Law: Organic Law 3/2018, of 5 December 2018, on the Protection of Personal Data and Guarantee of Digital Rights (only available in Spanish here) (LOPDGDD) and General Data Protection Regulation (Regulation (EU) 2016/679) (GDPR)
Regulator: Spanish data protection authority (AEPD)
Summary: Spain implemented the GDPR in 2018 through the Organic Law 3/2018, of 5 December 2018, on the Protection of Personal Data and Guarantee of Digital Rights (only available in Spanish here) (LOPDGDD) which came into effect on December 6, 2018. However, the LOPDGDD derogates from the GDPR in areas such as the appointment of data protection officers, digital rights in the working environment, and whistleblowing schemes. In addition, the Spanish data protection authority (AEPD) is an active regulator and regularly issues enforcement actions and responds to data subjects' complaints and requests. The AEPD has imposed several administrative penalties in cases affecting multinational organizations from different business sectors, as well as small to medium-sized enterprises and private subjects. Furthermore, the AEPD has issued substantive guidance on a range of key compliance areas, such as the use of cookies, data transfers mechanisms, and Data Protection Impact Assessment (DPIA) requirements, providing organizations with both a blacklist and a whitelist in relation to DPIAs.