Notice of compliance with the RGPD
Notice of Compliance with the RGPD
This page describes the framework of compliance in the area of data protection G729, SL, operator of electronic communications and holder of the trademark SMS.es.
1 · regulatory Framework
As a telecommunications operator, G729, SL is subject to a regulatory framework that is broader than that of a provider of services of the information society ordinary:
| Standard | Scope |
|---|---|
| Regulation (EU) 2016/679 (RGPD) | General system of protection of data |
| Organic law 3/2018 (LOPDGDD) | National development, including the regime of appointment of DPD (art. 34) |
| Law 34/2002 (LSSI-CE) | Storage devices (art. 22.2) and commercial communications (art. 21) |
| Law 11/2022, General of Telecommunications | Obligations as a registered trader, secrecy of communications |
| Law 25/2007 | Retention of data relating to electronic communications |
| Regulation (EU) 910/2014 (eIDAS) | Trust services are applicable to the SMS Certificate |
2 · Government data
- Data Protection officer: Designation communicated to the AEPD in accordance with art. 37.7 RGPD.
- Record of processing activities (art. 30 RGPD), maintained and updated both in our condition responsible for as a manager.
- Domestic policy of protection of data, which is mandatory for all staff.
- Commitments of confidentiality signed by all persons with access to personal data (art. 28.3.b and 32.4 RGPD).
- Periodic training staff with access to personal data.
3 · Privacy by design and by default
We apply the principles of the art. 25 RGPD in the development and evolution of the platform: data minimisation, purpose limitation, default configuration, more protective, and access control based on the principle of need-to-know.
4 · impact Assessments
We Impact assessments relating to the Protection of Data (art. 35 RGPD) when a treatment may result in a high risk to the rights and freedoms of data subjects, taking into account the criteria of the Guidelines of the European Committee for Data Protection and to the list published by the AEPD.
5 · security Measures
We apply technical and organisational measures in accordance with the art. 32 RGPD, evaluated according to the risk, including access control, encryption in transit, activity log, segregation of environments and procedures of continuity.
6 · Management of safety violations
We have a procedure documented detection, assessment and response to violations of the security of the personal data:
- Responsible for: notification to the AEPD without undue delay and, if possible, within a maximum period of 72 hours (art. 33 RGPD), and communication to stakeholders when the violation involves a high risk to your rights and freedoms (art. 34).
- As a manager: notice to the responsible customer without undue delay since we have knowledge (art. 33.2 RGPD), with the necessary information so that it can fulfil its own obligations.
- Internal register of all violations, regardless of whether they are reportable.
7 · Chain of treatment
The provision of courier services requires a chain of participants. Our position in each link is defined contractually:
- Our customers they are responsible for the processing of the data, their recipients.
- G729, SL it acts as the person in charge of the processing of this data, in virtue of the Agreement in Charge of the Treatment.
- Our subencargados are subject to contracts that impose the same obligations (art. 28.4 RGPD), a prior assessment of their warranties.
- Telecom operators involved in the routing, acting as a responsible independent of the traffic data required for the delivery, in accordance with the industry regulations.
8 · international Transfers
When there are transfers outside the European Economic area, under the mechanisms of the Chapter V of the RGPD. The detail of the mechanisms applicable to each recipient contained in the Privacy policy.
9 · Rights of the interested
The rights recognized in the arts. 15 to 22 of the RGPD and the channel to exercise them-are detailed in the Privacy policy.
When the request relates to data processed on behalf of a client of ours, will be transferred to the responsible without delay and we will assist you in your response, according to the art. 28.3.and RGPD.
10 · * Authority control
Spanish agency of Data Protection (AEPD) — C/ Jorge Juan, 6, 28001 Madrid — www.aepd.es
11 · Documentation of compliance to customers and bidders
Current customers, potential customers and contracting authorities may request:
- Agreement in Charge of Treatment for your signature
- Updated list of subencargados
- Certificate ISO/IEC 27001:2022, and statement of applicability
- Summary of technical and organizational measures
- Questionnaires security completed
G729, SL — SMS.es Last update: July 17, 2026.
