{
  "node_id": "ad-pdp-law-2021",
  "title": "Andorra Qualified Law No. 29/2021 on Personal Data Protection - AAPD",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-04-27",
  "bluf": "Andorra's Qualified Law No. 29/2021 on Personal Data Protection (Llei qualificada de protecció de dades personals), adopted by the General Council (Consell General) of Andorra and entered into force in 2021, is Andorra's comprehensive personal data protection legislation establishing a fully GDPR-aligned rights-based framework for the protection of personal data. Andorra is a microstate co-principality between France and Spain that maintains close economic and institutional ties with the European Union; although not an EU member state, Andorra participates in the EU Customs Union and has progressively aligned its legal framework with EU standards. Andorra's Qualified Law No. 29/2021 is comprehensively aligned with the EU General Data Protection Regulation, and Andorra has been recognised by the European Commission as providing adequate data protection for the purposes of international data transfers from the EU. The supervisory authority is the Andorran Data Protection Agency (Agència Andorrana de Protecció de Dades - AAPD), an independent institution responsible for oversight, enforcement, and guidance on personal data protection standards in Andorra. Key features of Andorra's Qualified Law No. 29/2021 on Personal Data Protection: (1) Scope - applies to personal data processing by any person established in Andorra or processing data of individuals located in Andorra; (2) Data processing principles - processing must comply with: lawfulness; purpose limitation; data minimisation; accuracy; storage limitation; security; and accountability; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health status; sexual orientation; criminal convictions; biometric data; and genetic data; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to restriction; right to object; right to data portability; and right not to be subject to solely automated decisions; (6) Data Protection Officer - required for public authorities and organisations processing personal data on a large scale or systematically; (7) Breach notification - controllers must notify the AAPD of personal data breaches within 72 hours; high-risk breaches require data subject notification; (8) Data Protection Impact Assessment - required for high-risk processing; (9) Cross-border transfers - personal data may only be transferred to countries providing adequate protection or using AAPD-approved safeguards; and (10) Administrative fines - graduated fines aligned with GDPR fine structures. Andorra's EU adequacy recognition and GDPR-equivalent framework position it as a European microstate fully integrated into the European data protection ecosystem.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "coe-convention-108-plus",
    "iso-27001-2022"
  ],
  "primary_citations_count": 7
}