
TLDR: What is GDPR in simple terms? GDPR is EU law that treats personal data as "loaned" to businesses, not owned by them.
In Spain, businesses must comply with both GDPR and LOPDGDD—a stricter Spanish law that adds requirements like mandatory data blocking, lower age of consent (14), and compulsory DPO appointments for specific sectors.
Key principle: Organizations must prove they're protecting data properly, or they're holding it unlawfully.