2021-05-27
The Spanish State enacted Organic Law 7/2021 to transpose EU Directive 2016/680, establishing a comprehensive legal framework for the processing of personal data by competent authorities for criminal prevention, investigation, and prosecution. The law defines specific competent authorities, such as police and judicial bodies, and mandates strict adherence to data protection principles, including purpose limitation, data minimization, and enhanced safeguards for special categories of data. It further regulates the exercise of data subject rights, imposes active responsibility and security obligations on data controllers, and sets rigorous conditions for international data transfers to ensure consistent protection standards across the European Union.