Certix

Data protection for freelancers and businesses: obligations and solutions in 2026

Certix
Certix®
· 7 Sep 2026 · 8 min read

Informative article. It does not replace individualised professional advice.

The GDPR has been in force since 2018 and the LOPDGDD complements it in Spain, yet in 2026 data protection remains the great pending subject for many freelancers and SMEs. The basic obligations have not changed; what has changed is the day-to-day of the business: more digital tools, more cloud providers and more client data moving through phones and email.

The problem is rarely bad intent. It is not knowing what is being overlooked: trusting a downloaded template, a PDF signed years ago or a low-cost provider that copied and pasted the documentation without analysing the real activity of the business. The result is a false sense of calm that holds up only until the first incident appears.

"Most businesses that come to us believe they already comply. The problem is not a lack of willingness: it is not knowing what is being overlooked."

Mario P. Talamillo · Managing Partner, Certix®

What does complying with data protection really involve?

It is not a matter of publishing a privacy policy on the website and forgetting about it. Being compliant means knowing what data your business processes, on what legal basis, how long you retain it, what security measures you apply and how you respond when a client exercises their rights or when an incident occurs.

Every activity is different. An online shop, a gestoría, a workshop or a clinic do not process the same data nor take on the same risks. That is why generic documents do not work: they describe a business that is not yours, they create a false sense of security —sometimes worse than having nothing— and they do not allow you to demonstrate diligence if a problem arises. Data protection is only effective when the documentation reflects your real operations.

What the GDPR requires of freelancers and SMEs in 2026

Regardless of size, if you process data of clients, employees or suppliers, there is a common base of obligations. These are not isolated formalities, but pieces of a single system:

  • Record of Processing Activities (RoPA): the inventory of what data you process and for what purpose (art. 30 GDPR). It is the starting point of everything, not the last paper to be signed.
  • A legal basis for each processing operation (art. 6 GDPR): performance of a contract, legal obligation, consent, legitimate interest… Not everything rests on consent, and choosing the wrong basis is one of the most common mistakes.
  • Duty to inform (art. 13 GDPR): the information clauses in your website forms, in contracts and at the first contact with the client. Informing clearly is mandatory even when the processing does not require consent.
  • Contracts with your processors (art. 28 GDPR): the management software, the cloud, the gestoría or the booking platform that process data on your behalf need their contract. And be careful with providers outside the EU: the lawfulness of those transfers depends on safeguards such as the Data Privacy Framework, not just a generic clause.
  • Security measures and a breach protocol (art. 32 and 33 GDPR): role-based access, individual passwords, backups and knowing what to do —and whom to notify— if something leaks.

A data protection officer (DPO) is only mandatory in the cases set out in art. 37 GDPR and art. 34 LOPDGDD. Not every business needs one: each case requires an individual analysis.

The most frequent mistakes freelancers and SMEs keep making

The failures we see most are not technical, they are matters of daily routine. They are corrected with habits, not with one more document in a drawer:

  • The personal phone's address book as a CRM: hundreds of client records mixed with personal ones, with no access control or backup, and on a device that is easily lost or replaced.
  • WhatsApp for everything: sending documentation, client data or sensitive information through personal WhatsApp, without separating the professional from the private.
  • Web forms with no clause: collecting name, email or phone number on the website without informing of the purpose or linking the privacy policy.
  • Generic templates: copying the privacy policy of another website that describes neither your processing operations nor your real providers.
  • Providers with no contract: using cloud software, a gestoría or an agency without the art. 28 processor agreement.

None of these mistakes is fixed with a stray PDF. They are fixed by ordering the activity, defining how data is handled in the day-to-day and documenting it in a way that can be demonstrated.

How to comply without turning it into a never-ending project

Adapting does not have to paralyse your business. At Certix we work with a clear method: we analyse your activity with a specialist, we produce documentation tailored to your real processing operations, and we give you access to a private platform where you have everything centralised and up to date.

There are no sales staff in between: you speak directly with whoever handles your data protection. And it is not a one-off formality. Activity changes —new providers, new services, more employees— and the documentation is kept current as your business evolves. That continuity is the difference between being genuinely compliant and holding papers that age on their own.

If you do not know what state your data protection is in right now, or you have doubts about your current provider, tell us about your case and we will analyse your situation: we will tell you what you have right, what is missing and what to prioritise. With no obligation.

Legal note: this content is merely indicative and informative; it does not constitute specialised legal advice. The application of the regulations to each specific case requires an individual analysis.

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →