Data Protection

CNMC and AEPD coordinate their digital supervision: what changes for platforms and telecoms in 2026

E
Equipo Editorial CambiosLegales
01 Sep 2026 7 min 0 views

Key data

RegulationResolution of August 26, 2026, from the Under-Secretariat, publishing the Cooperation and Collaboration Agreement between CNMC and AEPD
PublicationSeptember 1, 2026
Entry into forceSeptember 1, 2026
Affected partiesDigital platforms, telecommunications operators and audiovisual media supervised by CNMC and AEPD
CategoryData Protection / Digital Regulation
Regulations coveredDSA (Digital Services Regulation), Telecommunications Law, General Audiovisual Communication Law, e-commerce regulation
Meeting frequencyMinimum 2 times per year
Impact analysis reserved for subscribers
The detailed impact analysis of this regulation is available with the PRO and Business plans. Access the full content and receive personalized alerts.
From €9.99/month · Cancel anytime

Digital platforms, telecommunications operators and audiovisual media operating in Spain have faced since September 2026 a new regulatory scenario: two of their main supervisors, the National Commission of Markets and Competition (CNMC) and the Spanish Data Protection Authority (AEPD), have formalized a framework agreement for cooperation to coordinate their actions in all areas where their competencies overlap.

The agreement, published in the BOE on September 1, 2026 through the Under-Secretariat Resolution of August 26, 2026, enters into force on that same day. It is not a change in sanctions or substantive legal obligations, but it does radically change how supervision over these companies is exercised.

What does this regulation establish?

The agreement defines a stable framework for collaboration between CNMC and AEPD to act coherently in four major regulatory blocks where both have competencies:

Regulatory framework coveredMain regulatorArea of overlap
Digital Services Regulation (DSA)CNMC (DSA coordinator in Spain)Data processing on platforms, targeted advertising, recommendation systems
Telecommunications LawCNMCTraffic data, electronic communications, user privacy
General Audiovisual Communication LawCNMCAudience data, user profiling in audiovisual services
E-commerce regulationShared competenceCookies, consent, terms of use and personal data in transactions

The specific coordination mechanisms established by the agreement are:

  • Exchange of draft documents before their official publication, to avoid contradictory criteria between both regulators.
  • Sharing of information in early stages of procedures, which means that an investigation initiated by AEPD can feed a parallel action by CNMC, and vice versa.
  • Creation of joint working groups to analyze specific cases or sectors.
  • Periodic mandatory meetings, with a minimum frequency of twice per year.

Economic and operational impact

This agreement does not introduce new sanctions or modify the amounts of fines already existing in the GDPR, DSA or Telecommunications Law. Its impact is operational and strategic, and translates into three direct consequences for affected companies:

  • Greater risk of coordinated actions: A complaint or investigation before AEPD for misuse of data can automatically trigger a review by CNMC on market practices on the same platform. The file no longer remains isolated with a single regulator.
  • Reduction of regulatory contradictions: Until now, a company could receive different criteria from CNMC and AEPD on the same matter (for example, the use of data for targeted advertising). With the agreement, both bodies will align their positions before communicating them, which provides greater legal certainty but also less room for maneuver.
  • Increase in compliance costs: Affected companies must maintain a consistent position before two regulators that now share information. This requires greater internal coordination between legal, compliance and privacy teams, and will likely increase the costs of specialized external advice.

Who does it affect?

  • Large digital platforms designated or supervised under the DSA in Spain (marketplaces, social networks, search engines, content platforms).
  • Telecommunications operators subject to the Telecommunications Law and supervised by CNMC.
  • Audiovisual media and streaming services regulated by the General Audiovisual Communication Law.
  • E-commerce companies with significant activity in Spain that process personal data in their operations.
  • Legal advisors and DPOs (Data Protection Officers) of the above companies, who must adapt their compliance strategies to this new framework of joint supervision.

Practical example

Imagine a video-on-demand platform (like a streaming service) operating in Spain. Until now, if AEPD initiated an investigation into the use of viewing data for personalized advertising, CNMC did not necessarily need to be aware until advanced stages of the procedure.

With the new agreement, from the moment AEPD detects signs of infringement in that platform's data processing, it can share that information with CNMC in an early stage. CNMC, for its part, can analyze whether those same data practices also constitute an abuse of dominant position or an anticompetitive practice under the DSA or Telecommunications Law. The result: the platform faces two parallel, coordinated and coherent files with each other, instead of just one. The joint working groups provided for in the agreement can also issue common criteria that affect the entire sector, not just that company.

Do you need to monitor this and other regulations?

Check the full details on CambiosLegales

What should companies do now?

  1. Audit the consistency of your position before CNMC and AEPD: Review whether your company has maintained different criteria before each regulator in matters such as targeted advertising, use of traffic data or recommendation systems. Those inconsistencies are now a real risk.
  2. Coordinate internally the competition and privacy teams: Legal departments managing matters before CNMC and DPOs dealing with AEPD must work in an aligned manner. Create an internal coordination protocol if one does not exist.
  3. Review compliance with the DSA, Telecommunications Law and Audiovisual Communication Law in an integrated manner: The agreement explicitly covers these four regulations. Ensure that your compliance analysis addresses them jointly, not in isolation.
  4. Anticipate that any file before one regulator can reach the other: Adjust your strategy for responding to requests and files assuming that information can be shared with the other body from early stages.
  5. Monitor the joint working groups: The agreement provides for the creation of CNMC-AEPD working groups. Their conclusions and common criteria will set regulatory interpretation in the coming years. Follow their activity through the official channels of both bodies.

Frequently asked questions

What regulations does the agreement between CNMC and AEPD cover?

The agreement covers four regulatory frameworks: the Digital Services Regulation (DSA), the Telecommunications Law, the General Audiovisual Communication Law and e-commerce regulations. These are precisely the areas where the competencies of both regulators overlap most frequently.

Can AEPD share information from a file with CNMC?

Yes. The agreement explicitly establishes the exchange of information in early stages of procedures. This means that an investigation initiated by AEPD can be communicated to CNMC before a resolution is issued, and vice versa. Both bodies will also exchange draft documents before their official publication.

How often will CNMC and AEPD meet under this agreement?

The agreement establishes a minimum frequency of two meetings per year between both bodies. In addition, it provides for the creation of joint working groups to analyze specific cases or sectors, which may meet more frequently as needed.

Does this agreement introduce new sanctions for digital platforms?

No. The agreement does not modify existing sanctioning regimes or introduce new fines. Its impact is operational: it coordinates how both regulators act, which intensifies combined supervision but does not change the maximum amounts of sanctions already provided for in the GDPR, DSA or Telecommunications Law.

When did this agreement between CNMC and AEPD enter into force?

The agreement entered into force on September 1, 2026, the date of its publication in the BOE through the Under-Secretariat Resolution of August 26, 2026 (BOE-A-2026-18409). There is no transition period: coordination between both bodies is effective from that same date.

Official source

Consult complete regulation in official source

Notice: This article is for informational purposes only and does not constitute legal advice. For specific decisions, consult a qualified professional. Source: https://www.boe.es/diario_boe/txt.php?id=BOE-A-2026-18409



Share:
E
Equipo Editorial CambiosLegales

El equipo editorial de CambiosLegales analiza diariamente los cambios normativos que afectan a empresas y autónomos en España, ofreciendo análisis pro...

Comments

No comments yet. Be the first to comment!

Leave a comment
Activate alerts