SPAIN Law and Practice Contributed by: Vicente Moret, Rodrigo González, María Teresa Martínez and Cristina Durante, Deloitte Legal
Maximum penalties can reach EUR10 million or 2% of worldwide turnover for legal persons, and EUR5 million for natural persons, with public disclosure add - ing an additional reputational impact. Given DORA’s relatively recent applicability, formal Spain‑specific enforcement precedents were limited at the time of writing. 3.5 International Data Transfers DORA does not impose data localisation require - ments. Instead, it obliges financial entities to specify in their ICT contracts where data will be processed and stored. This approach provides transparency and enables supervisors to assess risks, without restrict - ing the geographical location of data. Where outsourcing involves personal data, GDPR international transfer rules apply in parallel. Lawful transfer mechanisms – such as adequacy decisions, Standard Contractual Clauses (SCCs), and Binding Corporate Rules (BCRs) – establish a legal basis for transfers but do not remove the need to evaluate practical risks, including the possibility of access by third‑country authorities under local laws. As a result, the EDPB’s transfer impact assessment methodol - ogy becomes operationally relevant within DORA’s outsourcing governance framework. A key upcoming development is the EUCS high‑assur - ance level under the Cybersecurity Act (CSA). This certification scheme is designed to assess cloud services against criteria that include protection from third‑country legal access to EU data, offering a standardised mechanism for managing sovereignty risk in cloud outsourcing. Spanish supervisory authorities, including the Banco de España , have also signalled that documented third‑country risk assessments should be treated as substantive elements of compliance rather than mere formalities. 3.6 Threat-Led Penetration Testing Threat-led penetration testing under DORA is designed to assess whether an institution can with - stand sophisticated, realistic adversaries targeting its critical functions, rather than simply verify whether known vulnerabilities have been remediated. In Spain,
the framework follows the ECB’s TIBER-EU method - ology, implemented domestically as TIBER-ES under the joint administration of the Banco de España and the CNMV. TIBER-ES comprises a sector-level Generic Threat Intelligence report, an institution-specific Targeted Threat Intelligence report, and a red-team exercise against live production systems conducted by an approved External Test Provider, guided by the gath - ered intelligence. Targeting production environments is operation - ally significant: it evaluates an institution’s detection and response capabilities under real conditions. This requires strict governance, robust risk controls, and well‑defined crisis communication protocols to ensure that the exercise remains safe while still delivering credible, high‑fidelity testing conditions. Spain’s cyber‑resilience framework is evolving along two intersecting lines: a rights‑based domestic tradi - tion, rooted in constitutional and fundamental rights instruments, and the EU’s emerging product‑security agenda, which is reshaping market access by impos - ing security‑by‑design duties on manufacturers. The interaction between these approaches is not merely conceptual. It redistributes responsibility – historically placed on operators through duties of care – upstream to manufacturers through life cycle obligations embed - ded in product regulation. Spain’s Charter of Digital Rights (2021), although non‑binding, is normatively significant in this land - scape. It frames cybersecurity as a digital right: a citi - zen’s reasonable expectation that digital systems and services can be used with adequate security guaran - tees. From this perspective, cyber resilience becomes a precondition for exercising rights in the digital envi - ronment. Insecure digital products are therefore not simply defective market offerings; they undermine both public trust and rights‑based expectations of safety in digital life. 4. Cyber-Resilience 4.1 Cyber-Resilience Legislation
337 CHAMBERS.COM
Powered by FlippingBook