Skip to main content
Home
  • Ethics and good governance
  • Values
  • Experts
  • Areas / sectors
    • Public Law
      Agri-food
      Arbitration
      Art and Cultural Heritage
      Competition
      Commercial Contracts
      Economía circular
      Energy
      Project Finance
      Finance & Banking
      Tax
      Mergers and acquisitions
      Infrastructure
      Real Estate
      Gaming & Gambling
      Employment
      Antitrust litigation
      Capital Markets
      Civil Litigation
      Criminal
      Restructuring and insolvency
      Financial Regulation and CISs
      Healthcare
      Corporate and Corporate Governance
      Information Technology
      Urban Planning and Environment
  • International
  • Talent
  • News
    • News
    • Events
    • Newsletter
    • Press Release
  • Blogs
    • Competition and agri-food blog
    • Ramón y cajal digital blog
  • Offices
  • linkedin
  • twitter
  • search
  • Legal Notice
  • Cookies Policy
  • Privacy Policy
  • Information security policy
  • Whistleblowing Channel
Español
#SomosRyC
New version of the Guide on personal data breach notification
26 de May de 2021

The Spanish Data Protection Authority (hereinafter, the “SDPA”) published yesterday, 25 May 2021, the new version of its "Guide on Personal Data Breach Notification" ("Guide").

The Spanish supervisory authority had published the first version of the Guide in June 2018, the year in which the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (“GDPR”) started to be implemented.

The main purpose of the Guide is to provide data controllers with instructions on how to comply with their obligations to notify data breaches affecting personal data to the supervisory authorities (Article 33 of the GDPR) and, where appropriate, to those affected by the data breach (Article 34 of the GDPR).

The new version of the Guide includes the experience gathered since the implementation of the GDPR by the SDPA, other supervisory authorities and the European Data Protection Broad. Likewise, the new version of the Guide includes some clearer indications with respect to the previous version on the obligations of data controllers in this area. For example, the SDPA has clarified that the 72-hour deadline for notifying a data breach to the supervisory authority includes the hours elapsed during weekends and bank holidays.

Please access the full Guide here[1].

 


[1] Only available in Spanish.

Further information:

Norman Heckh (nheckh@ramoncajal.com)

María Luisa González (mlgonzalez@ramoncajal.com)

Antonio Borjas (aborjas@ramoncajal.com)

Pablo Tena (ptena@ramoncajal.com)

Andrés Ruiz (aruiz@ramoncajal.com)

Madrid

Almagro, 16-18
Madrid 28010
T: (+34) 91 576 19 00

Barcelona

Avenida Diagonal 615, 8ª planta.
08028
T (+34) 93 494 74 82

Ramón y Cajalabogados
#SomosRyC
New version of the Guide on personal data breach notification
26 de May de 2021

The Spanish Data Protection Authority (hereinafter, the “SDPA”) published yesterday, 25 May 2021, the new version of its "Guide on Personal Data Breach Notification" ("Guide").

The Spanish supervisory authority had published the first version of the Guide in June 2018, the year in which the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (“GDPR”) started to be implemented.

The main purpose of the Guide is to provide data controllers with instructions on how to comply with their obligations to notify data breaches affecting personal data to the supervisory authorities (Article 33 of the GDPR) and, where appropriate, to those affected by the data breach (Article 34 of the GDPR).

The new version of the Guide includes the experience gathered since the implementation of the GDPR by the SDPA, other supervisory authorities and the European Data Protection Broad. Likewise, the new version of the Guide includes some clearer indications with respect to the previous version on the obligations of data controllers in this area. For example, the SDPA has clarified that the 72-hour deadline for notifying a data breach to the supervisory authority includes the hours elapsed during weekends and bank holidays.

Please access the full Guide here[1].

 


[1] Only available in Spanish.

Further information:

Norman Heckh (nheckh@ramoncajal.com)

María Luisa González (mlgonzalez@ramoncajal.com)

Antonio Borjas (aborjas@ramoncajal.com)

Pablo Tena (ptena@ramoncajal.com)

Andrés Ruiz (aruiz@ramoncajal.com)

Madrid

Almagro, 16-18
Madrid 28010
T: (+34) 91 576 19 00

Barcelona

Avenida Diagonal 615, 8ª planta.
08028
T (+34) 93 494 74 82