Ir al contenido
Launch offerOnly until … — after that, prices go back to normal.See pricing

RGPD gestorías

LOPDGDD: what it adds to the European law (RGPD) and what obligations you have

Author: Tranquilia by GRAC SA9 min read

General information about the law. It’s no substitute for a lawyer’s advice or a look at your specific case.

Direct answer: the LOPDGDD (Ley Orgánica 3/2018, de 5 de diciembre — Spain's data protection act) is the Spanish law that completes the RGPD (the EU data protection regulation): it does not replace it or repeat it, it develops the margins the European regulation leaves to each country and adds obligations that do not exist in the rest of the European Union. Among its most practical contributions are the age of 14 for a minor to give consent in Spain, a closed list of businesses required to have a data protection officer, and a whole block of digital rights — from digital disconnection at work to the digital will — that the RGPD does not even mention. It came into force on 7 December 2018 and today applies in Spain alongside the RGPD, never in its place.

This article is general information on data protection rules. It does not replace a lawyer's advice or a specific analysis of your business: use it as a map, not as a legal opinion.

Contents

  1. What is the LOPDGDD and how does it relate to the RGPD?
  2. Why is there a Spanish law if the RGPD already applies directly?
  3. What changes for minors?
  4. What does it say about the data of deceased people?
  5. What obligations does it add to your day-to-day business?
  6. When does it require a data protection officer?
  7. What are the digital rights in title X?
  8. What happens if you do not comply?
  9. Frequently asked questions
  10. Sources

What is the LOPDGDD and how does it relate to the RGPD?

The RGPD (Reglamento (UE) 2016/679) is the European data protection rule. It applies in the same way in the 27 countries of the Union since 25 May 2018, without each country having to translate it into its own law: that is why it is called a "regulation" and not a "directive". So far, nothing different from what you already know.

What happens is that the RGPD itself, in several of its articles, expressly says "each Member State decides this". The age of consent for minors, the penalty regime of each national authority, or how to handle data in the workplace are examples of points the regulation leaves open to each country.

The LOPDGDD — Ley Orgánica 3/2018, de 5 de diciembre, de Protección de Datos Personales y garantía de los derechos digitales — is the law with which Spain fills those gaps. It was published in BOE núm. 294, of 6 December 2018, and came into force the following day. It has 97 articles spread across ten titles, plus additional and final provisions.

Why is there a Spanish law if the RGPD already applies directly?

For two reasons that are worth telling apart:

  • To develop the margins the RGPD leaves open. For example, the age of consent for minors or the specific rules for the data protection officer in Spain.
  • To add rights the RGPD does not cover at all. Title X of the LOPDGDD governs digital rights — digital disconnection, the digital will, the right to be forgotten in search engines — that have no equivalent in the European regulation: they go beyond data protection and enter the ground of digital rights in general.

In practice, for your business this means that complying only with the RGPD is not complying with all the Spanish rules. You need to look at both texts together.

What changes for minors?

The RGPD (art. 8) sets the default age at 16 for a minor to give consent for online services aimed at them, but lets each country lower it to a minimum of 13.

Spain set that age at 14 (art. 7 LOPDGDD), and did so for consent in general, not only for online services. Below the age of 14, processing based on consent is only valid if it is authorised by whoever holds parental authority or guardianship over the minor. The exception: where the law already requires that authorisation for the act itself — signing a contract, for example — consent follows that same rule.

What does it say about the data of deceased people?

The RGPD leaves the data of deceased people outside its scope: it is a decision for each country. The LOPDGDD does regulate the case, in its article 3: people linked to the deceased by family or de facto ties, and their heirs, may ask the data controller to access that data, correct it or ask for it to be erased, unless the deceased had expressly forbidden it while alive or a law prevents it.

It is a right that does not exist as such in the RGPD: it is entirely a contribution of the Spanish law.

What obligations does it add to your day-to-day business?

Beyond the broad principles, the LOPDGDD brings very specific pieces a business may need to apply directly:

  • Duty of confidentiality (art. 5 LOPDGDD): it expressly requires everyone who takes part in any stage of the processing — not just the controller — not to disclose the data they see through their work. It is the basis of the confidentiality clause your team signs.
  • Special categories of data (art. 9 LOPDGDD): it reinforces the RGPD principle that consent alone is not always enough to process data on political opinions, trade union membership, religion, sexual orientation or health: sometimes an additional legal basis or an extra safeguard is needed.
  • Video surveillance (art. 22 LOPDGDD): it sets its own regime for security cameras — a mandatory information sign, deletion within a maximum of one month — which does not appear in that detail in the RGPD.
  • Advertising exclusion systems (art. 23 LOPDGDD), the so-called «listas Robinson»: it governs the obligation to consult these systems before running certain advertising campaigns aimed at people who are not customers.

None of these four pieces is developed this way in the text of the RGPD: they are rules specific to the Spanish law, added on top of the general European principles.

When does it require a data protection officer?

The RGPD (art. 37.1) requires appointing a data protection officer in three general cases: being a public authority, carrying out regular and systematic monitoring of people on a large scale, or processing special category data on a large scale.

The LOPDGDD adds something the RGPD does not have: a closed list of fifteen types of entity that are required to do so "in every case", regardless of whether they meet those general criteria (art. 34.1 LOPDGDD). It includes, among others, professional associations, regulated teaching centres, large-scale telecommunications operators, banks, insurers and investment services firms, energy and gas distributors, entities responsible for shared creditworthiness or fraud-prevention files, certain advertising and commercial prospecting companies, healthcare centres legally required to keep clinical records (with the exception of the professional practising individually), private security companies and sports federations when they process minors' data.

If your business does not fit any of those fifteen cases or the general criteria of the RGPD, you are under no obligation to appoint an officer. Appointing one voluntarily remains a valid option (art. 34.2 LOPDGDD), although it is worth knowing that, once appointed, you are subject to the same regime as if it were mandatory.

What are the digital rights in title X?

Title X of the LOPDGDD (arts. 79 to 97) is the part furthest from the RGPD: it does not develop any article of the European regulation, it is a charter of digital rights that Spain decided to include inside this same law. Some of its articles directly affect any business with employees:

  • Art. 87: right to privacy and to the use of digital devices in the workplace.
  • Art. 88: right to digital disconnection, with the employer's obligation to draw up an internal policy, having heard the workers' representatives.
  • Art. 89: right to privacy against the use of video surveillance and sound recording devices in the workplace.
  • Art. 93: right to be forgotten in internet search engines.
  • Art. 96: the so-called "digital will": whoever the deceased has designated, or their executor, may request access to their digital content in order to carry out their instructions.

If you have staff, the first three are the ones that touch you most: they require you to have in writing how the company's devices are used, how rest outside working hours is respected and, if there are cameras, that they never point at your team's workstations.

What happens if you do not comply?

The AEPD (Agencia Española de Protección de Datos, Spain's data protection authority) is the body that watches over this in Spain. It can ask for explanations, order changes, issue a warning or impose a fine. The RGPD sets the possible maximums at two levels: up to 10 million euros or 2 % of annual worldwide turnover, and up to 20 million or 4 %, depending on the infringement (art. 83 RGPD). The higher of the two figures applies. The LOPDGDD, in its title IX (arts. 70 to 78), develops how infringements are classified in Spain and their limitation periods; for the exact criteria used to grade each case it is best to consult the text of the law directly, through the link in this article's sources.

In practice those figures are the legal ceiling, not the usual outcome: the penalty is graded by seriousness, the size of the business and whether you have cooperated. A small business that gets organised and responds well is not in that scenario. That is why it is worth having this settled: not to avoid a one-off scare, but to stop thinking about it.

Frequently asked questions

Does the LOPDGDD replace the RGPD?

No. The RGPD is the European rule and takes precedence; the LOPDGDD completes it in Spain, developing the points the regulation itself leaves open to each country and adding digital rights the RGPD does not cover.

If my business already complies with the RGPD, do I have anything outstanding under the LOPDGDD?

Probably yes, even if they are specific pieces: check the age of consent for minors if you process data on young people, the explicit duty of confidentiality with your team, and — if you have employees — the title X policies on digital devices, disconnection and video surveillance at work.

From the age of 14 (art. 7 LOPDGDD). Below that, the consent of whoever holds parental authority or guardianship is needed.

Do all companies need a data protection officer?

No. Only those that meet the general criteria of art. 37.1 RGPD or appear in the closed list of fifteen types of entity in art. 34.1 LOPDGDD. Most small businesses and self-employed people are in neither group.

Where can I consult the official text of the LOPDGDD?

In the Boletín Oficial del Estado, consolidated text: boe.es/buscar/act.php?id=BOE-A-2018-16673.


Want to see this applied to your business? Tranquilia turns these obligations into a questionnaire and the documents that apply to you, adapted to your sector. If you run an asesoría or a gestoría (Spanish practices handling tax, payroll and admin for other businesses), see the guide for asesorías and gestorías. The free tier lets you try it with up to 2 companies, with no card and no time limit, at tranquilia.es.

Article produced by Tranquilia by GRAC SA. Published on 16 July 2026. Last reviewed: 16 July 2026. AI-assisted writing with primary-source verification; it does not constitute individual legal advice.

Sources

Review: Tranquilia by GRAC SA — AI-assisted writing with primary-source verification. Translation of the Spanish original, which prevails in case of divergence.

Get your clients GDPR-compliant in 15 minutes.

Set up my free instance

No card, no sales calls. Two companies free, for as long as you like.

Blog