Support Centre

Andorra

Summary

Law: Law 29/2021, of 28 October, of Personal Data Protection (only available in Catalan here) (the Law)

Regulator: Andorran data protection authority (APDA)

Summary: Law 29/2021, of October 28, of Personal Data Protection (only available in Catalan here) (the Law) was published in the Official Bulletin of the Principality of Andorra on November 17, 2021 and entered into force on May 17, 2022. The Law outlines a number of data protection principles, obligations, and data subject rights akin to those found within the GDPR, and empowers the Andorran data protection authority (APDA) to adopt corrective measures and administrative fines, ranging from €500 to €100,000. The APDA issued its first enforcement action, a reprimand, in June 2023.

Moreover, Decree 391/2022, Approving the Regulations for the Application of Law was published by the Government of Andorra in October 2022 (only available in Catalan here) (the Regulations) and integrate all the necessary regulatory provisions under the Law, clarifying and adapting their application in practice. Before that, in September 2022, the Government also issued Decree 368/2022, Approving the Regulations of the APDA (only available in Catalan here) (the APDA Regulations), further detailing the powers and functions of the APDA.

In addition, Andorra ratified, in September 2008, the Convention for the Protection of Individuals with Regard to Automatic Processing of Personal Data (the Convention 108) as well as the Amending Protocol (the Convention 108+), in October 2022.

Furthermore, in 2010 Andorra was recognized by the EU as providing adequate protection, which enables the free flow of data between Andorra and EU Member States.

Insights

The Government of Andorra published, on 5 October 2022, Decree 391/2022, of 28 September 2022, approving the Regulations for the application of Law 29/2021, of 28 October, of Personal Data Protection. In particular, the Regulations provide that Decree 391 will replace Decree 367/2022, of 14 September 2022, as several errors were noted, and ensure compliance with the constitutional principle of legal certainty, promote regulatory clarity, and facilitate the rule of law. OneTrust DataGuidance provide an overview of the Regulations and key provisions.

Law 29/2021, of 28 October, of Personal Data Protection ('the Law') was published, on 17 November 2021, in the Official Bulletin of the Principality of Andorra and repealed Qualified Act 15/2003, of 18 December, of Personal Data Protection ('the Qualified Act'). The Law notes that it comes into force within six months of publication in the Official Bulletin of the Principality of Andorra. Notably, the Law highlights that it aims to update and modernise the Andorran data protection frame in line with the General Data Protection Regulation (Regulation (EU) 2016/679) ('GDPR'). This Insight article provides an overview of the Law and its key requirements.