Category
GDPR Compliance
Guides and resources on GDPR and LOPDGDD compliance for Spanish businesses: audits, impact assessments, records of processing activities and ongoing compliance.
Complying with the GDPR and LOPDGDD is not a one-off formality. It is a continuous system of analysis, documentation and review that every business or self-employed professional who processes personal data must keep active. The most common problem is not a lack of willingness: it is the belief that a generic privacy policy or a low-cost consultancy is sufficient.
Real compliance begins by understanding what data your organisation processes, for what purpose, for how long and on what legal basis. From there, the Record of Processing Activities is built, contracts with suppliers and processors are adapted, forms and legal notices are reviewed, and procedures are established to respond to data subject rights.
In this section you will find practical guides on data protection audits, impact assessments (DPIA), GDPR compliance and everything related to keeping your business in order effectively and without unnecessary technical jargon.
Articles on GDPR Compliance
What a security breach is and what to do step by step
What a security breach is (art. 4.12 GDPR) and the response protocol: detect, contain, assess the risk, always document it (art. 33.5), notify the AEPD within 72 hours where appropriate (art. 33) and communicate to the affected individuals if the risk is high (art. 34).
Data protection complaint: what to do if your company receives a claim before the AEPD
What it means for your company to receive a claim before the AEPD (art. 77 GDPR), how it arrives, the phases of the procedure and how to respond: having your documentation in order and demonstrating accountability (art. 5.2) is the best position.
Facilita RGPD: what the AEPD tool is and how far it goes
What Facilita_RGPD is, the AEPD's free tool for generating basic documentation for very low-risk processing, who it serves and its limits: when it is NOT enough and why relying on it outside its scope gives a false sense of compliance.
Security camera and video surveillance regulations: what the law requires in Spain
Legal framework of video surveillance in Spain: art. 22 LOPDGDD, principles of purpose and minimisation, prohibited areas, duty to inform with the AEPD model sign, image retention period and workplace video surveillance (art. 89 LOPDGDD).
Data Protection Impact Assessment (DPIA): what it is and when it is mandatory
What the DPIA is (art. 35 GDPR), when it is mandatory due to high risk, its phases, the role of the DPO and when a prior consultation with the AEPD is required (art. 36). Why the DPIA does not, on its own, legitimise a processing operation.
Information security policy: what it is and what it must cover
What an information security policy is and its relationship with the GDPR (art. 32 measures appropriate to the risk, integrity and confidentiality of art. 5(1)(f)). What it must cover: role-based access, encryption, backups, devices, teleworking and breach management.
Access, rectification, erasure and objection: what each one is and how it is handled
A practical guide to the GDPR rights one by one: access (art. 15), rectification (art. 16), erasure or right to be forgotten (art. 17), objection (art. 21), restriction and portability. What each one allows, its limits and how your company responds on time.
Specially protected data: what the special categories of data are
What the special categories of data under art. 9 GDPR are (health, biometrics, ideology, trade union membership…), why their processing is prohibited as a general rule and what the dual-basis doctrine (art. 9.2 + art. 6) and the reinforced safeguards require.
Driving school student data: files, exams and DGT communication
How a driving school manages the student's file under the GDPR: legal bases, communication with the DGT, theoretical and practical test results, retention periods and delivery of the certificate of fitness.
GDPR at driving schools: basic information and mandatory documentation from the first student
Minimum proportionate documentation for the driving school under the GDPR: proportionate RoPA, registration information notice referencing the DGT, art. 28 contracts with technology providers and operational security policy.
Video surveillance in shops: how to install cameras complying with the GDPR and LOPDGDD
How to install cameras in a physical shop complying with the GDPR and LOPDGDD: security purpose, allowed and prohibited areas, signage, one-month maximum retention and processing record.
Loyalty programmes and customer cards: how to comply with the GDPR in retail
How to manage a loyalty programme with customer card under the GDPR: legal basis, express consent by purpose, commercial communications under the LSSICE and right to object.
Retail employee data: payroll, time tracking and workplace video surveillance
How to manage the data of shop workers under the GDPR and the Spanish Workers' Statute: payroll, time tracking with PIN or card, workplace video surveillance under art. 89 LOPDGDD and retention periods.
Franchises and GDPR: who is controller and who is processor in a brand network
How GDPR figures are allocated between franchisor and franchisee: independent controllership, joint controllership under art. 26 GDPR, processor status under art. 28, joint and several liability towards the customer and recommended contractual models.
Transferring customer data between franchisees of the same brand: when it is lawful and when it is not
Transferring and accessing customer data between franchisees of the same brand: legal bases, joint controllership under art. 26 GDPR for common programmes, shared CRM, loyalty and franchisor communications.
DPO in franchise networks: shared appointment, individual appointment and allocation of responsibilities
DPO appointment obligation in franchises under art. 37 GDPR and art. 34 LOPDGDD: when the franchisor needs one, when the franchisee, the art. 37.2 GDPR rule for groups and the coordinated model with a common external DPO.
GDPR from day 1 in a startup: minimum documentation before launching a product
Operational guide for founders: RoPA, privacy policy, DPAs with SaaS providers, international transfers with the Data Privacy Framework, impact assessment and continuous review cycle during the growth phase.
Freelancer and processor: the art. 28 GDPR contract your client expects (and the AEPD requires)
When a freelancer (web designer, developer, consultant) is a processor and what art. 28 GDPR contract should be signed with the client: minimum content, sub-processors, return of data.
Professional portfolio with client data: how to display your work without stepping on the GDPR
How to display projects done for clients in a professional portfolio: effective anonymisation of screenshots and data, consent for testimonials and image, and the right to use the work performed.
Developers, cookies and analytics: how to implement tracking without skipping GDPR
What a developer must do when implementing cookies, Google Analytics, Hotjar and marketing pixels: consent management platform, conditional loading, real granularity, inventory and evidence under art. 22.2 LSSICE and the AEPD guidance.
Before/after photos on social media: how to capture client consent in hair and beauty salons
Publishing client before/after photos on social media in hair and beauty salons: express, specific and withdrawable consent under the GDPR and Organic Law 1/1982 on the right to own image.
Online booking apps in hair and beauty salons: the processor role
Fresha, Treatwell, Booksy and other booking apps as the centre's processors: art. 28 GDPR processing agreement, international transfers, DPF, RoPA and client information notice.
CVs and recruitment processes: how long to keep candidate data and how to inform candidates correctly
Processing candidate data under the GDPR: legal basis of the process, reasonable retention (1-2 years with consent for future vacancies), information notice, data subject rights and clean erasure.
Workplace health data: occupational health surveillance, sickness absence and how far the employer can go
Workplace processing of health data under the GDPR and the Spanish Occupational Risk Prevention Act (Law 31/1995): occupational health surveillance, sickness notes, medical confidentiality, fitness assessment and the split of information between mutual, medical service and employer.
GPS and geolocation in company vehicles: labour limits and GDPR
Geolocation of company vehicles under art. 90 LOPDGDD: prior information to workers and legal representatives, limits to working hours, disciplinary use and digital disconnection outside working time.
GDPR in gyms and sports centres: minimum documentation and member access control
GDPR compliance adapted to a gym: proportional records of processing activities, sign-up privacy notice, contracts with technology providers, compatible access control system (RFID, PIN, app, QR) and operational security policy.
Medical questionnaires in gyms: member health data and GDPR
How to legally handle the member’s medical questionnaire in a gym: dual legal basis (art. 6 and art. 9 GDPR), explicit consent, vital interests, secure custody, restricted access and retention periods.
CCTV in gyms: permitted areas, prohibited areas and GDPR
Where a gym can and cannot install cameras: permitted areas (entrance, reception), prohibited areas (changing rooms, showers, massage rooms), signage under art. 22 LOPDGDD and retention periods.
Client data in architecture firms: project files, drawings and data protection
How an architecture firm manages client personal data: project files, signed drawings, current-state photographs, professional portfolio, neighbouring properties and final handover.
Architect as processor: when Art. 28 GDPR applies
When an architect is controller and when processor: direct work with end client, technical subcontracting, collaborative BIM platforms and Art. 28 GDPR contracts.
Retention of architecture projects and permits: statutory periods vs. the GDPR
How long to retain architecture projects: LOE, civil prescription, Commercial Code, General Tax Act and professional college rules against the GDPR storage-limitation principle.
SaaS and the GDPR: when your software acts as your clients' processor
How a SaaS company governs its role as processor under Art. 28 GDPR: a DPA with each client, the processor/controller duality, subprocessors, breaches and model training.
GDPR for small businesses: what is mandatory and what is proportionate to your size
GDPR compliance tailored to the Spanish SME: proportionate RoPA, information clauses, contracts with providers, operational security policy and breach protocol. Without overdoing or falling short.
Employees and GDPR in the SME: payroll, time recording and CCTV
How an SME handles its workforce data under the GDPR: information clause when signing the contract, time recording, workplace CCTV, employee offboarding and deletion of professional email.
External IT provider as processor: the Art. 28 GDPR contract many SMEs lack
How to govern the external IT provider, the maintenance company or the cloud supplier under Art. 28 GDPR: mandatory contract, minimum content, remote access, home copies and provider switching.
Self-employed professionals and GDPR: the minimum obligations every freelancer must meet
GDPR applied to a self-employed professional without employees: proportionate RoPA, information clause, website privacy policy and cookies, contracts with the gestoría and software, and reasonable retention of client data.
Client data on the self-employed professional's phone: WhatsApp, contacts and legal management
How to comply with the GDPR from the professional phone of a freelancer: WhatsApp Business, separate contacts, work photos, device encryption, what to do if it is lost and deletion when a client relationship ends.
Invoicing and retention of tax data for the self-employed: how long to keep them and how
Real retention periods for invoices and tax data of a self-employed professional under the Spanish Commercial Code, General Tax Act and Civil Code. Client tax ID, cloud copy, contract with the gestoría and cessation of activity.
Cookies and consent on an online store: how to comply with the GDPR and LSSICE
Cookie banner compliant with the AEPD Guide, GA4 integration, Meta and TikTok pixels, equal weight for accept and reject, consent expiry and accessible configuration link.
Ecommerce privacy policy: what it must include and how to draft it
Mandatory content of an online store's privacy policy: controller, purposes, legal bases, recipients, international transfers, retention periods, customer rights and ecommerce-specific obligations.
Data protection in a real estate agency: where to start
Minimum documentation for a real estate agency: legal bases for buyers, sellers and tenants, GDPR-compliant visit sheet, contracts with portals and information duty at first contact.
Data protection in a gestoría or asesoría: where to start
Minimum documentation for a gestoría or asesoría: a RAT separating employment and tax matters, art. 28 RGPD contracts with each client, information clauses and the duty of professional secrecy.
Daily good practices for a gestoría team to protect data
Routines for advisers and administrators: encrypted payslips, no WhatsApp for sick leave, paper destruction, access controls to the accounting software and custody of scanned IDs.
Accounting software and ERP in a gestoría as processor: the supplier's obligations under the RGPD
The cloud ERP or invoicing platform processes data of client companies on behalf of the gestoría. What art. 28 RGPD contract it must sign, safeguards and return of historical tax data.
Data protection in a travel agency: where to start
Minimum documentation for a travel agency: RoPA, package travel files, passports, minors' data, processor contracts and the duty to inform.
Daily good practices for the team of a travel agency to protect data
Concrete routines for the team of an agency: passports and ID cards without keeping the image, secure ticket sending, individual GDS accesses, custody of files.
Data protection in a rural guest house: where to start
Minimum data protection documentation for rural guest houses: traveller register, RoPA, information notices, processor contracts and communication to law enforcement authorities.
Daily good practices of the rural guest house owner to protect data
Concrete routines to manage guest data in a small tourist accommodation: recording the ID without photocopying it, custody of registers, personal mobiles, destruction of contracts.
Booking platforms (Booking, Airbnb) in a rural guest house: what to bear in mind under the GDPR
Booking, Airbnb and other portals: when they act as independent controllers and when as processors. What to require from the channel, what data you can keep and how to coordinate with the platform.
Data protection in a hotel: where to start
Minimum data protection documentation for hotels and accommodation: traveller register, RoPA, information notices, processor contracts and communication to law enforcement authorities.
Daily good practices of hotel staff to protect data
Concrete routines for reception, housekeeping, kitchen and administration: handling the ID/passport without photocopying it, custody of reports, communications, PMS passwords, video-surveillance and time recording.
Your hotel PMS as processor: what to require from the provider under the GDPR
The PMS is the heart of the hotel and processes personal data on its behalf. Which art. 28 GDPR contract must be signed, which safeguards to require, access profiles, international transfers and data return upon migration.
Data protection in a restaurant: where to start
Minimum data protection documentation to open or regularise a restaurant: RAT, legal notice, privacy policy, information clause, processor contracts. No scaremongering, step by step.
Daily good practices for a restaurant team to protect data
Concrete routines for the front-of-house, kitchen and admin teams: TPV password management, role-based access, allergy data, WhatsApp communications, control of paper copies and CCTV.
Booking software and TPV in a restaurant: the supplier's obligations under the RGPD
Your TPV and booking system process personal data on behalf of the restaurant. What processor contract (art. 28 RGPD) you must sign, what guarantees to require and what happens at the end of the service.
Data Protection Compliance: what it is and how to implement it
Data protection compliance integrates GDPR requirements as a continuous system in your organisation. What it includes, how it differs from an audit, and how to implement it.
ARCO rights: what they are today and how your company must respond
What ARCO rights are (terminology from the old LOPD) and what they have become under the GDPR: access, rectification, erasure, restriction, portability and objection. Deadline, free of charge and how a company handles each request.
Record of Processing Activities (RoPA): what it is and how to do it
What the Record of Processing Activities under art. 30 GDPR is, who is required to keep it, what it must include and a practical example of a RoPA row ready to use.
Data processor: what it is and when you need one
What the data processor is under art. 28 GDPR, how it differs from the controller, when a supplier is one and what contract must be signed with it.
Frequently asked questions about gdpr compliance
What does GDPR compliance actually include for a business?
GDPR compliance includes: analysis of data processing activities, preparation of the Record of Processing Activities (RoPA), adaptation of the website and forms, Data Processing Agreements with processors, procedures for the exercise of ARCO-POL rights, technical and organisational security measures, and staff training. It is not a document — it is an operating system.
How often should compliance be reviewed?
The regulations do not specify a fixed frequency, but the AEPD recommends reviewing compliance at least once a year and whenever a significant change occurs: a new processing activity, new suppliers, changes to IT systems or regulatory amendments. A one-off audit without subsequent follow-up does not guarantee ongoing compliance.
Is a single data protection audit enough to be covered?
No. An audit diagnoses the current state and establishes an action plan, but compliance requires continuous implementation and maintenance. Organisations that commission an audit without follow-up tend to fall back into non-compliance within months, especially when they change suppliers, expand services or take on new employees.
Do you need to bring your business into GDPR compliance?
At Certix you will be attended by a data protection expert, with no sales teams involved.