Certix

Daily good practices for a gestoría team to protect data

Certix
Certix®
· 1 Jun 2026 · 7 min read

Informative article. It does not replace individualised professional advice.

In a gestoría or asesoría, data protection is decided more in the small daily gestures than in the formal documentation. The RAT may be drafted to the letter and the art. 28 contract signed with every client, but if payslips travel by unencrypted email, sick-leave certificates arrive via WhatsApp on the adviser's personal mobile or the billing list is left forgotten on the printer tray, everything else stops working.

This guide sets out operational routines for the daily work of a gestoría team — advisers, administrators, interns, reception. It is not a legal course: these are habits that bring order to the firm's work and, in the process, meet the requirements of the RGPD, the LOPDGDD and the sector rules.

Payslip dispatch: PDF encryption as a daily practice

The mass dispatch of monthly payslips by email is the routine with the highest exposure for a gestoría and, at the same time, the most frequent data-leak scenario in the sector. Payslips contain full salary information, Social Security number, withholdings, family situation, garnishments and, where applicable, maintenance payments. The operational routines are:

  • Encrypt every PDF with a password before attaching it. The password does not travel in the same email: it is communicated to the worker by SMS to the mobile, by phone call or via the corporate channel designated by the client company.
  • One email, one worker. Never send payslips in bulk with several recipients visible in "To" or "CC". If the sending tool allows individualised bulk dispatch (transactional mailing), that is better than BCC.
  • Verify the recipient before pressing send. The addresses auto-completed by the mail client are the usual cause of a payslip landing in the wrong inbox.
  • Preferred alternative: the worker's private area within the ERP, where each employee downloads their own payslip with their own login. This sharply reduces the risk of mis-sending.
  • Billing lists and salary summaries sent to the client company: equally encrypted or channelled through the private area. Never pasted into the body of the email.

Sick-leave certificates: corporate channel, not the adviser's WhatsApp

The temporary disability certificate, the return-to-work certificate, the permanent disability certificate and, in general, any communication about the health of a client's worker, is special category data (art. 9 RGPD). The operational flow must be kept under control:

  • Verified corporate channel for receipt: the adviser's corporate email, fax or postal mail to the firm's address, or the client's private area in the ERP. Not the personal WhatsApp of any team member.
  • Clear communication to the client company about the single channel for receipt, so that the client can pass it on to its workforce and reflect it in its own information clause.
  • If it arrives by the wrong channel (a worker sends the photo of the certificate to the adviser's personal WhatsApp), the routine is: record the certificate in the employment file within the software, delete the image from the personal mobile and remind the client company of the reference corporate channel.
  • Notice to the client's employee, through the client company, about who receives their health data: the gestoría as processor, the mutual insurers as independent controllers, the TGSS as the receiving administration.

Paper printouts: secure destruction

The sector prints more paper than it needs. Billing lists, payslip summaries, control sheets for submitted forms, copies of TC forms and drafts left on the printer tray are the visible face of a physical breach. The practical routine:

  • "Clean desk" policy at the end of the day. Anything not in use goes back into the locked cabinet.
  • Immediate pick-up from the printer. Ideally, configure the printer with PIN release so that documents only print when the adviser is in front of the machine. Avoids forgetfulness.
  • Cross-cut shredder at the office for small volumes and daily drafts.
  • Contract with a specialist confidential destruction company for larger volumes and periodic clear-outs, with a destruction certificate kept on file as evidence.
  • Locked container with a narrow slot for documentation pending destruction. Not the common paper bin.
  • Locked cabinets for active physical files. In an area not accessible to the public and reserved for the team.

Access to accounting software and the Sistema RED

The accounting software, the payroll ERP, the tax tool and the TGSS's Sistema RED are the operational doors of the firm. Their security rests on one clear rule: one account per adviser, never shared.

  • Individual user per adviser, with a strong personal password and, where the supplier allows, second-factor authentication.
  • Differentiated profiles: not every adviser needs to see every client or modify every form. Roles are tailored to actual functions (employment, tax, accounting, commercial, reception).
  • Sign out at the end of the day and automatic screen lock on inactivity. Essential in shared offices.
  • Immediate revocation when someone leaves the gestoría: on the day of departure, users are deactivated in the software, in RED, SILTRA, corporate email, certificates, the client's private area and any auxiliary tool. The account is not reused for the replacement; a new one is created.
  • Quarterly periodic review of the list of active users: there should be no zombie accounts belonging to people no longer at the firm.
  • Custody of personal digital certificates (FNMT, legal-entity representative): each adviser with their own certificate, never shared certificates in common folders.

Traceability — knowing which adviser opened which file and when — is a measure under art. 32 RGPD and forms part of the firm's security policy. Sharing credentials destroys that traceability and leaves the firm without defence against any incident.

IDs and documents of individuals: minimisation

In daily work, copies of the DNI arrive at the firm from self-employed clients, legal representatives, attorneys, company directors and, in some operations, employees of the client. The practical rule is to minimise (art. 5.1.c RGPD):

  • Record the data in the system (name, surnames, DNI/NIE, date of birth, nationality if relevant). That is the operational information.
  • Do not keep the scanned image of the DNI by default. Only where a rule or specific procedure requires a copy to be produced (incorporation of a company, notarial transaction, specific registration) is it kept for the duration of that procedure, in an encrypted folder with restricted access.
  • Subsequent deletion: once the use has finished, it is removed from the operational environment.
  • Never store photographs of DNIs on the team's personal mobiles, on local desktops without encryption, or in the firm's internal WhatsApp groups.

Telephone customer service: identity verification

The phone is a particularly vulnerable channel because it allows impersonation. Data are not handed over without a minimum of verification. The routines:

  • Identity verification before handing over data: full name, company's NIF and, depending on the sensitivity, an additional question that only the real client could answer (date of the last invoice, amount of the last form, number of employees).
  • Written protocol known by the entire team, including reception and interns.
  • Never disclose payslips, bank details, sick-leave dates or workforce information to a person who has not been identified with certainty. When in doubt, call back to a known number for the client, not the one calling in.
  • Discretion at the office: phone conversations with client data are not held out loud in passageways. Audio filters, a separate room or simply lowering the voice.

Breaches in third-party software: how to act

The sector's technology suppliers (ERP, accounting software, document platform, client's private area) are frequent targets of security incidents. When a supplier reports a breach affecting data of the gestoría's clients, the routines are:

  • Activate the internal breach protocol and record the incident (art. 33.5 RGPD): description, data affected, time of detection, measures taken.
  • Identify the gestoría's role in each affected flow: if the breach affects the workforce data of a client company, the gestoría acts as processor and must notify the client company without undue delay (art. 33.2 RGPD). The client company, as controller, decides on notification to the AEPD and to the data subjects.
  • If the breach affects own data (clients of the gestoría as individuals, own suppliers, firm staff), the gestoría is the controller and must assess notification to the AEPD (art. 33 RGPD) and, where appropriate, to the data subjects (art. 34 RGPD).
  • Coordination with the supplier to understand the actual scope, the corrective measures and the recovery timeline.
  • Do not forward the supplier's email with the list of affected parties to unauthorised recipients. Management is internal and, where appropriate, with the client company and the AEPD.

Time-tracking for the gestoría team

The time-tracking of the firm's own staff can be implemented through several operational alternatives:

  • Individual PIN codes per adviser on a clocking terminal.
  • RFID proximity cards or key fobs.
  • Corporate mobile app with workplace geolocation, where there is operational justification.
  • Workstation login as a time-tracking mechanism when all work is carried out at the computer.

"En una gestoría, casi todo el riesgo de protección de datos se neutraliza con tres rutinas: cifrar los PDFs de nóminas, no aceptar partes de baja por el WhatsApp personal y revisar trimestralmente quién tiene acceso al software. El resto del cumplimiento se sostiene casi solo cuando esas tres están bien hechas."

Mario P. Talamillo · Managing Partner, Certix®

If you run a gestoría or asesoría and want to review your data protection documentation, at Certix we work specifically with gestorías and asesorías. No salespeople: from the very first contact, you will speak with a specialist.


This content is for general guidance and information purposes only; it does not in any case constitute specialised legal advice. Regional sectoral rules may extend or modify the deadlines and requirements of national legislation. The application of the rules to each specific case requires individual analysis.

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →