Data protection is one of those concepts everyone mentions but few define precisely. It has to do with your privacy, with the trust you place in a company when you give it your email or your national ID, and with a European legal framework that binds a multinational and a self-employed professional alike. This guide explains, rigorously but accessibly, what personal data protection is, what the law says in Spain and what it means for any organisation that processes information about people.
It is not just a matter of paperwork or a checkbox to accept. It is a fundamental right with a concrete legal framework: the European GDPR and the Spanish LOPDGDD. We will look at its legal basis, when it applies, when it is infringed, the principles that underpin it and the rights it grants you over your own information.
In short
- Data protection is the set of rules governing how the data of natural persons is processed; in Spain it is governed by the GDPR (Regulation (EU) 2016/679) and the LOPDGDD (Organic Law 3/2018).
- It has been mandatory since 25 May 2018 for any company, self-employed professional or entity that processes personal data, regardless of size or sector.
- It rests on 7 principles (art. 5 GDPR) and grants rights to individuals: access, rectification, erasure, restriction, portability, objection and rights regarding automated decisions.
- The supervisory authority in Spain is the AEPD, to which complaints are made under art. 77 GDPR.
Contents of this guide
- What is personal data protection?
- Legal basis: GDPR and LOPDGDD in Spain
- When is data protection compliance mandatory?
- When is data protection law breached?
- The principles of data protection (art. 5 GDPR)
- Individuals' rights over their data
- Data protection for companies and the self-employed
- Difference between the GDPR, the LOPDGDD and the former LOPD
- Frequently asked questions
What is personal data protection?
Personal data protection is the set of rights, principles and obligations that governs how organisations collect, use, store and share the information of identified or identifiable natural persons. In Spain and the European Union it is governed by the GDPR (Regulation (EU) 2016/679) and the LOPDGDD (Organic Law 3/2018), and it constitutes a fundamental right.
It is worth distinguishing two terms that are used as synonyms but are not identical. Data privacy is the broad concept: each person's right to control their personal information. Personal data protection is the concrete legal framework that makes that privacy enforceable, with rules, authorities and consequences. When we talk about "data and privacy" in legal terms, we are talking about protecting a right through verifiable rules.
What counts as personal data? Any information that allows a natural person to be identified, directly or indirectly: name, national ID, email address, phone number, IP address, location data or an online identifier. Some data receives enhanced protection because of its sensitivity — health, political opinions, religion, ethnic origin, sex life —: these are the special categories regulated in art. 9 GDPR, whose processing is subject to severe restrictions.
Legal basis: GDPR and LOPDGDD in Spain
Data protection in Spain rests on two pieces of legislation that operate together. The GDPR is the European framework; the LOPDGDD develops it and adapts it to the Spanish legal order. They are not alternatives to choose between: they apply simultaneously.
- GDPR — Regulation (EU) 2016/679: the General Data Protection Regulation. It is directly applicable in all Member States and has been applicable since 25 May 2018. Being a regulation, it does not require national transposition to be binding.
- LOPDGDD — Organic Law 3/2018, of 5 December: on the Protection of Personal Data and Guarantee of Digital Rights. It is the Spanish law that develops the GDPR, gives shape to the aspects the regulation left to each State's discretion and repealed the former LOPD (Organic Law 15/1999).
To this is added the duty of transparency. When an organisation collects your data directly from you (art. 13 GDPR) or from a third party (art. 14 GDPR), it must inform you of who processes your data, for what purpose, on what legal basis and how to exercise your rights. That information clause is the first point of contact between the rules and the individual.
If you want to explore each set of rules separately, you can consult our complete GDPR guide and our complete LOPDGDD guide.
When is data protection compliance mandatory?
Complying with data protection rules has been mandatory since 25 May 2018 for any company, self-employed professional or entity that processes personal data, regardless of its size or sector. There is no minimum turnover or headcount threshold below which the rules stop applying: it is enough to process the data of natural persons.
In practice, this reaches almost any professional activity. If you have a customer database, manage employee payroll, send commercial communications, install cookies on your website or keep your suppliers' contact details, you are processing personal data and the rules apply to you.
What does vary from one organisation to another is the intensity of the measures. The GDPR follows a risk-based approach: a company processing health data on a large scale must apply enhanced safeguards that are not required of a small shop. But the duty to comply with the principles and to respect individuals' rights is universal, not optional.
When is data protection law breached?
Data protection rules are infringed, among other cases, when data is processed without a legal basis under art. 6 GDPR, when the data subject is not informed in accordance with arts. 13 and 14, when appropriate security measures are not applied (art. 32) or when the data subject's rights are not addressed within the prescribed time limits and terms. Malicious intent is not required: non-compliance can arise from lack of awareness.
Some everyday examples of processing without a legal basis: sending advertising by email to someone who never consented, disclosing customer data to a third party without authorisation, or retaining CVs indefinitely without informing candidates of it. The absence of a processor agreement with suppliers who access your data (art. 28 GDPR) is another frequent failure.
When an infringement occurs, the AEPD may open a procedure. The GDPR sets out the sanctions regime in its art. 83, with two amount tiers: up to €10 million or 2% of total annual worldwide turnover (art. 83(4)), and up to €20 million or 4% (art. 83(5)), applying in each case the higher figure. The specific amount is determined proportionately, taking into account the gravity, duration and circumstances of the infringement. Anyone who considers their rights to have been infringed may lodge a complaint with the AEPD in accordance with art. 77 GDPR.
The principles of data protection (art. 5 GDPR)
Article 5 of the GDPR sets out the seven principles governing any processing of personal data. They are the backbone of the entire framework: if a processing activity does not fit under these principles, it should not be carried out. Understanding them is understanding what the law expects of any organisation.
| Principle | What it requires |
|---|---|
| Lawfulness, fairness and transparency | Data must be processed lawfully (with a legal basis), fairly (without deception) and transparently (the person must know what is being done with their data). |
| Purpose limitation | Data is collected for specified, explicit and legitimate purposes. It cannot later be reused for purposes incompatible with the original one. |
| Data minimisation | Only data that is adequate, relevant and limited to what is necessary for the intended purpose may be processed. Not one item more. |
| Accuracy | Data must be accurate and kept up to date. Inaccurate data must be erased or rectified without delay. |
| Storage limitation | Data cannot be kept longer than necessary. Once the retention period is over, it must be erased or anonymised. |
| Integrity and confidentiality | Data must be processed with technical and organisational measures that guarantee its security against unauthorised access, loss or destruction. |
| Accountability | The organisation must not only comply with the above principles: it must be able to actively demonstrate it. The burden of proof falls on the organisation. |
These principles are not abstract declarations. For a processing activity to be lawful (the first principle), it must rely on at least one of the six lawful bases in art. 6 GDPR: consent, performance of a contract, legal obligation, vital interests, public interest task or legitimate interests. Choosing the correct basis then conditions which rights the person can exercise and which information obligations the organisation takes on.
"Data protection does not begin with a document, it begins with a question: why do I have this piece of data and what am I doing with it? When an organisation answers that question honestly, compliance stops being a burden and becomes a way of respecting whoever trusted it."
Mario P. Talamillo · Managing Partner, Certix®
Individuals' rights over their data
Data protection does not only impose obligations on organisations: it grants rights to individuals over their own information. The GDPR regulates them in its articles 15 to 22, and anyone can exercise them against whoever processes their data. The general response deadline is one month, extendable to three in complex cases.
| Right | Article | What it allows the person to do |
|---|---|---|
| Access | Art. 15 | Know whether an organisation processes their data and access it, together with information about the processing. |
| Rectification | Art. 16 | Correct inaccurate data or complete data that is incomplete. |
| Erasure ("right to be forgotten") | Art. 17 | Request deletion of their data when it is no longer necessary, they withdraw consent or the processing is unlawful. |
| Restriction | Art. 18 | Suspend processing while a dispute over accuracy or lawfulness is resolved, keeping the data blocked. |
| Portability | Art. 20 | Receive their data in a structured, commonly used format and transmit it to another controller. |
| Objection | Art. 21 | Object to processing based on legitimate interests or the public interest. |
| Automated decisions | Art. 22 | Not to be subject to decisions based solely on automated processing, including profiling, with significant effects. |
To exercise any of these rights, it is enough to contact the organisation that processes the data, usually through the contact indicated in its privacy policy. If the response is not satisfactory, the person can turn to the AEPD and lodge a complaint under art. 77 GDPR.
Data protection for companies and the self-employed
If you run a company or are self-employed and you process the data of customers, employees or suppliers, the rules apply to you. The good news is that complying is not about piling up documents, but about ordering coherently how you handle information. These are the basic elements any organisation should have in order:
- Record of Processing Activities (RoPA, art. 30): the inventory of what data you process, for what purpose, for how long and with what measures. It is the foundation of all compliance.
- Lawful bases analysed (art. 6): identify, for each processing activity, which legal basis it relies on.
- Information clauses and privacy policy (arts. 13–14): inform clearly the people whose data you process.
- Processor agreements (art. 28): with every supplier that accesses data on your behalf (accountant, cloud software, courier).
- Security measures (art. 32): technical and organisational, proportionate to the risk of your processing activities.
- Rights and data breach procedures: knowing how to handle an access request or how to react to an incident.
In some cases, it will also be mandatory to appoint a Data Protection Officer (DPO). If you want to check whether your organisation is required to have one, consult our page on the Data Protection Officer. And if you prefer a quick first snapshot of your situation, you can take the GDPR compliance test.
Measures are not applied once and for all: data protection requires continuous, risk-based assessment, revisited whenever the processing activities, the technology or the regulatory context change.
Difference between the GDPR, the LOPDGDD and the former LOPD
It is easy to confuse these three acronyms, especially because they coexist in everyday language. The key is to understand that the former LOPD is no longer in force: it was repealed. Today the framework is made up of the European GDPR and the Spanish LOPDGDD.
| Legislation | What it is | Status |
|---|---|---|
| GDPR | Regulation (EU) 2016/679. European framework directly applicable in all Member States. | In force (since 25/5/2018) |
| LOPDGDD | Organic Law 3/2018, of 5 December. Develops and adapts the GDPR to the Spanish legal order. | In force |
| LOPD (former) | Organic Law 15/1999. Was the Spanish legislation prior to the GDPR. | Repealed by the LOPDGDD |
In summary: the GDPR sets the common European framework; the LOPDGDD gives it shape for Spain and, on entering into force, rendered the 1999 LOPD without effect. When someone today mentions "the LOPD" to refer to the current rules, the correct terms are GDPR and LOPDGDD.
Frequently asked questions
What is personal data protection?
It is the set of rights, principles and obligations that governs how organisations collect, use, store and share the information of identified or identifiable natural persons. In Spain and the EU it is governed by the GDPR (Regulation (EU) 2016/679) and the LOPDGDD (Organic Law 3/2018), and it constitutes a fundamental right.
When is data protection compliance mandatory?
Since 25 May 2018, the date the GDPR became applicable, complying with the rules has been mandatory for any company, self-employed professional or entity that processes personal data, regardless of its size or sector. There is no minimum turnover or headcount threshold below which the rules stop applying.
When is data protection law breached?
The rules are infringed, among other cases, when data is processed without a legal basis under art. 6 GDPR, when the data subject is not informed in accordance with arts. 13 and 14, when appropriate security measures are not applied (art. 32) or when the data subject's rights are not addressed. Malicious intent is not required: non-compliance can arise from lack of awareness.
What is the difference between the GDPR and the LOPDGDD?
The GDPR is the European regulation directly applicable in all Member States. The LOPDGDD is the Spanish law that develops and adapts it to the national legal order. They are not alternatives: they apply together. The LOPDGDD repealed the former LOPD (Organic Law 15/1999).
Who do you complain to about data protection in Spain?
The supervisory authority in Spain is the AEPD (Spanish Data Protection Agency). Anyone who considers their rights to have been infringed may lodge a complaint with it, in accordance with art. 77 GDPR, without prejudice to any action they may bring through the courts.
Conclusion
Data protection is not a formality or a PDF that is signed and filed away: it is a framework of rights and obligations that affects anyone who processes the information of others. Understanding its principles, its legal bases and the rights it grants is the first step to complying for real, not just in appearance.
Every organisation is different, and applying the rules to your specific case requires individual analysis. If you want an expert to review your situation and tell you exactly what you need, tell us about your case and you will speak directly with a specialist, with no salespeople in between.
This content is purely informational and educational; it does not constitute specialised legal advice in any case. Applying the rules to each specific case requires individual analysis.