The Spanish National Court suspended a generic corrective order

The full text of the order in the Judykatura database shows why a corrective measure cannot be confined to a general instruction to bring processing into compliance with the GDPR. The Spanish National Court held that a supervisory authority must identify the specific manner in which its order is to be complied with, rather than merely its legal objective.

This article is available free of charge in full. Subscribe to our newsletter to receive new case notes and a discount code for your first subscription.

Loading

⚖️ Key theses (click to expand)

Teza 1 — Specificity of corrective measures

The corrective power under Article 58(2)(d) GDPR permits a supervisory authority to order a controller to bring processing operations into compliance with the GDPR, but the order must specify both the particular manner of compliance and the deadline. These are cumulative requirements.

Teza 2 — Legal uncertainty from general orders

A corrective order framed in general terms may require structural measures directly affecting the ordinary operation of an undertaking. A lack of precision may create legal uncertainty and even impair the rights of defence where the addressee does not know how, specifically, it is required to rectify its conduct.

Teza 3 — Suspension pending specification

The court suspended the enforcement of the corrective order until the Spanish Data Protection Agency specifies and details the measures which the controller must adopt under Article 58(2) GDPR.

The ruling concerns the limits of the power to order a controller to bring processing operations into compliance.

In its order of 13 July 2026, the Audiencia Nacional, Spain’s National Court, granted interim relief and suspended enforcement of part of a decision of the Spanish Data Protection Agency. The suspension concerned only the order to adopt corrective measures; it did not concern two administrative fines of EUR 20,000 and EUR 200,000, which the company had paid.

What was the case about?

The Agency found infringements of Articles 13 and 6(1) GDPR. In addition to the fines, it ordered the controller, within six months of the decision becoming final and enforceable, to bring the processing into line with the applicable rules.

In the reasoning of its decision, the authority stated that the controller had to ensure that its processing operations had a legal basis and that data subjects received the information required by Article 13 GDPR. At the same time, it left the selection of the specific implementation procedures, mechanisms and instruments to the controller.

Is a reference to GDPR provisions sufficient?

The court referred to the wording of Article 58(2)(d) GDPR. The provision allows a supervisory authority to order a controller or processor to bring processing operations into compliance with the GDPR, where appropriate, “in a specified manner and within a specified period” (editorial translation).

According to the court, both elements are necessary. The authority had specified a deadline for compliance, but had not identified specifically how the controller was to implement the corrective measures. A general reference to Articles 6(1) and 13 GDPR could not replace that specification.

The court accepted the controller’s argument that the order, framed in this manner, was general and could require structural measures affecting the undertaking’s ordinary operations. It did not, however, determine which precise measures should be adopted or finally decide whether the infringements identified in the authority’s decision had occurred.

Why does precision matter?

The Audiencia Nacional held that an imprecise order may create legal uncertainty and may even impair the rights of defence. A controller should not be required to reconstruct the substantive content of an administrative obligation on its own, under the risk of a further enforcement proceeding.

The court also recalled its earlier position that a supervisory authority’s corrective power requires an appropriate degree of specificity. In the passage cited by the court, it was stated that “a general indication of all GDPR and Spanish data-protection provisions considered applicable is not sufficient” (editorial translation).

What has been decided and what remains open?

The order is an interim measure. The court suspended enforcement of the corrective order only until the supervisory authority specifies it. In these proceedings, it neither set aside the administrative fines nor finally ruled on the lawfulness of the Spanish Data Protection Agency’s entire decision.

The practical significance of the ruling is nevertheless clear: a corrective measure cannot shift onto a controller the task of determining what the authority actually requires. The controller remains responsible for selecting appropriate implementation tools, but the authority must first define clearly the specific obligation to be performed.


This material was prepared partly with the use of a general-purpose AI model and, despite due care, may contain errors. The information provided does not constitute legal advice — it reflects solely the Author's view.

The rest of this analysis, all theses and the full text of the ruling are available with an AKTUALNOŚCI PLUS subscription.

Find out how EU supervisory authorities, administrative and civil courts and the CJEU reason their decisions — and keep your organisation aligned with current case law.

Join — see pricing   Have an account? Log in

Wersja polska / Polish version