C/ Ramon Iglesias 2, Local 2, 08242 - Manresa (Barcelona)
    685 399 036
    info@atigroup.es

    AI Act · GDPR · NIS2

    AI, GDPR and legal clarity. Are you compliant?

    Regulatory compliance has changed. These three laws affect your business today, even if no one has explained them to you yet.

    Quick Assessment

    Can you answer these four questions?

    They're not rhetorical. These are the exact points the AEPD checks when sanctioning a company.

    ChatGPT, HR automations, software plugins... every undocumented AI use can expose you to sanctions under the AI Act.

    The AEPD already sanctions notices, contracts and forms that citizens cannot understand, even if they are legally correct.

    An RPA from 2018 or 2020 doesn't cover AI or current digital channels. Without an update, the AEPD won't consider it valid evidence.

    The law gives you exactly 72 hours. Without a defined protocol, meeting that deadline is practically impossible.

    Legal Framework

    The regulations that already apply to you

    This is not an optional service. It is legal compliance.

    The European Artificial Intelligence Regulation (EU Regulation 2024/1689) entered into force in August 2024 and began to apply progressively. From August 2025, governance obligations and requirements for general-purpose AI models are fully enforceable across the EU.

    The regulation classifies AI systems by risk level: unacceptable (prohibited), high risk, limited risk and minimal risk. It doesn't only affect AI developers: any company using AI tools (ChatGPT, candidate selection systems, customer service automations, software plugins) is subject to the regulation.

    Obligations include inventorying and classifying all AI systems in use, ensuring staff have sufficient training (AI literacy, mandatory) and issuing an official assessment. Without that assessment, any AI use can expose you to fines of up to €35 million or 7% of global annual turnover.

    The NIS2 Directive (EU 2022/2555) entered into force in January 2023 and had to be transposed into national law before October 2024. It significantly expands the scope of its predecessor: it applies to entities in more than 18 sectors (energy, transport, health, water, digital infrastructure, public administration) and lowers the size threshold. Medium-sized companies with more than 50 employees or over €10 million in turnover may already be obliged.

    Key obligations include implementing technical and organisational cybersecurity risk management measures, reporting significant incidents within a maximum of 72 hours, and establishing an accountability chain that reaches the management body. Directors can be held personally liable in the event of non-compliance.

    The sanctions regime is one of the harshest in European law: up to €10 million or 2% of global turnover for important entities. ATI assesses your exposure level, implements the required measures, and supports you in your dealings with INCIBE and the competent authorities.

    The General Data Protection Regulation has been in force since May 2018, but the reality of 2025 has overtaken it. The GDPR did not anticipate language models like ChatGPT, mass data scraping, automatic transfers between SaaS platforms, or the use of AI in HR processes.

    The Record of Processing Activities (RPA, Art. 30 GDPR) is the core document the AEPD requests in any inspection. An RPA from 2018 or 2020 that doesn't reflect current AI use, cloud tools or new acquisition channels has no value as evidence. The AEPD doesn't assess the document's existence: it assesses whether it reflects the company's active reality.

    The AEPD has imposed more than 300 sanctions in the last three years. SMEs and self-employed individuals represent the most frequent profile, with fines ranging from €900 to €100,000. The most serious infringements (unreported breaches, unlawful processing) can reach €20 million or 4% of global turnover.

    Sanction Scale

    How much can non-compliance cost?

    Fines are not only for large companies. An SME can receive sanctions that put the continuity of the business at risk.

    MINOR LEVEL

    Up to €40,000

    Formal infringements: incorrect legal notice, cookies without properly informed consent, illegible forms.

    • Outdated privacy notice
    • Cookie banner without a rejection option
    • Lack of basic information to the user

    SERIOUS LEVEL

    Up to €300,000

    No active RPA, no DPO when mandatory, failure to comply with data subject rights, lack of security measures.

    • No Record of Processing Activities
    • No technical security measures
    • Candidate CVs without proper handling

    VERY SERIOUS LEVEL

    Up to €20,000,000

    or 3% global turnover

    Unreported data breach, unlawful use of AI, unauthorised transfers. If you are self-employed, you are liable with your personal assets.

    • Breach not reported within 72 hours
    • AI use without assessment or policy
    • Unlawful processing of client data

    72 hours is the time the law gives you to notify the AEPD of a breach. Without a defined protocol, meeting that deadline is practically impossible.

    Real Cases

    What many companies do… and the AEPD sanctions

    These are not exceptional cases. They are the day-to-day reality of any business.

    ChatGPT in the office

    A law firm uses ChatGPT to draft briefs containing client data. This happens in thousands of offices every day and almost no one realises.

    • —Illegal without a data policy approved by the DPO
    • —Illegal without an active Information Security Plan
    • —Without a protocol, every drafted brief is a separate infringement

    In the event of a breach, the sanction could force closure

    The CV in the inbox

    A restaurant posts a job vacancy and receives 40 CVs by email. The manager saves them in their inbox and gets on with the day.

    • —The candidate is not informed of how their data will be processed
    • —CVs remain in the inbox after the process ends
    • —Stored longer than necessary without explicit consent

    AEPD fine: from €900 to €20,000 for an SME

    The work WhatsApp group

    An estate agency adds its clients to a WhatsApp group to send them property updates. It seems like a normal commercial gesture.

    • —Requires prior explicit consent from each person
    • —All members' data is visible to the rest
    • —Each person added without consent is a separate infringement

    Each member without consent = separate infringement

    The 2018 contract that no longer works

    A business signed its data protection contract back in 2018. It believes it is protected. The AEPD sees things very differently.

    • —Without an active, updated RPA, the signed paper is worthless
    • —The AEPD assesses real compliance evidence, not documents
    • —The GDPR has changed: that contract doesn't cover AI or new channels

    That client could be sanctioned today

    What We Offer

    The ATI Group solution

    Three laws. One point of contact. We handle everything so you don't have to.

    FIRST AND MANDATORY

    AI Act Assessment

    We analyse all artificial intelligence systems in your company, known or unknown, and issue the official assessment. Without this assessment, any AI use is already an infringement. It is the mandatory first step for any company, regardless of size.

    GDPR · Live RPA

    We keep your Record of Processing Activities up to date. Not a document gathering dust: active evidence the AEPD can verify at any time.

    Visual Law

    We redesign forms, legal notices and contracts to make them clear and understandable. The AEPD already sanctions texts that citizens cannot understand.

    Team Training

    A perfect protocol is useless if the team doesn't know how to apply it. We train employees in data protection, correct AI use and basic cybersecurity.

    NIS2 · Cybersecurity

    We assess your cybersecurity posture and implement the measures required by NIS 2: technical protection, 72-hour breach notification protocol and management accountability.

    Why ATI Group

    What makes us different

    01

    360 Advisory

    We don't just manage compliance. We are your all-in-one advisor: taxes, grants, Verifactu, payroll, audits. One single point of contact for everything.

    02

    Real evidence, not paperwork

    The AEPD doesn't value a 2018 contract. It values real, active evidence. We generate and maintain it.

    03

    Native Visual Law

    We believe laws should be understandable for everyone. We design your documents so that anyone can understand them.

    04

    Ongoing support

    We don't disappear after signing. Constant monitoring and updates with every regulatory change. Always accessible.

    No commitment

    Want to know exactly where your company stands?

    Know your real situation before the AEPD finds out.