The GDPR is not red tape.
It is your clients' trust.

Genuine GDPR compliance protects your company from multi-million fines and builds credibility with clients and partners who increasingly demand demonstrable compliance.

Free GDPR audit WhatsApp

Full compliance with the
GDPR and the LOPDGDD

We do not sell off-the-shelf documentation. We deliver genuine compliance tailored to your company: we audit what data you process, how and why, and build your compliance system from the ground up.

  • Audit of personal data processing
  • Record of Processing Activities (ROPA)
  • Risk analysis and data protection impact assessment (DPIA)
  • Tailored website privacy policy
  • Privacy notices for forms, apps and HR
  • Data processor agreements (DPA)
  • Confidentiality clauses for employees
  • Security breach response protocol
  • External Data Protection Officer (DPO)
  • Team training and annual updates

What the AEPD fines
companies for most

01

Cookies without valid consent

Banners that do not allow rejection, or that pre-tick boxes by default. Typical fines for SMEs range from 5,000 to 50,000 euros.

02

CCTV without notice

Cameras on premises or in car parks without an information sign or covering an excessive recording area. One of the most recurrent penalties for retailers.

03

Marketing communications without a legal basis

Sending advertising emails or SMS without express consent or without a simple opt-out. The LSSI (Spanish Information Society Services Act) adds fines on top of the GDPR.

04

Transfers to the US without safeguards

Using cloud services (Google Workspace, HubSpot, etc.) without updating your contracts under the EU-US framework. The AEPD is active on this front.

05

Unreported security breach

Failing to notify the AEPD within 72 hours of a breach affecting the rights of individuals doubles the penalty. Having a protocol in place is mandatory.

06

No agreements with processors

Outsourcing services that process client data (accountancy, cloud, CRM) without a signed data processor agreement is a serious infringement.

Data Protection Officer
as a service

Some companies are required to appoint a DPO. Others do so voluntarily. We offer an external DPO service with real availability and incident response.

Point of contact with the AEPD

We act as your official representative before the AEPD (Spanish Data Protection Agency) in any notification, enquiry or proceedings.

Handling data subject requests

We respond within the legal deadline (1 month) to requests for access, rectification, erasure, objection, portability and restriction of processing.

Annual review

We audit compliance every year to identify new processing activities, changes in providers and regulatory updates that affect your company.

Common questions
about the GDPR

What obligations does my company have under the GDPR?
It must keep a record of processing activities, carry out risk analyses and guarantee users' rights of access, rectification and erasure.
Do I need a data protection officer (DPO)?
It is only mandatory for public bodies or companies that process data on a large scale or handle special categories of data.
What legal texts does my website need?
The Legal Notice (identification), the Privacy Policy (data processing) and the Cookie Policy (technical consent) are mandatory.
What does a data protection audit involve?
It is an in-depth review of how your company collects, stores and uses data, to detect security gaps and ensure legal compliance.
What penalties can non-compliance with the GDPR bring?
Fines can reach up to 20 million euros or 4% of the company's total annual worldwide turnover.

We audit your current situation
with no obligation and at no cost.

An initial 30-minute audit lets us identify your critical risk points and propose a compliance plan with a real price, not an estimate.

Request a free audit Direct WhatsApp
Let's talk