Pasar al contenido principal
Inicio
  • Valores
  • Ética y buen gobierno
  • Expertos
  • Áreas / sectores
    • Administrativo y sectores regulados
      Agroalimentario
      Arbitraje
      Arte y Patrimonio Cultural
      Competencia
      Contratación comercial
      Economía circular
      Energía
      Financiación de proyectos
      Financiero y Bancario
      Fiscal
      Fusiones y adquisiciones
      Infraestucturas
      Inmobiliario
      Juego
      Laboral
      Litigación civil derivada de conductas anticompetitivas
      Mercado de Capitales
      Procesal Civil
      Procesal Penal
      Reestructuraciones e insolvencias
      Regulación financiera e inversiones alternativas
      Salud
      Societario y Gobierno Corporativo
      Tecnologías de la Información
      Urbanismo y medioambiente
  • Internacional
  • Talento
  • Actualidad
    • Noticias
    • Eventos
    • Newsletter
    • Sala de Prensa
  • Blogs
    • Blog Competencia y Agroalimentario
    • Blog Ramón y Cajal Digital
  • Contactar
  • linkedin
  • twitter
  • search
  • Aviso Legal
  • Política de Cookies
  • Política de Privacidad
  • Canal de Denuncias
  • Política de seguridad de la información
English
#SomosRyC
New version of the Guide on personal data breach notification
26 de Mayo de 2021

The Spanish Data Protection Authority (hereinafter, the “SDPA”) published yesterday, 25 May 2021, the new version of its "Guide on Personal Data Breach Notification" ("Guide").

The Spanish supervisory authority had published the first version of the Guide in June 2018, the year in which the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (“GDPR”) started to be implemented.

The main purpose of the Guide is to provide data controllers with instructions on how to comply with their obligations to notify data breaches affecting personal data to the supervisory authorities (Article 33 of the GDPR) and, where appropriate, to those affected by the data breach (Article 34 of the GDPR).

The new version of the Guide includes the experience gathered since the implementation of the GDPR by the SDPA, other supervisory authorities and the European Data Protection Broad. Likewise, the new version of the Guide includes some clearer indications with respect to the previous version on the obligations of data controllers in this area. For example, the SDPA has clarified that the 72-hour deadline for notifying a data breach to the supervisory authority includes the hours elapsed during weekends and bank holidays.

Please access the full Guide here[1].

 


[1] Only available in Spanish.

Further information:

Norman Heckh (nheckh@ramoncajal.com)

María Luisa González (mlgonzalez@ramoncajal.com)

Antonio Borjas (aborjas@ramoncajal.com)

Pablo Tena (ptena@ramoncajal.com)

Andrés Ruiz (aruiz@ramoncajal.com)

Madrid

Almagro, 16-18
Madrid 28010
T: (+34) 91 576 19 00

Barcelona

Avenida Diagonal 615, 8ª planta.
08028
T (+34) 93 494 74 82

Ramón y Cajalabogados
#SomosRyC
New version of the Guide on personal data breach notification
26 de Mayo de 2021

The Spanish Data Protection Authority (hereinafter, the “SDPA”) published yesterday, 25 May 2021, the new version of its "Guide on Personal Data Breach Notification" ("Guide").

The Spanish supervisory authority had published the first version of the Guide in June 2018, the year in which the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (“GDPR”) started to be implemented.

The main purpose of the Guide is to provide data controllers with instructions on how to comply with their obligations to notify data breaches affecting personal data to the supervisory authorities (Article 33 of the GDPR) and, where appropriate, to those affected by the data breach (Article 34 of the GDPR).

The new version of the Guide includes the experience gathered since the implementation of the GDPR by the SDPA, other supervisory authorities and the European Data Protection Broad. Likewise, the new version of the Guide includes some clearer indications with respect to the previous version on the obligations of data controllers in this area. For example, the SDPA has clarified that the 72-hour deadline for notifying a data breach to the supervisory authority includes the hours elapsed during weekends and bank holidays.

Please access the full Guide here[1].

 


[1] Only available in Spanish.

Further information:

Norman Heckh (nheckh@ramoncajal.com)

María Luisa González (mlgonzalez@ramoncajal.com)

Antonio Borjas (aborjas@ramoncajal.com)

Pablo Tena (ptena@ramoncajal.com)

Andrés Ruiz (aruiz@ramoncajal.com)

Madrid

Almagro, 16-18
Madrid 28010
T: (+34) 91 576 19 00

Barcelona

Avenida Diagonal 615, 8ª planta.
08028
T (+34) 93 494 74 82