#
Mature, fully operative omnibus regime with an active, well-resourced supervisory authority and clear statutory instruments.
Sub-modules (5)
Regulator And AuthorityGreen
AEPD is the sole general-purpose national DPA for Spain; certain autonomous communities (Cataluña, País Vasco, Andalucía) maintain regional DPAs for public-sector processing within their territory, but AEPD retains general and private-sector competence.
Claims (1):
- The Agencia Española de Protección de Datos (AEPD) is Spain's national data protection supervisory authority under GDPR and LOPDGDD.
Act And InstrumentsGreen
Core instruments are GDPR (directly applicable), LOPDGDD, LO 7/2021 (law-enforcement data), RD 389/2021 (AEPD Statute) and Ley 34/2002 LSSI for information-society services.
Claims (1):
- Spain's data protection regime rests on GDPR (Regulation (EU) 2016/679) applied directly, LOPDGDD, LO 7/2021, RD 389/2021 (AEPD Statute) and Ley 34/2002 (LSSI) for e-commerce/electronic communications.
Material ScopeGreen
GDPR/LOPDGDD apply to any processing of personal data relating to an identified or identifiable natural person; data of legal persons is excluded.
Claims (1):
- GDPR/LOPDGDD apply to the processing of personal data relating to identified or identifiable natural persons; data concerning legal persons is not covered.
Territorial ScopeGreen
Extraterritorial reach under GDPR Art 3(2) captures non-EU controllers/processors offering goods/services to, or monitoring the behaviour of, EU data subjects; such entities must designate an EU representative.
Claims (1):
- Non-EU-established controllers/processors offering goods or services to, or monitoring the behaviour of, EU data subjects fall within GDPR's territorial scope and must appoint an EU representative as contact point for supervisory authorities and data subjects.
Regulator Registration And FilingAmber
General file-notification/registration with AEPD was abolished from 25 May 2018 and replaced by the internal, non-filed Registro de Actividades de Tratamiento (ROPA). The only affirmative filing duty remaining is communication of DPO appointments/removals to AEPD within 10 days.
Claims (2):
- Since 25 May 2018, the obligation to register/notify processing files with AEPD has disappeared, both for public and private controllers, replaced by the internal Registro de Actividades de Tratamiento (ROPA).
- Controllers/processors that designate a DPO (mandatorily or voluntarily) must communicate the appointment, and any subsequent removal, to AEPD within 10 days.
Sources and claims (6)
- ConfirmedAgencia Española de Protección de Datos — The Agencia Española de Protección de Datos (AEPD) is Spain's national data protection supervisory authority under GDPR and LOPDGDD.observed
- ConfirmedAgencia Española de Protección de Datos — Spain's data protection regime rests on GDPR (Regulation (EU) 2016/679) applied directly, LOPDGDD, LO 7/2021, RD 389/2021 (AEPD Statute) and Ley 34/2002 (LSSI) for e-commerce/electronic communications.observed
- ConfirmedAgencia Española de Protección de Datos — GDPR/LOPDGDD apply to the processing of personal data relating to identified or identifiable natural persons; data concerning legal persons is not covered.observed
- ConfirmedAgencia Española de Protección de Datos — Non-EU-established controllers/processors offering goods or services to, or monitoring the behaviour of, EU data subjects fall within GDPR's territorial scope and must appoint an EU representative as contact point for supervisory authorities and data subjects.observed
- ConfirmedAgencia Española de Protección de Datos — Since 25 May 2018, the obligation to register/notify processing files with AEPD has disappeared, both for public and private controllers, replaced by the internal Registro de Actividades de Tratamiento (ROPA).observed
- ConfirmedAgencia Española de Protección de Datos — Controllers/processors that designate a DPO (mandatorily or voluntarily) must communicate the appointment, and any subsequent removal, to AEPD within 10 days.observed