News and resources on
data protection
Page 2 of 7
Video surveillance in shops: how to install cameras complying with the GDPR and LOPDGDD
How to install cameras in a physical shop complying with the GDPR and LOPDGDD: security purpose, allowed and prohibited areas, signage, one-month maximum retention and processing record.
Loyalty programmes and customer cards: how to comply with the GDPR in retail
How to manage a loyalty programme with customer card under the GDPR: legal basis, express consent by purpose, commercial communications under the LSSICE and right to object.
Retail employee data: payroll, time tracking and workplace video surveillance
How to manage the data of shop workers under the GDPR and the Spanish Workers' Statute: payroll, time tracking with PIN or card, workplace video surveillance under art. 89 LOPDGDD and retention periods.
Franchises and GDPR: who is controller and who is processor in a brand network
How GDPR figures are allocated between franchisor and franchisee: independent controllership, joint controllership under art. 26 GDPR, processor status under art. 28, joint and several liability towards the customer and recommended contractual models.
Transferring customer data between franchisees of the same brand: when it is lawful and when it is not
Transferring and accessing customer data between franchisees of the same brand: legal bases, joint controllership under art. 26 GDPR for common programmes, shared CRM, loyalty and franchisor communications.
DPO in franchise networks: shared appointment, individual appointment and allocation of responsibilities
DPO appointment obligation in franchises under art. 37 GDPR and art. 34 LOPDGDD: when the franchisor needs one, when the franchisee, the art. 37.2 GDPR rule for groups and the coordinated model with a common external DPO.
GDPR from day 1 in a startup: minimum documentation before launching a product
Operational guide for founders: RoPA, privacy policy, DPAs with SaaS providers, international transfers with the Data Privacy Framework, impact assessment and continuous review cycle during the growth phase.
Freelancer and processor: the art. 28 GDPR contract your client expects (and the AEPD requires)
When a freelancer (web designer, developer, consultant) is a processor and what art. 28 GDPR contract should be signed with the client: minimum content, sub-processors, return of data.
Professional portfolio with client data: how to display your work without stepping on the GDPR
How to display projects done for clients in a professional portfolio: effective anonymisation of screenshots and data, consent for testimonials and image, and the right to use the work performed.
Developers, cookies and analytics: how to implement tracking without skipping GDPR
What a developer must do when implementing cookies, Google Analytics, Hotjar and marketing pixels: consent management platform, conditional loading, real granularity, inventory and evidence under art. 22.2 LSSICE and the AEPD guidance.
Before/after photos on social media: how to capture client consent in hair and beauty salons
Publishing client before/after photos on social media in hair and beauty salons: express, specific and withdrawable consent under the GDPR and Organic Law 1/1982 on the right to own image.
Online booking apps in hair and beauty salons: the processor role
Fresha, Treatwell, Booksy and other booking apps as the centre's processors: art. 28 GDPR processing agreement, international transfers, DPF, RoPA and client information notice.
Do you need direct expert advice?
At Certix you will be attended by a data protection expert, with no sales teams involved.