News and resources on
data protection
Articles, guides and analysis from the Certix expert team.
What a security breach is and what to do step by step
What a security breach is (art. 4.12 GDPR) and the response protocol: detect, contain, assess the risk, always document it (art. 33.5), notify the AEPD within 72 hours where appropriate (art. 33) and communicate to the affected individuals if the risk is high (art. 34).
Data protection complaint: what to do if your company receives a claim before the AEPD
What it means for your company to receive a claim before the AEPD (art. 77 GDPR), how it arrives, the phases of the procedure and how to respond: having your documentation in order and demonstrating accountability (art. 5.2) is the best position.
Facilita RGPD: what the AEPD tool is and how far it goes
What Facilita_RGPD is, the AEPD's free tool for generating basic documentation for very low-risk processing, who it serves and its limits: when it is NOT enough and why relying on it outside its scope gives a false sense of compliance.
Security camera and video surveillance regulations: what the law requires in Spain
Legal framework of video surveillance in Spain: art. 22 LOPDGDD, principles of purpose and minimisation, prohibited areas, duty to inform with the AEPD model sign, image retention period and workplace video surveillance (art. 89 LOPDGDD).
Data Protection Impact Assessment (DPIA): what it is and when it is mandatory
What the DPIA is (art. 35 GDPR), when it is mandatory due to high risk, its phases, the role of the DPO and when a prior consultation with the AEPD is required (art. 36). Why the DPIA does not, on its own, legitimise a processing operation.
Information security policy: what it is and what it must cover
What an information security policy is and its relationship with the GDPR (art. 32 measures appropriate to the risk, integrity and confidentiality of art. 5(1)(f)). What it must cover: role-based access, encryption, backups, devices, teleworking and breach management.
Access, rectification, erasure and objection: what each one is and how it is handled
A practical guide to the GDPR rights one by one: access (art. 15), rectification (art. 16), erasure or right to be forgotten (art. 17), objection (art. 21), restriction and portability. What each one allows, its limits and how your company responds on time.
Specially protected data: what the special categories of data are
What the special categories of data under art. 9 GDPR are (health, biometrics, ideology, trade union membership…), why their processing is prohibited as a general rule and what the dual-basis doctrine (art. 9.2 + art. 6) and the reinforced safeguards require.
Processing of personal data: disclosure, processor and international transfers
What processing is (art. 4.2 GDPR), the difference between disclosure to a third party and a data processor (art. 28), and the valid mechanisms for transfers outside the EEA: adequacy decision, standard contractual clauses and the Data Privacy Framework for the US.
Pseudonymisation and anonymisation of data: what they are and why they are not the same
The key difference between pseudonymisation (art. 4.5 GDPR, the data remain personal) and true anonymisation (outside the scope of the GDPR, recital 26). Why confusing them is a common mistake and how to use pseudonymisation as a security measure.
Driving school student data: files, exams and DGT communication
How a driving school manages the student's file under the GDPR: legal bases, communication with the DGT, theoretical and practical test results, retention periods and delivery of the certificate of fitness.
GDPR at driving schools: basic information and mandatory documentation from the first student
Minimum proportionate documentation for the driving school under the GDPR: proportionate RoPA, registration information notice referencing the DGT, art. 28 contracts with technology providers and operational security policy.
Do you need direct expert advice?
At Certix you will be attended by a data protection expert, with no sales teams involved.