Skip to main content
Corpshore España
A stone doorway with a deep frame and a clean shadow line

Compliance and security

Compliance and security at Corpshore Spain

GDPR and LOPDGDD alignment in every delivery model, with data processing agreements available on request.

In summary: Corpshore Spain handles client data in line with GDPR and LOPDGDD in every delivery model, with data processing agreements available on request and specific safeguards for transfers outside the European Economic Area.

Our compliance framework

We align data handling with the General Data Protection Regulation (GDPR) and Spain's Organic Law on Data Protection and Digital Rights (LOPDGDD) in every delivery model, inside or outside Spain.

We provide a data processing agreement for every client, setting out the purposes of processing, the security measures applied and the sub-processing conditions that affect your project. You can request and review it as part of the proposal process, before committing to anything.

Information security

We apply role-based access control, encryption of data in transit and at rest, access logging, and mandatory security training for teams that handle client data.

Our security frameworks align with recognised industry practice. We do not currently claim any external certification, such as ISO 27001, that is not independently verified; we will update this page as soon as a certification is confirmed. We would rather state exactly what we have than imply what we do not.

Public sector

For public sector clients we align our controls with the requirements of Spain's National Security Scheme. See the public administrations page for detail on tendering and the requirements applicable to public procurement.

International data transfers

When a project involves the Latin America corridor or other hubs outside the European Economic Area, we apply the instruments GDPR requires: standard contractual clauses and, depending on data sensitivity, a transfer impact assessment. The dedicated international data transfers page explains the full detail, hub by hub.

Frequently asked questions about compliance and security

Is Corpshore Spain ISO 27001 certified?

Not at this time. Our security frameworks align with recognised industry practice, but we do not claim ISO 27001 certification while it is not confirmed and independently verified.

Do you hold National Security Scheme certification?

We align our controls with the National Security Scheme's requirements for public sector clients. We do not claim formal certification until one exists and is confirmed.

Can I review the data processing agreement before signing?

Yes. The data processing agreement is part of the proposal process and you can review it with your advisors before committing to a contract.

How do you protect data if the team works outside Spain?

We apply standard contractual clauses and, where relevant, a transfer impact assessment, alongside the same technical and organisational security measures we apply in Spain.

Does Corpshore act as controller or processor?

For most services Corpshore acts as processor on behalf of the client, who remains the controller. The exact split is set out in each project's agreement.

Do you have a data protection officer?

The group's data protection contact details are available on request as part of the data processing agreement.

Compliance questions before you contract?

Request the data processing agreement as part of your proposal, or book a call with our team.