Category
Digital & Privacy
Privacy on social networks, cookie policies, tracking pixels and data protection obligations in the digital environment for businesses.
A business's digital presence involves the constant processing of personal data that, in most cases, is managed without adequate controls. Social networks, analytics tools, tracking pixels, web forms, email marketing campaigns or video conferencing platforms are all sources of personal data processing that require a legal basis, clear information and security measures.
The digital environment presents specific challenges: international data transfers are common when using third-party tools with servers outside the European Economic Area, cookie consent remains one of the areas with the highest number of sanctions, and the management of data on corporate social networks often lacks internal protocols.
In this section you will find practical guides on social media privacy, cookie obligations, the use of tracking tools and how to reduce legal risk in your business's digital environment.
Articles on Digital & Privacy
Protect your personal data with proper social media privacy management
Social networks involve the constant processing of personal data. Understand your organisation's obligations and how to manage them correctly.
Protect your family by understanding internet dangers and how to avoid them
The internet is the main threat vector for data security. Discover the most common risks and how to reduce your exposure.
Website privacy policy for businesses: what it must include
What a website privacy policy is, why the duty to inform under art. 13 GDPR requires it and what it must include: controller, purposes, legal basis, recipients, retention, rights and complaint to the AEPD.
Website legal notice: what it must include and who is required to have one
What a website legal notice is, who is required to have one under art. 10 of the LSSI-CE and what it must include: identification of the owner, NIF/CIF, address, contact and registration or professional membership data where applicable.
Cookie policy and consent: what it is and how to make it compliant
What the cookie policy is, what art. 22.2 of the LSSICE requires, which cookies need consent and how a banner must look under the AEPD Cookie Guide: accept and reject on equal terms, granularity and easy withdrawal.
Frequently asked questions about digital & privacy
Is a cookie policy mandatory for any business website?
Yes. Any website that uses cookies that are not strictly necessary (analytics, advertising, social networks, maps, videos…) is obliged to provide information about them, obtain the user's consent before installing them and provide a mechanism to withdraw that consent at any time. The absence of a cookie banner or the use of dark patterns that make it difficult to refuse are infringements frequently sanctioned by the AEPD.
What does using Meta Pixel or Google Analytics on a website involve?
These tools transfer user behaviour data to third-party servers, usually outside the European Economic Area. Their use requires prior user consent, detailed information in the cookie policy and, in many cases, the signing of Standard Contractual Clauses (SCC) or reliance on the Data Privacy Framework (DPF) to ensure the legality of the international transfer. The AEPD has sanctioned the use of these tools without meeting these requirements.
Does a marketing agency managing our social networks need a special contract?
Yes. If an external agency or community manager accesses private messages, follower data or any personal information through the company's social profiles, they are a data processor. The GDPR requires a Data Processing Agreement (DPA) to be formalised, regulating what data they may use, for what purpose and what security measures they must apply. Operating without that contract is a direct GDPR infringement.
Is your business's digital privacy under control?
At Certix you will be attended by a data protection expert, with no sales teams involved.