Certix

Data protection compliance: what it is and how to implement it in your organisation

Certix
Certix®
· 22 May 2026 · 6 min read

Informative article. It does not replace individualised professional advice.

When a company does no more than "have a privacy policy" and little else, it does not have data protection compliance — it has a document. Compliance is something else entirely. It is the set of processes, controls, responsibilities and documentation that ensure the processing of personal data complies with the GDPR and the LOPDGDD on a continuous basis, not just at a single point in time. This article explains exactly what it is, how it differs from other instruments, and how to implement it.

What is data protection compliance?

Data protection compliance is the system by which an organisation integrates regulatory compliance in the area of privacy into its day-to-day management. It is not a one-off project or a set of documents: it is an ongoing function that ensures the company processes personal data in accordance with the law at all times, adapts its procedures when legislation or its own operations change, and can demonstrate this to any party — clients, auditors or the AEPD.

The term compliance originates in the Anglo-Saxon world and is increasingly used in Spain in regulatory contexts: criminal compliance, employment compliance, fiscal compliance. In data protection, the concept is equivalent: an active compliance system that goes beyond mere initial adaptation.

The GDPR implicitly incorporates this approach in the principle of accountability (art. 5.2): the controller must not only comply with the principles of the regulation, but must be able to demonstrate that compliance. Such demonstration requires documentation, procedures and periodic review — the three pillars of any compliance system.

"Compliance is not a project that gets closed out. It is a way of working. The companies that understand this are the ones that never get nasty surprises."

Mario P. Talamillo · Managing Partner, Certix®

The difference between compliance, auditing and GDPR adaptation

The three concepts are related but are not the same. Confusing them leads to companies that believe they are protected when in reality they have only completed an initial step.

  • GDPR adaptation is the process of achieving initial conformity: drawing up the Record of Processing Activities (RoPA), drafting privacy policies, signing contracts with processors, and reviewing legal bases. It is a project with a beginning and an end. Many companies do it once and never review anything again. This is not compliance.
  • Data protection auditing is a periodic, risk-based review of the state of compliance. It analyses whether processing activities remain compliant, whether documentation is up to date, and whether new gaps have emerged. Auditing is a component of compliance, not its equivalent. A company that only conducts ad-hoc audits without continuous interim management does not have compliance.
  • Data protection compliance is the system that encompasses both of the above: it includes initial adaptation, incorporates periodic audits, and — in between — keeps active the procedures for responding to data subject rights requests, managing incidents, reviewing new suppliers and training staff. It is a continuous function, not an event.

The most practically relevant difference: a company with compliance detects and corrects a deficiency before it becomes a problem. A company that only completed initial adaptation discovers it when an inspection arrives or a complaint is filed.

What a privacy compliance programme includes

A robust data protection compliance programme comprises the following elements:

  • A living Record of Processing Activities (RoPA). Not an archived document, but a register that is updated every time the company introduces a new processing activity, a new supplier, or changes the purpose of an existing processing activity.
  • Legal basis management. A procedure for reviewing that each processing activity has a valid legal basis and that the consents obtained remain compliant (particularly relevant for email marketing and cookies).
  • Up-to-date contracts with data processors. A process for identifying new suppliers with access to personal data and ensuring they sign the Data Processing Agreement (DPA) before the service commences, not after the fact.
  • Data subject rights channel. A documented procedure for receiving, handling and responding to requests for access, rectification, erasure, objection and portability within the one-month period required by the GDPR.
  • Data breach management protocol. A process for detecting, recording and notifying incidents to the AEPD within 72 hours and, where applicable, to the individuals affected.
  • Training and awareness plan. An ongoing training programme for employees with access to personal data, with a record of participation. Training is not an annual event: it is a recurring function.
  • Periodic compliance review. The periodic review is the system's control mechanism: it verifies that procedures are working and that documentation remains valid in light of regulatory and operational changes.
  • Data Protection Officer (DPO). In organisations where a DPO is mandatory or advisable, their supervisory function is a core part of compliance. The external DPO takes on the ongoing supervisory function without the need to bring a full-time internal resource on board.

Compliance and data protection in medium-sized and large companies

Data protection compliance is relevant to any company that processes personal data, but its complexity and strategic impact increase significantly in medium-sized and large organisations. In these contexts, needs arise that go beyond those of a standard SME:

Distributed organisational structure. Companies with multiple sites, branches or subsidiaries must manage compliance in a coordinated manner, preventing each unit from operating autonomously without regulatory coherence. This requires group-level internal policies and centralised supervisory mechanisms.

High-risk processing activities requiring a DPIA. Medium-sized and large companies are more likely to operate CCTV systems, customer behaviour analytics platforms or AI tools with effects on individuals. All of these processing activities may require a Data Protection Impact Assessment (DPIA). Particular attention is warranted for workplace biometrics: access control or attendance monitoring using fingerprints or facial recognition in the employment context is subject to very severe restrictions according to the AEPD's established position (Report 0023/2023); in the absence of a statutory provision explicitly enabling it, this processing activity generally lacks a valid legal basis, and a DPIA does not remedy that absence.

Regulated sectors. Financial institutions, insurers, healthcare providers, temporary employment agencies and information society service providers have additional obligations under the LOPDGDD. Compliance in these sectors must integrate both the GDPR and the relevant sector-specific legislation.

International data transfers. Companies using SaaS tools with servers outside the EEA — virtually any company using Google Workspace, Microsoft 365, Salesforce or HubSpot — must verify the legal safeguards for those transfers. The primary mechanism for US-based providers is currently the Data Privacy Framework (DPF); for other countries, Standard Contractual Clauses (SCCs) or other mechanisms under art. 46 GDPR apply. The validity of these mechanisms must be verified periodically. This is one of the areas of compliance that is generating the most sanctions in Europe.

Potential mandatory DPO requirement. For certain organisations in sectors such as healthcare, education, financial services or public administration, art. 37 GDPR and art. 34 LOPDGDD may require the designation of a Data Protection Officer. The precise application depends on the specific circumstances of each organisation; each case must be analysed individually. The absence of a DPO where one is required may constitute an infringement.

How to implement data protection compliance step by step

The implementation of a data protection compliance system follows a logical sequence from diagnosis to continuous maintenance:

Step 1 — Situation diagnosis (gap analysis). Before implementing anything, it is necessary to know where the company stands. An initial audit identifies existing processing activities, compliance gaps and priority risks. Without this starting point, implementation is blind.

Step 2 — Drawing up or updating the RoPA. The Record of Processing Activities is the backbone of the system. It must accurately reflect all processing activities, their purposes, legal bases, data categories, recipients and retention periods.

Step 3 — Review and validation of legal bases. Each processing activity requires a valid legal basis. In many cases, companies discover at this stage that they are processing data without a sufficient legal basis, or that the consents obtained do not meet GDPR requirements.

Step 4 — Documentation: policies, notices and contracts. Drafting or updating privacy policies, legal notices, information clauses in forms, and DPA contracts with all data processors. This documentation must be consistent and reflect the company's actual operational reality.

Step 5 — Implementation of security measures. Defining and documenting the technical and organisational measures proportionate to the risk of each processing activity: access controls, encryption, backups, password management, network segmentation.

Step 6 — Staff training. Employees with access to personal data must be aware of their obligations. Initial training is supplemented with periodic updates and documented in the compliance file.

Step 7 — Activation of operational procedures. Launching the data subject rights channel, the breach management protocol and the process for reviewing new suppliers. Without active operational procedures, documentation is merely paper.

Step 8 — Maintenance and continuous improvement. Periodic reviews, scheduled audits and updates in response to regulatory, technological or business changes. This is the phase that distinguishes genuine compliance from one-off adaptation.

At Certix we design and implement data protection compliance programmes tailored to the size and activities of each organisation. If you would like to know where your company stands and what you need to have a genuine compliance system in place, contact us and we will analyse your situation.

This content is for informational purposes only and does not constitute legal advice. The application of regulations to each specific case requires individual analysis.

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →