Law / Spain

Spain

European Union law applies in Spain Spain is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of Spain, described on this page below, applies here too.

24 of 32 named instruments researched to a stage, across all six areas of law we track: 17 in force, 6 proposed and 1 repealed, withdrawn or blocked. As of 12 September 2026.

When they take effect18 of 24 carry a date, 6 do not. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 0 instruments 2015: 2 instruments (1 in force, 1 repealed, withdrawn or blocked) ’15 2016: 0 instruments 2017: 0 instruments 2018: 9 instruments (9 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 6 instruments (6 in force) 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 2
  2. Privacy law 6
  3. Scraping law 3
  4. Cybersecurity law 4
  5. Age gating law 5
  6. News aggregation law 4

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 1 in force, 1 proposed

Research summary (176 words)

The EU AI Act (Regulation (EU) 2024/1689) applies directly in Spain and is not restated here as Spanish law; its Article 50 transparency and output-labeling duties took direct effect on 2 August 2026. Spain has two of its own instruments layered on that baseline.

Since 2021, Article 64.4.d) of the Estatuto de los Trabajadores, added by Ley 12/2021, gives a company's works council the right to be informed of the parameters, rules, and instructions behind an algorithm or AI system that affects decisions on working conditions or employment, including profiling.

As of September 2026 the Proyecto de Ley Organica para el buen uso y la gobernanza de la inteligencia artificial (121/000096), a Government bill sent to Congress on 12 June 2026 and still in committee, would create Spain's own infringement classification and penalty scale for a deployer that fails to disclose AI-generated or manipulated content under EU AI Act Article 50.4, and would confirm the Agencia Espanola de Supervision de la Inteligencia Artificial (AESIA) as the national point of contact. That bill is not yet law.

AI sector rules

Estatuto de los Trabajadores Article 64.4.d), Algorithmic Management Works Council Information Right

Ley 12/2021 de 28 de septiembre, articulo unico.Uno, inserting art. 64.4.d) into the Texto Refundido de la Ley del Estatuto de los Trabajadores (Real Decreto Legislativo 2/2015) (BOE-A-2021-15767)BOE, consolidated text of Ley 12/2021

In force since 30 September 2021. Binds private bodies.

What this law does

A works council has the right to be informed by the company of the parameters, rules, and instructions on which an algorithm or artificial intelligence system that affects decisions on working conditions, access to employment, or continued employment is based, including profiling, per new Article 64.4.d) of the Estatuto de los Trabajadores.

The obligation was introduced by Ley 12/2021, which formally replaced the earlier Real Decreto-ley 9/2021 (the so-called Ley Rider) after parliamentary processing, carrying the same substantive text forward.

What it requires

AI transparency

Proyecto de Ley Orgánica IA, National Enforcement of AI Act Content-Labeling Duties

Proyecto de Ley Organica para el buen uso y la gobernanza de la inteligencia artificial expte. 121/000096, arts. 21.1.b) and 30, BOCG Congreso Serie A Num. 97-1, 12 de junio de 2026Boletin Oficial de las Cortes Generales, Congreso de los Diputados, Serie A, Proyectos de Ley

Proposed: draft date not recorded. In committee, dated 12 June 2026, as of 12 September 2026. Binds public and private bodies.

What this law does

Not yet in force. As introduced, a deployer's failure to comply with EU AI Act Article 50.4, the duty to make public the artificial nature of output from a system that generates or manipulates image, audio, or video content amounting to a deepfake, or that generates or manipulates text meant to inform the public on matters of public interest, would be classed as a serious infringement under Article 21.1.b) of the bill.

A serious infringement carries a penalty of up to 7,500,000 euros or, for a business, up to 1 percent of total worldwide annual turnover for the prior financial year if that is higher, per Article 30.1.c). The bill would also confirm AESIA as Spain's single point of contact under the EU AI Act.

What it requires

Privacy law6 instruments, 6 in force

Research summary (105 words)

Spain's private-sector personal-data regime is the General Data Protection Regulation (GDPR) as given domestic effect by the Ley Organica 3/2018 (LOPDGDD, Organic Law on the Protection of Personal Data and the Guarantee of Digital Rights). Unlike a bare transposition, the LOPDGDD carries substantial national additions: a freestanding Titulo X of digital rights with no GDPR counterpart, a national international-transfer procedure layered on GDPR Chapter V, and an infraction taxonomy calibrated onto GDPR Article 83.

The AEPD is an unusually active biometrics regulator, evidenced by a EUR 2.52 million enforcement action against a retail facial-recognition deployment and its own guidance concluding no current Spanish statute authorizes biometric employee time-and-attendance systems.

Breach notification

GDPR Articles 33-34 and LOPDGDD Article 69, Breach Notification

Regulation (EU) 2016/679, Arts. 33-34; LOPDGDD, Art. 69, Art. 73(r)-(s)GDPR Arts. 33-34

In force since 25 May 2018, effective 7 December 2018. Binds public and private bodies.

What this law does

A controller must notify the AEPD within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk.

LOPDGDD Article 69 gives the AEPD its own provisional-measures power, including a cautionary data block tied specifically to international-transfer risk (Art. 69.2), and Titulo IX makes late, incomplete, or missing breach notification its own separate administrative infraction (Art. 73(r)-(s)), confirmed against Titulo IX's own text rather than inferring it from General Data Protection Regulation (GDPR) alone.

What it requires

Comprehensive regime

Ley Orgánica 3/2018 (LOPDGDD), GDPR-Aligned Comprehensive Regime

Ley Organica 3/2018, de 5 de diciembre, de Proteccion de Datos Personales y garantia de los derechos digitales (BOE-A-2018-16673)BOE, consolidated text

In force since 7 December 2018. Binds public and private bodies.

What this law does

Spain gives the General Data Protection Regulation (GDPR) domestic effect through the Ley Organica 3/2018 (LOPDGDD, Organic Law on the Protection of Personal Data and the Guarantee of Digital Rights), in force since 7 December 2018.

Unlike a bare implementing act, the LOPDGDD carries substantial national additions, confirmed against the BOE text: a freestanding Titulo X on digital rights (Arts. 79-97), a Titulo VI chapter on international transfers (Arts. 40-43) layered on GDPR Chapter V, and a Titulo IX administrative sanctioning regime (Arts. 70-78) calibrated onto GDPR Article 83's fine tiers.

Article 8, read verbatim, tightens rather than loosens GDPR's public-interest and legal-obligation bases: such processing is valid only where a Union-law norm or a Spanish statute-rank norm so provides.

What it requires

Cross border transfer

LOPDGDD Título VI, International Transfers, Layered on GDPR Chapter V

Regulation (EU) 2016/679, Arts. 44-49, 83(5); LOPDGDD, Arts. 40-43, 72.1(l)GDPR Arts. 44-49, 83(5)

In force since 25 May 2018, effective 7 December 2018. Binds public and private bodies.

What this law does

A transfer of personal data outside the EEA requires an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. LOPDGDD Titulo VI (Arts. 40-43), confirmed against the article headings, adds a national administrative-procedure layer: cases the AEPD may itself authorize, cases requiring AEPD prior authorization, and cases requiring prior notice to the competent authority.

LOPDGDD Article 72.1(l) separately makes an unauthorized international transfer its own "muy grave" national infraction category.

What it requires

Data subject rights

LOPDGDD Título III and Título X, Data-Subject and Digital Rights

LOPDGDD, Arts. 11-18, 93-96BOE, consolidated text, LOPDGDD Arts. 11-18, 93-96

In force since 7 December 2018. Binds public and private bodies.

What this law does

LOPDGDD Titulo III (Arts. 11-18) mirrors General Data Protection Regulation (GDPR) Articles 12-22 domestically: transparency, access, rectification, erasure, restriction, portability, and objection.

Titulo X then layers freestanding rights with no GDPR counterpart, confirmed against the article titles: Article 93's right to be forgotten against internet search engines, Article 94's equivalent against social-network services, Article 95's social-network portability right, and Article 96's right to a digital will governing a deceased person's digital accounts.

What it requires

Enforcement supervision

AEPD Enforcement, GDPR Article 82 and LOPDGDD Título IX

Regulation (EU) 2016/679, Arts. 82-83; LOPDGDD, Art. 47, Arts. 70-78GDPR Arts. 82-83

In force since 25 May 2018, effective 7 December 2018. Binds public and private bodies.

What this law does

The AEPD is Spain's supervisory authority; LOPDGDD Titulo IX (Arts. 70-78) sorts infractions into muy graves, graves, and leves, each defined by direct cross-reference to a General Data Protection Regulation (GDPR) Article 83 tier rather than an independent Spanish fine scale, confirmed against the text. GDPR Article 82 arms an individual with a direct private right of action.

The specific Spanish instrument transposing the EU Representative Actions Directive for collective data-protection claims is not confirmed; LOPDGDD's own Disposicion final septima only modifies a narrow amicus provision, not a class-action mechanism.

What it requires

Sensitive categories

GDPR Article 9 and AEPD Biometric Guidance, Special Categories

Regulation (EU) 2016/679, Art. 9; LOPDGDD, Art. 9AEPD, "Guia sobre tratamientos de control de presencia mediante sistemas biometricos" (Nov. 2023)

In force since 7 December 2018. Binds public and private bodies.

What this law does

LOPDGDD Article 9 supplies no independent biometric definition; it operates entirely within General Data Protection Regulation (GDPR) Article 9's special-category frame.

The AEPD's November 2023 guide on biometric presence-control systems (itself marked "en revision", under review, so treated as the AEPD's current stated position rather than a settled rule), concludes that current Spanish law contains no sufficiently specific statutory authorization for biometric employee time-and-attendance processing, applying the Tribunal Constitucional's STC 76/2019 reserva-de-ley standard.

The AEPD fined Mercadona EUR 2,520,000 (Resolucion PS/00120/2021) for a facial-recognition system matching shoppers against people with criminal convictions or restraining orders, holding the processing categorically prohibited under Article 9.1 with no Article 9.2 exception available.

What it requires

Scraping law3 instruments, 3 in force

Research summary (223 words)

Spain's computer-misuse crime, Codigo Penal Article 197 bis, requires breaching a security measure before an access becomes criminal, so crawling a public, unauthenticated page carries no criminal exposure under this article: there is no security measure to circumvent.

The Texto Refundido de la Ley de Propiedad Intelectual (TRLPI) gives a database maker a sui generis right against substantial extraction or reuse at Articles 133 to 137, running for 15 years from completion, with statutory exceptions for private, non-electronic use and for teaching or scientific research.

Real Decreto-ley 24/2021's own Fourth Book creates a text-and-data-mining exception for lawfully accessible works at Article 67, defeated by an express rightsholder opt-out for general use but not for research organizations and cultural-heritage institutions.

No Spanish statute or reported decision was located establishing whether a browsewrap or clickwrap terms-of-service restriction against scraping is enforceable as a matter of contract law, so that dimension is unsettled rather than governed by a specific regime; ordinary contract-formation rules in the Codigo Civil would apply.

General Data Protection Regulation (GDPR) and the Ley Organica 3/2018 (LOPDGDD), already the subject of a separate landed privacy-topic document for this jurisdiction, extend fully to personal data an operator scrapes from a public page: Spain records no publicly-available-data exemption from the general lawful-basis requirement. No Spain-specific robots.txt legal-weight statute or AI-training-specific crawling rule was located outside the text and data mining (TDM) exception itself.

Computer misuse

Código Penal Article 197 bis, Unauthorized Access to an Information System

Ley Organica 10/1995 de 23 de noviembre, del Codigo Penal, art. 197 bis, added by Ley Organica 1/2015, de 30 de marzo, art. unico.107 (BOE-A-1995-25444, BOE-A-2015-3439)BOE, consolidated text of the Codigo Penal

In force since 1 July 2015. Binds public and private bodies.

What this law does

Accessing or facilitating access to all or part of an information system, or remaining in it against the will of whoever has the legitimate right to exclude the actor, is a crime carrying six months to two years' imprisonment, but only where the actor breaches security measures established to prevent that access and lacks due authorization.

Intercepting non-public data transmissions to, from, or within an information system by technical means, without authorization, carries a separate penalty of three months to two years' imprisonment or a fine. Because the offense in the first paragraph requires vulnerating an established security measure, accessing a page with no access control in place, the ordinary case of public-web crawling, does not fall within Article 197 bis on the text of the article alone.

What it requires

Copyright and text and data mining (TDM)

RDL 24/2021 Article 67, Text and Data Mining Exception

Real Decreto-ley 24/2021, de 2 de noviembre, Libro Cuarto, Titulo II, art. 67 (Mineria de textos y datos) (BOE-A-2021-17910)BOE, consolidated text of Real Decreto-ley 24/2021

In force since 4 November 2021. Binds public and private bodies.

What this law does

No authorization from an intellectual-property rights holder is needed for reproductions of legitimately accessible works made for text and data mining purposes, per Article 67(1). That exception does not apply where rights holders have expressly reserved the use of their works through machine-readable means or other adequate means, per Article 67(3), an opt-out a crawler must honor to keep the general exception available.

A separate, unconditional exception in Article 67(4) covers research organizations and cultural-heritage institutions carrying out text and data mining for scientific research, without the opt-out that limits the general exception.

What it requires

Database right

TRLPI Articles 133 to 137, Sui Generis Database Right

Real Decreto Legislativo 1/1996 (TRLPI), arts. 133-137, added by Ley 5/1998, de 6 de marzo (BOE-A-1996-8930, BOE-A-1998-5568)BOE, consolidated text of the Texto Refundido de la Ley de Propiedad Intelectual

In force since 1 April 1998. Binds public and private bodies.

What this law does

A database maker who shows a substantial investment, evaluated qualitatively or quantitatively, in obtaining, verifying, or presenting its content may prohibit the extraction or reuse of the whole or a substantial part of that content, per Article 133.1. The right runs for 15 years from completion of the database, or from first making it available to the public if that happens before the term expires, per Article 136.

A legitimate user may extract or reuse a substantial part without authorization for private, non-electronic use, or for illustrative teaching or scientific-research purposes within the limits justified by the non-commercial aim and citing the source, per Article 135.1.

What it requires

Cybersecurity law4 instruments, 2 in force, 2 proposed

Research summary (442 words)

Spain's NIS2 transposition remains at the executive-approval stage.

The Consejo de Ministros approved the Anteproyecto de Ley de Coordinacion y Gobernanza de la Ciberseguridad in its first round on 14 January 2025 and ordered urgent processing so a second-round approval and formal remission to the Cortes Generales as a Proyecto de Ley can follow; as of September 2026 no second-round approval or Boletin Oficial de las Cortes Generales entry was located, Spain notified the text to the European Commission under the technical-regulations procedure on 21 February 2025, and the Commission sent Spain a reasoned opinion in May 2025 over the overdue transposition of Directive (EU) 2022/2555.

Pending enactment, Real Decreto-ley 12/2018, de 7 de septiembre (transposing the original NIS Directive, Directive (EU) 2016/1148) and its implementing Real Decreto 43/2021, de 26 de enero, remain in full force: they require an operator of essential services and a digital service provider (an online marketplace, online search engine or cloud computing service, with a micro- or small-enterprise exemption for the latter) to adopt proportionate security measures for their networks and information systems and to notify a significant incident to the competent authority through a CSIRT, on a severity-tiered clock that Real Decreto 43/2021's own national incident-notification instruction sets out (an interim notification within 24 to 48 hours and a final report within 20 days for a CRITICAL-severity incident, 72 hours and 40 days for a VERY HIGH-severity incident), rather than the fixed 24-hour and 72-hour clock Directive (EU) 2022/2555 itself sets.

No Spanish instrument imposes a product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here.

The Esquema Nacional de Seguridad (Real Decreto 311/2022) binds the public sector in full and extends to a private-sector entity only when, under a contractual relationship, it provides services to a public-sector entity for that entity's own exercise of its competencies; it does not impose a general private-sector duty and is a Government Accountability matter rather than a finding for this topic.

Both the still-enforced 2018 regime and the pending Anteproyecto bind a wider class of essential and important entity by sector and designation that no activity in this vocabulary expresses; only the digital-provider slice of that class (an online marketplace, online search engine or cloud computing service) is flagged here, and the broader sector classes are recorded as law the lint does not yet reach rather than flagged on a guess.

Spain's breach-notification duty for personal data, General Data Protection Regulation (GDPR) Articles 33 and 34 read with Ley Organica 3/2018 (LOPDGDD) Article 69, sits in the privacy topic and is not restated here.

Sector security regimes

Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad, Cybersecurity Risk-Management Measures

Anteproyecto de Ley de Coordinacion y Gobernanza de la Ciberseguridad text approved by the Consejo de Ministros on 14 January 2025 (transposing Directive (EU) 2022/2555)Anteproyecto de Ley (draft bill text)

Proposed: draft date not recorded. Approved by the executive for transmission to the legislature, dated 14 January 2025, as of 12 September 2026. Binds public and private bodies.

What this law does

The Anteproyecto, jointly proposed by the Interior, Defence and Digital Transformation ministries, would require an entity classified as essential or important under the future Act's sector list to carry out an individualised risk assessment and put in place technical, operational and organisational measures to secure the networks and information systems it uses and to prevent or minimise the impact of an incident, transposing NIS2 Article 21.

It would create the figure of the responsable de la seguridad de la informacion (information security officer) as the entity's point of contact and technical coordinator, with an accredited-personnel requirement for an essential entity's officer, and would create a single national competent authority, the Centro Nacional de Ciberseguridad attached to the Presidency of Government, alongside sector control authorities at the Interior, Defence and Digital Transformation ministries.

This duty does not yet bind: the Consejo de Ministros approved only the Anteproyecto's first round on 14 January 2025 and ordered urgent processing for a second round and parliamentary debate to follow, and no later approval or introduction as a Proyecto de Ley before the Cortes Generales was located as of September 2026.

What it requires

Real Decreto-ley 12/2018, Security Obligations for Operators of Essential Services and Digital Service Providers

Real Decreto-ley 12/2018 de 7 de septiembre, de seguridad de las redes y sistemas de informacion, art. 16, developed by Real Decreto 43/2021, de 26 de eneroBOE, consolidated text (ELI address), Real Decreto-ley 12/2018

In force since 9 September 2018. Binds public and private bodies.

What this law does

Article 16 requires an operator of essential services (an undertaking designated in the energy, transport, banking, financial-market-infrastructure, health, drinking-water or digital-infrastructure sectors under Ley 8/2011's critical-infrastructure regime) and a digital service provider under this Real Decreto-ley to adopt technical and organisational measures, proportionate to the risk, to manage the risks to the networks and information systems used to provide the service, even where that management is outsourced.

A digital service provider must additionally address, at minimum, the security of its systems and facilities, incident management, business-continuity management, monitoring, auditing and testing, and compliance with international standards.

Real Decreto 43/2021 develops this duty: an operator of essential services must designate a responsable de la seguridad de la informacion within three months of its designation and file a Declaracion de Aplicabilidad of the security measures it applies with the competent authority within six months, reviewed at least every three years.

This transposes the original NIS Directive (Directive (EU) 2016/1148) and, according to the Departamento de Seguridad Nacional, remains in full effect and covers the most critical operators within the State pending the NIS2 transposition described on this jurisdiction's Anteproyecto rows.

What it requires

Vulnerability and incident reporting

Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad, Incident Reporting Obligations

Anteproyecto de Ley de Coordinacion y Gobernanza de la Ciberseguridad text approved by the Consejo de Ministros on 14 January 2025 (transposing Directive (EU) 2022/2555)Anteproyecto de Ley (draft bill text)

Proposed: draft date not recorded. Approved by the executive for transmission to the legislature, dated 14 January 2025, as of 12 September 2026. Binds public and private bodies.

What this law does

The Anteproyecto would require an essential or important entity to notify a significant incident affecting the provision of its service, on its own networks or a third party's, to the competent authority, and to communicate to the recipients of its service, as soon as possible, a significant cyberthreat that could affect them along with any mitigating measures available to them, mirroring NIS2 Article 23.

The information security officer the Anteproyecto would create manages an entity's cybersecurity incidents as one of its named functions. This duty does not yet bind: the Consejo de Ministros approved only the Anteproyecto's first round on 14 January 2025 and ordered urgent processing for a second round and parliamentary debate to follow, and no later approval or introduction as a Proyecto de Ley before the Cortes Generales was located as of September 2026.

What it requires

Real Decreto-ley 12/2018, Incident Notification Obligation

Real Decreto-ley 12/2018 de 7 de septiembre, de seguridad de las redes y sistemas de informacion, arts. 19, 21 y 22, developed by Real Decreto 43/2021, de 26 de eneroBOE, consolidated text (ELI address), Real Decreto-ley 12/2018

In force since 9 September 2018. Binds public and private bodies.

What this law does

Article 19 requires an operator of essential services to notify the competent authority, through its reference CSIRT, of an incident that may have a significant disruptive effect on its service, and requires a digital service provider to notify an incident with a significant disruptive effect on its service, limited to cases where the provider has access to the information needed to assess the incident's impact.

Article 22 sets an initial notification made without undue delay (sin dilacion indebida), followed by interim and final notifications.

Real Decreto 43/2021's own national incident-notification and management instruction (its Anexo) fixes the clock by severity: for a CRITICO-severity incident, the initial notification is immediate, the interim notification is due within 24 to 48 hours and the final notification within 20 days; for a MUY ALTO-severity incident, the interim notification is due within 72 hours and the final notification within 40 days; an ALTO-severity incident requires only an immediate initial notification, and a MEDIO- or BAJO-severity incident carries no notification duty under the instruction.

This is a looser, severity-gated clock than the fixed 24-hour early warning and 72-hour notification Directive (EU) 2022/2555 itself sets, and it remains, according to official trackers, in full force pending the NIS2 transposition described on this jurisdiction's Anteproyecto rows.

What it requires

Age gating law5 instruments, 2 in force, 3 proposed

Research summary (204 words)

Spain's Ley Organica 8/2021 (LOPIVI, Comprehensive Law on the Protection of Children and Adolescents against Violence) classifies unsolicited exposure to pornography as a form of violence against minors and requires public administrations to run awareness campaigns and promote parental control tools, but it does not itself impose a binding age verification duty on pornography providers.

The current statutory minimum age at which a minor may independently consent to an information society service such as social media, without parental consent, is 14 under Article 7 of Ley Organica 3/2018 (LOPDGDD, Organic Law on Data Protection and Digital Rights Guarantee).

A government sponsored Proyecto de Ley Organica para la proteccion de las personas menores de edad en los entornos digitales (Draft Organic Law for the Protection of Minors in Digital Environments), approved by the Council of Ministers and formally submitted to Congress in March 2025, would raise the social media registration age to 16, require device manufacturers to install free parental control systems by default, and let authorities seek judicial orders blocking pornography and video sharing platforms that lack effective age verification.

It survived a whole bill rejection amendment in a Congress plenary vote and remained under committee level amendment review (ponencia) as of June 2026.

Adult content age verification (AV)

Ley Orgánica 8/2021, de 4 de junio, de protección integral a la infancia y la adolescencia frente a la violencia (LOPIVI, Organic Law 8/2021 on the comprehensive protection of children and adolescents against violence)

Ley Organica 8/2021, de 4 de junio (LOPIVI, Comprehensive Law on the Protection of Children and Adolescents against Violence)official consolidated statute text, Boletin Oficial del Estado

In force since 25 June 2021. Binds government bodies.

What this law does

Classifies unsolicited access to pornography as a form of violence against minors and requires public administrations to develop educational campaigns on the risks of pornography exposure and to promote parental control mechanisms, but does not impose a direct age verification obligation on pornography providers themselves.

Note and primary source

Proyecto de Ley Orgánica 121/000052 (Draft Organic Law for the Protection of Minors in Digital Environments), judicial blocking of noncompliant adult content platforms

Proyecto de Ley Organica 121/000052 (Congreso de los Diputados, XV Legislatura)official bill text (Boletin Oficial de las Cortes Generales) and status tracker, Congreso de los Diputados

Proposed: draft date not recorded. In committee, dated 12 December 2025, as of 12 September 2026. Binds private bodies.

What this law does

Would empower Spanish courts, on petition from the competent authority, to order the blocking or takedown of video sharing platforms distributing pornographic content in Spain that lack effective age verification mechanisms limiting access by minors.

Note and primary source

App store age verification (AV)

Proyecto de Ley Orgánica 121/000052 (Draft Organic Law for the Protection of Minors in Digital Environments), device level parental control mandate

Proyecto de Ley Organica 121/000052 (Congreso de los Diputados, XV Legislatura)official bill text (Boletin Oficial de las Cortes Generales) and status tracker, Congreso de los Diputados

Proposed: draft date not recorded. In committee, dated 12 December 2025, as of 12 September 2026. Binds private bodies.

What this law does

Would require manufacturers of smartphones and other digital terminal devices sold in Spain to install and activate, free of charge and by default, parental control systems that can limit device usage, block access to harmful sites, and log visited sites.

Note and primary source

Social media and minors

Ley Orgánica 3/2018, de 5 de diciembre, de Protección de Datos Personales y garantía de los derechos digitales (LOPDGDD, Organic Law 3/2018 on personal data protection and digital rights guarantee), Art. 7

Ley Organica 3/2018, de 5 de diciembre (LOPDGDD, Organic Law on Data Protection and Digital Rights Guarantee), Art. 7official consolidated statute text, Boletin Oficial del Estado

In force since 7 December 2018. Binds private bodies.

What this law does

Sets 14 as the minimum age at which a minor can independently consent to processing of personal data for an information society service, including registering for a social media account. Parental or guardian consent is required for processing based on consent for users under 14.

Note and primary source

Proyecto de Ley Orgánica para la protección de las personas menores de edad en los entornos digitales (121/000052, Draft Organic Law for the Protection of Minors in Digital Environments), minimum social media age

Proyecto de Ley Organica 121/000052 (Congreso de los Diputados, XV Legislatura)official bill text (Boletin Oficial de las Cortes Generales) and status tracker, Congreso de los Diputados

Proposed: draft date not recorded. In committee, dated 12 December 2025, as of 12 September 2026. Binds private bodies.

What this law does

Would raise from 14 to 16 the minimum age at which a minor can independently consent to a social media account and related information society services. Approved by the Council of Ministers on 25 March 2025, formally submitted to Congress the same month, survived a whole bill rejection amendment (enmienda a la totalidad) in a plenary vote, and remained under committee level amendment review as of June 2026.

Note and primary source

News aggregation law4 instruments, 3 in force, 1 repealed, withdrawn or blocked

Research summary (210 words)

Spain enacted a press-publisher neighbouring right and a text-and-data-mining exception through Real Decreto-ley 24/2021, which transposed the EU Digital Single Market Copyright Directive (2019/790) into national law. It replaced the country's 2014 AEDE levy, a mandatory and non-waivable charge on aggregators that prompted Google to close Google News in Spain for nearly seven years; that repealed provision is carried below as its own instrument.

The Texto Refundido de la Ley de Propiedad Intelectual (TRLPI), as amended, gives press publishers and news agencies an exclusive online reproduction and making-available right at Article 129 bis, exempting hyperlinks and very short extracts, and Article 32.2 requires a content-aggregation service to obtain that authorization before making press text or fragments available online.

Article 67 of Real Decreto-ley 24/2021's own Fourth Book creates a text-and-data-mining exception subject to an express rightsholder opt-out for general use, and a separate, unconditional exception for research organizations and cultural-heritage institutions.

Spain has no compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code or Canada's Online News Act; disputes over the Article 129 bis authorization go instead to the Comisión de Propiedad Intelectual, an administrative body, with judicial review available afterward. No hot-news or misappropriation doctrine distinct from ordinary unfair-competition law was located in the primary sources checked.

Press publishers' right

Spain, Artículo 32.2 Ley de Propiedad Intelectual (AEDE levy)

Ley 21/2014, de 4 de noviembre, por la que se modifica el texto refundido de la Ley de Propiedad Intelectual, BOE num. 268, 5 Nov. 2014Boletin Oficial del Estado

Repealed: no longer in force, effective 1 January 2015. Binds public and private bodies.

What this law does

This Spanish member-state law (not an EU instrument) introduced a mandatory, non-waivable remuneration right for press publishers against online content aggregators, deliberately designed so that publishers could not grant free licences as German publishers had done, with fees collected collectively through the SGAE successor body.

Google responded by shutting down Google News in Spain in December 2014, causing Spanish publishers to lose substantial referral traffic; the provision was repealed and replaced by Spain's transposition of Digital Single Market (DSM) Art. 15 via Real Decreto-ley 24/2021, after which Google News relaunched in Spain in November 2021.

Note and primary source

TRLPI Article 129 bis, Press Publisher and News Agency Online Rights

Real Decreto Legislativo 1/1996 (Texto Refundido de la Ley de Propiedad Intelectual) art. 129 bis, added by Real Decreto-ley 24/2021, de 2 de noviembre, art. 80.7 (BOE-A-2021-17910)BOE, consolidated text of the Texto Refundido de la Ley de Propiedad Intelectual

In force since 4 November 2021. Binds private bodies.

What this law does

Press publishers and news agencies established in Spain hold an exclusive reproduction and making-available right over their press publications for online use by information-society service providers, per Article 129 bis(1). The right does not reach hyperlinking, per Article 129 bis(6)(b). It also does not reach the use of single words or very short, insignificant extracts that does not harm the publishers' investment, per Article 129 bis(6)(c).

Negotiated authorizations must follow good-faith, due-diligence, transparency and free-competition principles, and disputes go to the Comisión de Propiedad Intelectual rather than a designated bargaining process.

Note and primary source

Snippet reproduction

TRLPI Article 32, Citation, Press-Review, and Aggregation-Service Exception

Real Decreto Legislativo 1/1996 (TRLPI) art. 32, paragraph 2 as amended by Real Decreto-ley 24/2021, de 2 de noviembre, art. 80.2 (BOE-A-2021-17910)BOE, consolidated text of the Texto Refundido de la Ley de Propiedad Intelectual

In force since 4 November 2021. Binds private bodies.

What this law does

Periodic compilations of press articles presented as citations or press reviews are exempt from authorization, but a compilation that consists essentially of mere reproduction for commercial purposes requires equitable remuneration to the author unless the author expressly objects, per Article 32.1.

Since the 2021 amendment, a content-aggregation service provider that makes press text or text fragments available to the public needs the Article 129 bis authorization from the rights holder, per Article 32.2. A search engine's keyword-search tool is exempt from authorization and remuneration when its display is strictly limited to what is needed for non-commercial search results and includes a link to the source page.

Note and primary source

Text and data mining (TDM) opt-out

RDL 24/2021 Article 67, Text and Data Mining Exception

Real Decreto-ley 24/2021, de 2 de noviembre, Libro Cuarto, Titulo II, art. 67 (Mineria de textos y datos) (BOE-A-2021-17910)BOE, consolidated text of Real Decreto-ley 24/2021

In force since 4 November 2021. Binds public and private bodies.

What this law does

No authorization from an intellectual-property rights holder is needed for reproductions of legitimately accessible works made for text and data mining purposes, per Article 67(1) of Real Decreto-ley 24/2021's own Fourth Book. That general exception does not apply where rights holders have expressly reserved the use of their works through machine-readable means or other adequate means, per Article 67(3), which is the opt-out.

A separate, non-waivable exception in Article 67(4) covers research organizations and cultural-heritage institutions carrying out text and data mining for scientific research, without the opt-out that limits the general exception.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.