Data Centres: The Draft Royal Decree Redefining Grid Access Rules and Energy Consumption in Spain
The Spanish Ministry for Ecological Transition and Demographic Challenge has published the Draft Royal Decree establishing new requirements for data centres in Spain.
The text published is currently subject to public consultation until 4 September and may therefore be amended. However, it is expected to be processed under the urgent procedure and could therefore enter into force before the end of the year.
The main requirements cover resilience and digital sovereignty, energy and water efficiency, renewable energy consumption, and information reporting and disclosure obligations.
Regarding renewable energy, two alternative compliance routes are envisaged: a national renewable generation share above 90%, subject to restrictions on consumption hours (to be published by the Secretary of State for Energy); or covering at least 80% of consumption through self-consumption or renewable PPAs, subject to additionality and hourly correlation requirements.
The Draft Royal Decree also introduces new requirements for the demand capacity tenders provided for in Article 20 quater of Royal Decree 1183/2020.
The Spanish Ministry for Ecological Transition and Demographic Challenge (MITECO) has published a Draft Royal Decree regulating the energy and environmental sustainability, resilience and digital sovereignty requirements applicable to data centres (the “Draft RD”, available in Spanish here), open for public consultation and hearing process until 4 September 2026.
This Draft RD implements the mandate of Royal Decree-Law 7/2026, of 20 March, and sets out the conditions that data centres must meet to obtain and retain access and connection permits to electricity transport and distribution networks. In particular, the new rules focus on four concepts: 1. resilience and digital sovereignty requirements; 2. energy efficiency and water usage effectiveness requirements; 3. renewable energy requirements; and 4. information reporting and disclosure obligations.
In general, the Draft RD applies to data centres with access capacity of 1 MW or more that connect to the network after the entry into force of the Royal Decree ultimately approved, and non-compliance may result in the loss of their access and connection permits.
The Draft RD is currently subject to the public consultation and hearing process. The deadline for submitting comments is 4 September 2026. After this process, the text will be referred to the Council of State (Spain's supreme consultative body) for a report and then submitted to the Council of Ministers for approval.
In short, the text analysed is not final and may change before it receives approval or, indeed, may not be approved at all.
Because the Draft RD is being processed under the urgency procedure, final approval could come within a few weeks (probably between October and November).
As regards the personal scope, the Draft RD, as published for consultation, addressed to operators or, failing that, owners of data centres that have applied or intend to apply for access and connection permits to electricity transport and distribution networks. In general, except for Article 14, the obligations under the new rules will apply to data centres with access power capacity of 1 MW or more. They will also cover groups of data centres located at the same site and under common ownership which, in aggregate, reach that capacity. However, data centres used exclusively for defence, civil protection and public safety are excluded.
As regards the temporal scope, the Draft RD applies to new permits applied for after the entry into force of the Royal Decree ultimately approved, as well as to permits applied before its entry into force but still pending. Data centres that are already connected to the electricity network and have entered into a third-party network access contract (ATR contract) will not be subject to these access requirements (although they will remain subject to the Article 14 disclosure obligations if their IT power capacity reaches 500 kW).
As a transitional matter, applicants with pending applications (not yet approved) will have three (3) months from the entry into force of the Royal Decree ultimately approved to demonstrate compliance with its requirements and conditions. If they fail to do so, their applications will be rejected (Transitional Provision 1). Projects that already hold permits but have not yet connected to the network will likewise have six (6) months to demonstrate compliance with the new rules. If they fail to do so, the permits will lapse, and the guarantees posted will be enforced (Transitional Provision 3).
By way of exception, the Draft RD provides a safety valve to avoid enforcement of the guarantees: those with a pending permit application or an existing permit who do not wish to accept the new requirements may withdraw their applications or relinquish their permits within that same (6) six-month period without enforcement of the guarantees (Additional Provision 2).
Finally, the resilience and digital sovereignty requirements (Article 5) will not apply until the ministerial order implementing them enters into force (Transitional Provision 5).
Article 4 of the Draft RD makes the granting of access and connection permits conditional on simultaneous compliance with three sets of requirements:
| Requirement | Reference | Key content |
| Resilience and digital sovereignty | Article 5 |
Establishment in the EU, data retention in the EU, control of access from third countries, supervision of subcontractors, and measures against transfers that contravene EU law. *Not applicable during the transitional period until the model responsible statement is approved by ministerial order under Transitional Provision 5. |
| Energy efficiency and water usage effectiveness | Article 6 | Demonstrate PUE (power usage effectiveness) and WUE (water usage effectiveness) levels corresponding to Class «A» of the European label. During the transitional period (until the common European sustainability label applies): PUE ≤ 1.15 and WUE ≤ 0.1. |
| Renewable energy (option 1) | Article 7 | Share of renewable generation in the national electricity system > 90% (year n-2). In that case, only the maximum number of consumption hours is limited. |
| Renewable energy (option 2) | Articles 8 & 9 |
Additionality: cover 80% of total electricity consumption through self-consumption or renewable PPAs (in both cases, from installations no more than 18 months old when the data centre starts operating). Hourly matching: back 80% of consumption, hour by hour, with renewable generation |
Each requirement, and when it must be demonstrated, is explained below.
The operator or owner must meet the following requirements (limited to matters under its direct or contractual control):
Data centres hosting systems subject to the National Security Framework must also ensure that public-sector data is processed, stored and transferred exclusively within the EU.
The resilience and cybersecurity requirements are not regulated by this Draft RD and remain governed by their specific legislation (in particular, the transposition of the NIS2 Directive).
The above requirements must be demonstrated through two responsible statements (declaraciones responsables):
A key restriction applies between these two milestones: the network operator cannot sign the ATR contract (an essential precondition for consuming electricity from the grid) until it has received evidence that the second responsible statement has been submitted.
A ministerial order will approve the model responsible statement, the required documentation and the criteria for subsequent checks; it may not add substantive requirements.
Data centres must demonstrate that their PUE (power usage effectiveness) and WUE (water usage effectiveness) levels correspond to Class «A» of the European sustainability label provided for in Delegated Regulation (EU) 2024/1364 under Directive (EU) 2023/1791.
As a transitional measure, until the common European sustainability label applies (expected in August 2027), the maximum values are PUE ≤ 1.15 and WUE ≤ 0.1, calculated in accordance with Annex III to Delegated Regulation (EU) 2024/1364.
As with the resilience and digital sovereignty requirements, Article 6 of the Draft RD provides for a two-stage process for demonstrating compliance.
MITECO will verify the accuracy of the responsible statements and may request additional documentation.
During the transitional period, until the European labelling system applies, compliance will be demonstrated through responsible statements submitted simultaneously to the network operator and both ministries.
The Draft RD offers two alternative routes for meeting the renewable energy requirements:
Route 1 – Renewable generation share (Article 7): The renewable energy requirements will be deemed satisfied if the average share of renewable electricity in the national electricity system’s generation mix exceeded 90% in year n-2 (where "n" is the year in which the grid access application is submitted). Once the 90% threshold has been exceeded, the share will be treated as sufficient for the next five years, unless it is 90% or lower in any calendar year.
In that case, the permit will be granted subject to an annual grid-consumption hours cap: the total number of hours in the year multiplied by the renewable share for year n-2.
The Secretary of State for Energy will publish this limit by resolution in the Official State Gazette (BOE) at least two (2) months before the start of each year. Until it is published, the share will be presumed to be below 90% (so Route 2 must be used).
Once the ATR contract has been signed, the network operator will verify annually that the data centre does not exceed the grid-consumption hours cap.
Route 2 – Additionality and hourly matching (Articles 8 and 9): While the renewable generation share does not exceed 90% (or while the relevant figure has not been published), data centres must meet two requirements simultaneously:
1. Additionality (Article 8): Cover at least 80% of total electricity consumption through self-consumption (in accordance with Royal Decree 244/2019, of 5 April) or through one or more renewable power purchase agreements (renewable PPAs) with producers that own facilities located in Spain. The associated facilities must have a commissioning certificate dated no more than 18 months before the data centre starts operating (for these purposes, commencement means signing the ATR contract or, if earlier, first electricity consumption).
The developer must submit to the network operator, together with the permit application, a responsible statement setting out its deployment (and expansion) plans and supporting documentation evidencing the associated renewable generation capacity. Once operating, the data centre's consumption will at all times be limited to the energy for which it can demonstrate additionality—the data centre may increase its consumption as it brings new renewable generation online.
The network operator will verify the responsible statement and add it to the file, forwarding it to MITECO. The network operator will also be responsible for verifying compliance with the additionality requirement on an annual basis, using generation data provided by the system operator.
2. Hourly matching (Article 9): Ensure that at least 80% of the data centre's electricity consumption in each hour is backed by an equivalent volume of renewable electricity generated in that same hour. This matching may be achieved through self-consumption (verified by the network operator) or renewable PPAs. The system operator is responsible for checking compliance with this requirement where it is met through a renewable PPA.
Article 12 governs the characteristics of renewable PPAs, including: a minimum term of 10 years; execution as a public deed (escritura pública); express identification of the associated generation or storage facilities; identification of the proposed matching formula between consumption and associated generation; and the exclusion of matching arrangements based on forwards products whose renewable origin is evidenced solely by guarantees of origin.
The Draft RD establishes a graduated regime of consequences that depends on the type of requirement breached:
1. Prior cure and procedural safeguards
In all cases, if the Administration detects a breach, the competent authority will require it to be cured within a proportionate period (not less than three months, except where there is a serious and immediate risk). Only a final administrative decision – issued after giving the affected party an opportunity to be heard - may affect the permits. The obligated party will not be held responsible for breaches relating to matters outside its direct or contractual control.
2. Progressive surcharges for breaches of the renewable energy requirements (Articles 7-9)
The surcharges operate as progressive financial penalties and apply prior the potential permit revocation:
The network operator party to the ATR contract will apply the surcharges and issue monthly invoices.
3. Loss of the access and connection permits (Article 11)
As a last resort, the access and connection permits may be revoked. The triggers differ by requirement:
Article 14 imposes annual reporting and disclosure obligations on operators or owners of data centres with IT power capacity ≥ 500 kW, regardless of their access capacity. This threshold differs from the applicable threshold for the other requirements (1 MW of power access capacity) but is consistent with the scope of Delegated Regulation (EU) 2024/1364.
Content and deadline: Each year, before 15 May, the operators or owners must submit to the Directorate-General for Energy Planning and Coordination (DGPCE) the information set out in Annexes I (identification data) and II (key performance and sustainability indicators) to Delegated Regulation (EU) 2024/1364. The information must cover the previous calendar year or the period during which the data centre operated, if shorter than one year.
Disclosure: The information will be made publicly available on MITECO’s website (except for information subject to trade and business secret protection).
European Code of Conduct: Data centres with IT power capacity ≥ 1 MW must also notify the DGPCE annually (before 15 May) whether and how they take into account the best practices in the latest version of the European Code of Conduct on Energy Efficiency in Data Centres. If they do not apply those practices, they must explain why.
Procedure: The reporting and disclosure procedures will be established by resolution of the head of the DGPCE.
These obligations also apply to data centres already connected to the electricity network (not only those applying for new permits).
The Draft RD introduces several specific rules for the demand capacity tenders provided for in Article 20 quater of Royal Decree 1183/2020:
Precondition for launching a tender (Additional Provision 1): When deciding whether to launch a tender and open the publication period, the transmission network operator will disregard applications that do not demonstrate, at the time of submission, compliance with the requirements of Article 4 of the Draft RD. Only applications that demonstrate compliance may trigger the tender.
Digital sovereignty criteria in tenders (Final Provision 1): The Draft RD amends Article 20 ter of Royal Decree 1183/2020 to add that, where applicable, the criteria for tenders in which data centres participate will include resilience and digital sovereignty criteria. This means that voluntary digital sovereignty commitments (reserving capacity for EU companies, guarantees that data will not be transferred, etc.) may confer a competitive advantage in the award process.
Change in consumption type (Additional Provision 4): Applications suspended because a tender has been launched will lose the right to participate if they change the type of consumption declared to the network operator at any time after submission. The application will be deemed inadmissible. If that subsequent inadmissibility means that the remaining applications can be accommodated without a tender, the tender will be called off.
Applications suspended because of a tender (Transitional Provision 2): Data centres' applications suspended because a tender has been launched will also have three (3) months from the entry into force of the Royal Decree finally approved to demonstrate compliance with the requirements. If they fail to do so, the applications will be rejected. The system operator will assess whether, in light of those rejections, it should award capacity to the remaining applications or release the node and call off the tender.
Ashurst Perkins Coie's leading multidisciplinary data centre team can assist you with project structuring, project development and financing, contract drafting and negotiation, regulatory strategy and engagement with the public consultation.
Authors: Ismael Fernández Antón, Partner; María Antonia de Prada, Senior Associate.
The information provided is not intended to be a comprehensive review of all developments in the law and practice, or to cover all aspects of those referred to.
Readers should take legal advice before applying it to specific issues or transactions.