# Blog

Articles on the GDPR, the LOPDGDD and the EU AI Act, written to be understood, with the official sources linked. If we don’t know something, we say so.

- [Code of ethics and conduct: the rules of the game that hold up your compliance](https://tranquilia.es/en/blog/codigo-etico-y-de-conducta) — What a code of ethics and conduct is, why it is a key piece of the crime prevention model in art. 31 bis of the Código Penal, and how it connects with the rest of criminal compliance. (Last reviewed: 2026-07-18)
- [Impact assessment (EIPD/AIPD): when you need one and how to tell](https://tranquilia.es/en/blog/evaluacion-de-impacto-aipd) — What the data protection impact assessment (EIPD) under art. 35 RGPD is, in which cases it is obligatory for an SME and what happens if you process high-risk data without having done one. (Last reviewed: 2026-07-18)
- [Risk assessment by job role: the document the Inspección asks for first](https://tranquilia.es/en/blog/evaluacion-de-riesgos-por-puesto) — What the occupational risk assessment by job role is, why Ley 31/1995 and RD 39/1997 require it, and how it connects with the planning of prevention measures. (Last reviewed: 2026-07-18)
- [Criminal risk map: where your company could get into criminal trouble](https://tranquilia.es/en/blog/mapa-de-riesgos-penales) — What the criminal risk map is, why art. 31 bis of the Código Penal requires you to identify the activities where offences could be committed, and why it is the first piece of compliance that works. (Last reviewed: 2026-07-18)
- [Emergency and evacuation plan: what art. 20 of the Ley de PRL requires](https://tranquilia.es/en/blog/plan-de-emergencia-y-evacuacion) — What the emergency and evacuation measures plan is, why art. 20 of Ley 31/1995 requires any company with workers to have one, and what it must include to be genuinely useful. (Last reviewed: 2026-07-18)
- [Crime prevention plan (criminal compliance): the shield of art. 31 bis of the Código Penal](https://tranquilia.es/en/blog/plan-de-prevencion-de-delitos) — What the crime prevention plan or criminal compliance model is, why art. 31 bis of the Código Penal turns it into a shield against your company's criminal liability, and why it also matters to a small business. (Last reviewed: 2026-07-18)
- [Occupational risk prevention plan: mandatory from your first worker](https://tranquilia.es/en/blog/plan-de-prevencion-de-riesgos-laborales) — What the occupational risk prevention plan is, why Ley 31/1995 requires it of any company with at least one worker, and what you risk before the Inspección de Trabajo if you do not have one. (Last reviewed: 2026-07-18)
- [Cookie policy: what the law requires and why a badly built banner gives you away](https://tranquilia.es/en/blog/politica-de-cookies) — What the cookie policy is, what art. 22.2 of the LSSI and the RGPD require about consent, and why a banner that does not let people refuse is one of the things the AEPD penalises most. (Last reviewed: 2026-07-18)
- [Digital disconnection policy: the art. 88 LOPDGDD document almost nobody has](https://tranquilia.es/en/blog/politica-de-desconexion-digital) — What the digital disconnection policy is, why art. 88 of the LOPDGDD requires every company to draw one up, and how it relates to your employees' right not to be available outside their working hours. (Last reviewed: 2026-07-18)
- [Privacy policy: what you must inform people about and where to put it](https://tranquilia.es/en/blog/politica-de-privacidad) — What the privacy policy must include under arts. 13 and 14 of the RGPD, where you have to show it on your website and your forms, and what risk you run if you don't inform people properly. (Last reviewed: 2026-07-18)
- [Rights procedure: what to do when someone asks to see or delete their data](https://tranquilia.es/en/blog/procedimiento-de-derechos) — What rights the RGPD recognises (access, rectification, erasure, objection and more), how long you have to reply and why it is worth having a written procedure before the first request arrives. (Last reviewed: 2026-07-18)
- [Harassment protocol: obligatory in every company, whatever its size](https://tranquilia.es/en/blog/protocolo-de-acoso) — What the protocol against sexual harassment and harassment on grounds of sex is, why art. 48 of LO 3/2007 requires it of any company whatever its headcount, and what LO 10/2022 reinforces. (Last reviewed: 2026-07-18)
- [Disciplinary regime: without it, your compliance model has no teeth](https://tranquilia.es/en/blog/regimen-disciplinario) — What the disciplinary regime is within criminal compliance, why art. 31 bis of the Código Penal requires a system that penalises breaches of the model, and how it rests on the Estatuto de los Trabajadores. (Last reviewed: 2026-07-18)
- [Record of processing activities (RAT): what it is and why almost no company escapes it](https://tranquilia.es/en/blog/registro-de-actividades-de-tratamiento) — What the record of processing activities under art. 30 RGPD is, why the exemption for companies with fewer than 250 employees almost never applies to you and what risk you run if you do not have it. (Last reviewed: 2026-07-18)
- [Consent record: how to prove you have permission to process the data](https://tranquilia.es/en/blog/registro-de-consentimientos) — What the consent record is, why art. 7 of the RGPD requires you to be able to prove that the person said yes and how to avoid the pre-ticked box mistake. (Last reviewed: 2026-07-18)
- [Training and EPI records: the proof that you informed and protected your people](https://tranquilia.es/en/blog/registro-de-formacion-y-epi) — Why Ley 31/1995 requires you to train and inform your workers (arts. 18 and 19) and to give them personal protective equipment (RD 773/1997), and why without a record it is as if you had not done it. (Last reviewed: 2026-07-18)
- [Working time records: what art. 34.9 of the Estatuto de los Trabajadores requires](https://tranquilia.es/en/blog/registro-de-jornada) — What the daily working time record is, why art. 34.9 of the Estatuto de los Trabajadores makes it obligatory for your whole workforce, and what risk of a serious penalty you run if you don't keep it. (Last reviewed: 2026-07-18)
- [Pay register: obligatory for every company with staff](https://tranquilia.es/en/blog/registro-retributivo) — What the pay register is, why RD 902/2020 and art. 28 of the Estatuto de los Trabajadores require it from any company with workers, and what employment risk you run if you don't have it. (Last reviewed: 2026-07-18)
- [Security breaches: what to do in the first 72 hours](https://tranquilia.es/en/blog/brechas-de-seguridad-primeras-72-horas) — What a data security breach is, when you have 72 hours to notify the AEPD and what you have to document even if you notify nothing, with the official RGPD and AEPD sources. (Last reviewed: 2026-07-16)
- [Checklist: get a company compliant with the RGPD in 15 minutes](https://tranquilia.es/en/blog/checklist-pon-una-empresa-en-regla-en-15-minutos) — The 10 minimum steps to get your business compliant with the RGPD, with the exact article that backs each one. Designed for you to do it yourself, without jargon, in 15 minutes. (Last reviewed: 2026-07-16)
- [Dental clinics and health data: EIPD, DPO and consents](https://tranquilia.es/en/blog/clinicas-dentales-datos-salud-eipd-dpo-consentimientos) — What RGPD obligations a dental clinic has for processing health data: when a data protection officer (DPO) is needed, when an EIPD has to be carried out and what consents to ask patients for. With official sources and a real penalty case. (Last reviewed: 2026-07-16)
- [Processor contract (art. 28 RGPD): when and with whom to sign it](https://tranquilia.es/en/blog/contrato-encargado-tratamiento-art-28-cuando-y-con-quien) — When the processor contract is obligatory, which providers you have to sign it with and what it must include as a minimum, under art. 28 of the RGPD and the AEPD's guidance. (Last reviewed: 2026-07-16)
- [Complete RGPD guide for gestorías and asesorías (2026): what the law requires of you and how to comply](https://tranquilia.es/en/blog/guia-completa-rgpd-gestorias-asesorias-2026) — Which documents, deadlines and obligations the RGPD and the LOPDGDD impose on a Spanish gestoría or asesoría in 2026: record of processing activities, processor contract, data protection officer, security breaches and your clients' rights, with official sources (AEPD, BOE, EUR-Lex). (Last reviewed: 2026-07-16)
- [LOPDGDD: what it adds to the European law (RGPD) and what obligations you have](https://tranquilia.es/en/blog/lopdgdd-que-anade-a-la-ley-europea) — The LOPDGDD does not replace the RGPD, it completes it. What obligations the Spanish law adds that are not in the European regulation: minors, deceased people, video surveillance, the data protection officer and the digital rights in title X, with the exact article and official sources (BOE, EUR-Lex, AEPD). (Last reviewed: 2026-07-16)
- [Marketing, newsletters and the Lista Robinson: how to do it legally](https://tranquilia.es/en/blog/marketing-newsletters-y-lista-robinson) — When you can send a newsletter or a commercial email, what the Lista Robinson is and how to ask your customers for permission without risking a spam penalty, with the official sources (LSSI, LOPDGDD, RGPD, AEPD). (Last reviewed: 2026-07-16)
- [The European AI Act for SMEs: the real 2026 timeline (with the June delay)](https://tranquilia.es/en/blog/reglamento-ia-europeo-para-pymes-calendario-2026) — What the European AI Act (Reglamento (UE) 2024/1689) already requires of a Spanish SME, what changes on 2 August 2026 and what has been moved by the «Digital Omnibus» approved by the Council of the EU on 29 June 2026. With official sources (EUR-Lex, Council of the EU, AEPD, BOE) and a clear timeline, with no invented dates. (Last reviewed: 2026-07-16)
- [RGPD in a restaurant: the 9 documents you need](https://tranquilia.es/en/blog/rgpd-en-un-restaurante-los-9-documentos) — What data protection paperwork a bar or restaurant in Spain needs: record of processing activities, clauses for customers and employees, camera sign, contract with suppliers and more. Explained without jargon, with official sources. (Last reviewed: 2026-07-16)
- [Real AEPD fines on SMEs: cases and lessons](https://tranquilia.es/en/blog/sanciones-reales-aepd-a-pymes-casos-y-lecciones) — The AEPD imposed 281 fines worth 35,592,200 € in 2024. We go through 3 real, public cases against small businesses —cameras, defaulters registers, sales calls— with a link to the original decision for each one. (Last reviewed: 2026-07-16)
- [Do you use ChatGPT or other AI in your business? Your legal obligations explained](https://tranquilia.es/en/blog/usas-chatgpt-u-otras-ia-en-tu-negocio-obligaciones) — If you use ChatGPT, Copilot or another AI in your business, two sets of rules apply to you at once: the RGPD and the new European AI Regulation. What is obligatory now, what arrives in August 2026 and how to comply, with official sources. (Last reviewed: 2026-07-16)
- [Video surveillance in your business: sign, time limits and rights](https://tranquilia.es/en/blog/videovigilancia-en-tu-negocio-cartel-plazos-derechos) — Which sign you need if you have cameras, how long you can keep the recordings and what someone caught on camera can ask you for. With the official AEPD sources and Spanish law. (Last reviewed: 2026-07-16)
