LOPD
What the Organic Law on Data Protection is and how to comply with it
The LOPD is the name many people use to refer to Spanish privacy regulations.
However, the old Organic Law 15/1999 is no longer in force.
Today, data protection in Spain is mainly governed by the European GDPR and Organic Law 3/2018. The latter is known as the LOPDGDD.
In short, these regulations govern how to collect, use, store, and delete personal data. They also grant rights to individuals and require organizations to demonstrate compliance.
The Organic Law on Data Protection affects almost any business that manages customers, employees, contacts, or subscribers. Therefore, it also impacts email marketing, web forms, and automations.
What is the LOPD and what is it for?
The acronym LOPD stands for Organic Law on Data Protection. Its purpose is to protect privacy and individuals’ control over their personal information.
The historical regulation was Organic Law 15/1999, on the Protection of Personal Data. However, it was repealed in 2018.
Currently, the applicable framework combines two essential regulations:
- The General Data Protection Regulation of the European Union, known as the GDPR or RGPD.
- Organic Law 3/2018, on the Protection of Personal Data and Guarantee of Digital Rights, known as the LOPDGDD.
That’s why, when someone looks for information on the current LOPD, they usually need to know about the GDPR and the LOPDGDD.
Both regulations aim for lawful, transparent, and secure data processing. Likewise, they require respecting the purpose communicated to the user.
Differences between the LOPD, LOPDGDD, GDPR, and LSSI
These acronyms are often confused, but they don’t mean the same thing.
| Regulation | Main scope | Status or function |
|---|---|---|
| LOPD 15/1999 | Data protection in Spain | Repealed since 2018 |
| GDPR | Data protection in the European Union | Directly applicable |
| LOPDGDD | Data protection and digital rights in Spain | Adapts and complements the GDPR |
| LSSI | Digital services and commercial communications | Regulates, among other aspects, the sending of electronic advertising |
The current Organic Law on Data Protection doesn’t replace the GDPR. It complements it within the Spanish legal system.
Additionally, an email marketing campaign must comply with the LSSI. Consequently, meeting privacy rules alone isn’t enough.
Who is obligated by the Organic Law on Data Protection?
The regulation affects freelancers, companies, associations, public administrations, and professionals handling personal data.
The size of the organization doesn’t eliminate this responsibility.
Processing includes many standard actions. For example, collecting addresses, viewing records, segmenting contacts, sending newsletters, or deleting entries.
It can also affect companies located outside the European Union. This happens when they offer goods or services to people in the EU, or analyze their behavior.
In practice, you should review your compliance if you do any of these activities:
- You maintain a database of customers or prospects.
- You collect emails through subscription forms.
- You send newsletters, promotions, or automated messages.
- You store resumes or employee data.
- You use external tools to analyze users.
- You create profiles or segments based on interests and behavior.
What does the current LOPD consider personal data?
Personal data is any information relating to an identified or identifiable natural person. It isn’t limited to a name or ID document.
An email, phone number, IP address, or online identifier can also be personal data. It all depends on whether they allow someone to be identified, directly or indirectly.
A generic corporate address, like ‘info@company.com’, might not identify a person. However, ‘firstname.lastname@company.com’ usually does.
Health, biometric, genetic, ideological, or sexual orientation data receive reinforced protection. Their processing requires specific conditions.
Pseudonymized data is still personal if it can be re-associated with someone. Truly anonymous data, on the other hand, falls outside the GDPR.
LOPD and GDPR principles you need to apply
The regulation doesn’t just consist of adding a checkbox to a form. It requires applying several principles throughout the data lifecycle.
Lawfulness, fairness, and transparency in data protection
You must have a valid legal basis and clearly explain the processing. Likewise, you shouldn’t surprise the user with unexpected uses.
Purpose limitation according to the LOPD
Collect data for specific, explicit, and legitimate purposes. Afterwards, don’t use it for an incompatible purpose without new justification.
Data minimization and accuracy
Only request the necessary information. Also, establish reasonable mechanisms to correct inaccurate or outdated data.
Storage limitation, security, and confidentiality
Don’t keep information indefinitely. Define timeframes and apply measures appropriate to the risk, such as permissions, backups, and secure authentication.
Proactive responsibility in the Data Protection Law
It isn’t enough to claim you comply. You must be able to demonstrate decisions, controls, and procedures through updated evidence.
How to comply with the LOPD step by step in a company
There isn’t a single document that guarantees compliance. Data protection requires a continuous system tailored to the risk.
1. Identify all data processing activities
Pinpoint what information you collect, where it comes from, and what you use it for. Also note where it is stored and who can access it.
An inventory prevents forgotten databases and processes without an owner. It also makes it easier to create the record of processing activities when applicable.
2. Choose a legal basis for each purpose
Consent is one possible basis, but it isn’t the only one. There’s also contract, legal obligation, vital interest, public interest, and legitimate interest.
The legal basis must be decided before processing the data. Therefore, you shouldn’t choose it afterwards to justify a practice that has already started.
If you use legitimate interest, document the necessity and the balancing test. Also evaluate the expectations and rights of individuals.
3. Inform clearly and accessibly
Privacy information must explain who processes the data, for what purpose, and for how long. It must also indicate the legal basis, recipients, and rights.
You can offer a summarized first layer next to the form. Then, link to a more detailed privacy policy.
4. Collect valid consent when necessary
Consent must be freely given, specific, informed, and unambiguous. A pre-ticked box or user silence doesn’t meet these requirements.
Furthermore, you must be able to prove when, how, and for what each person consented. Withdrawing consent should be as easy as giving it.
5. Review your data processors
A vendor that processes data following your instructions usually acts as a data processor. This could be a hosting service, an agency, or a mailing platform.
You must formalize the corresponding data processing agreement. Also, review the security guarantees and potential international transfers.
6. Facilitate data protection rights
Individuals can request access, rectification, erasure, objection, restriction, and portability. They can also ask not to be subject to certain automated decisions.
Define a channel to receive requests and verify identity. As a general rule, you must respond within a month, although extensions are possible.
7. Establish retention and deletion periods
Each purpose needs a timeframe. When the data is no longer necessary, proceed to delete or block it if there’s a legal obligation.
An unsubscribe doesn’t always mean deleting the entire record. It may be necessary to keep minimal information to respect the objection and prevent further mailings.
8. Apply security based on risk
Protect data with technical and organizational controls. These include permission management, training, encryption, and access reviews.
If a breach occurs, assess its impact on individuals. When there is a risk, you may need to notify the authority within a maximum of 72 hours.
If the risk is high, you might also be required to inform the affected parties. In any case, document the incident and the measures taken.
9. Assess whether you need a DPO or an impact assessment
Not all companies need a Data Protection Officer. The obligation depends on the activity, the type of organization, and the scale of the processing.
Not all require a data protection impact assessment either. However, it’s usually necessary when the processing can create a high risk for individuals.
LOPD and email marketing: requirements for sending campaigns
Email marketing combines data processing and commercial communications. Therefore, you must consider the GDPR, Spanish regulations, and the LSSI.
As a general rule, the LSSI prohibits unsolicited or unauthorized promotional emails. There is an exception for certain prior contractual relationships.
In that case, the company must have obtained the contact lawfully. Additionally, it can only promote its own products or services similar to those contracted.
Every commercial email must include a simple and free way to opt out. Unsubscribing must work and be handled without undue delay.
Is double opt-in mandatory according to the LOPD?
Double opt-in doesn’t appear as a general obligation under that name. However, it is very useful for confirming the address and keeping solid evidence.
The user fills out the form and receives a confirmation email. They only join the list after clicking the link.
This process reduces fake sign-ups, errors, and third-party addresses. It also improves the quality of your subscriber base.
Can you buy databases for email marketing?
Buying a list doesn’t make its contacts usable. The seller must prove the lawful origin, the information provided, and the applicable authorization.
Furthermore, the mailing must comply with the LSSI. An address published on the internet doesn’t grant automatic permission to send advertising either.
That’s why bought lists pose a high legal and reputational risk. They also tend to generate complaints, bounces, and deliverability issues.
How to manage campaigns that respect the Data Protection Law
At Mailrelay, our email marketing platform, we help you create campaigns, lists, segments, and automations from a simple dashboard.
We also offer real-time statistics, click maps, A/B testing, and custom fields. These features allow you to work with more relevant audiences and measure results.
Our free plan supports up to 80,000 monthly emails and 20,000 contacts. It also includes multilingual support via phone, chat, and tickets, even on free accounts.
Technology makes management easier, but it doesn’t replace the legal decisions of the data controller. Each company must define its legal basis, its texts, and its retention periods.
We recommend keeping lists clean, importing only legitimate contacts, and handling unsubscribes. Additionally, responsible segmentation reduces unnecessary emails.
Before activating lead generation or a campaign, review these points:
- The form identifies the data controller.
- The purpose of the mailing is stated specifically.
- The legal basis is defined and documented.
- The consent checkbox isn’t pre-ticked.
- The privacy policy is accessible before sign-up.
- Proof of consent is recorded.
- Each campaign clearly identifies the sender.
- All messages include a functional unsubscribe mechanism.
- Unsubscribes also apply to automations and segments.
- Access to the list follows the principle of least privilege.
- There are retention periods and a deletion policy.
- Vendors have contracts and reviewed guarantees.
This list works as an initial check. However, it doesn’t replace a legal analysis adapted to the activity and risk.
Common mistakes when applying the LOPD in digital marketing
One of the most common mistakes is using copied texts. A generic policy might describe processing activities that don’t exist and omit real ones.
Another mistake is grouping several purposes under a single acceptance. The user must understand what they will receive and which uses are optional.
It is also incorrect to condition a service on unnecessary consent. Consent is no longer free when the user doesn’t have a real alternative.
Likewise, many companies keep inactive contacts indefinitely. The lack of a retention criterion increases risk and contradicts minimization.
Lastly, some organizations believe that registering files with the AEPD is still mandatory. That system belonged to the previous framework and no longer applies.
Penalties for failing to comply with the Organic Law on Data Protection
Non-compliance can lead to warnings, adaptation orders, and processing limitations. It can also result in claims, reputational damage, and financial penalties.
The most serious GDPR infringements can reach 20 million euros. For companies, the limit can reach 4% of the total worldwide annual turnover of the preceding financial year.
Other infringements can reach 10 million euros or 2% of the global annual turnover. The higher figure on each scale applies.
The amount isn’t calculated automatically. Factors such as severity, duration, intentionality, cooperation, and corrective measures are considered.
Complying with the LOPD shouldn’t be considered just to avoid fines. Transparent management builds trust and improves the relationship with customers and subscribers.
Frequently asked questions about the LOPD
Is the LOPD still in force in Spain?
Organic Law 15/1999 has been repealed. Today, the GDPR and Organic Law 3/2018, known as the LOPDGDD, apply.
What does LOPD mean?
It stands for Organic Law on Data Protection. In current searches, the term is often used to refer to the set of Spanish privacy regulations.
What is the difference between the LOPD and the GDPR?
The GDPR is a European Union regulation. The Spanish law adapts and completes that framework regarding national matters and digital rights.
Who must comply with the Organic Law on Data Protection?
Any entity or professional processing personal data within its scope. This includes most companies, freelancers, and associations.
You usually need a prior request or authorization. The LSSI contemplates a limited exception for customers and similar own products or services.
Can I send advertising to emails found on the internet?
Not simply because they are public. You must have a valid basis and meet the requirements applicable to commercial communications.
How much time do I have to respond to a right of access or erasure?
As a general rule, one month from receipt. The deadline can be extended by two months in complex cases, but you must inform them of the extension.
When should I report a data breach to the AEPD?
When it’s likely to involve a risk to rights and freedoms. The notification must be made without delay and, at the latest, within 72 hours of becoming aware of it.
Does double opt-in guarantee LOPD compliance?
It doesn’t guarantee it on its own. It provides useful evidence, but you must also comply with information, purpose, security, and other requirements.
Does using Mailrelay make my campaigns automatically comply with the regulation?
No platform replaces the obligations of the data controller. Mailrelay provides features to manage campaigns, contacts, unsubscribes, segmentation, and statistics in an organized way.
Is it necessary to register files with the AEPD?
No. That obligation belonged to the previous system. Now you must apply proactive responsibility and keep documentation proving compliance.
At what age can a minor consent to the processing of their data in Spain?
Spanish legislation sets 14 years of age for consent based on the minor’s will. Below that age, whoever exercises parental authority or guardianship must intervene.
Disclaimer: This content is informational and doesn’t constitute legal advice. The specific application depends on each processing activity, purpose, and organization.