Beginning Of The Sanctioning Regime Of The Organic Law On Personal Data Protection

Published date05 June 2023
Subject MatterPrivacy, Data Protection
Law FirmCorralRosales
AuthorCorral Rosales

On May 26, 2021, the Organic Law for the Protection of Personal Data (the "LOPDP") entered into force with its publication in Official Gazette Supplement 459. However, the sanctioning regime began to apply as of May 26, 2023, as established in the First Transitory Provision: "(the...) provisions related to the corrective measures and the sanctioning regime will enter into force two years after the publication of this Law in the Official Gazette".

In the course of this time, whoever oversees the processing of personal data had to adapt its activities to the precepts established in the LOPDP, whose purpose is to protect the fundamental rights and freedoms of data owners and their right to the protection of personal data.

The process of adapting to the new information processing depends on the type of company (public entity, multinational, SME, self-employed, among others) and, above all, on the types of data processed (health data, credit data, data of children or adolescents).

The main obligations of companies are summarized below:

1. Scope of application of the LOPDP:

  • The law is applicable to any processing of personal data whether in physical or digital format, including its automation and any additional use.
  • Both legal and natural persons, public or private, must comply with the obligations imposed by the LOPDP.

2. Individuals involved in data protection:

  • The controller is the person, natural or legal, who decides on the purpose and treatment of the personal data collected.
  • The processor is the person who provides a service to the controller that involves the processing of personal data in the name and on behalf of the Controller.
  • The data subject is the natural person whose data is subject to processing, such as name, surname, ID card number, health data religion, credit data, gender, ethnicity, fingerprint, among others.

3. New obligations:

The LOPDP obliges to include new warnings, for example: the legal basis for data processing or data retention periods. In addition to the following:

  • Consent: this must be a free, specific, informed, and unequivocal manifestation. This implies that the data controller must be able to prove that it had the consent of the data subject.
  • Relationship between data controllers and data processors describes the type of contract between the data...

To continue reading

Request your trial

VLEX uses login cookies to provide you with a better browsing experience. If you click on 'Accept' or continue browsing this site we consider that you accept our cookie policy. ACCEPT