DIGITAL LAWS FOR BUSINESSES
This page brings together the European and Spanish digital rules that reach a business in Spain today, with the real legal status of each one. Some are already enforceable, others have a date set in the calendar, and one is still only a proposal under negotiation in the Council. Each entry links to the full analysis and is updated when the status of the rule changes.
| Rule | Status | Who it reaches |
|---|---|---|
| Digital regulatory framework | Overview | Starting point for placing all the others |
| AI Act | Applying in stages | Anyone who develops, distributes or uses artificial intelligence systems |
| AI transparency, Article 50 | Enforceable since 2 August 2026 | Anyone running chatbots or generating synthetic content |
| Algorithmic information for workers | Enforceable since 5 October 2026 | Any company that uses algorithms to decide on working conditions in Spain |
| Digital Omnibus and the GDPR | Proposal under negotiation, no Council common position yet | No one yet, but it would rewrite the GDPR |
| NIS2 Directive | Binding, not transposed in Spain | Essential and important entities in 18 sectors |
| Cyber Resilience Act | Reporting in force since 11 September 2026. Full application on 11 December 2027 | Manufacturers, importers and distributors of products with digital elements, software included |
| E-commerce law | In force | Online shops and platforms selling in Spain |
| Digital Services Act | In force, no penalty regime in Spain | Any intermediary, from web hosting to a website with comments |
| Protecting minors online | A European proposal and a lapsed Spanish draft, neither enforceable | Platforms, video services and terminal equipment manufacturers |
| MiCA Regulation | Transitional period over | Crypto-asset service providers |
The status column is not a formality. It determines whether an obligation reaches you today or whether you can still wait, and confusing the three cases is the most expensive mistake in digital compliance.
A European regulation binds directly from the date set in its own provisions, with no need for Spanish legislation. That is the case with the AI Act, the Cyber Resilience Act and MiCA.
A directive needs national transposition. NIS2 is the live example, because Spain has not transposed it and the European Commission has already referred it to the Court of Justice. Even so, the directive has effects, and the contractual obligations derived from it are already flowing through supply chains.
A Commission proposal binds no one until it is published in the Official Journal. Its content can change several times, or it may never be adopted. The Digital Omnibus on data has been under negotiation since November 2025 and the Council still has no common position.
Regulation (EU) 2024/1689 has applied in stages since February 2025. The AI Act guide covers the risk levels, the split of roles between provider and deployer, and the full timeline after the AI Omnibus.
The Article 50 transparency obligations have been enforceable since 2 August 2026 and affect any company with a chatbot or that publishes AI-generated content, whatever its size.
Since 5 October 2026, Spain’s Royal Decree 723/2026 also requires employers to explain to each worker the algorithms that decide on their working hours, tasks, pay or dismissal. The guide to algorithmic information for workers details what to provide and when.
What to agree with the software vendor in order to provide that information is covered in our guide on algorithmic transparency clauses with your software vendor.
Five guides cover the parts of the regulation that raise the most questions. Prohibited AI practices and high-risk AI systems explain what is banned and where the obligations concentrate. General-purpose AI models and AI Act penalties cover model providers and fines. And the AI Act and the GDPR sets out how the two laws fit together.
The GDPR continues to apply in full and without qualification. The Digital Omnibus on data would rewrite it in depth, with a relative definition of personal data, a new legal basis for artificial intelligence and cookies moving out of the ePrivacy Directive. None of this is binding yet.
The NIS2 Directive imposes risk management measures and management body accountability on essential and important entities in 18 sectors.
The Cyber Resilience Act acts on the product rather than on the organisation. Since 11 September 2026 it has required actively exploited vulnerabilities to be reported within 24 hours. The detail of that regime is in our analysis of vulnerability reporting. If you need to adapt your products, we explain how we work in our Cyber Resilience Act advice. Three guides cover the parts of the regulation that raise the most questions: Cyber Resilience Act penalties, the classification of important and critical products and CE marking and conformity assessment.
The e-commerce rules bring the LSSI-CE, the GDPR, Spanish consumer law and the Digital Services Act together on a single online shop.
The Digital Services Act is the law that reaches the most companies without their knowing. It binds any intermediary, not only the big platforms, and in Spain there is still no authority with powers to impose penalties under it.
Within the Digital Services Act itself, Article 28 is the provision that reaches services used by minors, and it is currently the only enforceable obligation in this area. The European proposal of September 2026 is still to be negotiated, and the Spanish draft organic law lapsed with the dissolution of Parliament in October 2026. How they divide up is covered in protecting minors in digital environments.
In crypto-assets, the Spanish transitional period ended on 1 July 2026. Our article on MiCA authorisation explains what binds providers that did not obtain it.
Those who need the licence can prepare it with our MiCA lawyer service in Spain, and the other regulation that applies to them is explained in DORA for crypto-asset service providers.
These are the dates already set in the European regulatory calendar.
| Date | What happens |
|---|---|
| 2 December 2026 | The transitional period for the new AI Act prohibited practices and the grace period for marking synthetic content end |
| 2 December 2027 | Obligations for Annex III high-risk AI systems |
| 11 December 2027 | General application of the Cyber Resilience Act |
| 2 August 2028 | Obligations for Annex I high-risk AI systems |
It depends on what the company does and what data it handles, not on its size. The GDPR reaches any company that processes personal data. The AI Act reaches anyone who uses artificial intelligence systems, even a customer service chatbot. NIS2 and the Cyber Resilience Act have thresholds by sector and by type of product.
A regulation binds from the date of application set in its own provisions, with no need for Spanish legislation. A directive needs transposition, although it can have effects earlier. A Commission proposal binds no one until it is published in the Official Journal. The table on this page shows the status of each one.
The penalty regimes are independent and cumulative. The GDPR goes up to €20 million or 4% of annual worldwide turnover. The AI Act reaches €35 million or 7% for prohibited practices. The Cyber Resilience Act stops at €15 million or 2.5%. A single incident can trigger several at once.
Whenever the status of one of these rules changes. European digital regulation moves fast and an out-of-date entry is worse than none. If you spot something that no longer adds up, write to us and we will correct it.
If you are not sure which of these rules reach you, which ones arrive in the coming months and which ones you can simply keep an eye on, write to us and we will review it.
Not sure which rules apply to you? Ask us.