Data Protection Lawyers

The protection and control of our personal data is a fundamental right, safeguarding individuals from misuse that could compromise their privacy and integrity.
Following the adaptation of the General Data Protection Regulation (GDPR), which repealed Directive 95/46/EC, and the enactment of Organic Law 3/2018 of 5 December on the Protection of Personal Data and Guarantee of Digital Rights, companies and organisations are required to demonstrate compliance and implement appropriate security measures based on risk assessments concerning the individuals whose data is processed.
Our data protection lawyers advise companies on data-driven projects and provide tailored legal solutions to meet their specific needs.
Who do we advise?
We provide data protection advice to freelancers, organisations, and businesses that process personal data in the course of their commercial activities, ensuring they comply with all applicable data protection laws and regulations.
What are our main Data Protection services?
Legal Data Protection Consultancy
Data Protection Officer (DPO) services
We act as external Data Protection Officers (DPOs) or support your company’s internal DPO, ensuring compliance with legal obligations. We help determine in which cases appointing a DPO is mandatory or advisable, and what their key responsibilities are within the current regulatory framework, according to your company’s specific needs.
Legitimate Interest Assessments
In cases where it is not easy to determine whether legitimate interest applies to a data processing activity, we support the client in analysing the situation and issue a corresponding report to determine whether the processing can be based on legitimate interest or if another legal basis should be considered.
Disruptive Technologies and Digital Regulatory Compliance
Advisory services for Disruptive Technologies
We provide data protection advice tailored to emerging technologies such as Big Data, Artificial Intelligence, Blockchain, biometrics, video games, and automated processes. These technologies require a specialised approach that includes:
- Impact assessments and the application of the Privacy by Design principle.
- Compliance with the Artificial Intelligence Regulation, the European Artificial Intelligence Regulation, and other key frameworks such as the Digital Services Act, the Digital Markets Act, the Digital Act, and Spain’s Law on Digital Services.
- Development of protocols for the use of disruptive tools and codes of good practice for the responsible use of AI in organisational settings.
- Legal support throughout the implementation of digital projects, ecommerce platforms, online services, and technological solutions — offering a comprehensive 360-degree compliance strategy.
This service is designed for organisations seeking to integrate technological innovation with legal certainty, minimising risks and strengthening user trust.
Document Management and Regulatory Compliance
Impact Assessments or Data Protection Impact Assessments (DPIA)
We carry out the impact assessments and Data Protection Impact Assessments (DPIAs) your company needs to comply with data protection regulations. This applies when the organisation processes large volumes of data or special categories of information (such as health or biometric data), engages in processing that may be considered invasive, or uses disruptive technologies that could involve automated or disproportionate processing in terms of user privacy.
Record of Processing Activities
We create and update the necessary documentation to record the types of data held by a company, organised by category.
Drafting Legal Information Clauses
We carry out the analysis for both physical data collection (on paper) and electronic formats (via websites or any other method), developing appropriate wording to obtain the data subject’s explicit consent where required for processing.
Drafting Data Processing Agreements
We review whether there are service providers processing data on behalf of your company, drafting contracts to regulate such processing by third parties or reviewing existing agreements, and monitoring procedures to ensure that service delivery is carried out in accordance with the law.
Data Subject Rights
Procedures for Exercising Rights
We establish procedures that clearly demonstrate when data subjects have exercised their rights, and we advise clients on how to comply with such requests in the legally required formats and timeframes.
Binding Corporate Rules (BCRs)
We prepare, implement and draft the necessary procedures for the approval of Binding Corporate Rules, facilitating data transfers within international corporate groups.
Legal Review of Websites and Digital Platforms
Website Legal Review
We review or draft the privacy policies and cookie policies required for your website, ecommerce platform or mobile application to ensure compliance with applicable regulations. We also support you in adapting your platform to legal requirements, including terms and conditions, legal notices, copyright, trademark rights, and more.
Compliance with Regulated Regulations
Data protection is closely linked to compliance with other regulations, such as e-commerce legislation (LSSICE), the Digital Services Act, the Digital Markets Act, and the Artificial Intelligence Regulation. In this regard, compliance with the European Artificial Intelligence Regulation and broader frameworks such as the Digital Act is essential to ensure the secure and lawful implementation of technology.
Therefore, if your organisation manages websites, online platforms, ecommerce services, applications or technological solutions, it is crucial to assess the impact these regulations may have on your project. We support you throughout the entire process, offering a comprehensive and strategic perspective — a true 360-degree approach — to ensure regulatory compliance and minimise legal and reputational risks.
Training and Awareness
Data Protection Training
We deliver specialised data protection training for employees, managers and technical teams, ensuring they have the knowledge required to comply with privacy regulations.

Why choose our Data Protection services?
- We assist the client in the development and implementation of data protection measures appropriate to their situation, providing effective legal solutions.
- We resolve any incidents that may arise during the implementation of data protection policies.
- We have a team that is highly specialised in this field, thus offering a comprehensive and personalised advisory service.
Do you need advice on Data Protection services?
Frequently asked questions on Data Protection
Related services
You may be interested
Events
Can we help you?
Write to us and we will advise you on all matters related to Data protection.
