LOPDP, notificación de vulneración de seguridad
LOPDP, arts. 43 y 46 (notificacion de vulneracion de seguridad)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 26 May 2021.
A breach notification rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Notify the Authority and the telecommunications regulator of a personal-data security breach as soon as possible and no later than five days after becoming aware of it.
- Notify the affected data subject within 3 days of learning of the risk, where the breach carries a risk to their fundamental rights and individual freedoms.
- As a processor, notify the controller of any personal-data security breach as soon as possible and within 2 days of learning of it.
- Give the reasons for the delay where your notification to the Authority is later than the five days article 43 allows.
- Where notifying every affected data subject would take a disproportionate effort, make a public communication of the breach instead.
What it reaches
Obligation class
Breach notice, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 43 requires the controller to notify a personal-data security breach to the Personal Data Protection Authority and to the telecommunications regulator as soon as possible and no later than five days after becoming aware of it, unless the breach is unlikely to pose a risk to the rights and freedoms of natural persons, and to give the reasons for any delay where the notification is later than that.
The same article requires the processor to notify the controller of any personal-data security breach as soon as possible and no later than two days from the date it learns of it.
Article 46 requires the controller to notify the data subject without delay where the breach carries a risk to their fundamental rights and individual freedoms, within three days from the date it learned of the risk, and excuses that notice only where the controller had applied demonstrably effective protection measures to the affected data, where it has taken measures ensuring the risk will not occur, or where notice would take a disproportionate effort, in which case it must make a public communication instead.
The law was published in Registro Oficial Suplemento 459 of 26 May 2021 and is recorded there as in force, which is the day these provisions began to bind.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometricsoperates_essential_service
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.