Law note · Spain

GDPR Articles 33-34 and LOPDGDD Article 69, Breach Notification

cite Regulation (EU) 2016/679, Arts. 33-34; LOPDGDD, Art. 69, Art. 73(r)-(s) stage In effect since 2018-12-07 reviewed 2026-08-24

A controller must notify the AEPD within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk.

LOPDGDD Article 69 gives the AEPD its own provisional-measures power, including a cautionary data block tied specifically to international-transfer risk (Art. 69.2), and Titulo IX makes late, incomplete, or missing breach notification its own separate administrative infraction (Art. 73(r)-(s)), confirmed by reading Titulo IX's text directly rather than inferring it from General Data Protection Regulation (GDPR) alone.

What it asks of an app

  • Notify the AEPD within 72 hours of becoming aware of a personal-data breach affecting a person in Spain, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, processes_biometrics, processes_voice

Primary source: GDPR Arts. 33-34
LOPDGDD Art. 69, Art. 73(r)-(s) (direct read)

← Back to the example  ·  Lint your app →