• Skip to primary navigation
  • Skip to main content

PKF Attest

  • Global Services
    • Audit and assurance
    • Legal and tax advice
    • Financial Advisory
      • Transactions
      • Ratings
      • Financial Modeling
      • Analytical and management accounting
      • Financial Advanced Solutions
      • Financing for companies
    • Consulting
    • Technology
    • Capital markets
      • Debt Capital Markets
      • Equity Capital Markets
    • Public R&D&I and investment incentives
    • Restructuring and insolvency
  • About us
  • Sectors
    • Public Administration
    • Automotive and mobility
    • Consumer goods
    • Energy and natural resources
    • Hospitality, tourism and leisure
    • Industry
    • Retail and distribution
    • Health and life sciences
    • Services Sector
    • Financial Services
    • Technology, media and telecommunications
  • News
  • Talent
  • Contact
Hide Search
x

RGPD

Data Protection

We manage your web privacy: Guaranteed Compliance with the RGPD

Ensuring compliance with the GDPR

Web privacy has become a crucial element for good business development. In our consultancy, PKF Attest, we empower and guide our clients to comply with data protection laws in their organizations. We offer specific, guided and practical advice to achieve and maintain compliance under the GDPR with any updates.

At PKF Attest, we ensure compliance and collaborate with companies to comply with current privacy regulations, including the General Data Protection Regulation (GDPR) and the Organic Law on Data Protection and Guarantee of Digital Rights (LOPDGDDD).

Discover our Data Protection services Protect your company!

Legal compliance consulting

RGPD-LOPDDGDD Consulting

Audit of data protection regulations

RGPD-LOPDDGDD Audit

Annual Data Protection Support

Follow-up of RGPD-LOPDDGDD

External or DPD service or support to the internal DPD

What is a DPD?

Advise and establish a privacy management system and provide evidence of proactive responsibility for GDPR compliance.

- Register of Processing Activities.
- Information clauses
- Contracts and clauses for processing orders
- Incident management procedures.
- Risk analysis report
- Presentation of results

Establish collaboration to carry out an audit of compliance with European regulations on Personal Data Protection.

- Verification of the system's current documentation.
- Internal Audit: Visit to the facilities.
- Preparation of the Audit Report.
- Identification of deficiencies, risks and non-compliance
- Preparation of the Action Plan.
- Improvement proposals.

Maintain the privacy management system and provide evidence of proactive responsibility through the reviews based on the RGPD regulations.

- Update of the RAT.
- Review and update of the Privacy Manual.
- Support in risk analysis:
- Improvement plans and awareness and training actions.
- Attention to consultations on the application of the regulations to specific cases of the organization. - Attention to consultations on the application of the regulations to specific cases of the organization.

In this area we offer services so that as an outsourced or internal DPD (Data Protection Delegate), the following functions can be fulfilled:

- Information and Advice function.
- Function of supervision of regulatory compliance.
- Function of cooperation and liaison with the supervisory authority.
- Function of attention to the interested parties.

Privacy Impact Assessments

EIPD Service

GDPR Situation Diagnosis Service

Data Protection Training

Conduct a PIA to pre-assess data processing risks.

- Register of Processing Activities.
- Informative clauses
- Contracts and clauses of processing orders
- Incident management procedures, attention to rights to be implemented in the organization.
- Risk analysis report
- Presentation of results

Reference: EIPD Guide of the Spanish Data Protection Agency.

Review the data protection system by analyzing:

- Processing activity
- Review of lawfulness, transparency, legitimacy...
- Compliance with the duty to provide information.
- Contracts with third parties.
- View of the exercise of rights.
- Management of security breaches.
- Internal security policies.
- Documentation in force.
- Internal Audit.
- Identification of deficiencies.
- Preparation of the Action Plan.
- Improvement proposals.

Provide training to data handlers in order to learn about processes and:


- Minimize the risk of infringement
- Manage risk situations
- Share and consult with advisors on guidelines for action in the event of incidents or requests for data.
- Review and update the ARP.
- Review and update the Privacy Manual.
- Provide support in risk analysis.
- Create improvement and awareness plans.
- Answer queries on the application of the regulation.

Ensure the security and compliance of your data!

We implement robust data policies and comply with current regulations to protect your customers' confidentiality and avoid legal risks!

Contact an expert

What is Data Protection?

RGPD, GDPR or Data Protection Law

Data Protection is a set of rules related to the processing of personal data by companies, organizations, institutions, public administrations, etc., responsible for the processing. These rules generate a series of rights that individuals can exercise and a series of obligations that data controllers must comply with. Whoever does not comply may be inspected by a supervisory authority (Data Protection Agencies) and be sanctioned with fines.

Data protection is regulated in the Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD) and in Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (GDPR).

GDPR Compliance: Dealing with data securely

We help you with Data Protection compliance!

The first element to be taken into account for compliance is that the data controller must identify which processing operations it has and create a file for each of these processing operations according to the content established in Art. 30 of the GDPR.

We provide you with an updated "Privacy Manual" with the compliance obligations issued by the different control authorities together with guidelines and legal reports.

What are the obligations of a data controller?

Adherence to legal principles

Have evidence of compliance

Adherence to legal principles
  • Principle of "legality, transparency and loyalty".

  • Principle of "finality".

  • Principle of "data minimization".

  • Principle of "accuracy".

  • Principle of "limitation of the conservation period".

  • Safety" principle.

  • Principle of "active liability" or "proven liability".

Have evidence of compliance
  • Right of information to those affected.

  • Attention to rights applications.

  • Establish legal links with data processors.

  • To have guarantees for international data transfers.

  • Assess risks related to the rights and freedoms of those affected.

  • Conduct an Impact Assessment in case of high risk.

  • Assign a Data Protection Officer when applicable.

  • Maintaining data security

Reference agencies and institutions

Spanish Data Protection Agency - PKF Attest
Data Protection
Catalan Data Protection Authority - PKF Attest
Transparency and Data Protection Council of Andalusia
EDPS

RGPD News

We solve all the doubts about data protection, we talk about the new regulations and how they could affect your company, we inform about changes and compliances in this space dedicated to data protection and RGPD.

Can I share an employee's personal phone without consent?
News

Can I share an employee's personal phone without consent?

Read more
Do facial recognition systems for access control comply with data protection regulations?
News

Do facial recognition systems for access control comply with data protection regulations?

Read more
Is the consent to process biometric data for access control valid?
News

Is the consent to process biometric data for access control valid?

Read more
Does your company comply with data protection regulations?
News

Does your company comply with data protection regulations?

Read more
Does registering travelers comply with data protection regulations?
News

Does registering travelers comply with data protection regulations?

Read more
Is it legal to monitor corporate devices of working personnel?
News

Is it legal to monitor corporate devices of working personnel?

Read more

Supplementary documents, reports and technical documentation

Downloadable PDF of time attendance treatment
Request Document

Title: Aspects to be taken into account in time and attendance control and time recording treatments by obtaining biometric data.

Summary:

In November 2023, the Spanish Data Protection Agency (AEPD) set new criteria on the use of biometric data, such as fingerprints, for time and attendance and access control. The use of biometric data involves a special category of data processing, for which the General Data Protection Regulation (GDPR) establishes strict limits and the need to pass an analysis of suitability, necessity and proportionality.

The Agency points out that, in order for the processing of biometric data to be legitimate, several factors must be fulfilled, such as the existence of a circumstance that lifts the prohibition of art. 9.2 of the RGPD, a Data Protection Impact Assessment must be carried out and the need for the processing must be substantiated and justified, showing that there is no other less intrusive measure for the persons concerned. Likewise, the AEPD recommends taking into account security issues.

Downloadable PDF of DNI data criteria
Request Document

Title: Criteria for the processing of DNI data

Summary:

In September 2023, the AEPD issued a legal report in which it compiled the criteria it had been using to justify the use of DNI copies by data controllers in various resolutions.

The AEPD reminds that the scanning or photocopying of the DNI is a processing of personal data, remarking that the DNI number is a particularly sensitive information. In addition, it points out that in order to carry out this type of processing, a condition of lawfulness is required, in addition to complying with the principle of data minimization. The Agency considers that the scanning or photocopying of the DNI could involve unnecessary data processing, and therefore excessive for the purpose of identifying the data subject, so organizations should consider whether obtaining a copy of the DNI is really necessary for the intended purpose.

Request Document

Title: New AEPD criteria on the use of cookies.

Summary:

In July 2023, the AEPD updated its Guide on the use of cookies in order to adapt it to the Guidelines 03/2022 on misleading patterns of the European Data Protection Committee (ECDC).

In the new guide, the Agency states that the actions of accepting or rejecting cookies must be reflected in prominent formats, both at the same level (color, size, font, location...) and without prompting the user to accept cookies.

Likewise, it incorporates several modifications related to personalization cookies and cookie walls. The AEPD warns us that the so-called "cookie walls" that do not offer an alternative to consent may not be used. There may be certain cases in which the non-acceptance of the use of cookies prevents access to the website or the total or partial use of the service, provided that the user is properly informed about it and an alternative access to the service is offered without the need to accept the use of cookies, noting that this alternative need not necessarily be free of charge.

Organizations must have these new criteria in place by January 11, 2024.

Contact RGPD

Complies with all Data Policy regulations, secures your company.

Name and surname(Required)
Consent

  • PKF Attest
  • Services
  • Sectors
  • Locations
  • Corporate policies and certificates
  • Communication Area
  • News
  • Corporate videos
  • Press releases
  • Events
  • Connect with us
  • Talent
  • Contact
  • PKF Attest
  • 2025 All rights reserved © © 2025
  • Legal Notice
  • Privacy Policy
  • Cookies Policy
  • Complaints channel
  • Links to social networks

PKF Attest is a member of PKF Global, the network of member firms of PKF International Limited, each of which is a separate and independent legal entity and accepts no responsibility or liability for the actions or inactions of any individual member or correspondent firm(s). "PKF" and the PKF logo are registered trademarks used by PKF International Limited and member firms of the PKF Global network. They may not be used by anyone other than a duly authorized member firm of the Network.

PKF Attest is a member of PKF Global, the network of member firms of PKF International Limited, each of which is a separate and independent legal entity and does not accept any responsibility or liability for the actions or inactions of any individual member or correspondent firm(s). "PKF" and the PKF logo are registered trademarks used by PKF International Limited and member firms of the PKF Global Network. They may not be used by anyone other than a duly licensed member firm of the Network.

Photo by Javier Jordán

Javier Jordan

Javier is an experienced banker and financial advisor with over 20 years of experience in banking and financial advisory services covering capital markets, project and structured finance, syndicated loans origination and distribution.

Prior to joining PKF Attest CM, he worked at Banco Santander and prior to that at Banesto were he was Head of Structured Financing for the Basque Country region, responsible for origination, risk analysis, debt structuring and syndication of a wide range of financing products: corporate finance, project finance, LBO and debt restructuring.

Before Joining Banesto, Javier worked at Accenture and Management Solutions where he was senior consultant in different international projects covering banking and insurance sectors.

Javier holds BA Hons in Economics and Business Administration from Deusto University

Photo by Jokin

Jokin Cantera

Jokin has over 25 years of commercial and investment banking experience, with most of his career developed at Banco Santander, Banesto and JP Morgan Chase.

Prior to PKF Attest CM, Jokin worked at Santander Global Banking & Markets division (SGBM) in London, where he was Head of Northern European Institutional Sales, covering credit markets, rates and FX distribution of flow and non-flow products.

Before joining Banco Santander, Jokin was deputy general manager of the wholesale banking division at Banesto, responsible for credit markets (origination, trading and distribution), ACPM, securitization, rates and structured products distribution. He was also head of institutional sales, responsible for the structuring, origination and distribution of credit, rates, FX and multi-asset products to institutional investors.

With a strong innovative mindset and an entrepreneurial approach, Jokin was co-responsible for the creation of the Banesto Funding Platform, a unique primary bond market platform that helped corporates access the capital markets recurrently and efficiently through primary MTNs and CP issuance. He was also a board member of Banesto Financial Products PLC.

Jokin holds a BA Hons degree in Economics and Business Administration from Deusto University and has attended IESE, Chicago GSB & IE management programmes in Madrid and London.

Photo by Wafi Saleh

Wafi Saleh

Wafi has over 20 years of corporate and investment banking experience, with most of his career developed at Banco Santander and Banesto.

Prior to joining PKF Attest CM, he occupied various positions at Santander Global Banking & Markets division (SGBM), where he was Head of Middle East Corporates, Head of the Global Funding Platform, Head of the MTN Desk at the European Bond Syndicate, responsible for Private Placements origination covering European: Corporates, FIG, & SSA issuers.

Before joining Banco Santander, Wafi worked at Banesto, where he was Head of DCM, Bond Syndicate and the Funding Platform. He has extensive experience in bond issuance and has set up and managed the SPV, the EMTN and ECP programmes for the bank and corporate clients, issuing vanillas and structured notes. He was a board member of Banesto Financial Products PLC and Santander International Products PLC.

Wafi has an outstanding fingerprint in the capital markets and is co-responsible for the creation and management of the Banesto Funding Platform, a unique primary bond market platform that helped corporates access capital markets recurrently and efficiently through primary MTNs and CP issuance.

Wafi holds a BA Hons degree in International Business and Management studies from the European Business School, London, and has attended IESE management development program in Madrid.

Report: IFRS Adoption Process

Access to exhaustive information on the International Financial Reporting Standards, identifying some of the main differences in valuation with the General Accounting Plan, without the scope of the work performed pretending to be exhaustive.

Fill in the form and get instant access to the report!

If you consent, we will use this information to send you PKF Attest related content.

 

M&A Report - Chemical Sector

Download our exclusive and free report "M&A Overview - chemical sector", prepared by PKF Attest's M&A experts. Access data and trends for 2024

If you give your consent, you are accepting our privacy policy and PKF Attest information security policies.

Iberian M&A Overview

Access data and trends in the pharmaceutical sector in 2024.

Download our exclusive and free report "Iberian M&A Overview", prepared by the M&A experts at PKF Attest.

If you consent, we will use this information to send you related content, discounts and other special offers.

M&A Report - Packaging Sector

Download our exclusive and free report "M&A Overview - Packaging Sector", prepared by the M&A experts at PKF Attest. Access 2024 and 2025 industry data and trends.

If you give your consent, you are accepting our privacy policy and PKF Attest information security policies.

M&A Report - Technology Sector

Download our exclusive and free report "M&A Overview - Technology Sector", prepared by the M&A experts at PKF Attest. Access 2024 and 2025 data and trends in the IT services sector.

If you give your consent, you are accepting our privacy policy and PKF Attest information security policies.

 

If you give your consent, you are accepting our privacy policy and PKF Attest information security policies.

Download our exclusive and free report "M&A Overview - Iberian Automotive sector", prepared by the M&A experts at PKF Attest. Access data and trends for 2024.

 

If you consent, we will use this information to send you related content.

M&A Report - Mechanical Engineering

Download our exclusive and free report "M&A Overview - Mechanical Engineering Sector", prepared by the M&A experts at PKF Attest. Access 2024 and 2025 data and trends in the industry.

If you give your consent, you are accepting our privacy policy and PKF Attest information security policies.

We love to see you here! PKF ATTEST SERVICIOS PROFESIONALES, S.L. uses its own and third party cookies for a variety of purposes, such as improving your browsing experience and our service. The use of cookies by third parties is subject to their own cookie policy. You can accept or reject all use of cookies by clicking on the "Accept all and close" or "Reject all" button. You can also set and save your cookie preferences by clicking on the "Set cookies" button. You can learn more about the use of cookies and your rights in our cookie policy.

 


Strictly necessary cookies

Third party cookies

Powered by GDPR Cookie Compliance
Privacy summary

This website uses cookies so that we can provide you with the best possible user experience. Cookie information is stored in your browser and performs functions such as recognizing you when you return to our site or helping our team understand which sections of the site you find most interesting and useful.

Strictly necessary cookies

Strictly necessary cookies must always be enabled so that we can save your cookie setting preferences.

If you disable this cookie we will not be able to save your preferences. This means that every time you visit this website you will have to enable or disable cookies again.

Third party cookies

This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, or the most popular pages.

Leaving this cookie active allows us to improve our website.

Please enable strictly necessary cookies first so that we can save your preferences!