---
title: "Complete RGPD guide for gestorías and asesorías (2026): what the law requires of you and how to comply"
description: "Which documents, deadlines and obligations the RGPD and the LOPDGDD impose on a Spanish gestoría or asesoría in 2026: record of processing activities, processor contract, data protection officer, security breaches and your clients' rights, with official sources (AEPD, BOE, EUR-Lex)."
published: "2026-07-16"
updated: "2026-07-16"
author: "Tranquilia by GRAC SA"
canonical: "https://tranquilia.es/en/blog/guia-completa-rgpd-gestorias-asesorias-2026"
note: "General information about the law. It’s no substitute for a lawyer’s advice or a look at your specific case."
---


# Complete RGPD guide for gestorías and asesorías (2026): what the law requires of you and how to comply

**Direct answer:** the RGPD (Reglamento (UE) 2016/679, the EU data protection regulation) and the LOPDGDD (Ley Orgánica 3/2018, Spain's data protection act) require every Spanish gestoría or asesoría (a firm that handles other companies' tax, accounting and payroll work) to keep a record of its data processing, to sign a processor contract (contrato de encargado del tratamiento, art. 28 RGPD) with every client whose data it handles, and to notify the AEPD (Spain's data protection authority) of any security breach within a maximum of 72 hours (art. 33 RGPD). Most gestorías do **not** need to appoint a data protection officer (delegado de protección de datos): the list of entities that must do so is closed in art. 34.1 LOPDGDD, and an asesoría does not appear in it simply because it is an obliged entity under the anti-money-laundering law. This guide, last reviewed on 16 July 2026, explains each obligation with its exact article.

> This article is general information about data protection law. It does not replace advice from a lawyer or a specific analysis of your own firm: use it as a map, not as a legal opinion.

## Contents

1. [Who does the RGPD bind, and why does it affect your gestoría twice?](#doble-papel)
2. [Which documents must your firm have?](#documentos)
3. [Do you need a data protection officer?](#dpd)
4. [What deadline do you have if there is a security breach?](#brecha)
5. [How long do you have to respond to a client who asks for their data?](#derechos)
6. [Does your gestoría have any extra obligations under the anti-money-laundering law?](#pbc)
7. [What happens if you do not comply?](#sanciones)
8. [Checklist: where to start](#checklist)
9. [Frequently asked questions](#faq)

## Who does the RGPD bind, and why does it affect your gestoría twice? {#doble-papel}

The RGPD applies to any business, autónomo (self-employed professional) or entity that processes the data of natural persons in the European Union, whatever its size. There is no exemption for SMEs or for the self-employed: a two-person asesoría and a multinational are governed by the same regulation, even though the number of specific measures each one needs is different (art. 5 RGPD, the accountability principle).

A gestoría or asesoría is special because it plays **two distinct roles that never mix**:

- **As a processor** (art. 28 RGPD): when you keep a client's accounts, payroll or taxes, you process the data of their employees, their clients or their suppliers on that client's instructions. They decide what those data are used for and answer for the legal basis; you sign a processor contract with them setting out what you may do, how you protect those data and what happens to them when the contract ends.
- **As a controller**: for your own business's data — your staff, your suppliers, your own invoicing, your marketing — you answer exactly like any other company.

If you handle the payroll side for several clients, you also process health data (sick leave, degree of disability) that appears on the payslips: this is special category data (art. 9 RGPD) and it calls for a reinforced confidentiality obligation with your team, even though the legal basis for processing it is your client's.

## Which documents must your firm have? {#documentos}

The documentary core that the RGPD requires of a gestoría, with its exact article:

- **Record of processing activities** (art. 30 RGPD): the list of which data you handle, what for and for how long. As a processor, your version of the record is shorter than a controller's (art. 30.2 RGPD).
- **Processor contract** (art. 28 RGPD) with every client whose data you handle — and with every subcontractor if you pass part of the work to another professional (art. 28.2 RGPD).
- **Privacy notices** for your own clients and for your staff (arts. 13-14 RGPD): which data you process, what for and on what legal basis.
- **Risk analysis** and, where applicable, a **data protection impact assessment (EIPD)** when the processing is likely to entail a high risk to individuals (art. 35 RGPD) — for example, if you handle the payroll side for many clients at once and therefore process health data on a large scale.
- **Security incident log** (art. 33.5 RGPD): every breach is documented internally, whether or not it is notified to the AEPD.
- **Retention policy**: how long you keep each piece of data and when you delete it (art. 5.1.e RGPD, the storage limitation principle).
- **Rights procedure**: how you respond when someone asks to access, rectify, erase or take away their data (arts. 12-22 RGPD).

## Do you need a data protection officer? {#dpd}

Almost certainly not, and it is worth explaining properly because it is one of the questions that circulates most among gestorías. Under art. 34.1 LOPDGDD (consolidated text on the BOE) there is a **closed list** of types of entity required to designate an officer, on top of the general cases in art. 37.1 RGPD (public authorities, regular and systematic monitoring on a large scale, or large-scale processing of special category data).

An asesoría or gestoría does not appear on that list by virtue of providing tax, accounting or payroll services. The only sub-paragraph of art. 34.1 LOPDGDD that mentions anti-money-laundering law is **sub-paragraph j)**, and it refers to whoever is the controller of a shared sector-wide file (the files on creditworthiness or on fraud prevention) — not to the professionals who, like a gestoría, consult or feed those files when applying their client identification obligations. Being an "obliged entity" (sujeto obligado) under the Ley 10/2010 does not make you the controller of a shared file.

That said, every firm is a specific case: if your volume of health data handled through the payroll side grows a great deal, or if you process data on a scale that is unusual for the sector, review your situation with a lawyer. Even where it is not compulsory for you, appointing an officer is always a valid voluntary option (art. 34.2 LOPDGDD) — with the caveat that, once appointed, you become subject to the same regime as if it were compulsory.

## What deadline do you have if there is a security breach? {#brecha}

If you lose a laptop with data on it, someone gets into your email, or you send information to the wrong person, the clock starts running. Under art. 33 RGPD you have a maximum of **72 hours from the moment you became aware** to notify the AEPD through its online portal (sede electrónica), unless it is unlikely to entail a risk to the rights of the people affected. If the risk is high, you must also warn the people affected directly, without delay and in clear language (art. 34 RGPD).

Even when you decide there is no need to notify the AEPD, the law still requires you to record the incident internally in your incident log (art. 33.5 RGPD): documenting every failure, whether or not it is notified, is obligatory.

## How long do you have to respond to a client who asks for their data? {#derechos}

When someone asks you for access to their data, to correct it, to erase it or to hand it over in a file so they can take it somewhere else, you have **one month from the day you receive the request** to respond (art. 12.3 RGPD). That deadline can be extended by a further two months for especially complex requests, provided you tell the person the reason within the first month.

If the deadline passes, the right course is not to ignore it: answer as soon as you can, record the actual date of your response and follow the procedure anyway.

## Does your gestoría have any extra obligations under the anti-money-laundering law? {#pbc}

If you provide tax, accounting or payroll advice, the Ley 10/2010, de prevención del blanqueo de capitales y de la financiación del terrorismo, makes you an "obliged entity" (art. 2.1) and requires you to identify your clients —including the beneficial ownership of companies— before you start working for them. This obligation is independent of the RGPD, but it generates data processing of its own (a copy of the identity document, the economic activity, the approximate origin of the funds) that also has to be documented and protected: restricted access, kept in separate custody from the ordinary tax file.

<!-- LEGAL REVIEW: the 10-year retention criterion for due diligence documentation is the one commonly applied by the sector, but the exact article of the Ley 10/2010 that sets it has not been verified in this article against the consolidated text on the BOE. Confirm it with your professional association or with a lawyer before applying it to a specific case. -->

## What happens if you do not comply? {#sanciones}

The AEPD is the body that supervises RGPD compliance in Spain. It can ask for explanations, order changes, issue a formal warning or impose a fine. Under art. 83 RGPD the possible maximums sit at two levels — up to 10 million euros or 2% of annual worldwide turnover, and up to 20 million or 4%, depending on the infringement, with the higher of the two figures applying.

In practice those figures are the legal ceiling, not the norm: the penalty is graded according to the seriousness, the size of the business and whether you have cooperated with the Agency. According to the AEPD itself, in 2025 the Agency received **30,931 complaints**, the highest figure in its history (+64% on 2024), and imposed fines totalling **€48,108,765** — almost 40% of that amount for badly handled security breaches. These are official figures, not a threat: they reflect that supervision is tightening, and that the area where most penalties fall (security breaches) is precisely the one you avoid with a clear internal procedure applied in time.

A small business that has its documentation in order, responds on time and cooperates with the Agency is not in the scenario of the maximum figures. That is why it is worth getting this settled: not to avoid a one-off scare, but to stop thinking about it.

## Checklist: where to start {#checklist}

If you have nothing prepared yet, this is the sensible order:

1. Write down in a list which data you process on your clients' instructions and which are your own (record of activities).
2. Check that you have a signed processor contract (art. 28 RGPD) with every active client.
3. Write down who responds if a rights request or a security breach comes in, and within what deadline.
4. Check where your software and backups are hosted: if they leave the European Union, review the safeguards for that transfer.
5. Put in writing, with a date, why you do not need a data protection officer (or why you do).

Each of these points has its own model document inside Tranquilia, generated from the answers in your wizard.

## Frequently asked questions {#faq}

### Does the RGPD apply the same way to an autónomo as to a large company?

Yes. The regulation does not distinguish by size or by legal form (art. 5 RGPD). What changes is the volume of specific measures you need: a small gestoría does not need the same as a large firm, but both start from the same baseline obligations.

### Does a gestoría need its clients' consent to keep their accounts?

No. The legal basis for providing the contracted service is performance of the contract (art. 6.1.b RGPD), not consent. Consent is only needed for what is not necessary for the service, such as sending newsletters or promotions.

### What is the difference between a controller and a processor?

The controller decides what the data are used for and on what legal basis. The processor processes them on someone else's behalf, following their instructions. A gestoría is the processor of its client's clients' data, and the controller of its own business's data (art. 4.7 and 4.8 RGPD).

### How long does the AEPD take to resolve a complaint?

This guide does not set a single resolution deadline for every complaint: it depends on the type of procedure. What does have a fixed deadline is your obligation to respond to individuals (one month, art. 12.3 RGPD) and to notify breaches (72 hours, art. 33 RGPD).

### Does having cloud-based gestoría software release me from liability?

No. The software you use is your processor (art. 28 RGPD): you remain responsible for there being a contract with it and for choosing a provider that offers sufficient guarantees. Responsibility is not delegated, it is shared out by contract.

---

**Want to see it applied to your own firm?** Tranquilia automatically generates the record of activities, the processor contract and the rest of the documents in this guide from a questionnaire tailored to asesorías and gestorías. The free tier lets you try it with up to 2 companies, with no card and no time limit — visit it at `tranquilia.es`.

*Guide produced by Tranquilia by GRAC SA. Published on 16 July 2026. Last reviewed: 16 July 2026. The content draws on the official sources cited below and does not constitute individual legal advice.*

## Sources

- [Reglamento (UE) 2016/679 (RGPD) — EUR-Lex](https://eur-lex.europa.eu/legal-content/ES/TXT/?uri=CELEX:32016R0679)
- [Ley Orgánica 3/2018, de 5 de diciembre (LOPDGDD) — texto consolidado, BOE](https://www.boe.es/buscar/act.php?id=BOE-A-2018-16673)
- [Ley 10/2010, de 28 de abril, de prevención del blanqueo de capitales — BOE](https://www.boe.es/buscar/act.php?id=BOE-A-2010-6737)
- [AEPD — Notificación de brechas de seguridad (art. 33 RGPD), Sede electrónica](https://sedeaepd.gob.es/sede-electronica-web/vistas/formBrechaSeguridad/nbs/procedimientoBrechaSeguridad.jsf)
- [AEPD — Nota de prensa: «La Agencia recibió más de 30,000 reclamaciones en 2025, un 64% más que el año anterior» (6 de mayo de 2026)](https://www.aepd.es/prensa-y-comunicacion/notas-de-prensa/la-agencia-recibio-mas-de-30.000-reclamaciones-en-2025-un-64-mas)
