Is ChatGPT GDPR-Compliant for Firms in Spain? The AEPD's Operational Sovereignty Doctrine, Explained
Short answer: Choosing a cloud AI provider's EU data region is not, by itself, enough to satisfy GDPR when a Spanish firm processes client data through it. The Agencia Española de Protección de Datos (AEPD) has published guidance formalizing operational sovereignty — the controller's actual ability to define, supervise, audit, and if necessary modify or cease the processing — as part of the Article 32 security-of-processing obligation. Data residency answers where the bytes sit. Operational sovereignty asks who can reach them, under what legal authority, regardless of where they sit.
> What "operational sovereignty" actually means
Under GDPR Article 32, a data controller must ensure "the continued confidentiality, integrity, availability and resilience of processing systems and services." The AEPD's guidance clarifies that this covers more than picking a server location. It covers whether the controller — the firm, not the vendor — retains real, exercisable control over the processing: can it audit what happens to the data, modify how it's handled, or stop the processing entirely, without depending on a third party's cooperation?
That distinction matters specifically for AI tools whose identity, key-management, or control-plane infrastructure sits with a provider subject to non-EU extraterritorial law (for example, the US CLOUD Act or FISA Section 702, which can compel US-headquartered providers to produce data regardless of where it's physically stored). A Spanish firm can select "EU" as the data region in ChatGPT, Claude, or Copilot's enterprise console and still not have resolved the operational-sovereignty question the AEPD is describing, because the region setting doesn't change who ultimately controls access.
> Why this is a live compliance question, not a theoretical one
The AEPD's guidance sits alongside a separate, related guidance on agentic AI, which addresses what happens when AI systems act autonomously — pulling data from inboxes, accounting software, or document stores rather than responding to a single prompt. That guidance places responsibility for systemic design failures on the controller, and is explicit that a human reviewing an AI agent's output afterward does not, by itself, transfer that responsibility back off the controller.
Together, the two guidances shift the practical question a Spanish firm needs to be able to answer from "did we sign a Data Processing Agreement?" to "can we actually demonstrate who can access this data, under what authority, and how we'd detect or stop unauthorized access?" A signed Article 28 DPA remains necessary — but the AEPD's guidance treats it as one input to the analysis, not the end of it.
> What this means in practice
For a Spanish law firm, gestoría, or asesoría, the practical exposure isn't limited to a hypothetical AEPD fine (though the agency has issued significant sanctions in recent years). It compounds with sector-specific duties that predate this guidance: professional secrecy obligations for abogados under Article 542.3 LOPJ, anti-money-laundering duties for gestorías classified as sujetos obligados under Ley 10/2010, and the EU AI Act's Article 50 transparency duties, which took effect on schedule on August 2, 2026 even after the Digital Omnibus deferred the Act's high-risk system obligations to December 2027 and August 2028 (see our article on what actually applies from August 2026). None of those are satisfied by a data-residency checkbox either.
The architectural response the AEPD's own framing points to is straightforward, even if implementing it isn't: processing that happens on infrastructure the firm itself controls — where the firm, not a vendor, holds the keys and can point to the physical hardware — closes the operational-sovereignty question by removing the third party from the access path entirely, rather than trying to contract around it.
> Sources
- AEPD — Operational Sovereignty in the Processing of Personal Data (English)
- AEPD — Soberanía operativa en tratamientos de datos personales (Spanish)
- GDPR — Regulation (EU) 2016/679, Article 32
- EU AI Act — Regulation (EU) 2024/1689
AI IBIZA builds local-first AI systems for Spanish law firms and gestorías where the firm holds the keys and the hardware. See Private AI for Despachos or Private AI for Gestorías.