Spain
Tier 2 Comprehensive law EuropePrincipal framework: GDPR + LOPDGDD (2018). Regulator: AEPD. Adds a ‘digital rights’ title — disconnection at work, digital wills, workplace monitoring rules.
At a glance
- Criminal offences
- None found — checked. LOPDGDD creates no criminal data protection offences; the general Penal Code applies
- Public-sector fines
- No — declaration of infringement only for public bodies (Art 77 LOPDGDD)
- Principal law
- GDPR + LOPDGDD
- Regulator
- Agencia Española de Protección de Datos (AEPD)
- Breach notification
- 72 hours to the supervisory authority (Art 33); undue-delay notice to individuals at high risk
- Maximum penalty
- Up to €20m or 4% of global annual turnover
- DPO required
- Public authorities; large-scale regular monitoring or special-category processing (Art 37)
- Digital consent age
- 14
- Extraterritorial reach
- Yes — targeting or monitoring people in the EU (Art 3(2))
- National implementing act
- LOPDGDD (2018)
Structure
- Structural pattern
- Pattern 3 — uniform private law, devolved public sector
- Sub-jurisdictions
- 0 (regulator-and-public-sector-only)
- ISO code
- ES
Transfers and adequacy
- EU member
- Yes
- EEA member
- Yes
- Holds EU adequacy
- Yes
EU/EEA member — intra-EEA transfers need no adequacy decision.
Instruments
Also applies here
Directly applicable as EU law, without national transposition. The national act supplements it rather than replacing it.
Sources
- Regulator Agencia Española de Protección de Datos (AEPD)
- Primary GDPR — EUR-Lex
- Primary LOPDGDD — BOE
- Regulator AEPD — regulator
Never independently verified — seeded from the prototype.