Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite Regulation (EU) 2016/679, Arts. 33-34; LOPDGDD, Art. 69, Art. 73(r)-(s)
stage In effect
since 2018-12-07
source GDPR Arts. 33-34
A controller must notify the AEPD within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk.
LOPDGDD Article 69 gives the AEPD its own provisional-measures power, including a cautionary data block tied specifically to international-transfer risk (Art. 69.2), and Titulo IX makes late, incomplete, or missing breach notification its own separate administrative infraction (Art. 73(r)-(s)), confirmed by reading Titulo IX's text directly rather than inferring it from General Data Protection Regulation (GDPR) alone.
What it asks of an app →
Comprehensive regime
cite Ley Organica 3/2018, de 5 de diciembre, de Proteccion de Datos Personales y garantia de los derechos digitales (BOE-A-2018-16673)
stage In effect
since 2018-12-07
source BOE, consolidated text (direct read)
Spain gives the General Data Protection Regulation (GDPR) domestic effect through the Ley Organica 3/2018 (LOPDGDD, Organic Law on the Protection of Personal Data and the Guarantee of Digital Rights), in force since 7 December 2018.
Unlike a bare implementing act, the LOPDGDD carries substantial national additions confirmed by reading the BOE text directly: a freestanding Titulo X on digital rights (Arts. 79-97), a Titulo VI chapter on international transfers (Arts. 40-43) layered on GDPR Chapter V, and a Titulo IX administrative sanctioning regime (Arts. 70-78) calibrated onto GDPR Article 83's fine tiers.
Article 8, read verbatim, tightens rather than loosens GDPR's public-interest and legal-obligation bases: such processing is valid only where a Union-law norm or a Spanish statute-rank norm so provides.
What it asks of an app →
Cross border transfer
cite Regulation (EU) 2016/679, Arts. 44-49, 83(5); LOPDGDD, Arts. 40-43, 72.1(l)
stage In effect
since 2018-12-07
source GDPR Arts. 44-49, 83(5)
A transfer of personal data outside the EEA requires an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. LOPDGDD Titulo VI (Arts. 40-43), confirmed by reading the article headings directly, adds a national administrative-procedure layer: cases the AEPD may itself authorize, cases requiring AEPD prior authorization, and cases requiring prior notice to the competent authority.
LOPDGDD Article 72.1(l) separately makes an unauthorized international transfer its own "muy grave" national infraction category.
What it asks of an app →
Data subject rights
cite LOPDGDD, Arts. 11-18, 93-96
stage In effect
since 2018-12-07
source BOE, consolidated text, LOPDGDD Arts. 11-18, 93-96 (direct read)
LOPDGDD Titulo III (Arts. 11-18) mirrors General Data Protection Regulation (GDPR) Articles 12-22 domestically: transparency, access, rectification, erasure, restriction, portability, and objection.
Titulo X then layers freestanding rights with no GDPR counterpart, confirmed by reading the article titles directly: Article 93's right to be forgotten against internet search engines, Article 94's equivalent against social-network services, Article 95's social-network portability right, and Article 96's right to a digital will governing a deceased person's digital accounts.
What it asks of an app →
Enforcement supervision
cite Regulation (EU) 2016/679, Arts. 82-83; LOPDGDD, Art. 47, Arts. 70-78
stage In effect
since 2018-12-07
source GDPR Arts. 82-83
The AEPD is Spain's supervisory authority; LOPDGDD Titulo IX (Arts. 70-78) sorts infractions into muy graves, graves, and leves, each defined by direct cross-reference to a General Data Protection Regulation (GDPR) Article 83 tier rather than an independent Spanish fine scale, confirmed by reading the text directly. GDPR Article 82 arms an individual with a direct private right of action.
This session could not confirm the specific Spanish instrument transposing the EU Representative Actions Directive for collective data-protection claims; LOPDGDD's own Disposicion final septima, read directly, only modifies a narrow amicus provision, not a class-action mechanism.
What it asks of an app →
Sensitive categories
cite Regulation (EU) 2016/679, Art. 9; LOPDGDD, Art. 9
stage In effect
since 2018-12-07
source AEPD, "Guia sobre tratamientos de control de presencia mediante sistemas biometricos" (Nov. 2023, direct read)
LOPDGDD Article 9 supplies no independent biometric definition; it operates entirely within General Data Protection Regulation (GDPR) Article 9's special-category frame.
The AEPD's November 2023 guide on biometric presence-control systems, read directly (and itself marked "en revision", under review, so treated as the AEPD's current stated position rather than a settled rule), concludes that current Spanish law contains no sufficiently specific statutory authorization for biometric employee time-and-attendance processing, applying the Tribunal Constitucional's STC 76/2019 reserva-de-ley standard.
The AEPD fined Mercadona EUR 2,520,000 (Resolucion PS/00120/2021) for a facial-recognition system matching shoppers against people with criminal convictions or restraining orders, holding the processing categorically prohibited under Article 9.1 with no Article 9.2 exception available.
What it asks of an app →