Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights — known as the LOPDGDD — is the Spanish legislation that adapts the European General Data Protection Regulation to the Spanish legal order while simultaneously establishing its own catalogue of digital rights.
This guide breaks down the 97 articles of the law into practical sections. No unnecessary jargon. With tables. So that in 15 minutes you have a complete picture of what it requires.
Why does the LOPDGDD exist and how does it relate to the GDPR?
The General Data Protection Regulation (GDPR) is the EU regulation that has applied across the entire European Union since May 2018. However, the GDPR is not a ceiling: it permits and sometimes requires each Member State to develop specific aspects. Spain did so through the LOPDGDD.
Both pieces of legislation form a single system: the GDPR provides the common European framework and the LOPDGDD adds national specifics. Where both instruments regulate the same matter, the GDPR prevails. Where the LOPDGDD covers ground that the GDPR leaves to Member States — national legal bases for processing, penalties, sectors required to have a DPO, digital labour rights — the LOPDGDD is the reference instrument.
| Aspect | GDPR | LOPDGDD |
|---|---|---|
| Legal rank | EU Regulation (directly applicable) | Spanish Organic Law |
| Scope | All European Union | Spain (adapts and supplements the GDPR) |
| Entry into force | 25 May 2018 | 7 December 2018 |
| Previous legislation | Directive 95/46/EC | LOPD 1999 (Organic Law 15/1999) |
| Supervisory authority | Each Member State designates its own | AEPD (Spanish Data Protection Agency) |
| Maximum penalties | Up to €20 M or 4% of global turnover | Adopts the GDPR tiers; public bodies: reprimand |
Structure of the LOPDGDD: the 10 Titles at a glance
| Title | Articles | What it regulates |
|---|---|---|
| Preliminary Title | Arts. 1–5 | Purpose, scope, data of deceased persons, accuracy and confidentiality |
| Title I | Arts. 6–10 | Legal bases for processing: consent, minors, legal obligation, special categories and criminal data |
| Title II | Arts. 11–18 | Transparency and information, and the ARSULIPO rights of data subjects |
| Title III | Arts. 19–33 | Processing in specific contexts: video surveillance, contact-tracing activities, credit information systems, archiving purposes, HR processing, etc. |
| Title IV | Arts. 34–44 | Data controller and data processor: obligations, contracts, mandatory DPO |
| Title V | Arts. 45–48 | International transfers of personal data |
| Title VI | Arts. 49–67 | Supervisory authorities: AEPD, regional authorities, cooperation |
| Title VII | Arts. 68–76 | Procedures for possible infringements: complaints, mediation, enforcement of rights |
| Title VIII | Arts. 77–89 | Sanctions regime: very serious, serious and minor infringements; penalties and criteria |
| Title IX | Arts. 79–97 | Digital rights: right to disconnect, workplace video surveillance, right to be forgotten in search engines, social networks, digital will, internet neutrality |
Who does the LOPDGDD apply to?
The LOPDGDD applies to any natural or legal person, public or private, that processes personal data in the context of the activities of an establishment in Spain, or — even where the controller is outside the EU — processes data relating to residents in Spain.
In practical terms: if your organisation has employees, clients, suppliers or contacts whose personal data you process (name, email, phone number, IP address, image, health data…), the LOPDGDD applies to you.
Excluded are processing activities carried out by natural persons in a purely personal or domestic sphere, as well as certain uses within the framework of national security.
Legal bases for processing (Title I, Arts. 6–10)
To process personal data, there must always be a legal basis that authorises it. Neither the GDPR nor the LOPDGDD permit processing data "just because". The bases recognised by the LOPDGDD — consistently with Art. 6 GDPR — are:
| Legal basis | When it applies | Practical example |
|---|---|---|
| Consent | Freely given, specific, informed and unambiguous. Cannot be a condition for providing a service where it is not necessary | Newsletter, non-essential cookies, commercial communications |
| Performance of a contract | Processing is necessary to perform a contract with the data subject | Client data for invoicing, employee data for payroll |
| Legal obligation | A statutory provision requires the processing | Reporting tax withholdings, reporting workplace accidents |
| Vital interests | Protecting the vital interests of the data subject or another person | Medical emergency when the patient cannot give consent |
| Public interest | Performance of a task carried out in the public interest or in the exercise of official authority | Public authorities in the exercise of their functions |
| Legitimate interests | The legitimate interest of the controller overrides the rights of the data subject. Requires a balancing test. Does not apply to public bodies | Anti-fraud systems, network security, B2B direct marketing with balancing test |
Consent of minors: the 14-year rule (Art. 7)
In Spain, children under 14 years of age cannot give consent to the processing of their data. This falls to those holding parental responsibility or guardianship. From age 14, the minor may consent personally, provided the language used is clear and adapted to their age.
Special category data (Art. 9)
Data concerning health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data processed for identification purposes, sex life or sexual orientation are subject to enhanced protection. They may only be processed where one of the enumerated exceptions in Art. 9.2 GDPR and Art. 9 LOPDGDD applies — including explicit consent, necessity on grounds of health, or the existence of an enabling statutory provision.
The practical rule: never process this category of data without prior legal analysis.
Rights of data subjects (Title II): the ARSULIPO acronym
The LOPDGDD (Arts. 11–18) develops the rights that any person may exercise against the data controller. The acronym ARSULIPO summarises them:
| Right | What it consists of | Response deadline |
|---|---|---|
| A · Access | Know whether your data is being processed, which data, for what purpose and who receives it | 1 month (extendable to 2 months) |
| R · Rectification | Correct inaccurate data or complete incomplete data | 1 month (extendable to 2 months) |
| S · Erasure (right to be forgotten) | Request that data be deleted when it is no longer necessary, consent has been withdrawn or it has been processed unlawfully | 1 month (extendable to 2 months) |
| U · Restriction of processing | Temporarily suspend processing while a dispute or challenge is being resolved | 1 month (extendable to 2 months) |
| L · Portability | Receive data in a structured, machine-readable format, or have it transmitted to another controller | 1 month (extendable to 2 months) |
| I · Object | Object to processing on grounds relating to the data subject's particular situation, or to processing for direct marketing purposes | 1 month (extendable to 2 months) |
| P · Not to be subject to automated decisions | Not to be subject to decisions based solely on automated processing that produce significant legal effects | 1 month (extendable to 2 months) |
| O · Redress before the AEPD | Lodge a complaint with the Spanish Data Protection Agency (AEPD) if the controller fails to honour the other rights within the deadline | — |
The data controller must respond to these requests free of charge. Where requests are manifestly unfounded or excessive, the controller may charge a reasonable fee or refuse to act, but must justify this decision.
General obligations of the data controller
The LOPDGDD and the GDPR establish a set of obligations that every entity processing personal data must fulfil. These are not recommendations: they are legal requirements whose non-compliance can result in penalties.
| Obligation | What it consists of | Tool / document |
|---|---|---|
| Record of Processing Activities (RoPA) | Internal inventory of all processing activities, including purpose, legal basis, retention periods, recipients and security measures | RoPA (Art. 30 GDPR) |
| Information to data subjects | Inform in a clear and accessible manner about who processes the data, for what purpose, for how long and what rights they have | Information clauses / privacy policy |
| Contracts with data processors | Formalise in writing the relationship with suppliers who access personal data on behalf of the controller (accountants, IT, hosting, etc.) | Data processing agreement (Art. 28 GDPR) |
| Security measures | Implement technical and organisational measures appropriate to the risk: access controls, encryption, backups, password policies | Policy / risk analysis |
| Personal data breach notification | If a breach affecting personal data occurs, notify the AEPD within a maximum of 72 hours of becoming aware of it. If the risk is high, also notify the data subjects | Breach management protocol |
| Data Protection Impact Assessment (DPIA) | Mandatory when processing is likely to result in a high risk to the rights and freedoms of individuals: large-scale video surveillance, profiling with sensitive data, automated decisions with legal effects | DPIA (Art. 35 GDPR) |
| Privacy by design and by default | Incorporate data protection from the outset of any project or system, not as an afterthought | Prior analysis in new projects |
| Accountability | Actively demonstrate compliance: it is not enough to comply — you must be able to prove it | Documentation, records, evidence |
The Data Protection Officer: who is required to have one
The Data Protection Officer (DPO, also referred to as DPD from the Spanish Delegado de Protección de Datos) is the figure responsible for supervising compliance with data protection regulations within the organisation. The DPO may be internal or external, but their appointment is mandatory in the cases set out in Art. 37 GDPR and, more specifically for Spain, Art. 34 LOPDGDD.
The information below is indicative. The final requirement will depend on the scale, volume and exact nature of the processing activities of each entity. Each case requires individual analysis.
| Type of entity / activity | DPO mandatory | Legal basis |
|---|---|---|
| Public administrations, bodies and entities in the public sector | Yes | Art. 37.1.a GDPR / Art. 34 LOPDGDD |
| Professional associations and their governing councils | Yes | Art. 34.1.a LOPDGDD |
| Educational centres (regulated education) and universities | Yes | Art. 34.1.b LOPDGDD |
| Entities providing electronic communications services | Yes | Art. 34.1.c LOPDGDD |
| Credit institutions (banks, savings banks, credit cooperatives) | Yes | Art. 34.1.e LOPDGDD |
| Insurance and reinsurance companies | Yes | Art. 34.1.g LOPDGDD |
| Healthcare establishments with access to clinical records, except sole-practitioner healthcare professionals | Yes | Art. 34.1.h LOPDGDD |
| Large-scale processing of special category data or criminal data | Yes | Art. 37.1.c GDPR / Art. 34 LOPDGDD |
| Regular and systematic large-scale monitoring of data subjects | Yes | Art. 37.1.b GDPR |
| Standard SME without high-risk activities | Depends on analysis | Art. 37 GDPR (risk assessment) |
The DPO must be registered with the AEPD. Their position is independent: they cannot be instructed in the performance of their duties and cannot be dismissed on that basis. They act as the point of contact between the organisation, the AEPD and data subjects.
"The DPO is not the one who signs paperwork. They are the one who knows the organisation's actual processing activities, identifies risks before they materialise and knows exactly what the AEPD would say if they called tomorrow. That cannot be improvised."
Mario P. Talamillo · Managing Partner, Certix®
Specific processing activities regulated in Title III
The LOPDGDD dedicates an entire title to specific situations that warrant particular regulation in Spain:
- Video surveillance (Art. 22): Images captured by security cameras may only be retained for a maximum of 30 days, unless they must be preserved to evidence the commission of acts. There is an obligation to inform via a visible sign.
- Defaulter registers / credit information systems (Art. 20): A person may only be included in a creditworthiness register if the debt is certain, due and enforceable, the creditor has previously informed the debtor and one month has elapsed since that notification.
- Advertising exclusion systems (Art. 23): The law expressly recognises the possibility of processing data to manage advertising exclusion lists (similar to the Robinson List).
- Processing for research purposes (Art. 31): The law opens the possibility of reusing data for scientific research, statistical or archiving purposes in the public interest, with appropriate safeguards.
- Rights of deceased persons (Art. 3): Heirs and persons linked to the deceased may exercise the rights of access, rectification and erasure of the deceased's data, unless the deceased had expressly prohibited this.
The sanctions regime (Title VIII)
The LOPDGDD classifies infringements into three tiers, further distinguishing between private entities and public sector bodies.
For private sector entities
| Tier | Limitation period | Maximum penalty (GDPR) | Examples of infringement |
|---|---|---|---|
| Very serious | 3 years | €20,000,000 or 4% of annual global turnover | Violating basic privacy principles, failing to honour data subject rights, unlawful international transfers, processing sensitive data without a legal basis |
| Serious | 2 years | €10,000,000 or 2% of annual global turnover | Not maintaining a RoPA, failing to notify breaches within the deadline, not applying adequate security measures, not appointing a DPO when mandatory |
| Minor | 1 year | Warning or up to €40,000 | Formal non-compliance: incomplete privacy policy, failing to respond to a straightforward rights request within the deadline |
For public sector bodies
Where the infringer is a Public Administration, public law entity or political party, the LOPDGDD (Art. 77) replaces the financial fine with a reprimand. The AEPD communicates the resolution to the competent body so that the person responsible is required to account for the matter. This does not preclude the possibility of disciplinary liability for the responsible employees or officeholders.
Criteria for determining the penalty
Fines are neither automatic nor linear. The AEPD takes into account aggravating and mitigating factors: the duration of the infringement, the number of individuals affected, the measures taken to mitigate the damage, the degree of cooperation, whether there is a history of prior infringement, the benefit obtained and the nature of the data processed.
Digital rights under Title IX
The LOPDGDD was the first European data protection law to include a specific catalogue of digital rights, both civil and labour-related. This Title IX (Arts. 79–97) is one of the major innovations of the legislation compared to the former LOPD.
| Digital right | What it protects |
|---|---|
| Right to be forgotten in search engines (Art. 93) | Request that search engines stop linking to outdated, inaccurate or rights-infringing personal information |
| Right to be forgotten on social networks (Art. 94) | Request erasure of personal data published on social networks, especially data shared during minority |
| Portability on social networks (Art. 95) | Request data from the platform in a portable format in order to migrate to another service |
| Privacy and devices in the workplace (Art. 87) | Employees have the right to protection of their privacy when using corporate digital devices. The employer may access them only where it has previously informed employees of the usage criteria |
| Right to digital disconnection (Art. 88) | Employees have the right not to respond to work communications outside their working hours. Companies must draw up an internal disconnection policy |
| Workplace video surveillance (Art. 89) | The employer may install cameras in the workplace, but must inform employees in advance and expressly. Cameras in changing rooms or bathrooms are prohibited |
| Geolocation in the workplace (Art. 90) | The employer may use geolocation systems to monitor vehicles or working hours compliance, but must inform employees in advance |
| Digital will (Art. 96) | Any person may designate someone to manage their digital profiles and content after death, including instructions for their deletion |
| Digital education (Art. 83) | Educational centres must promote safe internet and social network use among minors, with specific protocols |
| Correction in digital media (Art. 85) | Individuals have the right for digital media outlets to facilitate the exercise of the right to correct inaccurate information |
What changed compared to the former LOPD of 1999
The LOPDGDD is not a minor revision. It represents a complete paradigm shift compared to Organic Law 15/1999:
| Aspect | LOPD 1999 | LOPDGDD 2018 |
|---|---|---|
| Registration with the AEPD | Mandatory for all data files | Abolished. Replaced by the internal RoPA |
| Compliance approach | Formalistic: completing administrative procedures | Proactive (accountability): demonstrating real compliance |
| Consent | Could be tacit or by omission | Always active, freely given, specific and unambiguous |
| Data Protection Officer | Did not exist as a figure | Mandatory for numerous sectors |
| Maximum penalties | Up to €600,000 | Up to €20,000,000 or 4% of global turnover |
| Digital labour rights | Not contemplated | New Title IX with 19 rights |
| Breach notification | Not mandatory | Mandatory within 72 hours to the AEPD |
| Privacy by design | Not contemplated | Mandatory principle (Art. 25 GDPR) |
Checklist: does your organisation comply with the LOPDGDD?
This checklist is a starting point for an internal review. It does not replace an individual professional analysis.
- Up-to-date Record of Processing Activities (RoPA) covering all processing activities carried out by the organisation
- Information clauses or privacy policy in all forms, contracts and data collection points
- Legal basis identified for each processing activity (consent, contract, legal obligation…)
- Explicit and granular consent for commercial processing or where required, with a record of when and how it was obtained
- Data processing agreements signed with all suppliers who access data (accountants, IT, cloud, marketing…)
- Protocol for responding to rights requests with defined deadlines and responsible parties
- Personal data breach management protocol with the procedure for notifying the AEPD within 72 hours
- Documented technical and organisational security measures appropriate to the risk
- Cookie policy and consent banner in line with AEPD guidelines
- Video surveillance, geolocation and device clauses if the organisation uses these means
- Digital disconnection policy if the organisation has employees
- DPO appointed and registered with the AEPD if the organisation belongs to any of the mandatory sectors
Frequently asked questions about the LOPDGDD
Does the LOPDGDD apply to me even if I only have two employees?
Yes. The obligation is not conditional on the size of the company, but on whether you process personal data. With two employees you are already processing data (payroll, client data, suppliers, etc.). That said, obligations are proportionate to risk: a micro-business without special category data does not face the same requirements as a hospital.
Is the LOPDGDD the same as the GDPR?
No. They are complementary instruments. The GDPR is the directly applicable European regulation. The LOPDGDD is the Spanish law that adapts and develops it for Spain, adds national specifics and establishes digital rights. To comply, you must respect both.
What happens if I do not have a privacy policy on my website?
It is a defined infringement. The AEPD may issue a reprimand, impose a fine or both. Penalties for deficiencies in user information are typically classified as minor or serious, depending on the scope and the type of data affected.
Can the DPO be the company's own managing director or partner?
Only if there is no conflict of interests. The managing director cannot act as DPO if their managerial role leads them to make decisions about data processing activities, because they would then be supervising their own decisions. This is one of the reasons why an external DPO is common in medium and large organisations.
How long is there to respond to a rights request?
One month from receipt of the request. This may be extended by a further two months where the request is complex or the volume of requests is high, provided the data subject is informed within the first month and the reasons are explained.
What is a personal data breach and when must it be notified?
A personal data breach is any incident that leads to the destruction, loss, alteration or unauthorised access to personal data: a ransomware attack encrypting a server containing client data, the loss of a laptop with employee information, a mass email sent to the wrong recipients. If the breach has consequences for the rights and freedoms of individuals, it must be notified to the AEPD within 72 hours of becoming aware of it.
Legal notice: This content is for informational and educational purposes only; it does not constitute legal advice in any case. The application of regulations to each specific case requires individual analysis.