Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD)
Spain's Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD) supplements the EU GDPR with national provisions and establishes a catalogue of digital rights. The Spanish Data Protection Agency (AEPD — Agencia Española de Protección de Datos) oversees enforcement. Notable features include digital rights (right to disconnect, digital education, rectification on the internet), age of digital consent (14 years), deceased persons' data rights, and internal whistleblower provisions. AEPD is one of the most active DPAs in Europe.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (26)
Audit
| Code | Title |
|---|---|
| LOPDGDD-18 | Audit, Accountability and Evidence |
Consent
| Code | Title |
|---|---|
| LOPDGDD-02 | Consent Standards and Minors |
Digital Rights
| Code | Title |
|---|---|
| LOPDGDD-14 | Digital Rights of Citizens and Workers |
Documentation
| Code | Title |
|---|---|
| LOPDGDD-04 | Records of Processing Activities |
Employment
| Code | Title |
|---|---|
| LOPDGDD-12 | Employee Data and Workplace Monitoring |
Enforcement
| Code | Title |
|---|---|
| LOPDGDD-20 | Sanctions, Cooperation and Enforcement Readiness |
Governance
| Code | Title |
|---|---|
| LOPDGDD-06 | Data Protection Officer Designation |
Incident Response
| Code | Title |
|---|---|
| LOPDGDD-08 | Breach Notification to AEPD and Subjects |
Lawfulness
| Code | Title |
|---|---|
| LOPDGDD-01 | Lawful Basis and Spanish Specifics |
Lifecycle
| Code | Title |
|---|---|
| LOPDGDD-17 | Records Retention and Erasure |
Marketing
| Code | Title |
|---|---|
| LOPDGDD-15 | Marketing, Cookies and Profiling |
Public Sector
| Code | Title |
|---|---|
| LOPDGDD-16 | Public Sector Specific Provisions |
Rights
| Code | Title |
|---|---|
| LOPDGDD-05 | Data Subject Rights Handling |
Risk Assessment
| Code | Title |
|---|---|
| LOPDGDD-09 | DPIA for High Risk Processing |
Security
| Code | Title |
|---|---|
| LOPDGDD-07 | Security Measures and Risk Based Controls |
Special Data
| Code | Title |
|---|---|
| LOPDGDD-13 | Special Categories and Criminal Data |
Third Party
| Code | Title |
|---|---|
| LOPDGDD-10 | Processor Contracts and Sub-processing |
Title I — General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
Title II — Principles of Data Protection
| Code | Title |
|---|---|
| Art. 4 | Participating Institutions |
| Art. 5 | Prohibited AI Practices |
| Art. 6 | Writing |
| Art. 7 | Minimum Standards |
| Art. 9 | Risk Management System |
Title III — Rights of Data Subjects
| Code | Title |
|---|---|
| Art. 12 | Record-Keeping |
| Art. 13 | Transparency and Provision of Information to Deployers |
| Art. 14 | Human Oversight |
| Art. 15 | Accuracy, Robustness and Cybersecurity |
| Art. 16 | Obligations of Providers of High-Risk AI Systems |
| Art. 17 | Quality Management System |
| Art. 18 | Documentation Keeping |
Title IX — Regime of Penalties
| Code | Title |
|---|---|
| Art. 70 | Criminal Penalties for False Consent |
| Art. 71 | Criminal Penalties for Unlawful Processing |
| Art. 72 | Post-Market Monitoring by Providers and Post-Market Monitoring Plan for High-Risk AI Systems |
| Art. 73 | Reporting of Serious Incidents |
| Art. 74 | Minor infringements |
Title V — Data Protection Officer
| Code | Title |
|---|---|
| Art. 34 | Notification of Personal Information Breach |
| Art. 35 | Right of Access |
| Art. 36 | Right to Correction or Deletion |
| Art. 37 | Right to Suspension of Processing |
Title X — Digital Rights
| Code | Title |
|---|---|
| Art. 79 | Inspections |
| Art. 80 | Right to universal access to the internet |
| Art. 81 | Right to security of digital communications |
| Art. 82 | Inspection Procedure |
| Art. 87 | Administrative Fines |
| Art. 88 | Right to digital disconnection at work |
| Art. 89 | Right to privacy in video surveillance at work |
| Art. 93 | Right to digital will |
Training
| Code | Title |
|---|---|
| LOPDGDD-19 | Training and Awareness on Data Protection |
Transfers
| Code | Title |
|---|---|
| LOPDGDD-11 | International Data Transfers |
Transparency
| Code | Title |
|---|---|
| LOPDGDD-03 | Information Provided to Data Subjects |
Your Compliance Coverage
If you comply with Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD), you already cover:
BS 65000:2014 — Guidance on Organizational Resilience
25%
13 controls mapped
Compare →ILO Nursing Personnel Convention C149 (1977)
23%
12 controls mapped
Compare →6th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673)
23%
12 controls mapped
Compare →+ 627 more: ISO 8000 — Data Quality (23%), FATF Recommendation 16 — Virtual Asset Travel Rule (23%)
See all 630 mapped frameworks ↓Maps to 630 other frameworks
Frequently Asked Questions
What is Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD)?
Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) is a compliance framework from Spain with 26 domains and 52 controls. Spain's Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD) supplements the EU GDPR with national provisions and establishes a catalogue of digital rights. The Spanish Data Protection Agency (AEPD — Agencia Española de Protección de Datos) oversees enforcement. Notable features include digital rights (right to disconnect, digital education, rectification on the internet), age of digital consent (14 years), deceased persons' data rights, and internal whistleblower provisions. AEPD is one of the most active DPAs in Europe. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) have?
Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) has 52 controls organised across 26 domains. The largest domains are Title X — Digital Rights (8 controls), Title III — Rights of Data Subjects (7 controls), Title II — Principles of Data Protection (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) map to?
Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) maps to 630 other compliance frameworks. The top mapping partners are BS 65000:2014 — Guidance on Organizational Resilience (25% coverage), ILO Nursing Personnel Convention C149 (1977) (23% coverage), 6th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673) (23% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) compliance?
Start your Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 52 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required