Certix

Category

GDPR Compliance

Guides and resources on GDPR and LOPDGDD compliance for Spanish businesses: audits, impact assessments, records of processing activities and ongoing compliance.

Complying with the GDPR and LOPDGDD is not a one-off formality. It is a continuous system of analysis, documentation and review that every business or self-employed professional who processes personal data must keep active. The most common problem is not a lack of willingness: it is the belief that a generic privacy policy or a low-cost consultancy is sufficient.

Real compliance begins by understanding what data your organisation processes, for what purpose, for how long and on what legal basis. From there, the Record of Processing Activities is built, contracts with suppliers and processors are adapted, forms and legal notices are reviewed, and procedures are established to respond to data subject rights.

In this section you will find practical guides on data protection audits, impact assessments (DPIA), GDPR compliance and everything related to keeping your business in order effectively and without unnecessary technical jargon.

Articles on GDPR Compliance

Security 5 Jul 2026

What a security breach is and what to do step by step

What a security breach is (art. 4.12 GDPR) and the response protocol: detect, contain, assess the risk, always document it (art. 33.5), notify the AEPD within 72 hours where appropriate (art. 33) and communicate to the affected individuals if the risk is high (art. 34).

9 min Read
AEPD 6 Jul 2026

Data protection complaint: what to do if your company receives a claim before the AEPD

What it means for your company to receive a claim before the AEPD (art. 77 GDPR), how it arrives, the phases of the procedure and how to respond: having your documentation in order and demonstrating accountability (art. 5.2) is the best position.

9 min Read
AEPD 13 Jul 2026

Facilita RGPD: what the AEPD tool is and how far it goes

What Facilita_RGPD is, the AEPD's free tool for generating basic documentation for very low-risk processing, who it serves and its limits: when it is NOT enough and why relying on it outside its scope gives a false sense of compliance.

8 min Read
Video surveillance 3 Jul 2026

Security camera and video surveillance regulations: what the law requires in Spain

Legal framework of video surveillance in Spain: art. 22 LOPDGDD, principles of purpose and minimisation, prohibited areas, duty to inform with the AEPD model sign, image retention period and workplace video surveillance (art. 89 LOPDGDD).

10 min Read
DPIA 7 Jul 2026

Data Protection Impact Assessment (DPIA): what it is and when it is mandatory

What the DPIA is (art. 35 GDPR), when it is mandatory due to high risk, its phases, the role of the DPO and when a prior consultation with the AEPD is required (art. 36). Why the DPIA does not, on its own, legitimise a processing operation.

11 min Read
Security 8 Jul 2026

Information security policy: what it is and what it must cover

What an information security policy is and its relationship with the GDPR (art. 32 measures appropriate to the risk, integrity and confidentiality of art. 5(1)(f)). What it must cover: role-based access, encryption, backups, devices, teleworking and breach management.

10 min Read
Rights 14 Jul 2026

Access, rectification, erasure and objection: what each one is and how it is handled

A practical guide to the GDPR rights one by one: access (art. 15), rectification (art. 16), erasure or right to be forgotten (art. 17), objection (art. 21), restriction and portability. What each one allows, its limits and how your company responds on time.

11 min Read
Sensitive data 4 Jul 2026

Specially protected data: what the special categories of data are

What the special categories of data under art. 9 GDPR are (health, biometrics, ideology, trade union membership…), why their processing is prohibited as a general rule and what the dual-basis doctrine (art. 9.2 + art. 6) and the reinforced safeguards require.

10 min Read
Driving schools 2 Jun 2026

Driving school student data: files, exams and DGT communication

How a driving school manages the student's file under the GDPR: legal bases, communication with the DGT, theoretical and practical test results, retention periods and delivery of the certificate of fitness.

7 min Read
Driving schools 2 Jun 2026

GDPR at driving schools: basic information and mandatory documentation from the first student

Minimum proportionate documentation for the driving school under the GDPR: proportionate RoPA, registration information notice referencing the DGT, art. 28 contracts with technology providers and operational security policy.

7 min Read
Retail 2 Jun 2026

Video surveillance in shops: how to install cameras complying with the GDPR and LOPDGDD

How to install cameras in a physical shop complying with the GDPR and LOPDGDD: security purpose, allowed and prohibited areas, signage, one-month maximum retention and processing record.

8 min Read
Retail 2 Jun 2026

Loyalty programmes and customer cards: how to comply with the GDPR in retail

How to manage a loyalty programme with customer card under the GDPR: legal basis, express consent by purpose, commercial communications under the LSSICE and right to object.

7 min Read
Retail 2 Jun 2026

Retail employee data: payroll, time tracking and workplace video surveillance

How to manage the data of shop workers under the GDPR and the Spanish Workers' Statute: payroll, time tracking with PIN or card, workplace video surveillance under art. 89 LOPDGDD and retention periods.

8 min Read
Franchises 2 Jun 2026

Franchises and GDPR: who is controller and who is processor in a brand network

How GDPR figures are allocated between franchisor and franchisee: independent controllership, joint controllership under art. 26 GDPR, processor status under art. 28, joint and several liability towards the customer and recommended contractual models.

8 min Read
Franchises 2 Jun 2026

Transferring customer data between franchisees of the same brand: when it is lawful and when it is not

Transferring and accessing customer data between franchisees of the same brand: legal bases, joint controllership under art. 26 GDPR for common programmes, shared CRM, loyalty and franchisor communications.

8 min Read
Franchises 2 Jun 2026

DPO in franchise networks: shared appointment, individual appointment and allocation of responsibilities

DPO appointment obligation in franchises under art. 37 GDPR and art. 34 LOPDGDD: when the franchisor needs one, when the franchisee, the art. 37.2 GDPR rule for groups and the coordinated model with a common external DPO.

8 min Read
Startups 2 Jun 2026

GDPR from day 1 in a startup: minimum documentation before launching a product

Operational guide for founders: RoPA, privacy policy, DPAs with SaaS providers, international transfers with the Data Privacy Framework, impact assessment and continuous review cycle during the growth phase.

8 min Read
Freelance 2 Jun 2026

Freelancer and processor: the art. 28 GDPR contract your client expects (and the AEPD requires)

When a freelancer (web designer, developer, consultant) is a processor and what art. 28 GDPR contract should be signed with the client: minimum content, sub-processors, return of data.

7 min Read
Freelance 2 Jun 2026

Professional portfolio with client data: how to display your work without stepping on the GDPR

How to display projects done for clients in a professional portfolio: effective anonymisation of screenshots and data, consent for testimonials and image, and the right to use the work performed.

7 min Read
Freelance 2 Jun 2026

Developers, cookies and analytics: how to implement tracking without skipping GDPR

What a developer must do when implementing cookies, Google Analytics, Hotjar and marketing pixels: consent management platform, conditional loading, real granularity, inventory and evidence under art. 22.2 LSSICE and the AEPD guidance.

8 min Read
Hair & beauty 2 Jun 2026

Before/after photos on social media: how to capture client consent in hair and beauty salons

Publishing client before/after photos on social media in hair and beauty salons: express, specific and withdrawable consent under the GDPR and Organic Law 1/1982 on the right to own image.

7 min Read
Hair & beauty 2 Jun 2026

Online booking apps in hair and beauty salons: the processor role

Fresha, Treatwell, Booksy and other booking apps as the centre's processors: art. 28 GDPR processing agreement, international transfers, DPF, RoPA and client information notice.

7 min Read
HR 2 Jun 2026

CVs and recruitment processes: how long to keep candidate data and how to inform candidates correctly

Processing candidate data under the GDPR: legal basis of the process, reasonable retention (1-2 years with consent for future vacancies), information notice, data subject rights and clean erasure.

8 min Read
HR 2 Jun 2026

Workplace health data: occupational health surveillance, sickness absence and how far the employer can go

Workplace processing of health data under the GDPR and the Spanish Occupational Risk Prevention Act (Law 31/1995): occupational health surveillance, sickness notes, medical confidentiality, fitness assessment and the split of information between mutual, medical service and employer.

8 min Read
Transport & logistics 2 Jun 2026

GPS and geolocation in company vehicles: labour limits and GDPR

Geolocation of company vehicles under art. 90 LOPDGDD: prior information to workers and legal representatives, limits to working hours, disciplinary use and digital disconnection outside working time.

8 min Read
Gyms 2 Jun 2026

GDPR in gyms and sports centres: minimum documentation and member access control

GDPR compliance adapted to a gym: proportional records of processing activities, sign-up privacy notice, contracts with technology providers, compatible access control system (RFID, PIN, app, QR) and operational security policy.

8 min Read
Gyms 2 Jun 2026

Medical questionnaires in gyms: member health data and GDPR

How to legally handle the member’s medical questionnaire in a gym: dual legal basis (art. 6 and art. 9 GDPR), explicit consent, vital interests, secure custody, restricted access and retention periods.

7 min Read
Gyms 2 Jun 2026

CCTV in gyms: permitted areas, prohibited areas and GDPR

Where a gym can and cannot install cameras: permitted areas (entrance, reception), prohibited areas (changing rooms, showers, massage rooms), signage under art. 22 LOPDGDD and retention periods.

7 min Read
Architects 1 Jun 2026

Client data in architecture firms: project files, drawings and data protection

How an architecture firm manages client personal data: project files, signed drawings, current-state photographs, professional portfolio, neighbouring properties and final handover.

8 min Read
Architects 1 Jun 2026

Architect as processor: when Art. 28 GDPR applies

When an architect is controller and when processor: direct work with end client, technical subcontracting, collaborative BIM platforms and Art. 28 GDPR contracts.

8 min Read
Architects 1 Jun 2026

Retention of architecture projects and permits: statutory periods vs. the GDPR

How long to retain architecture projects: LOE, civil prescription, Commercial Code, General Tax Act and professional college rules against the GDPR storage-limitation principle.

8 min Read
Tech & SaaS 1 Jun 2026

SaaS and the GDPR: when your software acts as your clients' processor

How a SaaS company governs its role as processor under Art. 28 GDPR: a DPA with each client, the processor/controller duality, subprocessors, breaches and model training.

9 min Read
Small businesses 1 Jun 2026

GDPR for small businesses: what is mandatory and what is proportionate to your size

GDPR compliance tailored to the Spanish SME: proportionate RoPA, information clauses, contracts with providers, operational security policy and breach protocol. Without overdoing or falling short.

8 min Read
Small businesses 1 Jun 2026

Employees and GDPR in the SME: payroll, time recording and CCTV

How an SME handles its workforce data under the GDPR: information clause when signing the contract, time recording, workplace CCTV, employee offboarding and deletion of professional email.

8 min Read
Small businesses 1 Jun 2026

External IT provider as processor: the Art. 28 GDPR contract many SMEs lack

How to govern the external IT provider, the maintenance company or the cloud supplier under Art. 28 GDPR: mandatory contract, minimum content, remote access, home copies and provider switching.

8 min Read
Self-employed 1 Jun 2026

Self-employed professionals and GDPR: the minimum obligations every freelancer must meet

GDPR applied to a self-employed professional without employees: proportionate RoPA, information clause, website privacy policy and cookies, contracts with the gestoría and software, and reasonable retention of client data.

7 min Read
Self-employed 1 Jun 2026

Client data on the self-employed professional's phone: WhatsApp, contacts and legal management

How to comply with the GDPR from the professional phone of a freelancer: WhatsApp Business, separate contacts, work photos, device encryption, what to do if it is lost and deletion when a client relationship ends.

7 min Read
Self-employed 1 Jun 2026

Invoicing and retention of tax data for the self-employed: how long to keep them and how

Real retention periods for invoices and tax data of a self-employed professional under the Spanish Commercial Code, General Tax Act and Civil Code. Client tax ID, cloud copy, contract with the gestoría and cessation of activity.

7 min Read
Ecommerce 1 Jun 2026

Cookies and consent on an online store: how to comply with the GDPR and LSSICE

Cookie banner compliant with the AEPD Guide, GA4 integration, Meta and TikTok pixels, equal weight for accept and reject, consent expiry and accessible configuration link.

9 min Read
Ecommerce 1 Jun 2026

Ecommerce privacy policy: what it must include and how to draft it

Mandatory content of an online store's privacy policy: controller, purposes, legal bases, recipients, international transfers, retention periods, customer rights and ecommerce-specific obligations.

8 min Read
Real estate 1 Jun 2026

Data protection in a real estate agency: where to start

Minimum documentation for a real estate agency: legal bases for buyers, sellers and tenants, GDPR-compliant visit sheet, contracts with portals and information duty at first contact.

8 min Read
Accountancy & advisory 1 Jun 2026

Data protection in a gestoría or asesoría: where to start

Minimum documentation for a gestoría or asesoría: a RAT separating employment and tax matters, art. 28 RGPD contracts with each client, information clauses and the duty of professional secrecy.

8 min Read
Accountancy & advisory 1 Jun 2026

Daily good practices for a gestoría team to protect data

Routines for advisers and administrators: encrypted payslips, no WhatsApp for sick leave, paper destruction, access controls to the accounting software and custody of scanned IDs.

7 min Read
Accountancy & advisory 1 Jun 2026

Accounting software and ERP in a gestoría as processor: the supplier's obligations under the RGPD

The cloud ERP or invoicing platform processes data of client companies on behalf of the gestoría. What art. 28 RGPD contract it must sign, safeguards and return of historical tax data.

8 min Read
Travel agencies 1 Jun 2026

Data protection in a travel agency: where to start

Minimum documentation for a travel agency: RoPA, package travel files, passports, minors' data, processor contracts and the duty to inform.

8 min Read
Travel agencies 1 Jun 2026

Daily good practices for the team of a travel agency to protect data

Concrete routines for the team of an agency: passports and ID cards without keeping the image, secure ticket sending, individual GDS accesses, custody of files.

7 min Read
Rural houses 1 Jun 2026

Data protection in a rural guest house: where to start

Minimum data protection documentation for rural guest houses: traveller register, RoPA, information notices, processor contracts and communication to law enforcement authorities.

7 min Read
Rural houses 1 Jun 2026

Daily good practices of the rural guest house owner to protect data

Concrete routines to manage guest data in a small tourist accommodation: recording the ID without photocopying it, custody of registers, personal mobiles, destruction of contracts.

7 min Read
Rural houses 1 Jun 2026

Booking platforms (Booking, Airbnb) in a rural guest house: what to bear in mind under the GDPR

Booking, Airbnb and other portals: when they act as independent controllers and when as processors. What to require from the channel, what data you can keep and how to coordinate with the platform.

8 min Read
Hotels & accommodation 30 May 2026

Data protection in a hotel: where to start

Minimum data protection documentation for hotels and accommodation: traveller register, RoPA, information notices, processor contracts and communication to law enforcement authorities.

8 min Read
Hotels & accommodation 30 May 2026

Daily good practices of hotel staff to protect data

Concrete routines for reception, housekeeping, kitchen and administration: handling the ID/passport without photocopying it, custody of reports, communications, PMS passwords, video-surveillance and time recording.

8 min Read
Hotels & accommodation 30 May 2026

Your hotel PMS as processor: what to require from the provider under the GDPR

The PMS is the heart of the hotel and processes personal data on its behalf. Which art. 28 GDPR contract must be signed, which safeguards to require, access profiles, international transfers and data return upon migration.

8 min Read
Hospitality 30 May 2026

Data protection in a restaurant: where to start

Minimum data protection documentation to open or regularise a restaurant: RAT, legal notice, privacy policy, information clause, processor contracts. No scaremongering, step by step.

7 min Read
Hospitality 30 May 2026

Daily good practices for a restaurant team to protect data

Concrete routines for the front-of-house, kitchen and admin teams: TPV password management, role-based access, allergy data, WhatsApp communications, control of paper copies and CCTV.

8 min Read
Hospitality 30 May 2026

Booking software and TPV in a restaurant: the supplier's obligations under the RGPD

Your TPV and booking system process personal data on behalf of the restaurant. What processor contract (art. 28 RGPD) you must sign, what guarantees to require and what happens at the end of the service.

8 min Read
Compliance 22 May 2026

Data Protection Compliance: what it is and how to implement it

Data protection compliance integrates GDPR requirements as a continuous system in your organisation. What it includes, how it differs from an audit, and how to implement it.

6 min Read
Rights 12 Jul 2026

ARCO rights: what they are today and how your company must respond

What ARCO rights are (terminology from the old LOPD) and what they have become under the GDPR: access, rectification, erasure, restriction, portability and objection. Deadline, free of charge and how a company handles each request.

9 min Read
GDPR 27 Jun 2026

Record of Processing Activities (RoPA): what it is and how to do it

What the Record of Processing Activities under art. 30 GDPR is, who is required to keep it, what it must include and a practical example of a RoPA row ready to use.

8 min Read
GDPR 30 Jun 2026

Data processor: what it is and when you need one

What the data processor is under art. 28 GDPR, how it differs from the controller, when a supplier is one and what contract must be signed with it.

7 min Read

Frequently asked questions about gdpr compliance

What does GDPR compliance actually include for a business?

GDPR compliance includes: analysis of data processing activities, preparation of the Record of Processing Activities (RoPA), adaptation of the website and forms, Data Processing Agreements with processors, procedures for the exercise of ARCO-POL rights, technical and organisational security measures, and staff training. It is not a document — it is an operating system.

How often should compliance be reviewed?

The regulations do not specify a fixed frequency, but the AEPD recommends reviewing compliance at least once a year and whenever a significant change occurs: a new processing activity, new suppliers, changes to IT systems or regulatory amendments. A one-off audit without subsequent follow-up does not guarantee ongoing compliance.

Is a single data protection audit enough to be covered?

No. An audit diagnoses the current state and establishes an action plan, but compliance requires continuous implementation and maintenance. Organisations that commission an audit without follow-up tend to fall back into non-compliance within months, especially when they change suppliers, expand services or take on new employees.

Do you need to bring your business into GDPR compliance?

At Certix you will be attended by a data protection expert, with no sales teams involved.

INFORMACIÓN BÁSICA DE PROTECCIÓN DE DATOS: De conformidad con las normativas de Protección de Datos, le facilitamos la siguiente información del tratamiento: Responsable: Certificación y Gestión Normativa S.L.U. Finalidad: atender su solicitud y contactarle para ofrecerle la información solicitada. Derechos: acceso, rectificación, portabilidad, supresión, limitación y oposición, así como otros derechos detallados en la información adicional. + info: Puedes encontrar información más detallada en nuestra Política de privacidad.

Or tell us your full case →