Key principles
Personal data must be processed lawfully and transparently, for specific purposes, limited to what is necessary, kept accurate, retained only as long as needed and protected with appropriate security. The organisation must be able to demonstrate compliance, a principle known as accountability.
Security under the GDPR
Article 32 requires technical and organisational measures appropriate to the risk, such as encryption, access control, resilience and regular testing. Article 33 requires notifying a data breach to the authority within 72 hours in most cases. Contracts with service providers that process data on the company's behalf must meet Article 28.
Who enforces it in Spain
The AEPD supervises compliance in Spain. Fines can reach 20 million euros or 4% of global annual turnover, whichever is higher. The full text is available on EUR-Lex.
GDPR and security frameworks
The GDPR does not prescribe a specific standard. Many companies use ISO 27001 to structure their security measures, and in the public sector the ENS measures support the GDPR security requirements. NIS2 and DORA add cybersecurity obligations on top of the GDPR rather than replacing it.




