Skip to main content

How does Cyber Crucible support data protection requirements in Spain?

Short answer: In Spain, Cyber Crucible supports an organization's obligations under the GDPR and the Organic Law on Data Protection (LOPDGDD, enforced by the AEPD) by collecting no customer content, credentials, or keys and processing locally. Because there is minimal personal data in its custody, most obligations the AEPD enforces have little to attach to.

How it aligns

  • GDPR + LOPDGDD. Data minimization, encryption, and access control support the Spanish baseline; a data processing agreement is available.
  • Data residency. On-premises deployment keeps personal data in Spain where required.
  • Cybersecurity regime. Spain's NIS2 transposition was still in the legislative process as of 2026; Cyber Crucible supports covered entities' measures under the framework as adopted.

The honest boundary

The AEPD is one of the EU's more active enforcers; compliance is the organization's. Cyber Crucible holds no Spanish certification and supports these duties. Documentation is available on request.