What we do
- We review what data your business processes and on what legal basis, and prepare the record of processing activities.
- We draft privacy policies, legal notices, cookie policies and data processing agreements.
- We exercise your rights of access, rectification, erasure, objection, restriction and portability against whoever holds your data.
- We assist you with a security breach, including notification to the Spanish DPA within 72 hours where required.
- We file and answer complaints before the Spanish Data Protection Agency.
- We review technology contracts: software development, hosting, cloud services and terms of use.
What people usually bring us
- A letter from the Spanish Data Protection Agency that nobody knows how to answer.
- A business that has just opened and needs its website and forms in order.
- Personal data published online that should not be there.
- A technology supplier holding on to the company’s information.
Complying with data protection rules does not prevent an incident, and no firm can promise that a penalty will not arrive. What the preparatory work does change is the position you answer from: a company that can evidence what it did and when is not in the same place as one with nothing in writing.