When a breach happens, the notification form of the AEPD, Spain's data protection authority, asks very specific things: which data were affected, how many people, since when and what has been done about it. Plenty of firms have a privacy notice on the website and a processing register drawn up by their gestoría, yet cannot answer those questions within 72 hours, because nobody really knows what sits in the mailboxes, the shared folders and the management software. Apply is neither a legal practice nor anyone's DPO, and the legal calls belong to those professionals. Apply makes sure your systems do what your documents claim, and that you can prove it.
in which a personal data breach must reach the AEPD
1 month
standard deadline to answer a data subject request
€75
per hour + VAT outside a support plan
100 %
of the review and the fixes carried out remotely
What the work covers
The split is simple. Anything decided with the regulation open on the desk (lawful basis, retention, privacy wording) is settled by your DPO or legal counsel. Anything configured on a laptop, in Microsoft 365 or on a server is checked and fixed by Apply.
We trace personal data through the ERP and CRM, every Outlook mailbox, network shares, website forms, A3nom or Factorial, and those exported spreadsheets that end up on someone's desktop. What turns up feeds the processing register, and frequently corrects it.
A register of processors
Everyone handling data on your behalf: the gestoría, the email marketing tool, the web shop host, the e-signature platform, the payroll provider and Apply itself. Each entry records what they handle and from which country, so your adviser knows which processing agreement to check.
Technical risks for the DPIA
What can genuinely go wrong: patient records on an unencrypted laptop, cameras still on their factory password, fleet tracking visible to the whole office, a former supplier who can still log in. Should your data protection officer judge that an impact assessment is required, these findings are its raw material.
Controls applied from a distance
Two-factor sign-in on every account, drives encrypted through Intune, Entra ID roles in place of a shared “admin” login, Microsoft 365 sensitivity labels plus leak-prevention rules, and sign-in logs kept for the period your policy sets. Apply follows ISO 27001 principles without claiming any certification.
Breaches and data subject rights
A procedure spelling out who alerts whom, with which facts, when something goes wrong, built so that the decision to notify can be made inside 72 hours. Plus the technical route to find, export or erase one person's data across all your systems before the response deadline runs out.
One hour of staff training
Delivered over video and built on your own daily situations: a bogus bill that seems to come from a regular supplier, what must never be pasted into a public AI chat, why payslips are not forwarded to personal email, and what to do in the first ten minutes after a message is sent to the wrong recipient.
Four steps, no endless audit
Cheap and urgent comes first. Disabling a former employee's live account usually does more good than buying another product.
01
Kick-off with read-only access
A video call with the person responsible for data protection, plus read-only access to Microsoft 365 or Google Workspace, servers and devices. Nothing is changed at this stage; we only observe.
02
Findings in plain language
Which data exists and where, who handles it for you and what is missing, each point with a priority and an estimate in hours. Your DPO can lift sections unchanged into the processing register or the DPIA.
03
Quick, cheap wins first
Two-factor sign-in, orphaned accounts and public links are dealt with in the opening days. Encryption, labels and DLP follow on fixed dates, outside office hours whenever they interrupt a service.
04
A fresh look whenever something changes
A new tool, a new processor or the departure of someone with broad permissions all trigger a review of the inventory, on top of the annual one. Configuration screenshots are kept as evidence.
Suppose a sales rep at a Valencia distributor has a laptop stolen from the car. If the drive was encrypted with BitLocker and the recovery key is safe in Entra ID, the risk assessment for the customers whose data it held looks completely different. If it was not, your DPO will have to consider notifying the AEPD and possibly the people affected. The gap between those two outcomes is one Intune policy that takes an afternoon to roll out.
Common questions
No. A data protection officer needs expertise in data protection law and practice, and Apply is a technical company. What it does is work hand in hand with your DPO or lawyer: supplying the real inventory, answering their technical questions and implementing the controls they decide on. If you have nobody, you will hear that frankly, along with a suggestion to hire someone qualified for the legal work.
That depends on your activity. On top of the GDPR cases, Article 34 of the LOPDGDD lists sectors that must appoint one, among them schools, healthcare centres, insurers and financial institutions. A lawyer gives the answer for your situation. With or without a DPO, the regulation binds you regardless, and Apply works with whoever handles the topic: management, administration or HR.
Yes. Managing your machines remotely gives Apply a view into personal data, so legally it acts as a processor. The agreement can be yours or one Apply proposes, and it sets out the scope of access, any sub-processors, the security measures and the deadline for Apply to report an incident to you, so the 72-hour clock is not wasted chasing a supplier.
Write immediately to support@apply.es, or to helpme@apply.es if you are under contract. Technically it is possible to try recalling the message in Microsoft 365, revoke shared links, lock the account and use the logs to reconstruct who opened what and when. The decision to notify the AEPD through its online portal and to inform those affected belongs to the controller together with the DPO, but it will be taken with those facts to hand.
With a procedure prepared before the request arrives: where to look (ERP, CRM, email, web shop, newsletter tool, backups), who does it and how it is recorded. Whatever the law obliges you to keep, such as invoices, is blocked rather than deleted; your adviser confirms the details. Apply writes the procedure down and proves it works with a dummy case.
For a small company with low-risk processing it is a sound starting point and produces useful documents. But it is a questionnaire: it does not check whether laptops are encrypted, whether a former employee can still open the mailbox or whether backups can be restored. Apply verifies exactly those things and fixes what is missing, so the two complement each other.
Rarely at the outset. Microsoft 365 Business Premium already bundles Intune, conditional access, sensitivity labels and DLP, and many firms pay for it without switching those on. The review is billed at €75 per hour + VAT with the scope agreed in advance, or sits inside a Start, Business or Premium plan. Any purchase has to be backed by a specific finding.
Tell us what data you handle, in which programs and who looks after the topic today. We will reply with a review proposal and the questions worth putting to your DPO beforehand.
Hours Monday to Friday, 9:00-18:00 Spanish time (CET), answers within a working day
Meetings Video calls via Google Meet or Teams
Your request is with us
Expect an answer within one working day. A reported fault that has halted your team is handled first.
We clarify the brief. If a detail is missing before we can price the work, we email you or suggest a quick Google Meet or Teams session.
We draft a proposal. The scope of work, a price in euros with VAT shown separately and a realistic start date, with no small print.
The choice is yours. The proposal arrives by email. Read it at leisure, query any line you like and only then decide.
Choose a location
No match found. Try another spelling, or go with the closest provincial capital: every job is done remotely, so the location makes no difference to what we deliver anywhere in Spain.
This site only stores the cookies it needs to work and to remember your chosen city. No advertising or tracking cookies are set. See our privacy policy for the details.