Law / Spain

GDPR Articles 33-34 and LOPDGDD Article 69, Breach Notification

Regulation (EU) 2016/679, Arts. 33-34; LOPDGDD, Art. 69, Art. 73(r)-(s)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 25 May 2018, effective 7 December 2018.

A breach notification rule binding public and private bodies.

As of 24 August 2026.

What it requires

  • Notify the AEPD within 72 hours of becoming aware of a personal-data breach affecting a person in Spain, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A controller must notify the AEPD within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk.

LOPDGDD Article 69 gives the AEPD its own provisional-measures power, including a cautionary data block tied specifically to international-transfer risk (Art. 69.2), and Titulo IX makes late, incomplete, or missing breach notification its own separate administrative infraction (Art. 73(r)-(s)), confirmed against Titulo IX's own text rather than inferring it from General Data Protection Regulation (GDPR) alone.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • processes_voice

Read the law

GDPR Arts. 33-34
LOPDGDD Art. 69, Art. 73(r)-(s)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app