SPAIN Law and Practice Contributed by: Vicente Moret, Rodrigo González, María Teresa Martínez and Cristina Durante, Deloitte Legal
Certification and Procurement as Regulatory Drivers Procurement is often the decisive factor. Spanish pro - curement rules allow public bodies to require certi - fication as part of technical specifications or award criteria. Sectoral regulators likewise increasingly view certification as credible evidence of compliance. As a result, certification operates less as a voluntary assur - ance badge and more as a commercial prerequisite for participating in public sector or regulated markets. Practical Takeaway Organisations should adopt a strategic approach to certification. The key question is not whether a certi - fication is formally mandatory, but where it functions as a gatekeeper – for public sector access, regulated outsourcing, or cross border service deployment. Aligning procurement strategy, compliance planning, and assurance activities around the relevant certifica - tion pathways helps reduce duplication, friction, and regulatory risk. 6. Cybersecurity in Other Regulations 6.1 Cybersecurity and Data Protection The relationship between cybersecurity and data pro - tection in Spain is best understood as one of struc - tural interdependence rather than simple regulatory overlap. The GDPR is not a cybersecurity framework, and NIS2 is not a data protection regime. In practice, however, the most serious cyber incidents affect - ing Spanish organisations activate both frameworks simultaneously, and many compliance failures arise because organisations lack an integrated response model. Under the GDPR, security is framed as a risk‑manage - ment obligation that focuses on protecting individu - als’ rights and freedoms. Article 32 intentionally avoids mandating particular technologies, instead requiring measures proportionate to the risks presented by the processing. Spanish supervisory practice con - sistently treats security as a contextual assessment, where technical controls are relevant only insofar as they reflect a defensible risk analysis. What the GDPR adds – beyond traditional cybersecurity frameworks – is accountability: controllers must be able to dem -
onstrate why their chosen measures are appropriate, and shortcomings in documentation are treated as standalone infringements. Incident notification is where this interaction becomes operationally critical. The GDPR’s 72‑hour breach‑noti - fication period runs from the moment of awareness, not from the point of forensic certainty, and regula - tors expect transparency even when information is incomplete. For organisations that also qualify as essential or important entities under NIS2, a serious cyber incident may trigger parallel notification duties: an early warning under NIS2 within 24 hours, and a breach notification to the AEPD within 72 hours. These regimes differ in triggers, timelines, and required con - tent – and authorities do compare notifications. The Cyber Resilience Act adds another layer by imposing security‑by‑design obligations on products with digital elements. From a data‑protection perspec - tive, the CRA operates as a baseline for product‑level security: controllers that rely on products lacking secure defaults, vulnerability‑handling processes, or defined update life cycles are structurally unable to meet their Article 32 obligations, regardless of the organisational measures in place. Spain’s Organic Law 3/2018 reinforces this inte - grated approach through an expanded DPO regime. The independence and authority of the DPO during incidents are essential; when the role is nominal or under‑resourced, Spanish authorities have treated that failure as an infringement in its own right. 6.2 Cybersecurity and AI The AI Act is not a cybersecurity regulation in the traditional sense, but it embeds cybersecurity as a fundamental element of the EU’s concept of trustwor - thy AI. The Act addresses risks arising not only from system compromise, but also from manipulation of AI behaviour, data poisoning, and adversarial inputs – threats that may occur even when the underlying infrastructure remains technically secure. High‑risk AI systems must demonstrate appropri - ate levels of robustness and cybersecurity across their entire life cycle. This introduces obligations that extend beyond conventional information secu -
341 CHAMBERS.COM
Powered by FlippingBook