Ley Orgánica De Protección De Datos De Carácter Personal
   HOME

TheInfoList



OR:

The Organic Law 15/1999 of December 13 on Protection of Personal Data ( es, Ley Orgánica de Protección de Datos de Carácter Personal, LOPD) was Spanish organic law that guaranteed and protected the processing of personal data, public liberties, and
fundamental human rights Human rights are moral principles or normsJames Nickel, with assistance from Thomas Pogge, M.B.E. Smith, and Leif Wenar, 13 December 2013, Stanford Encyclopedia of PhilosophyHuman Rights Retrieved 14 August 2014 for certain standards of hum ...
, and especially of personal and family
honor Honour (British English) or honor (American English; see spelling differences) is the idea of a bond between an individual and a society as a quality of a person that is both of social teaching and of personal ethos, that manifests itself as a ...
and
privacy Privacy (, ) is the ability of an individual or group to seclude themselves or information about themselves, and thereby express themselves selectively. The domain of privacy partially overlaps with security, which can include the concepts of a ...
. It was approved by the General Court on December 13, 1999. This law was developed based on Article 18 of the
Spanish Constitution of 1978 The Spanish Constitution (Spanish, Asturleonese, and gl, Constitución Española; eu, Espainiako Konstituzioa; ca, Constitució Espanyola; oc, Constitucion espanhòla) is the democratic law that is supreme in the Kingdom of Spain. It was e ...
, the familiar and personal
right to privacy The right to privacy is an element of various legal traditions that intends to restrain governmental and private actions that threaten the privacy of individuals. Over 150 national constitutions mention the right to privacy. On 10 December 1948 ...
, and the secrecy of communications. Its main objective was to regulate the treatment of data and files, of a personal nature, regardless of the support in which they are treated, the rights of citizens over them and the obligations of those who create or treat them. This law affected all data that referred to registered humans on any support, computer or otherwise. Excluded from this regulation are those data collected for domestic use, classified materials of the state and those files that collected data on Terrorism and other forms of
organized crime Organized crime (or organised crime) is a category of transnational, national, or local groupings of highly centralized enterprises run by criminals to engage in illegal activity, most commonly for profit. While organized crime is generally th ...
(not simple delinquency). Based on this law, the Spanish Agency for Data Protection was created, at the state level, which ensures compliance with this Law. This act was repealed by the passage of a new data protection act, the Organic Law 3/2018 of December 5, about protection of personal data and guarantees of digital rights, to conform the Spanish legislation with the
General Data Protection Regulation The General Data Protection Regulation (GDPR) is a European Union regulation on data protection and privacy in the EU and the European Economic Area (EEA). The GDPR is an important component of EU privacy law and of human rights law, in partic ...


Regulatory development

* The Royal Decree 994/1999 on Security Measures for automated files that containing personal data of June 11, 1999 (RMS): It is a regulation that develops the Organic Law 5/1992, of October 29, of Regulation of the Automated Treatment of Personal Data (LORTAD), regulates the technical and organizational measures that must be applied to the information systems in which personal data are processed in an automated way. (Repealed since April 19 of 2010) * The Royal Decree 1720/2007, of December 21 on the development of the Organic Law on Data Protection. It is a development of the Organic Law 15/99 of Data Protection of December 13; develops the principles of the law, and the security measures to be applied in the information systems. It applies to files in automated support, as in any other type of media.


Control bodies and possible sanctions

The body responsible for monitoring compliance with data protection regulations at Spanish territory, in general, is the Spanish Agency for Data Protection (AEPD), there are other Data Protection Agencies of an autonomous nature, in
Autonomous Communities eu, autonomia erkidegoa ca, comunitat autònoma gl, comunidade autónoma oc, comunautat autonòma an, comunidat autonoma ast, comunidá autónoma , alt_name = , map = , category = Autonomous administra ...
of
Catalonia Catalonia (; ca, Catalunya ; Aranese Occitan: ''Catalonha'' ; es, Cataluña ) is an autonomous community of Spain, designated as a ''nationality'' by its Statute of Autonomy. Most of the territory (except the Val d'Aran) lies on the north ...
and in Basque Country. The sanctions are divided into three groups depending on the seriousness of the act committed, Spain being the country of the European Union that has the highest sanctions in terms of protection of data. These sanctions depend on the violation committed. The last company sanctioned has been the company Grupon, sanctioned by the state data protection agency, with 20 000 euros for storing the CVV codes of the Credit cards from their customers without informing them. They are divided into: Despite the amount of sanctions, there are many
companies A company, abbreviated as co., is a legal entity representing an association of people, whether natural, legal or a mixture of both, with a specific objective. Company members share a common purpose and unite to achieve specific, declared go ...
in Spain that have not yet adapted to it, or have done so in a partial manner or do not periodically review its adequacy; so that, maintenance and review of the adequacy carried out is essential. In the public sector, the mentioned Law also regulates the use and management of information and files with personal data used by all public administrations. The Spanish Agency for Data Protection ( AEPD) was created in 1994 in accordance with the provisions of the repealed LORTAD. Its headquarters are located in Madrid, although the Autonomous Communities of Madrid, the Basque Country and Catalonia have created their own autonomous Agencies.


Inspection and guardianship of Rights Procedures


Spanish Agency for Data Protection (AEPD)



Year 2012

In 2012 complaints filed with the AEPD, increased by 12%. The activity of the Agency has grown significantly in 2012, with an increase of 15% in the files registered and almost 40% in the resolutions issued. The allegations of identity theft, especially in the supply and commercialization of energy and water (222%) and in telecommunications (92%), have experienced a substantial increase. Of the 863 infringement decisions declared to private managers, more than 34% concluded in a warning, without imposing a penalty. On the other hand, most of the sanctions affect the telecommunications sector, which represents 73% of the total. Three of the main operators accumulate 70.94% of the total amount of fines.



Year 2011

In 2011, reported complaints were 51.6% higher than those filed in 2010. This increase is also reflected in the increase in declaratory resolutions of infringement of 37.7%. However, the application of the figure of the warning has determined a decrease of 14.5% in the declared economic sanctions. The sector where sanctions have increased most (64%) and have been declared to a greater extent (25.5%) and amount, (63%) is that of telecommunications. The amount of sanctions has grown by 12% compared to 2010.


Year 2009

In 2009 they increased by more than 75% of the complaints received, which reached the figure of 4,136, and the number of requests for protection of rights, by 58%. 709 sanctioning procedures were resolved, of which 621 ended with sanction with a total amount of 24.8 million euros. Source: Memory of the Spanish Agency for Data Protection (AEPD) for the years 2007, 2008, 2009.


Year 2008

In 2008 the number of facts reported to the AEPD (together with officio investigations initiated) increased by more than 45%, reaching the value of 2362. AEPD resolved in 2008 a total of 630 sanctioning procedures, almost 58% more than in 2007, of which 535 culminated with the imposition of sanctions. The fines imposed amounted to 22.6 million euros, representing an increase of 15% over the previous year. The number of procedures solved of declarations of infraction committed by the public administrations rose in 2008 almost 20% with respect to the previous year, going from 66 to 79, of which 59 ended with a declaration of infraction.


Year 2007

In 2007 the Spanish Agency for Data Protection resolved 399 sanctioning procedures, increasing by 32.5% with respect to the previous year. The economic sanctions imposed by the AEPD amounted to 19 600 000
euros The euro (symbol: €; code: EUR) is the official currency of 19 out of the member states of the European Union (EU). This group of states is known as the eurozone or, officially, the euro area, and includes about 340 million citizens . T ...
.


Autonomous data protection agencies


Year 2007

The Data Protection Agency of the Community of Madrid carried out 196 inspection procedures and 32 procedures for the protection of rights in 2007. The Basque Data Protection Agency-Datuak Babesteko Euskal Bulegoa (AVDP-DBEB), resolved 43 complaints and 18 infringement procedures in 2007.


Ibero-American Data Protection Network

The Ibero-American Data Protection Network (RIPD), since its creation in 2003, has developed an intense and fruitful work, such as the organization of ten meetings. In addition to contributing to that more than 150 million Latin American citizens currently have, along with the traditional protection of
habeas data ''Habeas data'' is a writ and constitutional remedy available in certain nations. The literal translation from Latin of ''habeas data'' is “ e commandyou have the data,” or "you he data subjecthave the data." The remedy varies from country t ...
, rules that allow to effectively guarantee the use of their personal information and specialized authorities with powers to protect said guarantee. In
Latin America Latin America or * french: Amérique Latine, link=no * ht, Amerik Latin, link=no * pt, América Latina, link=no, name=a, sometimes referred to as LatAm is a large cultural region in the Americas where Romance languages — languages derived f ...
policies are being developed for the protection of personal data. In 2012 two new laws were approved. In
Nicaragua Nicaragua (; ), officially the Republic of Nicaragua (), is the largest country in Central America, bordered by Honduras to the north, the Caribbean to the east, Costa Rica to the south, and the Pacific Ocean to the west. Managua is the cou ...
, Law No. 787 of Protection of Personal Data, of March 29, 2012 and Statutory Law No. 1581 of October 17, 2012, by which general provisions for the Protection of Personal Data are issued. In
Chile Chile, officially the Republic of Chile, is a country in the western part of South America. It is the southernmost country in the world, and the closest to Antarctica, occupying a long and narrow strip of land between the Andes to the east a ...
, also Law 19.628, of August 28, 1999, on Protection of Private Life, is currently in the process of reviewing part of its articles. The
National Assembly of Venezuela The National Assembly ( es, Asamblea Nacional) is the legislature for Venezuela that was first elected in 2000. It is a unicameral body made up of a variable number of members, who were elected by a "universal, direct, personal, and secret" vo ...
is processing the bill for the Protection of Personal Data of Habeas Data. And in
Costa Rica Costa Rica (, ; ; literally "Rich Coast"), officially the Republic of Costa Rica ( es, República de Costa Rica), is a country in the Central American region of North America, bordered by Nicaragua to the north, the Caribbean Sea to the no ...
there is already a Data Protection Agency of the Republic of Costa Rica, in compliance with the law approved in 2011.


Information Duty

Personal data are classified according to their greater or lesser degree of sensitivity, being the legal requirements and computer security measures more stringent in terms of this greater degree of sensitivity, being mandatory on the other hand, in any case the declaration of the data protection files to the "Spanish Agency for Data Protection". Interested parties to which personal data are requested must be previously informed in an express, precise and unambiguous way: 1. The existence of a file or treatment of personal data, the purpose of the collection of these and the recipients of the information. 2. Of the obligatory or optional character of his answer to the questions that are posed to them. 3. The consequences of obtaining the data or the refusal to supply them. 4. Of the possibility of exercising rights of access, rectification, cancellation and opposition. 5. The identity and address of the person responsible for the treatment or, if applicable, his representative. However, the processing of personal data without having been collected directly from the affected party or interested party is permitted, although it is not exempted from the obligation to report expressly, accurately and unequivocally, by the person responsible for the file or its representative, within of the three months following the start of data processing. Exception: Communication in three months of such information will not be necessary if the data has been collected from "sources accessible to the public", and are intended for advertising or commercial prospecting, in this case "in each communication addressed to the interested party, he will be informed of the origin of the data and the identity of the person responsible for the treatment, as well as the rights that assist him". ; Model clause This could be a model clause of information / consent of rights protected by the LOPD: ; Data whose treatment is prohibited * Those relating to "criminal or administrative infractions". * Exception: They can only be included in files of the competent public administrations.


Consent


Types of consent

A) Unmistakable consent The treatment of personal data will require the unambiguous consent of the affected party, unless the law provides otherwise. B) Tacit Consent This will be the normal form of consent in cases where an express or express consent is not required in writing. C) Express consent Personal data referring to racial origin, health and sexual life may only be collected, processed and assigned when, for reasons of general interest, it is provided by a law or the person expressly consents. D) Express and written consent Express consent is required in writing from the affected party regarding data related to ideology, union affiliation, religion and beliefs and may only be transferred with express consent.


Data communication

They have responsibility in the communication and treatment of data not only the
legal persons In law, a legal person is any person or 'thing' (less ambiguously, any legal entity) that can do the things a human person is usually able to do in law – such as enter into contracts, sue and be sued, own property, and so on. The reason for ...
(
companies A company, abbreviated as co., is a legal entity representing an association of people, whether natural, legal or a mixture of both, with a specific objective. Company members share a common purpose and unite to achieve specific, declared go ...
) but also freelancers, freelancers, associations, collectives and people who own a
blog A blog (a truncation of "weblog") is a discussion or informational website published on the World Wide Web consisting of discrete, often informal diary-style text entries (posts). Posts are typically displayed in reverse chronological order ...
(bloggers) through from which data from third parties are collected to make queries and for any other transaction. The personal data object of the treatment can only be communicated to a third party for the fulfillment of purposes directly related to the legitimate functions of the transferor and the transferee with the prior consent of the interested party. The consent required in the previous section will not be precise: # When the assignment is authorized by law. # In the case of data collected from sources accessible to the public. # When the treatment responds to the free and legitimate acceptance of a legal relationship whose development, compliance and control necessarily implies the connection of said treatment with third-party files. In this case the communication will only be legitimate as long as it is limited to the purpose that justifies it. # When the communication to be made is addressed to the Ombudsman, the Public Prosecutor or the Judges or Courts or the Court of Accounts, in the exercise of the functions assigned to it. Neither will consent be required when the communication is addressed to autonomous institutions with analogous functions to the Ombudsman or the Court of Auditors. # When the transfer occurs between Public Administrations and has as its objective the subsequent processing of the data for historical, statistical or scientific purposes. # When the transfer of personal data related to health is necessary to solve an emergency that requires access to a file or to perform epidemiological studies in the terms established in the legislation on state or regional health. The consent for the communication of personal data to a third party will be void when the information provided to the interested party does not allow him to know the purpose to which the data will be destined whose communication is authorized or the type of activity of the person to whom it is sent. They intend to communicate. The consent for the communication of personal data also has a revocable nature. The one to whom the personal data are communicated is obliged, by the mere fact of the communication, to observe the provisions of this Law. If the communication is made prior to the dissociation procedure, the provisions of the previous sections will not apply.


Access to the data by third parties

# The access of a third party to the data will not be considered as data communication when said access is necessary for the provision of a service to the data controller. # The performance of treatments on behalf of third parties must be regulated in a contract that must be recorded in writing or in some other form that allows proof of its conclusion and content, establishing expressly that the processor will only process the data according to the instructions of the person in charge of the treatment, which will not apply them or use them for purposes other than those stated in said contract, nor will they communicate them, even for their preservation, to other persons.
The contract will stipulate, in addition, the security measures to which refers to article 9 of this Law that the person in charge of the treatment is obliged to implement. # Once the contractual provision has been fulfilled, the personal data must be destroyed or returned to the data controller, as well as any support or documents that contain any personal data object of the treatment. # In the event that the person in charge of the treatment allocates the data for another purpose, communicates them or uses them in breach of the stipulations of the contract, it will also be considered responsible for the treatment, responding to the infractions that would have been incurred personally.


Criticisms and main problems

Certain aspects of the law were declared unconstitutional in November 2000 and deleted from the current text. It is considered that the increase in the creation of files and processing of personal data affects the right to protection of citizens' data; This concern was picked up by the European bodies that even ordered that January 28 be held annually on "
European Data Protection Day European, or Europeans, or Europeneans, may refer to: In general * ''European'', an adjective referring to something of, from, or related to Europe ** Ethnic groups in Europe ** Demographics of Europe ** European cuisine, the cuisines of Europe a ...
". The celebration dates back to 2006, when the Committee of Ministers of the Council of Europe established the annual celebration of the Data Protection Day in Europe on January 28, commemorating the anniversary of the signing of Convention 108 of the Council of Europe for the protection of persons with regard to the automated processing of personal data. A very strict compliance with the regulation on data protection could slow down the normal work of a File Manager for the documentary accreditation of the information and consent principles of the LOPD; also in the opposite direction, a mere fulfillment of formal obligations, would leave the law senseless and the citizens unprotected and go against the "spirit" of the LOPD. The possibility that companies can collect data without the consent of the affected has been criticized. Certain resolutions of the AEPD have been reason for controversy: * In October 2008, the Spanish Agency for Data Protection sanctioned the Popular Party ( PP), then in opposition, with a fine of 60 101.21 euros for a serious infringement of the Organic Law of Protection of Personal Data consisting of the inclusion, without their consent, of four
O Grove O Grove (alternative spelling: ''Ogrobe'') is a municipality belonging to the province of Pontevedra, in Galicia, Spain. A peninsula that faces the Atlantic Ocean and the shores of O Salnés valley, enclosed by the southern Galician estuaries, ...
neighbors as "false volunteers" of the election lists of Basque Country of May 2007. * The possibility offered by some websites to "send a friend" certain information, or "recommend this page to a friend" have also been sanctioned in strict application of the LOPD * La AEPD también resolvió que los datos relativos a los abortos practicados eran confidenciales, a raíz de la denuncias criminales interpuestas contra varias clínicas por presuntos abortos irregulares * The AEPD also resolved that the data regarding the abortions practiced were confidential, as a result of the criminal complaints filed against several clinics for alleged irregular abortions * In 2008, a judgment of the Supreme Court declared that the "baptismal books" of the
Catholic Church The Catholic Church, also known as the Roman Catholic Church, is the largest Christian church, with 1.3 billion baptized Catholics worldwide . It is among the world's oldest and largest international institutions, and has played a ...
are not "data files", disavowing a resolution of October 20, 2006 issued by the Spanish Agency for the Protection of Data; the agency had given the reason to an apostate who requested that, through the Agency, his inscription in the Baptism Book be canceled. * Due to breaches of data protection legislation, several insurers and health centers have been sanctioned, since they exchanged medical information about patients without their express consent. However, they are subject to reduced sanctions for not being assessed "intentionality in the commission of the offense" * AEPD sanctioned a company after a hacker attempted to blackmail it by finding a hole in its security and later denounced it * The LOPD continues to have gaps and social agents have requested certain reforms. In August 2008,
Bernat Soria Bernat Soria Escoms (born 7 May 1951) is a Spanish scientist. He is also affiliated with the Spanish Socialist Workers' Party, for whom he served as Minister of Health from 2007 to 2009. He was educated at the University of Valencia (MD, PhD), an ...
, Socialist Minister of Health and Consumer Affairs stated that action would be taken to create a law against companies that were making commercial calls not consented to homes, usually at meal times, which was a behavior popularly known as " telephone spam".«Fence to the 'junk calls'.
The Government wants to end the unsolicited calls, with the annoying and increasingly frequent telephone spam, with ringing at the time of nap to the fixed or to the mobile to offer a change of operator, a new credit or an offer of connection to Int ernet, often produced from "private numbers" or "unknown" or local locutions or from abroad, which makes it impossible for the consumer to report it. The Ministry of Health and Consumer Affairs in collaboration with the Ministry of Justice, Economy and Industry are working on a preliminary bill to transpose a European directive that considers this practice illegal. The Government expects to enter into force before the end of the year ... "Many are also produced at the time of siesta or at night, which makes them even more annoying," adds the head of Health and Consumption. Until now these practices were not regulated in a specific way. There is a law (of 2002) that prohibits unwanted email. (''
El Pais EL, El or el may refer to: Religion * El (deity), a Semitic word for "God" People * EL (rapper) (born 1983), stage name of Elorm Adablah, a Ghanaian rapper and sound engineer * El DeBarge, music artist * El Franco Lee (1949–2016), American p ...
'', August 2008).


See also

* Fundamental rights in the personal sphere *
Privacy Privacy (, ) is the ability of an individual or group to seclude themselves or information about themselves, and thereby express themselves selectively. The domain of privacy partially overlaps with security, which can include the concepts of a ...
*
Internet security Internet security is a branch of computer security. It encompasses the Internet, browser security, web site security, and network security as it applies to other applications or operating systems as a whole. Its objective is to establish rules a ...
*
Spam Spam may refer to: * Spam (food), a canned pork meat product * Spamming, unsolicited or undesired electronic messages ** Email spam, unsolicited, undesired, or illegal email messages ** Messaging spam, spam targeting users of instant messaging ( ...
*
European Data Protection Supervisor The European Data Protection Supervisor (EDPS) is an independent supervisory authority whose primary objective is to monitor and ensure that European institutions and bodies respect the right to privacy and data protection when they process pers ...


References


Bibliography

Translation of : "LOPD in Spanish"


External links


Organic Law 5/1992, of October 29, on Regulation of the automated processing of personal data
(LORTAD)
Organic Law 15/1999, of December 13, Protection of Personal Data
(LOPD)
Royal Decree 1720/2007, of December 21, by which the Regulation of development of the Organic Law 15/1999, of December 13, of protection of personal data is approved
(RLOPD)

(English)
Introduction to LOPD

Link of the Spanish Agency for Data Protection for File Registration

Association of Data Protection Companies

Protection of Personal Data in Spain

Latin American Journal of Protection of Personal Data
{{Authority control 1999 in Spain Consumer protection law Data laws of Europe Medical records Privacy law Protection of Personal Data