Law / Andorra

Andorra

12 of 13 named instruments researched to a stage, across five of the six areas of law we track: 11 in force and 1 proposed. As of 19 September 2026.

  1. AI law 1
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law 2
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 proposed

Research summary (85 words)

Andorra has no domestic AI-specific statute in force.

Its notable development is signing, on 5 September 2024, the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225), the first legally binding international treaty in this field; as of the Council of Europe Treaty Office's most recent count only the European Union among the treaty's signatories has ratified it, and Andorra has not, so the Convention does not yet bind an app operating in Andorra.

AI governance

Council of Europe Framework Convention on Artificial Intelligence, signed by Andorra

Council of Europe Framework Convention on Artificial Intelligence and Human Rights Democracy and the Rule of Law, Council of Europe Treaty Series No. 225, opened for signature 5 September 2024; signed by Andorra the same day, not yet ratifiedOfficial description of the Framework Convention on Artificial Intelligence and its scope

Proposed: draft date not recorded. Signed, with consent not yet expressed, dated 5 September 2024, as of 12 September 2026. Binds public and private bodies.

What this law does

This treaty has been signed by Andorra but not yet ratified or given effect in Andorran domestic law, so it does not currently bind an app operating in Andorra.

As drafted, it would require activities within the lifecycle of an artificial intelligence system to be consistent with human dignity, equality and non-discrimination, privacy, transparency, and accountability, including carrying out iterative risk and impact assessments on human rights, democracy, and the rule of law and establishing prevention and mitigation measures.

It covers the use of an AI system by a public authority, including a private actor acting on the authority's behalf, and by a private actor generally, and it would require giving notice that a person is interacting with an AI system rather than a human being, and providing an effective means to challenge a decision made through, or substantially based on, such a system.

Of the treaty's signatories, only the European Union had ratified it as of the Council of Europe Treaty Office's most recent count; Andorra remains a signatory without a ratification date.

What it requires

Privacy law6 instruments, 6 in force

Research summary (194 words)

Andorra has a comprehensive, General Data Protection Regulation (GDPR)-modelled data protection statute, the Llei Qualificada de Proteccio de Dades Personals (LQPD), Llei 29/2021 del 28 d'octubre, in force since 17 May 2022 under its own fourth final provision's six-month-after-publication rule, and amended by Llei 12/2024 and Llei 16/2024. Andorra also holds an EU adequacy decision (Commission Decision 2010/625/EU), retained in the Commission's January 2024 review of its legacy adequacy decisions.

Special categories of personal data, including biometric data used for unique identification, carry a heightened, necessity-based restriction reaching both public and private actors, and the statutory definition names facial images expressly, so an identifier derived from a photograph is squarely covered; the definition does not name voice specifically, and whether a voiceprint falls under its broader behavioural-characteristics language is not established by the law's own text.

Article 71 gives any person harmed by an infringement of this law a right to compensation from the controller or processor, with joint and several liability among every controller and processor involved in the same processing. The law's own sanctions regime, Article 73, sets three fixed euro fine tiers running from 500 to 100,000 euros by infringement severity, with no turnover-based tier.

Breach notification

LQPD, personal data breach notification

Llei 29/2021, arts. 36-37 (personal data breach notification)Consolidated statute text at portaljuridicandorra.ad

In force since 17 May 2022. Binds public and private bodies.

What this law does

Article 36(1) requires the controller, without undue delay and where possible within seventy-two hours of becoming aware of a personal data breach, to notify the Andorran Data Protection Agency of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Article 36(1) also requires a notification made after that seventy-two-hour period to justify the reasons for the delay.

Article 36(2) requires a processor to notify the controller without delay of any personal data breach it becomes aware of. Article 36(3) fixes what the Agency notification must contain at minimum, including the nature of the breach, the categories and approximate number of data subjects and personal data records concerned where possible, a contact point's name and details, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects.

Article 36(4) lets that information be given in phases without undue delay where it cannot all be given at once. Article 36(5) requires the controller to document every personal data breach, including its facts, effects and remedial measures, so the supervisory authority can verify compliance with the notification duty.

Article 37(1) requires the controller to communicate a personal data breach to the data subject without undue delay where the breach is likely to result in a high risk to the rights and freedoms of natural persons.

Article 37(3) excuses that communication where the controller had applied protective measures, such as encryption, that rendered the affected data unintelligible, where the controller has since eliminated the high risk, or where communication would take disproportionate effort and a public communication of equivalent effectiveness is made instead.

Article 37(4) still lets the Agency require the communication, or determine that one of the Article 37(3) conditions applies, where the controller has not itself communicated the breach to the data subject.

What it requires

Comprehensive regime

LQPD, Llei 29/2021 del 28 d'octubre

LQPD Llei 29/2021 del 28 d'octubre, arts. 1-2, 4-7, 11-14, 27-35, 38-41 (general provisions, lawful basis, controller and processor obligations, DPIA, the Data Protection Officer, and other general processing rules)Consolidated statute text at portaljuridicandorra.ad

In force since 17 May 2022. Binds public and private bodies.

What this law does

Llei 29/2021, del 28 d'octubre, qualificada de proteccio de dades personals (LQPD) is Andorra's general, General Data Protection Regulation (GDPR)-modelled data protection statute, consolidated to reflect amendments by Llei 12/2024 and Llei 16/2024.

Article 2(2) extends the law to a controller or processor not domiciled in Andorra or not constituted under Andorran law that uses processing means located in Andorran territory, automated or not, and requires such a controller or processor to designate a representative established in Andorra. Article 4 defines the terms the law uses, including personal data, consent, processing, profiling, controller, processor and personal data breach.

Article 5 sets the principles applicable to processing, covering lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, and integrity and confidentiality, and Article 6 lists the lawful bases for processing, led by the data subject's consent.

Articles 27 to 31 set the controller's and processor's obligations, covering accountability, data protection by design and by default, the representative duty Article 2 already states, a duty to block personal data on rectification or erasure pending any liability claims, and a processor's contractual obligations.

Article 34 requires a written record of processing activities, exempting a business or organisation with fewer than fifty workers unless the processing risks data subjects' rights, is not occasional, or involves special categories of data or criminal-offence data.

Article 32 requires a data protection impact assessment before high-risk processing, and Article 33 requires prior consultation with the Andorran Data Protection Agency where that assessment shows a high risk the controller has not mitigated. Article 35 requires appropriate technical and organisational security measures proportionate to the risk, and Articles 38 to 41 add a Data Protection Officer duty for public bodies and qualifying private controllers, and codes-of-conduct provisions.

Article 12 exempts processing for academic, artistic or literary expression, or professional journalistic activity, from several of the law's provisions, including the special-categories and criminal-offence-data rules and the whole cross-border transfer chapter, to the extent necessary to reconcile data protection with freedom of expression and information.

Article 14 presumes a legitimate-interest basis for processing the contact data of an individual entrepreneur's or professional's staff, limited to their professional capacity.

A separate future law, still to be presented under the LQPD's fourth final provision, will govern data processing for the prevention, investigation, detection or prosecution of criminal offences, following the model of Directive (EU) 2016/680, and until then Article 2(4)(c) excludes that processing from the LQPD's own scope.

The fourth final provision sets the law's entry into force at six months after its publication in the Official Bulletin of the Principality of Andorra, and the Andorran Data Protection Agency's own notice confirms that date as 17 May 2022.

What it requires

Cross border transfer

LQPD, transfers of personal data to third countries or international organisations

Llei 29/2021, arts. 42-45 (transfers of personal data to third countries or international organisations)Consolidated statute text at portaljuridicandorra.ad

In force since 17 May 2022. Binds public and private bodies.

What this law does

Article 42(1) bars international transfers of personal data where the destination country's or international organisation's rules do not establish a level of protection for personal data at least equivalent to this law's own. Article 43 treats a country, territory or sector the European Union has found adequate, or a state effectively subject to Council of Europe Convention 108+, as offering an adequate level of protection, and treats every European Union member state as offering one.

Article 44 lets a transfer proceed without an adequacy finding where appropriate safeguards exist and data subjects have enforceable rights and effective legal remedies, evidenced by a binding legal instrument between public authorities, binding corporate rules, standard data-protection clauses, a code of conduct with binding commitments, an approved certification mechanism with binding commitments, contractual clauses, or administrative arrangements with enforceable data-subject rights.

Article 44(2) directs the Andorran Data Protection Agency to weigh the rule of law and human rights record, relevant general and sectoral legislation including public-authority access to personal data, data protection and professional rules and security measures, case law, and effective administrative and judicial redress for data subjects, in assessing whether those safeguards are adequate.

Article 45(1) lets a transfer proceed without an adequacy finding or appropriate safeguards only under a listed derogation, including the data subject's informed explicit consent, contractual necessity, important public interest, legal claims, or vital interests.

Article 45(2) lets a transfer proceed on compelling legitimate interests where no adequacy finding, safeguard or Article 45(1) derogation applies, but only if it is not repetitive, affects a limited number of data subjects, and the controller has assessed the circumstances, offered adequate safeguards, and informed both the supervisory authority and the data subject.

Article 12 exempts processing for academic, artistic or literary expression, or professional journalistic activity, from this whole transfer chapter, to the extent necessary to reconcile data protection with freedom of expression and information.

What it requires

Data subject rights

LQPD, rights of the data subject

Llei 29/2021, arts. 15-26 (rights of the data subject)Consolidated statute text at portaljuridicandorra.ad

In force since 17 May 2022. Binds public and private bodies.

What this law does

Article 15 requires the controller to give the Article 16 and 17 information and handle an Article 18 to 25 request in a concise, transparent, intelligible and easily accessible form, free of charge and within one month of the request, extendable by two further months for complex or numerous requests.

Articles 16 and 17 set the information a controller must give a data subject, whether the data came from the subject or elsewhere, covering the controller's identity, the purposes and legal basis of processing, the recipients, any transfer to a third country, the storage period, and the data subject's rights. Article 18 gives a right of access to confirmation of processing, a copy of the personal data, and the accompanying information the article lists.

Article 19 gives a right to rectification of inaccurate personal data and completion of incomplete data. Article 20 gives a right to erasure, the right to be forgotten, on the listed grounds, including withdrawal of consent, unlawful processing, and collection under Article 8's information-society-service consent rule, and requires a controller whose data are accessed through a search engine to de-reference them.

Article 21 guarantees digital rights on the internet, including net neutrality, universal and non-discriminatory access, and the security of communications, and requires internet service providers to offer transparent service terms free of technical or economic discrimination.

Article 22 gives a right to restriction of processing where accuracy is contested, processing is unlawful, the controller no longer needs the data but the data subject does for legal claims, or an Article 24 objection is pending verification. Article 23 gives a right to data portability in a structured, commonly used and machine-readable format where processing rests on consent or a contract and is carried out by automated means.

Article 24(1) gives a right to object to processing the controller did not obtain directly from the data subject, for reasons related to their particular situation. Article 24(2) gives a separate, unconditional right to object to processing for direct marketing purposes, including related profiling.

Article 25 gives a right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning the data subject, subject to the listed exceptions and safeguards, and bars a minor from being subject to such a decision at all.

Article 26 lets these rights be restricted only by law, consistently with the essence of fundamental rights and freedoms, and only where necessary and proportionate to safeguard the listed public interests, including state security, defence, public safety, and the prevention, investigation, detection or prosecution of criminal offences.

What it requires

Enforcement supervision

LQPD, the Andorran Data Protection Agency, its powers, infractions and sanctions

Llei 29/2021, arts. 46-74 (the Andorran Data Protection Agency, its powers, infractions and sanctions)Consolidated statute text at portaljuridicandorra.ad

In force since 17 May 2022. Binds public and private bodies.

What this law does

Article 46 establishes the Andorran Data Protection Agency (APDA), created in 2003, as an independent public-law institution with its own legal personality, acting with full independence from Andorra's public administrations. Article 50bis places the Agency under a Head, designated by the Consell General by a two-thirds qualified majority, who exercises the Agency's legal and institutional representation independently and neutrally.

Article 61 gives a data subject the right to lodge a complaint with the Agency electronically or in person, and lets a representative body, organisation or non-profit association active in data-subject-rights protection lodge the complaint and pursue judicial remedies on the data subject's behalf.

Articles 62 and 63 give the Agency investigatory powers to demand information, conduct data-protection audits, access a controller's or processor's premises, equipment and processing means, and notify suspected infringements.

Article 65 splits the sanctioning procedure into an investigative phase run by the Agency's inspectors and a sanctioning phase decided by the Head of the Agency, and Article 69 requires the Head to notify the competent court and suspend the administrative procedure if signs of criminal conduct emerge during it.

Article 67 gives the Agency corrective powers, including a warning, a reprimand, an order to comply with a data subject's rights request, an order bringing processing into compliance, a temporary or definitive limitation or ban on processing, and an order suspending data flows to a third country or international organisation, cumulative with an administrative fine under Article 68.

Article 68 sets the criteria for an administrative fine, including the nature, gravity and duration of the infringement, intent or negligence, mitigating measures taken, the degree of cooperation with the Agency, and prior infringements, and caps the total fine for several infringements from the same conduct at the amount set for the most serious infringement.

Article 70 sets the limitation period for infringements at three years for very serious infringements, two years for serious infringements, and one year for minor infringements.

Article 71 gives any person who has suffered material or non-material damage from an infringement of this law the right to compensation from the controller or processor, holds every controller or processor involved in the same processing jointly and severally liable, and excuses one that proves it bears no responsibility for the damage.

Article 72 classifies infringements as very serious, serious or minor, with a very serious infringement including processing without a lawful basis, processing prohibited special categories of data without an Article 9 exception, and deliberately reversing an anonymisation process to re-identify a data subject.

Article 73 sanctions a very serious infringement with a fine of thirty thousand and one to one hundred thousand euros, a serious infringement with fifteen thousand and one to thirty thousand euros, and a minor infringement with five hundred to fifteen thousand euros, with no separate turnover-based tier. Article 74 limits the sanction against Andorra's general administration, the comuns, the Consell General, the judiciary and other listed public bodies to a reprimand rather than a fine.

What it requires

Sensitive categories

LQPD, special categories, children and criminal-offence data

Llei 29/2021, arts. 8-10 (special categories, children and criminal-offence data)Consolidated statute text at portaljuridicandorra.ad

In force since 17 May 2022. Binds public and private bodies.

What this law does

Article 9(1) prohibits processing personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union affiliation, and processing genetic data, biometric data for the purpose of uniquely identifying a natural person, health data, or data concerning sex life or sexual orientation.

Article 9(2) lifts that prohibition only under the listed circumstances, running from the data subject's explicit consent through employment and social security law, vital interests where the data subject is a person receiving support measures for exercising legal capacity, the legitimate activities of a non-profit body processing only its own members' data, data manifestly made public by the data subject, legal claims, essential public interest, preventive or occupational medicine, public health, and archiving, scientific, historical or statistical purposes.

Article 9(3) lets sectoral rules add requirements, conditions or limitations on the security and confidentiality of processing special categories of personal data. Article 4(17) defines biometric data as personal data obtained from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person that allow or confirm that person's unique identification, naming facial images, dactyloscopic data and iris patterns as examples.

Article 10 confines processing of personal data about criminal convictions and offences, or related security measures, to what is strictly necessary and authorised by law or supervised by public authorities with adequate safeguards, and keeps any comprehensive register of such data solely under the competent public authorities' control.

Article 8 sets the threshold for a minor's own consent to an information-society service at sixteen years, requiring a legal representative's consent or authorisation below that age and a controller's verification of that representative consent using available technology.

Whether a voiceprint falls inside Article 9's special-category restriction is not established by the law's own text: the biometric-data definition's core clause covers behavioural characteristics used for unique identification, but its illustrative examples name facial images, dactyloscopic data and iris patterns and do not name voice.

What it requires

Scraping law2 instruments, 2 in force

Research summary (248 words)

Andorra has no scraping-specific statute, so general law governs each dimension separately. The qualified Penal Code criminalizes unauthorized access to an information system, but article 225 requires defeating a security measure, so reading a public, unauthenticated page without circumventing an access control falls outside a plain reading of the offence, and no reported case has tested the point.

No Andorran court decision on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper was located.

The Law on Copyright and Neighboring Rights protects a collection of works or of mere data, including a database, only where the selection or arrangement of its contents is original, so Andorra has no sui generis database right; the same Law lets a lawful user access and make normal use of a database's contents without the rightholder's authorization, and this cannot be excluded by contract, but it predates the concept of a text-and-data-mining exception, so no such exception or machine-readable opt-out exists and no case law addresses whether bulk collection for model training fits the lawful-user exception.

The Qualified Personal Data Protection Law (LQPD, researched separately under the privacy topic) applies to personal data generally, without a blanket carve-out for information a person has made publicly available, so scraping personal data from a public Andorran website remains subject to its lawful-basis and cross-border-transfer duties.

No Andorran statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Penal Code, Attacks on Information Systems

Codi penal, Llei 9/2005, del 21 de febrer, qualificada del Codi penal, as consolidated, art. 225 (Atacs contra els sistemes d'informació)Consolidated Catalan text of the qualified Penal Code

In force. Binds public and private bodies.

What this law does

Article 225 of the qualified Penal Code punishes with imprisonment from three months to three years whoever, by any means, intentionally and without authorization, accesses all or part of an information system in violation of at least one security measure, when the result is serious; the same range of imprisonment applies to intentionally and without authorization obstructing or interrupting the operation of a network or information system, deleting, damaging, or altering data within an information system, intercepting non-public data transmissions, and producing, selling, or distributing hacking tools or access codes for those purposes.

Imprisonment of three to six years plus a fine of up to four times the damage caused applies where the conduct is committed by an organized group, causes especially serious damage, seriously harms an essential public service or critical infrastructure, or creates a serious danger to State security. Each paragraph requires defeating a security measure or acting without authorization, so reading a public, unauthenticated page does not fit a plain reading of the article.

The consolidated text carries no per-article amendment date, and its reference to essential services and critical infrastructure reflects a later revision of the article than the Code's original 2005 enactment, so no single commencement date for the article as currently worded is stated on the page.

What it requires

Database right

Copyright and Neighboring Rights Law, Database and Collection Protection

Llei sobre drets d'autor i drets veïns (Law on Copyright and Neighboring Rights) approved 10 June 1999, arts. 3-4, 14 (Derivative Works and Collections; Subject Matter Not Protected; Free Use of Data Bases)English translation of the Law on Copyright and Neighboring Rights

In force since 7 July 1999. Binds public and private bodies.

What this law does

Article 3(1)(b) protects a collection of works or of mere data, including a database in machine-readable form, as a copyright work only where the selection or arrangement of its contents is original; Andorra has no separate sui generis database right, so a non-original compilation of facts receives no protection under this Law.

Article 4(1) excludes mere data, and any idea, procedure, system, method of operation, concept, principle, or discovery, from copyright protection regardless of the work in which it is expressed, and article 4(2) excludes official legislative, administrative, or judicial texts.

Article 14 lets a lawful user of a database access its contents and make normal use of them, for whichever acts under article 5(1) that use requires, without the rightholder's authorization, and this exception cannot be excluded by contract. This Law predates the concept of a machine-readable text-and-data-mining reservation, so no copyright exception or opt-out mechanism written for that purpose exists.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (341 words)

Andorra enacted Llei 22/2022, del 9 de juny, de mesures per a la seguretat de les xarxes i dels sistemes d'informació (the Law of 9 June 2022 on Measures for the Security of Networks and Information Systems), a standalone cybersecurity statute that binds an operator by sector and size rather than by whether it holds personal data.

Andorra is not an EU member, so this Law is Andorra's own instrument rather than a transposition of the EU's NIS framework, though it follows that framework's shape closely: essential and important entities identified by two annexes, a national CSIRT, a competent-authority structure, and an incident-notification clock.

The Law establishes the Agència Nacional de Ciberseguretat del Principat d'Andorra (ANC-AD) as the national cybersecurity agency and CSIRT-AD as the national incident-response team, and designates the Autoritat Financera Andorrana (AFA) as the competent authority, coordinating with ANC-AD, for the banking and financial-market-infrastructure sectors.

AFA has issued its own technical communiqués operationalising the Law for the financial entities it supervises, including a 2023 self-assessment of network and information-system security (Comunicat tècnic 8/2023-SF) and a 2024 communiqué on the Information Security Delegate's communication channel (Comunicat tècnic 1/2024-SF); these are sector-specific implementing guidance under the Law rather than a separate regime, and are not filed as their own instruments here because the role they bind, a supervised financial entity, is not one this topic's activity vocabulary can express on its own.

The Law's implementing decrees, Decret 417/2022 approving the National Security Scheme (Esquema Nacional de Seguretat) and Decret 418/2022 approving the critical-infrastructure regulation, both amended in 2024 alongside a 2024 decree updating the Annex I and Annex II service lists, fill in technical detail under the same Law and are described here rather than filed as separate rows.

Andorra's Penal Code offence for unauthorised access to information systems (Llei 9/2005, as amended 2010) binds the intruder rather than the operator and is filed under the scraping topic, and the LQPD's (Llei 29/2021) own General Data Protection Regulation (GDPR)-Article-32-shaped security-of-processing duty and breach-notification duty are filed under the privacy topic; neither is repeated here.

Sector security regimes

Llei 22/2022, Cybersecurity Risk-Management Obligations

Llei 22/2022, del 9 de juny, arts. 12, 13, 17 i 18Consolidated statute text, portaljuridicandorra.ad, the official legal portal of the Principality of Andorra

In force since 23 June 2022. Binds public and private bodies.

What this law does

Llei 22/2022, del 9 de juny, de mesures per a la seguretat de les xarxes i dels sistemes d'informació (the Law of 9 June 2022 on Measures for the Security of Networks and Information Systems) applies to essential and important entities, defined by its Annex I and Annex II sector lists, that employ 50 or more people or whose annual turnover or annual balance sheet total exceeds ten million euros.

Article 13 requires these entities to adopt technical and organisational measures proportionate to the cybersecurity risks facing the networks and information systems they use to provide their services, in order to achieve a high level of resilience, covering at minimum a security policy for their critical infrastructure and information systems, a risk-management policy, incident management, business continuity and crisis management, supply-chain security, security in the acquisition, development and maintenance of systems, testing and audit procedures, and the use of cryptography and encryption.

Annex II names digital service providers, specifically providers of online marketplaces, online search engines and social networking services platforms, among the important entities this duty reaches, and Annex I separately reaches the banking and financial-market-infrastructure sectors and public administration entities of the Andorran government.

Each essential or important entity must also designate an Information Security Delegate (Delegat de la Seguretat de la Informació, DSI), a natural person, a unit or a collegiate body, as the point of contact and technical coordination between the entity and the competent national authority and CSIRT-AD.

What it requires

Vulnerability and incident reporting

Llei 22/2022, Incident Handling and Notification Obligation

Llei 22/2022, del 9 de juny, arts. 14 i 15Consolidated statute text, portaljuridicandorra.ad, the official legal portal of the Principality of Andorra

In force since 23 June 2022. Binds public and private bodies.

What this law does

Article 14 of Llei 22/2022, del 9 de juny, de mesures per a la seguretat de les xarxes i dels sistemes d'informació requires an essential or important entity to manage and resolve any security incident affecting the critical infrastructure, networks or information systems it uses to provide its essential or important service, including by ensuring that an external provider of those infrastructures, networks or systems applies the necessary security measures.

Article 15 requires the entity to notify the CSIRT-AD, without delay and in any event within seventy-two hours of detection, of any incident that has or may have significant effects on that service, together with any information letting the competent authority or CSIRT-AD determine the incident's cross-border effects.

Where the entity cannot yet establish that effect at the time of notifying, it may omit that information, provided it sends the CSIRT-AD a justificatory report within seventy-two hours of the notification explaining why. Where appropriate, the entity must also notify, without undue delay, the recipients of its services whom the incident may affect, together with the measures or remedies they can take in response.

A repeated failure to notify a significantly disruptive incident under Article 15, from the second such failure, and a failure to resolve an incident under Article 14 that has a significant disruptive effect on an essential or important service in Andorra or abroad, are each classified as a very serious violation.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (195 words)

Andorra has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, no recognized hot-news misappropriation doctrine distinct from ordinary copyright law, and no located statute or case law addressing hyperlinking or framing liability specifically; each of those dimensions is a sourced absence rather than an unresolved question.

The relevant instrument is the Law on Copyright and Neighboring Rights (Llei sobre drets d'autor i drets veïns), approved by the General Council on 10 June 1999 and in force from its 7 July 1999 publication, which excludes mere facts and data and official legislative, administrative, and judicial texts from copyright protection outright (art. 4), and which lets a newspaper or periodical reproduce, without the author's authorization, a published article on current economic, political, or religious topics, a short excerpt of a work seen or heard during a current event, or a public political speech, provided the source and author are credited (art. 11); no reported Andorran decision applies that exception to a systematic aggregator's reproduction of headlines and snippets, as opposed to a single newspaper's press coverage, and the Law predates the concept of a machine-readable text-and-data-mining reservation entirely, so no opt-out mechanism of that kind exists.

Snippet reproduction

Copyright and Neighboring Rights Law, Press and Current-Events Reproduction Exception

Llei sobre drets d'autor i drets veïns (Law on Copyright and Neighboring Rights) approved 10 June 1999, art. 11 (Free Use for Informatory Purposes)English translation of the Law on Copyright and Neighboring Rights

In force since 7 July 1999. Binds public and private bodies.

What this law does

Article 11 permits a newspaper or periodical, without the copyright owner's authorization, to reproduce, broadcast, or otherwise communicate to the public a published newspaper or periodical article, or a broadcast work of the same character, on current economic, political, or religious topics, provided the source and, as far as practicable, the author's name are indicated; this permission does not apply where the author has expressly reserved the right to authorize such reproduction.

The same article separately permits reproducing short excerpts of a work seen or heard during a current event, for the purpose of reporting that event and to the extent justified by that purpose, and permits a newspaper or periodical to reproduce a political speech, lecture, address, or similar work delivered in public. The exception carries no headline-length or short-extract cap distinct from the extent-justified-by-purpose test.

Article 4 separately excludes mere facts and data, and any official legislative, administrative, or judicial text, from copyright protection outright, so a bare fact or news item is never a protected work regardless of who reports it first.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.