
Belén Arribas, Abogada
INPLP member firm · Barcelona, Spain
Belén is an independent senior legal counsel and one of the pioneers of IT and Privacy law in Spain. She advises leading companies and clients in industries like telecom, technology and hospitality. Acts as Data Protection Officer for a group of companies. She is the President of IFCLA (International Federation of Computer Law Association) and Vice-President of ENATIC. Passatge Domingo, 11, 2º08007 Barcelona SPAIN Tel: +34 679105788Tel: +34 934879109E-Mail: barribas@icab.cathttps://www.linkedin.com/in/barribas/ Belén advises on digital transformation, platforms economy, Internet & e-commerce matters, data privacy and security, cybersecurity, telecoms, media and technology. Advises on AI and machine learning, Big Data, IoT, Blockchain, smart contracts and ICOs-STOs projects for industries like Proptechs, Fintechs, Insurtechs, Legaltechs. She is an expert in Data protection and Privacy and Data Security law: Assists in setting up corporate privacy offices including corporate privacy strategy. Carries out GDPR implementation projects across multiple jurisdictions, privacy risk governance projects, compliance audits, privacy impact assessments and international data transfers authorization procedures. Track record in enforcement procedures with important success rates. Acts as external DPO for several companies and is a trainer of DPOs. Advises the leading social media in privacy matters regarding their projects in Spain. Experience with other EU legislations and CCPA. Also an IP practitioner, she negotiates, drafts and reviews software contracts, licenses, data transfers, technology transfers, inter alia. Regarding Criminal and Corporate Compliance, she develops Crime Prevention Plans including codes of conduct and ethics frameworks in areas like data protection, anti-corruption, antibribery, economic sanctions, insider trading, anti-trust, etc. Advises the Board of Directors and trains Directors and Compliance officers in this area. Previously she was a partner with Andersen –where she was also the coordinator of the practice of IP-Data Protection and Digital Business at European level- as well as with other international law firms. She has been recognized in directories like Best Lawyers (Technology Law and Data Protection), Who’s Who Legal ( TMT, Data Security and Data Protection, and distinguished as Thought Leader) for ten consecutive years. Chairman, moderator and speaker at many panels and round tables on e-commerce, data protection and privacy in a wide array of forums and conferences like the Mobile World Congress, GSMA or the Digital Future Society think tank. Arbitrator appointed by Asociación Europea de Arbitraje, specializing in technology law. Works in 6 languages. She holds a Master in Law ( Universitat de Barcelona) and a Postgraduate Program in Technology Law (ESADE Business and Law School) as well as a Master in EU and International Law (Katholieke Universiteit Nijmegen, The Netherlands).
Representatives

Belén Arribas
partner
Contact
Publications
- THE SPANISH DPA ISSUES ITS LATEST REPORT: HOW DID THEY REDEFINE PRIVACY AND INNOVATION IN 2025How is data protection evolving in an era shaped by AI and rapid technological innovation? This article explores the main achievements of the Spanish Data Protection Authority (AEPD) during 2025, highlighting its strategic initiatives to integrate AI, strengthen privacy governance, promote regulatory compliance, and foster national and international collaboration. Through technological modernization and proactive regulation, the AEPD aims at redefining the future of privacy protection in an increasingly digital world.28 May 2026
- THE SPANISH DATA PROTECTION AUTHORITY NEW LEADERSHIP PUBLISHES STRATEGIC PLAN 2025-2030 AND SUBMITTS IT TO PUBLIC CONSULTATIONThe Spanish DPA (AEPD) has new leadership and has just published an Strategic Plan which has been submitted to public consultation and has gotten feedback from the leading professional associations.8 July 2025
- PRECAUTIONARY MEASURE ORDERED BY THE SPANISH DPA TO HALT META’S FUNCTIONALITIES “ELECTION DAY INFORMATION” AND “VOTER INFORMATION UNIT” IN SPAINThe Spanish DPA (AEPD) has ordered a precautionary measure against Meta Platforms Ireland Limited to immediately suspend the implementation of the Election Day Information (EDI) and Voter Information Unit (VIU) functionalities in Spain, in light of the upcoming European Parliament elections.4 June 2024
- New Guidelines With Updated Obligations on Cookies in Spain: Companies Have Just a Few Months to Adapt Their WebsitesThe Spanish DPA (AEPD) published earlier this week new guidelines on cookies in order to update the existing ones to the recommendations of the European Data Protection Board (EDPB).21 September 2023
- First European Report on the Use of Cloud Computing in the Public Sector From the Privacy PerspectiveThe Spanish DPA (AEPD) just published the conclusions of this first European report, coordinated by the European Data Protection Board, on the use of cloud in the public sector. This article summarizes its privacy and data protection implications.15 March 2023
- The Metaverse and privacy: guidance by the spanish data protection authorityThe Metaverse uses a variety of technologies such as AR and VR, DLTs (Blockchain), AI, IoT, IoRT, 5G, that enable the creation of immersive virtual environments and generate a multisensory experience for the user within the framework of web 3.0. Brands, firms and companies are entering the Metaverse with impetus. As the Spanish DPA (AEPD) in a recent article put it: “The current social and technical situation has created the ideal context for the Metaverse’s development and expansion, translating human experiences into digital data processing through simulations. However, the processing of this personal data is completely real”. This article analyzes its privacy and data protection implications.17 October 2022
- First European Code of Conduct for the pharma industry approvedA Code of Conduct regulating the processing of personal data in the field of clinical trials and other clinical research and pharmacovigilance has been approved. The code of conduct, promoted by Farmaindustria in Spain, regulates how the promoters of clinical studies with medicines and the CROs that decide to adhere thereto must apply the data protection regulations. Data controllers and data processors that adhere to the code of conduct are obliged to comply with its provisions.6 May 2022
- The Spanish Data Protection Authority (AEPD) publishes its Annual Report summarizing last year’s activities including enforcement casesThis Annual Report comprehensively collects the activities carried out by this institution, most relevant facts and figures, outstanding trends, the most relevant decisions and procedures of the year. It includes further an analysis of present and future challenges in the privacy arena in Spain.30 September 2021
- EDPB’s Guidelines on the concepts of controller and processor in the GDPRThe European Data Protection Board issued the Guidelines 07/2020 on the concepts of controller and processor in the GDPR, version 1.0, adopted on 02 September 2020. We made a selection of a number of paragraphs which offer relevant insight for groups of companies:27 April 2021
Join the network
Applications from qualified privacy practices are reviewed individually by the INPLP board.