Spain
Part of the European Union, so bloc-wide rules apply here too. Checked today.
The answer
Spain follows the normal European rule: personal data may leave the country once you have the right paperwork in place. But four named categories of data held by the Spanish state must physically stay inside the European Union, and may only travel further to a country Europe has officially approved. Spain's privacy regulator is one of the busiest in the world.
Eight questions about Spain
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Spain's rules apply to my company?
Yes. A company with no office in Spain is still caught if it offers goods or services to people in Spain or watches what they do online. There is no size or revenue threshold to hide under. If you have no base anywhere in Europe you must appoint a written representative inside Europe, and Spain's regulator will happily deal with that representative instead of you.
Two layers stack here. The bloc layer is Regulation (EU) 2016/679 (GDPR), Articles 3(2) and 27. The national layer is Ley Organica 3/2018 (LOPDGDD), whose Article 2 extends the Spanish statute to processing that the GDPR itself does not directly cover, for example activities outside European Union law. Article 2(2)(c) carves out processing governed by classified-information rules, which is the defence sector's exit door. Spain has no separate registration, licence or filing before you may start processing.
Sources
- Official sourceBoletin Oficial del EstadoLey Organica 3/2018 on data protection and the guarantee of digital rights, Article 2 (scope)
boe.es
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionGeneral Data Protection Regulation, Articles 3 and 27
eur-lex.europa.eu
Link checked 18 August 2026
Can I store my users' data outside Spain?
For most businesses, yes, with paperwork — the ordinary European rules apply and nothing in Spanish law says data must sit on Spanish soil. The exception is sharp. If the data is the electoral roll, a town-hall population register, Spanish tax records, or information about users of the Spanish national health service, the computers holding it must be inside the European Union, and that data may only go outside Europe to a country Europe has officially approved. A standard European transfer contract does not work for those four things.
The wall is Article 46 bis of Ley 40/2015, inserted by Real Decreto-ley 14/2019 on public-security grounds — the one ground that Regulation (EU) 2018/1807 leaves open to member states. Verbatim: 'Los sistemas de informacion y comunicaciones para la recogida, almacenamiento, procesamiento y gestion del censo electoral, los padrones municipales de habitantes y otros registros de poblacion, datos fiscales relacionados con tributos propios o cedidos y datos de los usuarios del sistema nacional de salud, asi como los correspondientes tratamientos de datos personales, deberan ubicarse y prestarse dentro del territorio de la Union Europea.' Sector ratings on top of the national picture: - Government and public-sector suppliers: data can leave with the right paperwork, but European Union location is compulsory for the four categories above, and any system sold into the Spanish public sector must be certified against the National Security Framework (Esquema Nacional de Seguridad). - Health: data can leave with the right paperwork generally; data can leave with the right paperwork and EU-wall for national health service user data via Article 46 bis. Private clinics outside the national health service are not caught by that article. - Online gambling: data can leave with the right paperwork. Contrary to widespread belief the technical decree expressly permits the operator's central gaming unit and its backup to sit anywhere in the world; what it demands is real-time monitoring from Spain, physical inspection access, and a Spanish '.es' website. The regulator does hold a live power to order named secondary systems into Spain. - Telecoms: data can leave with the right paperwork. Connection records must be kept for twelve months but no article says where. - Banking, payments, securities, insurance: data can leave with the right paperwork. No location rule found in the Spanish statutes, checked 18 August 2026. Insurance outsourcing is gated by a prior-notification and veto process instead. - Mapping and location data: no localisation rule found in Spanish law, checked 18 August 2026, medium confidence. - Defence and classified material: outside the data protection statute entirely and governed by the 1968 Official Secrets Act.
Sources
- Official sourceBoletin Oficial del EstadoLey 40/2015 on the legal regime of the public sector, Article 46 bis — location of information systems
boe.es
“deberan ubicarse y prestarse dentro del territorio de la Union Europea. Los datos a que se refiere el apartado anterior no podran ser objeto de transferencia a un tercer pais u organizacion internacional, con excepcion de los que hayan sido objeto de una decision de adecuacion de la Comision Europea”
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoReal Decreto-ley 14/2019 on urgent public-security measures in digital administration, Article 4 and second transitional provision
boe.es
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoReal Decreto 1613/2011 on technical requirements for gambling activity, Articles 13 and 14
boe.es
“La Unidad Central de Juegos y su replica, con independencia de su ubicacion, deberan poder ser monitorizadas desde territorio espanol”
Link checked 18 August 2026
What do I need in place before data leaves Spain?
The model is an approved-list one, run at European level, not by Spain. You may send data outside Europe if the destination country is on Europe's approved list, or if you sign Europe's standard contract, or if your corporate group has approved internal rules. The list is real and populated. Spain adds one twist: if you want to use a home-made contract instead of the standard one, you must get written permission from the Spanish regulator first.
Ley Organica 3/2018 Articles 40 to 43 bolt Spanish procedure onto the European framework. Article 41 lets the Spanish Agency, and the regional authorities in Catalonia, the Basque Country and Andalusia, adopt their own standard clauses and approve binding corporate rules, with a nine-month maximum for the latter. Article 42 makes prior authorisation compulsory for bespoke contractual safeguards and for certain public-body transfers. Article 43 requires you to tell the regulator in advance if you rely on the narrow 'compelling legitimate interests' route, and to tell the affected people too. On the approved list itself, the bloc-layer position applies unchanged: Andorra, Argentina, Brazil, Canada (commercial bodies), Faroe Islands, Guernsey, Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom, Uruguay, and the United States only for organisations self-certified under the EU-US Data Privacy Framework. None has been withdrawn or suspended as at 18 August 2026. For the four Article 46 bis categories the picture inverts: standard contracts and corporate rules are unavailable, and only the approved list works.
Sources
- Official sourceBoletin Oficial del EstadoLey Organica 3/2018, Articles 40 to 43 — international transfers, prior authorisation and prior information
boe.es
“Las transferencias internacionales de datos a paises u organizaciones internacionales que no cuenten con decision de adecuacion aprobada por la Comision ... requeriran una previa autorizacion de la Agencia Espanola de Proteccion de Datos”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Implementing Decision (EU) 2021/914 — standard contractual clauses
eur-lex.europa.eu
Link checked 18 August 2026
Who enforces the rules in Spain, and what can they do?
The Spanish Data Protection Agency, and it is very much awake. Its public decision database held 46,925 decisions when we checked on 18 August 2026, with rulings signed as recently as 12 August 2026. Three regional authorities also enforce, covering public bodies in Catalonia, the Basque Country and Andalusia. Spain's artificial intelligence supervisor is now operating too and met the privacy agency in July 2026 to divide up the work.
The Agencia Espanola de Proteccion de Datos (AEPD) is chaired by Lorenzo Cotino and publishes press releases, guidance and decisions continuously — items dated 9, 14, 15, 20, 21, 23, 27 and 28 July 2026 were live on its site. It is consistently among the highest-volume enforcers in Europe. Rating: aggressive. It runs a priority channel for urgent takedowns of intimate imagery, opens investigations on its own initiative, and its published caseload is dominated by finance and insurance (9,928 decisions), information and communications (8,435) and video surveillance (7,072). One large asterisk: Article 77 of Ley Organica 3/2018 means Spanish public bodies, the Bank of Spain, public universities and similar entities are not fined. They receive a warning and an order to fix the problem. So the regulator's fining power is aimed squarely at the private sector. The Catalan authority (Autoritat Catalana de Proteccio de Dades, director Meritxell Borras) was publishing through July 2026. The Basque and Andalusian authorities exist and are named in the statute; we did not separately re-verify their 2026 output in this run. Sector regulators that also bite: the Bank of Spain, the securities commission CNMV, the insurance directorate DGSFP, the gambling directorate DGOJ, the telecoms and competition authority CNMC, the National Cryptologic Centre for public-sector cyber incidents, and INCIBE for everyone else.
Sources
- Official sourceAgencia Espanola de Proteccion de DatosAEPD published decisions database — 46,925 results, most recent signed 12 August 2026
aepd.es
Link checked 18 August 2026
- Official sourceAgencia Espanola de Proteccion de DatosAEPD press releases, July 2026 — artificial intelligence data quality analysis, coordination with the AI supervisor AESIA, public-sector compliance recommendations
aepd.es
Link checked 18 August 2026
- Official sourceGeneralitat de CatalunyaAutoritat Catalana de Proteccio de Dades — active site with items dated July 2026
apdcat.gencat.cat
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoLey Organica 3/2018, Article 77 — public bodies are warned, not fined
boe.es
Link checked 18 August 2026
How long do I have to keep the data?
Both directions, and they collide. The longest floor is money laundering records: ten years, and the same law then orders you to destroy them. Business books run six years, clinical records at least five years from the end of each course of treatment, phone and internet connection records twelve months, and the taxman can come back four years. In the other direction Spain does something unusual: when someone asks you to delete their data you must not actually delete it, you must lock it away.
Floors, with citations: - Money laundering: ten years for customer due diligence papers and transaction records, Ley 10/2010 Article 25. After five years the file may only be opened by internal compliance staff and legal defence. At the ten-year mark deletion is mandatory, not optional — the statute says 'procediendo tras el mismo a su eliminacion'. This is one of the few genuine ceilings in Spanish law. - Business books and correspondence: six years from the last accounting entry, Commercial Code Article 30. - Clinical records: at least five years from discharge for each episode of care, Ley 41/2002 Article 17. Birth-related records are never destroyed. Several regions set longer periods in their own health laws. - Telecoms connection records: twelve months, Ley 25/2007 Article 5, adjustable by regulation between six months and two years. - Tax: the authorities' right to assess expires after four years, Ley 58/2003 Article 66, so four years is the practical floor for tax paperwork. The ceiling: Article 32 of Ley Organica 3/2018 creates a duty to 'block' data. When you rectify or erase, you must isolate the record, make it invisible to normal processing, and keep it available only to courts, prosecutors and regulators until the relevant limitation period runs out — then destroy it. If your system cannot do this you must record that fact and migrate at your next major upgrade. A global 'delete means delete' architecture is non-compliant in Spain. Conflict resolution: the sector floor wins over a person's erasure request, and the blocking rule is what bridges the gap.
Sources
- Official sourceBoletin Oficial del EstadoLey 10/2010 on money laundering prevention, Article 25 — ten years then mandatory destruction
boe.es
“Los sujetos obligados conservaran durante un periodo de diez anos la documentacion en que se formalice el cumplimiento de las obligaciones establecidas en la presente ley, procediendo tras el mismo a su eliminacion.”
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoCodigo de Comercio, Article 30 — six years of books and correspondence
boe.es
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoLey 41/2002 on patient autonomy, Article 17 — minimum five years of clinical documentation
boe.es
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoLey Organica 3/2018, Article 32 — the duty to block rather than delete
boe.es
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoLey 58/2003 General Tributaria, Article 66 — four-year tax limitation period
boe.es
Link checked 18 August 2026
What happens if there is a breach?
Count three clocks, not one. Everyone has 72 hours to tell the privacy regulator about a personal data breach. Phone and internet providers have only 24 hours under a separate European rule. And if you run something the state treats as an essential service, the cyber clock says report immediately, then send an update within 24 to 48 hours if the incident is critical, or 72 hours if it is very serious, with a final report 20 or 40 days later.
Clock one — privacy. Regulation (EU) 2016/679 Article 33, confirmed on the Spanish regulator's own breach page: 72 hours from becoming aware. You notify the Spanish agency if your only establishment is in Spain, or if Spain hosts your main European establishment. High-risk breaches must also be told to the affected people without undue delay. Clock two — telecoms. Commission Regulation (EU) 611/2013 gives providers of publicly available electronic communications services 24 hours from detection to make an initial notification. It applies directly and is easy to miss because it sits outside the GDPR. Clock three — cyber. Real Decreto 43/2021 with Real Decreto-ley 12/2018 governs operators of essential services and digital service providers. Its national instruction sets a reporting window table: initial notification immediate for CRITICAL, VERY HIGH and HIGH incidents; intermediate report at 24 to 48 hours (critical) or 72 hours (very high); final report at 20 days (critical) or 40 days (very high). Reporting goes through the National Platform for Cyber Incident Notification, to the National Cryptologic Centre for public bodies or INCIBE for private operators. The overlap is where people fail. A ransomware attack on a Spanish telecoms operator triggers all three at once, on three different forms, to two or three different bodies.
Sources
- Official sourceAgencia Espanola de Proteccion de DatosAEPD guidance on notifying personal data breaches to the supervisory authority
aepd.es
“El plazo para notificar a la autoridad de control es de 72 horas desde que la organizacion tiene constancia de la brecha.”
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoReal Decreto 43/2021, annex — national instruction on cyber incident notification, reporting window table
boe.es
“Ventana temporal de reporte. Nivel de peligrosidad o impacto / Notificacion inicial / Notificacion intermedia / Notificacion final. CRITICO. Inmediata. 24/48 horas. 20 dias. MUY ALTO. Inmediata. 72 horas. 40 dias.”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Regulation (EU) No 611/2013 — 24-hour breach notification for electronic communications providers
eur-lex.europa.eu
Link checked 18 August 2026
What trips people up in Spain?
Five things that ruin weekends. One: a child can consent at fourteen in Spain, not sixteen, so your global age gate is probably wrong here. Two: 'delete my data' legally means 'lock my data away', so a hard-delete pipeline breaks the law. Three: Spain forces far more organisations to appoint a data protection officer than Europe does, including every school, university, bank, insurer, energy supplier and online gambling operator. Four: misusing someone's personal records is a crime punishable by prison, and companies themselves can be prosecuted. Five: telecoms operators can be ordered to hand over the encryption method they use.
1. Age of consent — Article 7 of Ley Organica 3/2018 sets fourteen. Below fourteen you need a parent or guardian. Most global products are built to sixteen or thirteen; both are wrong for Spain. 2. Blocking — Article 32 of the same law. Rectified or erased data must be identified, reserved and made unavailable to everything except courts, prosecutors and regulators, for as long as liability could still be claimed, and only then destroyed. Where the system cannot do it, you must document that and fix it at the next major overhaul. 3. Mandatory data protection officers — Article 34 lists sixteen categories on top of the European test: professional colleges, all schools and universities, telecoms operators processing at large scale, online services that profile users at large scale, credit institutions, financial credit establishments, insurers and reinsurers, investment firms, electricity and gas retailers and distributors, credit-scoring and fraud-prevention file operators, advertising and market research firms that profile, health centres that keep clinical records, commercial-report issuers, and electronic gambling operators. 4. Criminal liability — Criminal Code Article 197(2) punishes appropriating, using or altering another person's reserved personal data held in any file, to their detriment, with one to four years in prison plus a fine. Article 197 quinquies extends liability to the company itself. This is prosecution, not an administrative fine, and it attaches to named individuals. 5. Encryption disclosure — Ley 11/2022 Article 62(2) allows the state to require an electronic communications operator to hand over the algorithms or any encryption procedure used, and to hand over cipher equipment free of charge, where essential state security, public security or a criminal investigation justifies it. Bonus trap: Real Decreto-ley 14/2019 restricted the use of distributed ledger (blockchain) systems for identifying and signing in dealings with Spanish public administrations, unless the central government acts as an intermediate authority. Teams building on-chain identity for Spanish public-sector work walk into this without warning.
Sources
- Official sourceBoletin Oficial del EstadoLey Organica 3/2018, Articles 7, 32 and 34 — age fourteen, data blocking, mandatory data protection officers
boe.es
“El tratamiento de los datos personales de un menor de edad unicamente podra fundarse en su consentimiento cuando sea mayor de catorce anos.”
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoLey Organica 10/1995 Criminal Code, Articles 197 and 197 quinquies
boe.es
“Las mismas penas se impondran al que, sin estar autorizado, se apodere, utilice o modifique, en perjuicio de tercero, datos reservados de caracter personal o familiar de otro que se hallen registrados en ficheros o soportes informaticos”
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoLey 11/2022 General Telecommunications Act, Article 62 — encryption in networks and services
boe.es
“se podra imponer la obligacion de facilitar a un organo de la Administracion General del Estado o a un organismo publico, los algoritmos o cualquier procedimiento de cifrado utilizado”
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoReal Decreto-ley 14/2019 — restriction on distributed ledger identification systems in public administration
boe.es
Link checked 18 August 2026
What is changing soon in Spain?
The biggest thing is what has not happened. Spain still has not passed the law that brings Europe's new cybersecurity rules into Spanish law, so the old 2018 regime is still what binds — expect that to change and to widen sharply who must report incidents. From 12 January 2027 no cloud provider may charge you to leave or to pull your data out. Watch three switches the government can flip with no consultation: taking over telecoms networks, ordering gambling systems into Spain, and demanding an operator's encryption method.
Confirmed gaps and dates: - Network and Information Security Directive 2 (NIS2): a search of the official gazette's consolidated national legislation on 18 August 2026 found no Spanish transposing act. The operative regime remains Real Decreto-ley 12/2018 and Real Decreto 43/2021. When the transposition lands it will expand the list of covered sectors, add management liability and change the reporting clocks. Treat the current comfort as temporary. - No Spanish artificial intelligence governance act appears in the gazette either, though the supervisory agency AESIA is up and running and coordinating with the privacy regulator as of July 2026. The EU AI Act's transparency duties started on 2 August 2026 regardless. - No organic law on protecting minors in digital environments appears in the gazette as at 18 August 2026. If and when it passes it is expected to disturb the fourteen-year consent age. - Data Act (EU) 2023/2854: cloud switching charges and data egress fees must be zero from 12 January 2027. Dormant switches, all live today: 1. Ley 11/2022 Article 4(6): the government may, exceptionally and temporarily, take over direct management of electronic communications services or networks for public and national security. No notice, no consultation. 2. Real Decreto 1613/2011 Article 14(3): the gambling regulator may require an operator to place named secondary systems inside Spain. Not currently exercised generally, and it converts a location-neutral regime into a localisation regime overnight. 3. Ley 11/2022 Article 62(2): the state may demand the encryption algorithms and procedures an operator uses. 4. Ley 40/2015 Article 46 bis is drafted around public security and is expressly provisional 'until progress is made within the European Union'. Its scope could be widened by another decree-law with immediate effect, exactly as it was created. 5. Bloc-level: the EU-US Data Privacy Framework remains valid but the European Data Protection Board formally asked the Commission on 31 July 2026 to examine its validity. Any Spanish architecture that relies on that framework alone should have a fallback.
Sources
- Official sourceBoletin Oficial del EstadoBoletin Oficial del Estado consolidated national legislation search, run 18 August 2026 — no NIS2 transposing act, no artificial intelligence governance act, no minors-in-digital-environments organic law
boe.es
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoLey 11/2022, Article 4(6) — emergency state takeover of electronic communications networks and services
boe.es
“El Gobierno, con caracter excepcional y transitorio, podra acordar la asuncion por la Administracion General del Estado de la gestion directa de determinados servicios de comunicaciones electronicas disponibles al publico”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionData Act (EU) 2023/2854 — zero switching and egress charges from 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
Bloc rules
Made by a group of countries together. Applies inside every member country.
2 rules here
Layer 2
National rules
Added by this country on top of any bloc rules.
1 rule here
Layer 3
Industry rules
Made by an industry regulator. These usually beat the general position.
9 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
Bloc rules2 rules
Reglamento (UE) 2016/679 — Reglamento General de Proteccion de Datos
Directly binding regulation · Regulation (EU) 2016/679
Europe's general data protection law. It does not say where data must be stored. It says what you must have in place before personal data leaves Europe, and it applies to companies outside Europe that target people in Spain.
Enforced by Spanish Data Protection Agency
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What it makes you do
- Put a transfer safeguard in placeA valid instrument plus a documented assessment of the destination country's surveillance laws.
- Report breaches to the regulator — within 72 hours
- Tell affected peopleWithout undue delay where the risk to individuals is high.
- Appoint a local representativeRequired where the controller has no establishment in Europe.
- Keep records of processing
- Assess high-risk projects
What it costs if you get it wrong
- Percentage of global turnover: €20 million or 4% of worldwide group turnover, whichever is higher (about $22 million at the floor) — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator's order.
- Order to stopOrder to stop processing or to suspend flows to a country outside Europe.
Sources
- Official sourcePublications Office of the European UnionGeneral Data Protection Regulation, official consolidated text
eur-lex.europa.eu
Link checked 18 August 2026
Data Act — Reglamento (UE) 2023/2854
Directly binding regulation · Regulation (EU) 2023/2854
Not about where data sits, but about being able to move it. From 12 January 2027 no cloud provider may charge you to switch away or to pull your data out. It also pushes back on non-European government demands for data held in Europe.
Transfer model: No restriction
What it makes you do
- Make switching cloud provider possible — from 12 January 2027All cloud switching charges and data egress fees must be zero from 12 January 2027.
- Do not hand data to foreign authorities on demandCloud providers must take technical, organisational and legal measures against non-European government access to non-personal data held in Europe where that would conflict with European law.
Sources
- Official sourcePublications Office of the European UnionData Act (EU) 2023/2854, official text
eur-lex.europa.eu
Link checked 18 August 2026
National rules1 rule
Ley Organica 3/2018, de 5 de diciembre, de Proteccion de Datos Personales y garantia de los derechos digitales
Act of parliament · BOE-A-2018-16673
Spain's national privacy statute, sitting on top of Europe's. Its distinctive parts are a digital consent age of fourteen, a duty to lock data away rather than delete it, a much longer list of organisations that must appoint a data protection officer, and a rule that public bodies get warnings instead of fines.
Enforced by Spanish Data Protection Agency
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Government sign-off needed
What it makes you do
- Get a parent's consent for children — applies at: Under 14 years old — Spain sets the digital consent age at 14, not 16Article 7.
- Let people delete their dataArticle 32: erasure means blocking. Data must be isolated and kept invisible except to courts, prosecutors and regulators until liability expires, then destroyed.
- Appoint a data protection officer — applies at: Sixteen listed categories including all schools and universities, telecoms operators, banks, insurers, investment firms, energy retailers, health centres holding clinical records, advertising profilers and online gambling operatorsArticle 34, on top of the European test.
- Put a transfer safeguard in placeArticles 40 to 43: prior regulator authorisation for bespoke contractual safeguards; prior notice for compelling legitimate interest transfers.
- Tell people what you do
- Keep records of processing
What it costs if you get it wrong
- Percentage of global turnover: €20 million or 4% of worldwide group turnover (about $22 million at the floor) — about $22 millionVery serious infringements, which time-bar after three years.
- Criminal liability: One to four years in prison plus a fine, under Criminal Code Article 197Appropriating, using or altering another person's reserved personal data to their detriment. Companies themselves can be prosecuted under Article 197 quinquies.
- Claims by individualsIndividuals may sue for compensation.
Sources
- Official sourceBoletin Oficial del EstadoLey Organica 3/2018, consolidated text
boe.es
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoCriminal Code, Articles 197 to 201
boe.es
Link checked 18 August 2026
Industry rules9 rules
Ley 40/2015, de 1 de octubre, de Regimen Juridico del Sector Publico, articulo 46 bis (anadido por el Real Decreto-ley 14/2019)
Act of parliament · BOE-A-2015-10566, art. 46 bis; inserted by BOE-A-2019-15790 art. 4.1 · Government
Spain's one true storage wall. Four categories of state-held data — the electoral roll, town-hall population registers, Spanish tax records, and national health service user data — must be held and processed inside the European Union, and may only leave Europe for a country Europe has officially approved. Standard transfer contracts do not help here.
Enforced by Secretariat General for Digital Administration
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision
What it makes you do
- Keep the data in the country — applies at: Electoral roll, municipal population registers and other population registers, tax data on Spain's own and ceded taxes, and data on users of the national health service, from 6 May 2020The systems and the processing must sit inside the European Union. Directly managed systems had six months from 6 November 2019; contracted systems had to adapt at renewal or re-tender.
- Put a transfer safeguard in placeStandard contractual clauses and binding corporate rules are NOT available for this data. Only an EU adequacy decision, or an international obligation binding on Spain, permits transfer outside the European Union.
What it costs if you get it wrong
- Order to stopNon-compliant public contracts can be challenged and the arrangement unwound; the underlying processing also breaches the data protection statute.
Sources
- Official sourceBoletin Oficial del EstadoLey 40/2015, Article 46 bis — location of information and communications systems for data registration
boe.es
“deberan ubicarse y prestarse dentro del territorio de la Union Europea”
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoReal Decreto-ley 14/2019, Article 4.1 and second transitional provision — six months to comply, adaptation at contract renewal
boe.es
Link checked 18 August 2026
Real Decreto 311/2022, de 3 de mayo, por el que se regula el Esquema Nacional de Seguridad
Directly binding regulation · BOE-A-2022-7191 · Government
The security rulebook for anything serving the Spanish public sector, including private contractors' own systems. It does not itself say data must stay in Spain or Europe. Instead it pushes the 'where is the data' question into the National Cryptologic Centre's technical guides, which is where the real answer lives.
Enforced by National Cryptologic Centre and its incident response team
Transfer model: Approval each time · Accepted routes: Certification scheme
What it makes you do
- Hold a security certificate — applies at: Any system serving a Spanish public body, including systems owned by private contractors, from 5 May 2024Conformity must be demonstrated with a formal conformity mark; medium and high category systems need certification, not just self-declaration.
- Prove the data stays under local controlThe cloud measure requires third-party cloud services to be compliant with the framework or with a National Cryptologic Centre technical guide covering, among other things, penetration testing, transparency, encryption and key management, and 'jurisdiction of the data'.
- Independent auditPeriodic audit and a signed statement of applicability.
What it costs if you get it wrong
- Order to stopLoss of the conformity mark disqualifies a supplier from public contracts; there is no direct cash fine in the decree.
Sources
- Official sourceBoletin Oficial del EstadoReal Decreto 311/2022, Annex II measure op.nub.1 and sole transitional provision
boe.es
“Cuando se utilicen servicios en la nube suministrados por terceros, los sistemas de informacion que los soportan deberan ser conformes con el ENS o cumplir con las medidas desarrolladas en una guia CCN-STIC que incluira, entre otros, requisitos relativos a: a) Auditoria de pruebas de penetracion. b) Transparencia. c) Cifrado y gestion de claves. d) Jurisdiccion de los datos.”
Link checked 18 August 2026
Real Decreto 1613/2011, de 14 de noviembre, por el que se desarrolla la Ley 13/2011 de regulacion del juego, en lo relativo a los requisitos tecnicos de las actividades de juego
Directly binding regulation · BOE-A-2011-17835 · Online gaming
The rule most people get backwards. Spain does NOT require an online gambling operator's central gaming system to sit in Spain — the decree says the opposite, 'regardless of its location'. What it demands is live monitoring from Spain, inspection access anywhere in the world, and a Spanish website. The regulator does hold an unused power to order named secondary systems into Spain.
Enforced by Directorate General for the Regulation of Gambling
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the country — applies at: Only if the regulator exercises its power — 'determinadas unidades secundarias de sus sistemas tecnicos se ubiquen en Espana'DORMANT SWITCH. Article 14(3) lets the regulator order named secondary systems into Spain at any time. Not exercised as a general requirement, so recorded as an unpopulated power rather than a live rule.
- Keep logsAn internal control system must capture and record every gaming operation and every money movement between players and the central gaming unit.
- Independent auditType approval of the technical system, valid for ten years, plus physical inspection access wherever the equipment sits.
- Register or notifyPlay by or for people in Spain must be served from the operator's own '.es' website; traffic from Spain to the group's other domains must be redirected there.
What it costs if you get it wrong
- Loss of your licenceOperating without an approved technical system, or refusing inspection access.
Sources
- Official sourceBoletin Oficial del EstadoReal Decreto 1613/2011, Articles 13, 14 and 15
boe.es
“el operador debera garantizar el acceso y la inspeccion de la Unidad Central de Juegos con independencia de su ubicacion fisica ... y cualquiera que sea el pais en que estos estuvieran ubicados. ... la Comision Nacional del Juego podra requerir al operador de juego que determinadas unidades secundarias de sus sistemas tecnicos se ubiquen en Espana.”
Link checked 18 August 2026
Ley 25/2007, de 18 de octubre, de conservacion de datos relativos a las comunicaciones electronicas y a las redes publicas de comunicaciones
Act of parliament · BOE-A-2007-18243 · Telecoms
Spanish telephone and internet providers must keep who-called-whom records for twelve months, and hand them to authorised agents only when a judge orders it. The law says nothing about where those records are stored. It was written to implement a European directive that Europe's top court later struck down, and Spain has never repealed or amended it.
Enforced by National Commission on Markets and Competition
Transfer model: No restriction
What it makes you do
- Keep data for a minimum period — 1 yearTwelve months from the date of the communication. A regulation may move this between six months and two years; none has.
- Keep logsHandover only to designated authorised agents and only with prior judicial authorisation.
What it costs if you get it wrong
- Fixed maximum fineFailure to retain or to hand over on a judicial order is sanctioned under the telecommunications regime.
Sources
- Official sourceBoletin Oficial del EstadoLey 25/2007, Article 5 — retention period
boe.es
“La obligacion de conservacion de datos impuesta cesa a los doce meses computados desde la fecha en que se haya producido la comunicacion.”
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoLey 11/2022, Article 61 — cross-reference confirming Ley 25/2007 still governs handover to authorised agents
boe.es
Link checked 18 August 2026
Ley 11/2022, de 28 de junio, General de Telecomunicaciones
Act of parliament · BOE-A-2022-10757 · Telecoms
Spain's telecoms act carries two powers that matter to anyone designing a secure network. The state can require an operator to disclose the encryption method it uses. And the government can take over the running of electronic communications networks and services on public or national security grounds, with no consultation.
Enforced by National Commission on Markets and Competition
Transfer model: No restriction
What it makes you do
- Secure the dataOperators must manage network security risks and notify significant incidents.
- Do not hand data to foreign authorities on demandCuts the other way in Spain: Article 62(2) obliges an operator to hand the Spanish state its encryption algorithms and procedures, and to supply cipher equipment free of charge, where essential state security, public security or a criminal investigation justifies it.
What it costs if you get it wrong
- Order to stopArticle 4(6): the government may take over direct management of covered services or networks for public and national security, exceptionally and temporarily.
Sources
- Official sourceBoletin Oficial del EstadoLey 11/2022, Articles 4(6) and 62
boe.es
“se podra imponer la obligacion de facilitar a un organo de la Administracion General del Estado o a un organismo publico, los algoritmos o cualquier procedimiento de cifrado utilizado, en casos justificados de proteccion de los intereses esenciales de seguridad del Estado y la seguridad publica”
Link checked 18 August 2026
Ley 10/2010, de 28 de abril, de prevencion del blanqueo de capitales y de la financiacion del terrorismo
Act of parliament · BOE-A-2010-6737 · Finance
Spain's money laundering law sets the longest keep-it floor in the country at ten years, and then does something unusual: it orders you to destroy the records once the ten years are up. In between, from year five, the file must be walled off so only compliance and legal defence staff can open it.
Enforced by Spanish financial intelligence unit
Transfer model: No restriction
What it makes you do
- Keep data for a minimum period — 10 yearsTen years for customer identification papers and for records evidencing transactions and business relationships.
- Delete data after a period — 10 yearsA rare hard ceiling: after ten years destruction is mandatory, not discretionary.
- Secure the dataFrom year five to year ten the file may only be accessed by internal control and compliance staff and by those handling the firm's legal defence. Ordinary business access must be cut off.
What it costs if you get it wrong
- Fixed maximum fine: Up to €10 million or 10% of annual turnover for very serious breaches (about $11 million at the cash cap) — about $11 millionFailure to keep or to produce required records.
Sources
- Official sourceBoletin Oficial del EstadoLey 10/2010, Article 25 — document retention
boe.es
“Transcurridos cinco anos desde la terminacion de la relacion de negocios o la ejecucion de la operacion ocasional, la documentacion conservada unicamente sera accesible por los organos de control interno del sujeto obligado”
Link checked 18 August 2026
Ley 41/2002, de 14 de noviembre, basica reguladora de la autonomia del paciente y de derechos y obligaciones en materia de informacion y documentacion clinica
Act of parliament · BOE-A-2002-22188 · Health and social care
Spanish health providers must keep clinical records for at least five years from the end of each course of treatment, and records tied to a patient's birth must never be destroyed. There is no rule saying the records must be in Spain — but if the patients are users of the national health service, the separate public-sector location rule applies and pins the data inside Europe.
Enforced by Ministry of Health
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Keep data for a minimum period — 5 yearsAt least five years from the discharge date of each episode of care. Birth-related records, including tests used to establish parentage, are never destroyed.
- Secure the dataRecords may be kept in any medium, not necessarily the original one, provided integrity and security are preserved.
What it costs if you get it wrong
- Percentage of global turnoverEnforced in practice through the data protection regime, since health data is sensitive data.
Sources
- Official sourceBoletin Oficial del EstadoLey 41/2002, Article 17 — retention of clinical documentation
boe.es
“como minimo, cinco anos contados desde la fecha del alta de cada proceso asistencial”
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoLey 40/2015, Article 46 bis — national health service user data must sit inside the European Union
boe.es
Link checked 18 August 2026
Real Decreto 43/2021, por el que se desarrolla el Real Decreto-ley 12/2018 de seguridad de las redes y sistemas de informacion
Directly binding regulation · BOE-A-2021-1192
Spain's cyber incident regime for essential services and digital service providers. Reporting is immediate for serious incidents, with follow-up reports on a fixed timetable. This is still the 2018 and 2021 regime: as at 18 August 2026 Spain has not yet passed a law bringing Europe's newer cybersecurity directive into Spanish law.
Enforced by National Cryptologic Centre and its incident response team
Transfer model: No restriction
What it makes you do
- Report cyber incidents — within 24 hoursInitial notification is 'immediate' for high, very high and critical incidents. The intermediate report is due at 24 to 48 hours for critical incidents and 72 hours for very high ones; final reports at 20 and 40 days.
- Publish a complaints contactAn information security officer must be designated within three months of being named an essential service operator, and notified to the competent authority.
- Independent auditA signed statement of applicability must be filed within six months and reviewed at least every three years.
What it costs if you get it wrong
- Fixed maximum fine: Up to €1 million for very serious breaches (about $1.1 million) — about $1 millionFailure to notify a significant incident or to adopt required security measures.
Sources
- Official sourceBoletin Oficial del EstadoReal Decreto 43/2021 and its annex, the national cyber incident notification instruction
boe.es
“Ventana temporal de reporte ... CRITICO. Inmediata. 24/48 horas. 20 dias. MUY ALTO. Inmediata. 72 horas. 40 dias. ALTO. Inmediata.”
Link checked 18 August 2026
Ley 20/2015, de 14 de julio, de ordenacion, supervision y solvencia de las entidades aseguradoras y reaseguradoras, articulo 67
Act of parliament · BOE-A-2015-7897 · Insurance
Spanish insurers face no rule about where policyholder data sits, but they cannot quietly move it. Handing a critical function to an outside supplier requires advance notice to the insurance supervisor, which then has one month to object — and changing cloud provider counts as a significant change.
Enforced by Directorate General for Insurance and Pension Funds
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Written vendor contractOutsourcing a critical or important function must be notified to the insurance supervisor in advance, along with any later significant change of provider, scope or responsible person.
- Publish a complaints contactA named person inside the insurer must own each outsourced function and be qualified to check the supplier's performance.
What it costs if you get it wrong
- Order to stopThe supervisor may object within one month, which blocks the arrangement.
Sources
- Official sourceBoletin Oficial del EstadoLey 20/2015, Article 67 — outsourcing of functions
boe.es
“Esta Direccion General podra oponerse a las mismas, en el plazo de un mes desde la recepcion de la comunicacion”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That no Spanish law transposing the second Network and Information Security Directive was in force on 18 August 2026
This is a negative. It rests on a title search of the official gazette's consolidated national legislation, which returned only university degree programmes for 'ciberseguridad' and nothing for 'seguridad de las redes' after 2022. A transposing act published in the days before this run, or one titled differently, would not have surfaced. Treat as strong but not conclusive.
That no organic law on protecting minors in digital environments, and no national artificial intelligence governance act, were in force on 18 August 2026
Same method, same limitation. Both have been widely reported as government bills. Nothing matching was found in the gazette's consolidated legislation.
The precise data-location requirements applying to public-sector cloud services
The National Security Framework decree itself contains no location rule; it delegates 'jurisdiction of the data' to a CCN-STIC technical guide issued by the National Cryptologic Centre. We could not open the current guide, which is distributed through a restricted portal. The practical wall for public-sector cloud may therefore be stricter than the decree text suggests.
Whether Spain's twelve-month telecoms retention law is still safely enforceable after Europe's court struck down the directive it implements
The law is unrepealed and unamended and Spanish courts continue to apply it, but we found no Spanish court or regulator source in this run that squarely resolves the tension with European case law. Recorded as in force with medium confidence rather than as disapplied.
That the Basque and Andalusian data protection authorities are actively issuing decisions in 2026
Both are named in the national statute and we have no reason to doubt they operate, but we verified 2026 activity only for the national agency and the Catalan authority in this run.
Any banking, payments or securities data-location rule in Spain
None found in the securities markets act or in the anti-money-laundering act, checked 18 August 2026. We did not reach the Bank of Spain's own circulars — its DORA supervision page returned a 404. Since the EU digital operational resilience regulation now overrides national banking IT rules, the risk of a missed Spanish rule is low but not zero.
Any mapping, geospatial or aerial-imagery localisation rule in Spain
A gazette title search for 'fotografia aerea' and 'cartografia' on 18 August 2026 returned nothing of the kind. Restrictions could sit in defence ministry orders that are not in the consolidated legislation database. Recorded as no rule found rather than as no rule existing.
The exact commencement date of the insurance supervision act's outsourcing article
We recorded 1 January 2016, the general commencement of the Solvency II regime in Spain, rather than a provision-specific date confirmed from the text.
60-day cadence. Spain holds four dormant switches that can flip with no consultation: the gambling regulator's power to order systems into Spain, the government's power to take over telecoms networks, the state's power to demand an operator's encryption method, and the ability to widen the Article 46 bis location wall by another decree-law exactly as it was created. The overdue cybersecurity transposition is also expected within this window.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- Spain versus Argentina
- Spain versus Armenia
- Spain versus Australia
- Spain versus Austria
- Spain versus Azerbaijan
- Spain versus Brazil
- Spain versus Bulgaria
- Spain versus Cambodia
- Spain versus Canada
- Spain versus China
- Spain versus Croatia
- Spain versus Cyprus
- Spain versus Estonia
- Spain versus France
- Spain versus Georgia
- Spain versus Germany
- Spain versus Greece
- Spain versus Hong Kong SAR
- Spain versus Hungary
- Spain versus Iceland
- Spain versus India
- Spain versus Indonesia
- Spain versus Ireland
- Spain versus Israel
- Spain versus Italy
- Spain versus Japan
- Spain versus Latvia
- Spain versus Lithuania
- Spain versus Luxembourg
- Spain versus Malta
- Spain versus Mexico
- Spain versus Mongolia
- Spain versus Nepal
- Spain versus Netherlands
- Spain versus Poland
- Spain versus Russia
- Spain versus Saudi Arabia
- Spain versus Serbia
- Spain versus Singapore
- Spain versus Slovakia
- Spain versus Slovenia
- Spain versus South Korea
- Spain versus Sri Lanka
- Spain versus Sweden
- Spain versus Switzerland
- Spain versus Taiwan
- Spain versus Thailand
- Spain versus Turkey
- Spain versus Ukraine
- Spain versus United Arab Emirates
- Spain versus United Kingdom
- Spain versus United States
- Spain versus Uzbekistan