The LOPDGDD adapts the Spanish framework to the RGPD and regulates key aspects of the processing of personal data in Spain.
For a company, data protection and security should not be separated: access controls, copies, suppliers, incidents and traceability are necessary in both worlds.
Legal notices, privacy, cookies, analytics and contact forms also come into play on a corporate website.
What a company should review
- Legal basis and duty of information.
- Contracts with treatment managers and suppliers.
- Appropriate technical and organizational measures.
- Management of security breaches and evidence.
How we work at Blue Moon
The practical recommendation is not to approach each standard as an isolated folder. ISO 27001, ENS, NIS2, DORA, data protection and secure development share assets, risks, controls, suppliers, incidents and evidence.
We can review whether this rule affects your company and turn it into a clear, prioritized and acceptable roadmap.
Request diagnosis →