RGPD gestorías
Complete RGPD guide for gestorías and asesorías (2026): what the law requires of you and how to comply
General information about the law. It’s no substitute for a lawyer’s advice or a look at your specific case.
Direct answer: the RGPD (Reglamento (UE) 2016/679, the EU data protection regulation) and the LOPDGDD (Ley Orgánica 3/2018, Spain's data protection act) require every Spanish gestoría or asesoría (a firm that handles other companies' tax, accounting and payroll work) to keep a record of its data processing, to sign a processor contract (contrato de encargado del tratamiento, art. 28 RGPD) with every client whose data it handles, and to notify the AEPD (Spain's data protection authority) of any security breach within a maximum of 72 hours (art. 33 RGPD). Most gestorías do not need to appoint a data protection officer (delegado de protección de datos): the list of entities that must do so is closed in art. 34.1 LOPDGDD, and an asesoría does not appear in it simply because it is an obliged entity under the anti-money-laundering law. This guide, last reviewed on 16 July 2026, explains each obligation with its exact article.
This article is general information about data protection law. It does not replace advice from a lawyer or a specific analysis of your own firm: use it as a map, not as a legal opinion.
Contents
- Who does the RGPD bind, and why does it affect your gestoría twice?
- Which documents must your firm have?
- Do you need a data protection officer?
- What deadline do you have if there is a security breach?
- How long do you have to respond to a client who asks for their data?
- Does your gestoría have any extra obligations under the anti-money-laundering law?
- What happens if you do not comply?
- Checklist: where to start
- Frequently asked questions
Who does the RGPD bind, and why does it affect your gestoría twice?
The RGPD applies to any business, autónomo (self-employed professional) or entity that processes the data of natural persons in the European Union, whatever its size. There is no exemption for SMEs or for the self-employed: a two-person asesoría and a multinational are governed by the same regulation, even though the number of specific measures each one needs is different (art. 5 RGPD, the accountability principle).
A gestoría or asesoría is special because it plays two distinct roles that never mix:
- As a processor (art. 28 RGPD): when you keep a client's accounts, payroll or taxes, you process the data of their employees, their clients or their suppliers on that client's instructions. They decide what those data are used for and answer for the legal basis; you sign a processor contract with them setting out what you may do, how you protect those data and what happens to them when the contract ends.
- As a controller: for your own business's data — your staff, your suppliers, your own invoicing, your marketing — you answer exactly like any other company.
If you handle the payroll side for several clients, you also process health data (sick leave, degree of disability) that appears on the payslips: this is special category data (art. 9 RGPD) and it calls for a reinforced confidentiality obligation with your team, even though the legal basis for processing it is your client's.
Which documents must your firm have?
The documentary core that the RGPD requires of a gestoría, with its exact article:
- Record of processing activities (art. 30 RGPD): the list of which data you handle, what for and for how long. As a processor, your version of the record is shorter than a controller's (art. 30.2 RGPD).
- Processor contract (art. 28 RGPD) with every client whose data you handle — and with every subcontractor if you pass part of the work to another professional (art. 28.2 RGPD).
- Privacy notices for your own clients and for your staff (arts. 13-14 RGPD): which data you process, what for and on what legal basis.
- Risk analysis and, where applicable, a data protection impact assessment (EIPD) when the processing is likely to entail a high risk to individuals (art. 35 RGPD) — for example, if you handle the payroll side for many clients at once and therefore process health data on a large scale.
- Security incident log (art. 33.5 RGPD): every breach is documented internally, whether or not it is notified to the AEPD.
- Retention policy: how long you keep each piece of data and when you delete it (art. 5.1.e RGPD, the storage limitation principle).
- Rights procedure: how you respond when someone asks to access, rectify, erase or take away their data (arts. 12-22 RGPD).
Do you need a data protection officer?
Almost certainly not, and it is worth explaining properly because it is one of the questions that circulates most among gestorías. Under art. 34.1 LOPDGDD (consolidated text on the BOE) there is a closed list of types of entity required to designate an officer, on top of the general cases in art. 37.1 RGPD (public authorities, regular and systematic monitoring on a large scale, or large-scale processing of special category data).
An asesoría or gestoría does not appear on that list by virtue of providing tax, accounting or payroll services. The only sub-paragraph of art. 34.1 LOPDGDD that mentions anti-money-laundering law is sub-paragraph j), and it refers to whoever is the controller of a shared sector-wide file (the files on creditworthiness or on fraud prevention) — not to the professionals who, like a gestoría, consult or feed those files when applying their client identification obligations. Being an "obliged entity" (sujeto obligado) under the Ley 10/2010 does not make you the controller of a shared file.
That said, every firm is a specific case: if your volume of health data handled through the payroll side grows a great deal, or if you process data on a scale that is unusual for the sector, review your situation with a lawyer. Even where it is not compulsory for you, appointing an officer is always a valid voluntary option (art. 34.2 LOPDGDD) — with the caveat that, once appointed, you become subject to the same regime as if it were compulsory.
What deadline do you have if there is a security breach?
If you lose a laptop with data on it, someone gets into your email, or you send information to the wrong person, the clock starts running. Under art. 33 RGPD you have a maximum of 72 hours from the moment you became aware to notify the AEPD through its online portal (sede electrónica), unless it is unlikely to entail a risk to the rights of the people affected. If the risk is high, you must also warn the people affected directly, without delay and in clear language (art. 34 RGPD).
Even when you decide there is no need to notify the AEPD, the law still requires you to record the incident internally in your incident log (art. 33.5 RGPD): documenting every failure, whether or not it is notified, is obligatory.
How long do you have to respond to a client who asks for their data?
When someone asks you for access to their data, to correct it, to erase it or to hand it over in a file so they can take it somewhere else, you have one month from the day you receive the request to respond (art. 12.3 RGPD). That deadline can be extended by a further two months for especially complex requests, provided you tell the person the reason within the first month.
If the deadline passes, the right course is not to ignore it: answer as soon as you can, record the actual date of your response and follow the procedure anyway.
Does your gestoría have any extra obligations under the anti-money-laundering law?
If you provide tax, accounting or payroll advice, the Ley 10/2010, de prevención del blanqueo de capitales y de la financiación del terrorismo, makes you an "obliged entity" (art. 2.1) and requires you to identify your clients —including the beneficial ownership of companies— before you start working for them. This obligation is independent of the RGPD, but it generates data processing of its own (a copy of the identity document, the economic activity, the approximate origin of the funds) that also has to be documented and protected: restricted access, kept in separate custody from the ordinary tax file.
What happens if you do not comply?
The AEPD is the body that supervises RGPD compliance in Spain. It can ask for explanations, order changes, issue a formal warning or impose a fine. Under art. 83 RGPD the possible maximums sit at two levels — up to 10 million euros or 2% of annual worldwide turnover, and up to 20 million or 4%, depending on the infringement, with the higher of the two figures applying.
In practice those figures are the legal ceiling, not the norm: the penalty is graded according to the seriousness, the size of the business and whether you have cooperated with the Agency. According to the AEPD itself, in 2025 the Agency received 30,931 complaints, the highest figure in its history (+64% on 2024), and imposed fines totalling €48,108,765 — almost 40% of that amount for badly handled security breaches. These are official figures, not a threat: they reflect that supervision is tightening, and that the area where most penalties fall (security breaches) is precisely the one you avoid with a clear internal procedure applied in time.
A small business that has its documentation in order, responds on time and cooperates with the Agency is not in the scenario of the maximum figures. That is why it is worth getting this settled: not to avoid a one-off scare, but to stop thinking about it.
Checklist: where to start
If you have nothing prepared yet, this is the sensible order:
- Write down in a list which data you process on your clients' instructions and which are your own (record of activities).
- Check that you have a signed processor contract (art. 28 RGPD) with every active client.
- Write down who responds if a rights request or a security breach comes in, and within what deadline.
- Check where your software and backups are hosted: if they leave the European Union, review the safeguards for that transfer.
- Put in writing, with a date, why you do not need a data protection officer (or why you do).
Each of these points has its own model document inside Tranquilia, generated from the answers in your wizard.
Frequently asked questions
Does the RGPD apply the same way to an autónomo as to a large company?
Yes. The regulation does not distinguish by size or by legal form (art. 5 RGPD). What changes is the volume of specific measures you need: a small gestoría does not need the same as a large firm, but both start from the same baseline obligations.
Does a gestoría need its clients' consent to keep their accounts?
No. The legal basis for providing the contracted service is performance of the contract (art. 6.1.b RGPD), not consent. Consent is only needed for what is not necessary for the service, such as sending newsletters or promotions.
What is the difference between a controller and a processor?
The controller decides what the data are used for and on what legal basis. The processor processes them on someone else's behalf, following their instructions. A gestoría is the processor of its client's clients' data, and the controller of its own business's data (art. 4.7 and 4.8 RGPD).
How long does the AEPD take to resolve a complaint?
This guide does not set a single resolution deadline for every complaint: it depends on the type of procedure. What does have a fixed deadline is your obligation to respond to individuals (one month, art. 12.3 RGPD) and to notify breaches (72 hours, art. 33 RGPD).
Does having cloud-based gestoría software release me from liability?
No. The software you use is your processor (art. 28 RGPD): you remain responsible for there being a contract with it and for choosing a provider that offers sufficient guarantees. Responsibility is not delegated, it is shared out by contract.
Want to see it applied to your own firm? Tranquilia automatically generates the record of activities, the processor contract and the rest of the documents in this guide from a questionnaire tailored to asesorías and gestorías. The free tier lets you try it with up to 2 companies, with no card and no time limit — visit it at tranquilia.es.
Guide produced by Tranquilia by GRAC SA. Published on 16 July 2026. Last reviewed: 16 July 2026. The content draws on the official sources cited below and does not constitute individual legal advice.
Sources
- Reglamento (UE) 2016/679 (RGPD) — EUR-Lex
- Ley Orgánica 3/2018, de 5 de diciembre (LOPDGDD) — texto consolidado, BOE
- Ley 10/2010, de 28 de abril, de prevención del blanqueo de capitales — BOE
- AEPD — Notificación de brechas de seguridad (art. 33 RGPD), Sede electrónica
- AEPD — Nota de prensa: «La Agencia recibió más de 30,000 reclamaciones en 2025, un 64% más que el año anterior» (6 de mayo de 2026)
Review: Tranquilia by GRAC SA — AI-assisted drafting with primary-source verification. Translation of the Spanish original, which prevails in case of divergence.
Get your clients GDPR-compliant in 15 minutes.
No card, no sales calls. Two companies free, for as long as you like.