The GDPR is not red tape.
It is your clients' trust.
Genuine GDPR compliance protects your company from multi-million fines and builds credibility with clients and partners who increasingly demand demonstrable compliance.
Full compliance with the
GDPR and the LOPDGDD
We do not sell off-the-shelf documentation. We deliver genuine compliance tailored to your company: we audit what data you process, how and why, and build your compliance system from the ground up.
- Audit of personal data processing
- Record of Processing Activities (ROPA)
- Risk analysis and data protection impact assessment (DPIA)
- Tailored website privacy policy
- Privacy notices for forms, apps and HR
- Data processor agreements (DPA)
- Confidentiality clauses for employees
- Security breach response protocol
- External Data Protection Officer (DPO)
- Team training and annual updates
What the AEPD fines
companies for most
Cookies without valid consent
Banners that do not allow rejection, or that pre-tick boxes by default. Typical fines for SMEs range from 5,000 to 50,000 euros.
CCTV without notice
Cameras on premises or in car parks without an information sign or covering an excessive recording area. One of the most recurrent penalties for retailers.
Marketing communications without a legal basis
Sending advertising emails or SMS without express consent or without a simple opt-out. The LSSI (Spanish Information Society Services Act) adds fines on top of the GDPR.
Transfers to the US without safeguards
Using cloud services (Google Workspace, HubSpot, etc.) without updating your contracts under the EU-US framework. The AEPD is active on this front.
Unreported security breach
Failing to notify the AEPD within 72 hours of a breach affecting the rights of individuals doubles the penalty. Having a protocol in place is mandatory.
No agreements with processors
Outsourcing services that process client data (accountancy, cloud, CRM) without a signed data processor agreement is a serious infringement.
Data Protection Officer
as a service
Some companies are required to appoint a DPO. Others do so voluntarily. We offer an external DPO service with real availability and incident response.
Point of contact with the AEPD
We act as your official representative before the AEPD (Spanish Data Protection Agency) in any notification, enquiry or proceedings.
Handling data subject requests
We respond within the legal deadline (1 month) to requests for access, rectification, erasure, objection, portability and restriction of processing.
Annual review
We audit compliance every year to identify new processing activities, changes in providers and regulatory updates that affect your company.
Common questions
about the GDPR
What obligations does my company have under the GDPR?
Do I need a data protection officer (DPO)?
What legal texts does my website need?
What does a data protection audit involve?
What penalties can non-compliance with the GDPR bring?
We audit your current situation
with no obligation and at no cost.
An initial 30-minute audit lets us identify your critical risk points and propose a compliance plan with a real price, not an estimate.
