Posts

Loss of an Employee Document and GDPR Breach Notification

Why losing an employee document may be a personal data breach and when employers must assess GDPR notification duties.
Linkedin contactos falsos

LinkedIn Contacts: Privacy, Fake Profiles and Business Risks

Risks of accepting LinkedIn contacts without checking them: fake profiles, phishing, social engineering and professional exposure.
Consejos para tener un servicio correcto Protección de Datos

How to Choose a Good Data Protection Service for Your Company

Key points for choosing a reliable data protection service: GDPR knowledge, processor agreements, clear deliverables and ongoing support.
Cómo protegerse de un troyano

How to Protect Against a Trojan: Measures for Businesses and Users

What a trojan is, how it infects devices and how to reduce the risk of data theft, fraud and personal data breaches.
Imagenes de menores en colegios y consentimiento RGPD

Images of Minors in Schools: Consent, Websites and Social Media

When a school may publish photos or videos of students, how to manage consent, social media, families and image removal.
Datos de salud de empleados y confidencialidad en la empresa

Employee Health Data: How to Process It Under the GDPR

How to process employee health data: what the company may know, common mistakes, confidentiality, minimisation and AEPD guidance.
Lista Robinson

Unsolicited Commercial Calls in Spain: AEPD Rules and Risks

When unsolicited commercial calls are lawful in Spain, AEPD requirements, Robinson List impact and risks for companies.
Delegado Protección de Datos

Data Protection Officer: When Appointing a DPO Is Mandatory

When appointing a Data Protection Officer is mandatory, DPO functions, common mistakes and official AEPD, EDPB and LOPDGDD sources.
WhatsApp group and GDPR fine for adding someone without consent.

Fine for adding someone to a WhatsApp group without consent

The AEPD fined a sports club 4,000 euros for adding a former user to WhatsApp groups without consent. GDPR lessons for companies.
Anonymisation and GDPR concept illustrating identification through web browsing patterns.

Identifying people through anonymous web browsing patterns

Anonymous web browsing data can identify people when URLs, habits and clickstream patterns are combined. GDPR lessons for data brokers and analytics.