Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD)
Spain's Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD) supplements the EU GDPR with national provisions and establishes a catalogue of digital rights. The Spanish Data Protection Agency (AEPD — Agencia Española de Protección de Datos) oversees enforcement. Notable features include digital rights (right to disconnect, digital education, rectification on the internet), age of digital consent (14 years), deceased persons' data rights, and internal whistleblower provisions. AEPD is one of the most active DPAs in Europe.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Title I — General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
Title II — Principles of Data Protection
| Code | Title |
|---|---|
| Art. 4 | Participating Institutions |
| Art. 5 | Legal Recognition of Data Messages |
| Art. 6 | Writing |
| Art. 7 | Minimum Standards |
| Art. 9 | Free Data Sharing |
Title III — Rights of Data Subjects
| Code | Title |
|---|---|
| Art. 12 | Data Ownership |
| Art. 13 | Data Security and Privacy |
| Art. 14 | Direct Data Flows |
| Art. 15 | Cybersecurity Requirements |
| Art. 16 | Data Quality |
| Art. 17 | Governance Structure |
| Art. 18 | Central Bank Supervision |
Title IX — Regime of Penalties
| Code | Title |
|---|---|
| Art. 70 | Criminal Penalties for False Consent |
| Art. 71 | Criminal Penalties for Unlawful Processing |
| Art. 72 | Criminal Sanctions |
| Art. 73 | Administrative Fines |
| Art. 74 | Minor infringements |
Title V — Data Protection Officer
| Code | Title |
|---|---|
| Art. 34 | Notification of Personal Information Breach |
| Art. 35 | Right of Access |
| Art. 36 | Right to Correction or Deletion |
| Art. 37 | Right to Suspension of Processing |
Title X — Digital Rights
| Code | Title |
|---|---|
| Art. 79 | Inspections |
| Art. 80 | Right to universal access to the internet |
| Art. 81 | Right to security of digital communications |
| Art. 82 | Inspection Procedure |
| Art. 87 | Administrative Fines |
| Art. 88 | Right to digital disconnection at work |
| Art. 89 | Right to privacy in video surveillance at work |
| Art. 93 | Right to digital will |
Maps to 605 other frameworks
Frequently Asked Questions
What is Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD)?
Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) is a compliance framework from Spain with 6 domains and 32 controls. Spain's Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD) supplements the EU GDPR with national provisions and establishes a catalogue of digital rights. The Spanish Data Protection Agency (AEPD — Agencia Española de Protección de Datos) oversees enforcement. Notable features include digital rights (right to disconnect, digital education, rectification on the internet), age of digital consent (14 years), deceased persons' data rights, and internal whistleblower provisions. AEPD is one of the most active DPAs in Europe. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) have?
Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) has 32 controls organised across 6 domains. The largest domains are Title X — Digital Rights (8 controls), Title III — Rights of Data Subjects (7 controls), Title II — Principles of Data Protection (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) map to?
Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) maps to 605 other compliance frameworks. The top mapping partners are BS 65000:2014 — Guidance on Organizational Resilience (41% coverage), ILO Nursing Personnel Convention C149 (1977) (38% coverage), EU Anti-Money Laundering Directive (AMLD6 / Directive 2018/1673) (38% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) compliance?
Start your Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 32 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required