Frequently asked questions
Everything you need to know about data protection, our services and how we work at Certix.
Data Protection Consultancy: Need and Risks
Is LOPDGDD and GDPR compliance mandatory for businesses and sole traders?
Yes, without exception. The regulatory framework (GDPR and LOPDGDD) requires any organisation that processes personal information — whether of customers, employees or suppliers — to have a demonstrable compliance system in place. At Certix we transform this legal obligation into added value and a source of trust for your business across Spain.
What risks does my company assume if it is not compliant or uses "free templates"?
The greatest risk today is not a routine AEPD inspection, but third-party complaints, information theft or loss, or cyberattacks. Templates downloaded from the internet or provided by "low-cost" companies lack technical and legal validity because they do not reflect your actual operations. In the event of an incident, relying on generic documentation is not a good position to be in; you need to be able to demonstrate diligence.
Is there any value in the "copy and paste" approach offered by other companies at low prices?
Categorically not. Many "low cost" competitors simply print generic documents without being experts in the regulations. They hand over a dossier and disappear. If your company undergoes an organisational change or the law is updated, you are left entirely unprotected. Data protection requires continuous specialist knowledge, and that is what Certix provides.
Pricing: Expert Consultancy vs. "Low Cost"
Why may Certix's initial fees be higher than a "low cost" service?
Because we do not sell "static paperwork". At Certix you invest in real expert consultancy with specialist professionals who analyse your company from start to finish. You invest in a cutting-edge technology platform, ongoing support and the peace of mind of having the right tools. In regulatory compliance, cheap is always expensive in the long run.
Do I pay the same amount every year? How much does maintenance cost?
No. We understand that in the first year, as we are not yet acquainted with your organisation, we require greater initial analysis and configuration effort. From the second year onwards (the development and update phase), the fee is significantly reduced. This development fee covers use of the platform, continuous technical support, updates in response to regulatory changes and scheduled reviews.
How long does it take for my company to achieve compliance?
It depends on the complexity of your activities, but thanks to our methodology, following an initial data-gathering session and planning meeting with your designated contact (approximately one and a half hours), we put your system in place promptly so your company achieves compliance in the shortest possible time.
My traditional accountant or adviser already handles these matters. Is that sufficient?
Privacy and information security are disciplines requiring a high level of technical expertise. Whilst an accountant specialises in tax or employment matters, at Certix we work exclusively on data protection advisory. We bring a level of specialisation and tools that a conventional accountant typically does not possess.
The Certix Platform: Our True Differentiator
How will we manage data protection on a day-to-day basis?
We work with a powerful, fully automated and self-manageable private cloud platform. As an online environment, we provide consultancy services to SMEs and companies across Spain. You will have a 360° view of your project status, with all your processes centralised and updated in real time.
Can I send and sign documents without using paper?
Yes. Our platform integrates an advanced electronic signature system. You can send contracts, confidentiality commitments or supplier agreements and receive their digital signature with full legal validity. You can also request compliance guarantees from data processors with complete traceability.
If a data subject exercises their rights, how do I handle it?
From the platform. As well as providing you with a specific protocol and training you to comply with it, we have a dedicated module for managing data subject rights (access, erasure, restriction, etc.). You can process the procedure in a guided manner and keep a record of its execution.
Website, E-commerce and LSSI-CE Regulations
In addition to data protection, can you help with regulations for my website or online shop?
Yes. Our service includes advisory and delivery of all documentation required to comply with the Law on Information Society Services and Electronic Commerce (LSSI-CE). We produce fully personalised Legal Notices, Privacy Policies, Terms of Sale (at additional cost) and cookie management tools for your digital environment.
Do you directly implement the cookie notice or legal texts in my website code?
No. We produce the strategy, documentation and technical management tools. This solution is delivered in a ready-to-use package for your web developer or IT team to implement easily in your website code.
Support, Incidents and Legal Responsibilities
How do I contact Certix if I have a query or problem?
Via our integrated incident ticketing system on the platform, by email or by telephone. You can open direct queries with our specialist consultants for technical support without intermediaries or delays.
What should I do in the event of a data security breach?
As well as knowing and applying the protocol, your only initial concern should be to contact us. We will advise you on how to manage and contain the breach, and assist you with any mandatory notifications to the AEPD and affected individuals, where applicable, within the strict period required by law.
Who is legally responsible for implementing the documentation and protocols?
Certix provides you with the best analysis, technology and technical knowledge. However, the data controller (your company) is responsible for validating and putting these measures into practice with its team. Success lies in collaboration: we provide the tools and you integrate them into your daily operations.
Specialist and Advanced Services
Do you offer training for my employees to comply with the regulations?
Yes. The human factor is crucial. Certix has an integrated training feature within its platform that includes PDF training content, multiple-choice assessments, certificate generation and documentary evidence. The most requested programmes cover information security and responsible use of Artificial Intelligence. Priced on a bespoke basis as an independent service.
Does my company need a Data Protection Officer (DPO)?
The DPO role may be mandatory in certain sectors (healthcare centres, schools, security companies, among others), although the precise obligation depends on an individualised analysis of each case. If your activities may require it, we analyse your situation and offer the external DPO service with an independent quote.
What happens if I am going to implement a high-risk technology?
If your new processes pose a high risk to privacy, we assess and prepare the mandatory Data Protection Impact Assessment (DPIA). This is a highly specialist service, quoted on a bespoke basis and separate from the standard consultancy service.
Transparency, Fees and Contract
Are there hidden costs in Certix's service?
Transparency is absolute in our service contract. The proposed cost covers compliance consultancy, documentation preparation, use of the cloud platform, tools and support. Only independent services are quoted separately, such as the external DPO, impact assessments (DPIAs), travel, staff training or major changes to the business model.
What happens to my company's documentation if I end the service?
All information and records generated belong to you. Should you decide at any point to stop working with us, you will be able to export and retain your documentation before the contract ends.
Can't find the answer to your question?
Contact a specialist directly. No salespeople, no waiting.
+34 611 030 124 · info@certix.es