Operations

What the LOPD is and what obligations it creates for your company

The LOPD is the Spanish law that implements the EU General Data Protection Regulation. If your company stores data on clients, suppliers or employees, it imposes a set of specific duties, and breaches are expensive. Here is what you need to know before setting up or expanding a business in Europe.

Updated on 2026-08-30 · By the Filnet team3 min read

What the LOPD is and how it relates to the GDPR

The current LOPD is Organic Law 3/2018 on the protection of personal data and the guarantee of digital rights (LOPDGDD), in force since December 2018. It does not replace the GDPR: it complements and specifies it where the European regulation leaves room for each country.

Regulation (EU) 2016/679 has applied directly throughout the Union since May 2018. In practice, the substantive obligations come from the GDPR, and the LOPDGDD adds the Spanish details: ages of consent, penalty regime, digital rights and how the AEPD operates.

Who it applies to

Any organisation that processes personal data: names, emails, payslips, phone numbers, IP addresses or camera images. Size does not matter: a sole trader with a customer list is covered, and so is a subsidiary with fifty employees.

The GDPR has extraterritorial scope: if your company is not in the EU but offers services to people in the EU, it still applies. For a Spanish SME opening a subsidiary in Portugal or Germany, each company is an independent controller of its own processing, even if they share a brand and address.

The obligations that really matter

You do not need to set up a compliance department to start: most SMEs comply with a simple record, contracts with suppliers and clear policies. The common mistake is paying for a consultancy report and not doing the basics.

Key points

  • Record of processing activities: an inventory of what data you process, for what purpose and on what legal basis
  • Information for data subjects: clearly explaining what is done with their data, in privacy clauses
  • Legal basis: consent, contract, legal obligation or legitimate interest, never a "just in case"
  • Processors: a contract with anyone processing data on your behalf, such as accountants, payroll providers, hosting or email marketing
  • Security measures proportionate to the risk: encryption, access control, password management
  • Security breaches: notify the authority within 72 hours if there is a risk to individuals, and notify those affected if the risk is high

The data protection officer

A DPO is only mandatory in specific cases: public administrations, large-scale processing of special categories of data, or systematic large-scale monitoring of individuals. An ordinary SME with customers and employees does not need one.

The LOPDGDD extends the obligation to certain regulated sectors, such as centres that process health data, but the general rule for the average company is that it is not required. If you are asked for one, it is because the processing has a particular scale or sensitivity.

Penalties and how to avoid them

GDPR fines reach up to 20 million euros or 4% of global annual turnover, whichever is greater. In Spain, the AEPD grades LOPDGDD infringements as minor, serious and very serious, with amounts ranging from a few thousand euros up to that 20 million cap.

Most cases against SMEs end in much lower figures, but the real cost tends to lie in managing the incident and in the publicity. Penalties are mitigated by acknowledging the breach, correcting it and cooperating with the authority.

Frequently asked questions

Yes, if they process personal data, even if it is just a customer list or a contact book. The obligations are adapted to the volume, but they do not disappear.

A document that lists what data you process, for what purpose, about whom and on what legal basis. It is the first obligation the AEPD reviews in an inspection.

Only in specific cases: public administrations, large-scale processing of sensitive data or systematic large-scale monitoring of individuals. Most SMEs do not need one.

Up to 20 million euros or 4% of global annual turnover, whichever is greater. In practice the AEPD applies graduated amounts depending on the severity and the cooperation.

Book a free call with a specialist

In 30 minutes we outline your expansion strategy with you: target market, legal structure and taxation for your case. No commitment.

FilioShall we talk?