Data Protection Atlas

Spain

Tier 2 Comprehensive law Europe

Principal framework: GDPR + LOPDGDD (2018). Regulator: AEPD. Adds a ‘digital rights’ title — disconnection at work, digital wills, workplace monitoring rules.

At a glance

Criminal offences
None found — checked. LOPDGDD creates no criminal data protection offences; the general Penal Code applies
Public-sector fines
No — declaration of infringement only for public bodies (Art 77 LOPDGDD)
Principal law
GDPR + LOPDGDD
Regulator
Agencia Española de Protección de Datos (AEPD)
Breach notification
72 hours to the supervisory authority (Art 33); undue-delay notice to individuals at high risk
Maximum penalty
Up to €20m or 4% of global annual turnover
DPO required
Public authorities; large-scale regular monitoring or special-category processing (Art 37)
Digital consent age
14
Extraterritorial reach
Yes — targeting or monitoring people in the EU (Art 3(2))
National implementing act
LOPDGDD (2018)

Structure

Structural pattern
Pattern 3 — uniform private law, devolved public sector
Sub-jurisdictions
0 (regulator-and-public-sector-only)
ISO code
ES

Transfers and adequacy

EU member
Yes
EEA member
Yes
Holds EU adequacy
Yes

EU/EEA member — intra-EEA transfers need no adequacy decision.

Instruments

Also applies here

Directly applicable as EU law, without national transposition. The national act supplements it rather than replacing it.

Sources

Never independently verified — seeded from the prototype.