Investing in data protection
is not a cost. It is a decision.
The real cost is not what you pay for compliance. It is what you pay when you fail to comply.
Tell us about your activities and we will send you a proposal tailored to your reality within 24 hours.
Certix Services
Consultancy and advisory
GDPR · LOPDGDD · LSSI-CE
External DPO
Independent contract
Staff training
E-learning with certificates
Impact Assessment (DPIA)
For high-risk processing
Personalised quote
Proposal within 24 hours
For companies
What determines the investment in data protection?
Investment in GDPR and LOPDGDD compliance implementation varies depending on the size of the company, sector, number of employees and complexity of the data processing activities you carry out. Implementing compliance for a dental clinic is not the same as for an online shop.
The market offers very different proposals. The differences are not only about price: there are real analyses and there are generic templates that prove nothing to the AEPD. We are not the cheapest option — and we have no wish to be.
At Certix we prepare all documentation based on your specific activities. The quote is set following the initial analysis, with no surprises.
The initial consultation is the point at which we analyse your activities and determine exactly what you need. Directly, without ambiguity.
Factors that determine the final price
Number of employees
More employees → more HR processing and a larger RoPA
Sector of activity
Healthcare, education and banking require greater attention
Volume of clients
More data subjects → higher risk and more documentation
High-risk processing
Special-category, biometric data or systematic monitoring
Tools and suppliers
Each piece of software with data requires a processing agreement
Starting point
Starting from scratch requires more initial work
For sole traders
Data protection pricing for sole traders
Sole traders are also required to comply with the GDPR and LOPDGDD if they process the personal data of clients, suppliers or collaborators. And the majority do, even if they are not always aware of it.
The cost for sole traders is typically lower than for a company because the volume of processing activities is smaller. The initial analysis determines exactly what documentation is required in each case.
At Certix we prepare all necessary documentation: the RoPA, website and contact form updates, contracts with suppliers who access your data, and ongoing support for any query or incident. Contact us and we will send you a quote within 24 hours.
Sole trader service · Certix
- GDPR and LOPDGDD compliance implementation
- Privacy policy and website legal notice
- Information clauses for clients
- Contracts with data processors
- Personalised record of processing activities
- Ongoing support for queries and incidents
- Online document management platform
Data Protection Officer
Data Protection Officer (DPO) pricing
The external DPO is the figure that supervises your company's regulatory compliance and acts as the official liaison with the AEPD. Appointment is mandatory in certain sectors (healthcare, education, security, financial institutions) and recommended for any organisation wishing to strengthen its privacy culture.
Certix's external DPO service is an independent contract that includes formal designation with the AEPD, registration in the DPO Register, compliance monitoring, acting as the point of contact with data subjects and the AEPD, and advisory on impact assessments.
The cost is quoted based on the organisation's activities and the complexity of its processing. Contact us and we will send a proposal within 24 hours.
What does Certix's external DPO include?
More about the DPO
Functions, mandatory requirements and how to appoint one
Transparency
What determines the final price?
Company size
The number of employees, sites and volume of clients determines the complexity of the project. A micro-business and a company of 50 people have very different needs.
Sector of activity
Sectors such as healthcare, education and financial services process particularly sensitive data and require additional measures, which is reflected in the price.
Tools and software
Each supplier with access to personal data (CRM, ERP, accountancy software, hosting) requires a data processing agreement. More suppliers means more work.
Digital presence
Having a website, online shop, social media or newsletter multiplies the data collection points and the documentation required to comply with the LSSICE.
Starting point
Starting from scratch requires more work than updating existing but out-of-date documentation. The initial consultation allows us to assess the starting point.
Frequency of changes
Companies that launch new products, frequently engage new suppliers or change their business model require more frequent reviews.
No small print
What Certix's consultancy service includes
Everything you need to implement GDPR and LOPDGDD compliance for your company, with documentation prepared on the basis of your actual activities.
The external DPO service, formal audits and Data Protection Impact Assessments (DPIAs) are contracted and priced independently.
The right perspective
How much does non-compliance with data protection cost?
When discussing sanctions, two sets of rules apply: the Spanish rules (which govern day-to-day practice) and the European rules (which establish the absolute maximum thresholds).
1. The sanctions scale in Spain (LOPDGDD)
- Minor infringements (up to €40,000): Formal or procedural errors, such as having an incomplete privacy policy or failing to respond to a simple data subject request in time.
- Serious infringements (from €40,001 to €300,000): Significant non-compliance: absence of a Record of Processing Activities, sending commercial emails without consent, or failure to apply basic security measures.
- Very serious infringements (from €300,001): Fundamental breaches: processing special-category data (health, ideology) without express authorisation or unlawfully transferring databases to third parties.
2. European maximum thresholds (GDPR)
- Up to €10,000,000 or 2% of total annual global turnover: security failures, absence of a mandatory DPO or failure to notify data breaches.
- Up to €20,000,000 or 4% of total annual global turnover: infringement of fundamental privacy principles or failure to respect data subjects' rights.
Beyond these figures, however, the real risk for most SMEs does not come from AEPD inspections. The actual danger lies in complaints from dissatisfied customers or employees: a client angered by unsolicited emails, a disgruntled ex-employee or a poorly signposted camera can trigger a sanctions procedure at any moment, instantly and without warning.
The definitive comparison
Minor infringement (LOPDGDD)
Formal or procedural errors
Very serious infringement (LOPDGDD)
Special-category data, unlawful transfers
GDPR maximum threshold
Or 4% of global turnover
Certix full service
Personalised proposal within 24 h
The right perspective: investment in compliance is always lower than the impact of a sanction. AEPD fines are public, indexed in search engines and cause lasting reputational damage.
Personalised proposal within 24 hours.
Tell us about your activities. An expert analyses your case and sends you a tailored proposal — directly, without salespeople, without fixed pricing.
If you are looking for the cheapest service, we are probably not the right consultancy. If you want it done properly, let's talk.
Request your initial assessmentResponse within 24 h · +34 611 030 124
FAQ
Frequently asked questions about pricing
What determines the cost of GDPR compliance?
Investment varies according to the size of the company, the number and type of processing activities, the sector and whether a Data Protection Officer is required. Certix prepares a personalised proposal following an initial analysis of your activities.
Does the first year cost the same as subsequent years?
No. The first year includes the initial analysis, the full preparation of documentation and platform configuration. From the second year onwards, the service focuses on continuous maintenance, updates in response to regulatory changes and support for queries and incidents.
Is the external DPO service quoted separately?
Yes. The Data Protection Officer service is an independent contract that includes formal designation with the AEPD, compliance monitoring, acting as the point of contact with data subjects and advisory on DPIAs. It is priced based on the organisation's activities.
What is the difference between generic documentation and Certix's service?
Generic internet templates do not analyse the company's actual processing activities and do not demonstrate diligence to the AEPD. Certix prepares all documentation based on an analysis of your specific activities: Record of Processing Activities, privacy policies, information clauses, contracts with processors and breach protocols. In the event of an inspection, the difference is critical.
How do I request a quote?
You can contact us by telephone (+34 611 030 124), by email (info@certix.es) or via the contact form. We carry out an initial analysis of your situation and send you a personalised proposal within 24 hours, without sales calls.
Achieve compliance
for less than you think.
Personalised proposal within 24 hours. No salespeople, no surprises.
Response within 24 h · info@certix.es