Spain
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Spain — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Spain follows the normal European rule. Personal data may leave the country once you have the right paperwork in place. But four named kinds of data held by the Spanish state must stay inside the European Union. They may only travel further to a country Europe has officially approved as safe enough. Spain's privacy regulator is one of the busiest in the world.
Data governance in Spain
The eight things that decide how you handle data about people in Spain. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. A company with no office in Spain is still covered if it offers goods or services to people in Spain. The same applies if it watches what people in Spain do online. There is no size or revenue level below which you are free. If you have no base anywhere in Europe, you must appoint a written representative inside Europe. Spain's regulator will deal with that representative instead of you.
- What you have to do here:
- Appoint a representative
Two layers stack here. The European layer is the General Data Protection Regulation, Regulation (EU) 2016/679. It sets the reach test and the duty to name a representative in Europe. The Spanish layer is Ley Organica 3/2018 (LOPDGDD). It stretches the Spanish law to cover uses of data that the European rules do not reach directly, such as activities outside European Union law. It also leaves out anything covered by classified-information rules. That is the exit door for the defence industry. Spain has no separate registration, licence or filing before you may start using personal data.
Sources
- Official sourceBoletin Oficial del EstadoLey Organica 3/2018 on data protection and the guarantee of digital rights, Article 2 (scope)
boe.es
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionGeneral Data Protection Regulation, Articles 3 and 27
eur-lex.europa.eu
Link checked 18 August 2026
Where the data is allowed to live
For most businesses, yes, with paperwork. The ordinary European rules apply. Nothing in Spanish law says data must sit on Spanish soil. The exception is sharp. Four kinds of data must be held on computers inside the European Union. They are the electoral roll, town-hall population registers, Spanish tax records, and information about users of the Spanish national health service. That data may only go outside Europe to a country Europe has officially approved as safe enough. Europe's standard transfer contract does not work for those four things.
- What you have to do here:
- Keep the data in the country
The ban comes from Ley 40/2015, as amended by Real Decreto-ley 14/2019 on public-security grounds. Public security is the one ground that Regulation (EU) 2018/1807 leaves open to member states. The Spanish text reads: 'Los sistemas de informacion y comunicaciones para la recogida, almacenamiento, procesamiento y gestion del censo electoral, los padrones municipales de habitantes y otros registros de poblacion, datos fiscales relacionados con tributos propios o cedidos y datos de los usuarios del sistema nacional de salud, asi como los correspondientes tratamientos de datos personales, deberan ubicarse y prestarse dentro del territorio de la Union Europea.' Industry by industry, on top of the national position: - Government and public-sector suppliers: data can leave only if conditions are met European Union location is compulsory for the four kinds of data above. Any system sold into the Spanish public sector must also be certified against Spain's national security standard for public bodies, the Esquema Nacional de Seguridad. - Health: data can leave only if conditions are met in general. For national health service user data it is conditional with EU wall, because of the four-category rule. Private clinics outside the national health service are not covered by that rule. - Online gambling: data can leave only if conditions are met The technical decree expressly allows the operator's central gaming unit and its backup to sit anywhere in the world. What it demands is real-time monitoring from Spain, physical inspection access, and a Spanish '.es' website. The regulator does hold a live power to order named secondary systems into Spain. - Telecoms: data can leave only if conditions are met Connection records must be kept for twelve months. No rule says where. - Banking, payments, securities, insurance: data can leave only if conditions are met We found no location rule in the Spanish laws, checked 18 August 2026. Insurance outsourcing is controlled instead by advance notice and a right to veto. - Mapping and location data: we found no rule forcing data to stay in the country, checked 18 August 2026, medium confidence. - Defence and classified material: outside the data protection law entirely. It is governed by the 1968 Official Secrets Act.
Sources
- Official sourceBoletin Oficial del EstadoLey 40/2015 on the legal regime of the public sector, Article 46 bis — location of information systems
boe.es
“deberan ubicarse y prestarse dentro del territorio de la Union Europea. Los datos a que se refiere el apartado anterior no podran ser objeto de transferencia a un tercer pais u organizacion internacional, con excepcion de los que hayan sido objeto de una decision de adecuacion de la Comision Europea”
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoReal Decreto-ley 14/2019 on urgent public-security measures in digital administration, Article 4 and second transitional provision
boe.es
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoReal Decreto 1613/2011 on technical requirements for gambling activity, Articles 13 and 14
boe.es
“La Unidad Central de Juegos y su replica, con independencia de su ubicacion, deberan poder ser monitorizadas desde territorio espanol”
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
You can only send data to approved countries, and Europe keeps the list, not Spain. You may send data outside Europe in three ways. The destination country is on Europe's approved list. Or you sign Europe's standard contract. Or your corporate group has approved internal rules. The list is real and has countries on it. Spain adds one twist. If you want to use a contract you wrote yourself instead of the standard one, you must get written permission from the Spanish regulator first.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Government sign-off needed
Ley Organica 3/2018 adds Spanish procedure on top of the European rules. The Spanish Agency can adopt its own standard clauses and approve group-wide internal rules. So can the regional authorities in Catalonia, the Basque Country and Andalusia. Group-wide rules take up to nine months to approve. You need permission in advance for a contract you wrote yourself, and for certain transfers by public bodies. If you rely on the narrow 'compelling legitimate interests' route, you must tell the regulator in advance and tell the affected people too. The approved list is the European one, unchanged. It covers Andorra, Argentina, Brazil, Canada (commercial bodies), Faroe Islands, Guernsey, Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom, Uruguay, and the United States only for organisations signed up to the EU-US Data Privacy Framework. None has been withdrawn or suspended as at 18 August 2026. For the four kinds of state-held data it works the other way round. Standard contracts and group-wide rules are not available. Only the approved list works.
Sources
- Official sourceBoletin Oficial del EstadoLey Organica 3/2018, Articles 40 to 43 — international transfers, prior authorisation and prior information
boe.es
“Las transferencias internacionales de datos a paises u organizaciones internacionales que no cuenten con decision de adecuacion aprobada por la Comision ... requeriran una previa autorizacion de la Agencia Espanola de Proteccion de Datos”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Implementing Decision (EU) 2021/914 — standard contractual clauses
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Spanish Data Protection Agency, and it is very active. Its public decision database held 46,925 decisions when we checked on 18 August 2026. Some rulings were signed as recently as 12 August 2026. Three regional authorities also enforce. They cover public bodies in Catalonia, the Basque Country and Andalusia. Spain's artificial intelligence supervisor is now operating too. It met the privacy agency in July 2026 to divide up the work.
The Agencia Espanola de Proteccion de Datos (AEPD) is chaired by Lorenzo Cotino. It publishes press releases, guidance and decisions continuously. Items dated 9, 14, 15, 20, 21, 23, 27 and 28 July 2026 were live on its site. It is consistently among the highest-volume enforcers in Europe. We rate it aggressive. It runs a fast channel for urgent takedowns of intimate images. It opens investigations on its own initiative. Its published caseload is dominated by finance and insurance (9,928 decisions), information and communications (8,435) and video surveillance (7,072). One big exception. Under Ley Organica 3/2018, Spanish public bodies, the Bank of Spain, public universities and similar entities are not fined. They get a warning and an order to fix the problem. So the power to fine is aimed at private companies. The Catalan authority (Autoritat Catalana de Proteccio de Dades) is led by Meritxell Borras. It was publishing through July 2026. The Basque and Andalusian authorities exist and are named in the law. We did not separately check their 2026 output. Other regulators also enforce: the Bank of Spain, the securities commission CNMV, the insurance directorate DGSFP, the gambling directorate DGOJ, the telecoms and competition authority CNMC, the National Cryptologic Centre for public-sector cyber incidents, and INCIBE for everyone else.
Sources
- Official sourceAgencia Espanola de Proteccion de DatosAEPD published decisions database — 46,925 results, most recent signed 12 August 2026
aepd.es
Link checked 18 August 2026
- Official sourceAgencia Espanola de Proteccion de DatosAEPD press releases, July 2026 — artificial intelligence data quality analysis, coordination with the AI supervisor AESIA, public-sector compliance recommendations
aepd.es
Link checked 18 August 2026
- Official sourceGeneralitat de CatalunyaAutoritat Catalana de Proteccio de Dades — active site with items dated July 2026
apdcat.gencat.cat
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoLey Organica 3/2018, Article 77 — public bodies are warned, not fined
boe.es
Link checked 18 August 2026
How long you must keep it — and when to delete it
There are both minimum and maximum keep-times, and they clash. The longest minimum is money laundering records: ten years. The same law then orders you to destroy them. Business books run six years. Clinical records run at least five years from the end of each course of treatment. Phone and internet connection records run twelve months. The tax office can come back four years. Spain also does something unusual. When someone asks you to delete their data, you must not actually delete it. You must lock it away.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Let people delete their data
MINIMUM KEEP-TIMES: - Money laundering: ten years for customer checks and transaction records, under Ley 10/2010. After five years only internal compliance staff and legal defence staff may open the file. At ten years you must delete it. The law says 'procediendo tras el mismo a su eliminacion'. This is one of the few real deadlines to delete in Spanish law. - Business books and correspondence: six years from the last accounting entry, under the Commercial Code. - Clinical records: at least five years from discharge for each episode of care, under Ley 41/2002. Birth-related records are never destroyed. Several regions set longer periods in their own health laws. - Telecoms connection records: twelve months, under Ley 25/2007. A regulation can move this between six months and two years. - Tax: the authorities' right to assess runs out after four years, under Ley 58/2003. So four years is the working minimum for tax paperwork. MAXIMUM KEEP-TIMES: Ley Organica 3/2018 creates a duty to 'block' data. When you correct or erase, you must isolate the record. You must make it invisible to normal use. You keep it available only to courts, prosecutors and regulators until the relevant time limit runs out. Then you destroy it. If your system cannot do this, you must write that down and fix it at your next major upgrade. A system where delete means delete does not comply in Spain. CLASHES: the minimum keep-time set for your industry beats a person's request to erase. The blocking rule is what bridges the gap.
Sources
- Official sourceBoletin Oficial del EstadoLey 10/2010 on money laundering prevention, Article 25 — ten years then mandatory destruction
boe.es
“Los sujetos obligados conservaran durante un periodo de diez anos la documentacion en que se formalice el cumplimiento de las obligaciones establecidas en la presente ley, procediendo tras el mismo a su eliminacion.”
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoCodigo de Comercio, Article 30 — six years of books and correspondence
boe.es
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoLey 41/2002 on patient autonomy, Article 17 — minimum five years of clinical documentation
boe.es
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoLey Organica 3/2018, Article 32 — the duty to block rather than delete
boe.es
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoLey 58/2003 General Tributaria, Article 66 — four-year tax limitation period
boe.es
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
There are three separate deadlines. Everyone has 72 hours to tell the privacy regulator about a personal data breach. Phone and internet providers have only 24 hours under a separate European rule. If you run something the state treats as an essential service, the cyber deadline is different again. You report immediately. Then you send an update within 24 to 48 hours if the incident is critical, or 72 hours if it is very serious. A final report follows 20 or 40 days later.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Deadline one, privacy. Regulation (EU) 2016/679 gives you 72 hours from becoming aware. The Spanish regulator confirms this on its own breach page. You notify the Spanish agency if your only office is in Spain, or if Spain hosts your main European office. If the risk to people is high, you must also tell them without undue delay. Deadline two, telecoms. Commission Regulation (EU) 611/2013 gives providers of public electronic communications services 24 hours from detection to send a first notice. It applies directly and is easy to miss, because it sits outside the main European privacy rules. Deadline three, cyber. Real Decreto 43/2021, together with Real Decreto-ley 12/2018, covers operators of essential services and digital service providers. The national instruction sets the timetable. The first notice is immediate for CRITICAL, VERY HIGH and HIGH incidents. The interim report is due at 24 to 48 hours for critical incidents, or 72 hours for very high ones. The final report is due at 20 days for critical, or 40 days for very high. You report through the National Platform for Cyber Incident Notification. That goes to the National Cryptologic Centre for public bodies, or INCIBE for private operators. The overlap is where people fail. A ransomware attack on a Spanish telecoms operator sets off all three at once, on three different forms, to two or three different bodies.
Sources
- Official sourceAgencia Espanola de Proteccion de DatosAEPD guidance on notifying personal data breaches to the supervisory authority
aepd.es
“El plazo para notificar a la autoridad de control es de 72 horas desde que la organizacion tiene constancia de la brecha.”
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoReal Decreto 43/2021, annex — national instruction on cyber incident notification, reporting window table
boe.es
“Ventana temporal de reporte. Nivel de peligrosidad o impacto / Notificacion inicial / Notificacion intermedia / Notificacion final. CRITICO. Inmediata. 24/48 horas. 20 dias. MUY ALTO. Inmediata. 72 horas. 40 dias.”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Regulation (EU) No 611/2013 — 24-hour breach notification for electronic communications providers
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things catch people out. One: a child can consent at fourteen in Spain, not sixteen. Your global age gate is probably wrong here. Two: 'delete my data' legally means 'lock my data away'. A system that hard-deletes breaks the law. Three: Spain forces far more organisations to appoint a data protection officer than Europe does. That includes every school, university, bank, insurer, energy supplier and online gambling operator. Four: misusing someone's personal records is a crime that can mean prison. Companies themselves can be prosecuted too. Five: telecoms operators can be ordered to hand over the encryption method they use.
- What you have to do here:
- Get a parent's consent for children · Appoint a data protection officer
- What it costs if you get it wrong:
- Criminal liability
1. Age of consent. Ley Organica 3/2018 sets it at fourteen. Below fourteen you need a parent or guardian. Most global products are built to sixteen or thirteen. Both are wrong for Spain. 2. Blocking. The same law says data you correct or erase must be identified, set aside and made unavailable to everything except courts, prosecutors and regulators. It stays that way for as long as someone could still bring a claim. Only then do you destroy it. If your system cannot do this, you must write that down and fix it at the next major overhaul. 3. Compulsory data protection officers. The law lists sixteen kinds of organisation on top of the European test. They are professional colleges, all schools and universities, telecoms operators handling data at large scale, online services that profile users at large scale, credit institutions, financial credit establishments, insurers and reinsurers, investment firms, electricity and gas retailers and distributors, credit-scoring and fraud-prevention file operators, advertising and market research firms that profile people, health centres that keep clinical records, commercial-report issuers, and electronic gambling operators. 4. Criminal liability. The Criminal Code punishes taking, using or altering another person's private personal data held in any file, to their harm. The penalty is one to four years in prison plus a fine. The Code also makes the company itself liable. This is a prosecution, not an administrative fine, and it attaches to named individuals. 5. Handing over encryption. Ley 11/2022 lets the state require an electronic communications operator to hand over the algorithms or any encryption method it uses. It must also hand over cipher equipment free of charge. This applies where essential state security, public security or a criminal investigation justifies it. One more trap. Real Decreto-ley 14/2019 limited the use of blockchain systems in dealings with Spanish public bodies. That covers using blockchain to identify people and to sign. It is allowed only if the central government acts as an intermediate authority. Teams building blockchain identity for Spanish public-sector work walk into this without warning.
Sources
- Official sourceBoletin Oficial del EstadoLey Organica 3/2018, Articles 7, 32 and 34 — age fourteen, data blocking, mandatory data protection officers
boe.es
“El tratamiento de los datos personales de un menor de edad unicamente podra fundarse en su consentimiento cuando sea mayor de catorce anos.”
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoLey Organica 10/1995 Criminal Code, Articles 197 and 197 quinquies
boe.es
“Las mismas penas se impondran al que, sin estar autorizado, se apodere, utilice o modifique, en perjuicio de tercero, datos reservados de caracter personal o familiar de otro que se hallen registrados en ficheros o soportes informaticos”
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoLey 11/2022 General Telecommunications Act, Article 62 — encryption in networks and services
boe.es
“se podra imponer la obligacion de facilitar a un organo de la Administracion General del Estado o a un organismo publico, los algoritmos o cualquier procedimiento de cifrado utilizado”
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoReal Decreto-ley 14/2019 — restriction on distributed ledger identification systems in public administration
boe.es
Link checked 18 August 2026
What's changing next
The biggest thing is what has not happened. Spain still has not passed the law that brings Europe's new cybersecurity rules into Spanish law. So the old 2018 rules are what bind you today. Expect that to change, and to sharply widen who must report incidents. From 12 January 2027 no cloud provider may charge you to leave or to pull your data out. Also watch three powers the government can use with no consultation. It can take over telecoms networks. It can order gambling systems into Spain. And it can demand an operator's encryption method.
Confirmed gaps and dates: - Europe's second network and information security directive: we searched the official gazette's consolidated national legislation on 18 August 2026. We found no Spanish law bringing it in. What binds today is Real Decreto-ley 12/2018 and Real Decreto 43/2021. When the new law lands it will expand the list of covered industries, add personal liability for managers, and change the reporting deadlines. Treat today's comfort as temporary. - No Spanish artificial intelligence governance act appears in the gazette either. The supervisory agency AESIA is up and running and coordinating with the privacy regulator as of July 2026. The EU AI Act's transparency duties started on 2 August 2026 anyway. - No law on protecting children in digital environments appears in the gazette as at 18 August 2026. If it passes, it is expected to move the fourteen-year consent age. - Data Act (EU) 2023/2854: cloud switching charges and data export fees must be zero from 12 January 2027. Powers the government can use today, with no new law: 1. Ley 11/2022 lets the government take over the direct running of electronic communications services or networks, for public and national security. This is meant to be exceptional and temporary. There is no notice and no consultation. 2. Real Decreto 1613/2011 lets the gambling regulator require an operator to place named secondary systems inside Spain. It is not used as a general rule today. If it were used, it would force data into Spain overnight. 3. Ley 11/2022 lets the state demand the encryption algorithms and methods an operator uses. 4. The four-category rule in Ley 40/2015 is built around public security and is expressly temporary, 'until progress is made within the European Union'. It could be widened by another decree-law with immediate effect, exactly as it was created. 5. At European level, the EU-US Data Privacy Framework is still valid. But on 31 July 2026 the European Data Protection Board formally asked the Commission to examine whether it should stand. Any Spanish setup that relies on it alone should have a backup plan.
Sources
- Official sourceBoletin Oficial del EstadoBoletin Oficial del Estado consolidated national legislation search, run 18 August 2026 — no NIS2 transposing act, no artificial intelligence governance act, no minors-in-digital-environments organic law
boe.es
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoLey 11/2022, Article 4(6) — emergency state takeover of electronic communications networks and services
boe.es
“El Gobierno, con caracter excepcional y transitorio, podra acordar la asuncion por la Administracion General del Estado de la gestion directa de determinados servicios de comunicaciones electronicas disponibles al publico”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionData Act (EU) 2023/2854 — zero switching and egress charges from 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Diarise 12 January 2027 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries9 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Government data must stay in the country
Official name: Ley 40/2015, de 1 de octubre, de Regimen Juridico del Sector Publico, articulo 46 bis (anadido por el Real Decreto-ley 14/2019) · BOE-A-2015-10566, art. 46 bis; inserted by BOE-A-2019-15790 art. 4.1 · Act of parliament
Spain's one real ban on moving data. Four kinds of state-held data must be held and used inside the European Union. They are the electoral roll, town-hall population registers, Spanish tax records, and national health service user data. That data may only leave Europe for a country Europe has officially approved as safe enough. Europe's standard transfer contract does not help here.
Enforced by Secretariat General for Digital Administration
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision
What you have to do
- Keep the data in the country — applies at: Electoral roll, municipal population registers and other population registers, tax data on Spain's own and ceded taxes, and data on users of the national health service, from 6 May 2020The systems, and the use of the data, must sit inside the European Union. Systems run directly by the state had six months from 6 November 2019. Contracted systems had to adapt at renewal or re-tender.
- Put a transfer safeguard in placeEurope's standard contract and group-wide internal rules are NOT available for this data. You can only send it out of the European Union to a country Europe has officially decided is safe enough. A treaty that binds Spain also works.
What it costs if you get it wrong
- Order to stopNon-compliant public contracts can be challenged and the arrangement unwound; the underlying processing also breaches the data protection statute.
Sources
- Official sourceBoletin Oficial del EstadoLey 40/2015, Article 46 bis — location of information and communications systems for data registration
boe.es
“deberan ubicarse y prestarse dentro del territorio de la Union Europea”
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoReal Decreto-ley 14/2019, Article 4.1 and second transitional provision — six months to comply, adaptation at contract renewal
boe.es
Link checked 18 August 2026
Government data needs a sovereign cloud
Official name: Real Decreto 311/2022, de 3 de mayo, por el que se regula el Esquema Nacional de Seguridad · BOE-A-2022-7191 · Directly binding regulation
The security rulebook for anything serving the Spanish public sector, including private contractors' own systems. It does not itself say data must stay in Spain or Europe. Instead it hands the question of where data sits to the National Cryptologic Centre's technical guides. That is where the real answer lives.
Enforced by National Cryptologic Centre and its incident response team
How this country controls where data goes: Approval each time · Accepted routes: Certification scheme
What you have to do
- Hold a security certificate — applies at: Any system serving a Spanish public body, including systems owned by private contractors, from 5 May 2024You must show you comply with a formal conformity mark. Medium and high category systems need certification, not just a self-declaration.
- Prove the data stays under local controlOutside cloud services must meet Spain's public-sector security standard, or a National Cryptologic Centre technical guide. Those guides cover penetration testing, transparency, encryption and key management, and which country's law applies to the data.
- Independent auditRegular audits, plus a signed statement of which measures apply to you.
What it costs if you get it wrong
- Order to stopLoss of the conformity mark disqualifies a supplier from public contracts; there is no direct cash fine in the decree.
Sources
- Official sourceBoletin Oficial del EstadoReal Decreto 311/2022, Annex II measure op.nub.1 and sole transitional provision
boe.es
“Cuando se utilicen servicios en la nube suministrados por terceros, los sistemas de informacion que los soportan deberan ser conformes con el ENS o cumplir con las medidas desarrolladas en una guia CCN-STIC que incluira, entre otros, requisitos relativos a: a) Auditoria de pruebas de penetracion. b) Transparencia. c) Cifrado y gestion de claves. d) Jurisdiccion de los datos.”
Link checked 18 August 2026
Online gaming data rules
Official name: Real Decreto 1613/2011, de 14 de noviembre, por el que se desarrolla la Ley 13/2011 de regulacion del juego, en lo relativo a los requisitos tecnicos de las actividades de juego · BOE-A-2011-17835 · Directly binding regulation
Spain does NOT require an online gambling operator's central gaming system to sit in Spain. The decree says the opposite, 'regardless of its location'. What it demands is live monitoring from Spain, inspection access anywhere in the world, and a Spanish website. The regulator does hold an unused power to order named secondary systems into Spain.
Enforced by Directorate General for the Regulation of Gambling
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the country — applies at: Only if the regulator exercises its power — 'determinadas unidades secundarias de sus sistemas tecnicos se ubiquen en Espana'A power the regulator can use at any time. It can order named secondary systems into Spain. It has not used this as a general requirement, so we record it as an unused power rather than a live rule.
- Keep logsAn internal control system must capture and record every gaming operation, and every money movement between players and the central gaming unit.
- Independent auditYou need type approval of the technical system, valid for ten years. You must also allow physical inspection wherever the equipment sits.
- Register or notifyPlay by or for people in Spain must be served from the operator's own '.es' website. Traffic from Spain to the group's other web addresses must be redirected there.
What it costs if you get it wrong
- Loss of your licenceOperating without an approved technical system, or refusing inspection access.
Sources
- Official sourceBoletin Oficial del EstadoReal Decreto 1613/2011, Articles 13, 14 and 15
boe.es
“el operador debera garantizar el acceso y la inspeccion de la Unidad Central de Juegos con independencia de su ubicacion fisica ... y cualquiera que sea el pais en que estos estuvieran ubicados. ... la Comision Nacional del Juego podra requerir al operador de juego que determinadas unidades secundarias de sus sistemas tecnicos se ubiquen en Espana.”
Link checked 18 August 2026
Internet and platform rules
Official name: Ley 25/2007, de 18 de octubre, de conservacion de datos relativos a las comunicaciones electronicas y a las redes publicas de comunicaciones · BOE-A-2007-18243 · Act of parliament
Spanish telephone and internet providers must keep records of who called whom for twelve months. They hand them to authorised agents only when a judge orders it. The law says nothing about where those records are stored. It was written to implement a European directive that Europe's top court later struck down. Spain has never repealed or amended it.
Enforced by National Commission on Markets and Competition
How this country controls where data goes: No restriction
What you have to do
- Keep data for a minimum period — 1 yearTwelve months from the date of the communication. A regulation could move this to between six months and two years. None has.
- Keep logsYou hand data over only to named authorised agents, and only with a judge's permission first.
What it costs if you get it wrong
- Fixed maximum fineFailure to retain or to hand over on a judicial order is sanctioned under the telecommunications regime.
Sources
- Official sourceBoletin Oficial del EstadoLey 25/2007, Article 5 — retention period
boe.es
“La obligacion de conservacion de datos impuesta cesa a los doce meses computados desde la fecha en que se haya producido la comunicacion.”
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoLey 11/2022, Article 61 — cross-reference confirming Ley 25/2007 still governs handover to authorised agents
boe.es
Link checked 18 August 2026
Telecoms rules
Official name: Ley 11/2022, de 28 de junio, General de Telecomunicaciones · BOE-A-2022-10757 · Act of parliament
Spain's telecoms law carries two powers that matter to anyone designing a secure network. The state can require an operator to hand over the encryption method it uses. And the government can take over the running of electronic communications networks and services on public or national security grounds, with no consultation.
Enforced by National Commission on Markets and Competition
How this country controls where data goes: No restriction
What you have to do
- Secure the dataOperators must manage network security risks and report significant incidents.
- Do not hand data to foreign authorities on demandThis runs the other way in Spain. An operator must hand the Spanish state its encryption algorithms and methods, and supply cipher equipment free of charge. This applies where essential state security, public security or a criminal investigation justifies it.
What it costs if you get it wrong
- Order to stopArticle 4(6): the government may take over direct management of covered services or networks for public and national security, exceptionally and temporarily.
Sources
- Official sourceBoletin Oficial del EstadoLey 11/2022, Articles 4(6) and 62
boe.es
“se podra imponer la obligacion de facilitar a un organo de la Administracion General del Estado o a un organismo publico, los algoritmos o cualquier procedimiento de cifrado utilizado, en casos justificados de proteccion de los intereses esenciales de seguridad del Estado y la seguridad publica”
Link checked 18 August 2026
State and security data rules
Official name: Ley 10/2010, de 28 de abril, de prevencion del blanqueo de capitales y de la financiacion del terrorismo · BOE-A-2010-6737 · Act of parliament
Spain's money laundering law sets the country's longest minimum keep-time at ten years. It then does something unusual. It orders you to destroy the records once the ten years are up. In between, from year five, the file must be closed off so only compliance and legal defence staff can open it.
Enforced by Spanish financial intelligence unit
How this country controls where data goes: No restriction
What you have to do
- Keep data for a minimum period — 10 yearsTen years for customer identity papers, and for records showing transactions and business relationships.
- Delete data after a period — 10 yearsA rare firm deadline to delete. After ten years you must destroy the records. It is not optional.
- Secure the dataFrom year five to year ten, only internal control and compliance staff, and the people handling the firm's legal defence, may open the file. Ordinary business access must be cut off.
What it costs if you get it wrong
- Fixed maximum fine: Up to €10 million or 10% of annual turnover for very serious breaches (about $11 million at the cash cap) — about $11 millionFailure to keep or to produce required records.
Sources
- Official sourceBoletin Oficial del EstadoLey 10/2010, Article 25 — document retention
boe.es
“Transcurridos cinco anos desde la terminacion de la relacion de negocios o la ejecucion de la operacion ocasional, la documentacion conservada unicamente sera accesible por los organos de control interno del sujeto obligado”
Link checked 18 August 2026
Health data rules
Official name: Ley 41/2002, de 14 de noviembre, basica reguladora de la autonomia del paciente y de derechos y obligaciones en materia de informacion y documentacion clinica · BOE-A-2002-22188 · Act of parliament
Spanish health providers must keep clinical records for at least five years from the end of each course of treatment. Records tied to a patient's birth must never be destroyed. No rule says the records must be in Spain. But if the patients are users of the national health service, the separate public-sector rule applies and pins the data inside Europe.
Enforced by Ministry of Health
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Keep data for a minimum period — 5 yearsAt least five years from the discharge date of each episode of care. Birth-related records, including tests used to establish parentage, are never destroyed.
- Secure the dataYou may keep records in any form, not just the original one, as long as they stay complete and secure.
What it costs if you get it wrong
- Percentage of global turnoverEnforced in practice through the data protection regime, since health data is sensitive data.
Sources
- Official sourceBoletin Oficial del EstadoLey 41/2002, Article 17 — retention of clinical documentation
boe.es
“como minimo, cinco anos contados desde la fecha del alta de cada proceso asistencial”
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoLey 40/2015, Article 46 bis — national health service user data must sit inside the European Union
boe.es
Link checked 18 August 2026
Cyber security rules
Official name: Real Decreto 43/2021, por el que se desarrolla el Real Decreto-ley 12/2018 de seguridad de las redes y sistemas de informacion · BOE-A-2021-1192 · Directly binding regulation
Spain's cyber incident rules for essential services and digital service providers. You report serious incidents immediately, then send follow-up reports on a fixed timetable. These are still the 2018 and 2021 rules. As at 18 August 2026 Spain has not passed a law bringing Europe's newer cybersecurity directive into Spanish law.
Enforced by National Cryptologic Centre and its incident response team
How this country controls where data goes: No restriction
What you have to do
- Report cyber incidents — within 24 hoursThe first notice is 'immediate' for high, very high and critical incidents. The interim report is due at 24 to 48 hours for critical incidents, and 72 hours for very high ones. Final reports are due at 20 and 40 days.
- Publish a complaints contactYou must name an information security officer within three months of being named an essential service operator, and tell the responsible authority who it is.
- Independent auditYou must file a signed statement of which measures apply to you within six months, and review it at least every three years.
What it costs if you get it wrong
- Fixed maximum fine: Up to €1 million for very serious breaches (about $1.1 million) — about $1 millionFailure to notify a significant incident or to adopt required security measures.
Sources
- Official sourceBoletin Oficial del EstadoReal Decreto 43/2021 and its annex, the national cyber incident notification instruction
boe.es
“Ventana temporal de reporte ... CRITICO. Inmediata. 24/48 horas. 20 dias. MUY ALTO. Inmediata. 72 horas. 40 dias. ALTO. Inmediata.”
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Ley 20/2015, de 14 de julio, de ordenacion, supervision y solvencia de las entidades aseguradoras y reaseguradoras, articulo 67 · BOE-A-2015-7897 · Act of parliament
Spanish insurers face no rule about where policyholder data sits. But they cannot quietly move it. Handing a critical job to an outside supplier needs advance notice to the insurance supervisor. The supervisor then has one month to object. Changing cloud provider counts as a significant change.
Enforced by Directorate General for Insurance and Pension Funds
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Written vendor contractYou must tell the insurance supervisor in advance before handing a critical or important job to an outside supplier. You must also report any later significant change of supplier, scope or responsible person.
- Publish a complaints contactA named person inside the insurer must own each outsourced job. They must be qualified to check the supplier's work.
What it costs if you get it wrong
- Order to stopThe supervisor may object within one month, which blocks the arrangement.
Sources
- Official sourceBoletin Oficial del EstadoLey 20/2015, Article 67 — outsourcing of functions
boe.es
“Esta Direccion General podra oponerse a las mismas, en el plazo de un mes desde la recepcion de la comunicacion”
Link checked 18 August 2026
Applies to every company1 rule
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: Ley Organica 3/2018, de 5 de diciembre, de Proteccion de Datos Personales y garantia de los derechos digitales · BOE-A-2018-16673 · Act of parliament
Spain's national privacy law, sitting on top of Europe's. Four parts stand out. The digital consent age is fourteen. You must lock data away rather than delete it. A much longer list of organisations must appoint a data protection officer. And public bodies get warnings instead of fines.
Enforced by Spanish Data Protection Agency
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Government sign-off needed
What you have to do
- Get a parent's consent for children — applies at: Under 14 years old — Spain sets the digital consent age at 14, not 16Spain sets the digital consent age at fourteen. Below that age a parent or guardian must consent.
- Let people delete their dataErasing means locking away. You must isolate the data and keep it invisible to everyone except courts, prosecutors and regulators, until the time limit for claims runs out. Then you destroy it.
- Appoint a data protection officer — applies at: Sixteen listed categories including all schools and universities, telecoms operators, banks, insurers, investment firms, energy retailers, health centres holding clinical records, advertising profilers and online gambling operatorsSpain lists sixteen kinds of organisation on top of the European test.
- Put a transfer safeguard in placeYou need the regulator's permission in advance to use a contract you wrote yourself. You must give advance notice if you rely on the compelling legitimate interest route.
- Tell people what you do
- Keep records of how you use data
What it costs if you get it wrong
- Percentage of global turnover: €20 million or 4% of worldwide group turnover (about $22 million at the floor) — about $22 millionVery serious infringements, which time-bar after three years.
- Criminal liability: One to four years in prison plus a fine, under Criminal Code Article 197Appropriating, using or altering another person's reserved personal data to their detriment. Companies themselves can be prosecuted under Article 197 quinquies.
- Claims by individualsIndividuals may sue for compensation.
Sources
- Official sourceBoletin Oficial del EstadoLey Organica 3/2018, consolidated text
boe.es
Link checked 18 August 2026
- Official sourceBoletin Oficial del EstadoCriminal Code, Articles 197 to 201
boe.es
Link checked 18 August 2026
Applies across the European Union2 rules
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: Reglamento (UE) 2016/679 — Reglamento General de Proteccion de Datos · Regulation (EU) 2016/679 · Directly binding regulation
Europe's general data protection law. It does not say where data must be stored. It says what you must have in place before personal data leaves Europe. It applies to companies outside Europe that target people in Spain.
Enforced by Spanish Data Protection Agency
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What you have to do
- Put a transfer safeguard in placeYou need a valid legal route, plus a written check on the destination country's surveillance laws.
- Report breaches to the regulator — within 72 hours
- Tell affected peopleWithout undue delay where the risk to individuals is high.
- Appoint a representativeYou need this if you have no office in Europe.
- Keep records of how you use data
- Assess high-risk projects
What it costs if you get it wrong
- Percentage of global turnover: €20 million or 4% of worldwide group turnover, whichever is higher (about $22 million at the floor) — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator's order.
- Order to stopOrder to stop processing or to suspend flows to a country outside Europe.
Sources
- Official sourcePublications Office of the European UnionGeneral Data Protection Regulation, official consolidated text
eur-lex.europa.eu
Link checked 18 August 2026
Cloud and outsourcing rules (2027)
Official name: Data Act — Reglamento (UE) 2023/2854 · Regulation (EU) 2023/2854 · Directly binding regulation
This is not about where data sits. It is about being able to move it. From 12 January 2027 no cloud provider may charge you to switch away or to pull your data out. It also pushes back on non-European government demands for data held in Europe.
That is a long gap: the duty is real law today, but no penalty can follow until 12 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.
How this country controls where data goes: No restriction
What you have to do
- Make switching cloud provider possible — from 12 January 2027All cloud switching charges and data export fees must be zero from 12 January 2027.
- Do not hand data to foreign authorities on demandCloud providers must take technical, organisational and legal steps to stop non-European governments getting at non-personal data held in Europe. This applies where that access would clash with European law.
Sources
- Official sourcePublications Office of the European UnionData Act (EU) 2023/2854, official text
eur-lex.europa.eu
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That no Spanish law transposing the second Network and Information Security Directive was in force on 18 August 2026
We found no Spanish law bringing Europe's newer cybersecurity directive into national law, but we could not confirm this against a complete index. We searched the official gazette's consolidated national legislation by title. That returned only university degree programmes for 'ciberseguridad' and nothing for 'seguridad de las redes' after 2022. A law published in the days before our check, or one with a different title, would not have shown up. Treat this as strong but not conclusive.
That no organic law on protecting minors in digital environments, and no national artificial intelligence governance act, were in force on 18 August 2026
We found no Spanish artificial intelligence act and no law on children in digital environments. We used the same title search, with the same limits. Both have been widely reported as government bills. Nothing matching appeared in the gazette's consolidated legislation.
The precise data-location requirements applying to public-sector cloud services
We could not confirm the real cloud rules for the Spanish public sector. The public-sector security decree itself contains no rule on where data must sit. It hands that question to a CCN-STIC technical guide from the National Cryptologic Centre. That guide is distributed through a restricted portal we could not open. The real limits on public-sector cloud may therefore be stricter than the decree text suggests.
Whether Spain's twelve-month telecoms retention law is still safely enforceable after Europe's court struck down the directive it implements
We could not confirm whether Spain's telecoms data retention law still stands after European case law. The law has not been repealed or amended, and Spanish courts still apply it. We found no Spanish court or regulator source that settles the tension. We record it as in force at medium confidence, rather than as no longer applied.
That the Basque and Andalusian data protection authorities are actively issuing decisions in 2026
We could not confirm 2026 activity for the Basque and Andalusian authorities. Both are named in the national law and we have no reason to doubt they operate. We checked 2026 activity only for the national agency and the Catalan authority.
Any banking, payments or securities data-location rule in Spain
We found no rule forcing Spanish bank or securities data to stay in the country, but we could not check every source. We looked at the securities markets act and the anti-money-laundering act on 18 August 2026 and found nothing. We did not reach the Bank of Spain's own circulars, because its page on the European digital operational resilience rules returned a 404 error. Those European rules now override national banking IT rules, so the chance of a missed Spanish rule is low but not zero.
Any mapping, geospatial or aerial-imagery localisation rule in Spain
We found no rule restricting Spanish mapping or aerial photography data. We searched the gazette by title for 'fotografia aerea' and 'cartografia' on 18 August 2026 and found nothing of the kind. Restrictions could sit in defence ministry orders that are not in the consolidated legislation database. We record this as no rule found, not as no rule existing.
The exact commencement date of the insurance supervision act's outsourcing article
We could not confirm the exact start date for the Spanish insurance outsourcing duty. We recorded 1 January 2016, the general start date for the European Solvency II insurance rules in Spain. We did not confirm a specific date from the text itself.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.