SPAIN Law and Practice Contributed by: Vicente Moret, Rodrigo González, María Teresa Martínez and Cristina Durante, Deloitte Legal
Deloitte Legal has a digital law department that inte - grates a first-class legal team, experienced in sophis - ticated privacy matters, with strategy, process, tech - nology, and risk consultants. This synergy provides a broad, practical perspective to address clients’ challenges in an increasingly complex regulatory and business landscape, supporting both informed deci - sion-making and seamless multidisciplinary imple - mentation. Focused on digital transformation across diverse sectors and maturity levels, the firm’s cross-
market view enables it to anticipate emerging needs and adapt proven solutions to new contexts. A core differentiator is its profound specialisation in digital regulation and comprehensive cybersecurity adviso - ry. The firm expertly navigates the complex interplay of critical frameworks – including NIS 2, CER, CSA, CRA, and DORA. By bridging business, technology, and legal disciplines, it fosters a common language to deliver forward-looking, resilient, and highly practi - cal solutions.
Authors
Vicente Moret is a counsel at Deloitte Legal, with extensive experience advising both public and private sector clients in digital law, particularly cybersecurity regulation. He joined the firm in 2023, combining
María Teresa Martínez joined Deloitte Legal in 2017 in the digital law department. Teresa as nine years of experience in data protection and technology law. She provides complete legal advice and legal audits
legal expertise with Deloitte’s cybersecurity consulting and managed services capabilities. In February 2025, he fully transitioned to private practice at Deloitte Legal. Over the past five years, he has advised major Spanish and international companies on DORA, the NIS 2 Directive, the Cyber Resilience Act, the Cyber Security Act, and the AI Act. He also co-ordinated the regulatory working group of Spain’s National Cybersecurity Forum between 2020 and 2024.
on cybersecurity matters. In particular, she is specialised in the following tasks: applicability analysis of the different regulations, gap analysis and legal risks and impact evaluation regarding different cybersecurity regulations such as NIS 2, the CRA Act, and CER. She also provides advice on data protection matters from a legal perspective, computer and advertising contracting, and legal regime applicable to electronic commercial campaigns: spam and direct marketing; e-mail, SMS, MMS, etc; and express consent (opt-in) and tacit consent (opt-out).
Rodrigo González joined Deloitte Legal in 2018 and leads the IP&IT and Data Law practice in Spain, with over 20 years of experience in Digital Law.
Cristina Durante joined Deloitte Legal in 2023. She combines her role as senior associate with the position of Deputy Secretary of the Board of the ESYS Foundation (Business, Security, and Digital Society). Cristina provides
He holds the prestigious CIPP/E certification from the IAPP and the Data Protection Officer certificate issued by the Spanish Data Protection Authority. He has co-ordinated GDPR implementation projects, whistle-blowing systems, and legal website reviews, as well as drafting and negotiating software licensing agreements. Rodrigo advises on big data, cloud computing, social networks, cookies, IoT, outsourcing, and hosting agreements. He also leads the firm’s innovation strategy, driving digital and regulatory transformation initiatives.
complete legal advice and legal audits on digital security matters (adaptation of companies to the new European and national regulatory framework – DORA Regulation, NIS 2 Directive, DREC, ENS, etc), preparation of legal risk maps, development of ICT policies and procedures, development of governance strategies, adaptation and advisory services for national and international companies regarding personal data protection, and other issues.
326 CHAMBERS.COM
Powered by FlippingBook