Facilita RGPD is one of the best-known tools of the Spanish Data Protection Agency, and also one of the most misinterpreted. It is free, it is useful and it is designed with good intentions, but it only works for a very specific business profile. This guide explains what Facilita is, what documentation it generates, who it really serves and —most importantly— where its limits lie, so that you know whether your company falls within its scope or has slipped outside it without noticing.
In 15 seconds
- Facilita RGPD is a free AEPD tool for generating basic data protection documentation.
- It only covers very low-risk processing: identifying and contact data, with no special categories or profiling.
- If there is health data, video surveillance, profiling, large volumes or complex disclosures, it is not enough.
- Accountability (art. 5.2 GDPR) still rests with the controller, whether or not the tool is used.
What is Facilita RGPD?
Facilita RGPD is a free online tool developed by the Spanish Data Protection Agency (AEPD). Its aim is to help the smallest companies and self-employed professionals who carry out very low-risk data processing to generate basic data protection documentation without needing prior legal knowledge. It works as a guided questionnaire: you answer a series of questions about the activity and the tool returns several indicative documents ready to download.
The logic behind Facilita is reasonable. The AEPD wants the micro-business that only handles the name, phone number and email of its customers to have a first set of documents at hand, rather than being left with nothing out of ignorance or the initial cost. It is a tool for awareness and first support, conceived to lower the barrier to compliance in the simplest cases.
It is worth being clear from the outset about an idea the tool itself warns of: Facilita is not designed for everyone. It is limited, by design, to a minimal-risk profile. The moment a company's activity moves away from that profile, the tool stops fitting, and the documents it produces cease to be adequate. Understanding that boundary is the most important part of this article.
What documentation it generates
Based on the questionnaire responses, Facilita generates a package of basic starter documentation. Without going into the exact detail of each template —which the tool itself adapts according to the answers—, the documents it produces cover, in general terms, four pieces:
- Information notices to comply with the information duty of art. 13 GDPR: the texts that must be provided to or shown to the people whose data is collected (customers, providers, employees) explaining who processes their data, for what purpose and what rights they have.
- A basic record of processing activities, the minimal version of the art. 30 GDPR document that inventories the organisation's processing.
- An annex with indicative security measures, a reference list of technical and organisational good practices for simple processing.
- A model clause for processor contracts, designed to govern the relationship with providers who access data on behalf of the company (art. 28 GDPR).
It is a good starting point for someone who has absolutely nothing. But it must be read for what it is: generic templates generated from a questionnaire, not an analysis of the organisation. The tool does not know your business; it knows the boxes you ticked. And it only works if those boxes describe genuinely low-risk processing.
Who it serves: the low-risk business
Facilita is designed for the business that carries out low-risk processing. In practice, this describes a company or self-employed professional that handles little more than identifying and contact data —name, national ID, phone, email, address— of its customers, providers and employees, for the sole purpose of managing the ordinary commercial or employment relationship.
Processing fits that low-risk profile when it meets, broadly, these characteristics:
- It is limited to identifying and contact data, strictly what is necessary to provide the service or manage the relationship.
- It does not include special categories of data under art. 9 GDPR: health, ethnic origin, political opinions, trade union membership, sexual orientation, biometric or genetic data.
- There is no profiling or automated decisions that evaluate or classify people.
- No large volumes of data are handled and there is no systematic monitoring of people.
- There are no complex international transfers or mass disclosures to third parties beyond those required by law.
The typical example would be a small workshop, a neighbourhood shop, a self-employed professional invoicing a small client base or a one-person practice that only keeps contact data. For that profile, Facilita fulfils its function: it sets in motion starter documentation that did not exist before. The problem starts when a business that believes it is low-risk actually is not.
The limits of Facilita: where it falls short
Here is the critical point of this article. Facilita only covers low-risk processing, and most real companies have, without being aware of it, at least one processing operation that falls outside that framework. As soon as just one of the following elements appears, the tool ceases to be sufficient:
- Special categories of data (art. 9 GDPR): health data, biometric data, membership data, ideology, etc. Simply collecting medical reports, detailed sick notes or any sensitive data takes you outside the scope of Facilita.
- Video surveillance. Installing cameras that record customers or employees is processing with its own implications that the tool does not resolve.
- Profiling or automated decisions: customer segmentation, scoring, behaviour-based marketing, advanced personalised advertising.
- Large volumes of data or systematic monitoring of people, typical of e-commerce with thousands of customers, platforms or businesses with extensive databases.
- Complex processing: regular disclosures to third parties, international transfers, intensive use of technology providers, processing of children's data, or any activity that combines several sensitive purposes.
The risk is not that Facilita "fails": the tool does exactly what it promises. The risk is that a business owner uses it outside its scope, downloads its documents and assumes they are compliant when they are not. That is the trap: the documentation exists, it looks good and it has the AEPD's name behind it, but it describes a low-risk business that does not match the reality of the company that generated it. The result is a false sense of compliance, which is often worse than having nothing, because it switches off the alarm.
"Facilita is a good tool for what it was designed for: the minimal-risk business. The problem is not the tool, it is using it when your company has already outgrown it. A downloaded PDF does not analyse your activity. And the liability, when something goes wrong, is still yours, not the box you ticked."
Mario P. Talamillo · Managing Partner, Certix®
Table: when it serves and when it does not
The quickest way to place your business is to contrast your activity with the two columns below. If you recognise yourself in any row on the right, Facilita has fallen short for your case.
| Facilita DOES serve (low risk) | Facilita is NOT enough (you need analysis) |
|---|---|
| Only identifying and contact data of customers and employees | Health data or other special categories (art. 9 GDPR) |
| No security cameras | Video surveillance of premises, customers or staff |
| No customer segmentation or profiling | Profiling or automated decisions |
| A small base of customers or providers | Large volumes of data or systematic monitoring |
| No disclosures or transfers beyond the legal ones | Regular disclosures to third parties or international transfers |
| Stable activity, with one or a few simple purposes | Children's data, advanced marketing or combined processing |
The boundary between the two columns is not always as sharp as it looks on paper. Many businesses cross to the right without realising: a shop that installs a camera, a gestoría that receives sick notes, an e-commerce that grows and starts segmenting. The processing that yesterday was low-risk is no longer so today, and the Facilita documentation stays anchored in a snapshot that stopped being true.
How to use it well
If, after reading the above, you are clear that your business fits the low-risk profile, Facilita is a perfectly valid resource to start with. Correct use is straightforward:
- Access the tool from the official AEPD website. It is free and does not require registering your data on third-party platforms. Be wary of sites that offer it "for a fee" or that ask for unnecessary information.
- Answer the questionnaire honestly. The quality of the documents depends entirely on the accuracy of your answers. Ticking boxes to "simplify" only produces documents that do not describe your reality.
- If any risk signal appears in the questionnaire —the tool will warn you if it detects that your case exceeds low risk—, do not force the machine: it is the sign that you need to go beyond Facilita.
- Review the generated documents and compare them with what you really do. The information notices must reflect your actual purposes, and the record of activities must include all your processing, not only the ones the template presupposes.
- Provide and implement the documentation. Downloading the files is not compliance: the information notices must be shown at first contact (art. 13 GDPR) and the security measures must be genuinely applied.
And a precaution that applies to any automatic tool: a generated document does not replace knowing what you are doing. Facilita gives you a starting point; keeping it alive and consistent with your activity is still your responsibility.
Checklist before relying on it
Before accepting the Facilita documentation as valid, contrast your situation with this list. If you answer "yes" to any of the points, the tool does not cover your case and you need a data protection audit or assessment that genuinely analyses your activity:
- ☐ Do you collect health, biometric or any other special category data under art. 9 GDPR?
- ☐ Do you have video surveillance cameras on your premises or facilities?
- ☐ Do you segment, profile or classify your customers in an automated way?
- ☐ Do you handle a high volume of data or systematically monitor people?
- ☐ Do you disclose data to third parties regularly or make international transfers?
- ☐ Do you process the data of minors?
- ☐ Do you use several tools or technology providers that access your customers' data?
- ☐ Has your activity changed since you generated the documents so that they no longer match what you do?
All boxes blank means that you are probably the profile Facilita was designed for. A single ticked box means you have left its scope, and relying on it alone would leave you with documentation that does not protect what you really process.
When Facilita is not enough and what we do at Certix
Let us acknowledge it plainly: for the minimal-risk micro-business, Facilita is an honest and sufficient tool, and at Certix we are not going to pretend otherwise. The problem is that most companies have at least one processing operation that exceeds its scope —a camera, a health record, a provider that manages the customer base, a volume that has grown— and they do not always know it. That is where an automatic template stops serving and the analysis work begins.
The underlying difference is simple. Facilita presumes that your business is low-risk based on a few boxes; a consultancy checks whether it is based on your real activity. The accountability principle of art. 5.2 GDPR requires the controller to be able to demonstrate compliance at any moment, and that demonstration is not sustained by a downloaded PDF, but by an analysis that connects each processing operation with its legal basis, its deadlines and its measures.
At Certix we start from a real assessment of your activity: we identify what processing you genuinely carry out, whether any of it falls outside the low-risk profile and what documentation you need —from the full record of processing activities to the notices and contracts your specific case requires—. With no generic templates and taking nothing for granted. If you have doubts about whether Facilita covers your business or has become too small for it, speaking to a consultant is the step that resolves the uncertainty.
Frequently asked questions
What is Facilita RGPD from the AEPD?
It is a free online tool from the Spanish Data Protection Agency that helps companies and self-employed professionals with very low-risk processing to generate basic starter documentation: information notices, a simple record of activities, an annex with indicative security measures and a model clause for processor contracts. It is designed as a first support for the micro-business with minimal data, not for complex processing.
Does Facilita RGPD serve to comply with the GDPR in any company?
No. It only covers low-risk processing: identifying and contact data, with no special categories, no profiling and no large volumes. If your organisation handles health data, uses video surveillance, builds profiles, processes large amounts of data or makes disclosures and international transfers, the tool does not cover your situation and the documentation it generates is insufficient. In those cases an individualised professional analysis is needed.
Does the documentation from Facilita RGPD exempt me from liability?
No. The accountability principle of art. 5.2 GDPR always rests with the controller, not with the tool used to generate its documents. Facilita provides a starting point, but it is the company that must ensure that those documents reflect what it really does with the data and that its case fits the low-risk profile the tool presupposes. Using it when it does not apply creates a false sense of compliance.
How do I know if my business is low-risk?
Broadly, processing is low-risk when it is limited to identifying and contact data necessary for the relationship with customers, providers or employees, with no sensitive data, no profiling, no automated decisions and no high volumes. As soon as any of those elements appears, it ceases to be so. The boundary is not always obvious, and confusing it is the most common mistake: that is why an expert assessment is advisable before assuming that Facilita is enough.
In summary
Facilita RGPD is a free and well-conceived AEPD tool so that the minimal-risk business has basic starter documentation. It fulfils its function for that specific profile. The mistake —very widespread— is using it when the company's activity has already outgrown low risk: a camera, a health record, a growing volume, and the tool falls short without the owner noticing. The documentation exists, but it stops protecting what is really processed, and the liability of art. 5.2 GDPR still rests with the controller. Before relying on it, the right question is not whether Facilita is good, but whether your business is still within its scope.
Related reading
- Record of Processing Activities (RoPA): what it is and how to do it — the art. 30 GDPR document that Facilita generates in its basic version.
- Data protection audit and assessment — the analysis that checks whether your activity exceeds low risk.
- Certix data protection consultancy — how we work when an automatic template is not enough.
This content is purely informational and educational; it does not constitute specialised legal advice. Applying the regulations to each specific case requires individual analysis.
Not sure whether Facilita covers your business?
At Certix we analyse your real activity and tell you with judgement whether low-risk processing is enough or whether you need to go further. With no generic templates.
Speak to a consultant