{"id":8205,"date":"2018-04-26T15:42:52","date_gmt":"2018-04-26T13:42:52","guid":{"rendered":"https:\/\/blog.sheetgo.com\/?p=8205"},"modified":"2025-09-23T01:03:52","modified_gmt":"2025-09-22T23:03:52","slug":"gdrp-compliance-in-spreadsheets","status":"publish","type":"post","link":"https:\/\/www.sheetgo.com\/es\/blog\/business-processes\/gdrp-compliance-in-spreadsheets\/","title":{"rendered":"Cumplimiento del GDPR en hojas de c\u00e1lculo"},"content":{"rendered":"\n[et_pb_section fb_built=&#8221;1&#8243; module_class=&#8221;sheetgo-post&#8221; _builder_version=&#8221;4.16&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_row _builder_version=&#8221;4.16&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.16&#8243; custom_padding=&#8221;|||&#8221; global_colors_info=&#8221;{}&#8221; custom_padding__hover=&#8221;|||&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.16&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<p><a href=\"https:\/\/ec.europa.eu\/info\/law\/law-topic\/data-protection\/reform\/what-does-general-data-protection-regulation-gdpr-govern_en\" target=\"_blank\" rel=\"noopener noreferrer\">Europe&#8217;s General Data Protection Regulation (GDPR)<\/a> is a new law governing data protection and privacy for citizens of the European Union. Its aim is to give individuals control over their data and simplify existing regulations. GDPR becomes enforceable on May 25th 2018 and companies that are found to not comply with the regulation can be fined up to \u20ac10 million or 2% of worldwide revenue. Spreadsheets are the least controlled data repositories for the most companies and are therefore the most prone to be non-compliant with GDPR regulations. In this article, we will give you recommendations to manage GDPR compliance for your spreadsheets.<\/p>\n<h2>What data is covered under GDPR?<\/h2>\n<p>The regulation applies to companies that are located in the EU or that control or process data of people located in the EU. GDPR covers all personal data which is defined by the European Commission as &#8220;any information relating to an individual, whether it relates to his or her private, professional or public life. It can be anything from a name, a home address, a photo, an email address, bank details, posts on social networking websites, medical information, or a computer\u2019s IP address.&#8221;<\/p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.16&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<h2>What are the responsibilities of data controllers and processors?<\/h2>\n<p>Data controllers must implement protective measures for personal data. This includes &#8220;pseudonymizing&#8221; personal data as soon as possible, so that data points cannot be linked to a persons name or ID. Further, data may not be processed unless there is a lawful basis to do so. A lawful basis includes the explicit consent of the data subject, for <a href=\"https:\/\/www.sheetgo.com\/legal\/\" target=\"_blank\" rel=\"noopener\">legal compliance<\/a>, and to perform a contract to which the data subject is the party, among others.<\/p>\n<h2>How does this impact the governance of spreadsheets?<\/h2>\n<p>Virtually all companies either store in, or download their data to, spreadsheets for analysis and reporting. Frequently this means it leaves a controlled environment (such as an ERP) and goes to an uncontrolled environment (e.g. a spreadsheet which can be freely shared among colleagues and others). GDPR does not prohibit your company from storing personal data, it requires that you have proper controls over it, including knowing what information you have, where it is stored, and whom has access. The steps to ensuring your spreadsheets are GDPR compliant are:<\/p>\n<ol>\n<li>Know which spreadsheets contain personal data<\/li>\n<li>Delete spreadsheets that are not essential to day-to-day operations<\/li>\n<li>Restrict access to said spreadsheets to only those that need to know<\/li>\n<li>Routinely repeat steps 1-3 to assure that you are in constant compliance<\/li>\n<\/ol>\n<h2>How can Sheetgo help you achieve GDPR compliance in spreadsheets?<\/h2>\n<p>Sheetgo&#8217;s enhanced Scan Sheets feature can scan all of the spreadsheets on your Google Drive, read all of the tab names, and header names (<a href=\"https:\/\/www.sheetgo.com\/legal\/privacy\/\" target=\"_blank\" rel=\"noopener noreferrer\">we don&#8217;t have access to any data in your spreadsheet that is not in the header row<\/a>), flag sheets that potentially have personal data and inform you of all users inside and outside of your domain that have access to said sheets. <strong>Request your free report by filling out the form below:<\/strong><\/p>[\/et_pb_text][et_pb_contact_form email=&#8221;chad@sheetgo.com&#8221; success_message=&#8221;Thanks for your interest in analyzing your GDPR risk. Our team will follow up shortly with a report on potentially non compliant spreadsheets.&#8221; submit_button_text=&#8221;SEND&#8221; module_id=&#8221;et_pb_contact_form_0&#8243; _builder_version=&#8221;4.16&#8243; _unique_id=&#8221;1fddef85-331d-4b21-80a6-7a0b0db682e3&#8243; custom_button=&#8221;on&#8221; button_text_color=&#8221;#ffffff&#8221; button_bg_color=&#8221;#4caf50&#8243; button_border_width=&#8221;0&#8243; button_border_radius=&#8221;2&#8243; button_use_icon=&#8221;off&#8221; box_shadow_style_button=&#8221;preset2&#8243; box_shadow_horizontal_button=&#8221;3px&#8221; box_shadow_vertical_button=&#8221;3px&#8221; box_shadow_blur_button=&#8221;10px&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_contact_field field_id=&#8221;Name&#8221; field_title=&#8221;Name&#8221; _builder_version=&#8221;4.16&#8243; global_colors_info=&#8221;{}&#8221; button_text_size__hover_enabled=&#8221;off&#8221; button_one_text_size__hover_enabled=&#8221;off&#8221; button_two_text_size__hover_enabled=&#8221;off&#8221; button_text_color__hover_enabled=&#8221;off&#8221; button_one_text_color__hover_enabled=&#8221;off&#8221; button_two_text_color__hover_enabled=&#8221;off&#8221; button_border_width__hover_enabled=&#8221;off&#8221; button_one_border_width__hover_enabled=&#8221;off&#8221; button_two_border_width__hover_enabled=&#8221;off&#8221; button_border_color__hover_enabled=&#8221;off&#8221; button_one_border_color__hover_enabled=&#8221;off&#8221; button_two_border_color__hover_enabled=&#8221;off&#8221; button_border_radius__hover_enabled=&#8221;off&#8221; button_one_border_radius__hover_enabled=&#8221;off&#8221; button_two_border_radius__hover_enabled=&#8221;off&#8221; button_letter_spacing__hover_enabled=&#8221;off&#8221; button_one_letter_spacing__hover_enabled=&#8221;off&#8221; button_two_letter_spacing__hover_enabled=&#8221;off&#8221; button_bg_color__hover_enabled=&#8221;off&#8221; button_one_bg_color__hover_enabled=&#8221;off&#8221; button_two_bg_color__hover_enabled=&#8221;off&#8221; theme_builder_area=&#8221;post_content&#8221;][\/et_pb_contact_field][et_pb_contact_field field_id=&#8221;Email&#8221; field_title=&#8221;Email Address&#8221; field_type=&#8221;email&#8221; _builder_version=&#8221;4.16&#8243; global_colors_info=&#8221;{}&#8221; button_text_size__hover_enabled=&#8221;off&#8221; button_one_text_size__hover_enabled=&#8221;off&#8221; button_two_text_size__hover_enabled=&#8221;off&#8221; button_text_color__hover_enabled=&#8221;off&#8221; button_one_text_color__hover_enabled=&#8221;off&#8221; button_two_text_color__hover_enabled=&#8221;off&#8221; button_border_width__hover_enabled=&#8221;off&#8221; button_one_border_width__hover_enabled=&#8221;off&#8221; button_two_border_width__hover_enabled=&#8221;off&#8221; button_border_color__hover_enabled=&#8221;off&#8221; button_one_border_color__hover_enabled=&#8221;off&#8221; button_two_border_color__hover_enabled=&#8221;off&#8221; button_border_radius__hover_enabled=&#8221;off&#8221; button_one_border_radius__hover_enabled=&#8221;off&#8221; button_two_border_radius__hover_enabled=&#8221;off&#8221; button_letter_spacing__hover_enabled=&#8221;off&#8221; button_one_letter_spacing__hover_enabled=&#8221;off&#8221; button_two_letter_spacing__hover_enabled=&#8221;off&#8221; button_bg_color__hover_enabled=&#8221;off&#8221; button_one_bg_color__hover_enabled=&#8221;off&#8221; button_two_bg_color__hover_enabled=&#8221;off&#8221; theme_builder_area=&#8221;post_content&#8221;][\/et_pb_contact_field][et_pb_contact_field field_id=&#8221;Message&#8221; field_title=&#8221;Message&#8221; field_type=&#8221;text&#8221; fullwidth_field=&#8221;on&#8221; _builder_version=&#8221;4.16&#8243; global_colors_info=&#8221;{}&#8221; button_text_size__hover_enabled=&#8221;off&#8221; button_one_text_size__hover_enabled=&#8221;off&#8221; button_two_text_size__hover_enabled=&#8221;off&#8221; button_text_color__hover_enabled=&#8221;off&#8221; button_one_text_color__hover_enabled=&#8221;off&#8221; button_two_text_color__hover_enabled=&#8221;off&#8221; button_border_width__hover_enabled=&#8221;off&#8221; button_one_border_width__hover_enabled=&#8221;off&#8221; button_two_border_width__hover_enabled=&#8221;off&#8221; button_border_color__hover_enabled=&#8221;off&#8221; button_one_border_color__hover_enabled=&#8221;off&#8221; button_two_border_color__hover_enabled=&#8221;off&#8221; button_border_radius__hover_enabled=&#8221;off&#8221; button_one_border_radius__hover_enabled=&#8221;off&#8221; button_two_border_radius__hover_enabled=&#8221;off&#8221; button_letter_spacing__hover_enabled=&#8221;off&#8221; button_one_letter_spacing__hover_enabled=&#8221;off&#8221; button_two_letter_spacing__hover_enabled=&#8221;off&#8221; button_bg_color__hover_enabled=&#8221;off&#8221; button_one_bg_color__hover_enabled=&#8221;off&#8221; button_two_bg_color__hover_enabled=&#8221;off&#8221; theme_builder_area=&#8221;post_content&#8221;][\/et_pb_contact_field][\/et_pb_contact_form][\/et_pb_column][\/et_pb_row][\/et_pb_section]\n","protected":false},"excerpt":{"rendered":"<p>Europe&#8217;s General Data Protection Regulation (GDPR) is a new law governing data protection and privacy for citizens of the European Union. Its aim is to give individuals control over their data and simplify existing regulations. GDPR becomes enforceable on May 25th 2018 and companies that are found to not comply with the regulation can be [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":8211,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[66],"tags":[28],"class_list":["post-8205","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business-processes","tag-spreadsheets"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.sheetgo.com\/es\/wp-json\/wp\/v2\/posts\/8205","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.sheetgo.com\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.sheetgo.com\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.sheetgo.com\/es\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.sheetgo.com\/es\/wp-json\/wp\/v2\/comments?post=8205"}],"version-history":[{"count":0,"href":"https:\/\/www.sheetgo.com\/es\/wp-json\/wp\/v2\/posts\/8205\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.sheetgo.com\/es\/wp-json\/wp\/v2\/media\/8211"}],"wp:attachment":[{"href":"https:\/\/www.sheetgo.com\/es\/wp-json\/wp\/v2\/media?parent=8205"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.sheetgo.com\/es\/wp-json\/wp\/v2\/categories?post=8205"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.sheetgo.com\/es\/wp-json\/wp\/v2\/tags?post=8205"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}