Certix

Spanish Data Protection Law: the LOPDGDD explained

Certix
Certix®
· 27 May 2026 · 14 min read

Informative article. It does not replace individualised professional advice.

Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights — known as the LOPDGDD — is the Spanish legislation that adapts the European General Data Protection Regulation to the Spanish legal order while simultaneously establishing its own catalogue of digital rights.

This guide breaks down the 97 articles of the law into practical sections. No unnecessary jargon. With tables. So that in 15 minutes you have a complete picture of what it requires.

Why does the LOPDGDD exist and how does it relate to the GDPR?

The General Data Protection Regulation (GDPR) is the EU regulation that has applied across the entire European Union since May 2018. However, the GDPR is not a ceiling: it permits and sometimes requires each Member State to develop specific aspects. Spain did so through the LOPDGDD.

Both pieces of legislation form a single system: the GDPR provides the common European framework and the LOPDGDD adds national specifics. Where both instruments regulate the same matter, the GDPR prevails. Where the LOPDGDD covers ground that the GDPR leaves to Member States — national legal bases for processing, penalties, sectors required to have a DPO, digital labour rights — the LOPDGDD is the reference instrument.

Aspect GDPR LOPDGDD
Legal rank EU Regulation (directly applicable) Spanish Organic Law
Scope All European Union Spain (adapts and supplements the GDPR)
Entry into force 25 May 2018 7 December 2018
Previous legislation Directive 95/46/EC LOPD 1999 (Organic Law 15/1999)
Supervisory authority Each Member State designates its own AEPD (Spanish Data Protection Agency)
Maximum penalties Up to €20 M or 4% of global turnover Adopts the GDPR tiers; public bodies: reprimand

Structure of the LOPDGDD: the 10 Titles at a glance

Title Articles What it regulates
Preliminary Title Arts. 1–5 Purpose, scope, data of deceased persons, accuracy and confidentiality
Title I Arts. 6–10 Legal bases for processing: consent, minors, legal obligation, special categories and criminal data
Title II Arts. 11–18 Transparency and information, and the ARSULIPO rights of data subjects
Title III Arts. 19–33 Processing in specific contexts: video surveillance, contact-tracing activities, credit information systems, archiving purposes, HR processing, etc.
Title IV Arts. 34–44 Data controller and data processor: obligations, contracts, mandatory DPO
Title V Arts. 45–48 International transfers of personal data
Title VI Arts. 49–67 Supervisory authorities: AEPD, regional authorities, cooperation
Title VII Arts. 68–76 Procedures for possible infringements: complaints, mediation, enforcement of rights
Title VIII Arts. 77–89 Sanctions regime: very serious, serious and minor infringements; penalties and criteria
Title IX Arts. 79–97 Digital rights: right to disconnect, workplace video surveillance, right to be forgotten in search engines, social networks, digital will, internet neutrality

Who does the LOPDGDD apply to?

The LOPDGDD applies to any natural or legal person, public or private, that processes personal data in the context of the activities of an establishment in Spain, or — even where the controller is outside the EU — processes data relating to residents in Spain.

In practical terms: if your organisation has employees, clients, suppliers or contacts whose personal data you process (name, email, phone number, IP address, image, health data…), the LOPDGDD applies to you.

Excluded are processing activities carried out by natural persons in a purely personal or domestic sphere, as well as certain uses within the framework of national security.

Legal bases for processing (Title I, Arts. 6–10)

To process personal data, there must always be a legal basis that authorises it. Neither the GDPR nor the LOPDGDD permit processing data "just because". The bases recognised by the LOPDGDD — consistently with Art. 6 GDPR — are:

Legal basis When it applies Practical example
Consent Freely given, specific, informed and unambiguous. Cannot be a condition for providing a service where it is not necessary Newsletter, non-essential cookies, commercial communications
Performance of a contract Processing is necessary to perform a contract with the data subject Client data for invoicing, employee data for payroll
Legal obligation A statutory provision requires the processing Reporting tax withholdings, reporting workplace accidents
Vital interests Protecting the vital interests of the data subject or another person Medical emergency when the patient cannot give consent
Public interest Performance of a task carried out in the public interest or in the exercise of official authority Public authorities in the exercise of their functions
Legitimate interests The legitimate interest of the controller overrides the rights of the data subject. Requires a balancing test. Does not apply to public bodies Anti-fraud systems, network security, B2B direct marketing with balancing test

Consent of minors: the 14-year rule (Art. 7)

In Spain, children under 14 years of age cannot give consent to the processing of their data. This falls to those holding parental responsibility or guardianship. From age 14, the minor may consent personally, provided the language used is clear and adapted to their age.

Special category data (Art. 9)

Data concerning health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data processed for identification purposes, sex life or sexual orientation are subject to enhanced protection. They may only be processed where one of the enumerated exceptions in Art. 9.2 GDPR and Art. 9 LOPDGDD applies — including explicit consent, necessity on grounds of health, or the existence of an enabling statutory provision.

The practical rule: never process this category of data without prior legal analysis.

Rights of data subjects (Title II): the ARSULIPO acronym

The LOPDGDD (Arts. 11–18) develops the rights that any person may exercise against the data controller. The acronym ARSULIPO summarises them:

Right What it consists of Response deadline
A · Access Know whether your data is being processed, which data, for what purpose and who receives it 1 month (extendable to 2 months)
R · Rectification Correct inaccurate data or complete incomplete data 1 month (extendable to 2 months)
S · Erasure (right to be forgotten) Request that data be deleted when it is no longer necessary, consent has been withdrawn or it has been processed unlawfully 1 month (extendable to 2 months)
U · Restriction of processing Temporarily suspend processing while a dispute or challenge is being resolved 1 month (extendable to 2 months)
L · Portability Receive data in a structured, machine-readable format, or have it transmitted to another controller 1 month (extendable to 2 months)
I · Object Object to processing on grounds relating to the data subject's particular situation, or to processing for direct marketing purposes 1 month (extendable to 2 months)
P · Not to be subject to automated decisions Not to be subject to decisions based solely on automated processing that produce significant legal effects 1 month (extendable to 2 months)
O · Redress before the AEPD Lodge a complaint with the Spanish Data Protection Agency (AEPD) if the controller fails to honour the other rights within the deadline

The data controller must respond to these requests free of charge. Where requests are manifestly unfounded or excessive, the controller may charge a reasonable fee or refuse to act, but must justify this decision.

General obligations of the data controller

The LOPDGDD and the GDPR establish a set of obligations that every entity processing personal data must fulfil. These are not recommendations: they are legal requirements whose non-compliance can result in penalties.

Obligation What it consists of Tool / document
Record of Processing Activities (RoPA) Internal inventory of all processing activities, including purpose, legal basis, retention periods, recipients and security measures RoPA (Art. 30 GDPR)
Information to data subjects Inform in a clear and accessible manner about who processes the data, for what purpose, for how long and what rights they have Information clauses / privacy policy
Contracts with data processors Formalise in writing the relationship with suppliers who access personal data on behalf of the controller (accountants, IT, hosting, etc.) Data processing agreement (Art. 28 GDPR)
Security measures Implement technical and organisational measures appropriate to the risk: access controls, encryption, backups, password policies Policy / risk analysis
Personal data breach notification If a breach affecting personal data occurs, notify the AEPD within a maximum of 72 hours of becoming aware of it. If the risk is high, also notify the data subjects Breach management protocol
Data Protection Impact Assessment (DPIA) Mandatory when processing is likely to result in a high risk to the rights and freedoms of individuals: large-scale video surveillance, profiling with sensitive data, automated decisions with legal effects DPIA (Art. 35 GDPR)
Privacy by design and by default Incorporate data protection from the outset of any project or system, not as an afterthought Prior analysis in new projects
Accountability Actively demonstrate compliance: it is not enough to comply — you must be able to prove it Documentation, records, evidence

The Data Protection Officer: who is required to have one

The Data Protection Officer (DPO, also referred to as DPD from the Spanish Delegado de Protección de Datos) is the figure responsible for supervising compliance with data protection regulations within the organisation. The DPO may be internal or external, but their appointment is mandatory in the cases set out in Art. 37 GDPR and, more specifically for Spain, Art. 34 LOPDGDD.

The information below is indicative. The final requirement will depend on the scale, volume and exact nature of the processing activities of each entity. Each case requires individual analysis.

Type of entity / activity DPO mandatory Legal basis
Public administrations, bodies and entities in the public sector Yes Art. 37.1.a GDPR / Art. 34 LOPDGDD
Professional associations and their governing councils Yes Art. 34.1.a LOPDGDD
Educational centres (regulated education) and universities Yes Art. 34.1.b LOPDGDD
Entities providing electronic communications services Yes Art. 34.1.c LOPDGDD
Credit institutions (banks, savings banks, credit cooperatives) Yes Art. 34.1.e LOPDGDD
Insurance and reinsurance companies Yes Art. 34.1.g LOPDGDD
Healthcare establishments with access to clinical records, except sole-practitioner healthcare professionals Yes Art. 34.1.h LOPDGDD
Large-scale processing of special category data or criminal data Yes Art. 37.1.c GDPR / Art. 34 LOPDGDD
Regular and systematic large-scale monitoring of data subjects Yes Art. 37.1.b GDPR
Standard SME without high-risk activities Depends on analysis Art. 37 GDPR (risk assessment)

The DPO must be registered with the AEPD. Their position is independent: they cannot be instructed in the performance of their duties and cannot be dismissed on that basis. They act as the point of contact between the organisation, the AEPD and data subjects.

"The DPO is not the one who signs paperwork. They are the one who knows the organisation's actual processing activities, identifies risks before they materialise and knows exactly what the AEPD would say if they called tomorrow. That cannot be improvised."

Mario P. Talamillo · Managing Partner, Certix®

Specific processing activities regulated in Title III

The LOPDGDD dedicates an entire title to specific situations that warrant particular regulation in Spain:

  • Video surveillance (Art. 22): Images captured by security cameras may only be retained for a maximum of 30 days, unless they must be preserved to evidence the commission of acts. There is an obligation to inform via a visible sign.
  • Defaulter registers / credit information systems (Art. 20): A person may only be included in a creditworthiness register if the debt is certain, due and enforceable, the creditor has previously informed the debtor and one month has elapsed since that notification.
  • Advertising exclusion systems (Art. 23): The law expressly recognises the possibility of processing data to manage advertising exclusion lists (similar to the Robinson List).
  • Processing for research purposes (Art. 31): The law opens the possibility of reusing data for scientific research, statistical or archiving purposes in the public interest, with appropriate safeguards.
  • Rights of deceased persons (Art. 3): Heirs and persons linked to the deceased may exercise the rights of access, rectification and erasure of the deceased's data, unless the deceased had expressly prohibited this.

The sanctions regime (Title VIII)

The LOPDGDD classifies infringements into three tiers, further distinguishing between private entities and public sector bodies.

For private sector entities

Tier Limitation period Maximum penalty (GDPR) Examples of infringement
Very serious 3 years €20,000,000 or 4% of annual global turnover Violating basic privacy principles, failing to honour data subject rights, unlawful international transfers, processing sensitive data without a legal basis
Serious 2 years €10,000,000 or 2% of annual global turnover Not maintaining a RoPA, failing to notify breaches within the deadline, not applying adequate security measures, not appointing a DPO when mandatory
Minor 1 year Warning or up to €40,000 Formal non-compliance: incomplete privacy policy, failing to respond to a straightforward rights request within the deadline

For public sector bodies

Where the infringer is a Public Administration, public law entity or political party, the LOPDGDD (Art. 77) replaces the financial fine with a reprimand. The AEPD communicates the resolution to the competent body so that the person responsible is required to account for the matter. This does not preclude the possibility of disciplinary liability for the responsible employees or officeholders.

Criteria for determining the penalty

Fines are neither automatic nor linear. The AEPD takes into account aggravating and mitigating factors: the duration of the infringement, the number of individuals affected, the measures taken to mitigate the damage, the degree of cooperation, whether there is a history of prior infringement, the benefit obtained and the nature of the data processed.

Digital rights under Title IX

The LOPDGDD was the first European data protection law to include a specific catalogue of digital rights, both civil and labour-related. This Title IX (Arts. 79–97) is one of the major innovations of the legislation compared to the former LOPD.

Digital right What it protects
Right to be forgotten in search engines (Art. 93) Request that search engines stop linking to outdated, inaccurate or rights-infringing personal information
Right to be forgotten on social networks (Art. 94) Request erasure of personal data published on social networks, especially data shared during minority
Portability on social networks (Art. 95) Request data from the platform in a portable format in order to migrate to another service
Privacy and devices in the workplace (Art. 87) Employees have the right to protection of their privacy when using corporate digital devices. The employer may access them only where it has previously informed employees of the usage criteria
Right to digital disconnection (Art. 88) Employees have the right not to respond to work communications outside their working hours. Companies must draw up an internal disconnection policy
Workplace video surveillance (Art. 89) The employer may install cameras in the workplace, but must inform employees in advance and expressly. Cameras in changing rooms or bathrooms are prohibited
Geolocation in the workplace (Art. 90) The employer may use geolocation systems to monitor vehicles or working hours compliance, but must inform employees in advance
Digital will (Art. 96) Any person may designate someone to manage their digital profiles and content after death, including instructions for their deletion
Digital education (Art. 83) Educational centres must promote safe internet and social network use among minors, with specific protocols
Correction in digital media (Art. 85) Individuals have the right for digital media outlets to facilitate the exercise of the right to correct inaccurate information

What changed compared to the former LOPD of 1999

The LOPDGDD is not a minor revision. It represents a complete paradigm shift compared to Organic Law 15/1999:

Aspect LOPD 1999 LOPDGDD 2018
Registration with the AEPD Mandatory for all data files Abolished. Replaced by the internal RoPA
Compliance approach Formalistic: completing administrative procedures Proactive (accountability): demonstrating real compliance
Consent Could be tacit or by omission Always active, freely given, specific and unambiguous
Data Protection Officer Did not exist as a figure Mandatory for numerous sectors
Maximum penalties Up to €600,000 Up to €20,000,000 or 4% of global turnover
Digital labour rights Not contemplated New Title IX with 19 rights
Breach notification Not mandatory Mandatory within 72 hours to the AEPD
Privacy by design Not contemplated Mandatory principle (Art. 25 GDPR)

Checklist: does your organisation comply with the LOPDGDD?

This checklist is a starting point for an internal review. It does not replace an individual professional analysis.

  • Up-to-date Record of Processing Activities (RoPA) covering all processing activities carried out by the organisation
  • Information clauses or privacy policy in all forms, contracts and data collection points
  • Legal basis identified for each processing activity (consent, contract, legal obligation…)
  • Explicit and granular consent for commercial processing or where required, with a record of when and how it was obtained
  • Data processing agreements signed with all suppliers who access data (accountants, IT, cloud, marketing…)
  • Protocol for responding to rights requests with defined deadlines and responsible parties
  • Personal data breach management protocol with the procedure for notifying the AEPD within 72 hours
  • Documented technical and organisational security measures appropriate to the risk
  • Cookie policy and consent banner in line with AEPD guidelines
  • Video surveillance, geolocation and device clauses if the organisation uses these means
  • Digital disconnection policy if the organisation has employees
  • DPO appointed and registered with the AEPD if the organisation belongs to any of the mandatory sectors

Frequently asked questions about the LOPDGDD

Does the LOPDGDD apply to me even if I only have two employees?

Yes. The obligation is not conditional on the size of the company, but on whether you process personal data. With two employees you are already processing data (payroll, client data, suppliers, etc.). That said, obligations are proportionate to risk: a micro-business without special category data does not face the same requirements as a hospital.

Is the LOPDGDD the same as the GDPR?

No. They are complementary instruments. The GDPR is the directly applicable European regulation. The LOPDGDD is the Spanish law that adapts and develops it for Spain, adds national specifics and establishes digital rights. To comply, you must respect both.

What happens if I do not have a privacy policy on my website?

It is a defined infringement. The AEPD may issue a reprimand, impose a fine or both. Penalties for deficiencies in user information are typically classified as minor or serious, depending on the scope and the type of data affected.

Can the DPO be the company's own managing director or partner?

Only if there is no conflict of interests. The managing director cannot act as DPO if their managerial role leads them to make decisions about data processing activities, because they would then be supervising their own decisions. This is one of the reasons why an external DPO is common in medium and large organisations.

How long is there to respond to a rights request?

One month from receipt of the request. This may be extended by a further two months where the request is complex or the volume of requests is high, provided the data subject is informed within the first month and the reasons are explained.

What is a personal data breach and when must it be notified?

A personal data breach is any incident that leads to the destruction, loss, alteration or unauthorised access to personal data: a ransomware attack encrypting a server containing client data, the loss of a laptop with employee information, a mass email sent to the wrong recipients. If the breach has consequences for the rights and freedoms of individuals, it must be notified to the AEPD within 72 hours of becoming aware of it.


Legal notice: This content is for informational and educational purposes only; it does not constitute legal advice in any case. The application of regulations to each specific case requires individual analysis.

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →