Solicitor in Torrox, Nerja, Torre del Mar & the Axarquía

Professionals and companies · Data protection

Data protection for businesses and the self-employed in the Axarquía

If your business handles data on customers, suppliers or employees, and almost every business does, I help you comply with data protection law without unnecessary complications. I review what data you process and why, prepare the documents you need and explain what to do day to day. That gives you peace of mind, and your customers too.

  • 4.8 · 50+ Google reviews
  • Málaga Bar member no. 8,108
  • 10+ years’ experience
A laptop with a padlock and filing cabinets holding customer records in an office

What’s included

What I do for you

  • Initial assessment

    I review what data you collect, through which channels, for what purpose and who you share it with.

  • Record of processing activities

    I prepare the document describing each use you make of personal data, as the GDPR requires.

  • Privacy notices and consent

    I draft the wording for forms, contracts, invoices, your website and marketing emails.

  • Contracts with suppliers

    I review or draft data processing agreements with your gestoría (administrative agency), IT provider, web host or other suppliers.

  • CCTV

    I tell you how to install and signpost cameras on your premises in line with the law and the rights of customers and employees.

  • Individuals’ rights

    I help you respond to requests for access, rectification, erasure or objection within the legal deadline.

  • Data breaches

    If you lose data or suffer an attack, I advise you on whether and how you must notify the Agencia Española de Protección de Datos (the Spanish Data Protection Agency).

  • AEPD requests

    I prepare your response if the Agency asks you for information following a complaint.

Sound familiar?

Situations where I can help

Tell me about your case
  • You have a shop or a restaurant and want to know whether your security cameras comply with the law.
  • You are about to send offers to your customers by email or WhatsApp and do not know whether you need their consent.
  • A clinic, gym or school you own processes health data or data on minors.
  • A customer asks you to delete all their data and you do not know what you can keep.
  • The business laptop holding your customer database has been stolen.
  • You have received a letter from the Spanish Data Protection Agency about a complaint.

How I work

Step by step, no surprises

  1. Initial consultationYou explain your business and how you handle data. Online, by video call or in person.
  2. AssessmentI identify what processing you carry out, what risks it involves and what documents or measures you are missing.
  3. Bringing you into lineI prepare the wording, contracts and records, and explain what to change in the way you work.
  4. UpkeepWe review your compliance when you change activity or suppliers, on a one-off basis or as part of my ongoing advice service.

Even if you think not, you process personal data

You may think that, given the kind of business you run, you do not handle sensitive data on customers or suppliers. But at the very least you need their name, tax identification number and address to issue or receive invoices. That is already personal data, and holding it obliges you to protect it and to meet a series of duties towards the people concerned and the authorities.

Depending on your business, you may end up processing much more private information: health data, criminal records, family relationships, sexual orientation or religious beliefs. The law calls most of these special categories of data and requires greater care in processing them.

Which rules apply

This area is constantly evolving, always towards stricter requirements for the self-employed and businesses. Today the foundation is the General Data Protection Regulation (GDPR), a European Union regulation that has applied directly since May 2018 and replaced the regime of the old Spanish law of 1999. In Spain it is supplemented by Ley Orgánica 3/2018, de Protección de Datos Personales y garantía de los derechos digitales (LOPDGDD, the Spanish Data Protection and Digital Rights Act).

If you have a website or online shop, or send marketing by email or messaging apps, the Ley de Servicios de la Sociedad de la Información (LSSI, the Spanish Information Society Services Act) also applies. Among other things, it regulates cookies and advertising messages.

The obligations are not the same for everyone. They are stricter the larger the volume of data, the more sensitive it is, and depending on the channels through which you collect it and what you use it for.

The basic obligations

  • Have a legal basis for each use of the data: a contract, a legal obligation, consent or a well-justified legitimate interest.
  • Inform people of who processes their data, for what purpose, for how long and how to exercise their rights.
  • Keep a record of processing activities. Small businesses have an exemption, but it does not apply when processing is regular, which in practice covers almost any business with customers or employees.
  • Sign contracts with your processors, meaning the suppliers that access data on your behalf, such as your gestoría or IT service.
  • Apply security measures appropriate to the risk and notify the Spanish Data Protection Agency of any breaches that pose a risk to individuals, within 72 hours.
  • Respond to requests to exercise the rights of access, rectification, erasure, objection, restriction and portability, as a general rule within one month.

Do you need a data protection officer?

The data protection officer is the person who oversees compliance within the organisation. Whether you need one depends less on the size of the business than on its activity. The GDPR requires one, among other cases, when the core activity consists of processing special categories of data on a large scale or regularly and systematically monitoring individuals. The LOPDGDD adds a list of sectors that must appoint one, such as healthcare centres, schools, insurers, financial institutions and private security firms. I tell you whether this applies to you.

Situations with rules of their own

CCTV cameras, monitoring employees and their use of digital devices, and sending advertising all have specific rules. For example, camera footage must be deleted within one month at most, unless it is needed to prove a serious incident, and cameras must be signposted with an information sign.

If your collaborators access your customers’ data, also review your contracts with collaborators. And if you want me to keep everything up to date on an ongoing basis, I can include it in the comprehensive legal advice service.

Would you like an online consultation?

Get an online consultation for just €75

Book your consultation
  1. Book the consultation€75 including VAT. Pay by debit or credit card or Bizum.
  2. Explain your questionTell me about your case in writing and attach any related documents.
  3. Receive the answerBy email, grounded in Spanish law, within 12 to 72 working hours.

Frequently asked questions

What people ask me most

Can’t find your answer?

If your question isn’t here, write to me or give me a call.

Does a self-employed person have to comply with data protection law?

Yes, if they process data on individuals in the course of their business, such as customers, self-employed suppliers or employees. Simply holding their names, phone numbers or addresses is enough. The obligations are adapted to the volume and sensitivity of the data, but informing people, applying security measures and respecting their rights apply to everyone.

Can I send advertising to my customers by email or WhatsApp?

It depends. By email and equivalent means, the law generally requires the recipient’s prior consent. There is an exception for existing customers, if you offer them products or services similar to those they bought from you and give them a simple way to unsubscribe. It is worth checking how you collected their details.

What do I have to do if I install cameras on my premises?

You must put up a visible information sign, record only what is necessary for security and not capture the public street beyond what is strictly essential. Footage must be deleted within one month at most, unless it proves a serious incident. If the cameras affect employees, you must inform them beforehand. I help you check all this.

What happens if I suffer a data breach?

If the loss, theft or unauthorised access to data poses a risk to individuals, you must notify the Spanish Data Protection Agency within 72 hours of becoming aware of it. If the risk is high, you must also inform the people affected. You must also document every breach, even if it does not need to be notified.

How much does it cost to check whether my business complies?

You can start with a written online consultation for €75 including VAT, with a reply within 12 to 72 working hours, or a 30-minute video call for €75. I also see clients by appointment in Torrox Costa and Nerja. Afterwards I explain what would be needed to bring your business into line.

Contact

Any questions? Get in touch

Tell me about your case and I will call you back within 24 working hours. You can also message me on WhatsApp or visit one of the offices by appointment.

Send me a message

Tell me briefly what it is about and I will call you back within 24 working hours.

Prefer a written answer? Online consultation, €75 · or email diego@montosa-abogado.com

Montosa Abogado

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.