Ley Orgánica 3/2018 (LOPDGDD), GDPR-Aligned Comprehensive Regime
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 7 December 2018.
A comprehensive regime rule binding public and private bodies.
As of 24 August 2026.
What it requires
- Establish a General Data Protection Regulation (GDPR) Article 6 lawful basis before processing personal data of a person in Spain, and rely on a statute-rank Spanish or EU norm rather than mere regulation if the basis is public interest or legal obligation, per LOPDGDD Article 8.
- Follow LOPDGDD Titulo V's controller and processor obligations, including its DPO qualification rule at Article 35.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Spain gives the General Data Protection Regulation (GDPR) domestic effect through the Ley Organica 3/2018 (LOPDGDD, Organic Law on the Protection of Personal Data and the Guarantee of Digital Rights), in force since 7 December 2018.
Unlike a bare implementing act, the LOPDGDD carries substantial national additions, confirmed against the BOE text: a freestanding Titulo X on digital rights (Arts. 79-97), a Titulo VI chapter on international transfers (Arts. 40-43) layered on GDPR Chapter V, and a Titulo IX administrative sanctioning regime (Arts. 70-78) calibrated onto GDPR Article 83's fine tiers.
Article 8, read verbatim, tightens rather than loosens GDPR's public-interest and legal-obligation bases: such processing is valid only where a Union-law norm or a Spanish statute-rank norm so provides.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.