Tranquilidad con simplicidad
Compliance for companies with fewer than 50 employees
The four pillars of compliance that affect a small company or self-employed professional with fewer than 50 employees: data protection, criminal compliance, occupational risk prevention, and equality and employment records. Plus every document Tranquilia generates for each one.
Compliance is not just the RGPD. A company or self-employed professional with fewer than 50 employees has to answer, at the same time, to the Agencia Española de Protección de Datos (Spain's data protection authority), to the Inspección de Trabajo (the labour inspectorate) and, if it comes to it, to the criminal courts. That is four fronts with different laws, and on almost every one there are documents the law simply assumes you have.
Tranquilia starts from a short questionnaire per company and generates those documents already adapted to your line of business, in plain language and ready to sign. Here are the four pillars and, within each one, the documents it covers, with an article explaining each in detail.
Data protection (RGPD and LOPDGDD)
The best-known pillar, but not the only one. It is about the personal data you handle: your clients', your staff's and your suppliers'. It is governed by Regulation (EU) 2016/679 (RGPD) and by Ley Orgánica 3/2018 (LOPDGDD), and it is supervised by the AEPD.
- Record of processing activities (RAT) — the inventory of what data you process and what for (art. 30 RGPD).
- Data protection impact assessment (AIPD/EIPD) — only for high-risk processing (art. 35 RGPD).
- Privacy policy — the duty to inform (arts. 13 and 14 RGPD).
- Cookie policy — consent on your website (art. 22 LSSI).
- Processor agreement — with every supplier that processes data on your behalf (art. 28 RGPD).
- Data breach procedure — what to do in the first 72 hours (arts. 33 and 34 RGPD).
- Data subject rights procedure — how you handle someone asking to see or delete their data (arts. 15 to 22 RGPD).
- Record of consents — the proof that you have permission (art. 7 RGPD).
Criminal compliance (corporate liability)
Since art. 31 bis of the Código Penal (Spain's criminal code), a company can be held criminally liable for offences committed on its behalf. An adequate and effective crime prevention model is the shield that can exempt it from that liability or mitigate it. It is not a fine for not having one: it is being left with no defence if something happens.
- Crime prevention plan — the compliance model that acts as the shield (art. 31 bis CP).
- Criminal risk map — where your company is exposed to an offence.
- Code of ethics and conduct — the ground rules that hold the model up.
- Disciplinary rules — the consequences that give the model teeth.
Occupational risk prevention (PRL)
The moment you have a single worker, Ley 31/1995 requires you to protect their safety and health, and to be able to prove it. It is supervised by the Inspección de Trabajo, and the infringements are among the most far-reaching in Spanish employment law.
- Occupational risk prevention plan — mandatory from the first worker (art. 16 LPRL).
- Risk assessment by job role — what can cause harm in each role (art. 16 LPRL and RD 39/1997).
- Harassment protocol — mandatory in every company, whatever its size (art. 48 LO 3/2007).
- Emergency and evacuation plan — what to do if something goes badly wrong (art. 20 LPRL).
- Training and PPE record — the proof that you informed and protected (arts. 18 and 19 LPRL, RD 773/1997).
Equality and employment records
A group of employment obligations that many small companies do not know about, because they believe they only affect large ones. Most of them, in fact, do not depend on size.
- Pay register — mandatory for every company with staff (RD 902/2020 and art. 28 ET).
- Working time record — the daily record of clocking in and out (art. 34.9 ET).
- Digital disconnection policy — the right not to be available outside working hours (art. 88 LOPDGDD).
One questionnaire, the whole folder
You do not need to know in advance which documents apply to you. You register the company, the app recognises its line of business and asks you only what is needed. At the end, out come the documents from the four pillars that apply to it, with its name and its logo. You can try it with up to 2 companies, with no card and no time limit.
Get your clients GDPR-compliant in 15 minutes.
No card, no sales calls. Two companies free, for as long as you like.