Securfy
OPINIONJune 10, 202612 min read

Are Encrypted Phones Legal in Spain?

A full legal analysis of encrypted devices in Spain: the applicable laws, the Encrochat case, case law, and what Spanish regulation says about encrypting communications.

Fabio Marco

Cybersecurity Engineer · Network management

Are Encrypted Phones Legal in Spain?

Using encrypted devices is entirely legal in Spain. No law prohibits encrypting communications, running encrypted operating systems or owning encrypted devices. In fact, the fundamental right to personal and family privacy, set out in article 18.1 of the Spanish Constitution, actively protects the use of tools that safeguard the privacy of communications.

Organic Law 3/2018 on Personal Data Protection and the Guarantee of Digital Rights (LOPDGDD) states in article 7 that citizens have a right to the protection of their personal data, and that this protection covers technical measures such as encryption. The European General Data Protection Regulation (GDPR), directly applicable in Spain, requires companies handling personal data to implement technical security measures, encryption among them. In other words: it is not only legal, in many cases it is mandatory.

The Spanish Criminal Code, in article 197.4, makes unauthorised access to computer systems a criminal offence. Encrypted systems used to protect information are therefore not an act of concealment but a legitimate protective measure recognised by the law itself. Owning an encrypted phone is neither a crime nor an infraction of any kind.

The Encrochat case and its impact in Spain

The Encrochat case has caused enormous confusion about the legality of encrypted devices. In 2020, European authorities, working with France's national intelligence agency, compromised the Encrochat communications network — a company selling modified Android devices with end-to-end encryption — and collected millions of customer messages across Europe.

In Spain, Operation Villamañán grew out of that interception and led to dozens of arrests. But it is essential to understand what was actually prosecuted: nobody was convicted for using an encrypted phone. What was investigated and convicted were pre-existing offences — mainly drug trafficking and money laundering — whose evidence surfaced through the interception. The encrypted device was the communication tool, not the offence.

Spanish courts, following the doctrine of the European Court of Human Rights (ECtHR), have held that the Encrochat interception was an investigative measure requiring judicial oversight. The legality of encryption as a technology has never been in question. Encryption is legally neutral: it can protect legitimate information or conceal unlawful activity, just as a car can take you to work or carry you away from a robbery. The tool is not the crime.

What does Spanish case law say?

The Audiencia Nacional and the Supreme Court have issued significant rulings on the interception of communications and the use of evidence obtained through encrypted systems. The settled doctrine holds that:

First, encrypting communications is a legitimate right of the citizen. STS 169/2023, on evidence obtained through intelligence techniques, establishes that the mere use of secure communication systems cannot be treated as evidence of a crime. Some other factual basis must justify the investigation.

Second, intercepting encrypted communications requires prior judicial authorisation and reasoning. The Criminal Procedure Act (articles 579 and following) sets out a strict procedure for telematic interception. Law enforcement cannot order it unilaterally.

Third, evidence obtained in breach of those procedures can be declared void. The fruits of the poisonous tree doctrine — not formally recognised in Spain under that name — operates in practice: if the interception was unlawful, the evidence is tainted and can be thrown out.

The NIS2 Directive and mandatory security

The transposition of the NIS2 Directive in Spain, through Royal Decree-Law 5/2023, has strengthened the legitimacy of encryption further. The rules require essential service companies and important digital entities to implement technical cybersecurity measures, including the encryption of data in transit and at rest. For many companies, using an encrypted device is not an option but a compliance requirement.

The National Cybersecurity Institute (INCIBE) regularly publishes guidance recommending encryption as one of the basic protective measures. The same public administrations that investigate crimes actively promote encryption to protect citizens' information. That duality shows encryption is a dual-use technology, with legitimate and necessary applications in most cases.

What happens if your device is seized?

In the hypothetical case that a police or judicial authority requests access to your encrypted device, Spanish rules set clear limits. Article 18.2 of the Constitution protects the secrecy of communications. An obligation to reveal an unlock password is not explicitly set out in Spanish criminal law, unlike in other countries such as the United Kingdom.

In practice, if a judicial authority orders passwords to be handed over and the owner refuses, the owner may be in contempt of judicial authority. That situation still requires a prior court order and a formal procedure. It is not a decision police can take on the spot during an arrest or a search. And on a well-configured GrapheneOS device, the system can be set to wipe the encryption keys automatically after a number of failed attempts, leaving the device technically inaccessible.

Buying, owning and using an encrypted phone in Spain is entirely legal and constitutionally protected. Encryption is a right, not a privilege, and data protection law itself promotes its use. The Encrochat case did not change the legality of encryption: it changed public perception, not the legal framework. To understand what technically separates these devices from a conventional smartphone, read our comparison of encrypted phones vs normal phones.

For lawyers, journalists, doctors, business owners and any citizen concerned about privacy, an encrypted device is a legitimate protective tool — recognised and, in many cases, mandatory. What matters is using the technology for lawful ends, which is exactly what 99.9% of Securfy users do. Visit our encrypted phone store or our cybersecurity and digital privacy audit.

If you have specific questions about legality in your professional sector, consult a lawyer specialising in data protection or cybersecurity. At Securfy we work with law firms that advise our business clients on the regulatory compliance of their encrypted devices.

legalitySpainencryptionlawEncrochat

Want a phone with this protection?

Discover our encrypted devices with GrapheneOS and hardened iOS. Discreet shipping, included support and privacy guaranteed.

View devices