Back to Browse

Spanish Law MCP Server

Developer ToolsUse Caution4.2Local
Free

Spanish legislation via MCP — full-text search across statutes and provisions

About

Spanish legislation via MCP — full-text search across statutes and provisions

Security Report

4.2
Use Caution4.2High Risk

This MCP server is a well-structured legal research tool with appropriate security controls and no critical vulnerabilities. Authentication is properly delegated to the Ansvar OAuth gateway for hosted deployments, and self-hosted variants can operate without credentials for local development. Code quality is generally good with proper input validation, and permissions (network_http, env_vars, file_read) are appropriate for a legal research tool that ingests data from BOE and EU sources. Minor concerns include broad exception handling and lack of explicit rate limiting in the tool implementations, but these are low-severity quality issues that do not impact the security posture. Supply chain analysis found 6 known vulnerabilities in dependencies (2 critical, 2 high severity). Package verification found 1 issue.

4 files analyzed · 12 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "eu-ansvar-spanish-law-mcp": {
      "args": [
        "-y",
        "@ansvar/spanish-law-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Spanish Law MCP Server

The Spanish law corpus is now served through the Ansvar Gateway. Connect your AI assistant (Claude, Copilot, Cursor, custom MCP client) to https://gateway.ansvar.eu/mcp — one OAuth connection, free tier available, covering this corpus plus EU regulations, national law across 28 audited jurisdictions, and CVE/security intelligence, every result with a verbatim source citation. Start at https://ansvar.eu/docs/quickstart

Connect

Claude Code (one line):

claude mcp add ansvar --transport http https://gateway.ansvar.eu/mcp

Claude Desktop / Cursor — add to claude_desktop_config.json (or mcp.json):

{
  "mcpServers": {
    "ansvar": {
      "type": "url",
      "url": "https://gateway.ansvar.eu/mcp"
    }
  }
}

Claude.ai — Settings → Connectors → Add custom connector → paste https://gateway.ansvar.eu/mcp

First request opens an OAuth signup flow (setup details: ansvar.eu/docs/quickstart). After signup, your client is bound to your account; tier (free / premium / team / company) determines fan-out, quota, and which downstream MCPs are reachable.


Self-host this MCP

You can also clone this repo and build the corpus yourself. The schema, fetcher, and tool implementations all live here. What is not in the repo is the pre-built database — TDM and standards-licensing constraints on the upstream sources mean we host the corpus on Ansvar infrastructure rather than redistribute it as a public artifact.

Build your own: run this repo's ingestion script (entry-point varies per repo — typically scripts/ingest.sh, npm run ingest, or make ingest; check the repo root).

The BOE (Boletín Oficial del Estado) alternative for the AI age.

MCP Registry License GitHub stars CI Daily Data Check Database Provisions

Query 12,181 Spanish statutes -- from la LOPDGDD y el RGPD, el Código Penal, and el Estatuto de los Trabajadores to el Código Civil, la Ley de Sociedades de Capital, and more -- directly from Claude, Cursor, or any MCP-compatible client.

If you're building legal tech, compliance tools, or doing Spanish legal research, this is your verified reference database.

Built by Ansvar Systems -- Stockholm, Sweden


Why This Exists

Spanish legal research means navigating the Boletín Oficial del Estado, regional BOCAs, and EUR-Lex, then manually reconciling between national and EU law. Whether you're:

  • A lawyer validating citations in a brief or contract
  • A compliance officer checking LOPDGDD obligations or ENS requirements
  • A legal tech developer building tools on Spanish law
  • A researcher tracing legislative provisions across 12,181 national statutes

...you shouldn't need dozens of browser tabs and manual cross-referencing. Ask Claude. Get the exact provision. With context.

This MCP server makes Spanish law searchable, cross-referenceable, and AI-readable.


Example Queries

Once connected, just ask naturally:

  • "¿Qué dice el artículo 6 de la LOPDGDD sobre el tratamiento de datos personales?"
  • "Búsqueda 'protección de datos' en el derecho español (LOPDGDD, RGPD)"
  • "¿Qué artículos del Código Penal regulan los delitos informáticos?"
  • "Encuentra disposiciones sobre despido improcedente en el Estatuto de los Trabajadores"
  • "What EU directives does the LOPDGDD implement?"
  • "Which Spanish laws implement the NIS2 Directive?"
  • "Valida la cita 'Art. 197 CP' (Código Penal)"
  • "Busca 'responsabilidad civil' en el Código Civil español"
  • "Compare incident notification requirements under NIS2 and the Spanish transposition"
  • "¿Está en vigor el Real Decreto-ley 14/2019 sobre medidas urgentes de administración digital?"

What's Included

CategoryCountDetails
Statutes12,181 statutesComprehensive Spanish legislation from BOE
Provisions297,760 articlesFull-text searchable with FTS5
Preparatory Works12,193 documentsPremium tier -- exposiciones de motivos, proyectos de ley
Case Law0 (free tier)Reserved for future ingestion
Agency Guidance0 (free tier)Reserved for future ingestion
Database Size~849 MBOptimized SQLite, portable
Daily UpdatesAutomatedFreshness checks against BOE

Verified data only -- every citation is validated against official sources (BOE, boe.es). Zero LLM-generated content.


See It In Action

Why This Works

Verbatim Source Text (No LLM Processing):

  • All statute text is ingested from the BOE Datos Abiertos API (boe.es/datosabiertos)
  • Provisions are returned unchanged from SQLite FTS5 database rows
  • Zero LLM summarization or paraphrasing -- the database contains regulation text, not AI interpretations

Smart Context Management:

  • Search returns ranked provisions with BM25 scoring (safe for context)
  • Provision retrieval gives exact text by statute identifier + article number
  • Cross-references help navigate without loading everything at once

Technical Architecture:

BOE Datos Abiertos API --> Parse --> SQLite --> FTS5 snippet() --> MCP response
                            ^                        ^
                     Provision parser         Verbatim database query

Traditional Research vs. This MCP

Traditional ApproachThis MCP Server
Search BOE by statute nameSearch by plain Spanish: "protección datos personales"
Navigate multi-title statutes manuallyGet the exact article with context
Manual cross-referencing between codesbuild_legal_stance aggregates across sources
"¿Está este artículo vigente?" -> check manuallycheck_currency tool -> answer in seconds
Find EU basis -> dig through EUR-Lexget_eu_basis -> linked EU directives instantly
Check BOE, EUR-Lex, AEPD separatelyDaily automated freshness checks
No API, no integrationMCP protocol -> AI-native

Traditional: Search BOE -> Download PDF -> Ctrl+F -> Cross-reference with RGPD -> Check EUR-Lex -> Repeat

This MCP: "¿Qué normativa europea da base al artículo 22 de la LOPDGDD sobre decisiones automatizadas?" -> Done.


Available Tools (13)

Core Legal Research Tools (8)

ToolDescription
search_legislationFTS5 full-text search across 297,760 provisions with BM25 ranking
get_provisionRetrieve specific provision by statute identifier + article number
validate_citationValidate citation against database (zero-hallucination check)
build_legal_stanceAggregate citations from statutes, preparatory works, and case law
format_citationFormat citations per Spanish conventions (full/short/pinpoint)
check_currencyCheck if statute is in force, amended, or repealed
list_sourcesList all available statutes with metadata and data provenance
aboutServer info, capabilities, dataset statistics, and coverage summary

EU Law Integration Tools (5)

ToolDescription
get_eu_basisGet EU directives/regulations underlying a Spanish statute
get_spanish_implementationsFind Spanish laws implementing a specific EU act
search_eu_implementationsSearch EU documents with Spanish implementation counts
get_provision_eu_basisGet EU law references for a specific provision
validate_eu_complianceCheck implementation status against EU directives

EU Law Integration

Spain is a full EU member state. Spanish law has systematic EU cross-references across data protection, cybersecurity, financial regulation, and consumer rights.

MetricValue
EU IntegrationFull EU member (accession 1986)
GDPR ImplementationLOPDGDD (Ley Orgánica 3/2018, AEPD oversight)
NIS2 TranspositionReal Decreto-ley + Ley de Seguridad de las Redes y Sistemas de Información
AI ActDirect application (EU regulation, no transposition needed)
ENSEsquema Nacional de Seguridad (Real Decreto 311/2022)
EUR-Lex IntegrationAutomated metadata fetching

Key EU Acts with Spanish Implementations

  1. GDPR (2016/679) -- LOPDGDD (Ley Orgánica 3/2018) + AEPD decisions
  2. NIS2 Directive (2022/2555) -- Ley de Ciberseguridad (transposition pending as of 2026)
  3. eIDAS Regulation (910/2014) -- Ley 6/2020 (firma y certificados electrónicos)
  4. AI Act (2024/1689) -- Direct application
  5. DORA (2022/2554) -- Direct application in financial sector

See EU_INTEGRATION_GUIDE.md for detailed documentation.


Data Sources & Freshness

All content is sourced from authoritative Spanish legal databases:

Data Provenance

FieldValue
AuthorityAgencia Estatal Boletín Oficial del Estado
Retrieval methodBOE Datos Abiertos REST API
LanguagesSpanish (official language of law)
LicenseSpanish-TRLPI-Art-13 -- Spanish statutory public domain (TRLPI Art. 13)
Coverage12,181 consolidated statutes (national + regional)
Last ingested2026-02-25

Automated Freshness Checks (Daily)

A daily GitHub Actions workflow monitors all data sources:

SourceCheckMethod
Statute amendmentsBOE API date comparisonAll 12,181 statutes checked
New statutesBOE publications (90-day window)Diffed against database
Preparatory worksBOE proyecto de ley API (30-day window)New texts detected
EU reference stalenessGit commit timestampsFlagged if >90 days old

Security

This project uses multiple layers of automated security scanning:

ScannerWhat It DoesSchedule
CodeQLStatic analysis for security vulnerabilitiesWeekly + PRs
SemgrepSAST scanning (OWASP top 10, secrets, TypeScript)Every push
GitleaksSecret detection across git historyEvery push
TrivyCVE scanning on filesystem and npm dependenciesDaily
Docker SecurityContainer image scanning + SBOM generationDaily
Socket.devSupply chain attack detectionPRs
OSSF ScorecardOpenSSF best practices scoringWeekly
DependabotAutomated dependency updatesWeekly

See SECURITY.md for the full policy and vulnerability reporting.


Important Disclaimers

Legal Advice

THIS TOOL IS NOT LEGAL ADVICE

Statute text is sourced from official BOE publications. However:

  • This is a research tool, not a substitute for professional legal counsel
  • Court case coverage is not included in the free tier -- do not rely solely on this for case law research
  • Verify critical citations against primary sources for court filings
  • EU cross-references are extracted from Spanish statute text, not EUR-Lex full text
  • Regional legislation (Comunidades Autónomas) may not be fully covered

Before using professionally, read: DISCLAIMER.md | PRIVACY.md

Client Confidentiality

Queries go through the Claude API. For privileged or confidential matters, use on-premise deployment. For guidance on professional obligations, consult the Consejo General de la Abogacía Española. See PRIVACY.md for compliance guidance.


Documentation


Development

Setup

git clone https://github.com/Ansvar-Systems/spanish-law-mcp
cd spanish-law-mcp
npm install
npm run build
npm test

Running Locally

npm run dev                                       # Start MCP server
npx @anthropic/mcp-inspector node dist/index.js   # Test with MCP Inspector

Data Management

npm run ingest                    # Ingest statutes from BOE Datos Abiertos
npm run build:db                  # Rebuild SQLite database
npm run drift:detect              # Run drift detection against anchors
npm run check-updates             # Check for amendments and new statutes
npm run census                    # Generate coverage census report

Performance

  • Search Speed: <100ms for most FTS5 queries
  • Database Size: ~849 MB (efficient, portable)
  • Reliability: 100% ingestion success rate across 12,181 statutes

More Ansvar MCPs

Full fleet coverage at ansvar.eu/coverage.

Contributing

Contributions welcome! See CONTRIBUTING.md for guidelines.

Priority areas:

  • Court case law expansion (Tribunal Supremo, Audiencia Nacional)
  • AEPD decisions and guidance ingestion
  • Historical statute versions and amendment tracking
  • Autonomous community legislation coverage

Roadmap

  • Core statute database with FTS5 search

  • Full corpus ingestion (12,181 statutes, 297,760 provisions)

  • EU law integration tools

  • Vercel Streamable HTTP deployment

  • Premium preparatory works (12,193 documents)

  • Tribunal Supremo case law coverage

  • AEPD guidance documents

  • Historical statute versions (amendment tracking)

  • Autonomous community legislation


Citation

If you use this MCP server in academic research:

@software{spanish_law_mcp_2026,
  author = {Ansvar Systems AB},
  title = {Spanish Law MCP Server: Production-Grade Legal Research Tool},
  year = {2026},
  url = {https://github.com/Ansvar-Systems/spanish-law-mcp},
  note = {12,181 Spanish statutes with 297,760 provisions and EU law cross-references}
}

License

Apache License 2.0. See LICENSE for details.

Data Licenses

  • Statutes & Legislation: Spanish-TRLPI-Art-13 -- Spanish statutory public domain. TRLPI Art. 13 (Real Decreto Legislativo 1/1996) provides that laws or regulations, draft bills, decisions of judicial bodies and acts of public authorities, as well as official translations of all such texts, are not the subject of intellectual property protection. Verified verbatim 2026-05-17 -- see docs/audits/2026-05-17-eu-copyright-statutory-works-batch-1b-DE-IE-IT-NL-ES.md. Catalog entry: Spanish-TRLPI-Art-13 in infrastructure/attribution-licenses.json.
  • EU Metadata: EUR-Lex (EU public domain, Decision 2011/833/EU)

About Ansvar Systems

We build AI-accelerated compliance and legal research tools for the European market. This MCP server started as our internal reference tool for Spanish law -- turns out everyone building for the Spanish and EU markets has the same research frustrations.

So we're open-sourcing it. Navigating 12,181 statutes shouldn't require a law degree.

ansvar.eu -- Stockholm, Sweden


Reviews

No reviews yet

Be the first to review this server!