The digital regulatory framework in Spain and the EU: which laws apply to your business

The digital regulatory framework is the set of European and national rules governing data, artificial intelligence, cybersecurity and digital services for businesses operating in technology-driven environments. In less than a decade the European Union has built the most extensive body of digital law in the world. According to a January 2026 report by the Spanish think tank Fedea, Spanish SMEs and the self-employed have to comply with more than a hundred digital laws, organised in five overlapping layers and enforced by different authorities. For a technology company, the problem is no longer complying with one specific law. It is knowing which ones apply at the same time, when they take effect and who supervises them.

This article puts that map in order: which laws make up the framework, who they affect, on what dates and how to tackle them as a whole rather than law by law.

If you need digital law advice, request a free initial assessment with us.

Table of contents

What is the digital regulatory framework?

The digital regulatory framework brings together the rules governing businesses’ use of technology: processing of personal and non-personal data, artificial intelligence systems, cybersecurity, online markets and platforms, and digital identity. Most of them are directly applicable EU regulations, which means they bind companies in Spain without any national law transposing them. Directives, by contrast, do require transposition. That difference explains why some laws are already enforceable and others depend on the Spanish legislative calendar.

The five layers of the framework

The digital regulatory framework is organised in five thematic layers. The first is the data layer: the GDPR for personal data and the Data Act for data generated by connected products. The second is artificial intelligence, governed by the AI Act. The third is cybersecurity, with the NIS2 Directive and, in the financial sector, the DORA Regulation. The fourth covers digital markets and platforms through the DSA and the DMA. The fifth governs digital identity and trust services through eIDAS2. The same company may be subject to several layers at once.

Who supervises each layer in Spain

Each layer has its own supervisory authority, and that fragmentation is one of the framework’s difficulties. The Spanish Data Protection Agency (AEPD) supervises the GDPR. For the AI Act, Spain created the Spanish Agency for the Supervision of Artificial Intelligence (AESIA) by Royal Decree 729/2023, with its seat in A Coruña; its formal designation as market surveillance authority and the national penalty regime depend on an organic law that does not yet exist, because the draft lapsed when the Spanish Parliament was dissolved in October 2026. INCIBE and the National Cryptologic Centre (CCN) handle cybersecurity. The National Markets and Competition Commission (CNMC) acts as Digital Services Coordinator for the DSA. The Bank of Spain and the CNMV supervise DORA and MiCA in the financial sphere. A single incident can trigger reporting obligations to several of these authorities at once.

The key laws of the digital regulatory framework, one by one

The framework is made up of several regulations and directives with different scopes and dates. Each law is described below with its definition, who it applies to and when it is enforceable. At the end of the section you will find a master table summarising the deadlines and penalties for all of them.

GDPR: the foundation of data protection

The General Data Protection Regulation (Regulation (EU) 2016/679) governs the processing of personal data and has applied in Spain since 25 May 2018. It affects any company that processes data about individuals, whatever its sector. It is the oldest and best-known layer of the framework, and it remains the reference on which later laws build. Its fines reach €20 million or 4% of annual worldwide turnover.

AI Act: the artificial intelligence regulation

The AI Act (Regulation (EU) 2024/1689) is the world’s first law to regulate artificial intelligence systems by level of risk. It entered into force on 1 August 2024 and applies in stages. Prohibited practices have been enforceable since 2 February 2025 and the obligations for general-purpose AI models since 2 August 2025. Most obligations for high-risk systems were due to apply from 2 August 2026, but the AI Omnibus, Regulation (EU) 2026/1744, postponed them to 2 December 2027 for Annex III systems and 2 August 2028 for those in Annex I. It affects AI providers and deployers, with extraterritorial reach similar to the GDPR’s. Fines reach €35 million or 7% of worldwide turnover. Given its complexity, we cover it in detail in our AI Act compliance guide.

NIS2: cybersecurity of essential services

The NIS2 Directive (Directive (EU) 2022/2555) strengthens the cybersecurity of essential and important entities and has been binding at EU level since January 2023. It applies across eighteen sectors where the company has fifty or more employees or a turnover above ten million euros, with specific exceptions for highly critical sectors. As a directive, it needs a national law to transpose it. Spain missed the transposition deadline of 17 October 2024, and the European Commission sent it a reasoned opinion on 7 May 2025. The preliminary draft of the Cybersecurity Coordination and Governance Act, approved by the Council of Ministers in January 2025, has not become law. In July 2026 the Commission referred Spain to the Court of Justice of the European Union, and with the Spanish Parliament dissolved since 6 October 2026, no law can go through until the new chambers are constituted. The planned fines are up to €10 million or 2% of turnover for essential entities, and €7 million or 1.4% for important entities. You can read more in our cybersecurity and NIS2 practice area and in our guide to the NIS2 Directive in Spain.

CRA: cybersecurity of products with digital elements

The Cyber Resilience Act (Regulation (EU) 2024/2847) imposes cybersecurity requirements on products, not on organisations. It covers manufacturers, importers and distributors of hardware and software with a data connection, from a router to a business management app. It entered into force on 10 December 2024. The obligations to report exploited vulnerabilities have been enforceable since 11 September 2026, and the rest of the regulation, with essential requirements and CE marking, applies from 11 December 2027. Fines reach €15 million or 2.5% of worldwide turnover. An importer or distributor that sells someone else’s product under its own brand is liable as a manufacturer. The full analysis is in our guide to what the Cyber Resilience Act is and which companies it covers.

DORA: digital operational resilience in the financial sector

The DORA Regulation (Regulation (EU) 2022/2554) sets digital operational resilience requirements for the financial sector and has applied since 17 January 2025. It requires banks, insurers, payment institutions, crypto-asset service providers and the rest of the 21 categories of entities listed in its Article 2 to manage technology risk, report major incidents and oversee their critical ICT providers. The management body is directly responsible for the risk management framework. DORA does not replace other financial rules: it integrates them and prevails over them in the areas it governs.

MiCA: the crypto-asset market

The MiCA Regulation (Regulation (EU) 2023/1114) creates the first common European framework for the issuance of crypto-assets and crypto-asset services. It applies gradually: the rules for stablecoins have applied since June 2024, and the general regime for crypto-asset service providers since 30 December 2024. In Spain, the transitional period for providers already active ended on 30 June 2026, as we explain in our article on MiCA authorisation in Spain. It affects issuers, trading platforms and custodians, which must be authorised and meet governance and client protection obligations. MiCA does not cover crypto-assets that qualify as financial instruments, which fall under MiFID II. Compliance with this regime is the focus of our crypto-assets and MiCA practice.

DSA and DMA: digital services and markets

The Digital Services Act (DSA, Regulation (EU) 2022/2065) and the Digital Markets Act (DMA, Regulation (EU) 2022/1925) regulate online platforms. The DSA sets obligations on transparency, content moderation and user protection, and has applied in full since 17 February 2024 to all services concerned. Its fines reach 6% of worldwide turnover. The DMA imposes obligations on large platforms designated as gatekeepers and provides for fines of up to 10% of worldwide turnover, rising to 20% for repeat infringements. The DSA updates the old 2000 E-Commerce Directive. It should not be mistaken for a law only for the giants, because it reaches any intermediary. We cover it in our guide to the Digital Services Act.

Data Act: fair access to and use of data

The Data Act (Regulation (EU) 2023/2854) governs access to data generated by connected products and related services, and has applied generally since 12 September 2025. It gives users, whether businesses or individuals, the right to access the data they generate with their device and to share it with third parties. It affects manufacturers of connected products, cloud service providers and users of IoT products. It includes rules on portability and switching cloud providers. The access-by-design requirements for new connected products have applied since 12 September 2026.

eIDAS2: European digital identity

The eIDAS2 Regulation (Regulation (EU) 2024/1183) updates the European framework for digital identity and trust services, and was adopted in 2024. Its main innovation is the European Digital Identity Wallet (EUDI Wallet), which Member States must make available to citizens and businesses to identify themselves and sign documents throughout the EU. It also governs electronic signatures, time stamps and qualified certificates, tools commonly used in digital contracting between businesses.

Master table of the digital regulatory framework

LawWhat it governsWho it applies toApplicationMaximum penalty
GDPR (EU 2016/679)Personal dataAny company processing personal dataSince 25 May 2018€20m or 4% of worldwide turnover
AI Act (EU 2024/1689)Artificial intelligence systemsAI providers and deployersIn stages: Feb 2025, Aug 2025; high-risk Dec 2027 and Aug 2028€35m or 7% of worldwide turnover
NIS2 (EU 2022/2555)Cybersecurity of essential and important services18 sectors, ≥50 employees or >€10mEU since 2023; transposition in Spain pendingEssential €10m/2%; important €7m/1.4%
CRA (EU 2024/2847)Cybersecurity of products with digital elementsManufacturers, importers and distributors of hardware and softwareReporting since Sep 2026; full application Dec 2027€15m or 2.5% of worldwide turnover
DORA (EU 2022/2554)Digital operational resilienceFinancial sector (21 categories)Since 17 Jan 2025Measures and fines set by the competent authority
MiCA (EU 2023/1114)Crypto-assetsIssuers and crypto-asset service providersStablecoins Jun 2024; general regime 30 Dec 2024Set by the national authority
DSA (EU 2022/2065)Digital services and platformsOnline intermediaries and platformsIn full since 17 Feb 2024Up to 6% of worldwide turnover
DMA (EU 2022/1925)Digital marketsLarge platforms designated as gatekeepersObligations since 2023-2024Up to 10% (20% for repeat infringements)
Data Act (EU 2023/2854)Access to and use of data from connected productsManufacturers, cloud providers and IoT usersSince 12 Sep 2025Set by the national authority
eIDAS2 (EU 2024/1183)Digital identity and trust servicesStates, businesses and citizensAdopted in 2024; EUDI Wallet rollout under waySet by the national authority

How do I know which digital laws apply to my business?

To find out which digital laws apply to a company, three variables have to be crossed: what data it processes, what activity it carries out, and its size and sector. No law applies to every company in the same way, and almost no company is subject to just one. The method is to map these three variables before designing any compliance measure.

By the type of data you process

If your company processes personal data, the GDPR always applies, whatever your size. If your connected products or cloud services generate usage data, the Data Act comes into play from September 2025. A healthtech company processing clinical data also takes on the GDPR’s special categories and, if it uses AI for diagnosis, the AI Act’s high-risk obligations.

By your activity

Your activity determines the additional layers. An online platform or marketplace falls under the DSA. A fintech, payment institution or crypto-asset service provider adds DORA and, where relevant, MiCA. A company that develops or integrates artificial intelligence systems comes under the AI Act. A provider of essential services in energy, health, transport or digital infrastructure will be subject to NIS2 once Spain completes its transposition.

By your size and sector

Size switches obligations on or off. As a general rule, NIS2 requires fifty or more employees or a turnover above ten million euros, with exceptions for highly critical sectors. The Data Act exempts micro and small enterprises from some obligations, unless they belong to a group that exceeds the thresholds. DORA applies a proportionality principle according to size and risk profile. Knowing the thresholds avoids both non-compliance and over-compliance with laws that do not apply.

The digital omnibus: the EU wants to simplify the framework

The digital omnibus is a legislative package that the European Commission presented on 19 November 2025 to simplify and reorganise the digital regulatory framework. Its aim is to reduce administrative burdens, harmonise scattered obligations and improve consistency between laws such as the GDPR, the AI Act, NIS2, DORA and eIDAS2. One of its measures is to create a single entry point for incident reporting, so that the same security breach does not have to be reported separately under each law.

The package ended up being split in two. The artificial intelligence part is already law, Regulation (EU) 2026/1744, in force since 27 July 2026, which postponed the high-risk obligations to December 2027 and August 2028. The data part, which would rewrite the GDPR, the Data Act and NIS2, is still under negotiation in the Council without a common position. We analyse what would change and where it stands in our guide to the Digital Omnibus on data.

How to comply with the digital regulatory framework as a whole

Complying with the digital regulatory framework as a whole means managing all applicable laws as a single system, not as isolated obligations. The process has four phases: an assessment that identifies which laws apply to the company, a gap analysis for each one, a roadmap that prioritises the actions, and continuous monitoring that updates the programme as the rules change. This approach avoids duplicated effort, because many obligations (records, policies, notifications) are shared across several laws.

The most common mistake in a technology company is not breaching one specific law. It is not having a map of which laws apply to it at the same time, and finding out too late. An example shows the pattern. A healthtech scale-up with an AI-based product reaches a funding round, and due diligence reveals that it is suddenly subject to four overlapping frameworks. The GDPR for clinical data, the AI Act for the diagnostic system, the Data Act for the connected device’s data and, given its size, the future NIS2 obligations. Each with its own authority and timetable. Sorting it out against the clock during the round takes weeks. Doing it with a map drawn up beforehand takes days. That is why we offer comprehensive technology law advice that covers every layer in a single compliance programme.

Which digital laws are mandatory for an SME in Spain?

For almost any Spanish SME, the GDPR is mandatory from the first employee, because the company processes personal data of customers and staff. Beyond that, it depends on the activity: an online shop adds the DSA and e-commerce rules; a company with connected products, the Data Act; and one that uses artificial intelligence, the AI Act. NIS2 only applies if the SME operates in an essential or important sector and exceeds the size thresholds.

There is no single authority. The AEPD supervises data protection; AESIA is the agency created for artificial intelligence, pending the law that formally designates it; INCIBE and the CCN handle cybersecurity; the CNMC oversees digital services under the DSA; and the Bank of Spain and the CNMV supervise financial rules such as DORA and MiCA. This multiplicity of supervisors is one of the reasons compliance is best managed in a coordinated way.

The consequences vary by law, but the penalties are high. The GDPR provides for fines of up to €20 million or 4% of worldwide turnover, and the AI Act reaches €35 million or 7%. Beyond fines, authorities can order activities to be suspended, require audits or, in the case of NIS2, hold managers personally liable. Reputational damage and stalled investment processes often weigh as much as the financial penalty.

The digital regulatory framework requires knowledge of several European regulations at once, an understanding of the technology they govern and the ability to anticipate how they fit together. A general adviser can cover specific points, but the value of a lawyer focused on digital law lies in the full map: knowing which laws apply, in what order to tackle them and how to avoid duplicated work. The more technology-driven the activity, the more layers overlap and the more that overall view matters.

If you are not sure which of these laws apply to your business, or in what order to tackle them, the first step is the map. At Innovatech we identify the laws that apply to you, the gaps in each one and a prioritised roadmap. Tell us about your case and we will give you a free initial assessment.

Managing Partner at Innovatech Legal | Website | + posts

Marta Suárez-Mansilla is Managing Partner of Innovatech Legal and a Spanish lawyer (abogada), Madrid Bar (ICAM), working in technology law. She completed Harvard Law School's Copyright course and BerkeleyX's Blockchain programme, and has advised technology companies for more than eight years.