Is it allowed to deploy AI in Andorran government services without a data protection officer?

Last updated on November 21, 2025

No. Under Andorra’s data protection law (Llei 29/2021), any public entity processing personal data—including through AI systems—must appoint a Data Protection Officer (DPO). This requirement ensures compliance with privacy principles and accountability obligations.

The Legal Landscape

Andorra’s approach to data protection is firmly aligned with European standards. In 2021, the country enacted Llei 29/2021, qualificada de protecció de dades personals, a law modeled on the EU’s General Data Protection Regulation (GDPR). This legislation modernized Andorra’s privacy framework, introducing stricter obligations for both public and private entities. Among these obligations is the mandatory appointment of a Delegat de Protecció de Dades (DPD)—the local term for Data Protection Officer—when processing activities involve sensitive data or pose significant risks to individuals’ rights.

Deploying AI in government services almost always involves automated decision-making and large-scale data processing. These activities trigger heightened compliance requirements, including impact assessments, records of processing activities, and the designation of a DPO. The DPO acts as an independent advisor, monitoring compliance, guiding risk management, and serving as a liaison with the Andorran Data Protection Agency (APDA).

Why Is a DPO Mandatory?

The rationale is simple: AI systems amplify privacy risks. They often rely on profiling, predictive analytics, and automated decisions that can affect citizens’ rights. Andorra’s law explicitly addresses these concerns by requiring proactive accountability measures. A DPO ensures that government agencies implement privacy by design, conduct impact assessments, and maintain transparency in data handling.

Failure to appoint a DPO is not a minor oversight—it constitutes a breach of the law. The APDA has enforcement powers, including issuing fines and corrective orders. Recent cases show that Andorran authorities take compliance seriously, even sanctioning public bodies for transparency failures in data processing.

Cultural and Practical Context

Andorra’s commitment to data protection reflects its strategic position in Europe’s digital economy. Although not an EU member, the principality signed Convention 108+ and adopted GDPR-inspired rules to maintain adequacy status for cross-border data flows. This alignment is crucial for attracting investment and ensuring trust in digital services.

Government adoption of AI is part of Andorra’s broader innovation agenda, but it comes with strict safeguards. The law emphasizes responsabilitat proactiva—proactive responsibility—requiring entities to demonstrate compliance rather than merely claim it. This cultural shift prioritizes citizen rights over administrative convenience.

Fun Facts

Did you know Andorra was among the first microstates to sign the Council of Europe’s Convention 108+ on data protection? This move positioned the country as a leader in privacy compliance despite its small size. Another interesting point: the APDA runs public campaigns under the slogan “Junts les fem segures” (“Together we make them safe”), highlighting the importance of data security in everyday governance.

Practical Implications

For government agencies planning AI deployment, the compliance checklist includes:

  • Appointing a qualified DPO registered with the APDA.
  • Conducting a Data Protection Impact Assessment (DPIA) before implementation.
  • Maintaining detailed records of processing activities.
  • Ensuring transparency and citizen rights, including the right not to be subject to fully automated decisions without safeguards.

Skipping these steps can lead to sanctions, reputational damage, and suspension of AI projects.

Looking Ahead

As AI adoption accelerates, Andorra’s regulatory framework will likely evolve to address emerging risks such as algorithmic bias and cybersecurity threats. For now, the message is clear: innovation is welcome, but only within the boundaries of strong data protection governance.

See more about Andorra

Sources

Andorran Data Protection Agency (APDA)
https://www.apda.ad/en
Ongoing

Llei 29/2021, qualificada de protecció de dades personals
http://www.portaljuridicandorra.ad/L2021029
Ongoing

Scroll to Top