{"id":6396,"date":"2020-12-28T13:35:28","date_gmt":"2020-12-28T12:35:28","guid":{"rendered":"https:\/\/edorteam.com\/consultancy-of-adaptation-to-the-rgpd\/"},"modified":"2026-05-04T17:32:29","modified_gmt":"2026-05-04T15:32:29","slug":"consultancy-of-adaptation-to-the-rgpd","status":"publish","type":"page","link":"https:\/\/nova.edorteam.com\/en\/consultancy-of-adaptation-to-the-rgpd\/","title":{"rendered":"GDPR consulting for companies and SMEs"},"content":{"rendered":"<div class=\"et_pb_section_0 et_pb_section et_section_regular et_block_section\"><div class=\"et_pb_row_0 et_pb_row et_pb_equal_columns et_block_row\"><div class=\"et_pb_column_0 et_pb_column et_pb_column_2_5 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_text_0 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h2>Leave GDPR consulting in our hands<\/h2>\n<\/div><\/div><div class=\"et_pb_text_1 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><p>Complete <strong>GDPR \/ LOPD consulting<\/strong> solution for your business. It complies with the regulations in the most<strong> efficient and economical<\/strong> possible with a<strong> totally tailored solution<\/strong> of the reality of your company.<\/p>\n<\/div><\/div><div class=\"et_pb_module et_pb_button_module_wrapper et_pb_button_0_wrapper\"><a class=\"et_pb_button_0 et_pb_button et_pb_bg_layout_dark et_pb_module et_block_module\" href=\"#consultoria\">Company obligations<\/a><\/div><div class=\"et_pb_module et_pb_button_module_wrapper et_pb_button_1_wrapper\"><a class=\"et_pb_button_1 et_pb_button et_pb_bg_layout_dark et_pb_module et_block_module\" href=\"#demo\" data-icon=\"$\">Budget for SMEs and large companies<\/a><\/div><\/div><div class=\"et_pb_column_1 et_pb_column et_pb_column_3_5 et-last-child et_block_column et_pb_column_empty et_pb_css_mix_blend_mode_passthrough\"><\/div><\/div><\/div><div class=\"et_pb_section_1 et_pb_section et_section_regular et_block_section et_animated\"><div class=\"et_pb_row_1 et_pb_row et_block_row\"><div class=\"et_pb_column_2 et_pb_column et_pb_column_1_2 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_image_0 et_pb_image et_animated et_pb_module et_block_module\"><span class=\"et_pb_image_wrap\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/nova.edorteam.com\/wp-content\/uploads\/lopd-rgpd-proteccion-datos-empresas-lleida-madrid-06.png\" width=\"1280\" height=\"768\" srcset=\"https:\/\/nova.edorteam.com\/wp-content\/uploads\/lopd-rgpd-proteccion-datos-empresas-lleida-madrid-06.png 1280w, https:\/\/nova.edorteam.com\/wp-content\/uploads\/lopd-rgpd-proteccion-datos-empresas-lleida-madrid-06-980x588.png 980w, https:\/\/nova.edorteam.com\/wp-content\/uploads\/lopd-rgpd-proteccion-datos-empresas-lleida-madrid-06-480x288.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1280px, 100vw\" class=\"wp-image-13713\" title=\"GDPR consulting for companies and SMEs\" alt=\"Is my company obliged to comply with the GDPR?\" \/><\/span><\/div><div class=\"et_pb_text_2 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h3>LOPD is Spanish data protection law, while GDPR is the European law. Both must be applied in Spain, until LOPD update that includes new GDPR features is published.<\/h3>\n<\/div><\/div><div class=\"et_pb_divider_0 et_pb_divider et_pb_space et_pb_divider_position_top et_pb_module\"><div class=\"et_pb_divider_internal\"><\/div><\/div><\/div><div class=\"et_pb_column_3 et_pb_column et_pb_column_1_2 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_text_3 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h2>Is my company obliged to comply with the GDPR?<\/h2>\n<p>The GDPR has been mandatory since May 25, 2018, and applies to the total or partial processing of personal data by <strong>controllers or processors established in the EU<\/strong>, as well as those not established in the EU, if they carry out processing intended for EU citizens.<\/p>\n<p>Spanish companies that process personal data <strong>are obliged to<\/strong> comply with this new regulation and must correctly adapt to the new features and obligations it establishes.<\/p>\n<p>Although a <strong>Data Protection<\/strong> Law already existed in Spain, the GDPR introduces some new obligations and, therefore, both regulations must now be applied.<\/p>\n<p>Our experience with clients who handle <strong>highly protected<\/strong> data allows us to offer the best and most complete solution to easily adapt to current legislation.<\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"et_pb_section_2 et_pb_section et_section_regular et_block_section\"><div class=\"et_pb_row_2 et_pb_row et_block_row\"><div class=\"et_pb_column_4 et_pb_column et_pb_column_4_4 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_text_4 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h2>Adaptation to the GDPR data protection regulations: what is it?<\/h2>\n<\/div><\/div><\/div><\/div><div class=\"et_pb_row_3 et_pb_row et_block_row\"><div class=\"et_pb_column_5 et_pb_column et_pb_column_4_4 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough et_animated\"><div class=\"et_pb_text_5 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h3>You get customized solutions for your company and professional activity<\/h3>\n<p>\u2714 Privacy policies.<br \/>\u2714 Updated data processing records.<br \/>\u2714 Correct management of social networks and website: publication of images, minors, legal texts, cookie policy...<br \/>\u2714 Administrative adaptation: emails, invoices, delivery notes, SEPA orders, contracts, correct WhatsApp management, and more!<br \/>\u2714 HR management: confidentiality agreements and other documents for your employees.<br \/>\u2714 Video surveillance and geolocation: posters and protocols for the correct management of video surveillance and geolocation.<br \/>\u2714 Attention to customer rights: clear and efficient protocols.<br \/>\u2714 Confidentiality agreements with collaborators and suppliers.<br \/>\u2714 Legal advice on data protection: continuous and specialized support in all phases of the process.<\/p>\n<\/div><\/div><\/div><\/div><div class=\"et_pb_row_4 et_pb_row et_block_row\"><div class=\"et_pb_column_6 et_pb_column et_pb_column_4_4 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough et_animated\"><div class=\"et_pb_text_6 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h3>You get access to a cloud management platform<\/h3>\n<p class=\"p1\">Our data protection service includes access to a cloud application from where you can manage the <strong>Record of Processing Activities<\/strong> and keep all legal documentation always up to date. These are the main functions that can be performed from the application: <\/p>\n<\/div><\/div><\/div><\/div><div class=\"et_pb_row_5 et_pb_row et_pb_row_5col et_block_row et_block_row_5col\"><div class=\"et_pb_column_7 et_pb_column et_pb_column_1_5 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_blurb_0 et_pb_blurb et_pb_bg_layout_light et_pb_text_align_center et_pb_blurb_position_top et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">i<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h3 class=\"et_pb_module_header\">Consult and download the Record of Processing Activities<\/h3><\/div><\/div><\/div><\/div><div class=\"et_pb_column_8 et_pb_column et_pb_column_1_5 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_blurb_1 et_pb_blurb et_pb_bg_layout_light et_pb_text_align_center et_pb_blurb_position_top et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">+<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h3 class=\"et_pb_module_header\">Manage ARCO-POL rights<\/h3><\/div><\/div><\/div><\/div><div class=\"et_pb_column_9 et_pb_column et_pb_column_1_5 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_blurb_2 et_pb_blurb et_pb_bg_layout_light et_pb_text_align_center et_pb_blurb_position_top et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">~<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h3 class=\"et_pb_module_header\">Generate confidentiality agreements and other contracts<\/h3><\/div><\/div><\/div><\/div><div class=\"et_pb_column_10 et_pb_column et_pb_column_1_5 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_blurb_3 et_pb_blurb et_pb_bg_layout_light et_pb_text_align_center et_pb_blurb_position_top et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">s<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h3 class=\"et_pb_module_header\">Register security incidents quickly<\/h3><\/div><\/div><\/div><\/div><div class=\"et_pb_column_11 et_pb_column et_pb_column_1_5 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_blurb_4 et_pb_blurb et_pb_bg_layout_light et_pb_text_align_center et_pb_blurb_position_top et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">Z<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h3 class=\"et_pb_module_header\">Keep the I\/O media registry up to date<\/h3><\/div><\/div><\/div><\/div><\/div><div class=\"et_pb_row_6 et_pb_row et_block_row\"><div class=\"et_pb_column_12 et_pb_column et_pb_column_4_4 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough et_animated\"><div class=\"et_pb_text_7 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h3>Assessment to determine if the figure of the DPO is necessary<\/h3>\n<p>The Data Protection Officer (DPO) <strong>is a specialist in Data Protection,<\/strong> usually with a law degree, whose function is to guarantee compliance with the regulations.<\/p>\n<p>Our legal compliance experts will determine if your company should appoint a Data Protection Officer (DPO). In that case, <strong>Edorteam will be your external DPO<\/strong> to carry out information, coordination and supervision tasks of the company's data protection policy, ensuring compliance at all times.<\/p>\n<\/div><\/div><\/div><\/div><div class=\"et_pb_row_7 et_pb_row et_block_row\"><div class=\"et_pb_column_13 et_pb_column et_pb_column_4_4 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough et_animated\"><div class=\"et_pb_text_8 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h3>Adapting to the GDPR without applying technical security measures is <strong>useless<\/strong><\/h3>\n<p>During the data protection audit, <strong>the technical security measures<\/strong> implemented by the organization will also be evaluated. If deficiencies or improvable aspects are detected in the computer network, this will be stated in the audit indicating its level of priority. <\/p>\n<p>During the data protection audit, <strong>the technical security measures<\/strong> implemented by the organization will also be evaluated. If deficiencies or improvable aspects are detected in the computer network, this will be stated in the audit indicating its level of priority. <\/p>\n<p>The Edorteam computer systems department will be at the company's disposal to guide, advise and <strong>implement the technical measures necessary to guarantee the organization's regulatory compliance,<\/strong> both software and hardware. The implementation service will always be carried out under prior budget and is not included in this economic proposal. <\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"et_pb_section_3 et_pb_section et_section_regular et_block_section section_has_divider et_pb_top_divider\"><div class=\"et_pb_top_inside_divider et-no-transition\"><\/div><div class=\"et_pb_row_8 et_pb_row et_pb_row_5col et_pb_equal_columns et_pb_gutters2 et_block_row et_block_row_5col\"><div class=\"et_pb_column_14 et_pb_column et_pb_column_1_5 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_text_9 et_pb_text et_pb_bg_layout_dark et_pb_module et_block_module et_pb_text_align_right et_pb_text_align_left-tablet\"><div class=\"et_pb_text_inner\"><p>Advantages and benefits of complying with the GDPR<\/p>\n<\/div><\/div><\/div><div class=\"et_pb_column_15 et_pb_column et_pb_column_1_5 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_blurb_5 et_pb_blurb et_pb_bg_layout_dark et_pb_text_align_center et_pb_blurb_position_top et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">R<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h3 class=\"et_pb_module_header\">Avoid fines and sanctions that would jeopardize your business<\/h3><\/div><\/div><\/div><\/div><div class=\"et_pb_column_16 et_pb_column et_pb_column_1_5 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_blurb_6 et_pb_blurb et_pb_bg_layout_dark et_pb_text_align_center et_pb_blurb_position_top et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">v<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h3 class=\"et_pb_module_header\">Direct communication with your expert data protection consultant at Edorteam<\/h3><\/div><\/div><\/div><\/div><div class=\"et_pb_column_17 et_pb_column et_pb_column_1_5 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_blurb_7 et_pb_blurb et_pb_bg_layout_dark et_pb_text_align_center et_pb_blurb_position_top et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">\ue022<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h3 class=\"et_pb_module_header\">Regular audits and training by our specialists<\/h3><\/div><\/div><\/div><\/div><div class=\"et_pb_column_18 et_pb_column et_pb_column_1_5 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_blurb_8 et_pb_blurb et_pb_bg_layout_dark et_pb_text_align_center et_pb_blurb_position_top et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">\ue003<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h3 class=\"et_pb_module_header\">If you wish, we can carry out the service 100% online, with documentation always updated and available.<\/h3><\/div><\/div><\/div><\/div><\/div><\/div><div class=\"et_pb_section_4 et_pb_section et_section_regular et_block_section\"><div class=\"et_pb_row_9 et_pb_row et_pb_row_1-4_3-4 et_block_row et_block_row_1-4_3-4\"><div class=\"et_pb_column_19 et_pb_column et_pb_column_1_4 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_image_1 et_pb_image et_animated et_pb_module et_block_module\"><span class=\"et_pb_image_wrap\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/nova.edorteam.com\/wp-content\/uploads\/almacenamiento-fichero-datos-personales-lopd.jpg\" width=\"509\" height=\"339\" srcset=\"https:\/\/nova.edorteam.com\/wp-content\/uploads\/almacenamiento-fichero-datos-personales-lopd.jpg 509w\" sizes=\"(max-width: 509px) 100vw, 509px\" class=\"wp-image-2021\" title=\"storage-file-personal-data-lopd\" alt=\"Keys about GDPR regulation and its compliance\" \/><\/span><\/div><\/div><div class=\"et_pb_column_20 et_pb_column et_pb_column_3_4 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_text_10 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h2>Keys about GDPR regulation and its compliance<\/h2>\n<p>Below, you will find a selection about the most important GDPR articles and what we propose to fulfill your obligations.<\/p>\n<\/div><\/div><\/div><\/div><div class=\"et_pb_row_10 et_pb_row et_pb_equal_columns et_pb_gutters2 et_block_row\"><div class=\"et_pb_column_21 et_pb_column et_pb_column_1_3 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_blurb_9 et_pb_blurb et_pb_bg_layout_light et_pb_text_align_center et_pb_blurb_position_top et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_blurb_container\"><h3 class=\"et_pb_module_header\">Article 7<\/h3><div class=\"et_pb_blurb_description\"><p><strong>Consent obtained<\/strong> prior to the date of application of the European Regulation (25\/05\/2018) will only remain valid if it has been obtained in compliance with the criteria set out in the Regulation itself (free, informed, specific and unambiguous).<\/p>\n<\/div><\/div><\/div><\/div><div class=\"et_pb_blurb_10 et_pb_blurb et_pb_bg_layout_light et_pb_text_align_center et_pb_blurb_position_top et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_blurb_container\"><h3 class=\"et_pb_module_header\">Edorteam&#039;s solution<\/h3><div class=\"et_pb_blurb_description\"><p>Change of consents and revision of contracts on behalf of third parties and data processors to adapt them to the new regulations.<\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"et_pb_column_22 et_pb_column et_pb_column_1_3 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_blurb_11 et_pb_blurb et_pb_bg_layout_light et_pb_text_align_center et_pb_blurb_position_top et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_blurb_container\"><h3 class=\"et_pb_module_header\">Article 28<\/h3><div class=\"et_pb_blurb_description\"><p>Contract with <strong>data processors<\/strong> that have adhered to data protection compliant certifications, mechanisms or codes of conduct.<\/p>\n<\/div><\/div><\/div><\/div><div class=\"et_pb_blurb_12 et_pb_blurb et_pb_bg_layout_light et_pb_text_align_center et_pb_blurb_position_top et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_blurb_container\"><h3 class=\"et_pb_module_header\">Edorteam&#039;s solution<\/h3><div class=\"et_pb_blurb_description\"><p>Creation of codes of conduct specialised in data protection regulations.<\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"et_pb_column_23 et_pb_column et_pb_column_1_3 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_blurb_13 et_pb_blurb et_pb_bg_layout_light et_pb_text_align_center et_pb_blurb_position_top et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_blurb_container\"><h3 class=\"et_pb_module_header\">Article 31.1.d<\/h3><div class=\"et_pb_blurb_description\"><p>Regular verification, evaluation and assessment of the effectiveness of technical and organisational measures to ensure data protection security.<\/p>\n<\/div><\/div><\/div><\/div><div class=\"et_pb_blurb_14 et_pb_blurb et_pb_bg_layout_light et_pb_text_align_center et_pb_blurb_position_top et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_blurb_container\"><h3 class=\"et_pb_module_header\">Edorteam&#039;s solution<\/h3><div class=\"et_pb_blurb_description\"><p>Carrying out audits to verify security measures compliance.<\/p>\n<\/div><\/div><\/div><\/div><\/div><\/div><div class=\"et_pb_row_11 et_pb_row et_pb_equal_columns et_pb_gutters2 et_block_row\"><div class=\"et_pb_column_24 et_pb_column et_pb_column_1_3 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_blurb_15 et_pb_blurb et_pb_bg_layout_light et_pb_text_align_center et_pb_blurb_position_top et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_blurb_container\"><h3 class=\"et_pb_module_header\">Articles 30 and 32<\/h3><div class=\"et_pb_blurb_description\"><p>Management and administration of users, control of equipment and maintenance of an <strong>activity log<\/strong>.<\/p>\n<p>Set up of data recovery systems and regular <strong>backups<\/strong> of equipment.<\/p>\n<\/div><\/div><\/div><\/div><div class=\"et_pb_blurb_16 et_pb_blurb et_pb_bg_layout_light et_pb_text_align_center et_pb_blurb_position_top et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_blurb_container\"><h3 class=\"et_pb_module_header\">Edorteam&#039;s solution<\/h3><div class=\"et_pb_blurb_description\"><p>Setup the IT equipment with ET Seguridad and ET Backup software, if other solutions with same features are not available.<\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"et_pb_column_25 et_pb_column et_pb_column_1_3 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_blurb_17 et_pb_blurb et_pb_bg_layout_light et_pb_text_align_center et_pb_blurb_position_top et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_blurb_container\"><h3 class=\"et_pb_module_header\">Article 32.2<\/h3><div class=\"et_pb_blurb_description\"><p><strong>Assessment of the risks<\/strong> presented by data processing, in particular as a result of accidental or unlawful destruction, loss or alteration of data, or unauthorized disclosure of or access to such data.<\/p>\n<\/div><\/div><\/div><\/div><div class=\"et_pb_blurb_18 et_pb_blurb et_pb_bg_layout_light et_pb_text_align_center et_pb_blurb_position_top et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_blurb_container\"><h3 class=\"et_pb_module_header\">Edorteam&#039;s solution<\/h3><div class=\"et_pb_blurb_description\"><p>Study and implementation of risk assessments in treatments by means of evaluations from a personalised point of view, taking into account the different specifications.<\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"et_pb_column_26 et_pb_column et_pb_column_1_3 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_blurb_19 et_pb_blurb et_pb_bg_layout_light et_pb_text_align_center et_pb_blurb_position_top et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_blurb_container\"><h3 class=\"et_pb_module_header\">Article 34<\/h3><div class=\"et_pb_blurb_description\"><p>Obligation on companies to report any leakage of personal data within <strong>72 hours<\/strong>.<\/p>\n<\/div><\/div><\/div><\/div><div class=\"et_pb_blurb_20 et_pb_blurb et_pb_bg_layout_light et_pb_text_align_center et_pb_blurb_position_top et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_blurb_container\"><h3 class=\"et_pb_module_header\">Edorteam&#039;s solution<\/h3><div class=\"et_pb_blurb_description\"><p>Preventive folders and documents encryption with ET Encrypt or similar software. The use of encryption on personal information removes the obligation to notify those affected that a security breach has occurred.<\/p>\n<\/div><\/div><\/div><\/div><\/div><\/div><div class=\"et_pb_row_12 et_pb_row et_block_row\"><div class=\"et_pb_column_27 et_pb_column et_pb_column_3_5 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_text_11 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h2>What are the penalties for GDPR non-compliance?<\/h2>\n<p>As one of the key new features, GDPR <strong>strengthens the penalty regime<\/strong>, establishing fines of up to 4% of the company's global turnover or 20 million euros, with the higher of the two amounts being applied as a fine.<\/p>\n<\/div><\/div><div class=\"et_pb_text_12 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h3>Fines can reach 20 million euros or 4% of the company's global turnover, whichever is higher.<\/h3>\n<\/div><\/div><div class=\"et_pb_divider_1 et_pb_divider et_pb_space et_pb_divider_position_top et_pb_module\"><div class=\"et_pb_divider_internal\"><\/div><\/div><\/div><div class=\"et_pb_column_28 et_pb_column et_pb_column_2_5 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_image_2 et_pb_image et_animated et_pb_module et_block_module\"><span class=\"et_pb_image_wrap\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/nova.edorteam.com\/wp-content\/uploads\/ley-proteccion-datos-europa-2018.jpg\" width=\"1000\" height=\"666\" srcset=\"https:\/\/nova.edorteam.com\/wp-content\/uploads\/ley-proteccion-datos-europa-2018.jpg 1000w, https:\/\/nova.edorteam.com\/wp-content\/uploads\/ley-proteccion-datos-europa-2018-600x400.jpg 600w\" sizes=\"(max-width: 1000px) 100vw, 1000px\" class=\"wp-image-2018\" title=\"data protection-law-europe-2018\" alt=\"What are the penalties for GDPR non-compliance?\" \/><\/span><\/div><\/div><\/div><\/div><div class=\"et_pb_section_5 et_pb_section et_section_regular et_block_section\"><div class=\"et_pb_row_13 et_pb_row et_block_row et_animated\"><div class=\"et_pb_column_29 et_pb_column et_pb_column_4_4 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_text_13 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module et_pb_text_align_center\"><div class=\"et_pb_text_inner\"><h2>What's new in the GDPR compared to the LOPD?<\/h2>\n<\/div><\/div><div class=\"et_pb_toggle_0 et_pb_toggle et_pb_toggle_item et_pb_toggle_close et_pb_module et_block_module preset--module--divi-toggle--default\"><h3 class=\"et_pb_toggle_title\">Specific consent<\/h3><div class=\"et_pb_toggle_content clearfix\"><p>Consent must be free, informed, specific and unambiguous. The requirement of consent is reinforced by an unequivocal manifestation or a positive action, and cannot be inferred from silence or inaction. This establishes the obligation to have consent registration systems so that verification is possible in the event of an audit.<\/p>\n<\/div><\/div><div class=\"et_pb_toggle_1 et_pb_toggle et_pb_toggle_item et_pb_toggle_close et_pb_module et_block_module preset--module--divi-toggle--default\"><h3 class=\"et_pb_toggle_title\">Specially protected data<\/h3><div class=\"et_pb_toggle_content clearfix\"><p>Consent shall be explicit for the processing of sensitive data.<\/p>\n<p>Specially protected or sensitive data:<\/p>\n<ul>\n<li>Ideology<\/li>\n<li>Religion and beliefs<\/li>\n<li>Union membership<\/li>\n<li>Related to: beliefs, racial origin, health and \/ or sexual life.<\/li>\n<li>Relating to the commission of criminal or administrative offenses<\/li>\n<\/ul>\n<p><strong>GDPR adds:<\/strong><\/p>\n<ul>\n<li>Genetic data (DNA analysis)<\/li>\n<li>Biometric data (fingerprint or eye iris)<\/li>\n<\/ul>\n<\/div><\/div><div class=\"et_pb_toggle_2 et_pb_toggle et_pb_toggle_item et_pb_toggle_close et_pb_module et_block_module preset--module--divi-toggle--default\"><h3 class=\"et_pb_toggle_title\">Privacy notices<\/h3><div class=\"et_pb_toggle_content clearfix\"><p>The legal basis for the data processing, the length of time the data will be retained, as well as informing data subjects that they can address their complaints to the data protection authorities should be explained. All this information should be included in the web pages or in the communication channels available.<\/p>\n<\/div><\/div><div class=\"et_pb_toggle_3 et_pb_toggle et_pb_toggle_item et_pb_toggle_close et_pb_module et_block_module preset--module--divi-toggle--default\"><h3 class=\"et_pb_toggle_title\">Guardianship rights<\/h3><div class=\"et_pb_toggle_content clearfix\"><ul>\n<li>Right to portability, oblivion and transparency.<\/li>\n<\/ul>\n<\/div><\/div><div class=\"et_pb_toggle_4 et_pb_toggle et_pb_toggle_item et_pb_toggle_close et_pb_module et_block_module preset--module--divi-toggle--default\"><h3 class=\"et_pb_toggle_title\">Active responsibility<\/h3><div class=\"et_pb_toggle_content clearfix\"><p>Companies need to take steps to reasonably ensure that they are in a position to comply with the principles, rights and safeguards of the new regulation. It is understood that acting only when an infringement has already occurred is insufficient as a strategy, so a set of measures is envisaged:<\/p>\n<ul>\n<li>Data protection from the point of view of risk analysis in data processing<\/li>\n<li>Data protection by default (from the start)<\/li>\n<li>Security measures<\/li>\n<li>Maintenance of a treatment record<\/li>\n<li>Conducting Data Protection Impact Assessments (DPIA)<\/li>\n<li>Appointment of a Data Protection Officer (DPO)<\/li>\n<li>Codes of conduct and certification schemes promotion<\/li>\n<\/ul>\n<\/div><\/div><div class=\"et_pb_toggle_5 et_pb_toggle et_pb_toggle_item et_pb_toggle_close et_pb_module et_block_module preset--module--divi-toggle--default\"><h3 class=\"et_pb_toggle_title\">Conducting Personal Data Impact Assessments (DPIA)<\/h3><div class=\"et_pb_toggle_content clearfix\"><p>Data protection impact assessments are required to be carried out only when the use of advanced technologies, the volume or type of data processed (specially protected data) may entail a risk to the rights and freedoms of the persons concerned.<\/p>\n<p>The Regulation considers that a DPIA has to be carried out to assess the origin, nature, particularities and risk to which the personal data are exposed. The controller shall seek advice from the Data Protection Officer in carrying out the DPIA.<\/p>\n<p>The Spanish Data Protection Agency is responsible for publishing lists of the types of processing operations that require impact assessments.<\/p>\n<\/div><\/div><div class=\"et_pb_toggle_6 et_pb_toggle et_pb_toggle_item et_pb_toggle_close et_pb_module et_block_module preset--module--divi-toggle--default\"><h3 class=\"et_pb_toggle_title\">Appointment of a Data Protection Officer (DPO)<\/h3><div class=\"et_pb_toggle_content clearfix\"><p>Among DPO functions, we monitorize the correct applying of measures to reduce risks and advice your company data processors.<\/p>\n<p>GDPR allows the DPO to be internal or external to the company, being able to hire the service to natural or legal persons outside the organization.<\/p>\n<p>This figure is mandatory in:<\/p>\n<ul>\n<li>Organizations and public institutions.<\/li>\n<li>Controllers or processors whose main activities include processing operations requiring regular and systematic observation of data subjects on a large scale.<\/li>\n<li>Controllers or processors whose main activities include the large-scale processing of sensitive data.<\/li>\n<\/ul>\n<\/div><\/div><div class=\"et_pb_toggle_7 et_pb_toggle et_pb_toggle_item et_pb_toggle_close et_pb_module et_block_module preset--module--divi-toggle--default\"><h3 class=\"et_pb_toggle_title\">Data Security Breach Notifications<\/h3><div class=\"et_pb_toggle_content clearfix\"><p>Obligation on companies to inform the national data protection authority and also the affected parties themselves if any personal data is leaked within 72 hours.<\/p>\n<p>The use of encryption on personal information removes the obligation to notify those affected that a security breach has occurred, in which their personal data has been exposed.<\/p>\n<\/div><\/div><div class=\"et_pb_toggle_8 et_pb_toggle et_pb_toggle_item et_pb_toggle_close et_pb_module et_block_module preset--module--divi-toggle--default\"><h3 class=\"et_pb_toggle_title\">Strengthening the sanctions regime<\/h3><div class=\"et_pb_toggle_content clearfix\"><p>Regulation strengthens the sanctioning regime: fines can reach up to <strong>4% of the company's global turnover<\/strong> or <strong>20 million euros<\/strong>, wherever is higher.<\/p>\n<\/div><\/div><div class=\"et_pb_toggle_9 et_pb_toggle et_pb_toggle_item et_pb_toggle_close et_pb_module et_block_module preset--module--divi-toggle--default\"><h3 class=\"et_pb_toggle_title\">One Stop Shop<\/h3><div class=\"et_pb_toggle_content clearfix\"><p>The \"One-Stop-Shop\" aims to reduce bureaucratic hurdles by making it possible for all procedures affecting Data Protection to be addressed to a one-stop-shop that resolves cases at European level.<\/p>\n<p>The management will be carried out by the national authority (developing an intermediary role), having to inform the interested party of the final outcome of the complaint or denunciation.<\/p>\n<\/div><\/div><div class=\"et_pb_toggle_10 et_pb_toggle et_pb_toggle_item et_pb_toggle_close et_pb_module et_block_module preset--module--divi-toggle--default\"><h3 class=\"et_pb_toggle_title\">Data processor and person in charge of the treatment<\/h3><div class=\"et_pb_toggle_content clearfix\"><p>The person in charge must be extremely careful and regularize the contracts in accordance with the requirements and the necessary documentation.<\/p>\n<p>Right to compensation and liability and extension to damages that may have been caused by those in charge of the treatment, establishing joint and several liability between the controller and the person in charge of the treatment.<\/p>\n<\/div><\/div><div class=\"et_pb_toggle_11 et_pb_toggle et_pb_toggle_item et_pb_toggle_close et_pb_module et_block_module preset--module--divi-toggle--default\"><h3 class=\"et_pb_toggle_title\">Security measures<\/h3><div class=\"et_pb_toggle_content clearfix\"><ul>\n<li>Pseudonymisation and encryption of personal data.<\/li>\n<li>Ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services.<\/li>\n<li>Ability to restore availability and access to personal data quickly in the event of a physical or technical incident.<\/li>\n<li>Process of regular verification, evaluation and assessment of the effectiveness of technical and organizational measures to ensure the security of the processing.<\/li>\n<li>Assessment of the risks presented by data processing, in particular as a result of the accidental or unlawful destruction, loss or alteration of personal data transmitted, stored or otherwise processed, or unauthorized disclosure of or access to such data.<\/li>\n<li>Contract with data processors that have adhered to data protection compliant certifications, mechanisms or codes of conduct.<\/li>\n<li>Notify the authorities in the event of a breach of security of personal data.<\/li>\n<\/ul>\n<\/div><\/div><\/div><\/div><div class=\"et_pb_row_14 et_pb_row et_pb_row_1-4_3-4 et_block_row et_block_row_1-4_3-4\"><div class=\"et_pb_column_30 et_pb_column et_pb_column_1_4 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_image_3 et_pb_image et_animated et_pb_module et_block_module\"><span class=\"et_pb_image_wrap\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/nova.edorteam.com\/wp-content\/uploads\/cambios-lopd-rgpd-diferencias.jpg\" width=\"667\" height=\"1001\" srcset=\"https:\/\/nova.edorteam.com\/wp-content\/uploads\/cambios-lopd-rgpd-diferencias.jpg 667w, https:\/\/nova.edorteam.com\/wp-content\/uploads\/cambios-lopd-rgpd-diferencias-600x900.jpg 600w\" sizes=\"(max-width: 667px) 100vw, 667px\" class=\"wp-image-2056\" title=\"changes-lopd-rgpd-differences\" alt=\"Security measures to comply with the GDPR\" \/><\/span><\/div><\/div><div class=\"et_pb_column_31 et_pb_column et_pb_column_3_4 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_text_14 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h2>What do the security measures of the European regulations mean in practical terms?<\/h2>\n<\/div><\/div><div class=\"et_pb_blurb_21 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">N<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Mandatory file encryption.<\/h4><\/div><\/div><\/div><div class=\"et_pb_blurb_22 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">N<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Management and administration of users, controlling access to the equipment containing the data.<\/h4><\/div><\/div><\/div><div class=\"et_pb_blurb_23 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">N<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Carrying out audits to verify security measures compliance.<\/h4><\/div><\/div><\/div><div class=\"et_pb_blurb_24 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">N<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Review of contracts for third party data processors and adaptation to the new regulations, if required.<\/h4><\/div><\/div><\/div><div class=\"et_pb_blurb_25 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">N<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Activity log setup.<\/h4><\/div><\/div><\/div><div class=\"et_pb_blurb_26 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">N<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Appointment of a Data Protection Officer in the specified cases.<\/h4><\/div><\/div><\/div><div class=\"et_pb_blurb_27 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">N<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Carrying out a risk assessment that especially contemplates the analysis of CV and payroll files, when dealing with sensitive data.<\/h4><\/div><\/div><\/div><div class=\"et_pb_blurb_28 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">N<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Establish mechanisms of action and foresight to deal with security breaches.<\/h4><\/div><\/div><\/div><\/div><\/div><\/div><div class=\"et_pb_section_6 et_pb_section et_section_regular et_block_section et_animated\"><div class=\"et_pb_row_15 et_pb_row et_pb_row_4col et_pb_equal_columns et_pb_gutters1 et_block_row et_block_row_4col\"><div class=\"et_pb_column_32 et_pb_column et_pb_column_1_4 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_text_15 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h3>Record access to your computer equipment with Edorteam DLP<\/h3>\n<p>Protect the personal data stored on your equipment and prevent unauthorized uses. We're not saying it, it's an <strong>obligation included in the GDPR.<\/strong> <\/p>\n<\/div><\/div><div class=\"et_pb_module et_pb_button_module_wrapper et_pb_button_2_wrapper\"><a class=\"et_pb_button_2 et_pb_button et_pb_bg_layout_dark et_pb_module et_block_module\" href=\"https:\/\/nova.edorteam.com\/software-dlp-prevencion-fuga-de-datos-personales\/\">Know more<\/a><\/div><\/div><div class=\"et_pb_column_33 et_pb_column et_pb_column_1_4 et_block_column et_pb_css_mix_blend_mode_passthrough et_clickable\"><div class=\"et_pb_divider_2 et_pb_divider_hidden et_pb_space et_pb_divider_position_top et_pb_module\"><div class=\"et_pb_divider_internal\"><\/div><\/div><\/div><div class=\"et_pb_column_34 et_pb_column et_pb_column_1_4 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_text_16 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h3>Encrypt files, folders and USBs with ET Encrypt<\/h3>\n<p>ET Encrypt is an encryption tool with a practically impenetrable algorithm, <strong>encrypts the data<\/strong> that you send attached by e-mail as required by the GDPR.<\/p>\n<\/div><\/div><div class=\"et_pb_module et_pb_button_module_wrapper et_pb_button_3_wrapper\"><a class=\"et_pb_button_3 et_pb_button et_pb_bg_layout_dark et_pb_module et_block_module\" href=\"https:\/\/nova.edorteam.com\/cifrar-archivos-encriptar-aes-256\/\">Know more<\/a><\/div><\/div><div class=\"et_pb_column_35 et_pb_column et_pb_column_1_4 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough et_clickable\"><div class=\"et_pb_divider_3 et_pb_divider_hidden et_pb_space et_pb_divider_position_top et_pb_module\"><div class=\"et_pb_divider_internal\"><\/div><\/div><\/div><\/div><\/div><div class=\"et_pb_section_7 et_pb_section et_section_regular et_block_section\"><div class=\"et_pb_row_16 et_pb_row et_block_row\"><div class=\"et_pb_column_36 et_pb_column et_pb_column_4_4 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_text_17 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><p style=\"text-align: center;\">Frequently asked questions<\/p>\n<\/div><\/div><div class=\"et_pb_accordion_0 et_pb_accordion et_pb_module et_block_module\"><div class=\"et_pb_accordion_item_0 et_pb_accordion_item et_pb_toggle et_pb_module et_pb_toggle_open et_block_module\"><h4 class=\"et_pb_toggle_title\">What is the GDPR and how does it affect my company?<\/h4><div class=\"et_pb_toggle_content\"><p>The GDPR is the General Data Protection Regulation of the European Union that regulates the processing of personal data. It affects any company that operates within the EU or that handles data of EU citizens, regardless of their location, requiring strict data protection measures.<\/p>\n<\/div><\/div><div class=\"et_pb_accordion_item_1 et_pb_accordion_item et_pb_toggle et_pb_module et_pb_toggle_close et_block_module\"><h4 class=\"et_pb_toggle_title\">What are the differences between the LOPD and the GDPR?<\/h4><div class=\"et_pb_toggle_content\"><p>The LOPD is the Spanish regulation that regulates the protection of personal data, while the GDPR is the regulation at the European level. The GDPR introduces stricter requirements such as explicit consent, extended rights for individuals over their data, and significant penalties for non-compliance.<\/p>\n<\/div><\/div><div class=\"et_pb_accordion_item_2 et_pb_accordion_item et_pb_toggle et_pb_module et_pb_toggle_close et_block_module\"><h4 class=\"et_pb_toggle_title\">Is my company obliged to designate a Data Protection Officer (DPO)?<\/h4><div class=\"et_pb_toggle_content\"><p>The appointment of a DPO is mandatory for public authorities, organizations that carry out systematic and regular monitoring on a large scale, or those that handle special categories of personal data on a large scale.<\/p>\n<\/div><\/div><div class=\"et_pb_accordion_item_3 et_pb_accordion_item et_pb_toggle et_pb_module et_pb_toggle_close et_block_module\"><h4 class=\"et_pb_toggle_title\">What does a data protection impact assessment (DPIA) involve and when is it necessary?<\/h4><div class=\"et_pb_toggle_content\"><p>A DPIA evaluates the risks of processing personal data and is necessary when such processing could result in a high risk to the rights and freedoms of individuals, such as in the processing of sensitive data on a large scale.<\/p>\n<\/div><\/div><div class=\"et_pb_accordion_item_4 et_pb_accordion_item et_pb_toggle et_pb_module et_pb_toggle_close et_block_module\"><h4 class=\"et_pb_toggle_title\">How can your service help our company with the GDPR?<\/h4><div class=\"et_pb_toggle_content\"><p>Our service includes the review and updating of privacy policies, advice on data handling and protection, implementation of security measures, staff training and design of processes in accordance with the GDPR to ensure regulatory compliance.<\/p>\n<\/div><\/div><div class=\"et_pb_accordion_item_5 et_pb_accordion_item et_pb_toggle et_pb_module et_pb_toggle_close et_block_module\"><h4 class=\"et_pb_toggle_title\">What sanctions do we face if we do not comply with the GDPR?<\/h4><div class=\"et_pb_toggle_content\"><p>Fines can be up to 20 million euros or 4% of the total global annual turnover, whichever is greater, depending on the severity of the breach.<\/p>\n<\/div><\/div><div class=\"et_pb_accordion_item_6 et_pb_accordion_item et_pb_toggle et_pb_module et_pb_toggle_close et_block_module\"><h4 class=\"et_pb_toggle_title\">How does your service manage GDPR updates and other legal changes?<\/h4><div class=\"et_pb_toggle_content\"><p>We provide regular updates and audits to ensure that your company remains compliant with the GDPR and other relevant legislation, adjusting policies and practices according to legal developments.<\/p>\n<\/div><\/div><div class=\"et_pb_accordion_item_7 et_pb_accordion_item et_pb_toggle et_pb_module et_pb_toggle_close et_block_module\"><h4 class=\"et_pb_toggle_title\">What technical and organizational measures do you implement to protect data?<\/h4><div class=\"et_pb_toggle_content\"><p>We implement data encryption, access control, periodic security assessments and employee training, among other measures to ensure effective data protection.<\/p>\n<\/div><\/div><div class=\"et_pb_accordion_item_8 et_pb_accordion_item et_pb_toggle et_pb_module et_pb_toggle_close et_block_module\"><h4 class=\"et_pb_toggle_title\">Can your service help in the event of a data security breach?<\/h4><div class=\"et_pb_toggle_content\"><p>Yes, we offer immediate assistance to manage data breaches, including notifications to authorities and those affected, as well as measures to mitigate and prevent future incidents.<\/p>\n<\/div><\/div><div class=\"et_pb_accordion_item_9 et_pb_accordion_item et_pb_toggle et_pb_module et_pb_toggle_close et_block_module\"><h4 class=\"et_pb_toggle_title\">What specific benefits does your GDPR management software offer?<\/h4><div class=\"et_pb_toggle_content\"><div class=\"phenom-desc\">\n<div class=\"comment-container\">\n<div class=\"action-comment can-view-video markeddown js-comment is-comments-rewrite\" dir=\"auto\">\n<div class=\"current-comment js-friendly-links js-open-card\">\n<p>Our software facilitates the management of the security document, incident registration, and maintenance of records of data processing activities. In addition, it allows direct and constant communication with your LOPD consultant, ensuring that you are always up to date with your legal obligations. <\/p>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"js-embed-previews\"><\/div>\n<div class=\"hide unfurled-comment comment-preview\"><\/div>\n<\/div>\n<div class=\"phenom-reactions\">\n<div class=\"js-reaction-piles reaction-piles-container last\">\n<div class=\"reaction-piles reaction-piles-empty\"><\/div>\n<\/div>\n<\/div>\n<\/div><\/div><\/div><\/div><\/div><\/div>","protected":false},"excerpt":{"rendered":"","protected":false},"author":1,"featured_media":5674,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-6396","page","type-page","status-publish","has-post-thumbnail","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>GDPR consulting for companies and SMEs | Data protection<\/title>\n<meta name=\"description\" content=\"GDPR \/ LOPDGDD adaptation and consulting service for companies, regardless of their size or activity. Solutions for the self-employed.\" \/>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"GDPR consulting for companies and SMEs | Data protection\" \/>\n<meta property=\"og:description\" content=\"GDPR \/ LOPDGDD adaptation and consulting service for companies, regardless of their size or activity. Solutions for the self-employed.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/nova.edorteam.com\/en\/consultancy-of-adaptation-to-the-rgpd\/\" \/>\n<meta property=\"og:site_name\" content=\"Edorteam\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/edorteam\/\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-04T15:32:29+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/nova.edorteam.com\/wp-content\/uploads\/adecuacion-norma-rgpd-empresa.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1800\" \/>\n\t<meta property=\"og:image:height\" content=\"1000\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@edorteam\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/consultancy-of-adaptation-to-the-rgpd\\\/\",\"url\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/consultancy-of-adaptation-to-the-rgpd\\\/\",\"name\":\"GDPR consulting for companies and SMEs | Data protection\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/consultancy-of-adaptation-to-the-rgpd\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/consultancy-of-adaptation-to-the-rgpd\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/nova.edorteam.com\\\/wp-content\\\/uploads\\\/adecuacion-norma-rgpd-empresa.jpg\",\"datePublished\":\"2020-12-28T12:35:28+00:00\",\"dateModified\":\"2026-05-04T15:32:29+00:00\",\"description\":\"GDPR \\\/ LOPDGDD adaptation and consulting service for companies, regardless of their size or activity. Solutions for the self-employed.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/consultancy-of-adaptation-to-the-rgpd\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/consultancy-of-adaptation-to-the-rgpd\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/consultancy-of-adaptation-to-the-rgpd\\\/#primaryimage\",\"url\":\"https:\\\/\\\/nova.edorteam.com\\\/wp-content\\\/uploads\\\/adecuacion-norma-rgpd-empresa.jpg\",\"contentUrl\":\"https:\\\/\\\/nova.edorteam.com\\\/wp-content\\\/uploads\\\/adecuacion-norma-rgpd-empresa.jpg\",\"width\":1800,\"height\":1000},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/consultancy-of-adaptation-to-the-rgpd\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Portada\",\"item\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"GDPR consulting for companies and SMEs\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/\",\"name\":\"Consultor\u00eda Compliance y protecci\u00f3n de datos\",\"description\":\"Empresa de Ciberseguridad y Protecci\u00f3n de Datos\",\"publisher\":{\"@id\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/#organization\"},\"alternateName\":\"Edorteam\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/#organization\",\"name\":\"Edorteam | Cibersecurity services and data protection company\",\"alternateName\":\"Edorteam\",\"url\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/nova.edorteam.com\\\/wp-content\\\/uploads\\\/cropped-favicon.png\",\"contentUrl\":\"https:\\\/\\\/nova.edorteam.com\\\/wp-content\\\/uploads\\\/cropped-favicon.png\",\"width\":512,\"height\":512,\"caption\":\"Edorteam | Cibersecurity services and data protection company\"},\"image\":{\"@id\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/edorteam\\\/\",\"https:\\\/\\\/x.com\\\/edorteam\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/edorteam\\\/\",\"https:\\\/\\\/www.instagram.com\\\/edorteam\\\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"GDPR consulting for companies and SMEs | Data protection","description":"GDPR \/ LOPDGDD adaptation and consulting service for companies, regardless of their size or activity. Solutions for the self-employed.","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"GDPR consulting for companies and SMEs | Data protection","og_description":"GDPR \/ LOPDGDD adaptation and consulting service for companies, regardless of their size or activity. Solutions for the self-employed.","og_url":"https:\/\/nova.edorteam.com\/en\/consultancy-of-adaptation-to-the-rgpd\/","og_site_name":"Edorteam","article_publisher":"https:\/\/www.facebook.com\/edorteam\/","article_modified_time":"2026-05-04T15:32:29+00:00","og_image":[{"width":1800,"height":1000,"url":"https:\/\/nova.edorteam.com\/wp-content\/uploads\/adecuacion-norma-rgpd-empresa.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_site":"@edorteam","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/nova.edorteam.com\/en\/consultancy-of-adaptation-to-the-rgpd\/","url":"https:\/\/nova.edorteam.com\/en\/consultancy-of-adaptation-to-the-rgpd\/","name":"GDPR consulting for companies and SMEs | Data protection","isPartOf":{"@id":"https:\/\/nova.edorteam.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/nova.edorteam.com\/en\/consultancy-of-adaptation-to-the-rgpd\/#primaryimage"},"image":{"@id":"https:\/\/nova.edorteam.com\/en\/consultancy-of-adaptation-to-the-rgpd\/#primaryimage"},"thumbnailUrl":"https:\/\/nova.edorteam.com\/wp-content\/uploads\/adecuacion-norma-rgpd-empresa.jpg","datePublished":"2020-12-28T12:35:28+00:00","dateModified":"2026-05-04T15:32:29+00:00","description":"GDPR \/ LOPDGDD adaptation and consulting service for companies, regardless of their size or activity. Solutions for the self-employed.","breadcrumb":{"@id":"https:\/\/nova.edorteam.com\/en\/consultancy-of-adaptation-to-the-rgpd\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/nova.edorteam.com\/en\/consultancy-of-adaptation-to-the-rgpd\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/nova.edorteam.com\/en\/consultancy-of-adaptation-to-the-rgpd\/#primaryimage","url":"https:\/\/nova.edorteam.com\/wp-content\/uploads\/adecuacion-norma-rgpd-empresa.jpg","contentUrl":"https:\/\/nova.edorteam.com\/wp-content\/uploads\/adecuacion-norma-rgpd-empresa.jpg","width":1800,"height":1000},{"@type":"BreadcrumbList","@id":"https:\/\/nova.edorteam.com\/en\/consultancy-of-adaptation-to-the-rgpd\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Portada","item":"https:\/\/nova.edorteam.com\/en\/"},{"@type":"ListItem","position":2,"name":"GDPR consulting for companies and SMEs"}]},{"@type":"WebSite","@id":"https:\/\/nova.edorteam.com\/en\/#website","url":"https:\/\/nova.edorteam.com\/en\/","name":"Consultor\u00eda Compliance y protecci\u00f3n de datos","description":"Empresa de Ciberseguridad y Protecci\u00f3n de Datos","publisher":{"@id":"https:\/\/nova.edorteam.com\/en\/#organization"},"alternateName":"Edorteam","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/nova.edorteam.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/nova.edorteam.com\/en\/#organization","name":"Edorteam | Cibersecurity services and data protection company","alternateName":"Edorteam","url":"https:\/\/nova.edorteam.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/nova.edorteam.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/nova.edorteam.com\/wp-content\/uploads\/cropped-favicon.png","contentUrl":"https:\/\/nova.edorteam.com\/wp-content\/uploads\/cropped-favicon.png","width":512,"height":512,"caption":"Edorteam | Cibersecurity services and data protection company"},"image":{"@id":"https:\/\/nova.edorteam.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/edorteam\/","https:\/\/x.com\/edorteam","https:\/\/www.linkedin.com\/company\/edorteam\/","https:\/\/www.instagram.com\/edorteam\/"]}]}},"_links":{"self":[{"href":"https:\/\/nova.edorteam.com\/en\/wp-json\/wp\/v2\/pages\/6396","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nova.edorteam.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/nova.edorteam.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/nova.edorteam.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nova.edorteam.com\/en\/wp-json\/wp\/v2\/comments?post=6396"}],"version-history":[{"count":4,"href":"https:\/\/nova.edorteam.com\/en\/wp-json\/wp\/v2\/pages\/6396\/revisions"}],"predecessor-version":[{"id":20407,"href":"https:\/\/nova.edorteam.com\/en\/wp-json\/wp\/v2\/pages\/6396\/revisions\/20407"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nova.edorteam.com\/en\/wp-json\/wp\/v2\/media\/5674"}],"wp:attachment":[{"href":"https:\/\/nova.edorteam.com\/en\/wp-json\/wp\/v2\/media?parent=6396"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}