9112 Emergency Hub: Spain (ES)

Flag of Spain

This protocol is for critical cyber incidents affecting legal entities operating within Spanish jurisdiction. Ensure all internal containment actions are documented to comply with the strict regulatory deadlines detailed below.

1. Operational & NIS2 Early Warning (24 Hours)

Operators of essential services must report significant cyber incidents within 24 hours.

  • Authority: INCIBE-CERT / CCN-CERT (for critical infrastructure)
  • Direct Reporting Portal: INCIBE-CERT Incident Reporting
  • Emergency Contact: incidentes@incibe-cert.es

2. GDPR Data Breach Notification (72 Hours)

If the incident involves the compromise of personal data, a formal notification must be submitted within 72 hours.

  • Authority: Agencia Española de Protección de Datos (AEPD)
  • Direct Reporting Portal: AEPD Notification Portal
  • Contact: Via the AEPD electronic headquarters.

3. Law Enforcement / Cybercrime (Optional but Recommended)

For incidents involving extortion, ransomware, or state-sponsored actors, coordinate with federal law enforcement.

  • Authority: Policía Nacional (BIT) or Guardia Civil
  • Contact: cibercrimen@policia.es or local authorities (091 / 062)

← Back to European Master Matrix