Skip to the content
Global Data RulesData governance rules, country by country

Spain

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Spain — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Aggressive

Spain follows the normal European rule. Personal data may leave the country once you have the right paperwork in place. But four named kinds of data held by the Spanish state must stay inside the European Union. They may only travel further to a country Europe has officially approved as safe enough. Spain's privacy regulator is one of the busiest in the world.

Data governance in Spain

The eight things that decide how you handle data about people in Spain. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. A company with no office in Spain is still covered if it offers goods or services to people in Spain. The same applies if it watches what people in Spain do online. There is no size or revenue level below which you are free. If you have no base anywhere in Europe, you must appoint a written representative inside Europe. Spain's regulator will deal with that representative instead of you.

What you have to do here:
Appoint a representative

Where the data is allowed to live

For most businesses, yes, with paperwork. The ordinary European rules apply. Nothing in Spanish law says data must sit on Spanish soil. The exception is sharp. Four kinds of data must be held on computers inside the European Union. They are the electoral roll, town-hall population registers, Spanish tax records, and information about users of the Spanish national health service. That data may only go outside Europe to a country Europe has officially approved as safe enough. Europe's standard transfer contract does not work for those four things.

What you have to do here:
Keep the data in the country

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

You can only send data to approved countries, and Europe keeps the list, not Spain. You may send data outside Europe in three ways. The destination country is on Europe's approved list. Or you sign Europe's standard contract. Or your corporate group has approved internal rules. The list is real and has countries on it. Spain adds one twist. If you want to use a contract you wrote yourself instead of the standard one, you must get written permission from the Spanish regulator first.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Government sign-off needed

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Spanish Data Protection Agency, and it is very active. Its public decision database held 46,925 decisions when we checked on 18 August 2026. Some rulings were signed as recently as 12 August 2026. Three regional authorities also enforce. They cover public bodies in Catalonia, the Basque Country and Andalusia. Spain's artificial intelligence supervisor is now operating too. It met the privacy agency in July 2026 to divide up the work.

How long you must keep it — and when to delete it

There are both minimum and maximum keep-times, and they clash. The longest minimum is money laundering records: ten years. The same law then orders you to destroy them. Business books run six years. Clinical records run at least five years from the end of each course of treatment. Phone and internet connection records run twelve months. The tax office can come back four years. Spain also does something unusual. When someone asks you to delete their data, you must not actually delete it. You must lock it away.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Let people delete their data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There are three separate deadlines. Everyone has 72 hours to tell the privacy regulator about a personal data breach. Phone and internet providers have only 24 hours under a separate European rule. If you run something the state treats as an essential service, the cyber deadline is different again. You report immediately. Then you send an update within 24 to 48 hours if the incident is critical, or 72 hours if it is very serious. A final report follows 20 or 40 days later.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things catch people out. One: a child can consent at fourteen in Spain, not sixteen. Your global age gate is probably wrong here. Two: 'delete my data' legally means 'lock my data away'. A system that hard-deletes breaks the law. Three: Spain forces far more organisations to appoint a data protection officer than Europe does. That includes every school, university, bank, insurer, energy supplier and online gambling operator. Four: misusing someone's personal records is a crime that can mean prison. Companies themselves can be prosecuted too. Five: telecoms operators can be ordered to hand over the encryption method they use.

What you have to do here:
Get a parent's consent for children · Appoint a data protection officer
What it costs if you get it wrong:
Criminal liability

What's changing next

The biggest thing is what has not happened. Spain still has not passed the law that brings Europe's new cybersecurity rules into Spanish law. So the old 2018 rules are what bind you today. Expect that to change, and to sharply widen who must report incidents. From 12 January 2027 no cloud provider may charge you to leave or to pull your data out. Also watch three powers the government can use with no consultation. It can take over telecoms networks. It can order gambling systems into Spain. And it can demand an operator's encryption method.

What to do: Diarise 12 January 2027 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries9 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Government data must stay in the country

Official name: Ley 40/2015, de 1 de octubre, de Regimen Juridico del Sector Publico, articulo 46 bis (anadido por el Real Decreto-ley 14/2019) · BOE-A-2015-10566, art. 46 bis; inserted by BOE-A-2019-15790 art. 4.1 · Act of parliament

In forceYes, with paperwork

Spain's one real ban on moving data. Four kinds of state-held data must be held and used inside the European Union. They are the electoral roll, town-hall population registers, Spanish tax records, and national health service user data. That data may only leave Europe for a country Europe has officially approved as safe enough. Europe's standard transfer contract does not help here.

In force since 6 November 2019Enforced from 6 May 2020

Enforced by Secretariat General for Digital Administration

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision

Government

Government data needs a sovereign cloud

Official name: Real Decreto 311/2022, de 3 de mayo, por el que se regula el Esquema Nacional de Seguridad · BOE-A-2022-7191 · Directly binding regulation

In forceYes, with paperwork

The security rulebook for anything serving the Spanish public sector, including private contractors' own systems. It does not itself say data must stay in Spain or Europe. Instead it hands the question of where data sits to the National Cryptologic Centre's technical guides. That is where the real answer lives.

In force since 5 May 2022Enforced from 5 May 2024

Enforced by National Cryptologic Centre and its incident response team

How this country controls where data goes: Approval each time · Accepted routes: Certification scheme

Online gaming

Online gaming data rules

Official name: Real Decreto 1613/2011, de 14 de noviembre, por el que se desarrolla la Ley 13/2011 de regulacion del juego, en lo relativo a los requisitos tecnicos de las actividades de juego · BOE-A-2011-17835 · Directly binding regulation

In forceYes, with paperwork

Spain does NOT require an online gambling operator's central gaming system to sit in Spain. The decree says the opposite, 'regardless of its location'. What it demands is live monitoring from Spain, inspection access anywhere in the world, and a Spanish website. The regulator does hold an unused power to order named secondary systems into Spain.

In force since 16 November 2011

Enforced by Directorate General for the Regulation of Gambling

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed

Applies to every company1 rule

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: Ley Organica 3/2018, de 5 de diciembre, de Proteccion de Datos Personales y garantia de los derechos digitales · BOE-A-2018-16673 · Act of parliament

In forceYes, with paperwork

Spain's national privacy law, sitting on top of Europe's. Four parts stand out. The digital consent age is fourteen. You must lock data away rather than delete it. A much longer list of organisations must appoint a data protection officer. And public bodies get warnings instead of fines.

In force since 7 December 2018

Enforced by Spanish Data Protection Agency

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Government sign-off needed

Applies across the European Union2 rules

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: Reglamento (UE) 2016/679 — Reglamento General de Proteccion de Datos · Regulation (EU) 2016/679 · Directly binding regulation

In forceYes, with paperwork

Europe's general data protection law. It does not say where data must be stored. It says what you must have in place before personal data leaves Europe. It applies to companies outside Europe that target people in Spain.

In force since 24 May 2016Enforced from 25 May 2018

Enforced by Spanish Data Protection Agency

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

Cloud and outsourcing rules (2027)

Official name: Data Act — Reglamento (UE) 2023/2854 · Regulation (EU) 2023/2854 · Directly binding regulation

In forceYes — store it anywhere

This is not about where data sits. It is about being able to move it. From 12 January 2027 no cloud provider may charge you to switch away or to pull your data out. It also pushes back on non-European government demands for data held in Europe.

In force since 12 September 2025In force now, but not enforced until 12 January 2027

That is a long gap: the duty is real law today, but no penalty can follow until 12 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.

How this country controls where data goes: No restriction

Who you would hear from

  • Agencia Espanola de Proteccion de Datos

    General data protection law across Spain, private sector and central government

    Fully staffed, and among the highest-volume enforcers in Europe. Its public database held 46,925 decisions on 18 August 2026. The most recent was signed on 12 August 2026. It is chaired by Lorenzo Cotino. Note that the national law bars cash fines against public bodies, so its power to fine is aimed at private companies.

  • Autoritat Catalana de Proteccio de Dades

    Public bodies and public-sector contractors in Catalonia

    Its site was publishing continuously through July 2026. The director is Meritxell Borras i Sole.

  • Datuak Babesteko Euskal Bulegoa / Agencia Vasca de Proteccion de Datos

    Public bodies in the Basque Country

    Named in the national law as a responsible authority. We did not separately check its 2026 output. See the unconfirmed list.

  • Consejo de Transparencia y Proteccion de Datos de Andalucia

    Public bodies in Andalusia

    Named in the national law as a responsible authority. We did not separately check its 2026 output.

  • Centro Criptologico Nacional / CCN-CERT

    Public-sector cyber security, the National Security Framework, and its binding technical guides

    It issues and maintains the CCN-STIC technical guides. Those guides carry the real cloud rules, and the rules on which country's law applies to public-sector data.

  • Instituto Nacional de Ciberseguridad (INCIBE-CERT)

    Cyber incident response for private operators and citizens

  • Secretaria General de Administracion Digital

    Public-sector digital administration, including the location rule for state-held data

  • Direccion General de Ordenacion del Juego

    Online gambling licensing and technical system approval

    So the gambling rules here come from the official gazette instead of the regulator's own site.

  • Banco de Espana

    Banking and payments supervision

  • Comision Nacional del Mercado de Valores

    Securities markets and investment firms

  • Direccion General de Seguros y Fondos de Pensiones

    Insurance and reinsurance supervision, including outsourcing approvals

  • SEPBLAC

    Money laundering and terrorist financing prevention

  • Comision Nacional de los Mercados y la Competencia

    Telecommunications and competition

  • Agencia Espanola de Supervision de la Inteligencia Artificial

    Artificial intelligence supervision

    Confirmed active. It met the data protection agency in July 2026 to coordinate on test environments, biometrics and elections.

  • Ministerio de Sanidad

    National health system policy; clinical records are largely run by the regions

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That no Spanish law transposing the second Network and Information Security Directive was in force on 18 August 2026

    We found no Spanish law bringing Europe's newer cybersecurity directive into national law, but we could not confirm this against a complete index. We searched the official gazette's consolidated national legislation by title. That returned only university degree programmes for 'ciberseguridad' and nothing for 'seguridad de las redes' after 2022. A law published in the days before our check, or one with a different title, would not have shown up. Treat this as strong but not conclusive.

  • That no organic law on protecting minors in digital environments, and no national artificial intelligence governance act, were in force on 18 August 2026

    We found no Spanish artificial intelligence act and no law on children in digital environments. We used the same title search, with the same limits. Both have been widely reported as government bills. Nothing matching appeared in the gazette's consolidated legislation.

  • The precise data-location requirements applying to public-sector cloud services

    We could not confirm the real cloud rules for the Spanish public sector. The public-sector security decree itself contains no rule on where data must sit. It hands that question to a CCN-STIC technical guide from the National Cryptologic Centre. That guide is distributed through a restricted portal we could not open. The real limits on public-sector cloud may therefore be stricter than the decree text suggests.

  • Whether Spain's twelve-month telecoms retention law is still safely enforceable after Europe's court struck down the directive it implements

    We could not confirm whether Spain's telecoms data retention law still stands after European case law. The law has not been repealed or amended, and Spanish courts still apply it. We found no Spanish court or regulator source that settles the tension. We record it as in force at medium confidence, rather than as no longer applied.

  • That the Basque and Andalusian data protection authorities are actively issuing decisions in 2026

    We could not confirm 2026 activity for the Basque and Andalusian authorities. Both are named in the national law and we have no reason to doubt they operate. We checked 2026 activity only for the national agency and the Catalan authority.

  • Any banking, payments or securities data-location rule in Spain

    We found no rule forcing Spanish bank or securities data to stay in the country, but we could not check every source. We looked at the securities markets act and the anti-money-laundering act on 18 August 2026 and found nothing. We did not reach the Bank of Spain's own circulars, because its page on the European digital operational resilience rules returned a 404 error. Those European rules now override national banking IT rules, so the chance of a missed Spanish rule is low but not zero.

  • Any mapping, geospatial or aerial-imagery localisation rule in Spain

    We found no rule restricting Spanish mapping or aerial photography data. We searched the gazette by title for 'fotografia aerea' and 'cartografia' on 18 August 2026 and found nothing of the kind. Restrictions could sit in defence ministry orders that are not in the consolidated legislation database. We record this as no rule found, not as no rule existing.

  • The exact commencement date of the insurance supervision act's outsourcing article

    We could not confirm the exact start date for the Spanish insurance outsourcing duty. We recorded 1 January 2016, the general start date for the European Solvency II insurance rules in Spain. We did not confirm a specific date from the text itself.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.