Blog
Checklist: get a company compliant with the RGPD in 15 minutes
General information about the law. It’s no substitute for a lawyer’s advice or a look at your specific case.
Getting your company compliant with the RGPD in 15 minutes means completing 10 minimum steps: knowing what data you handle, having your privacy notice clauses ready, signing the contracts with whoever processes data on your behalf and knowing what to do if there is a security failure. This checklist takes you step by step, with the exact article of Reglamento (UE) 2016/679 (RGPD) or of Ley Orgánica 3/2018 (LOPDGDD, Spain's data protection act) that backs each point. Last reviewed: 16 July 2026.
Contents
- What does this checklist cover and what does it not cover?
- Step 1: do you know what data your business handles?
- Step 2: do you have your record of processing activities?
- Step 3: do your customers know what you do with their data?
- Step 4: do you have cameras? Is the sign up?
- Step 5: who processes data on your behalf, and do you have the contract signed?
- Step 6: does your team know they must keep confidentiality?
- Step 7: do you know what to do if there is a security failure?
- Step 8: do you know how to reply if someone asks you for their data?
- Step 9: does your website have a privacy policy and a cookie policy?
- Step 10: when do you review it again?
- What happens if you are not compliant?
- Frequently asked questions
What does this checklist cover and what does it not cover?
This checklist gives you a defensible minimum baseline, not a full audit. It works for self-employed people, SMEs and businesses in any sector: a restaurant, a hairdresser's, a clinic, a workshop. It does not replace an analysis tailored to your business, above all if you handle delicate data such as health data.
Each step has three things: what to check, how long it takes and the article of the law that requires it. If you answer “I don't know” at any point, mark it and come back to it calmly: you do not have to finish it all in the same session.
Step 1: do you know what data your business handles? (2 minutes)
Before any document, you need the basic list. Jot down, without thinking about it too much:
- Your customers' data (name, email, phone, and whether you keep anything else).
- Your employees' data (payroll, contract, and whether you use a fingerprint or a camera for clocking in).
- Your suppliers' data.
- Whether you have cameras, a marketing newsletter or forms on your website.
It does not have to be perfect. It is the draft on which you are going to build the rest of the checklist. This first inventory is the basis of the record of processing activities required by article 30 of the RGPD.
Step 2: do you have your record of processing activities? (3 minutes)
The record of processing activities (RAT) is your list of the data you handle and what for, processing operation by processing operation. It lets you demonstrate it if the Agencia Española de Protección de Datos (AEPD, Spain's data protection authority) asks you for it.
- [ ] You have a file for each thing you do with data: customers, employees, suppliers, cameras, marketing.
- [ ] Each file says what the data is, what you use it for, who else sees it and how long you keep it.
This document is obligatory for practically any business (art. 30 RGPD). The AEPD offers a free tool, Facilita RGPD, designed for businesses with low-risk processing: a questionnaire of about 20 minutes that generates the minimum documents, including the RAT.
Step 3: do your customers know what you do with their data? (2 minutes)
Every time you ask a customer for a piece of data —on a form, a contract or a booking— you have to tell them what you do with it. This is called informing about the processing (art. 13 RGPD).
- [ ] Your forms and contracts carry a clause that says who you are, what you use the data for and how long you keep it.
- [ ] If you ask for consent for something (for example, sending advertising), the box is empty by default: nobody ticks it for you.
A pre-ticked consent is not valid: the law requires a clear affirmative action from the person (art. 4.11 and art. 7 RGPD).
Step 4: do you have cameras? Is the sign up? (2 minutes)
If you record images of people —the one in the shop window, the one in the warehouse, even a fixed mobile phone camera—, you are processing their data.
- [ ] There is a visible sign at every entrance to the area with cameras, with your identity and where to exercise data protection rights.
- [ ] You know how long you keep the recordings and why.
The sign has an official template: the AEPD itself publishes the videosurveillance sign ready to print (art. 22 LOPDGDD, art. 13 RGPD). You do not have to invent it: you copy it as it is.
Step 5: who processes data on your behalf, and do you have the contract signed? (3 minutes)
A gestoría (a Spanish firm handling tax, payroll and administrative filings), an IT technician, a hosting company or an email marketing tool that handles your customers' or employees' data is what the law calls a data processor: an external company that handles data on your behalf.
- [ ] You have a list of who processes data on your behalf outside your business.
- [ ] With each of them, there is a signed contract that requires them to protect that data just as you do.
This contract is obligatory, not optional (art. 28 RGPD). If you take on someone new who is going to touch your customers' or your team's data, the contract is signed before you give them access, not afterwards.
Step 6: does your team know they must keep confidentiality? (1 minute)
Anyone who works with you and sees customer data or data about other colleagues has a commitment not to tell what they see at work.
- [ ] Each person on your team has signed a confidentiality commitment, or has it in writing in their contract.
This obligation is expressly provided for the private sector (art. 5 LOPDGDD). It is one of the quickest documents to sort out and one of the most often forgotten.
Step 7: do you know what to do if there is a security failure? (1 minute)
It does not have to be the case that nothing ever happens to you. But it is worth knowing, before it happens, what you have to do if you lose a mobile with data on it, if someone gets into your email or if you send data to the wrong person.
- [ ] You know that you have 72 hours from when you find out to notify the AEPD, if the failure poses a risk to the people affected.
- [ ] You know that, even if you do not have to notify the AEPD, you have to write it down in your internal incident log.
The 72-hour deadline and the internal incident log are in article 33 of the RGPD. The AEPD publishes a practical guide to managing and notifying security breaches with the complete step by step.
Step 8: do you know how to reply if someone asks you for their data? (1 minute)
Any person —a customer, a former employee— can ask you to see their data, to correct it, to erase it or to send it to them in a file.
- [ ] You know that you have 1 month to reply from when you receive the request (with the possibility of extending it by 2 more months if the request is complex).
- [ ] You are clear about which email or address that request must reach.
The one-month deadline is in article 12.3 of the RGPD. The AEPD publishes a model form for the right of access that you can adapt to your business.
Step 9: does your website have a privacy policy and a cookie policy? (1 minute)
If you have a website, even if it is only informational, you need two basic texts: what you do with the data you collect (contact form, newsletter) and what cookies you use.
- [ ] Your website has a privacy policy linked from any form.
- [ ] The cookie notice lets people choose “accept” and “reject” with the same visual weight: none of a big accept button and a small link to reject.
This combines the RGPD with the Spanish rules on information society services (LSSI) for non-essential cookies.
Step 10: when do you review it again? (1 minute)
This checklist is not filled in just once. It is reviewed when something real changes in your business: a new employee, a new supplier, a new camera, a new tool.
- [ ] You have a date in the calendar to go over it, at least once a year.
With this you have the 10 points covered. If you have got this far and you are missing several, that is fine: note down which ones and carry on with the next one that is easiest for you.
What happens if you are not compliant?
The AEPD is the body that supervises this in Spain. It can ask for explanations, order changes, give a warning or impose a fine. The RGPD sets the possible maximums at two levels: up to 10 million euros or 2 % of annual worldwide turnover, and up to 20 million or 4 %, depending on the infringement (art. 83 RGPD). The higher of the two figures applies.
In practice those figures are the legal ceiling, not the norm: the penalty is graded according to the seriousness, the size of the business and whether you have cooperated. A small business that gets organised and responds well is not in that scenario. That is why you are here: to have it done and stop thinking about it.
Frequently asked questions
Does this checklist replace a full audit?
No. It is a minimum baseline for businesses with low-risk data processing. If you handle health data, data about minors or you do large-scale profiling, you need a more in-depth analysis, and possibly an impact assessment (art. 35 RGPD).
Is it useful for self-employed people with no employees?
Yes. If you have customers, suppliers or a website with a form, you already process personal data. Steps 6 (employee confidentiality) do not apply if you work alone, but the rest do.
Do I need a data protection officer (DPD)?
It depends on your activity and on the volume of data you handle, not on the number of employees. Most SMEs and self-employed people are not required to have one. The AEPD guidance for SMEs explains the specific cases in which one is needed.
What happens if I find that something is missing when I do the checklist?
Nothing urgent or retroactive: simply do it as soon as you can, starting with the easiest. The AEPD values the attitude of those who get organised and put things right, not just the final result at a given moment.
How often do I have to go over this checklist?
At least once a year, and whenever something real changes in your business: a new employee, a new camera, a new supplier or a new tool that touches customer data.
Is this checklist a legal document on its own?
No. It is informational content to guide you. The documents you really need (record of activities, clauses, contracts, sign) are separate items, tailored to your business.
Would you rather do these 10 steps in a guided way, with the documents already drafted and ready to sign? Tranquilia's free tier covers up to 2 companies, with all the features, with no time limit and no card. Try it free or check the prices if you need more companies.
If your business has cameras, the natural next step is to generate your videosurveillance sign with your details already filled in.
Content produced with the support of artificial intelligence and verified against official sources (AEPD, BOE, EUR-Lex) by Tranquilia by GRAC SA. It does not constitute an official certification or a legal opinion. Consult your gestoría or a legal professional for your specific case.
Sources cited in this article:
- Reglamento (UE) 2016/679 (RGPD) — consolidated text, EUR-Lex
- Ley Orgánica 3/2018, de 5 de diciembre (LOPDGDD) — BOE-A-2018-16673
- AEPD — What is the record of processing activities?
- AEPD — Facilita RGPD
- AEPD — Guidance for small and medium-sized enterprises (PYMES)
- AEPD — Personal data breaches
- AEPD — Guide to notifying personal data breaches (PDF)
- AEPD — Videosurveillance information sign, official template (PDF)
- AEPD — Frequently asked questions about video cameras
- AEPD — Form for exercising the right of access (PDF)
Review: Written with AI support and verified against official sources (AEPD, BOE, EUR-Lex). It does not replace individualised legal advice. Translation of the Spanish original, which prevails in case of divergence.
Get your clients GDPR-compliant in 15 minutes.
No card, no sales calls. Two companies free, for as long as you like.