Certix

News and resources on
data protection

Articles, guides and analysis from the Certix expert team.

Security 5 Jul 2026

What a security breach is and what to do step by step

What a security breach is (art. 4.12 GDPR) and the response protocol: detect, contain, assess the risk, always document it (art. 33.5), notify the AEPD within 72 hours where appropriate (art. 33) and communicate to the affected individuals if the risk is high (art. 34).

9 min Read
AEPD 6 Jul 2026

Data protection complaint: what to do if your company receives a claim before the AEPD

What it means for your company to receive a claim before the AEPD (art. 77 GDPR), how it arrives, the phases of the procedure and how to respond: having your documentation in order and demonstrating accountability (art. 5.2) is the best position.

9 min Read
AEPD 13 Jul 2026

Facilita RGPD: what the AEPD tool is and how far it goes

What Facilita_RGPD is, the AEPD's free tool for generating basic documentation for very low-risk processing, who it serves and its limits: when it is NOT enough and why relying on it outside its scope gives a false sense of compliance.

8 min Read
Video surveillance 3 Jul 2026

Security camera and video surveillance regulations: what the law requires in Spain

Legal framework of video surveillance in Spain: art. 22 LOPDGDD, principles of purpose and minimisation, prohibited areas, duty to inform with the AEPD model sign, image retention period and workplace video surveillance (art. 89 LOPDGDD).

10 min Read
DPIA 7 Jul 2026

Data Protection Impact Assessment (DPIA): what it is and when it is mandatory

What the DPIA is (art. 35 GDPR), when it is mandatory due to high risk, its phases, the role of the DPO and when a prior consultation with the AEPD is required (art. 36). Why the DPIA does not, on its own, legitimise a processing operation.

11 min Read
Security 8 Jul 2026

Information security policy: what it is and what it must cover

What an information security policy is and its relationship with the GDPR (art. 32 measures appropriate to the risk, integrity and confidentiality of art. 5(1)(f)). What it must cover: role-based access, encryption, backups, devices, teleworking and breach management.

10 min Read
Rights 14 Jul 2026

Access, rectification, erasure and objection: what each one is and how it is handled

A practical guide to the GDPR rights one by one: access (art. 15), rectification (art. 16), erasure or right to be forgotten (art. 17), objection (art. 21), restriction and portability. What each one allows, its limits and how your company responds on time.

11 min Read
Sensitive data 4 Jul 2026

Specially protected data: what the special categories of data are

What the special categories of data under art. 9 GDPR are (health, biometrics, ideology, trade union membership…), why their processing is prohibited as a general rule and what the dual-basis doctrine (art. 9.2 + art. 6) and the reinforced safeguards require.

10 min Read
GDPR 2 Jul 2026

Processing of personal data: disclosure, processor and international transfers

What processing is (art. 4.2 GDPR), the difference between disclosure to a third party and a data processor (art. 28), and the valid mechanisms for transfers outside the EEA: adequacy decision, standard contractual clauses and the Data Privacy Framework for the US.

12 min Read
GDPR 1 Jul 2026

Pseudonymisation and anonymisation of data: what they are and why they are not the same

The key difference between pseudonymisation (art. 4.5 GDPR, the data remain personal) and true anonymisation (outside the scope of the GDPR, recital 26). Why confusing them is a common mistake and how to use pseudonymisation as a security measure.

9 min Read
Driving schools 2 Jun 2026

Driving school student data: files, exams and DGT communication

How a driving school manages the student's file under the GDPR: legal bases, communication with the DGT, theoretical and practical test results, retention periods and delivery of the certificate of fitness.

7 min Read
Driving schools 2 Jun 2026

GDPR at driving schools: basic information and mandatory documentation from the first student

Minimum proportionate documentation for the driving school under the GDPR: proportionate RoPA, registration information notice referencing the DGT, art. 28 contracts with technology providers and operational security policy.

7 min Read

Do you need direct expert advice?

At Certix you will be attended by a data protection expert, with no sales teams involved.

INFORMACIÓN BÁSICA DE PROTECCIÓN DE DATOS: De conformidad con las normativas de Protección de Datos, le facilitamos la siguiente información del tratamiento: Responsable: Certificación y Gestión Normativa S.L.U. Finalidad: atender su solicitud y contactarle para ofrecerle la información solicitada. Derechos: acceso, rectificación, portabilidad, supresión, limitación y oposición, así como otros derechos detallados en la información adicional. + info: Puedes encontrar información más detallada en nuestra Política de privacidad.

Or tell us your full case →