Spain's Data Protection Law Overview
Spain's Data Protection Law Overview
SUMMA UNIVERSITY
PROJECT MANAGEMENT II
MIAMI
2022
Development
In Spain, Organic Law 15/1999, of December 13, on the protection of personal data
the personal was developed to adapt Directive 95/46/EC. This law aimed to
guarantee and protect, in relation to the processing of personal data and rights
fundamentals of individuals, and especially of their honor and personal privacy
familiar.
The law would apply to personal data recorded in physical format, which the
make them susceptible to treatment, and to any subsequent use modality of this data by the
public and private sectors. All processing of personal data would be governed by law.
when the treatment is carried out in Spanish territory within the framework of activities of a
establishment of the data controller.
After several modifications of the organic law, the European Union (EU) develops the
new Regulation (EU) 2016/679 of the European Parliament and of the Council, known as
General Data Protection Regulation, which came into effect 18 months ago from
Today, it will start to be implemented exactly 4 months from today's date.
resulting mandatory for organizations to implement the new measures. This
Regulation repeals Directive 95/46/EC.
The Regulation aims to harmonize the protection across all countries of the European Union.
natural persons regarding the processing of personal data and the free movement
of data. In addition, it seeks to respond to the reality of personal data within the
current information society.
The new requirements of the Regulation pose significant challenges for everyone
entities due to the high volume of personal data they manage, turning
the protection of personal data is a critical aspect that all organizations must
keep in mind. The Regulation is a rule directly applicable to the legal system
Spanish, not requiring specific internal norms either for development or for their application.
The Regulation contains concepts, principles, and mechanisms similar to those established by the
Directive 95/46. Therefore, organizations that currently comply with the LOPD have
good starting point to evolve towards a correct application of the new regulation.
3
In general, the new considerations that must be taken into account are the
next:
Two general elements constitute the greatest innovation of the Regulation for the
responsible and project onto all the obligations of the organizations:
Organizations are required to analyze what data they process, for what purposes.
they do and what type of treatment operations they carry out.
Enhanced consent: consent must be 'unequivocal', being that
that has been provided through a manifestation of the interested party or through a clear
affirmative action. No forms of consent are accepted in any way.
tacit or by omission, since they are based on inaction. Situations are contemplated in
those for which consent, in addition to being unequivocal, must be explicit:
Treatment of sensitive data.
Adoption of automated decisions.
International transfers.
The information to the interested parties, both regarding the conditions of the treatments that they
they affect like in the answers to the rights exercises, it must be provided in the form
concise, transparent, intelligible and easily accessible, with clear and simple language.
they have been transmitted to the interested party themselves in advance, as long as this is
Responsible individuals or those in charge whose main activities include the handling of
large scale of sensitive data.
records constitute security violations under the GDPR and must be addressed
appropriately. Some obligations on the part of organizations are as follows:
When a data security breach occurs, the responsible party must notify
to the competent data protection authority, unless it is unlikely that the
violation poses a risk to the rights and freedoms of those affected.
The bankruptcy notification to the authorities must occur without undue delay and be
possible, within 72 hours following the responsible party's awareness of it.
The GDPR adds to the contents of the notification the recommendations on the measures.
What can those interested take to cope with the consequences of bankruptcy?
Questions
The organization you work for is a large engineering company that is composed of
by various departments such as:
1. Human resources.
2. Financial.
3. Wind engineering.
4. Hydraulic engineering.
Geothermal engineering.
6. Civil engineering
7. Legal and processing.
8. Systems.
9. Project Management Office (PMO).
As a member of the Systems Department of the organization, you are appointed Director of the
Project to adapt or modify existing systems and tools or create systems or
necessary tools to implement all the previously mentioned measures,
included in the GDPR, which must be implemented before the date set by
the Regulation (+4 months from today), under the possibility of incurring high penalties
for their non-compliance. Systems or tools can affect any department
within the organization.
At the same time, you are offered the possibility of hiring an external expert if you consider it.
necessary due to the absence or unavailability of a specific profile within the organization.
A budget of €200,000 is assigned as a maximum. Considering the importance of
The project sponsor will be the director of the project management office (PMO).
The following assumptions will need to be taken into account to properly develop the
subsequent analysis:
6
. Your organization fully complies with the existing regulations regarding the
Data protection (LOPD 15/1999).
. As of today, your organization has not yet begun to adapt its systems and
tools to the considerations of the new Data Protection Regulation
(GDPR), so you must start from scratch.
. Your organization has processes, procedures, and policies that must be
respected and like, for example, the following:
Policy for risk control and management.
Compliance Policy.
Cybersecurity Policy.
. Any other data or information not included in this document will be assumed for the
Project Director.
MATRIX OF INTEREST/INFLUENCE
8
Conclusions
owner of the project in this case to the European Union and is established as the project director to
systems manager as the person responsible within the company.
The level of influence is established on a scale from 1 to 6, with one being the level of
lowest influence and 6 the highest which in this case would be occupied by the European Union and
The project manager of the company.
The level of interest is established on a scale from 1 to 6, with one being the level of
lowest interest and 6 the highest. Understanding interest as the level of impact that
You can have the project about your management and from there derive your level of interest.
There is also a classification that is defined in collaborating and communicating, as it does not
Everyone communicates, but everyone is a collaborator; for this reason, they are part of the project.
Bibliographic references
Summa University. (n.d.). Stakeholders Management. Link where it was obtained from.
document
The provided link does not contain any translatable text.
[Link]/resources/
library/pdf/
9
quality assurance/
unit3_pdf1.pd
The provided text is not translatable as it appears to be a URL.
[Link]/resources/
library/pdf/
quality_assurance/
unit3_pdf1.pd
Invalid input: URL provided instead of text for translation.
[Link]/resources/
library/pdf/
quality_assurance/
unit3_pdf1.pd
Summa University. (n.d.). Stakeholder management. Continuous Improvement. Link to where it
obtained the document:
htInvalid URLtto [Link]/resources/libraryteca_summa/pdf/project_managementt_ii/
unit1_pdf1.pdf
Summa University. (n.d.). Cost Management. Link to where the document was obtained:
htps://[Link]/resources/biblioteca_summa/pdf/project_managementt
unit1_pdf1.pdf
10
Summa University. (n.d.). Management of communications. Link from where it was obtained
document:
htInvalid input, please provide a valid text for [Link]/resources/libraryteca_summa/pdf/project_management_ii/
unit1_pdf1.pdf
Implementing GDPR compliance poses several challenges, including coordinating across departments such as HR, finance, and engineering, as data might intersect various operational areas. Aligning organizational policies with GDPR requirements requires collaborative efforts, training, and potentially hiring external experts. Ensuring budget constraints and resource availability, while adapting existing systems to GDPR standards, adds complexity to compliance efforts .
GDPR mandates that information provided to stakeholders must be concise, transparent, and easily understandable. This requirement ensures that stakeholders are well-informed about data processing operations affecting them, reinforcing trust and accountability. Clear information dissemination helps prevent misunderstandings and potential conflicts, thereby facilitating smoother compliance operations .
Organizations should use an Interest/Influence matrix to manage stakeholders in GDPR compliance projects. This matrix assesses the level of influence and interest of each stakeholder, which helps to determine their involvement in the project. The European Union typically holds high influence, guiding the level of interest based on how the project's outcome might impact their operations and compliance with GDPR .
GDPR defines 'data security breaches' as incidents causing destruction, loss, alteration, unauthorized disclosure, or access to personal data. Organizations must notify the competent data protection authority within 72 hours of awareness of the breach unless it is unlikely to pose risks to the affected individuals. The notification should include the breach's nature, data categories affected, measures taken, and mitigation plans. Organizations must document all breaches .
The 'Right to Be Forgotten' under GDPR requires organizations to delete personal data when it's no longer necessary or the data subject withdraws consent, enhancing individual data control. This right challenges organizations to implement robust data management and deletion systems, ensuring compliance without compromising data integrity or operational efficiency .
A Data Protection Officer (DPO) under GDPR is responsible for overseeing data protection strategies and ensuring compliance with GDPR protocols. It is mandatory to appoint a DPO in public authorities, organizations carrying out large-scale systematic monitoring, or processing sensitive data on a large scale .
Under GDPR, consent must be clear and affirmative for data processing, especially for sensitive data, automated decisions, and international transfers. Consent can sometimes be implicit, inferred through user actions like continued website browsing. However, explicit consent is needed for significant data processing actions. Information to stakeholders must be concise and clear, respecting the conditions that affect the exercises of data rights .
Organizations must implement encryption systems and two-factor authentication for data security, even when handling data considered basic level. These measures are part of GDPR's requirements to protect personal data during its collection, storage, and processing .
The GDPR introduces the right to data portability, which allows personal data to be transmitted directly from one data controller to another without requiring transmission to the data subject first, as long as it's technically feasible. This right is an advanced form of the right of access, where the data provided to the data subject must be in a structured, commonly used, and machine-readable format .
GDPR requires organizations to provide remote access to personal data as part of the right of access, where feasible. This allows data subjects direct access to their personal data in a secure manner. The rationale is to enhance data subjects' control and transparency over personal data usage, aligning with GDPR's emphasis on individual rights .