A gestoría or asesoría is, by the very nature of its work, a data-intensive hub: payroll for client companies' workforces, sick-leave certificates, invoicing, accounting books, corporate deeds, tax forms, communications with the General Social Security Treasury (TGSS) and with the Tax Agency (AEAT). Data protection in this sector is not a process running parallel to the firm: it is part of the professional service billed to the client.
This guide summarises the minimum documentation any gestoría should have available — to open a new firm, regularise an existing one or review the position after a change of software or partner — under the framework of the RGPD (EU Regulation 2016/679), the LOPDGDD (Organic Law 3/2018) and the applicable national sector rules.
Why a gestoría is a special case: a dual legal role
The defining feature of the sector is that a gestoría acts simultaneously in two distinct roles under the RGPD, and it pays to be clear about this from day one:
- Controller over the data of its own client companies (identifying, contact and billing data), of its suppliers (IT, hosting, telephony, outside adviser) and of its own staff (advisers, administrators, interns). In those processing activities the gestoría decides on purposes and means.
- Processor (art. 28 RGPD) over the data of the workforce, suppliers and customers of each client company. The gestoría processes payroll, files Social Security returns, calculates taxes or keeps the books on behalf of the company, which remains the controller. The company decides what data, for what purpose and for how long; the gestoría carries out that processing in accordance with its documented instructions.
That duality has a very practical consequence: the data protection documentation of the gestoría must be structured in two clearly distinct blocks, and the art. 28 RGPD contract with each client company is not optional — it is the central piece of the sector.
Minimum documentation for the firm
These are the documents that, as a minimum, a gestoría should have ready before its first client. Some are mandatory under the rules; others are good practices that save trouble when an inspection comes in, an employee of a client lodges a complaint or there is a software migration.
| Document | Legal basis | Purpose |
|---|---|---|
| RAT as controller | Art. 30.1 RGPD | Inventory of own processing activities: client companies, suppliers, own staff, marketing. |
| RAT as processor | Art. 30.2 RGPD | Inventory of processing activities carried out on behalf of each client company. |
| Art. 28 RGPD contract with each client | Art. 28.3 RGPD | Specific annex governing the controller–processor relationship with each client company. |
| Information clause for the client company | Art. 13 RGPD | Information about the data of the company and its legal representatives that the gestoría processes as controller. |
| Website privacy policy and legal notice | Arts. 13–14 RGPD · Art. 10 LSSICE | Identification of the owner, purposes and rights for website users. |
| Cookie policy and banner | Art. 22.2 LSSICE | Information layer and granular consent for cookies that are not strictly necessary. |
| Security policy | Art. 32 RGPD | Technical and organisational measures: individual accounts, encryption, backups, control of paper. |
| Staff confidentiality undertakings | Art. 5.1.f RGPD · Art. 28.3.b RGPD | Duty of secrecy signed by every adviser, administrator or intern. |
| Breach protocol | Arts. 33–34 RGPD | Procedure to detect, assess and, where applicable, notify the client, the AEPD and the data subjects. |
| Data subject rights procedure | Arts. 15–22 RGPD | Channel to handle (or pass on to the client company) access, rectification, erasure, objection, restriction and portability. |
A sector-specific RAT: separating controller and processor
The Record of Processing Activities is where the sector's legal duality is given concrete form. Art. 30 RGPD distinguishes two sections that should not be mixed:
- RAT as controller (art. 30.1 RGPD): includes the processing activities in which the gestoría decides on purposes and means. At a minimum: management of client companies, management of own suppliers, management of own staff (recruitment, hiring, internal payroll, training), own marketing if any, handling of website enquiries and internal CCTV where applicable.
- RAT as processor (art. 30.2 RGPD): includes the processing activities carried out by the gestoría on behalf of each client company. At a minimum, the various areas are broken down: employment (payroll, contracts, sick leave, TC forms, severance), tax (tax returns, statements, withholdings), accounting (books, invoices, bank reconciliations) and company/commercial (deeds, corporate books, general meetings).
Each entry in the RAT should identify the purpose, the legal basis, the categories of data subjects, the categories of data, the recipients (TGSS, AEAT, mutual insurers, registries, financial institutions), international transfers if any, retention periods and security measures.
Art. 28 RGPD contracts with each client company
The processor contract is, in a gestoría, the most important document in the sector. It is not a short clause inserted in the fee letter: it is a specific document or annex that must be signed with each client company and must cover the minimum content of art. 28.3 RGPD.
| Contract element | What it must contain |
|---|---|
| Subject matter, duration, nature and purpose | Employment, tax, accounting and/or commercial services that the gestoría provides to the company. |
| Types of data and categories of data subjects | Identifying, economic, social security, tax and health data (sick leave). Data subjects: the client's workforce, self-employed workers and legal representatives, the client's suppliers. |
| Obligations of the controller and the processor | Documented instructions from the client company, processing on its behalf, prohibition on use for own purposes. |
| Confidentiality of the gestoría's personnel | Undertaking that every adviser, administrator and intern is subject to a reinforced duty of professional secrecy. |
| Security measures | Technical and organisational measures under art. 32 RGPD: encryption, individual access to software, backups, logs of access to the Sistema RED. |
| Sub-processors | List or authorisation mechanism for engaging sub-processors (cloud ERP, hosting, technical support). |
| Assistance to the controller | Cooperation in handling data subject rights, DPIAs and breach notifications. |
| Breach notification | Notification to the client company without undue delay (art. 33.2 RGPD) when the gestoría becomes aware of a breach. |
| Return or deletion at the end | Obligation under art. 28.3.g RGPD: return or export the data to the client company at its choice before any deletion. |
| Audits and inspections | Availability of information to demonstrate compliance and the possibility of reasoned audits or inspections. |
The return clause deserves particular attention: at the end of the relationship with a client company, the gestoría must return or export the employment, tax and accounting data to the client — in a useful and structured format — so that it can continue meeting its own legal retention periods. Only after that does the deletion of the gestoría's records follow.
Information clause for the client company (art. 13 RGPD)
The duty to inform under art. 13 RGPD is mandatory even where the legal basis is the performance of a professional contract. The gestoría must give the client company an information clause covering at least two angles:
- Data of the client company and its legal representatives that the gestoría processes as controller (identifying, tax, contact and billing data): purpose, legal basis (performance of the professional contract, art. 6.1.b), communications, retention periods and rights.
- Data of the client company's workforce and suppliers over which the gestoría acts as processor: an express statement that those data are processed on behalf of the client company, in accordance with the art. 28 RGPD contract, and that it is the client company that must inform its own workforce of the existence of the gestoría as processor.
The clause should be available at the usual collection points: engagement letter, initial quote, web form and, if the gestoría sends a newsletter or information circulars, on the subscription form.
Duty of confidentiality and professional secrecy
The sector carries a duty of confidentiality reinforced from two directions:
- Art. 5.1.f RGPD: the integrity and confidentiality principle. Data must be processed in such a way that adequate security is ensured, including protection against unauthorised or unlawful processing.
- Codes of professional conduct and statutes of the gestores administrativos, economists, commercial graduates, social-relations graduates (graduados sociales) and in-house lawyers providing services in the sector. The duty of professional secrecy attaches to professionals on the relevant rolls and extends to all client information.
In practice, every team member (adviser, administrator, intern in training, cleaning staff with access to the firm) must sign a specific confidentiality undertaking before starting work. That signature is kept in the employment file and renewed on significant changes of role.
The gestoría's habitual processors: sub-processors
The gestoría, like any controller, in turn engages suppliers that process data on its behalf. In the gestoría's role as processor for its client companies, those suppliers are sub-processors (arts. 28.2 and 28.4 RGPD) and must be authorised — generally or specifically — in the contract with the client company.
- Cloud ERP and accounting/payroll software: the operational heart of the gestoría. It is covered in detail in the third article of this guide.
- SILTRA platform and the TGSS's Sistema RED: an important nuance here. The General Social Security Treasury is not a processor of the gestoría: it is an independent public-administration controller that receives the data in compliance with legal obligations (art. 6.1.c RGPD). The client software the gestoría uses to communicate with the TGSS (transmission systems, digital certificates) may be a technology supplier that does act as a sub-processor.
- AEAT electronic office: same regime. The AEAT is an independent controller; the software for online filing may be a technology supplier acting as sub-processor.
- Electronic signature systems (FNMT, qualified trust service providers): these usually act as independent controllers in the issuance and validation of the certificate.
- Secure document-exchange platforms with the client company (private area, cloud document manager): sub-processor.
- Website hosting and mail server: sub-processor, with an art. 28 RGPD contract and verification of server location.
- External IT maintenance service with remote access to the gestoría's equipment: sub-processor, with a contract and specific confidentiality undertakings.
The gestoría must keep an updated list of sub-processors and communicate it — or refer to it — in the art. 28 contracts with its client companies, together with the procedure for notifying new additions and allowing reasoned objection.
Retention periods: employment, tax and commercial
The retention period is one of the points on which the gestoría must align with the client company. As a general criterion:
- Tax documentation: the limitation period under art. 66 of the General Tax Law is four years. Documentation with tax implications is kept at least for that horizon, and may be extended if proceedings are open or losses are pending offset.
- Commercial documentation: art. 30 of the Commercial Code requires the trader to keep books, correspondence, documentation and supporting records for six years.
- Employment and Social Security documentation: there are specific periods in the Workers' Statute (ET), the General Social Security Act and the occupational risk prevention rules, as well as periods derived from the limitation of employment-law claims. It is sensible to parameterise them by type of document in the RAT.
- Contractual periods with the client: the art. 28 contract may agree specific periods. The gestoría aligns with those periods and, once they have elapsed, returns or exports to the client and only then deletes.
Regional sector rules may extend or modify specific periods in some areas (subsidies, grants, professional registers). It is mandatory to check the rules applicable to each firm and each client.
"En una gestoría, la mitad del cumplimiento de protección de datos se resuelve el día en que el RAT separa con claridad lo que se trata como responsable y lo que se trata por cuenta de cada cliente, y se firma un anexo del artículo 28 con cada empresa. A partir de ahí, lo demás encaja casi solo."
Mario P. Talamillo · Managing Partner, Certix®
If you run a gestoría or asesoría and want to review your data protection documentation, at Certix we work specifically with gestorías and asesorías. No salespeople: from the very first contact, you will speak with a specialist.
Data protection guide for gestorías and asesorías
This content is for general guidance and information purposes only; it does not in any case constitute specialised legal advice. Regional sectoral rules may extend or modify the deadlines and requirements of national legislation. The application of the rules to each specific case requires individual analysis.