LOPDP, comprehensive personal-data protection regime
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 26 May 2021.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Do not process personal data without a lawful basis under the Act, and obtain explicit consent before processing a sensitive category of data unless another enumerated ground applies.
- Secure personal data with the technical and organisational measures articles 37 to 41 require, determined from a risk, threat and vulnerability analysis, and build data protection into the design of your processing and make it the default.
- Carry out an impact assessment of the processing where article 42 requires one.
- Designate a data protection delegate where the law requires one, and let the delegate carry out the functions article 49 sets.
- Register with the national register of personal data protection as article 51 requires.
What it reaches
Obligation class
Consent, Security, DPIA, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 2 applies the law to the processing of personal data in any medium, automated or not, by any public or private controller or processor, with narrow exclusions for purely personal or household use and for the personal data of deceased persons, and article 3 sets its territorial reach. Article 7 makes processing legitimate only on one of the grounds it lists, article 8 governs consent and article 9 legitimate interest. Article 10 carries the principles.
Articles 33 to 36 govern the transfer or communication of personal data to another controller, access by a processor and access by third parties, and the exceptions to consent for those. Article 37 requires the controller or processor to secure personal data, article 39 requires data protection by design and by default, article 40 a risk, threat and vulnerability analysis, article 41 the determination of the applicable security measures and article 42 an impact assessment.
Article 47 lists the obligations of the controller and processor, articles 48 to 50 the designation, functions and special position of the data protection delegate, article 51 the national register, and articles 52 to 54 self-regulation, codes of conduct and certification entities. The law was published in Registro Oficial Suplemento 459 of 26 May 2021 and is recorded there as in force, which is the day these provisions began to bind.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.