Complete data protection for businesses

We adapt your company to the GDPR, the LOPDGDD and the LSSI. With continuous advice, training and our own platform.

At Sellarès Assessors we help you comply with current data protection regulations. We assess your situation, draft the necessary policies, implement the appropriate technical and organisational measures and accompany you in continuous compliance. All this with legal support, specialized training and access to your own platform to keep your company always up to date with the GDPR, the LOPDGDD and the LSSI.
Contact us
By submitting the form, you agree that we will process your data to respond to your query. More info in our Privacy Policy.

Our payroll management service in Barcelona includes everything your company needs to comply with labor regulations and keep daily operations under control.

Monthly payroll management

Registrations, cancellations and hiring

Technology and reporting

Our outsourced labor management service in Barcelona includes everything your company needs to comply with regulations and keep daily operations under control.

Registrations, cancellations and hiring

Technology and reporting

Monthly payroll management

GDPR compliant without hassle or risk

Diagnosis and regulatory adaptation

Ongoing Compliance Services

Data Protection Officer (DPO)

Training and online platform

Common risks of not complying with data protection

Lack of visible policies or legal clauses

Not having a legal notice or privacy policy can lead to penalties.

Not properly reporting data usage

The law requires transparency, consent and traceability.

Lack of knowledge of the type of data being processed

Not properly identifying treatments prevents the application of appropriate measures.

Absence of technical or organisational security measures

The GDPR requires active diligence to be demonstrated.

Not having internal training for employees

The company is responsible for how its workers act.

Not having a DPO when required

Failure to comply can lead to serious penalties and loss of confidence.

Tailored, non-bureaucratic data protection

At Sellarès Assessors we understand that each company is different, which is why we apply the GDPR with a useful and realistic approach. We do not use generic templates: we analyse your operations, draft the necessary clauses, implement proportionate measures and train the people involved in data processing.

In addition, our system does not end with the delivery of documents: we accompany you throughout the year, resolving doubts, adapting what changes and updating the content when necessary. If you have an inspection, a breach or a claim, you are already prepared.

Proprietary platform to manage compliance

We give you access to an online platform where you can monitor compliance status, access your documentation, update treatments and train your team. Without wasting time or depending on paper.

  • Digital repository with up-to-date documents and policies
  • Follow-up of treatments, registries and risks
  • Alerts for pending expirations or revisions
  • Training Record and Compliance Control by User

Meet Sellarès Assessors

At Sellarès Assessors we have been accompanying SMEs for more than five decades.

Our multidisciplinary team offers comprehensive advice in the labour, tax, accounting and legal areas, with a strategic, human and technologically up-to-date perspective.

+50

Years of experience

50

Professional

6.500

Monthly payrolls

3.200

Annual training hours

85%

of our customers recommends us

7,550

Annual tax settlements

Figures that support our commitment

With more than 50 years of experience and a multidisciplinary legal team, we help companies comply with their data protection obligations without losing focus on their activity. We work with legal, technical and organisational criteria, aligned with the business reality.

+50

Years of excellence

50

Professional

6.500

Payslips per month

3.200

Annual training hours

85%

of our satisfied customers

7,550

Annual tax settlements

Sellarès in numbers: References and data

+50

Years of experience

50

Professional

6.500

Monthly payrolls

7.550

Annual tax settlements

3.200

annual hours invested in training work teams

85%

of satisfaction of our customers

Benchmarks in data protection and digital regulations

Do you have doubts about how to comply with data protection?

Answer: In Spain, you must mainly comply with the General Data Protection Regulation (GDPR), which regulates the processing of personal data throughout the European Union, applicable to any organization that handles data of European citizens, regardless of their location. Organic Law 3/2018 on Data Protection and Guarantee of Digital Rights (LOPDGDD) complements the GDPR in Spain, addressing aspects such as data on minors, health or video surveillance. If you have a website or make commercial mailings, you must also comply with Law 34/2002 on Information Society Services and Electronic Commerce (LSSI), which regulates aspects such as the use of cookies and consent for electronic communications. If you operate internationally, additional regulations may apply, such as the CCPA in California for resident data, or industry regulations (e.g., health or telecommunications). From 2025, the EU Artificial Intelligence Regulation may also be relevant if you use AI systems that process personal data.
Yes, any entity that processes personal data, such as that of employees, customers, or suppliers, must comply with the GDPR, regardless of its size, whether it is a large company, a freelancer, or an association. However, the specific obligations may vary depending on the volume and type of data processed. For example, micro-enterprises with fewer than 250 employees may be exempt from keeping a record of processing activities, according to Article 30.5 of the GDPR, provided that the processing does not involve high risks. This reduces the administrative burden, but does not exempt from overall regulatory compliance.
A Data Protection Officer (DPO) is mandatory only in certain cases, according to Article 37 of the GDPR: public entities (except courts in judicial functions), organizations that carry out large-scale processing of personal data, or that handle sensitive data (e.g., health, criminal convictions) on a large scale. In Spain, the LOPDGDD extends this obligation to sectors such as educational centres, professional associations, insurance companies or advertising agencies that prepare commercial profiles. If you are not obliged, you can appoint a DPO voluntarily, either internally or externally. The DPO must be independent, with specialized knowledge and without receiving instructions about their work, which highlights the importance of choosing a qualified professional.
Failure to comply with the GDPR can result in fines of up to €20 million or 4% of global annual turnover, whichever is greater, for serious breaches, such as processing data without a legal basis, failing to obtain consent, or violating data subject rights. For less serious infractions, such as failing to keep a record of processing activities, fines can reach €10 million or 2% of turnover. In Spain, the LOPDGDD also provides for specific sanctions. In addition, the Spanish Data Protection Agency may impose warnings, cease-and-desist orders, restrictions on access to data or cause reputational damage. The severity depends on factors such as the volume of data affected, intentionality, recidivism, or cooperation with authorities.
Although the GDPR does not explicitly state the mandatory nature of training, the principle of proactive accountability (Article 39) implies that data controllers must ensure that staff are trained to comply with the regulations. The LOPDGDD reinforces this by requiring that employees who handle personal data be properly trained. Training should be specific to the employee’s role, ongoing, up-to-date on regulatory changes or incidents, and documented to demonstrate compliance in inspections. It is not enough to provide documentation; Employees must know how to act in practice.
Yes, many compliance platforms are designed to be intuitive, allowing non-legal managers to manage compliance through document templates, guides for activity records, impact assessments, and training modules. However, in complex cases, such as impact assessments for high-risk treatments or responses to security breaches, specialized legal advice is recommended. The platform must be up to date with the GDPR, the LOPDGDD and recent regulations, such as the AI Regulation. Professional accompaniment is key to interpreting complex requirements or responding to inspections, ensuring robust compliance.
Contact us without obligation
By submitting the form, you agree that we will process your data to respond to your query. More info in our Privacy Policy.

Take the first step now

Fill out the form and an expert will contact you to answer your questions.

Response in less than 24 hours.