How can ManageEngine support LOPDGDD compliance?
With ManageEngine Log360, organizations can align with LOPDGDD requirements through centralized log collection and correlation across systems that store personal data, continuous auditing of who accessed which records and when, real-time detection of personal data breaches with automated alerting to support notification timelines to the AEPD and affected individuals, file integrity monitoring over personal data repositories, and secure, tamper-evident log retention. These capabilities help implement the risk-based security measures the law requires, enforce accountability, and produce the audit evidence expected during AEPD scrutiny.
Principles of data protectionTítulo II — Principios de protección de datos (Principles of data protection)
| Clause | Functionality | Explanation |
|---|---|---|
| Art. 4. Exactitud de los datos. Personal data shall be accurate and, where necessary, kept up to date; inaccurate data shall be erased or rectified without delay, and controllers shall be able to identify the source of the data. | Log360 - Database change auditing, file integrity monitoring, real-time alerts, DML/DDL audit reports | Log360 audits create, modify, and delete operations on the databases and file systems that hold personal data, and raises real-time alerts on unauthorised change, helping the controller keep records accurate and evidence when and by whom data was altered. It does not itself judge the factual accuracy of a record; the controller must still action rectification and erasure decisions. |
| Art. 5. Deber de confidencialidad. Controllers and processors, and anyone involved in any phase of processing, are bound by a duty of confidentiality over the personal data they access. | Log360 - Privileged user monitoring, file access auditing, DLP | Log360 monitors privileged-user activity and audits file access so unauthorised viewing of confidential personal data is detected, and data loss prevention stops it from leaving controlled repositories. Restricting who holds that access in the first place is an identity function outside Log360, addressed by an IAM layer such as AD360. |
| Art. 9. Categorías especiales de datos. Processing of special categories of data (such as health, biometric, and ideology data) requires a legal basis reserved by law and additional safeguards against unauthorised access. | Log360 - Data discovery, data classification, file integrity monitoring, DLP, exfiltration anomaly detection | Log360 discovers and classifies special-category data such as health and biometric records across monitored file systems and databases, then applies file integrity monitoring, data loss prevention, and exfiltration anomaly detection to guard it against unauthorised access, which are the additional safeguards the article requires. Restricting access to authorised roles is an IAM function, and the legal-basis determination reserved by law is an organisational decision outside the suite. |
Rights of individualsTítulo III — Derechos de las personas (Rights of individuals)
| Clause | Functionality | Explanation |
|---|---|---|
| Art. 11-18. Ejercicio de los derechos. The controller shall facilitate the exercise of the rights of access, rectification, erasure, restriction, portability, and objection, and be able to locate and act on the personal data held about the individual. | Log360 - Data discovery, file access auditing, log search, audit-ready reports | Log360 data discovery locates where an individual's personal data is stored across monitored file servers, databases, and cloud repositories, so the controller can act on access, rectification, erasure, restriction, and portability requests, and its log search and reports evidence the action taken. Log360 does not itself execute the rectification or erasure in the source system, and the request intake workflow and legal validation of each request sit outside the suite. |
Controller and processorTítulo V — Responsable y encargado del tratamiento (Controller and processor)
| Clause | Functionality | Explanation |
|---|---|---|
| Art. 28. Obligaciones generales del responsable y encargado. Following a risk-based approach, the controller and processor shall adopt technical and organisational measures appropriate to the risk to ensure and demonstrate compliance. | Log360 - Security and risk posture management, real-time analytics, correlation engine, log retention, audit-ready reports | Log360 supports the risk-based approach through security and risk posture management, which scans Active Directory and SQL configurations for misconfigurations and exposure so measures are chosen against actual risk. Continuous analytics, correlation, log retention, and audit-ready reports then demonstrate that those measures are operating, meeting the demonstrate-compliance limb of the article. The corresponding access-side controls are an IAM function. |
| Art. 30. Representantes de los responsables o encargados no establecidos en la UE. Records and oversight of processing carried out by controllers or processors, including through representatives, remain the controller's responsibility. | Log360 - Multi-source log collection, cloud security monitoring, audit-ready reports | Log360 collects and analyses logs from hosted, outsourced, and cloud environments and extends monitoring to cloud-hosted assets, so the controller retains oversight and evidence of processing carried out beyond its own premises. The appointment of a representative is an organisational and contractual act with no software control. |
| Art. 31. Registro de las actividades de tratamiento. The controller and processor shall maintain a record of the processing activities carried out under their responsibility. | Log360 - Centralised log management, log retention, log search, audit-ready reports | Log360 centrally collects and retains activity from the servers, databases, applications, and cloud services in scope, so the controller can evidence which processing activities were carried out, by whom, and when. Its log search and audit-ready reports export that history into the record of processing activities. The register document itself is compiled and maintained by the controller. |
| Art. 32. Bloqueo de los datos. Personal data shall be blocked — retained in a restricted, inaccessible state and made available only to specified authorities — rather than deleted, where retention is legally required, until statutory limitation periods elapse. | Log360 - File access auditing, DLP, log retention, real-time alerts | Log360 partially addresses this clause. Data loss prevention restricts movement of blocked data, file access auditing records every access to it, and log retention preserves that record for the statutory limitation period, so any release to a specified authority is evidenced. Log360 provides no native application-level blocking state; the controller must implement the blocked-but-retained status in the source systems and use these controls to evidence the restriction. |
| Art. 33. Encargado del tratamiento. Processing by a processor shall be governed by a contract, and the controller shall retain visibility and control over personal data processed on its behalf. | Log360 - Multi-source log collection, cloud security monitoring, correlation engine, real-time alerts | Log360 collects and analyses logs from systems run by processors in hosted and cloud environments and alerts on anomalous activity, preserving the controller's visibility over personal data processed on its behalf. Restricting and revoking processor access is an IAM function outside Log360. The processing contract the article requires is a legal instrument, not a software control. |
Data protection authoritiesTítulo VII — Autoridades de protección de datos (Data protection authorities)
| Clause | Functionality | Explanation |
|---|---|---|
| Art. 53 bis. Actuaciones de investigación a través de sistemas digitales. On investigation, the controller shall be able to produce records evidencing its processing activities and access to personal data. | Log360 - Log search, forensic analysis, audit-ready reports, incident timelines | Log360 log search and forensic analysis reconstruct who accessed personal data, when, and what changed, and its audit-ready reports and incident timelines package that evidence for an AEPD investigation across the configured retention window. The conduct of the investigation itself is the authority's function, not a controlled clause. |
Penalty regime and breach handlingTítulo IX — Régimen sancionador (Penalty regime) and breach handling
| Clause | Functionality | Explanation |
|---|---|---|
| Art. 28 / Disposición adicional novena, in conjunction with Art. 33-34 of Regulation (EU) 2016/679. In the case of a personal data breach, the controller shall detect it, notify the AEPD without undue delay where feasible within 72 hours, and document the breach, its effects, and the remedial action. | Log360 - Correlation engine, UEBA, threat detection, Incident Workbench, SOAR playbooks, forensic analysis | Log360 detects breaches through 2000+ MITRE-mapped correlation rules, UEBA anomaly scoring, and threat detection, then the Incident Workbench and forensic analysis reconstruct scope and cause and SOAR playbooks record the remedial action, meeting the detect-and-document sequence the 72-hour window demands. Identity-based breaches such as account compromise are additionally surfaced by an IAM layer. The notification message to the AEPD is submitted by the controller. |
Guarantee of digital rightsTítulo X — Garantía de los derechos digitales (Guarantee of digital rights)
| Clause | Functionality | Explanation |
|---|---|---|
| Art. 82. Derecho a la seguridad digital. Individuals have the right to the security of the data and communications they exchange with providers, requiring appropriate technical measures against unauthorised access. | Log360 - Threat detection, file integrity monitoring, real-time analytics, DLP | Log360 protects the data and communications individuals exchange with the controller by detecting intrusion and anomalous access in real time, monitoring the integrity of the files that hold them, and blocking exfiltration through data loss prevention. The authentication and access-restriction measures this right also implies are an IAM function outside Log360. |
| Art. 87-90. Intimidad y uso de dispositivos digitales en el ámbito laboral. Where an employer monitors workplace digital devices, systems, or geolocation, monitoring shall be proportionate and access to the resulting personal data controlled. | Log360 - File access auditing, privileged user monitoring, log retention, DLP | Log360 partially addresses this clause, on the data-handling side. File access auditing and privileged user monitoring record who viewed the personal data produced by workplace device and geolocation monitoring, DLP restricts its movement, and log retention preserves it under controlled access. The proportionality of the monitoring, and the internal device-use and digital-disconnection policies the articles require, are HR and labour-policy decisions outside Log360. |

