By Rafael Luque Ocaña

Facilita RGPD and Gestiona RGPD: what they solve well — and where the coverage ends

The AEPD's free tools are an excellent starting point for an SME's basic GDPR compliance. The Agency itself warns of their limit: obtaining the documents doesn't mean you comply. And AI, by design, falls outside their scope.

When a Spanish SME takes its first steps in data protection, two names come up right away: Facilita RGPD and Gestiona RGPD, the free tools from the Spanish Data Protection Agency (AEPD). And they come up for good reason: they're a well-built public service. They guide the company through simple questionnaires and generate the basic documentation the GDPR requires for low-risk processing — a record of processing activities, privacy notices, data processing agreements. For thousands of small businesses, they've been the difference between having nothing and having the essentials.

Precisely because they're valuable, it's worth understanding just as clearly what they solve and what they don't. And here the starting point isn't ours to set — it's the AEPD's own: it warns that obtaining the documents from these tools does not, on its own, mean compliance with the law. The documentation generated is a starting point that has to be adapted, maintained and, above all, put into practice.

What's left out, by design

The AEPD's tools are designed for a specific scenario: low-risk processing of personal data, under the GDPR and Spain's LOPDGDD. Anything outside that scenario falls outside their scope — not because the tools fall short, but because they never set out to cover it. In 2026, for a company that uses artificial intelligence, that "outside" keeps getting bigger:

The AI Act doesn't exist in them. The AI Regulation introduces its own body of obligations — literacy, transparency, risk classification, and a calendar that rolls out between 2025 and 2028 — that sits outside the GDPR perimeter these tools cover. None of their questionnaires ask which AI systems you use or which obligations they trigger.

Neither does the specificity AI requires. A record of processing activities is not an AI systems inventory. Classifying a processing activity by its legal basis is not the same as classifying a system by its risk level. And the fastest-growing scenarios — generative AI in the workplace, autonomous agents, scoring of individuals — require analysis that a generic document generator can't do.

Living evidence is the third limit. The documents generated are a snapshot of the day they were generated. Compliance — with the GDPR and, increasingly, with the AI Act — is a moving picture: systems change, uses change, obligations activate on fixed dates. Without a record that lives alongside the organisation, the snapshot ages in silence.

The mistake isn't using them; it's stopping there

None of the above is a criticism of the tools. It's a description of their perimeter, consistent with the Agency's own warning. The mistake we see in practice isn't using Facilita or Gestiona: it's believing that, once the documents are generated, "data protection" is sorted — and, by extension, that AI is too. The first isn't entirely true — the AEPD says so itself — and the second has no basis at all.

A sensible sequence for an SME that uses AI looks something like this:

  1. Use the public tools for your GDPR baseline if your scenario fits their scope. They're free, official, and good at what they do.
  2. Recognise where they stop: as soon as there's AI evaluating people, special-category data, automated decisions, or simply the question "what does the AI Act require of me?", you're outside their perimeter.
  3. Cover that stretch with method: a systems inventory, risk classification, obligations mapped to dates, and traceable evidence of every decision — which is exactly what you'll be asked for one day, and what generic documents can't give you.

If you want to know how much of that stretch applies to you, the free diagnostic gives you that first snapshot in a few minutes: which AI Act obligations apply to you based on what you already use. From there, the difference between the snapshot and actual compliance comes down to the usual thing: evidence.

Facilita RGPD and Gestiona RGPD are public services provided by the Spanish Data Protection Agency (AEPD). This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.