Service · Cybersecurity

GDPR and personal data protection

The GDPR asks for “appropriate technical and organisational measures” and leaves each controller to work out what that means. In a Spanish SME the question tends to reach IT through the back door: a customer exercises her right of access and nobody knows how many systems hold her details, the AEPD asks for an explanation after a complaint, or a dental clinic in Seville discovers that a report containing health data went out by email to the wrong address. Our part is the technical side of compliance: finding where personal data actually lives, deciding who can see it, recording every access and getting the business ready for the first hours of a breach. Legal analysis and contract wording stay with your data protection officer (DPD) or your lawyer; we give their work a real, checkable foundation.

Art. 32
of the GDPR turned into settings
72 h
to notify a breach to the AEPD
Named accounts
not a single shared login
Remote
with no pause to daily work

What falls within the scope of this service

Protecting clinical records is a different job from protecting a newsletter list. We size the work to the category and volume of the data, and we do not build defences the actual risk does not call for.

Pin down the details with one of our engineers

Personal data inventory

We walk through the places where data really sits: the payroll system, the CRM, SharePoint and OneDrive, server file shares, mailboxes and the Excel exports left on laptops. The result feeds straight into your record of processing activities, which often describes systems nobody uses any more.

Role-based permissions

We check who can open what. Reception has no need for payslips and the sales team has no need for the sick-leave folder. Permissions are granted through groups in Entra ID or Google Workspace rather than person by person.

No more shared accounts

Logins such as “reception” or “admin”, with the password taped to the monitor, give way to named accounts with multi-factor authentication. Every access to a record then has an identifiable owner.

Traceability

We switch on the Microsoft 365 audit log and file-access auditing on the server, with retention long enough to work out who opened a file weeks after the event.

Data subject rights

We prepare the technical side of handling an access, erasure or portability request within the one-month deadline: content searches in Microsoft Purview, CRM exports and a checklist of systems to look in.

Joiners and leavers

A procedure agreed with HR so that access ends on the last day of employment, including cloud services outside the directory such as the recruitment portal or Factorial.

Breach plan

A one-page sheet for the first hours: who assesses the incident, how the DPD is told, which logs are frozen and what information the person drafting the AEPD notification will need.

How the engagement unfolds, one stage at a time

We start with whatever removes the most risk for the least effort. The longer projects come once the basics are in place.

01

Assessment

A video call with whoever is responsible for data protection, or with the DPD, followed by a remote review of your environment. You receive a list of systems holding personal data and how well each one is protected today.

02

Quick fixes

Accounts of former staff, shared logins and sign-ins without a second factor disappear in the first few days. It costs little and the effect is immediate.

03

Technical measures

Laptop encryption, audit logging, a proper permission structure and limits on external sharing, rolled out in groups so nobody is blocked.

04

Written description

We hand over the list of technical measures in place, written so it can be added to your record of processing and to the documentation the AEPD would look at during an inspection.

The AEPD does not ask whether you have antivirus; it asks whether you can prove what you did. After a complaint or a breach, what counts is the trail: who had access, since when, which log shows it and when it was last reviewed. Correct settings with no evidence carry barely more weight than none at all, which is why every measure we apply is recorded with its date.

Common questions

With the systems listed in the inventory: ERP, CRM, email, shared folders and backups. In Microsoft 365 a content search finds messages and documents containing her name or DNI in minutes; the ERP needs an export of her record. You have one month to reply, extendable for complex cases, and your DPD or adviser should check the answer before it goes out.

Within the European Union there is no international transfer to worry about. Microsoft, Google and AWS let you pin regions in Spain or elsewhere in the EU, and European providers such as OVHcloud, Arsys or IONOS make it simple. We check where your services really keep the data; reviewing data processing agreements is a job for your DPD or lawyer.

Write straight away to support@apply.es, or to helpme@apply.es if you have a contract with Apply. We try to recall the message, freeze the logs and gauge the scope. With that information your DPD decides whether the AEPD must be notified within 72 hours and whether the people affected need to be told. The legal judgement is theirs, not IT's.

They are processors, and Article 28 of the GDPR requires a contract with each of them. On the technical side we check what access they really have to your systems, whether they use named accounts with MFA and where they keep the information. If a supplier logs in through a shared account or without MFA, that is the first thing to fix.

It depends on what you process and at what scale; Article 34 of the LOPDGDD lists specific cases such as healthcare providers and schools. It is a legal decision best taken with an adviser. If you already have a DPD, in-house or external, we work with them directly and supply the technical detail they need, including for a data protection impact assessment (EIPD).

Get your personal data in order

Tell us which systems hold customer and staff data. We will reply with a first view of the weak spots we usually find in organisations like yours.

Hours
Monday to Friday, 9:00-18:00 Spanish time (CET), answers within a working day
Meetings
Video calls via Google Meet or Teams

This site only stores the cookies it needs to work and to remember your chosen city. No advertising or tracking cookies are set. See our privacy policy for the details.