Agentic Artificial Intelligence from the Perspective of Data Protection
Spain's regulator has published one of the fullest maps we have found of how the GDPR applies when the system doing the processing acts on its own. Seventy-one pages, in English, taking agentic AI apart into the properties that make it agentic — autonomy, memory, planning, action-taking, the external tools it calls without being told to — and walking each back to the obligation it engages.
- Published by
- Agencia Española de Protección de Datos (AEPD) — the Spanish supervisory authority
- Type
- Guidance — final. Version 1.1, February 2026 (published 18 February 2026). 71 pages. English edition (also published in Spanish).
- Jurisdiction
- Spain (AEPD) — not binding in the UK; ICO guidance remains the UK reference. The analysis is portable: it is built on GDPR concepts — controller responsibility, purpose limitation, data minimisation, automated decision-making, DPIAs, transfers — that the UK GDPR carries across in substantially the same form.
- Primary audience
- DPOs, controllers and processors designing or deploying AI agents; AI governance leads who have to make the accountability case
- Topic tags
- agentic AI · AI governance · DPIA · automated decision-making (Art. 22) · data minimisation · international transfers · privacy by design
- Availability
- Free, aepd.es (English and Spanish editions)
Why it matters
Agentic AI is being deployed ahead of the governance for it, and the question underneath every deployment is the one this guide answers first: when an agent plans and acts on its own, who is responsible for what it does with personal data? The AEPD's answer is the load-bearing line for anyone building the accountability case — an AI agent is a technical means through which processing is carried out, not an autonomous legal actor, and the processing remains legally attributable to the controller (or processor) that sets its purposes and essential means. Technical autonomy does not move the legal responsibility (Arts. 4(7), 5(2), 24). From there the guide is a methodical walk through the obligations agentic architectures put under pressure: automated decision-making, where whether an agent's action is a solely-automated decision with legal or significant effect turns on the effect and on meaningful human intervention, not on the mere use of autonomous technology (Art. 22); memory, where short-term context, long-term stores and logs each engage purpose limitation and data minimisation (Art. 5(1)(b)–(c)), and where a single agent serving several processing activities risks purpose drift unless its memories are kept logically separate; data-subject rights, which reach into that memory and those logs (Arts. 15–17); and external services, where an agent that selects its own tools and sources extends the processing chain and forces a look at processor terms, onward-transfer terms and technical measures (Arts. 28, 32, 44–49). It names four places agentic systems are structurally exposed — interaction with the environment, the “BYOAgentic” service-integration problem of agents wiring in their own external tools, the layered memory (short-term, long-term and logs), and the auditability cost of autonomy — and it carries a DPIA subsection that reads naturally alongside the AEPD's own risk-management and DPIA methodology, which we surfaced in a previous issue. The commercial point is straightforward, and it runs both ways: reassessing your risk analyses and structuring the DPIA against this map before an agent goes live is far cheaper than retrofitting governance onto a system already in production — and the controls that make an agent defensible are, in the main, the same controls that keep it safe for the people whose data it touches. That the ICO reached for similar themes in its early agentic-AI work, and the Dutch authority issued its own warning on highly autonomous agents in February 2026, is a fair signal that this is where supervisory attention is settling. Read it alongside the ICO's material as the UK reference, not instead of it.
