Law note · Spain
GDPR Articles 33-34 and LOPDGDD Article 69, Breach Notification
A controller must notify the AEPD within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk.
LOPDGDD Article 69 gives the AEPD its own provisional-measures power, including a cautionary data block tied specifically to international-transfer risk (Art. 69.2), and Titulo IX makes late, incomplete, or missing breach notification its own separate administrative infraction (Art. 73(r)-(s)), confirmed by reading Titulo IX's text directly rather than inferring it from General Data Protection Regulation (GDPR) alone.
What it asks of an app
- Notify the AEPD within 72 hours of becoming aware of a personal-data breach affecting a person in Spain, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, processes_biometrics, processes_voice
Primary source: GDPR Arts. 33-34
LOPDGDD Art. 69, Art. 73(r)-(s) (direct read)