
What DORA requires from crypto-asset service providers
What DORA requires from crypto-asset service providers authorised under MiCA, from ICT risk management to reporting major incidents in Spain.

What DORA requires from crypto-asset service providers authorised under MiCA, from ICT risk management to reporting major incidents in Spain.

Which clauses to ask your software vendor for, so you can explain to staff the algorithms that decide their working conditions in Spain since 5 October.

Since 1 July 2026 only authorised crypto-asset service providers may operate in Spain. Who needs CNMV authorisation and what firms without it must do.

Online selling in Spain is governed by the LSSI, the GDPR, consumer law, the DSA, the Omnibus Directive and the GPSR. What each one requires of your shop.

The Digital Omnibus on data would amend the GDPR, the Data Act and NIS2, but the Council has no common position yet. What would change and what to do now.

What binds platforms and manufacturers today on protecting minors online, and what may come with the EU KIDS Act and a future Spanish organic law.

The DSA binds every online intermediary, not just the big platforms. What applies at each tier and why, in Spain, no authority can impose fines yet.

GDPR, AI Act, NIS2, CRA, DORA, MiCA, DSA, Data Act and eIDAS2: which EU and Spanish digital laws apply to your business, from when and who enforces them.

The CRA covers manufacturers, importers and distributors of products with digital elements. Scope, classification, deadlines and penalties.

Since 11 September 2026 manufacturers must report actively exploited vulnerabilities within 24 hours. Deadlines, channel and CRA penalties.

The four Article 32 procedures, which one fits each category, what the technical documentation contains and where CE marking goes on software.

The 19 class I categories, the 4 class II categories and the 3 critical products of the CRA, with the technical descriptions of Regulation 2025/2392.

Three tiers of fines, up to 15 million or 2.5 %, two exceptions and one piece still missing in Spain, the national penalty regime.

Who NIS2 covers, essential and important entities, the Article 21 measures, reporting deadlines, fines and why Spain has still not transposed it.

Who the AI Act applies to, its four risk levels, the obligations by role, the timeline to 2028, the fines and how AESIA supervises it in Spain.

Who must label AI content under Article 50 of the AI Act, provider or deployer, the editorial exception, the fines and what Spain can enforce today.

The GDPR still applies to any AI that processes personal data. What the AI Act adds, what the Omnibus changed and how the two assessments fit together.

Three tiers of fines, up to 35 million or 7 %, the rule that protects SMEs and small mid-caps, and the Spanish regime that does not exist yet.