Certix

Investing in data protection
is not a cost. It is a decision.

The real cost is not what you pay for compliance. It is what you pay when you fail to comply.

Tell us about your activities and we will send you a proposal tailored to your reality within 24 hours.

Certix Services

Consultancy and advisory

GDPR · LOPDGDD · LSSI-CE

External DPO

Independent contract

Staff training

E-learning with certificates

Impact Assessment (DPIA)

For high-risk processing

Personalised quote

Proposal within 24 hours

For companies

What determines the investment in data protection?

Investment in GDPR and LOPDGDD compliance implementation varies depending on the size of the company, sector, number of employees and complexity of the data processing activities you carry out. Implementing compliance for a dental clinic is not the same as for an online shop.

The market offers very different proposals. The differences are not only about price: there are real analyses and there are generic templates that prove nothing to the AEPD. We are not the cheapest option — and we have no wish to be.

At Certix we prepare all documentation based on your specific activities. The quote is set following the initial analysis, with no surprises.

The initial consultation is the point at which we analyse your activities and determine exactly what you need. Directly, without ambiguity.

Factors that determine the final price

Number of employees

More employees → more HR processing and a larger RoPA

Sector of activity

Healthcare, education and banking require greater attention

Volume of clients

More data subjects → higher risk and more documentation

High-risk processing

Special-category, biometric data or systematic monitoring

Tools and suppliers

Each piece of software with data requires a processing agreement

Starting point

Starting from scratch requires more initial work

For sole traders

Data protection pricing for sole traders

Sole traders are also required to comply with the GDPR and LOPDGDD if they process the personal data of clients, suppliers or collaborators. And the majority do, even if they are not always aware of it.

The cost for sole traders is typically lower than for a company because the volume of processing activities is smaller. The initial analysis determines exactly what documentation is required in each case.

At Certix we prepare all necessary documentation: the RoPA, website and contact form updates, contracts with suppliers who access your data, and ongoing support for any query or incident. Contact us and we will send you a quote within 24 hours.

Sole trader service · Certix

  • GDPR and LOPDGDD compliance implementation
  • Privacy policy and website legal notice
  • Information clauses for clients
  • Contracts with data processors
  • Personalised record of processing activities
  • Ongoing support for queries and incidents
  • Online document management platform
Request a sole trader quote

Data Protection Officer

Data Protection Officer (DPO) pricing

The external DPO is the figure that supervises your company's regulatory compliance and acts as the official liaison with the AEPD. Appointment is mandatory in certain sectors (healthcare, education, security, financial institutions) and recommended for any organisation wishing to strengthen its privacy culture.

Certix's external DPO service is an independent contract that includes formal designation with the AEPD, registration in the DPO Register, compliance monitoring, acting as the point of contact with data subjects and the AEPD, and advisory on impact assessments.

The cost is quoted based on the organisation's activities and the complexity of its processing. Contact us and we will send a proposal within 24 hours.

What does Certix's external DPO include?

Formal designation as DPO with the AEPD
Registration with the AEPD DPO Register
Continuous compliance monitoring
Point of contact with data subjects and the AEPD
Advisory on Data Protection Impact Assessments (DPIAs)
Support in the event of inspections and complaints

More about the DPO

Functions, mandatory requirements and how to appoint one

Transparency

What determines the final price?

Company size

The number of employees, sites and volume of clients determines the complexity of the project. A micro-business and a company of 50 people have very different needs.

Sector of activity

Sectors such as healthcare, education and financial services process particularly sensitive data and require additional measures, which is reflected in the price.

Tools and software

Each supplier with access to personal data (CRM, ERP, accountancy software, hosting) requires a data processing agreement. More suppliers means more work.

Digital presence

Having a website, online shop, social media or newsletter multiplies the data collection points and the documentation required to comply with the LSSICE.

Starting point

Starting from scratch requires more work than updating existing but out-of-date documentation. The initial consultation allows us to assess the starting point.

Frequency of changes

Companies that launch new products, frequently engage new suppliers or change their business model require more frequent reviews.

No small print

What Certix's consultancy service includes

Everything you need to implement GDPR and LOPDGDD compliance for your company, with documentation prepared on the basis of your actual activities.

Initial activity and data processing analysis
RoPA (Record of Processing Activities)
Definition of technical and organisational structure
Information clauses for contracts and forms
Bespoke website legal notice and privacy policy
Cookie policy and consent banner management
Advisory on contracts with data processors
Confidentiality commitment and consent templates
Data breach response and notification protocol
Data subject rights management procedure
Online document management platform, available 24/7
Continuous telephone and remote support
Documentation updates in response to regulatory changes
Advisory in the event of AEPD inspections and complaints

The external DPO service, formal audits and Data Protection Impact Assessments (DPIAs) are contracted and priced independently.

The right perspective

How much does non-compliance with data protection cost?

When discussing sanctions, two sets of rules apply: the Spanish rules (which govern day-to-day practice) and the European rules (which establish the absolute maximum thresholds).

1. The sanctions scale in Spain (LOPDGDD)

  • Minor infringements (up to €40,000): Formal or procedural errors, such as having an incomplete privacy policy or failing to respond to a simple data subject request in time.
  • Serious infringements (from €40,001 to €300,000): Significant non-compliance: absence of a Record of Processing Activities, sending commercial emails without consent, or failure to apply basic security measures.
  • Very serious infringements (from €300,001): Fundamental breaches: processing special-category data (health, ideology) without express authorisation or unlawfully transferring databases to third parties.

2. European maximum thresholds (GDPR)

  • Up to €10,000,000 or 2% of total annual global turnover: security failures, absence of a mandatory DPO or failure to notify data breaches.
  • Up to €20,000,000 or 4% of total annual global turnover: infringement of fundamental privacy principles or failure to respect data subjects' rights.

Beyond these figures, however, the real risk for most SMEs does not come from AEPD inspections. The actual danger lies in complaints from dissatisfied customers or employees: a client angered by unsolicited emails, a disgruntled ex-employee or a poorly signposted camera can trigger a sanctions procedure at any moment, instantly and without warning.

The definitive comparison

Minor infringement (LOPDGDD)

Formal or procedural errors

up to €40,000

Very serious infringement (LOPDGDD)

Special-category data, unlawful transfers

+€300,000

GDPR maximum threshold

Or 4% of global turnover

€20,000,000

Certix full service

Personalised proposal within 24 h

Bespoke

The right perspective: investment in compliance is always lower than the impact of a sanction. AEPD fines are public, indexed in search engines and cause lasting reputational damage.

Personalised proposal within 24 hours.

Tell us about your activities. An expert analyses your case and sends you a tailored proposal — directly, without salespeople, without fixed pricing.

If you are looking for the cheapest service, we are probably not the right consultancy. If you want it done properly, let's talk.

Request your initial assessment

Response within 24 h · +34 611 030 124

FAQ

Frequently asked questions about pricing

What determines the cost of GDPR compliance?

Investment varies according to the size of the company, the number and type of processing activities, the sector and whether a Data Protection Officer is required. Certix prepares a personalised proposal following an initial analysis of your activities.

Does the first year cost the same as subsequent years?

No. The first year includes the initial analysis, the full preparation of documentation and platform configuration. From the second year onwards, the service focuses on continuous maintenance, updates in response to regulatory changes and support for queries and incidents.

Is the external DPO service quoted separately?

Yes. The Data Protection Officer service is an independent contract that includes formal designation with the AEPD, compliance monitoring, acting as the point of contact with data subjects and advisory on DPIAs. It is priced based on the organisation's activities.

What is the difference between generic documentation and Certix's service?

Generic internet templates do not analyse the company's actual processing activities and do not demonstrate diligence to the AEPD. Certix prepares all documentation based on an analysis of your specific activities: Record of Processing Activities, privacy policies, information clauses, contracts with processors and breach protocols. In the event of an inspection, the difference is critical.

How do I request a quote?

You can contact us by telephone (+34 611 030 124), by email (info@certix.es) or via the contact form. We carry out an initial analysis of your situation and send you a personalised proposal within 24 hours, without sales calls.

Achieve compliance
for less than you think.

Personalised proposal within 24 hours. No salespeople, no surprises.

INFORMACIÓN BÁSICA DE PROTECCIÓN DE DATOS: De conformidad con las normativas de Protección de Datos, le facilitamos la siguiente información del tratamiento: Responsable: Certificación y Gestión Normativa S.L.U. Finalidad: atender su solicitud y contactarle para ofrecerle la información solicitada. Derechos: acceso, rectificación, portabilidad, supresión, limitación y oposición, así como otros derechos detallados en la información adicional. + info: Puedes encontrar información más detallada en nuestra Política de privacidad.

Or tell us your full case →

Response within 24 h · info@certix.es