.

Correduria de Seguros Carrefour, S.A.

Pandora Jewellery Spain S.L.U.

Work highlights

  • Advising Centros Comerciales Carrefour in relation to data protection and e-commerce issues.
  • Providing Correduria de Seguros Carrefour recurrent advice from a regulatory and data protection perspective.
  • Providing recurrent advice to Pandora Jewellery Spain on several corporate, contractual, digital and data protection matters.