News and resources on
data protection
Page 3 of 7
CVs and recruitment processes: how long to keep candidate data and how to inform candidates correctly
Processing candidate data under the GDPR: legal basis of the process, reasonable retention (1-2 years with consent for future vacancies), information notice, data subject rights and clean erasure.
Workplace health data: occupational health surveillance, sickness absence and how far the employer can go
Workplace processing of health data under the GDPR and the Spanish Occupational Risk Prevention Act (Law 31/1995): occupational health surveillance, sickness notes, medical confidentiality, fitness assessment and the split of information between mutual, medical service and employer.
GPS and geolocation in company vehicles: labour limits and GDPR
Geolocation of company vehicles under art. 90 LOPDGDD: prior information to workers and legal representatives, limits to working hours, disciplinary use and digital disconnection outside working time.
GDPR in gyms and sports centres: minimum documentation and member access control
GDPR compliance adapted to a gym: proportional records of processing activities, sign-up privacy notice, contracts with technology providers, compatible access control system (RFID, PIN, app, QR) and operational security policy.
Medical questionnaires in gyms: member health data and GDPR
How to legally handle the member’s medical questionnaire in a gym: dual legal basis (art. 6 and art. 9 GDPR), explicit consent, vital interests, secure custody, restricted access and retention periods.
CCTV in gyms: permitted areas, prohibited areas and GDPR
Where a gym can and cannot install cameras: permitted areas (entrance, reception), prohibited areas (changing rooms, showers, massage rooms), signage under art. 22 LOPDGDD and retention periods.
Client data in architecture firms: project files, drawings and data protection
How an architecture firm manages client personal data: project files, signed drawings, current-state photographs, professional portfolio, neighbouring properties and final handover.
Architect as processor: when Art. 28 GDPR applies
When an architect is controller and when processor: direct work with end client, technical subcontracting, collaborative BIM platforms and Art. 28 GDPR contracts.
Retention of architecture projects and permits: statutory periods vs. the GDPR
How long to retain architecture projects: LOE, civil prescription, Commercial Code, General Tax Act and professional college rules against the GDPR storage-limitation principle.
SaaS and the GDPR: when your software acts as your clients' processor
How a SaaS company governs its role as processor under Art. 28 GDPR: a DPA with each client, the processor/controller duality, subprocessors, breaches and model training.
GDPR for small businesses: what is mandatory and what is proportionate to your size
GDPR compliance tailored to the Spanish SME: proportionate RoPA, information clauses, contracts with providers, operational security policy and breach protocol. Without overdoing or falling short.
Employees and GDPR in the SME: payroll, time recording and CCTV
How an SME handles its workforce data under the GDPR: information clause when signing the contract, time recording, workplace CCTV, employee offboarding and deletion of professional email.
Do you need direct expert advice?
At Certix you will be attended by a data protection expert, with no sales teams involved.