What Andorra Qualified Law No. 29/2021 on Personal Data Protection - AAPD requires
Andorra's Qualified Law No. 29/2021 on Personal Data Protection (Llei qualificada de protecció de dades personals), adopted by the General Council (Consell General) of Andorra and entered into force in 2021, is Andorra's comprehensive personal data protection legislation establishing a fully GDPR-aligned rights-based framework for the protection of personal data. Andorra is a microstate co-principality between France and Spain that maintains close economic and institutional ties with the European Union; although not an EU member state, Andorra participates in the EU Customs Union and has progressively aligned its legal framework with EU standards. Andorra's Qualified Law No. 29/2021 is comprehensively aligned with the EU General Data Protection Regulation, and Andorra has been recognised by the European Commission as providing adequate data protection for the purposes of international data transfers from the EU. The supervisory authority is the Andorran Data Protection Agency (Agència Andorrana de Protecció de Dades - AAPD), an independent institution responsible for oversight, enforcement, and guidance on personal data protection standards in Andorra. Key features of Andorra's Qualified Law No. 29/2021 on Personal Data Protection: (1) Scope - applies to personal data processing by any person established in Andorra or processing data of individuals located in Andorra; (2) Data processing principles - processing must comply with: lawfulness; purpose limitation; data minimisation; accuracy; storage limitation; security; and accountability; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health status; sexual orientation; criminal convictions; biometric data; and genetic data; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to restriction; right to object; right to data portability; and right not to be subject to solely automated decisions; (6) Data Protection Officer - required for public authorities and organisations processing personal data on a large scale or systematically; (7) Breach notification - controllers must notify the AAPD of personal data breaches within 72 hours; high-risk breaches require data subject notification; (8) Data Protection Impact Assessment - required for high-risk processing; (9) Cross-border transfers - personal data may only be transferred to countries providing adequate protection or using AAPD-approved safeguards; and (10) Administrative fines - graduated fines aligned with GDPR fine structures. Andorra's EU adequacy recognition and GDPR-equivalent framework position it as a European microstate fully integrated into the European data protection ecosystem.
Pillar: Cybersecurity · Authority: Andorran Data Protection Agency - AAPD (Agència Andorrana de Protecció de Dades) · Version: 1.0.0 · Last updated:
Primary source: https://www.apda.ad/
SHA-256 integrity: bd62b38fdeffd4295e254225067b6b5f91dc97c1e6cd633f0b364b881dcd5a1a
Primary Citations — 7 traced to source
- Qualified Law No. 29/2021 on Personal Data Protection (Llei qualificada de protecció de dades personals, Andorra) - GDPR-equivalent processing principles: lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, security, accountability; sensitive personal data: racial/ethnic origin, political opinions, religious beliefs, trade union membership, health, sexual orientation, criminal convictions, biometric, genetic; data subject rights: access, rectification, erasure, restriction, portability, objection, automated decision-making protection; DPO mandatory; 72-hour AAPD breach notification; DPIA required; GDPR-equivalent transfer framework
- Andorran Data Protection Agency - AAPD (Agència Andorrana de Protecció de Dades, Andorra) - independent supervisory authority established under Qualified Law No. 29/2021; mandate covers oversight, enforcement, and guidance on personal data protection standards; registers DPO notifications; receives breach notifications; investigates complaints; conducts inspections; issues binding orders; imposes administrative fines graduated in line with GDPR fine structures; publishes compliance guidance aligned with EU EDPB standards; apda.ad is the official AAPD portal
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/ad-pdp-law-2021.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/ad-pdp-law-2021.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/ad-pdp-law-2021
- Back to registry: Browse all 10,085 compliance nodes