Skip to the content
Global Data RulesData governance rules, country by country

Spain

Part of the European Union, so bloc-wide rules apply here too. Checked today.

The answer

Depends on your industryWork: HighEnforcement: Aggressive

Spain follows the normal European rule: personal data may leave the country once you have the right paperwork in place. But four named categories of data held by the Spanish state must physically stay inside the European Union, and may only travel further to a country Europe has officially approved. Spain's privacy regulator is one of the busiest in the world.

Eight questions about Spain

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Spain's rules apply to my company?

Yes. A company with no office in Spain is still caught if it offers goods or services to people in Spain or watches what they do online. There is no size or revenue threshold to hide under. If you have no base anywhere in Europe you must appoint a written representative inside Europe, and Spain's regulator will happily deal with that representative instead of you.

High confidenceNational rulesAppoint a local representative

Can I store my users' data outside Spain?

For most businesses, yes, with paperwork — the ordinary European rules apply and nothing in Spanish law says data must sit on Spanish soil. The exception is sharp. If the data is the electoral roll, a town-hall population register, Spanish tax records, or information about users of the Spanish national health service, the computers holding it must be inside the European Union, and that data may only go outside Europe to a country Europe has officially approved. A standard European transfer contract does not work for those four things.

High confidenceDepends on your industryAllowlistKeep the data in the country

What do I need in place before data leaves Spain?

The model is an approved-list one, run at European level, not by Spain. You may send data outside Europe if the destination country is on Europe's approved list, or if you sign Europe's standard contract, or if your corporate group has approved internal rules. The list is real and populated. Spain adds one twist: if you want to use a home-made contract instead of the standard one, you must get written permission from the Spanish regulator first.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesGovernment sign-off needed

Who enforces the rules in Spain, and what can they do?

The Spanish Data Protection Agency, and it is very much awake. Its public decision database held 46,925 decisions when we checked on 18 August 2026, with rulings signed as recently as 12 August 2026. Three regional authorities also enforce, covering public bodies in Catalonia, the Basque Country and Andalusia. Spain's artificial intelligence supervisor is now operating too and met the privacy agency in July 2026 to divide up the work.

High confidenceAggressive

How long do I have to keep the data?

Both directions, and they collide. The longest floor is money laundering records: ten years, and the same law then orders you to destroy them. Business books run six years, clinical records at least five years from the end of each course of treatment, phone and internet connection records twelve months, and the taxman can come back four years. In the other direction Spain does something unusual: when someone asks you to delete their data you must not actually delete it, you must lock it away.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logsLet people delete their data

What happens if there is a breach?

Count three clocks, not one. Everyone has 72 hours to tell the privacy regulator about a personal data breach. Phone and internet providers have only 24 hours under a separate European rule. And if you run something the state treats as an essential service, the cyber clock says report immediately, then send an update within 24 to 48 hours if the incident is critical, or 72 hours if it is very serious, with a final report 20 or 40 days later.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Spain?

Five things that ruin weekends. One: a child can consent at fourteen in Spain, not sixteen, so your global age gate is probably wrong here. Two: 'delete my data' legally means 'lock my data away', so a hard-delete pipeline breaks the law. Three: Spain forces far more organisations to appoint a data protection officer than Europe does, including every school, university, bank, insurer, energy supplier and online gambling operator. Four: misusing someone's personal records is a crime punishable by prison, and companies themselves can be prosecuted. Five: telecoms operators can be ordered to hand over the encryption method they use.

High confidenceGet a parent's consent for childrenAppoint a data protection officerCriminal liabilityChildren's data

What is changing soon in Spain?

The biggest thing is what has not happened. Spain still has not passed the law that brings Europe's new cybersecurity rules into Spanish law, so the old 2018 regime is still what binds — expect that to change and to widen sharply who must report incidents. From 12 January 2027 no cloud provider may charge you to leave or to pull your data out. Watch three switches the government can flip with no consultation: taking over telecoms networks, ordering gambling systems into Spain, and demanding an operator's encryption method.

Medium confidenceIn forceProposed

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    Bloc rules

    Made by a group of countries together. Applies inside every member country.

    2 rules here

  2. Layer 2

    National rules

    Added by this country on top of any bloc rules.

    1 rule here

  3. Layer 3

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    9 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

Bloc rules2 rules

Reglamento (UE) 2016/679 — Reglamento General de Proteccion de Datos

Directly binding regulation · Regulation (EU) 2016/679

In forceYes, with paperwork

Europe's general data protection law. It does not say where data must be stored. It says what you must have in place before personal data leaves Europe, and it applies to companies outside Europe that target people in Spain.

In force since 24 May 2016But only enforceable from 25 May 2018

Enforced by Spanish Data Protection Agency

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

High confidence

Data Act — Reglamento (UE) 2023/2854

Directly binding regulation · Regulation (EU) 2023/2854

In forceYes — store it anywhere

Not about where data sits, but about being able to move it. From 12 January 2027 no cloud provider may charge you to switch away or to pull your data out. It also pushes back on non-European government demands for data held in Europe.

In force since 12 September 2025But only enforceable from 12 January 2027

Transfer model: No restriction

High confidence

National rules1 rule

Ley Organica 3/2018, de 5 de diciembre, de Proteccion de Datos Personales y garantia de los derechos digitales

Act of parliament · BOE-A-2018-16673

In forceYes, with paperwork

Spain's national privacy statute, sitting on top of Europe's. Its distinctive parts are a digital consent age of fourteen, a duty to lock data away rather than delete it, a much longer list of organisations that must appoint a data protection officer, and a rule that public bodies get warnings instead of fines.

In force since 7 December 2018

Enforced by Spanish Data Protection Agency

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Government sign-off needed

High confidence

Industry rules9 rules

Ley 40/2015, de 1 de octubre, de Regimen Juridico del Sector Publico, articulo 46 bis (anadido por el Real Decreto-ley 14/2019)

Act of parliament · BOE-A-2015-10566, art. 46 bis; inserted by BOE-A-2019-15790 art. 4.1 · Government

In forceYes, with paperwork

Spain's one true storage wall. Four categories of state-held data — the electoral roll, town-hall population registers, Spanish tax records, and national health service user data — must be held and processed inside the European Union, and may only leave Europe for a country Europe has officially approved. Standard transfer contracts do not help here.

In force since 6 November 2019But only enforceable from 6 May 2020

Enforced by Secretariat General for Digital Administration

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision

High confidence

Real Decreto 311/2022, de 3 de mayo, por el que se regula el Esquema Nacional de Seguridad

Directly binding regulation · BOE-A-2022-7191 · Government

In forceYes, with paperwork

The security rulebook for anything serving the Spanish public sector, including private contractors' own systems. It does not itself say data must stay in Spain or Europe. Instead it pushes the 'where is the data' question into the National Cryptologic Centre's technical guides, which is where the real answer lives.

In force since 5 May 2022But only enforceable from 5 May 2024

Enforced by National Cryptologic Centre and its incident response team

Transfer model: Approval each time · Accepted routes: Certification scheme

High confidence

Real Decreto 1613/2011, de 14 de noviembre, por el que se desarrolla la Ley 13/2011 de regulacion del juego, en lo relativo a los requisitos tecnicos de las actividades de juego

Directly binding regulation · BOE-A-2011-17835 · Online gaming

In forceYes, with paperwork

The rule most people get backwards. Spain does NOT require an online gambling operator's central gaming system to sit in Spain — the decree says the opposite, 'regardless of its location'. What it demands is live monitoring from Spain, inspection access anywhere in the world, and a Spanish website. The regulator does hold an unused power to order named secondary systems into Spain.

In force since 16 November 2011

Enforced by Directorate General for the Regulation of Gambling

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed

High confidence

Who you would hear from

  • Agencia Espanola de Proteccion de Datos

    General data protection law across Spain, private sector and central government

    Fully staffed and among the highest-volume enforcers in Europe. 46,925 decisions in its public database on 18 August 2026, most recent signed 12 August 2026. Chaired by Lorenzo Cotino. Note that Article 77 of the national statute bars cash fines against public bodies, so its fining power is aimed at the private sector.

  • Autoritat Catalana de Proteccio de Dades

    Public bodies and public-sector contractors in Catalonia

    Site publishing continuously through July 2026; director Meritxell Borras i Sole.

  • Datuak Babesteko Euskal Bulegoa / Agencia Vasca de Proteccion de Datos

    Public bodies in the Basque Country

    Named in the national statute as a competent authority. Its 2026 output was not separately re-verified in this run — see the unconfirmed list.

  • Consejo de Transparencia y Proteccion de Datos de Andalucia

    Public bodies in Andalusia

    Named in the national statute as a competent authority. Its 2026 output was not separately re-verified in this run.

  • Centro Criptologico Nacional / CCN-CERT

    Public-sector cyber security, the National Security Framework, and its binding technical guides

    Issues and maintains the CCN-STIC technical guides that carry the real cloud and data-jurisdiction requirements for public-sector systems.

  • Instituto Nacional de Ciberseguridad (INCIBE-CERT)

    Cyber incident response for private operators and citizens

  • Secretaria General de Administracion Digital

    Public-sector digital administration, including the location rule for state-held data

  • Direccion General de Ordenacion del Juego

    Online gambling licensing and technical system approval

    Its website returned a server error (HTTP 503) on 18 August 2026, so the gambling rules here are sourced from the official gazette instead of the regulator's own site.

  • Banco de Espana

    Banking and payments supervision

  • Comision Nacional del Mercado de Valores

    Securities markets and investment firms

  • Direccion General de Seguros y Fondos de Pensiones

    Insurance and reinsurance supervision, including outsourcing approvals

  • SEPBLAC

    Money laundering and terrorist financing prevention

  • Comision Nacional de los Mercados y la Competencia

    Telecommunications and competition

  • Agencia Espanola de Supervision de la Inteligencia Artificial

    Artificial intelligence supervision

    Confirmed active: met the data protection agency in July 2026 to coordinate on sandboxes, biometrics and elections.

  • Ministerio de Sanidad

    National health system policy; clinical records are largely run by the regions

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That no Spanish law transposing the second Network and Information Security Directive was in force on 18 August 2026

    This is a negative. It rests on a title search of the official gazette's consolidated national legislation, which returned only university degree programmes for 'ciberseguridad' and nothing for 'seguridad de las redes' after 2022. A transposing act published in the days before this run, or one titled differently, would not have surfaced. Treat as strong but not conclusive.

  • That no organic law on protecting minors in digital environments, and no national artificial intelligence governance act, were in force on 18 August 2026

    Same method, same limitation. Both have been widely reported as government bills. Nothing matching was found in the gazette's consolidated legislation.

  • The precise data-location requirements applying to public-sector cloud services

    The National Security Framework decree itself contains no location rule; it delegates 'jurisdiction of the data' to a CCN-STIC technical guide issued by the National Cryptologic Centre. We could not open the current guide, which is distributed through a restricted portal. The practical wall for public-sector cloud may therefore be stricter than the decree text suggests.

  • Whether Spain's twelve-month telecoms retention law is still safely enforceable after Europe's court struck down the directive it implements

    The law is unrepealed and unamended and Spanish courts continue to apply it, but we found no Spanish court or regulator source in this run that squarely resolves the tension with European case law. Recorded as in force with medium confidence rather than as disapplied.

  • That the Basque and Andalusian data protection authorities are actively issuing decisions in 2026

    Both are named in the national statute and we have no reason to doubt they operate, but we verified 2026 activity only for the national agency and the Catalan authority in this run.

  • Any banking, payments or securities data-location rule in Spain

    None found in the securities markets act or in the anti-money-laundering act, checked 18 August 2026. We did not reach the Bank of Spain's own circulars — its DORA supervision page returned a 404. Since the EU digital operational resilience regulation now overrides national banking IT rules, the risk of a missed Spanish rule is low but not zero.

  • Any mapping, geospatial or aerial-imagery localisation rule in Spain

    A gazette title search for 'fotografia aerea' and 'cartografia' on 18 August 2026 returned nothing of the kind. Restrictions could sit in defence ministry orders that are not in the consolidated legislation database. Recorded as no rule found rather than as no rule existing.

  • The exact commencement date of the insurance supervision act's outsourcing article

    We recorded 1 January 2016, the general commencement of the Solvency II regime in Spain, rather than a provision-specific date confirmed from the text.

60-day cadence. Spain holds four dormant switches that can flip with no consultation: the gambling regulator's power to order systems into Spain, the government's power to take over telecoms networks, the state's power to demand an operator's encryption method, and the ability to widen the Article 46 bis location wall by another decree-law exactly as it was created. The overdue cybersecurity transposition is also expected within this window.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.