Real Decreto 1720/2007, de 21 de diciembre, por el que se aprueba el Reglamento de desarrollo de la Ley Orgánica 15/1999, de 13 de diciembre, de protección de datos de carácter personal. | BOE-A-2008-979 — Spain law | Esheria

Real Decreto 1720/2007, de 21 de diciembre, por el que se aprueba el Reglamento de desarrollo de la Ley Orgánica 15/1999, de 13 de diciembre, de protección de datos de carácter personal.

This article states the regulation’s purpose: it develops the Personal Data Protection Organic Law and, in Chapter III of Title IX, sets rules for the Spanish Data Protection Agency’s sanctioning power.

AI-assisted research synopsis — verify against the official legal text below.

Jurisdiction
Spain
Instrument
Regulation
Citation
BOE-A-2008-979
Version
Undated source snapshot
Language
es
Updated
Official source
View official record ↗

Citation provenance: source:es:boe · schema StatuteEnrichmentPublicV1.

IT systems inspection access control access logging access requests access rights access to personal data administrative enforcement administrative filings administrative procedure administrative procedures administrative silence advertising campaigns age verification allegations application processing application scope audit logging authentication authorization authorization application authorization delegation authorization procedure automated decision-making autoridad competente +249 more

Statute overview

About this statute

The file controller’s authorization is required before data recovery procedures can be carried out, and the incident log must also record those recovery procedures and related details. Personal data on media must be handled with clear labels and encryption or equivalent safeguards, especially when transported or used on portable devices. A backup copy of data and recovery procedures must be kept in a different location from the equipment that processes the data, or otherwise protected by elements that ensure integrity and recovery. La norma exige registrar intentos de acceso, guardar ciertos datos, mantener el sistema bajo control del responsable de seguridad, conservar la información al menos dos años y revisarla mensualmente. When high-level security measures must be implemented under Article 81.3, personal data sent over public or wireless electronic communications networks must be encrypted or otherwise protected so third parties cannot read or tamper with it.