News and resources on
data protection
Page 4 of 7
External IT provider as processor: the Art. 28 GDPR contract many SMEs lack
How to govern the external IT provider, the maintenance company or the cloud supplier under Art. 28 GDPR: mandatory contract, minimum content, remote access, home copies and provider switching.
Self-employed professionals and GDPR: the minimum obligations every freelancer must meet
GDPR applied to a self-employed professional without employees: proportionate RoPA, information clause, website privacy policy and cookies, contracts with the gestoría and software, and reasonable retention of client data.
Client data on the self-employed professional's phone: WhatsApp, contacts and legal management
How to comply with the GDPR from the professional phone of a freelancer: WhatsApp Business, separate contacts, work photos, device encryption, what to do if it is lost and deletion when a client relationship ends.
Invoicing and retention of tax data for the self-employed: how long to keep them and how
Real retention periods for invoices and tax data of a self-employed professional under the Spanish Commercial Code, General Tax Act and Civil Code. Client tax ID, cloud copy, contract with the gestoría and cessation of activity.
Cookies and consent on an online store: how to comply with the GDPR and LSSICE
Cookie banner compliant with the AEPD Guide, GA4 integration, Meta and TikTok pixels, equal weight for accept and reject, consent expiry and accessible configuration link.
Ecommerce privacy policy: what it must include and how to draft it
Mandatory content of an online store's privacy policy: controller, purposes, legal bases, recipients, international transfers, retention periods, customer rights and ecommerce-specific obligations.
Data protection in a real estate agency: where to start
Minimum documentation for a real estate agency: legal bases for buyers, sellers and tenants, GDPR-compliant visit sheet, contracts with portals and information duty at first contact.
Data protection in a gestoría or asesoría: where to start
Minimum documentation for a gestoría or asesoría: a RAT separating employment and tax matters, art. 28 RGPD contracts with each client, information clauses and the duty of professional secrecy.
Daily good practices for a gestoría team to protect data
Routines for advisers and administrators: encrypted payslips, no WhatsApp for sick leave, paper destruction, access controls to the accounting software and custody of scanned IDs.
Accounting software and ERP in a gestoría as processor: the supplier's obligations under the RGPD
The cloud ERP or invoicing platform processes data of client companies on behalf of the gestoría. What art. 28 RGPD contract it must sign, safeguards and return of historical tax data.
Data protection in a travel agency: where to start
Minimum documentation for a travel agency: RoPA, package travel files, passports, minors' data, processor contracts and the duty to inform.
Daily good practices for the team of a travel agency to protect data
Concrete routines for the team of an agency: passports and ID cards without keeping the image, secure ticket sending, individual GDS accesses, custody of files.
Do you need direct expert advice?
At Certix you will be attended by a data protection expert, with no sales teams involved.