Skip to content

Professional firms

What is said in your firm stays there.

Confidentiality is your raw material. Having the website respect it — and explain that it does — is part of what you sell.

The firm’s website is published with forms that ask only for what is needed, legal texts explaining the legal basis and retention of the processing, and a restrictive cookie banner, all consistent with the duty of confidentiality the profession carries.

Last reviewed:

A firm is a permanent data processing operation

Payslips, contracts, deeds, records, family situations: a professional firm handles information daily that often falls into the most protected categories of the GDPR. The website is a small part of that, but it is the visible part, and therefore the first thing anybody looks at.

Forms that do not invite oversharing

An open «tell us about your case» field on a firm’s website collects, through an easy channel, information that should arrive by another. The answer is not to forbid it: it is not to invite it. You ask for what is needed to call back and say explicitly that the matter is dealt with in consultation.

The privacy policy has to say who the controller is, what the site collects, on what legal basis, how long it is kept and what rights exist. And the legal notice, the details required by article 10 of Spain’s Law 34/2002, permanently and directly available.

Cookies and third parties, with the same caution

An advertising pixel on the «dismissals» page is telling a third party something very specific about whoever is visiting. So in professional firms it pays to be restrictive: strictly necessary only by default and everything else with prior consent, on the terms of the AEPD cookie guide of May 2024.

What the website does not settle

The firm’s record of processing activities, processor contracts with suppliers, the physical archive and, in some cases, the obligations of Spain’s Law 10/2010 on money laundering prevention, are another job. Here we put the website in order and say so plainly rather than letting you assume otherwise.

The same thing, explained in general: GDPR and cookies

What we do about it

Part of the maintenance: you never have to ask, and it is never billed apart.

  • Forms that ask only what is needed Without inviting anyone to write out their case.
  • A privacy policy of your own Controller, legal basis, retention and rights.
  • A complete legal notice With the details the law requires, always available.
  • A restrictive cookie banner Nothing beyond the strictly necessary without prior permission.
  • A short notice by the form The information at the point of collection.
  • Revision when the rules change And when what your site does changes.

And this you change with one sentence

You write what you want changed and we publish it.

Take out the «describe your case» field

Removed, and replaced with an explanation of what is dealt with in consultation.

We have become a professional company

Controller changed in the legal notice and in the privacy policy.

We are going to advertise on search engines

We check what that loads on the site and adjust the banner beforehand.

Frequently asked questions

Does this make me GDPR compliant?

It puts the website where it should be. The firm’s internal side — record of processing, supplier contracts, archive, training — is another job and worth having done.

Can I use a form for legal enquiries?

You can, but it has to be built knowing what it collects: legal basis, retention and an appropriate channel. It is not just another contact form.

Do I need a data protection officer?

It depends on the volume and the kind of processing. It is not a question a website answers without knowing the firm.

Can I publish success stories?

With great care and without identifying details. The duty of confidentiality comes ahead of any marketing argument.

What does your firm’s form ask for today?

If it invites people to write out their case, that is where to start. And it gets fixed in an afternoon.

Write to us