GDPR adaptation for businesses:
a method, not a pack of PDFs
Adapting your company to the GDPR is not signing a few generic documents. It is analysing what you really do and ordering it, step by step. This is the method we follow with every client.
9
steps of the method
Art. 5.2
GDPR — proactive accountability
0€
initial analysis of your activity
GDPR + LOPDGDD
applicable framework in Spain
What it is
What is GDPR adaptation for a company?
Adapting a company to the GDPR and the LOPDGDD means putting in order everything the regulation requires: knowing what data you process, on what legal basis, documenting it, protecting it, informing people and knowing how to respond to their rights and to an incident.
Most of the market solves this by handing over a pack of generic documents that does not match what the company actually does. Signing that paperwork is not complying: it is having a folder full of PDFs that would not hold up under review. Certix does not work that way.
A real adaptation follows a method. The one you see below is the same one we apply with every client, and each step links to the guide where we explain it in detail.
Your real activity
We start from what you actually do, not from a standard model.
An ordered method
9 steps with a legal basis, from the inventory to the breach protocol.
Ongoing compliance
Adaptation does not end: it is reviewed when something relevant changes.
The method
How to adapt your company to the GDPR, step by step
Each step links to the full guide where we explain it in detail. It is the journey we make with every client.
Proactive accountability
The starting point is not filling in paperwork: it is accepting that the company (the controller) must be able to demonstrate that it complies, at all times (art. 5.2 and 24 GDPR). Everything else is ordered around the principles of art. 5.
What data protection isData inventory
You cannot protect what you do not know. You identify which data you process and of what type: basic identifying data versus the special categories of art. 9 GDPR (health, biometrics, ideology…), which require reinforced safeguards.
Specially protected dataLegal bases
Every processing activity needs a legal basis under art. 6 GDPR (contract, legal obligation, consent, legitimate interest…). If there is art. 9 data, a dual basis with an art. 9.2 exception is required.
Processing, disclosure and transfersDocumentation and RoPA
The Record of Processing Activities (art. 30 GDPR) is the map of everything above. It comes with the information notices and the processing agreements with each provider that accesses data (art. 28 GDPR).
Record of Processing Activities (RoPA)Security and risks
Technical and organisational measures proportionate to the risk (art. 32 GDPR): access control, encryption, backups, protocols. When a processing activity may entail a high risk, a Data Protection Impact Assessment (art. 35 GDPR) is required.
Information security policyDuty to inform
The data subject has the right to know what is done with their data, and the company the obligation to inform them clearly and in advance (art. 13 and 14 GDPR). This takes shape in the information notices and the website privacy policy.
Your website privacy policyData subjects' rights
A free and timely procedure to handle access, rectification, erasure, objection, restriction and portability (arts. 15-22 GDPR). Having them is not enough: you have to know how to respond to them.
Access, rectification, erasure…Data Protection Officer
Some organisations must appoint a DPO (art. 37 GDPR, extended by art. 34 LOPDGDD). It is not universal: it depends on the type and scale of the processing. The initial analysis determines whether it applies in your case.
Data Protection OfficerBreach protocol
Zero risk does not exist. Maturity is measured by the reaction: document every breach, notify the AEPD within 72 hours where appropriate (art. 33) and communicate to the affected individuals if the risk is high (art. 34).
What to do in a breachWhy Certix
We analyse. We don't hand out templates.
Most of the market analyses nothing. It copies, pastes, charges and disappears. The result is a company with documents that do not reflect its activity and that are useless when a complaint arrives.
Our work starts by understanding what your company does. From there we order each step of the method around your reality, with a private documentary management platform and ongoing support. No sales reps in between: you are looked after by someone who understands the regulation.
And it does not end with delivery: the regulation changes and so does your activity, so the adaptation is kept alive with ongoing updates.
What the method puts in order
Free tool
Data protection self-check
Check in 5 minutes your overall adaptation level in personal data protection.
No email · Anonymous · No commitment
Shall we start by analysing your company?
Tell us about your activity and an expert will tell you where to start and what your company needs to comply for real.
Request an initial analysisResponse within 24 h · +34 611 030 124
FAQ
Frequently asked questions about GDPR adaptation
What is GDPR adaptation for a company?
It is the process by which a company or self-employed professional puts in order everything that data protection law (GDPR and LOPDGDD) requires of it: knowing what data it processes, on what legal basis, documenting it (Record of Processing Activities, notices, contracts with providers), protecting the information with security measures, informing data subjects and knowing how to respond to their rights and to a breach. It is not signing a pack of documents: it is adapting the reality of the company to the regulation.
Is GDPR adaptation mandatory for the self-employed and SMEs?
Yes. The regulation applies to any company, self-employed professional or entity that processes personal data of customers, employees or providers, regardless of its size or sector. There is no minimum threshold below which it stops applying.
Where does a company start adapting to the GDPR?
With the inventory: identifying what data is processed, for what purpose and who accesses it. That map is what guides everything else (legal bases, documentation, security). At Certix, that initial analysis of your activity is the starting point of every project.
How long does it take a company to adapt to the GDPR?
It depends on the volume and complexity of the processing. The initial adaptation is a defined project, but compliance is not an end point: it is an ongoing, risk-based assessment that is reviewed whenever something relevant changes in the company.
Adapting well
starts with analysing.
No sales reps, no templates. A data protection expert analyses your activity and tells you what your company really needs.
Initial analysis · Response within 24 h · info@certix.es