GDPR Articles 33-34 and LOPDGDD Article 69, Breach Notification
Regulation (EU) 2016/679, Arts. 33-34; LOPDGDD, Art. 69, Art. 73(r)-(s)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 25 May 2018, effective 7 December 2018.
A breach notification rule binding public and private bodies.
As of 24 August 2026.
What it requires
- Notify the AEPD within 72 hours of becoming aware of a personal-data breach affecting a person in Spain, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A controller must notify the AEPD within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk.
LOPDGDD Article 69 gives the AEPD its own provisional-measures power, including a cautionary data block tied specifically to international-transfer risk (Art. 69.2), and Titulo IX makes late, incomplete, or missing breach notification its own separate administrative infraction (Art. 73(r)-(s)), confirmed against Titulo IX's own text rather than inferring it from General Data Protection Regulation (GDPR) alone.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometricsprocesses_voice
Read the law
GDPR Arts. 33-34
LOPDGDD Art. 69, Art. 73(r)-(s)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.