Skip to content

Evidence request lists

Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD)

Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Breach

SPAINLOPDGDD-4
Breach, Enforcement

Per LOPDGDD: 72-hour breach notification + AEPD enforcement + criminal penalties.

Artefacts an auditor will ask for
  • LOPDGDD evidence for SPAINLOPDGDD-4
Where this commonly fails
  • digital rights + AEPD partial

Digital Rights

LOPDGDD-14
Digital Rights of Citizens and Workers

Implement the digital rights chapter including rights to disconnect, digital education, digital will, privacy in workplace devices and right to be forgotten in search engines.

Artefacts an auditor will ask for
  • Right to disconnect policy
  • Digital device use policy
  • Procedures for digital will requests
  • Worker awareness records
Where this commonly fails
  • Right to disconnect not policy backed
  • Device use policy outdated
  • No procedure for digital will
SPAINLOPDGDD-2
Digital Rights, Spanish Specifics

Per LOPDGDD Title X: digital rights including right to digital education + right to be forgotten + digital workplace rights.

Artefacts an auditor will ask for
  • LOPDGDD evidence for SPAINLOPDGDD-2
Where this commonly fails
  • digital rights + AEPD partial

Employment and Special Categories

LOPDGDD-12
Employee Data and Workplace Monitoring

Apply specific rules for processing employee personal data including video surveillance, geolocation and digital devices, informing workers and their representatives.

Artefacts an auditor will ask for
  • Workplace monitoring policy
  • Worker information and consultation records
  • Camera placement assessments
  • Geolocation justification documents
Where this commonly fails
  • Workers not informed of monitoring
  • Camera coverage excessive
  • No assessment of geolocation necessity
LOPDGDD-13
Special Categories and Criminal Data

Apply enhanced safeguards to special categories of personal data and criminal convictions data including additional lawful bases under LOPDGDD.

Artefacts an auditor will ask for
  • Inventory of special category data
  • Specific safeguards documentation
  • Restricted access controls
  • Justification for processing
Where this commonly fails
  • Health data outside dedicated systems
  • Criminal data without legal basis
  • Safeguards generic

Governance

SPAINLOPDGDD-3
DPO, Records, Governance

Per LOPDGDD: DPO designation + RoPA + AEPD cooperation.

Artefacts an auditor will ask for
  • LOPDGDD evidence for SPAINLOPDGDD-3
Where this commonly fails
  • digital rights + AEPD partial

Governance and Data Protection Officer

LOPDGDD-06
Data Protection Officer Designation

Appoint a Data Protection Officer where required by GDPR or LOPDGDD, notify AEPD and ensure independence, resourcing and direct reporting to top management.

Artefacts an auditor will ask for
  • DPO appointment letter
  • AEPD notification confirmation
  • DPO reporting line documented
  • DPO budget and resourcing plan
Where this commonly fails
  • DPO not notified to AEPD
  • DPO reports to compliance manager not top management
  • Conflicts of interest in DPO role
LOPDGDD-18
Audit, Accountability and Evidence

Demonstrate accountability through internal audits, compliance dashboards and management reviews aligned with AEPD expectations.

Artefacts an auditor will ask for
  • Internal audit plan and reports
  • Management review minutes
  • Compliance dashboard
  • Corrective action tracker
Where this commonly fails
  • Audit plan not executed
  • No management review on data protection
  • Dashboards not maintained
LOPDGDD-19
Training and Awareness on Data Protection

Train staff and contractors on LOPDGDD obligations, digital rights and incident reporting with role specific content.

Artefacts an auditor will ask for
  • Training plan
  • Completion records
  • Specialist training for high risk roles
  • Awareness materials
Where this commonly fails
  • Training annual and generic
  • No specialist content for HR or marketing
  • Contractors excluded

Lawful Basis and Consent

LOPDGDD-01
Lawful Basis and Spanish Specifics

Document lawful bases for processing personal data in line with GDPR and Spanish specific bases such as legal obligations and tasks in the public interest under LOPDGDD.

Artefacts an auditor will ask for
  • Lawful basis register per processing activity
  • Legitimate interest assessments
  • Public interest task references
  • Reviews after legal changes
Where this commonly fails
  • Lawful basis defaulting to consent for employment processing
  • Legitimate interest assessments missing
  • No review after sectoral law updates
LOPDGDD-02
Consent Standards and Minors

Obtain valid consent meeting LOPDGDD requirements including a minimum age of 14 for direct consent from minors and verifiable parental consent below that age.

Artefacts an auditor will ask for
  • Consent capture screens and logs
  • Age verification mechanisms
  • Parental consent workflows
  • Withdrawal mechanisms
Where this commonly fails
  • No age verification for online services
  • Parental consent process informal
  • Withdrawal harder than granting
LOPDGDD-03
Information Provided to Data Subjects

Provide layered, clear and accessible information to data subjects covering identity of controller, purposes, lawful basis, recipients, retention and rights.

Artefacts an auditor will ask for
  • Privacy notices for each touchpoint
  • Layered notice templates
  • Versioning history
  • Evidence of provision at collection
Where this commonly fails
  • Notices missing on legacy forms
  • Layered notices not used in apps
  • No proof notice was shown

Marketing, Cookies and Profiling

LOPDGDD-15
Marketing, Cookies and Profiling

Govern direct marketing, cookie consent and profiling activities in line with LOPDGDD, LSSI and AEPD cookie guidance.

Artefacts an auditor will ask for
  • Cookie banner configuration
  • Consent records
  • Marketing suppression list
  • Profiling explanations
Where this commonly fails
  • Cookie walls and dark patterns
  • No suppression list
  • Profiling logic undocumented

Processors and International Transfers

LOPDGDD-10
Processor Contracts and Sub-processing

Use written contracts with processors meeting GDPR article 28 requirements, including approval of sub-processors and instructions for processing.

Artefacts an auditor will ask for
  • Data processing agreements
  • Sub-processor list and approvals
  • Audit rights clauses
  • Processor due diligence records
Where this commonly fails
  • Sub-processors not approved
  • Contracts predate GDPR
  • Audit rights not exercised
LOPDGDD-11
International Data Transfers

Govern transfers of personal data to third countries through adequacy decisions, standard contractual clauses, BCRs or other GDPR mechanisms with transfer impact assessments.

Artefacts an auditor will ask for
  • Transfer register
  • Signed SCCs or BCRs
  • Transfer impact assessments
  • Supplementary measures evidence
Where this commonly fails
  • TIAs missing
  • Old SCCs still in use
  • Supplementary measures not documented

Public Sector Provisions

LOPDGDD-16
Public Sector Specific Provisions

Apply LOPDGDD provisions specific to public administrations including their lawful bases, mandatory DPO and coordination with ENS.

Artefacts an auditor will ask for
  • Public administration DPO appointment
  • Coordination procedure with ENS responsible roles
  • Sectoral lawful basis references
  • Inter-administration agreements
Where this commonly fails
  • DPO and ENS roles not coordinated
  • Lawful basis cited generically
  • Agreements lack data protection clauses

Records, Rights and Retention

LOPDGDD-04
Records of Processing Activities

Maintain records of processing activities for controllers and processors with categories of data, purposes, retention, recipients and transfers in line with GDPR and LOPDGDD.

Artefacts an auditor will ask for
  • Controller RoPA
  • Processor RoPA
  • Annual review evidence
  • Owner assignment
Where this commonly fails
  • RoPA out of date
  • Processor RoPA missing
  • Owners not assigned
LOPDGDD-05
Data Subject Rights Handling

Establish processes to handle access, rectification, erasure, restriction, portability and objection requests within statutory deadlines and Spanish guidance.

Artefacts an auditor will ask for
  • Rights request procedure
  • Ticketing logs with SLA
  • Templates for responses
  • Refusal justification log
Where this commonly fails
  • SLA exceeded without justification
  • Identity verification inconsistent
  • Refusals lack legal basis
LOPDGDD-17
Records Retention and Erasure

Define and apply retention periods aligned with legal obligations and erase personal data after the period expires, including secure disposal.

Artefacts an auditor will ask for
  • Retention schedule
  • Erasure logs
  • Secure disposal certificates
  • Backup expiry handling
Where this commonly fails
  • Retention schedule absent
  • Backups outlive primary data
  • Erasure not evidenced

Sanctions and Cooperation

LOPDGDD-20
Sanctions, Cooperation and Enforcement Readiness

Prepare for AEPD inspections, cooperate with supervisory authorities and track sanctions risk including statute of limitations under LOPDGDD.

Artefacts an auditor will ask for
  • Inspection readiness playbook
  • Records of AEPD interactions
  • Sanctions risk register
  • Legal counsel engagement plan
Where this commonly fails
  • No inspection playbook
  • AEPD correspondence not centralised
  • Sanctions risk not tracked

Scope

SPAINLOPDGDD-1
Scope, Lawful Basis, GDPR Implementation in Spain

Per Spain Organic Law 3/2018 (LOPDGDD) implementing GDPR: scope + lawful basis + Spanish supplements.

Artefacts an auditor will ask for
  • LOPDGDD evidence for SPAINLOPDGDD-1
Where this commonly fails
  • digital rights + AEPD partial

Security, Assessment and Breach

LOPDGDD-07
Security Measures and Risk Based Controls

Implement appropriate technical and organisational measures, including those expected by the AEPD, proportional to the risk to data subjects and aligned with ENS where applicable.

Artefacts an auditor will ask for
  • Security policy referencing LOPDGDD and ENS
  • Risk treatment plan
  • Technical controls catalogue
  • Annual review evidence
Where this commonly fails
  • Security measures not linked to risk assessment
  • No alignment with ENS for public sector providers
  • Technical catalogue not updated
LOPDGDD-08
Breach Notification to AEPD and Subjects

Detect, assess and notify personal data breaches to AEPD within 72 hours and to affected subjects when high risk exists, with documented decision rationale.

Artefacts an auditor will ask for
  • Breach register
  • AEPD notification submissions
  • Subject notification templates
  • Decision rationale for non-notification
Where this commonly fails
  • Decisions to not notify undocumented
  • Late submissions without justification
  • Subject notifications missing
LOPDGDD-09
DPIA for High Risk Processing

Conduct Data Protection Impact Assessments for processing likely to result in high risk, following AEPD criteria and consulting AEPD where required.

Artefacts an auditor will ask for
  • DPIA methodology
  • Completed DPIAs
  • Mitigation tracker
  • Prior consultation submissions
Where this commonly fails
  • DPIA only at go-live, not updated
  • Mitigations not tracked
  • AEPD consultation skipped
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.