The LOPDGDD adapts the EU GDPR to the Spanish framework. It was created to strengthen the fundamental rights of individuals by establishing a regulation applicable to companies and public bodies in the digital world, while avoiding the dispersion of regulations that may arise in different national systems, thus providing a unified line of action.
The LOPDGDD establishes, among other aspects, the requirements needed when collecting personal data, providing at least the following information:
- Processing, purpose and recipients
- Exercise of rights
- Identity and contact details of the controller
- Legal basis for processing
- Data retention periods
- The use of data for profiling
- Compliance of international data transfers with the legal framework
It also makes a distinction between digital rights of a personal nature and those that affect individuals in the workplace.
Other aspects covered by the regulation include the minimum age for consent, the possibility of withdrawing minors’ data during their minority, the ability to exercise access, rectification or erasure rights over the data of a deceased person, and the establishment of the maximum period for retaining personal data related to non‑payment of financial obligations.
Our framework has also been strengthened by the Cookie Usage Guide published by the AEPD, in force since October 31, 2020, which compiles the guidelines and obligations included in the LSSI and LOPDGDD.
Internet Security Auditors covers a wide range of services to help your company align with the regulation:
Adaptation and Implementation
- Analysis of the company's level of compliance.
- Drafting of security documentation such as policies, standards, procedures and instructions.
- Execution of data protection impact assessments.
- Adaptation of legal texts in forms, contracts or other documents.
Training and Awareness
All company staff must know their obligations. Based on the principle of proactive responsibility established by the regulation, the Data Controller is responsible for complying with the GDPR and must be able to demonstrate it.
Internet Security Auditors offers personalized training services to meet this requirement through our e‑learning platform.
Support and Maintenance Offices
We offer companies support tailored to their needs for:
- Consultations.
- Technical and legal advice.
- Documentation updates.
- Information on regulatory changes. Periodic follow‑up and control visits.
Control Audit
To verify your company's level of compliance with the applicable legal framework.
Data Protection Officer
We offer a delegated service for the role of Data Protection Officer (DPO) for organizations that choose to outsource the service or do not wish to include it as part of their staff.
If your company fails to meet its legal obligations, it may face fines of up to 20 million euros or up to 4% of its global annual turnover, not to mention reputational damage and loss of credibility with customers.