
{"id":19053,"date":"2025-01-15T01:01:00","date_gmt":"2025-01-15T00:01:00","guid":{"rendered":"https:\/\/www.rosello-mallol.com\/?p=19053"},"modified":"2025-02-12T10:57:40","modified_gmt":"2025-02-12T09:57:40","slug":"mistakes","status":"publish","type":"post","link":"https:\/\/www.rosello-mallol.com\/en\/mistakes\/","title":{"rendered":"Common mistakes when implementing the GDPR in your company"},"content":{"rendered":"\n<p>We present below some common mistakes when implementing the GDPR. Non-compliance with the General Data Protection Regulation (GDPR) not only jeopardizes user privacy but can also lead to significant fines imposed by the Spanish Data Protection Agency (AEPD). Below, we explain the 5 most common mistakes businesses make when implementing the GDPR, along with real examples of penalties imposed by the AEPD.<\/p>\n\n\n\n<p><strong>1. Not conducting an initial risk analysis<\/strong><\/p>\n\n\n\n<p>A hospital and a restaurant are not the same, but both may collect personal data for their operations. The risk associated with the use of that data is completely different in each case, so the risks related to processing these data are distinct. Clearly identify the types of personal data you will process (using the <a href=\"https:\/\/www.rosello-mallol.com\/en\/record-processing-activities\/\">Record of Processing Activities<\/a>) and tailor your measures to the data you handle.<\/p>\n\n\n\n<p>Failing to identify how personal data is processed in the company can lead to security breaches and vulnerabilities that go unnoticed.<\/p>\n\n\n\n<p><strong>Real case<\/strong>: The AEPD <a href=\"https:\/\/www.aepd.es\/documento\/ps-00238-2024.pdf\">fined<\/a> a company \u20ac270,000 for sharing an employee&#8217;s payroll with 446 other workers.<\/p>\n\n\n\n<p><strong>How to avoid it<\/strong>: Perform an analysis of the personal data processed to identify risks in data processing and define corrective measures from the outset.<\/p>\n\n\n\n<p><strong>2. Lack of explicit consent<\/strong><\/p>\n\n\n\n<p>Consent is one of the six legal bases for data processing. Failing to properly assess the legal basis is a common mistake. Requesting personal data without express, clear, and verifiable consent is a serious violation under the GDPR. This includes using pre-checked boxes or failing to properly inform individuals about how their data will be used.<\/p>\n\n\n\n<p><strong>Real case<\/strong>: A bank was <a href=\"https:\/\/www.aepd.es\/documento\/ps-00380-2024.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">fined<\/a> \u20ac180,000 for accessing the credit history of a former customer without a legal basis.<\/p>\n\n\n\n<p><strong>How to avoid it<\/strong>: When necessary, ensure that consent is clear and documented. Use unchecked acceptance boxes and explain in simple terms how the data will be used.<\/p>\n\n\n\n<p><strong>3. Failing to update privacy policies<\/strong><\/p>\n\n\n\n<p>A Privacy Policy provides users with the necessary information to understand their rights and ensure that their data is provided knowingly. Having outdated or incomplete privacy policies is a recurring mistake that can lead to user distrust and legal penalties.<\/p>\n\n\n\n<p><strong>Real case<\/strong>: A company was <a href=\"https:\/\/www.aepd.es\/documento\/ps-00546-2023.pdf\">fined<\/a> \u20ac10,000 for failing to properly inform users in its privacy policy about personal data processing.<\/p>\n\n\n\n<p><strong>How to avoid it<\/strong>: Review your privacy policies periodically and ensure they include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>What data you collect<\/li>\n\n\n\n<li>How you use it<\/li>\n\n\n\n<li>How long you store it<\/li>\n\n\n\n<li>User rights under the GDPR<\/li>\n<\/ul>\n\n\n\n<p><strong>4. Failing to appoint a Data Protection Officer (DPO)<\/strong><\/p>\n\n\n\n<p>Not all companies need a DPO, but those that handle sensitive data or large volumes of personal data are required to appoint one. Ignoring this obligation can result in fines.<\/p>\n\n\n\n<p><strong>Real case<\/strong>: A well-known restaurant chain was <a href=\"https:\/\/www.aepd.es\/documento\/ps-00546-2023.pdf\">fined<\/a> \u20ac25,000 for failing to appoint a DPO, despite it being mandatory due to the nature of the data processed.<\/p>\n\n\n\n<p><strong>How to avoid it<\/strong>: Assess whether your company needs a DPO (it\u2019s mandatory for public entities and companies handling sensitive data) and appoint a qualified professional for the role.<\/p>\n\n\n\n<p><strong>5. Failing to properly manage user requests<\/strong><\/p>\n\n\n\n<p>The GDPR grants users rights such as access, rectification, erasure, and data portability. Failing to address these requests in a timely manner can result in significant fines. Ensure your company has a single entry channel to handle these rights properly.<\/p>\n\n\n\n<p><strong>Real case<\/strong>: A well-known airline was <a href=\"https:\/\/www.aepd.es\/documento\/ps-00138-2023.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">fined<\/a> \u20ac40,000 for failing to respond to a customer&#8217;s access request.<\/p>\n\n\n\n<p><strong>How to avoid it<\/strong>: Implement an efficient system to manage these requests and ensure they are responded to within 30 days, as required by the regulation.<\/p>\n\n\n\n<p><strong>Conclusion<\/strong><\/p>\n\n\n\n<p>Avoiding common mistakes is simple if you carefully analyze your business activities. Complying with the GDPR is not just a legal obligation but also a way to gain your customers\u2019 trust. Avoiding the mistakes mentioned above can protect you from penalties by the AEPD and enhance your reputation.<\/p>\n\n\n\n<p>Author: <strong>Victor Rosell\u00f3<\/strong>, Lawyer.<\/p>\n\n\n\n<p>If you need more informarion, contact us!<\/p>\n\n\n\n<div class=\"wp-block-contact-form-7-contact-form-selector\">\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f13645-o1\" lang=\"en-US\" dir=\"ltr\" data-wpcf7-id=\"13645\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/en\/wp-json\/wp\/v2\/posts\/19053#wpcf7-f13645-o1\" method=\"post\" class=\"wpcf7-form init\" aria-label=\"Contact form\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"13645\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.6\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"en_US\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f13645-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/><input type=\"hidden\" name=\"_wpcf7_recaptcha_response\" value=\"\" \/>\n<\/fieldset>\n<p><label> Name (required) <span class=\"wpcf7-form-control-wrap\" data-name=\"your-name\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required uk-input\" aria-required=\"true\" aria-invalid=\"false\" value=\"\" type=\"text\" name=\"your-name\" \/><\/span> <\/label>\n<\/p>\n<p><label> Email (required) <span class=\"wpcf7-form-control-wrap\" data-name=\"your-email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email uk-input\" aria-required=\"true\" aria-invalid=\"false\" value=\"\" type=\"email\" name=\"your-email\" \/><\/span> <\/label>\n<\/p>\n<p><label> Contact phone (telephone contact) <span class=\"wpcf7-form-control-wrap\" data-name=\"telefon\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text uk-input\" aria-invalid=\"false\" value=\"\" type=\"text\" name=\"telefon\" \/><\/span> <\/label>\n<\/p>\n<p><label> Message <span class=\"wpcf7-form-control-wrap\" data-name=\"your-message\"><textarea cols=\"40\" rows=\"5\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea uk-textarea\" aria-invalid=\"false\" name=\"your-message\"><\/textarea><\/span> <\/label>\n<\/p>\n<p><span class=\"wpcf7-form-control-wrap\" data-name=\"aceptacion-RGPD\"><span class=\"wpcf7-form-control wpcf7-acceptance\"><span class=\"wpcf7-list-item\"><label><input type=\"checkbox\" name=\"aceptacion-RGPD\" value=\"1\" aria-invalid=\"false\" \/><span class=\"wpcf7-list-item-label\">I read and accept the <a href=\"https:\/\/www.rosello-mallol.com\/en\/policy-privacy\/\" target=\"_blank\">Privacy Policy<\/a><\/span><\/label><\/span><\/span><\/span><br \/>\n<label><br \/>\n<span class=\"wpcf7-form-control-wrap\" data-name=\"acceptance-360\"><span class=\"wpcf7-form-control wpcf7-acceptance optional\"><span class=\"wpcf7-list-item\"><label><input type=\"checkbox\" name=\"acceptance-360\" value=\"1\" aria-invalid=\"false\" \/><span class=\"wpcf7-list-item-label\">I agree to receive the newsletter.<\/span><\/label><\/span><\/span><\/span><br \/>\n<input class=\"wpcf7-form-control wpcf7-submit has-spinner uk-button uk-button-primary\" type=\"submit\" value=\"Send\" \/><\/label>\n<\/p><p style=\"display: none !important;\" class=\"akismet-fields-container\" data-prefix=\"_wpcf7_ak_\"><label>&#916;<textarea name=\"_wpcf7_ak_hp_textarea\" cols=\"45\" rows=\"8\" maxlength=\"100\"><\/textarea><\/label><input type=\"hidden\" id=\"ak_js_1\" name=\"_wpcf7_ak_js\" value=\"130\"\/><script>\ndocument.getElementById( \"ak_js_1\" ).setAttribute( \"value\", ( new Date() ).getTime() );\n<\/script>\n<\/p><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<\/div>\n\n\n\n<h6 class=\"wp-block-heading has-medium-font-size\">Information on data protection<\/h6>\n\n\n\n<p><small><strong>Company name<\/strong><br><strong>LEGAL IT GLOBAL 2017, SLP<\/strong><br><strong>Purpose<br><\/strong>Providing the service.<br>Sending the newsletter.<br><strong>Legal basis<br><\/strong>Compliance with the service provision.<br>Consent.<br><strong>Recipients<\/strong><br>Your data will not be shared with any third party, except service providers with which we have signed a valid service agreement.<\/small><br><small><strong>Rights<\/strong><br>You may access, rectify or delete your data and exercise the rights indicated in our Privacy Policy.<\/small><br><small><strong>Further information<\/strong><br>See the&nbsp;<a href=\"https:\/\/www.rosello-mallol.com\/en\/policy-privacy\/\" target=\"_blank\" rel=\"noreferrer noopener\">Privacy Policy<\/a>.<\/small><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We present below some common mistakes when implementing the GDPR. Non-compliance with the General Data Protection Regulation (GDPR) not only jeopardizes user privacy but can also lead to significant fines imposed by the Spanish Data Protection Agency (AEPD). Below, we explain the 5 most common mistakes businesses make when implementing the GDPR, along with real [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":19045,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","_joinchat":[],"footnotes":""},"categories":[246],"tags":[449,1372,1371,395,1370,1369,394],"class_list":["post-19053","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-data-protection","tag-data-protection-andorra","tag-data-protection-spain","tag-gdpr-2","tag-privacy-andorra","tag-privacy-spain","tag-rgpd-es-en"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.3 (Yoast SEO v27.7) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Common mistakes when implementing the GDPR in your company | Rosell\u00f3 Mallol<\/title>\n<meta name=\"description\" content=\"The 5 most common RGPD mistakes and the sanctions imposed by the AEPD. Learn how to avoid them to protect your company.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.rosello-mallol.com\/en\/mistakes\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Common mistakes when implementing the GDPR in your company\" \/>\n<meta property=\"og:description\" content=\"We present below some common mistakes when implementing the GDPR. Non-compliance with the General Data Protection Regulation (GDPR) not only jeopardizes\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.rosello-mallol.com\/en\/mistakes\/\" \/>\n<meta property=\"og:site_name\" content=\"Rosell\u00f3 Mallol\" \/>\n<meta property=\"article:published_time\" content=\"2025-01-15T00:01:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-02-12T09:57:40+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.rosello-mallol.com\/wp-content\/uploads\/traffic-signs-464659_1280.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"904\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"DespatxRM\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@vic_rosello\" \/>\n<meta name=\"twitter:site\" content=\"@vic_rosello\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"DespatxRM\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Common mistakes when implementing the GDPR in your company | Rosell\u00f3 Mallol","description":"The 5 most common RGPD mistakes and the sanctions imposed by the AEPD. Learn how to avoid them to protect your company.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.rosello-mallol.com\/en\/mistakes\/","og_locale":"en_US","og_type":"article","og_title":"Common mistakes when implementing the GDPR in your company","og_description":"We present below some common mistakes when implementing the GDPR. Non-compliance with the General Data Protection Regulation (GDPR) not only jeopardizes","og_url":"https:\/\/www.rosello-mallol.com\/en\/mistakes\/","og_site_name":"Rosell\u00f3 Mallol","article_published_time":"2025-01-15T00:01:00+00:00","article_modified_time":"2025-02-12T09:57:40+00:00","og_image":[{"width":1280,"height":904,"url":"https:\/\/www.rosello-mallol.com\/wp-content\/uploads\/traffic-signs-464659_1280.jpg","type":"image\/jpeg"}],"author":"DespatxRM","twitter_card":"summary_large_image","twitter_creator":"@vic_rosello","twitter_site":"@vic_rosello","twitter_misc":{"Written by":"DespatxRM","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.rosello-mallol.com\/en\/mistakes\/#article","isPartOf":{"@id":"https:\/\/www.rosello-mallol.com\/en\/mistakes\/"},"author":{"name":"DespatxRM","@id":"https:\/\/www.rosello-mallol.com\/en\/#\/schema\/person\/594f32415eefd4edf26d6f2f2ad25ad3"},"headline":"Common mistakes when implementing the GDPR in your company","datePublished":"2025-01-15T00:01:00+00:00","dateModified":"2025-02-12T09:57:40+00:00","mainEntityOfPage":{"@id":"https:\/\/www.rosello-mallol.com\/en\/mistakes\/"},"wordCount":730,"publisher":{"@id":"https:\/\/www.rosello-mallol.com\/en\/#organization"},"image":{"@id":"https:\/\/www.rosello-mallol.com\/en\/mistakes\/#primaryimage"},"thumbnailUrl":"https:\/\/www.rosello-mallol.com\/wp-content\/uploads\/traffic-signs-464659_1280.jpg","keywords":["Data Protection","Data protection Andorra","Data protection Spain","gdpr","Privacy Andorra","Privacy Spain","RGPD"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.rosello-mallol.com\/en\/mistakes\/","url":"https:\/\/www.rosello-mallol.com\/en\/mistakes\/","name":"Common mistakes when implementing the GDPR in your company | Rosell\u00f3 Mallol","isPartOf":{"@id":"https:\/\/www.rosello-mallol.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.rosello-mallol.com\/en\/mistakes\/#primaryimage"},"image":{"@id":"https:\/\/www.rosello-mallol.com\/en\/mistakes\/#primaryimage"},"thumbnailUrl":"https:\/\/www.rosello-mallol.com\/wp-content\/uploads\/traffic-signs-464659_1280.jpg","datePublished":"2025-01-15T00:01:00+00:00","dateModified":"2025-02-12T09:57:40+00:00","description":"The 5 most common RGPD mistakes and the sanctions imposed by the AEPD. Learn how to avoid them to protect your company.","breadcrumb":{"@id":"https:\/\/www.rosello-mallol.com\/en\/mistakes\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.rosello-mallol.com\/en\/mistakes\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.rosello-mallol.com\/en\/mistakes\/#primaryimage","url":"https:\/\/www.rosello-mallol.com\/wp-content\/uploads\/traffic-signs-464659_1280.jpg","contentUrl":"https:\/\/www.rosello-mallol.com\/wp-content\/uploads\/traffic-signs-464659_1280.jpg","width":1280,"height":904,"caption":"Errores"},{"@type":"BreadcrumbList","@id":"https:\/\/www.rosello-mallol.com\/en\/mistakes\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Inici","item":"https:\/\/www.rosello-mallol.com\/en\/"},{"@type":"ListItem","position":2,"name":"Common mistakes when implementing the GDPR in your company"}]},{"@type":"WebSite","@id":"https:\/\/www.rosello-mallol.com\/en\/#website","url":"https:\/\/www.rosello-mallol.com\/en\/","name":"Rosell\u00f3 Mallol","description":"Despatx advocats experts en TIC i Protecci\u00f3 de dades","publisher":{"@id":"https:\/\/www.rosello-mallol.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.rosello-mallol.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.rosello-mallol.com\/en\/#organization","name":"Rosell\u00f3 Mallol - Advocats especialistes en dret digital","url":"https:\/\/www.rosello-mallol.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.rosello-mallol.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.rosello-mallol.com\/wp-content\/uploads\/logo-definitiu-web.png","contentUrl":"https:\/\/www.rosello-mallol.com\/wp-content\/uploads\/logo-definitiu-web.png","width":4000,"height":736,"caption":"Rosell\u00f3 Mallol - Advocats especialistes en dret digital"},"image":{"@id":"https:\/\/www.rosello-mallol.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/vic_rosello","https:\/\/www.instagram.com\/rosellomallol\/","https:\/\/www.linkedin.com\/in\/victorrosello\/","https:\/\/www.youtube.com\/channel\/UCxcqAdksWzsEaZ5UYoFJd0Q\/featured"]},{"@type":"Person","@id":"https:\/\/www.rosello-mallol.com\/en\/#\/schema\/person\/594f32415eefd4edf26d6f2f2ad25ad3","name":"DespatxRM","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/514c88e026ea3d52a2f2e8160d0a6a33ddffa36275325c971e52c19709a18d74?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/514c88e026ea3d52a2f2e8160d0a6a33ddffa36275325c971e52c19709a18d74?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/514c88e026ea3d52a2f2e8160d0a6a33ddffa36275325c971e52c19709a18d74?s=96&d=mm&r=g","caption":"DespatxRM"},"url":"https:\/\/www.rosello-mallol.com\/en\/author\/despatxrm\/"}]}},"jetpack_featured_media_url":"https:\/\/www.rosello-mallol.com\/wp-content\/uploads\/traffic-signs-464659_1280.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.rosello-mallol.com\/en\/wp-json\/wp\/v2\/posts\/19053","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rosello-mallol.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.rosello-mallol.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.rosello-mallol.com\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rosello-mallol.com\/en\/wp-json\/wp\/v2\/comments?post=19053"}],"version-history":[{"count":0,"href":"https:\/\/www.rosello-mallol.com\/en\/wp-json\/wp\/v2\/posts\/19053\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.rosello-mallol.com\/en\/wp-json\/wp\/v2\/media\/19045"}],"wp:attachment":[{"href":"https:\/\/www.rosello-mallol.com\/en\/wp-json\/wp\/v2\/media?parent=19053"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.rosello-mallol.com\/en\/wp-json\/wp\/v2\/categories?post=19053"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.rosello-mallol.com\/en\/wp-json\/wp\/v2\/tags?post=19053"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}