Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD)
Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Breach
Per LOPDGDD: 72-hour breach notification + AEPD enforcement + criminal penalties.
- LOPDGDD evidence for SPAINLOPDGDD-4
- digital rights + AEPD partial
Digital Rights
Implement the digital rights chapter including rights to disconnect, digital education, digital will, privacy in workplace devices and right to be forgotten in search engines.
- Right to disconnect policy
- Digital device use policy
- Procedures for digital will requests
- Worker awareness records
- Right to disconnect not policy backed
- Device use policy outdated
- No procedure for digital will
Per LOPDGDD Title X: digital rights including right to digital education + right to be forgotten + digital workplace rights.
- LOPDGDD evidence for SPAINLOPDGDD-2
- digital rights + AEPD partial
Employment and Special Categories
Apply specific rules for processing employee personal data including video surveillance, geolocation and digital devices, informing workers and their representatives.
- Workplace monitoring policy
- Worker information and consultation records
- Camera placement assessments
- Geolocation justification documents
- Workers not informed of monitoring
- Camera coverage excessive
- No assessment of geolocation necessity
Apply enhanced safeguards to special categories of personal data and criminal convictions data including additional lawful bases under LOPDGDD.
- Inventory of special category data
- Specific safeguards documentation
- Restricted access controls
- Justification for processing
- Health data outside dedicated systems
- Criminal data without legal basis
- Safeguards generic
Governance
Per LOPDGDD: DPO designation + RoPA + AEPD cooperation.
- LOPDGDD evidence for SPAINLOPDGDD-3
- digital rights + AEPD partial
Governance and Data Protection Officer
Appoint a Data Protection Officer where required by GDPR or LOPDGDD, notify AEPD and ensure independence, resourcing and direct reporting to top management.
- DPO appointment letter
- AEPD notification confirmation
- DPO reporting line documented
- DPO budget and resourcing plan
- DPO not notified to AEPD
- DPO reports to compliance manager not top management
- Conflicts of interest in DPO role
Demonstrate accountability through internal audits, compliance dashboards and management reviews aligned with AEPD expectations.
- Internal audit plan and reports
- Management review minutes
- Compliance dashboard
- Corrective action tracker
- Audit plan not executed
- No management review on data protection
- Dashboards not maintained
Train staff and contractors on LOPDGDD obligations, digital rights and incident reporting with role specific content.
- Training plan
- Completion records
- Specialist training for high risk roles
- Awareness materials
- Training annual and generic
- No specialist content for HR or marketing
- Contractors excluded
Lawful Basis and Consent
Document lawful bases for processing personal data in line with GDPR and Spanish specific bases such as legal obligations and tasks in the public interest under LOPDGDD.
- Lawful basis register per processing activity
- Legitimate interest assessments
- Public interest task references
- Reviews after legal changes
- Lawful basis defaulting to consent for employment processing
- Legitimate interest assessments missing
- No review after sectoral law updates
Obtain valid consent meeting LOPDGDD requirements including a minimum age of 14 for direct consent from minors and verifiable parental consent below that age.
- Consent capture screens and logs
- Age verification mechanisms
- Parental consent workflows
- Withdrawal mechanisms
- No age verification for online services
- Parental consent process informal
- Withdrawal harder than granting
Provide layered, clear and accessible information to data subjects covering identity of controller, purposes, lawful basis, recipients, retention and rights.
- Privacy notices for each touchpoint
- Layered notice templates
- Versioning history
- Evidence of provision at collection
- Notices missing on legacy forms
- Layered notices not used in apps
- No proof notice was shown
Marketing, Cookies and Profiling
Govern direct marketing, cookie consent and profiling activities in line with LOPDGDD, LSSI and AEPD cookie guidance.
- Cookie banner configuration
- Consent records
- Marketing suppression list
- Profiling explanations
- Cookie walls and dark patterns
- No suppression list
- Profiling logic undocumented
Processors and International Transfers
Use written contracts with processors meeting GDPR article 28 requirements, including approval of sub-processors and instructions for processing.
- Data processing agreements
- Sub-processor list and approvals
- Audit rights clauses
- Processor due diligence records
- Sub-processors not approved
- Contracts predate GDPR
- Audit rights not exercised
Govern transfers of personal data to third countries through adequacy decisions, standard contractual clauses, BCRs or other GDPR mechanisms with transfer impact assessments.
- Transfer register
- Signed SCCs or BCRs
- Transfer impact assessments
- Supplementary measures evidence
- TIAs missing
- Old SCCs still in use
- Supplementary measures not documented
Public Sector Provisions
Apply LOPDGDD provisions specific to public administrations including their lawful bases, mandatory DPO and coordination with ENS.
- Public administration DPO appointment
- Coordination procedure with ENS responsible roles
- Sectoral lawful basis references
- Inter-administration agreements
- DPO and ENS roles not coordinated
- Lawful basis cited generically
- Agreements lack data protection clauses
Records, Rights and Retention
Maintain records of processing activities for controllers and processors with categories of data, purposes, retention, recipients and transfers in line with GDPR and LOPDGDD.
- Controller RoPA
- Processor RoPA
- Annual review evidence
- Owner assignment
- RoPA out of date
- Processor RoPA missing
- Owners not assigned
Establish processes to handle access, rectification, erasure, restriction, portability and objection requests within statutory deadlines and Spanish guidance.
- Rights request procedure
- Ticketing logs with SLA
- Templates for responses
- Refusal justification log
- SLA exceeded without justification
- Identity verification inconsistent
- Refusals lack legal basis
Define and apply retention periods aligned with legal obligations and erase personal data after the period expires, including secure disposal.
- Retention schedule
- Erasure logs
- Secure disposal certificates
- Backup expiry handling
- Retention schedule absent
- Backups outlive primary data
- Erasure not evidenced
Sanctions and Cooperation
Prepare for AEPD inspections, cooperate with supervisory authorities and track sanctions risk including statute of limitations under LOPDGDD.
- Inspection readiness playbook
- Records of AEPD interactions
- Sanctions risk register
- Legal counsel engagement plan
- No inspection playbook
- AEPD correspondence not centralised
- Sanctions risk not tracked
Scope
Per Spain Organic Law 3/2018 (LOPDGDD) implementing GDPR: scope + lawful basis + Spanish supplements.
- LOPDGDD evidence for SPAINLOPDGDD-1
- digital rights + AEPD partial
Security, Assessment and Breach
Implement appropriate technical and organisational measures, including those expected by the AEPD, proportional to the risk to data subjects and aligned with ENS where applicable.
- Security policy referencing LOPDGDD and ENS
- Risk treatment plan
- Technical controls catalogue
- Annual review evidence
- Security measures not linked to risk assessment
- No alignment with ENS for public sector providers
- Technical catalogue not updated
Detect, assess and notify personal data breaches to AEPD within 72 hours and to affected subjects when high risk exists, with documented decision rationale.
- Breach register
- AEPD notification submissions
- Subject notification templates
- Decision rationale for non-notification
- Decisions to not notify undocumented
- Late submissions without justification
- Subject notifications missing
Conduct Data Protection Impact Assessments for processing likely to result in high risk, following AEPD criteria and consulting AEPD where required.
- DPIA methodology
- Completed DPIAs
- Mitigation tracker
- Prior consultation submissions
- DPIA only at go-live, not updated
- Mitigations not tracked
- AEPD consultation skipped
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.