SPAIN Law and Practice Contributed by: Vicente Moret, Rodrigo González, María Teresa Martínez and Cristina Durante, Deloitte Legal
Deloitte Legal (Deloitte Abogados y Asesores Tributarios, S.L.U.) Plaza Pablo Ruiz Picasso 1 28020 Madrid Spain Tel: +34 915 145 000 Email: rgonzalezruiz@deloitte.es Web: www2.deloitte.com/es
1. General Overview of Laws and Regulators 1.1 Cybersecurity Regulation Strategy Spain’s cybersecurity strategy operates on two com - plementary levels: the EU framework, which provides the overarching regulatory direction, and national stra - tegic instruments, which implement that framework domestically. At the EU level, the Cybersecurity Strat - egy of December 2020 positions cyber resilience as a foundation for digital sovereignty, the functioning of the internal market, and the protection of fundamental rights. This strategic orientation has since been trans - lated into a comprehensive legislative programme that includes NIS2, DORA, the Cyber Resilience Act (CRA), the EU Cybersecurity Act (CSA), the Critical Entities Resilience Directive (CER), the Cyber Solidarity Act and the AI Act. At the national level, Spain’s primary instruments are the Estrategia Nacional de Ciberseguridad (2019, cur - rently under revision) and the Plan Nacional de Ciber- seguridad . These documents structure public action around five core objectives: • strengthening the security and resilience of net - works and systems; • developing national cybersecurity capabilities; • reinforcing cybersecurity within the public sector; • enhancing international co-operation; and • promoting a cybersecurity culture. Legislatively, Spain emphasises harmonised cross- sector baseline requirements, the protection of critical
infrastructure, and co-ordinated incident response, while preserving sector-specific regimes for areas such as financial services, energy and healthcare. Overall, the legislature presents EU and national instru - ments as mutually reinforcing layers within a unified cyber-risk governance architecture. This model places particular emphasis on proportionality of obligations, legal certainty for operators, and effective enforce - ment delivered through a co-ordinated network of competent authorities. 1.2 Cybersecurity Laws Spain’s Cybersecurity Framework: A Stacked Regulatory Architecture Spain’s cybersecurity regime is largely shaped by EU legislation and is best understood as a layered regu - latory stack rather than a collection of discrete rules. Directly applicable EU regulations – most notably DORA and the Cyber Resilience Act – coexist with directives that require national transposition, such as NIS2 and CER. These sit atop a domestic layer still influenced by earlier implementation choices and national standards, most prominently the Esquema Nacional de Seguridad (ENS) and the national frame - work developed under NIS1. For organisations operating in Spain – especially those with EU wide operations – the complexity stems from the fact that compliance obligations increasingly depend on where the requirement sits in the stack (entity, sector, or product level), and on the reality that transposition timelines and national implementation choices differ across member states.
327 CHAMBERS.COM
Powered by FlippingBook