SOC 2 for Companies Selling Into Spain: Where ENS and AEPD Fit Alongside Your Report
Understand how ENS, AEPD and LOPDGDD requirements complement SOC 2 for SaaS companies selling into Spain, including DPO and AI governance.
Accorp Compliance Team
Our team of compliance experts specializes in PCI DSS, SOC 2, and other security frameworks to help businesses achieve and maintain compliance.
A SaaS vendor with a clean SOC 2 Type 2 report sends it over during a Spanish enterprise deal, expecting the security review to close quickly the way it usually does elsewhere. Instead, two separate threads open up at once: the client's IT security team wants to know about ENS certification, and — a step later, once legal and the client's DPO get involved — a completely different set of questions arrives about LOPDGDD alignment, DPO registration, and how the vendor handles data subject rights requests under Spanish law specifically.
This is the pattern worth understanding clearly before it costs weeks mid-deal: a SOC 2 auditor certification answers one question well, but selling into Spain surfaces two genuinely separate compliance conversations layered on top of it — one about security (ENS), and one about privacy enforcement (AEPD) — and conflating the two, or assuming a strong SOC 2 report covers both, is where deals stall.
Two Different Questions, Two Different Authorities
It's worth being precise about the distinction upfront, because vendors new to the Spanish market often treat "Spanish compliance" as one undifferentiated bucket. ENS, the Esquema Nacional de Seguridad, is Spain's national security framework — a certification regime, primarily relevant when selling to public sector entities or handling public sector data, that evaluates technical and organisational security controls. AEPD, the Agencia Española de Protección de Datos, is something structurally different: Spain's independent data protection supervisory authority, responsible for enforcing GDPR and Spain's own privacy law, the LOPDGDD, across essentially every organisation processing personal data of people in Spain — public sector or not, security-certified or not.
A SOC 2 Type 2 audit demonstrates that a vendor's security controls operated effectively over time. It says very little about either of these — ENS certification status, or genuine compliance with Spain's specific privacy enforcement regime — because both operate on criteria a US-style security audit was never built to test.
ENS, Briefly: The Security-Side Requirement
ENS, established under Royal Decree 311/2022, is mandatory for organisations processing information for Spanish public administrations or delivering digital services to public entities, certified at one of three levels — Básico, Medio, or Alto — depending on the sensitivity and criticality of the systems involved. ISO 27001 accelerates ENS readiness meaningfully but doesn't substitute for it, since ENS layers in Spain-specific technical requirements, national cryptology rules, and CCN-STIC guide adherence that no international framework covers on its own. For vendors targeting Spanish public sector or public-adjacent deals specifically, this remains a hard prerequisite, not a nice-to-have.
But ENS only tells half the story for most SaaS vendors entering Spain, because a large share of Spanish enterprise deals — private companies, not public administration — never touch ENS at all. What they do touch, without exception, is AEPD.
AEPD: Spain's Genuinely Active Privacy Enforcement Authority
The AEPD enforces two overlapping layers of law: the GDPR baseline that applies across the EU, and Spain's own Organic Law 3/2018, the LOPDGDD, which adds national-level obligations on top of GDPR. It's worth knowing that the AEPD is consistently ranked among the most active data protection authorities in Europe, issuing substantial fines across both public and private sectors on a regular basis — this isn't a dormant regulator vendors can reasonably assume will never notice them.
Two aspects of the LOPDGDD specifically go beyond what a typical GDPR compliance program built for other EU markets already covers. First, Article 72 of the LOPDGDD classifies the deliberate reversal of an anonymisation process — intentionally making anonymised data re-identifiable — as a very serious offence in its own right, a notably strict standard that pushes vendors handling anonymised or pseudonymised Spanish data toward genuinely robust, irreversible anonymisation techniques rather than lighter approaches that might pass elsewhere. Second, Title X of the LOPDGDD establishes specific digital workplace rights covering employee monitoring, which matters directly for any SaaS product touching HR tech, workforce analytics, or employee-facing tools sold into Spanish companies.
The DPO Requirement Most Vendors Don't Expect
Under the LOPDGDD, Data Protection Officer appointment is mandatory across sixteen specific sectors, regardless of company size — including insurance, telecommunications, financial institutions, educational institutions, and healthcare providers. This is a meaningfully broader mandatory-DPO requirement than the general GDPR baseline, which ties the requirement more to processing scale and sensitivity than to sector membership outright. Once appointed, the DPO must be registered with the AEPD within ten days — a specific, short administrative deadline that catches vendors off guard when their Spanish client's own DPO asks whether the vendor has completed this registration on their end, assuming it applies.
Extraterritorial Reach: Being Outside Spain Doesn't Mean Being Outside AEPD's Jurisdiction
A common and costly assumption among SaaS vendors without a physical Spanish presence is that AEPD enforcement is somehow a domestic concern that doesn't reach them. It isn't. Any business that targets Spanish consumers or processes personal data of Spanish residents falls within GDPR's scope and is potentially subject to AEPD investigation, regardless of where the company is incorporated or headquartered — a point reinforced clearly by a 2026 AEPD fine against a UK company with no Spanish operations at all. For SaaS vendors evaluating whether Spain-specific privacy compliance is worth the investment before a first Spanish deal closes, this extraterritorial reach is the detail that should settle the question.
Breach Notification: AEPD's Own Process, and a Separate Risk Worth Knowing
The AEPD provides its own free assessment tools specifically to help organisations determine breach notification obligations — ASESORA BRECHA for assessing whether a breach needs to be reported to the AEPD itself, and COMUNICA-BRECHA RGPD for assessing whether affected individuals need to be notified directly. These exist because the two notification triggers are genuinely separate decisions under GDPR, not a single determination, and Spanish organisations are expected to be able to walk through both independently rather than treating notification as one blanket step.
There's a further, less obvious risk worth flagging here: under Article 31 of GDPR, controllers and processors are obligated to cooperate with the AEPD when it requests information, and failing to cooperate adequately — even before the AEPD has confirmed any underlying breach occurred — can itself constitute a very serious infringement, carrying the same fine exposure as a substantive violation: up to €20 million or 4% of global annual turnover. A vendor that mishandles or ignores an AEPD information request is exposed on a completely separate basis from whatever originally triggered the inquiry.
AEPD and AI: A Genuinely Current Development Worth Watching
For SaaS vendors building AI-enabled features into products sold in Spain, there's a recent and specific development worth knowing about. In February 2026, the AEPD published detailed guidance mapping GDPR obligations directly onto agentic AI architectures — addressing characteristics like autonomy, environmental perception, action-taking, and memory, and making clear that greater technical autonomy in an AI system does not reduce an organisation's legal accountability under GDPR. The AEPD has also clarified that it can act against prohibited AI systems under existing GDPR authority even ahead of Spain's own national AI legislation being finalised, making this a live enforcement risk rather than a future consideration for AI-enabled SaaS products entering the Spanish market now.
What This Means Practically for a SOC 2-Compliant Vendor Entering Spain
The practical gap for most vendors isn't a lack of general GDPR compliance — most enterprise SaaS companies selling into the EU already have that. It's the Spain-specific layer sitting on top: confirming whether the DPO mandatory-appointment sectors apply to the target client relationship, making sure anonymisation practices meet the LOPDGDD's stricter Article 72 standard if handling anonymised Spanish data, having Spanish-language privacy notices and DPAs ready rather than translated English originals, and being prepared to answer AI-governance-specific questions if the product involves any agentic or autonomous AI functionality, given AEPD's active enforcement posture in this area specifically.
None of this replaces the value of a strong SOC 2 Type 2 report — it remains a genuinely important credibility signal in any Spanish enterprise deal. It simply isn't the whole conversation, and vendors that walk in prepared for the ENS and AEPD dimensions specifically close deals considerably faster than those discovering these requirements mid-negotiation.
Where Accorp Fits In
Accorp Partners helps SaaS companies map exactly which Spain-specific requirements — ENS certification, LOPDGDD-driven DPO obligations, or AEPD's current AI governance expectations — actually apply to a given deal, so a solid SOC 2 compliance foundation translates into closed business rather than stalling on a Spanish-specific question the sales team wasn't prepared for.
Frequently Asked Questions
1. Does a SOC 2 Type 2 report satisfy AEPD's data protection requirements?
No. A SOC 2 report addresses security control effectiveness, while AEPD enforcement covers GDPR and LOPDGDD-specific privacy obligations — DPO appointment, data subject rights handling, and Spain-specific rules like the anonymization-reversal prohibition — that a security audit doesn't test.
2. Is DPO appointment mandatory for every SaaS vendor selling into Spain?
Not universally, but the LOPDGDD mandates it across sixteen specific sectors regardless of company size, including insurance, financial services, telecoms, education, and healthcare — a broader trigger than the general GDPR standard.
3. Can the AEPD investigate a company with no physical presence in Spain?
Yes. Any organization targeting Spanish consumers or processing Spanish residents' personal data falls within AEPD's jurisdiction regardless of where it's headquartered, as confirmed by a 2026 enforcement action against a UK company with no Spanish operations.
4. Does ENS certification cover AEPD's privacy requirements as well?
No. ENS addresses security controls, primarily for public-sector-facing systems. AEPD's requirements under GDPR and LOPDGDD apply separately and more broadly, regardless of whether ENS certification is in place.





