Spain’s Organic Law 3/2018 is not the law that was published. It has been amended several times, and some of those changes affect very concrete parts of a company’s daily life: how long the Agency has to sanction you, where your whistleblowing channel is now regulated, and what you may do with advertising exclusion lists. Here is each amendment to Spain’s Data Protection Act and what it obliges you to review.
In this article we will discuss...
2021: scope of application
Organic Law 7/2021 of 26 May amended Article 2 to adjust the scope of application in relation to processing for the purposes of preventing and investigating criminal offences. It is the reform with the least impact for an ordinary company: worth knowing, but it requires no changes.
2023: the whistleblowing channel leaves the Act
Law 2/2023 of 20 February, on the protection of persons who report regulatory breaches, amended Article 24. That article was retitled “Processing of data for the protection of persons reporting regulatory breaches” and now refers the regime of the internal system to Law 2/2023 itself.
The change matters more than it looks. Any organisation with a channel implemented before 2023, with documentation built on the old Article 24, has a structural problem: the retention periods, the figure of the system manager, the confidentiality regime protecting the reporting person and the information duties are no longer where they used to be. The record of processing activities, the channel policy and the appointment of the person responsible all need updating.
2023: the deadlines that matter if proceedings are opened against you
The reform with the greatest practical consequences came with Law 11/2023 of 8 May, which amended Articles 48(2), 50, 64, 65, 66(1), 67(2), 75 and 77(2), and inserted an Article 53 bis. These are the changes that count:
- The warning is configured as a procedure distinct from the sanctioning one, lasting six months.
- The sanctioning procedure goes from nine to twelve months.
- Preliminary investigation actions go from twelve to eighteen months.
- Investigation by digital means is expressly enabled.
- Mandatory forms are imposed for lodging complaints with the Agency.
Adding preliminary actions and the procedure itself, a company’s exposure window before the Spanish Agency goes from twenty-one months to two and a half years. And the preliminary phase, which many organisations treat as a minor formality, has become the longest one: it is where the file that will later be decided is actually built. Answering a first request for information properly is worth far more today than it was in 2018.
2025: advertising exclusion lists
In December 2025, the law on customer service amended Article 23, which governs advertising exclusion systems. The new wording restricts who may operate them — representative bodies under Article 40(2) GDPR — limits the data that may be included to the strict minimum, provides for preference services and leaves the detail to implementing regulations.
If your company does direct marketing, this is the reform that concerns you. Consulting the opt-out list before a campaign remains mandatory; what changes is the framework governing those systems and the data they hold.
What has not been amended
This is worth stating too, because there is a good deal of noise about it. To date, Article 32 on data blocking has not been amended, nor has Title X on digital rights. Anyone whose documentation is built on those provisions does not need to redo it.
What is coming: the AI governance act
Before the Spanish Parliament is the draft organic law on the good use and governance of artificial intelligence, approved by the Council of Ministers in May 2026 and published in the parliamentary gazette in June. It designates the Spanish AI Supervision Agency as the single point of contact and confers on the Data Protection Agency supervisory powers over prohibited practices and biometrics. Its sanctioning regime provides for fines of up to 35 million euros or 7% of turnover.
It is not yet law, but it tells you who will be knocking on the door once it is. For a company using biometrics — access control, time recording, identity verification — it is notice that your file could end up before the Spanish Agency through two separate routes.
In parallel, the European digital omnibus package that would amend the GDPR itself remains in the legislative pipeline. Worth following, but not worth anticipating changes that do not yet exist.
What to review in your company
- Record of processing activities: move the whistleblowing channel activity across to Law 2/2023, review the direct marketing activity after the new Article 23 and register any activities involving artificial intelligence.
- Internal channel policy: retention periods, system manager and confidentiality regime in line with Law 2/2023, not the old Article 24.
- Internal procedure for dealing with the Agency: who receives a request, who answers it and within what time. With eighteen months of preliminary actions, improvising is expensive.
- Information notices: check they remain consistent with the legal bases declared.
- Marketing: review the use of advertising exclusion systems and the prior consultation before campaigns.
None of these reforms requires rebuilding a compliance system from scratch. All of them require reviewing specific documents which, in most companies, are still drafted as they were in 2018. That gap between what the documentation says and what the law now says is exactly what surfaces in a data protection audit.





Leave a Reply
Want to join the discussion?Feel free to contribute!