{"id":91623,"date":"2026-09-02T17:46:53","date_gmt":"2026-09-02T17:46:53","guid":{"rendered":"https:\/\/mailrelay.com\/glossary\/lopd-organic-law-data-protection\/"},"modified":"2026-09-25T09:42:27","modified_gmt":"2026-09-25T09:42:27","slug":"lopd-organic-law-data-protection","status":"publish","type":"glossary","link":"https:\/\/mailrelay.com\/en\/glossary\/lopd-organic-law-data-protection\/","title":{"rendered":"LOPD"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The <strong>LOPD<\/strong> is the name many people use to refer to Spanish privacy regulations. <\/p>\n\n<p class=\"wp-block-paragraph\">However, the old Organic Law 15\/1999 is no longer in force.<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Today, data protection in Spain is mainly governed by the European GDPR and Organic Law 3\/2018. The latter is known as the LOPDGDD.<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">In short, these regulations govern how to collect, use, store, and delete personal data. They also grant rights to individuals and require organizations to demonstrate compliance.<\/p>\n\n<p class=\"wp-block-paragraph\">The <strong>Organic Law on Data Protection<\/strong> affects almost any business that manages customers, employees, contacts, or subscribers. Therefore, it also impacts email marketing, web forms, and automations.<\/p>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n<h2 class=\"wp-block-heading\">What is the LOPD and what is it for?<\/h2>\n\n<p class=\"wp-block-paragraph\">The acronym <strong>LOPD<\/strong> stands for Organic Law on Data Protection. Its purpose is to protect privacy and individuals&#8217; control over their personal information.<\/p>\n\n<p class=\"wp-block-paragraph\">The historical regulation was Organic Law 15\/1999, on the Protection of Personal Data. However, it was repealed in 2018.<\/p>\n\n<p class=\"wp-block-paragraph\">Currently, the applicable framework combines two essential regulations:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>The General Data Protection Regulation of the European Union, known as the GDPR or RGPD.<\/li>\n\n\n\n<li>Organic Law 3\/2018, on the Protection of Personal Data and Guarantee of Digital Rights, known as the LOPDGDD.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">That&#8217;s why, when someone looks for information on the <strong>current LOPD<\/strong>, they usually need to know about the GDPR and the LOPDGDD.<\/p>\n\n<p class=\"wp-block-paragraph\">Both regulations aim for lawful, transparent, and secure data processing. Likewise, they require respecting the purpose communicated to the user.<\/p>\n\n<h2 class=\"wp-block-heading\">Differences between the LOPD, LOPDGDD, GDPR, and LSSI<\/h2>\n\n<p class=\"wp-block-paragraph\">These acronyms are often confused, but they don&#8217;t mean the same thing.<\/p>\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Regulation<\/th><th>Main scope<\/th><th>Status or function<\/th><\/tr><\/thead><tbody><tr><td>LOPD 15\/1999<\/td><td>Data protection in Spain<\/td><td>Repealed since 2018<\/td><\/tr><tr><td>GDPR<\/td><td>Data protection in the European Union<\/td><td>Directly applicable<\/td><\/tr><tr><td>LOPDGDD<\/td><td>Data protection and digital rights in Spain<\/td><td>Adapts and complements the GDPR<\/td><\/tr><tr><td>LSSI<\/td><td>Digital services and commercial communications<\/td><td>Regulates, among other aspects, the sending of electronic advertising<\/td><\/tr><\/tbody><\/table><\/figure>\n\n<p class=\"wp-block-paragraph\">The <strong>current Organic Law on Data Protection<\/strong> doesn&#8217;t replace the GDPR. It complements it within the Spanish legal system.<\/p>\n\n<p class=\"wp-block-paragraph\">Additionally, an email marketing campaign must comply with the LSSI. Consequently, meeting privacy rules alone isn&#8217;t enough.<\/p>\n\n<h2 class=\"wp-block-heading\">Who is obligated by the Organic Law on Data Protection?<\/h2>\n\n<p class=\"wp-block-paragraph\">The regulation affects freelancers, companies, associations, public administrations, and professionals handling personal data. <\/p>\n\n<p class=\"wp-block-paragraph\"><strong>The size of the organization doesn&#8217;t eliminate this responsibility.<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">Processing includes many standard actions. For example, collecting addresses, viewing records, segmenting contacts, sending newsletters, or deleting entries.<\/p>\n\n<p class=\"wp-block-paragraph\">It can also affect companies located outside the European Union. This happens when they offer goods or services to people in the EU, or analyze their behavior.<\/p>\n\n<p class=\"wp-block-paragraph\">In practice, you should review your compliance if you do any of these activities:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>You maintain a database of customers or prospects.<\/li>\n\n\n\n<li>You collect emails through subscription forms.<\/li>\n\n\n\n<li>You send newsletters, promotions, or automated messages.<\/li>\n\n\n\n<li>You store resumes or employee data.<\/li>\n\n\n\n<li>You use external tools to analyze users.<\/li>\n\n\n\n<li>You create profiles or segments based on interests and behavior.<\/li>\n<\/ul>\n\n<h2 class=\"wp-block-heading\">What does the current LOPD consider personal data?<\/h2>\n\n<p class=\"wp-block-paragraph\"><strong>Personal data is any information relating to an identified or identifiable natural person. It isn&#8217;t limited to a name or ID document.<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">An email, phone number, IP address, or online identifier can also be personal data. It all depends on whether they allow someone to be identified, directly or indirectly.<\/p>\n\n<p class=\"wp-block-paragraph\">A generic corporate address, like &#8216;info&#64;company.com&#8217;, might not identify a person. However, &#8216;firstname.lastname&#64;company.com&#8217; usually does.<\/p>\n\n<p class=\"wp-block-paragraph\">Health, biometric, genetic, ideological, or sexual orientation data receive reinforced protection. Their processing requires specific conditions.<\/p>\n\n<p class=\"wp-block-paragraph\">Pseudonymized data is still personal if it can be re-associated with someone. Truly anonymous data, on the other hand, falls outside the GDPR.<\/p>\n\n<h2 class=\"wp-block-heading\">LOPD and GDPR principles you need to apply<\/h2>\n\n<p class=\"wp-block-paragraph\">The regulation doesn&#8217;t just consist of adding a checkbox to a form. It requires applying several principles throughout the data lifecycle.<\/p>\n\n<h3 class=\"wp-block-heading\">Lawfulness, fairness, and transparency in data protection<\/h3>\n\n<p class=\"wp-block-paragraph\">You must have a valid legal basis and clearly explain the processing. Likewise, you shouldn&#8217;t surprise the user with unexpected uses.<\/p>\n\n<h3 class=\"wp-block-heading\">Purpose limitation according to the LOPD<\/h3>\n\n<p class=\"wp-block-paragraph\">Collect data for specific, explicit, and legitimate purposes. Afterwards, don&#8217;t use it for an incompatible purpose without new justification.<\/p>\n\n<h3 class=\"wp-block-heading\">Data minimization and accuracy<\/h3>\n\n<p class=\"wp-block-paragraph\">Only request the necessary information. Also, establish reasonable mechanisms to correct inaccurate or outdated data.<\/p>\n\n<h3 class=\"wp-block-heading\">Storage limitation, security, and confidentiality<\/h3>\n\n<p class=\"wp-block-paragraph\">Don&#8217;t keep information indefinitely. Define timeframes and apply measures appropriate to the risk, such as permissions, backups, and secure authentication.<\/p>\n\n<h3 class=\"wp-block-heading\">Proactive responsibility in the Data Protection Law<\/h3>\n\n<p class=\"wp-block-paragraph\">It isn&#8217;t enough to claim you comply. You must be able to demonstrate decisions, controls, and procedures through updated evidence.<\/p>\n\n<h2 class=\"wp-block-heading\">How to comply with the LOPD step by step in a company<\/h2>\n\n<p class=\"wp-block-paragraph\">There isn&#8217;t a single document that guarantees compliance. Data protection requires a continuous system tailored to the risk.<\/p>\n\n<h3 class=\"wp-block-heading\">1. Identify all data processing activities<\/h3>\n\n<p class=\"wp-block-paragraph\">Pinpoint what information you collect, where it comes from, and what you use it for. Also note where it is stored and who can access it.<\/p>\n\n<p class=\"wp-block-paragraph\">An inventory prevents forgotten databases and processes without an owner. It also makes it easier to create the record of processing activities when applicable.<\/p>\n\n<h3 class=\"wp-block-heading\">2. Choose a legal basis for each purpose<\/h3>\n\n<p class=\"wp-block-paragraph\">Consent is one possible basis, but it isn&#8217;t the only one. There&#8217;s also contract, legal obligation, vital interest, public interest, and legitimate interest.<\/p>\n\n<p class=\"wp-block-paragraph\">The legal basis must be decided before processing the data. Therefore, you shouldn&#8217;t choose it afterwards to justify a practice that has already started.<\/p>\n\n<p class=\"wp-block-paragraph\">If you use legitimate interest, document the necessity and the balancing test. Also evaluate the expectations and rights of individuals.<\/p>\n\n<h3 class=\"wp-block-heading\">3. Inform clearly and accessibly<\/h3>\n\n<p class=\"wp-block-paragraph\">Privacy information must explain who processes the data, for what purpose, and for how long. It must also indicate the legal basis, recipients, and rights.<\/p>\n\n<p class=\"wp-block-paragraph\">You can offer a summarized first layer next to the form. Then, link to a more detailed privacy policy.<\/p>\n\n<h3 class=\"wp-block-heading\">4. Collect valid consent when necessary<\/h3>\n\n<p class=\"wp-block-paragraph\">Consent must be freely given, specific, informed, and unambiguous. A pre-ticked box or user silence doesn&#8217;t meet these requirements.<\/p>\n\n<p class=\"wp-block-paragraph\">Furthermore, you must be able to prove when, how, and for what each person consented. Withdrawing consent should be as easy as giving it.<\/p>\n\n<h3 class=\"wp-block-heading\">5. Review your data processors<\/h3>\n\n<p class=\"wp-block-paragraph\">A vendor that processes data following your instructions usually acts as a data processor. This could be a hosting service, an agency, or a mailing platform.<\/p>\n\n<p class=\"wp-block-paragraph\">You must formalize the corresponding data processing agreement. Also, review the security guarantees and potential international transfers.<\/p>\n\n<h3 class=\"wp-block-heading\">6. Facilitate data protection rights<\/h3>\n\n<p class=\"wp-block-paragraph\">Individuals can request access, rectification, erasure, objection, restriction, and portability. They can also ask not to be subject to certain automated decisions.<\/p>\n\n<p class=\"wp-block-paragraph\">Define a channel to receive requests and verify identity. As a general rule, you must respond within a month, although extensions are possible.<\/p>\n\n<h3 class=\"wp-block-heading\">7. Establish retention and deletion periods<\/h3>\n\n<p class=\"wp-block-paragraph\">Each purpose needs a timeframe. When the data is no longer necessary, proceed to delete or block it if there&#8217;s a legal obligation.<\/p>\n\n<p class=\"wp-block-paragraph\">An unsubscribe doesn&#8217;t always mean deleting the entire record. It may be necessary to keep minimal information to respect the objection and prevent further mailings.<\/p>\n\n<h3 class=\"wp-block-heading\">8. Apply security based on risk<\/h3>\n\n<p class=\"wp-block-paragraph\">Protect data with technical and organizational controls. These include permission management, training, encryption, and access reviews.<\/p>\n\n<p class=\"wp-block-paragraph\">If a breach occurs, assess its impact on individuals. When there is a risk, you may need to notify the authority within a maximum of 72 hours.<\/p>\n\n<p class=\"wp-block-paragraph\">If the risk is high, you might also be required to inform the affected parties. In any case, document the incident and the measures taken.<\/p>\n\n<h3 class=\"wp-block-heading\">9. Assess whether you need a DPO or an impact assessment<\/h3>\n\n<p class=\"wp-block-paragraph\">Not all companies need a Data Protection Officer. The obligation depends on the activity, the type of organization, and the scale of the processing.<\/p>\n\n<p class=\"wp-block-paragraph\">Not all require a data protection impact assessment either. However, it&#8217;s usually necessary when the processing can create a high risk for individuals.<\/p>\n\n<h2 class=\"wp-block-heading\">LOPD and email marketing: requirements for sending campaigns<\/h2>\n\n<p class=\"wp-block-paragraph\">Email marketing combines data processing and commercial communications. Therefore, you must consider the GDPR, Spanish regulations, and the LSSI.<\/p>\n\n<p class=\"wp-block-paragraph\">As a general rule, the LSSI prohibits unsolicited or unauthorized promotional emails. There is an exception for certain prior contractual relationships.<\/p>\n\n<p class=\"wp-block-paragraph\">In that case, the company must have obtained the contact lawfully. Additionally, it can only promote its own products or services similar to those contracted.<\/p>\n\n<p class=\"wp-block-paragraph\">Every commercial email must include a simple and free way to opt out. Unsubscribing must work and be handled without undue delay.<\/p>\n\n<h3 class=\"wp-block-heading\">Is double opt-in mandatory according to the LOPD?<\/h3>\n\n<p class=\"wp-block-paragraph\">Double opt-in doesn&#8217;t appear as a general obligation under that name. However, it is very useful for confirming the address and keeping solid evidence.<\/p>\n\n<p class=\"wp-block-paragraph\">The user fills out the form and receives a confirmation email. They only join the list after clicking the link.<\/p>\n\n<p class=\"wp-block-paragraph\">This process reduces fake sign-ups, errors, and third-party addresses. It also improves the quality of your subscriber base.<\/p>\n\n<h3 class=\"wp-block-heading\">Can you buy databases for email marketing?<\/h3>\n\n<p class=\"wp-block-paragraph\">Buying a list doesn&#8217;t make its contacts usable. The seller must prove the lawful origin, the information provided, and the applicable authorization.<\/p>\n\n<p class=\"wp-block-paragraph\">Furthermore, the mailing must comply with the LSSI. An address published on the internet doesn&#8217;t grant automatic permission to send advertising either.<\/p>\n\n<p class=\"wp-block-paragraph\">That&#8217;s why bought lists pose a high legal and reputational risk. They also tend to generate complaints, bounces, and deliverability issues.<\/p>\n\n<h3 class=\"wp-block-heading\">How to manage campaigns that respect the Data Protection Law<\/h3>\n\n<p class=\"wp-block-paragraph\">At <a href=\"https:\/\/mailrelay.com\/en\/\">Mailrelay, our email marketing platform<\/a>, we help you create campaigns, lists, segments, and automations from a simple dashboard.<\/p>\n\n<p class=\"wp-block-paragraph\">We also offer real-time statistics, click maps, A\/B testing, and custom fields. These features allow you to work with more relevant audiences and measure results.<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Our free plan supports up to 80,000 monthly emails and 20,000 contacts. It also includes multilingual support via phone, chat, and tickets, even on free accounts.<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">Technology makes management easier, but it doesn&#8217;t replace the legal decisions of the data controller. Each company must define its legal basis, its texts, and its retention periods.<\/p>\n\n<p class=\"wp-block-paragraph\">We recommend keeping lists clean, importing only legitimate contacts, and handling unsubscribes. Additionally, responsible segmentation reduces unnecessary emails.<\/p>\n\n<h2 class=\"wp-block-heading\">LOPD checklist for forms and newsletters<\/h2>\n\n<p class=\"wp-block-paragraph\">Before activating lead generation or a campaign, review these points:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>The form identifies the data controller.<\/li>\n\n\n\n<li>The purpose of the mailing is stated specifically.<\/li>\n\n\n\n<li>The legal basis is defined and documented.<\/li>\n\n\n\n<li>The consent checkbox isn&#8217;t pre-ticked.<\/li>\n\n\n\n<li>The privacy policy is accessible before sign-up.<\/li>\n\n\n\n<li>Proof of consent is recorded.<\/li>\n\n\n\n<li>Each campaign clearly identifies the sender.<\/li>\n\n\n\n<li>All messages include a functional unsubscribe mechanism.<\/li>\n\n\n\n<li>Unsubscribes also apply to automations and segments.<\/li>\n\n\n\n<li>Access to the list follows the principle of least privilege.<\/li>\n\n\n\n<li>There are retention periods and a deletion policy.<\/li>\n\n\n\n<li>Vendors have contracts and reviewed guarantees.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">This list works as an initial check. However, it doesn&#8217;t replace a legal analysis adapted to the activity and risk.<\/p>\n\n<h2 class=\"wp-block-heading\">Common mistakes when applying the LOPD in digital marketing<\/h2>\n\n<p class=\"wp-block-paragraph\">One of the most common mistakes is using copied texts. A generic policy might describe processing activities that don&#8217;t exist and omit real ones.<\/p>\n\n<p class=\"wp-block-paragraph\">Another mistake is grouping several purposes under a single acceptance. The user must understand what they will receive and which uses are optional.<\/p>\n\n<p class=\"wp-block-paragraph\">It is also incorrect to condition a service on unnecessary consent. Consent is no longer free when the user doesn&#8217;t have a real alternative.<\/p>\n\n<p class=\"wp-block-paragraph\">Likewise, many companies keep inactive contacts indefinitely. The lack of a retention criterion increases risk and contradicts minimization.<\/p>\n\n<p class=\"wp-block-paragraph\">Lastly, some organizations believe that registering files with the AEPD is still mandatory. That system belonged to the previous framework and no longer applies.<\/p>\n\n<h2 class=\"wp-block-heading\">Penalties for failing to comply with the Organic Law on Data Protection<\/h2>\n\n<p class=\"wp-block-paragraph\">Non-compliance can lead to warnings, adaptation orders, and processing limitations. It can also result in claims, reputational damage, and financial penalties.<\/p>\n\n<p class=\"wp-block-paragraph\">The most serious GDPR infringements can reach 20 million euros. For companies, the limit can reach 4% of the total worldwide annual turnover of the preceding financial year.<\/p>\n\n<p class=\"wp-block-paragraph\">Other infringements can reach 10 million euros or 2% of the global annual turnover. The higher figure on each scale applies.<\/p>\n\n<p class=\"wp-block-paragraph\">The amount isn&#8217;t calculated automatically. Factors such as severity, duration, intentionality, cooperation, and corrective measures are considered.<\/p>\n\n<p class=\"wp-block-paragraph\">Complying with the <strong>LOPD<\/strong> shouldn&#8217;t be considered just to avoid fines. Transparent management builds trust and improves the relationship with customers and subscribers.<\/p>\n\n<h2 class=\"wp-block-heading\">Frequently asked questions about the LOPD<\/h2>\n\n<h3 class=\"wp-block-heading\">Is the LOPD still in force in Spain?<\/h3>\n\n<p class=\"wp-block-paragraph\">Organic Law 15\/1999 has been repealed. Today, the GDPR and Organic Law 3\/2018, known as the LOPDGDD, apply.<\/p>\n\n<h3 class=\"wp-block-heading\">What does LOPD mean?<\/h3>\n\n<p class=\"wp-block-paragraph\">It stands for Organic Law on Data Protection. In current searches, the term is often used to refer to the set of Spanish privacy regulations.<\/p>\n\n<h3 class=\"wp-block-heading\">What is the difference between the LOPD and the GDPR?<\/h3>\n\n<p class=\"wp-block-paragraph\">The GDPR is a European Union regulation. The Spanish law adapts and completes that framework regarding national matters and digital rights.<\/p>\n\n<h3 class=\"wp-block-heading\">Who must comply with the Organic Law on Data Protection?<\/h3>\n\n<p class=\"wp-block-paragraph\">Any entity or professional processing personal data within its scope. This includes most companies, freelancers, and associations.<\/p>\n\n<h3 class=\"wp-block-heading\">Do I need consent to send a newsletter?<\/h3>\n\n<p class=\"wp-block-paragraph\">You usually need a prior request or authorization. The LSSI contemplates a limited exception for customers and similar own products or services.<\/p>\n\n<h3 class=\"wp-block-heading\">Can I send advertising to emails found on the internet?<\/h3>\n\n<p class=\"wp-block-paragraph\">Not simply because they are public. You must have a valid basis and meet the requirements applicable to commercial communications.<\/p>\n\n<h3 class=\"wp-block-heading\">How much time do I have to respond to a right of access or erasure?<\/h3>\n\n<p class=\"wp-block-paragraph\">As a general rule, one month from receipt. The deadline can be extended by two months in complex cases, but you must inform them of the extension.<\/p>\n\n<h3 class=\"wp-block-heading\">When should I report a data breach to the AEPD?<\/h3>\n\n<p class=\"wp-block-paragraph\">When it&#8217;s likely to involve a risk to rights and freedoms. The notification must be made without delay and, at the latest, within 72 hours of becoming aware of it.<\/p>\n\n<h3 class=\"wp-block-heading\">Does double opt-in guarantee LOPD compliance?<\/h3>\n\n<p class=\"wp-block-paragraph\">It doesn&#8217;t guarantee it on its own. It provides useful evidence, but you must also comply with information, purpose, security, and other requirements.<\/p>\n\n<h3 class=\"wp-block-heading\">Does using Mailrelay make my campaigns automatically comply with the regulation?<\/h3>\n\n<p class=\"wp-block-paragraph\">No platform replaces the obligations of the data controller. Mailrelay provides features to manage campaigns, contacts, unsubscribes, segmentation, and statistics in an organized way.<\/p>\n\n<h3 class=\"wp-block-heading\">Is it necessary to register files with the AEPD?<\/h3>\n\n<p class=\"wp-block-paragraph\">No. That obligation belonged to the previous system. Now you must apply proactive responsibility and keep documentation proving compliance.<\/p>\n\n<h3 class=\"wp-block-heading\">At what age can a minor consent to the processing of their data in Spain?<\/h3>\n\n<p class=\"wp-block-paragraph\">Spanish legislation sets 14 years of age for consent based on the minor&#8217;s will. Below that age, whoever exercises parental authority or guardianship must intervene.<\/p>\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Disclaimer: This content is informational and doesn&#8217;t constitute legal advice. The specific application depends on each processing activity, purpose, and organization.<\/strong><\/p>\n<\/blockquote>\n","protected":false},"template":"","class_list":["post-91623","glossary","type-glossary","status-publish","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>LOPD - Mailrelay<\/title>\n<meta name=\"description\" content=\"Discover what the LOPD is, which regulation is currently in force, who it affects, and how to comply with the Organic Law on Data Protection in email marketing\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/mailrelay.com\/en\/glossary\/lopd-organic-law-data-protection\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"LOPD - Mailrelay\" \/>\n<meta property=\"og:description\" content=\"Discover what the LOPD is, which regulation is currently in force, who it affects, and how to comply with the Organic Law on Data Protection in email marketing\" \/>\n<meta property=\"og:url\" content=\"https:\/\/mailrelay.com\/en\/glossary\/lopd-organic-law-data-protection\/\" \/>\n<meta property=\"og:site_name\" content=\"Mailrelay\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Mailrelay\/\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-25T09:42:27+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@mailrelay\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/mailrelay.com\\\/en\\\/glossary\\\/lopd-organic-law-data-protection\\\/\",\"url\":\"https:\\\/\\\/mailrelay.com\\\/en\\\/glossary\\\/lopd-organic-law-data-protection\\\/\",\"name\":\"LOPD - Mailrelay\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/mailrelay.com\\\/en\\\/#website\"},\"datePublished\":\"2026-09-02T17:46:53+00:00\",\"dateModified\":\"2026-09-25T09:42:27+00:00\",\"description\":\"Discover what the LOPD is, which regulation is currently in force, who it affects, and how to comply with the Organic Law on Data Protection in email marketing\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/mailrelay.com\\\/en\\\/glossary\\\/lopd-organic-law-data-protection\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/mailrelay.com\\\/en\\\/glossary\\\/lopd-organic-law-data-protection\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/mailrelay.com\\\/en\\\/glossary\\\/lopd-organic-law-data-protection\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/mailrelay.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"LOPD\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/mailrelay.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/mailrelay.com\\\/en\\\/\",\"name\":\"Mailrelay\",\"description\":\"Mailrelay.com - Email Marketing Software\",\"publisher\":{\"@id\":\"https:\\\/\\\/mailrelay.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/mailrelay.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/mailrelay.com\\\/en\\\/#organization\",\"name\":\"Mailrelay\",\"url\":\"https:\\\/\\\/mailrelay.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/mailrelay.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/mailrelay.com\\\/wp-content\\\/uploads\\\/2019\\\/05\\\/mailrelay-logo.jpg\",\"contentUrl\":\"https:\\\/\\\/mailrelay.com\\\/wp-content\\\/uploads\\\/2019\\\/05\\\/mailrelay-logo.jpg\",\"width\":613,\"height\":291,\"caption\":\"Mailrelay\"},\"image\":{\"@id\":\"https:\\\/\\\/mailrelay.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Mailrelay\\\/\",\"https:\\\/\\\/x.com\\\/mailrelay\",\"https:\\\/\\\/www.youtube.com\\\/mailrelay-email-marketing\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"LOPD - Mailrelay","description":"Discover what the LOPD is, which regulation is currently in force, who it affects, and how to comply with the Organic Law on Data Protection in email marketing","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/mailrelay.com\/en\/glossary\/lopd-organic-law-data-protection\/","og_locale":"en_US","og_type":"article","og_title":"LOPD - Mailrelay","og_description":"Discover what the LOPD is, which regulation is currently in force, who it affects, and how to comply with the Organic Law on Data Protection in email marketing","og_url":"https:\/\/mailrelay.com\/en\/glossary\/lopd-organic-law-data-protection\/","og_site_name":"Mailrelay","article_publisher":"https:\/\/www.facebook.com\/Mailrelay\/","article_modified_time":"2026-09-25T09:42:27+00:00","twitter_card":"summary_large_image","twitter_site":"@mailrelay","twitter_misc":{"Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/mailrelay.com\/en\/glossary\/lopd-organic-law-data-protection\/","url":"https:\/\/mailrelay.com\/en\/glossary\/lopd-organic-law-data-protection\/","name":"LOPD - Mailrelay","isPartOf":{"@id":"https:\/\/mailrelay.com\/en\/#website"},"datePublished":"2026-09-02T17:46:53+00:00","dateModified":"2026-09-25T09:42:27+00:00","description":"Discover what the LOPD is, which regulation is currently in force, who it affects, and how to comply with the Organic Law on Data Protection in email marketing","breadcrumb":{"@id":"https:\/\/mailrelay.com\/en\/glossary\/lopd-organic-law-data-protection\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/mailrelay.com\/en\/glossary\/lopd-organic-law-data-protection\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/mailrelay.com\/en\/glossary\/lopd-organic-law-data-protection\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/mailrelay.com\/en\/"},{"@type":"ListItem","position":2,"name":"LOPD"}]},{"@type":"WebSite","@id":"https:\/\/mailrelay.com\/en\/#website","url":"https:\/\/mailrelay.com\/en\/","name":"Mailrelay","description":"Mailrelay.com - Email Marketing Software","publisher":{"@id":"https:\/\/mailrelay.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/mailrelay.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/mailrelay.com\/en\/#organization","name":"Mailrelay","url":"https:\/\/mailrelay.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/mailrelay.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/mailrelay.com\/wp-content\/uploads\/2019\/05\/mailrelay-logo.jpg","contentUrl":"https:\/\/mailrelay.com\/wp-content\/uploads\/2019\/05\/mailrelay-logo.jpg","width":613,"height":291,"caption":"Mailrelay"},"image":{"@id":"https:\/\/mailrelay.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Mailrelay\/","https:\/\/x.com\/mailrelay","https:\/\/www.youtube.com\/mailrelay-email-marketing"]}]}},"uagb_featured_image_src":[],"uagb_author_info":{"display_name":"Jose Argudo","author_link":"https:\/\/mailrelay.com\/en\/blog\/author\/"},"uagb_comment_info":0,"uagb_excerpt":"The LOPD is the name many people use to refer to Spanish privacy regulations. However, the old Organic Law 15\/1999 is no longer in force. Today, data protection in Spain is mainly governed by the European GDPR and Organic Law 3\/2018. The latter is known as the LOPDGDD. In short, these regulations govern how to&hellip;","_links":{"self":[{"href":"https:\/\/mailrelay.com\/en\/wp-json\/wp\/v2\/glossary\/91623","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mailrelay.com\/en\/wp-json\/wp\/v2\/glossary"}],"about":[{"href":"https:\/\/mailrelay.com\/en\/wp-json\/wp\/v2\/types\/glossary"}],"version-history":[{"count":2,"href":"https:\/\/mailrelay.com\/en\/wp-json\/wp\/v2\/glossary\/91623\/revisions"}],"predecessor-version":[{"id":95037,"href":"https:\/\/mailrelay.com\/en\/wp-json\/wp\/v2\/glossary\/91623\/revisions\/95037"}],"wp:attachment":[{"href":"https:\/\/mailrelay.com\/en\/wp-json\/wp\/v2\/media?parent=91623"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}