Certix

GDPR adaptation for businesses:
a method, not a pack of PDFs

Adapting your company to the GDPR is not signing a few generic documents. It is analysing what you really do and ordering it, step by step. This is the method we follow with every client.

9

steps of the method

Art. 5.2

GDPR — proactive accountability

0€

initial analysis of your activity

GDPR + LOPDGDD

applicable framework in Spain

What it is

What is GDPR adaptation for a company?

Adapting a company to the GDPR and the LOPDGDD means putting in order everything the regulation requires: knowing what data you process, on what legal basis, documenting it, protecting it, informing people and knowing how to respond to their rights and to an incident.

Most of the market solves this by handing over a pack of generic documents that does not match what the company actually does. Signing that paperwork is not complying: it is having a folder full of PDFs that would not hold up under review. Certix does not work that way.

A real adaptation follows a method. The one you see below is the same one we apply with every client, and each step links to the guide where we explain it in detail.

Your real activity

We start from what you actually do, not from a standard model.

An ordered method

9 steps with a legal basis, from the inventory to the breach protocol.

Ongoing compliance

Adaptation does not end: it is reviewed when something relevant changes.

The method

How to adapt your company to the GDPR, step by step

Each step links to the full guide where we explain it in detail. It is the journey we make with every client.

01

Proactive accountability

The starting point is not filling in paperwork: it is accepting that the company (the controller) must be able to demonstrate that it complies, at all times (art. 5.2 and 24 GDPR). Everything else is ordered around the principles of art. 5.

What data protection is
02

Data inventory

You cannot protect what you do not know. You identify which data you process and of what type: basic identifying data versus the special categories of art. 9 GDPR (health, biometrics, ideology…), which require reinforced safeguards.

Specially protected data
03

Legal bases

Every processing activity needs a legal basis under art. 6 GDPR (contract, legal obligation, consent, legitimate interest…). If there is art. 9 data, a dual basis with an art. 9.2 exception is required.

Processing, disclosure and transfers
04

Documentation and RoPA

The Record of Processing Activities (art. 30 GDPR) is the map of everything above. It comes with the information notices and the processing agreements with each provider that accesses data (art. 28 GDPR).

Record of Processing Activities (RoPA)
05

Security and risks

Technical and organisational measures proportionate to the risk (art. 32 GDPR): access control, encryption, backups, protocols. When a processing activity may entail a high risk, a Data Protection Impact Assessment (art. 35 GDPR) is required.

Information security policy
06

Duty to inform

The data subject has the right to know what is done with their data, and the company the obligation to inform them clearly and in advance (art. 13 and 14 GDPR). This takes shape in the information notices and the website privacy policy.

Your website privacy policy
07

Data subjects' rights

A free and timely procedure to handle access, rectification, erasure, objection, restriction and portability (arts. 15-22 GDPR). Having them is not enough: you have to know how to respond to them.

Access, rectification, erasure…
08

Data Protection Officer

Some organisations must appoint a DPO (art. 37 GDPR, extended by art. 34 LOPDGDD). It is not universal: it depends on the type and scale of the processing. The initial analysis determines whether it applies in your case.

Data Protection Officer
09

Breach protocol

Zero risk does not exist. Maturity is measured by the reaction: document every breach, notify the AEPD within 72 hours where appropriate (art. 33) and communicate to the affected individuals if the risk is high (art. 34).

What to do in a breach

Full guide: how to adapt my company to the GDPR →

Why Certix

We analyse. We don't hand out templates.

Most of the market analyses nothing. It copies, pastes, charges and disappears. The result is a company with documents that do not reflect its activity and that are useless when a complaint arrives.

Our work starts by understanding what your company does. From there we order each step of the method around your reality, with a private documentary management platform and ongoing support. No sales reps in between: you are looked after by someone who understands the regulation.

And it does not end with delivery: the regulation changes and so does your activity, so the adaptation is kept alive with ongoing updates.

What the method puts in order

Initial analysis of your real activity
Record of Processing Activities (RoPA)
Information notices and privacy policy
Contracts with providers (data processors)
Security and breach protocol
Procedure for handling rights requests
Private platform and ongoing support
Updates in response to regulatory change

Free tool

Data protection self-check

Check in 5 minutes your overall adaptation level in personal data protection.

No email · Anonymous · No commitment

Start the test

Shall we start by analysing your company?

Tell us about your activity and an expert will tell you where to start and what your company needs to comply for real.

Request an initial analysis

Response within 24 h · +34 611 030 124

FAQ

Frequently asked questions about GDPR adaptation

What is GDPR adaptation for a company?

It is the process by which a company or self-employed professional puts in order everything that data protection law (GDPR and LOPDGDD) requires of it: knowing what data it processes, on what legal basis, documenting it (Record of Processing Activities, notices, contracts with providers), protecting the information with security measures, informing data subjects and knowing how to respond to their rights and to a breach. It is not signing a pack of documents: it is adapting the reality of the company to the regulation.

Is GDPR adaptation mandatory for the self-employed and SMEs?

Yes. The regulation applies to any company, self-employed professional or entity that processes personal data of customers, employees or providers, regardless of its size or sector. There is no minimum threshold below which it stops applying.

Where does a company start adapting to the GDPR?

With the inventory: identifying what data is processed, for what purpose and who accesses it. That map is what guides everything else (legal bases, documentation, security). At Certix, that initial analysis of your activity is the starting point of every project.

How long does it take a company to adapt to the GDPR?

It depends on the volume and complexity of the processing. The initial adaptation is a defined project, but compliance is not an end point: it is an ongoing, risk-based assessment that is reviewed whenever something relevant changes in the company.

Adapting well
starts with analysing.

No sales reps, no templates. A data protection expert analyses your activity and tells you what your company really needs.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →

Initial analysis · Response within 24 h · info@certix.es