What the LOPD is and how it relates to the GDPR
The current LOPD is Organic Law 3/2018 on the protection of personal data and the guarantee of digital rights (LOPDGDD), in force since December 2018. It does not replace the GDPR: it complements and specifies it where the European regulation leaves room for each country.
Regulation (EU) 2016/679 has applied directly throughout the Union since May 2018. In practice, the substantive obligations come from the GDPR, and the LOPDGDD adds the Spanish details: ages of consent, penalty regime, digital rights and how the AEPD operates.
Who it applies to
Any organisation that processes personal data: names, emails, payslips, phone numbers, IP addresses or camera images. Size does not matter: a sole trader with a customer list is covered, and so is a subsidiary with fifty employees.
The GDPR has extraterritorial scope: if your company is not in the EU but offers services to people in the EU, it still applies. For a Spanish SME opening a subsidiary in Portugal or Germany, each company is an independent controller of its own processing, even if they share a brand and address.
The obligations that really matter
You do not need to set up a compliance department to start: most SMEs comply with a simple record, contracts with suppliers and clear policies. The common mistake is paying for a consultancy report and not doing the basics.
Key points
- Record of processing activities: an inventory of what data you process, for what purpose and on what legal basis
- Information for data subjects: clearly explaining what is done with their data, in privacy clauses
- Legal basis: consent, contract, legal obligation or legitimate interest, never a "just in case"
- Processors: a contract with anyone processing data on your behalf, such as accountants, payroll providers, hosting or email marketing
- Security measures proportionate to the risk: encryption, access control, password management
- Security breaches: notify the authority within 72 hours if there is a risk to individuals, and notify those affected if the risk is high
The data protection officer
A DPO is only mandatory in specific cases: public administrations, large-scale processing of special categories of data, or systematic large-scale monitoring of individuals. An ordinary SME with customers and employees does not need one.
The LOPDGDD extends the obligation to certain regulated sectors, such as centres that process health data, but the general rule for the average company is that it is not required. If you are asked for one, it is because the processing has a particular scale or sensitivity.
Penalties and how to avoid them
GDPR fines reach up to 20 million euros or 4% of global annual turnover, whichever is greater. In Spain, the AEPD grades LOPDGDD infringements as minor, serious and very serious, with amounts ranging from a few thousand euros up to that 20 million cap.
Most cases against SMEs end in much lower figures, but the real cost tends to lie in managing the incident and in the publicity. Penalties are mitigated by acknowledging the breach, correcting it and cooperating with the authority.





