Skip to content

GDPR compliance for companies: avoid fines and protect your business

The General Data Protection Regulation (GDPR), known in Spain as the RGPD (Reglamento General de Protección de Datos), and the Ley Orgánica de Protección de Datos y Garantía de Derechos Digitales (LOPDGDD) impose a compliance framework on Spanish companies that many continue to meet only partially. The Agencia Española de Protección de Datos (AEPD) has significantly stepped up its enforcement activity, with fines ranging from 1,000 euros for minor infringements to 20 million euros or 4% of global turnover for the most serious ones. Many companies have a legal notice on their website but lack a records of processing activities register, have not signed data processing agreements with their suppliers, have not completed the required risk analysis, and do not know how to respond to a data breach.

Since 2010 · 16 years Tax agent AEAT

Pick a slot in the specialist's calendar.

Tell us when to call and a partner will contact you in your chosen window.

Write to us and we'll reply within 24 business hours.

Data processed in the EU · GDPR · No commitment

How we work

From first contact to case completion

  1. Initial compliance audit

    We carry out a full diagnostic of your company's compliance position: we identify all personal data processing operations, assess the legal basis for each treatment, review existing documentation, and quantify compliance gaps together with their associated risk level.

  2. Compliance plan

    We prepare a prioritised action plan organised by risk level to achieve full compliance. We draft or update the privacy policy, sector-specific privacy notices, clauses in employment and client contracts, and the records of processing activities register.

  3. Contractual and technical formalisation

    We draft or review data processing agreements with suppliers that access your client or employee data (payroll advisers, SaaS software providers, external consultants), implement documented technical and organisational measures, and configure the data breach management protocol.

  4. External DPO and ongoing maintenance

    We act as your external Data Protection Officer: point of contact with the AEPD, ongoing advisory on regulatory changes and new processing operations, annual employee training, handling of data subject rights requests, and breach notification within the 72-hour deadline.

Self-check · 45 seconds

Do you need this service?

Answer three questions and we'll show you the most relevant service for your case.

Do you currently reside in Spain?
Do you have assets or income in another country?
Have you received or are you expecting an inheritance?
Are you considering setting up a company?
Answer to see your recommended services.

The problem

The General Data Protection Regulation (GDPR), known in Spain as the RGPD (Reglamento General de Protección de Datos), and the Ley Orgánica de Protección de Datos y Garantía de Derechos Digitales (LOPDGDD) impose a compliance framework on Spanish companies that many continue to meet only partially. The Agencia Española de Protección de Datos (AEPD) has significantly stepped up its enforcement activity, with fines ranging from 1,000 euros for minor infringements to 20 million euros or 4% of global turnover for the most serious ones. Many companies have a legal notice on their website but lack a records of processing activities register, have not signed data processing agreements with their suppliers, have not completed the required risk analysis, and do not know how to respond to a data breach.

Our solution

BMC offers a comprehensive service for the initial adaptation and ongoing maintenance of data protection compliance for companies of all sizes. We analyse all personal data processing operations carried out by your company, document the records of processing activities register, draft or review privacy notices and information clauses, formalise data processing agreements, and, where your business requires it, act as external Data Protection Officer (DPO) with formal notification to the AEPD.

Process

How we do it

1

Initial compliance audit

We carry out a full diagnostic of your company's compliance position: we identify all personal data processing operations, assess the legal basis for each treatment, review existing documentation, and quantify compliance gaps together with their associated risk level.

2

Compliance plan

We prepare a prioritised action plan organised by risk level to achieve full compliance. We draft or update the privacy policy, sector-specific privacy notices, clauses in employment and client contracts, and the records of processing activities register.

3

Contractual and technical formalisation

We draft or review data processing agreements with suppliers that access your client or employee data (payroll advisers, SaaS software providers, external consultants), implement documented technical and organisational measures, and configure the data breach management protocol.

4

External DPO and ongoing maintenance

We act as your external Data Protection Officer: point of contact with the AEPD, ongoing advisory on regulatory changes and new processing operations, annual employee training, handling of data subject rights requests, and breach notification within the 72-hour deadline.

72h
Deadline to report a data breach
20M€
Maximum GDPR fine
100%
Clients without AEPD sanction

We were receiving data subject rights requests and did not know how to handle them. BMC carried out the audit, updated all our documentation, and now acts as our external DPO. We no longer live in constant fear of a sanction, and the team knows exactly how to respond. (anonymised case)

Patricia Llorente HR Director, Multiservices Llorente SL

The GDPR in Spain: current regulatory framework

The General Data Protection Regulation (GDPR), directly applicable in Spain since May 2018, operates alongside the Ley Orgánica de Protección de Datos y Garantía de Derechos Digitales (LOPDGDD), adopted in December 2018, which adapts the GDPR to the Spanish legal system and introduces specific provisions on employment, minors, and new technologies.

The Agencia Española de Protección de Datos (AEPD) is the supervisory authority in Spain and has demonstrated increasingly active enforcement in recent years. Spanish companies have been fined for practices as common as using cookies without valid consent, failing to delete former employees’ data, or transferring data to third countries without adequate safeguards.

Most common data processing activities in Spanish companies

Almost all companies, regardless of size or sector, carry out personal data processing that requires GDPR compliance:

  • Employee data: Payroll management, attendance monitoring, video surveillance, use of corporate devices, internal communications.
  • Client data: CRM, invoicing, purchase histories, commercial communications, satisfaction surveys.
  • Supplier and contact data: Contact directories, business card exchanges, business communications.
  • Website data: Cookies, contact forms, user registration, online shops, chatbots.

The role of the external DPO

The Data Protection Officer (DPO) is the key figure in the GDPR compliance system. The DPO’s functions include informing and advising the controller and employees, supervising regulatory compliance, cooperating with the supervisory authority, and acting as the point of contact with the AEPD.

The external DPO offers the same advantages as an internal one — specialised expertise, independence, and access to up-to-date regulatory information — without the cost of a full-time hire. It is the most efficient solution for the majority of small and medium businesses.

International data transfers

If your company uses cloud services from US providers (Google Workspace, Microsoft 365, Salesforce, AWS, etc.), you are carrying out international transfers of personal data to third countries. Since the invalidation of the Privacy Shield in 2020 and the adoption of the EU-US Data Privacy Framework in 2023, the legal framework for these transfers has changed. BMC advises on the appropriate safeguards to implement for each provider and region.

Article 6 GDPR establishes six legal bases that can legitimise the processing of personal data: consent from the data subject; performance of a contract to which the data subject is party; compliance with a legal obligation; protection of vital interests; performance of a task carried out in the public interest; and the legitimate interests of the controller or a third party, provided these do not override the rights of the data subject.

Choosing the correct legal basis for each processing operation is one of the most important decisions in the GDPR adaptation process. Selecting consent as the legal basis when it is not appropriate is one of the most frequent errors: consent must be freely given, specific, informed, and unambiguous, and the data subject has the right to withdraw it at any time. If the processing is necessary to perform a contract with the data subject (for example, processing a client’s billing data), the correct basis is performance of the contract, not consent. Requesting consent when the applicable basis is contract performance creates a false expectation that the data subject can oppose the processing by withdrawing consent, when in reality the processing is necessary for the contractual relationship.

For employee data processing, the primary legal basis is legal obligation (the Estatuto de los Trabajadores and labour legislation require the company to process certain data) and performance of the employment contract, supplemented by legitimate interest in some cases (video surveillance within limits, access controls). Employee consent is not a valid legal basis for processing tied to the employment relationship, given that the power imbalance makes that consent unfree.

Special category data: the enhanced protection regime

Article 9 GDPR establishes an enhanced protection regime for certain categories of personal data whose processing is prohibited as a general rule, unless one of the specific exceptions applies: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used to uniquely identify a person, health data, and data concerning a person’s sex life or sexual orientation.

In the business context, the most frequent processing of special category data involves: employee health data in the context of managing sick leave or temporary incapacity (the company may process the fact of the absence, but not the diagnosis); biometric data in fingerprint or facial recognition attendance systems (requires a Data Protection Impact Assessment and a specific legal basis, generally explicit consent or necessity for managing the employment relationship under a collective agreement); and trade union membership data in the context of salary deductions for union dues.

The Data Protection Impact Assessment (DPIA), known in Spanish as Evaluación de Impacto de Protección de Datos (EIPD), is mandatory when the processing involves large-scale special category data, large-scale systematic monitoring of a publicly accessible area, or systematic evaluation of individuals through profiling. The DPIA must be carried out before processing begins and must include a description of the processing, an assessment of its necessity and proportionality, an assessment of the risks, and the measures to address them.

Data breach management: the 72-hour protocol

Article 33 GDPR imposes the obligation to notify the supervisory authority (the AEPD in Spain) of any personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, within 72 hours of the controller becoming aware of it.

The data breach management process must follow an established protocol: detection and containment (isolate the affected systems, prevent the incident from spreading); impact assessment (what data has been affected, how many individuals, what probability of harm to those affected); notification to the AEPD if risk is likely (via the system provided on the AEPD website, including at minimum the nature of the breach, the categories of data affected, the approximate number of data subjects, and the measures taken); and communication to the data subjects if the risk is high (for example, where there is risk of identity theft, financial loss, or reputational harm to those affected).

Failure to meet the 72-hour deadline, failing to notify breaches that should have been notified, or providing incorrect or incomplete notification are infringements sanctionable by the AEPD. BMC acts as the point of contact with the AEPD in data breaches and manages the complete protocol from detection through to resolution of the incident.

International data transfers: the post-Schrems II framework

Regulation EU 2016/679 provides that personal data may only be transferred to third countries that offer a level of protection equivalent to that of the EU. Following the CJEU ruling in Schrems II (July 2020), which invalidated the EU-USA Privacy Shield, the principal mechanism for transfers to the United States and other countries without an adequacy decision is the Standard Contractual Clauses (SCCs), known in Spanish as Cláusulas Contractuales Tipo (CCT), adopted by the European Commission.

Spanish companies using cloud services from US providers (Google Workspace, Microsoft 365, Salesforce, AWS, Zoom, Slack, HubSpot, etc.) are carrying out international transfers of personal data relating to their employees, clients, and contacts. In most cases these providers offer the SCCs as the transfer mechanism, but the Spanish company is responsible for verifying that the provider has the SCCs signed and updated (the SCCs were updated in 2021) and for carrying out a Transfer Impact Assessment (TIA) to evaluate whether the legislation of the destination country allows authorities to access data in a way that is incompatible with the rights of European data subjects.

The approval of the EU-US Data Privacy Framework in July 2023 offers an additional transfer mechanism for US companies that self-certify under the framework, equivalent to the former Safe Harbor and Privacy Shield. However, the legal robustness of the framework is contested and may be subject to further challenges before the CJEU. BMC advises on the most appropriate transfer mechanism for each provider and updates clients’ international transfer documentation when the regulatory framework changes.

Records of processing activities: the backbone of GDPR compliance

The records of processing activities (RoPA), known in Spanish as the registro de actividades de tratamiento (RAT), is the central document of the GDPR compliance system for data controllers. Article 30 GDPR requires each controller to maintain a written record (on paper or in electronic format) of all processing activities under their responsibility.

For each processing activity, the RoPA must include: the name and contact details of the controller and, where applicable, the DPO; the purposes of the processing; a description of the categories of data subjects and personal data; the categories of recipients; transfers to third countries; data retention periods; and the technical and organisational security measures in place. The RoPA is not a document prepared once and then forgotten: it must be updated whenever a new processing activity is introduced, when the purpose or legal basis of an existing activity changes, or when there is a change of supplier or technological system. BMC maintains an up-to-date RoPA for its clients and reviews it on a semi-annual basis.

FAQ

Frequently asked questions

The main obligations are: having a legitimate legal basis for each data processing operation (consent, contract, legal obligation, legitimate interest...); informing data subjects clearly about processing activities; maintaining a Records of Processing Activities register; applying technical and organisational measures proportionate to the risk; formalising data processing agreements with processors; establishing a procedure for handling data subject rights requests; and notifying data breaches to the AEPD within 72 hours.
The appointment of a DPO is mandatory for public authorities, for companies carrying out large-scale processing of special category data (health, political opinions, ethnicity...) or conducting large-scale systematic monitoring of individuals. For other companies it is not mandatory, but it is strongly recommended, as the DPO serves as the point of contact with the AEPD and the internal reference on all privacy matters.
Sanctions fall into two tiers: minor and serious infringements carry fines of up to 40,000 euros for individuals and up to 300,000 euros for legal entities under the LOPDGDD. The most serious infringements (those governed directly by the GDPR) can reach 20 million euros or 4% of annual global turnover, whichever is higher. The AEPD has imposed multi-million euro fines on large companies and fines of thousands of euros on small and medium businesses.
A security breach is any incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. The most common examples are: cyberattacks that expose client databases, emails containing personal data sent to the wrong recipient, the loss of a laptop holding client or employee information, or the accidental publication of personal data on a website. Following a breach, the company has 72 hours to notify the AEPD if the incident poses a risk to the individuals affected.
Data subjects hold the right of access, rectification, erasure, objection, restriction, and portability. Requests must be addressed within one month of receipt, extendable by two additional months for complex cases. The company must have a designated channel for receiving requests, verify the identity of the person making the request, respond within the deadline, and keep a record of all requests received and responses given.
You need data processing agreements with all suppliers that process personal data on your behalf: the payroll adviser managing your salaries, your CRM provider, the cleaning company that accesses your premises, your cloud backup service, the marketing agency sending emails in your name... These agreements must cover the purpose of the processing, the type of data, the security measures in place, and the processor's obligations in the event of a breach.

Speak with a specialist

Complimentary first call. No commitment. Response within 1 hour during office hours.

Free first consultation 30 minutes with a specialist in your area
Fixed quote before we start No surprises, no success fees
Registered tax agent Electronic filing of all tax returns

4.8/5 · Data processed in the EU · GDPR · No commitment

Frequently asked questions

Questions about Data Protection for Companies (GDPR) | BMC

The main obligations are: having a legitimate legal basis for each data processing operation (consent, contract, legal obligation, legitimate interest...); informing data subjects clearly about processing activities; maintaining a Records of Processing Activities register; applying technical and organisational measures proportionate to the risk; formalising data processing agreements with processors; establishing a procedure for handling data subject rights requests; and notifying data breaches to the AEPD within 72 hours.
The appointment of a DPO is mandatory for public authorities, for companies carrying out large-scale processing of special category data (health, political opinions, ethnicity...) or conducting large-scale systematic monitoring of individuals. For other companies it is not mandatory, but it is strongly recommended, as the DPO serves as the point of contact with the AEPD and the internal reference on all privacy matters.
Sanctions fall into two tiers: minor and serious infringements carry fines of up to 40,000 euros for individuals and up to 300,000 euros for legal entities under the LOPDGDD. The most serious infringements (those governed directly by the GDPR) can reach 20 million euros or 4% of annual global turnover, whichever is higher. The AEPD has imposed multi-million euro fines on large companies and fines of thousands of euros on small and medium businesses.
A security breach is any incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. The most common examples are: cyberattacks that expose client databases, emails containing personal data sent to the wrong recipient, the loss of a laptop holding client or employee information, or the accidental publication of personal data on a website. Following a breach, the company has 72 hours to notify the AEPD if the incident poses a risk to the individuals affected.
Data subjects hold the right of access, rectification, erasure, objection, restriction, and portability. Requests must be addressed within one month of receipt, extendable by two additional months for complex cases. The company must have a designated channel for receiving requests, verify the identity of the person making the request, respond within the deadline, and keep a record of all requests received and responses given.
You need data processing agreements with all suppliers that process personal data on your behalf: the payroll adviser managing your salaries, your CRM provider, the cleaning company that accesses your premises, your cloud backup service, the marketing agency sending emails in your name... These agreements must cover the purpose of the processing, the type of data, the security measures in place, and the processor's obligations in the event of a breach.
Email
Contact