Compliance Node Overview
Spain's Organic Law 3/2018 of 5 December on the Protection of Personal Data and Guarantee of Digital Rights (Ley Orgánica 3/2018, de 5 de diciembre, de Protección de Datos Personales y garantía de los derechos digitales - LOPDPGDD), published in the Official State Gazette (BOE) No. 294 on 6 December 2018 and entering into force on 7 December 2018, is Spain's primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Spain. The GDPR is directly applicable Spanish law by virtue of Spain's EU membership; the LOPDPGDD repeals the prior Spanish data protection law (LOPD, Ley Orgánica 15/1999) and provides national derogations and additions. A distinctive feature of the LOPDPGDD compared to other EU GDPR national implementations is its Chapter XI, which establishes a catalogue of digital rights in the workplace and online that go beyond GDPR - including the right to digital disconnect (derecho a la desconexión digital), the right to privacy in the use of digital devices in employment, the right to digital will (derechos digitales en el testamento - posthumous data rights), and the right to digital neutrality (neutralidad en Internet). Enforcement: Agencia Española de Protección de Datos (AEPD) is Spain's independent data protection supervisory authority. The AEPD is Spain's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Key Spanish national provisions: (1) Age of digital consent: Spain has set the age of consent for information society services at 14 years (GDPR Art. 8 permits member states to set between 13 and 16); data subjects under 14 require parental or guardian consent; (2) Digital rights in employment - employers must have a policy on digital device use and inform employees of monitoring scope; the right to digital disconnection requires employers to have an internal policy allowing employees to disconnect from digital communications outside working hours; (3) Right to digital will (testamento digital) - the LOPDPGDD allows the family of a deceased person to instruct data controllers to delete or transfer the deceased's personal data; (4) Whistleblower channels - the LOPDPGDD provides specific provisions on internal whistleblowing channels and their data protection implications; (5) Criminal data - restrictions on processing personal data relating to criminal convictions and offences; (6) Scientific research and statistics: specific provisions permitting extended processing with appropriate safeguards. Fines: GDPR administrative fines apply in Spain - up to EUR 20 million or 4% of global annual turnover for the most serious violations. The AEPD has been one of the most active EU DPAs, with major fines against Google Spain, BBVA, Amazon Spain Services, and Vodafone Spain, as well as enforcement across telecommunications, financial services, and political data processing sectors. The AEPD has also published specific guidance on data processing in political activities, election campaigns, and social media analytics.
Pillar: Cybersecurity · Authority: Agencia Española de Protección de Datos (AEPD, Spain) · Version: 1.0.0 · Last updated:
Primary source: https://www.aepd.es/
SHA-256 integrity: fdb8bea394bbc5f7c6d4b70f3a009722387f32a4c7909b00918ee473d354bd04
Primary Citations — 6 traced to source
- Ley Orgánica 3/2018, de 5 de diciembre, de Protección de Datos Personales y garantía de los derechos digitales (LOPDPGDD, Spain) - published BOE No. 294, 6 December 2018; in force 7 December 2018; repeals LOPD (Ley Orgánica 15/1999); national derogations: age of digital consent 14 years; digital rights catalogue including right to disconnect (desconexión digital), digital privacy in employment, digital will (testamento digital); ENS cybersecurity requirements for public sector
- EU GDPR (Regulation (EU) 2016/679) - directly applicable in Spain; fines up to EUR 20 million or 4% of global annual turnover; AEPD is Spain's supervisory authority and EDPB member; 72-hour breach notification to AEPD (Comunica-Brecha RGPD tool) under Art. 33; DPIA under Art. 35 for high-risk processing; AEPD enforcement against Google Spain, BBVA, Vodafone Spain, and Amazon Spain across telecommunications, financial services, and digital sectors
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access