Cybersecurity 2026

SPAIN Trends and Developments Contributed by: Rodrigo González, Vicente Moret, María Teresa Martínez and Cristina Durante, Deloitte Legal

The implications extend beyond regulatory compli - ance. In the event of a significant cyber incident, the quality of board-level governance – the existence and content of documented risk assessments, the records of board decisions and oversight activities, and the adequacy of investment in cybersecurity controls – will be scrutinised not only by supervisory authori - ties but potentially by shareholders, counterparties, and courts. Directors and senior managers who can - not demonstrate that they exercised their oversight responsibilities diligently face the risk of personal administrative sanctions, and, in the most serious cases, exposure to civil liability claims. Spanish organisations are advised to review their cor - porate governance structures with specific reference to these obligations. Audit and risk committees should incorporate cybersecurity as a standing agenda item. Board members should receive structured briefings – documented to create an evidentiary record – on the organisation’s cyber risk profile, the controls in place, and the results of any required resilience test - ing. The Chief Information Security Officer (CISO), or equivalent function, should have a clear reporting line to the board or a designated board committee, not merely to the Chief Technology Officer or Chief Oper - ating Officer. The Digital Omnibus: simplification on the horizon On 19 November 2025, the European Commission proposed the Digital Omnibus package, a legislative initiative designed to reduce the regulatory burden of the EU’s digital rulebook on businesses while preserv - ing the substance of existing rights and obligations. For cybersecurity, the most significant element is a proposal to create a unified incident reporting entry point covering NIS 2, DORA, GDPR, eIDAS, and the CER Directive – a “report once, share many” system that would eliminate the need for organisations to file separate notifications to different authorities under dif - ferent timelines and formats. The Omnibus also introduces targeted amendments to NIS 2, including simplifications to jurisdictional rules for cross-border entities and a reinforced co-ordina - tion role for ENISA. On data protection, it proposes adjustments to the GDPR and, significantly, proposes migrating the rules on terminal equipment access from

the ePrivacy Directive to the GDPR – a long-awaited reform that would harmonise the legal basis for cookie consent and device access across EU member states. For AI, the Omnibus proposes to defer the application of high-risk AI obligations by up to 16 months, linking compliance timelines to the availability of supporting harmonised standards. The Omnibus remains in the early stages of the ordi - nary legislative procedure. It must pass through the European Parliament and the Council, where it is likely to face significant scrutiny and amendment, particu - larly on GDPR provisions where the European Data Protection Board and the European Data Protection Supervisor have expressed concerns. Spanish organi - sations should monitor its progress, but they should not treat the prospect of simplification as a reason to pause their compliance programmes. The core obliga - tions of NIS 2, DORA, and the CRA are not subject to negotiation within the Omnibus; what may change is the administrative architecture around reporting and supervisory co-ordination. Convergence with artificial intelligence regulation The intersection of cybersecurity and artificial intelli - gence regulation is emerging as one of the most tech - nically demanding areas of practice in Spanish digital law. The EU AI Act, which entered into force in August 2024 and is progressively rolling out its obligations, directly interacts with the cybersecurity framework in several respects. High-risk AI systems – covering areas such as critical infrastructure management, employment decisions, and law enforcement tools – must meet cybersecurity robustness requirements as part of their conformity assessment. AI systems embedded in products with digital elements are also subject to CRA obligations. For operators of AI systems used in sectors cov - ered by NIS 2 – energy, health, transport, and digital infrastructure – there is a dual compliance obligation: meeting the AI Act’s requirements for the AI system itself while ensuring that the broader ICT environment in which it operates meets NIS 2 risk management standards. The interaction is particularly complex where AI systems are used for cybersecurity purposes – such as anomaly detection, threat intelligence, or automated incident response – since these systems

349 CHAMBERS.COM

Powered by