Most SMEs believe they are roughly GDPR compliant. Few can prove it when a regulator, a client or an investor asks - and proof is the only thing that counts. Being GDPR compliant means you can show, on demand, which personal data you process, why, on what legal basis, and how you protect it. This guide turns that into something concrete: a self-assessment, a GDPR compliance checklist you can work through today, and a structured plan to fix what's missing. Start with the free check below to see where you actually stand.
- GDPR compliance is documented proof, not good intentions - an inspection asks for records, not assurances.
- Seven core duties cover the bulk of what an SME needs: legal basis, privacy notice, ROPA, security measures, breach process, DPIA and a DPO where required.
- Fines can reach up to €20M or 4% of worldwide turnover, and the Managing Director can additionally be personally liable where supervisory duties are breached (under German law: §130 OWiG, §43 GmbHG).
- A focused 30-60-90-day plan gets a typical SME to a defensible baseline.
Answer a short set of yes/no questions about your data, your documentation and your team. You get an immediate read on where your gaps are, plus the full checklist to download. It is the fastest honest answer to "are we GDPR compliant?"
What Does "GDPR Compliant" Actually Mean?
Is compliance a state, or something you have to prove?
It's something you prove. A company is GDPR compliant when it can produce complete, current documentation showing that its data processing follows the regulation - even if the underlying processing was already correct. Article 5 of the GDPR sets the principles every activity must meet: lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. That last one, accountability, is the practical heart of it: you must be able to demonstrate compliance, not just assert it.
For an SME, this rarely means the data handling is fundamentally wrong. It means the evidence is incomplete - a missing record here, an outdated notice there. The work of getting compliant is mostly the work of making your existing practice visible and verifiable. The next step is knowing exactly which records that requires.
The 7 Core GDPR Duties for SMEs
What does the regulation actually require of a company like mine?
These seven duties cover the large majority of GDPR obligations for a typical SME. Map your current state against each one - this is the backbone of any serious GDPR risk assessment.
| Duty | Article | What it means in practice |
|---|---|---|
| Legal basis for processing | Art. 6 | Every use of personal data needs a valid basis (consent, contract, legitimate interest, etc.) - documented per activity |
| Transparency / privacy notice | Art. 13-14 | A clear privacy notice telling people what you do with their data, naming your actual tools |
| Record of Processing Activities (ROPA) | Art. 30 | A central register of every process involving personal data |
| Technical & organisational measures (TOM) | Art. 32 | Concrete security: encryption, access control, backups, logging, policies |
| Breach notification process | Art. 33-34 | The ability to notify the supervisory authority within 72 hours of a breach, and to inform affected individuals where the risk is high |
| Data Protection Impact Assessment (DPIA) | Art. 35 | A risk assessment for high-risk processing - especially AI-assisted decisions |
| Data Protection Officer (DPO) | Art. 37 | A formally appointed DPO where the law requires one |
Two of these carry most of the weight in practice: the ROPA, which is the master record everything else hangs off, and your security measures, which are what an authority inspects most closely. For the full build of the documentation layer, see our ROPA & GDPR documentation guide; to check whether you're legally required to appoint a DPO, see external Data Protection Officer.
The GDPR Compliance Checklist
What should I actually have in place - a checklist I can work through?
Work through the list below. If you can answer "yes, and I can show the document" to each item, you have a defensible baseline. Anything you can't evidence is a gap to close.
- Lawful basis documented for every processing activity (Art. 6).
- Privacy notice published and current - covering your website, app and customer communications, naming the specific tools you use (Art. 13-14).
- Record of Processing Activities (ROPA) maintained and reviewed, not created once and forgotten (Art. 30).
- Data Processing Agreements (DPAs) signed with every vendor that processes data on your behalf - hosting, email, CRM, AI tools.
- Technical and organisational measures documented - encryption, role-based access, tested backups, logging (Art. 32).
- Breach response process defined - who is notified, how, and within the 72-hour window (Art. 33).
- DPIA completed for any high-risk processing, including AI-assisted decisions about people (Art. 35).
- DPO appointed if your company meets the threshold, and contactable (Art. 37-39).
- Data subject request process in place - access, rectification, erasure, objection - with a defined response time.
- Staff trained on handling personal data in their role, with the training documented.
- Retention and deletion policy defined and applied - you don't keep data longer than you need it.
- Named ownership for keeping all of the above current.
This is the short, working version. Download the full GDPR compliance checklist as a PDF to track progress across your team, and run the free compliance check for your gap status.
Audit Preparation: What Authorities Actually Check
What happens in a data protection audit, and what will they ask for?
They ask for documentation. A supervisory authority - in Germany, your state data protection authority - does not test whether you understand the rules; it requests evidence that you follow them (the accountability principle). In a GDPR audit or data protection audit, the common requests are: your ROPA, your privacy notice, your DPAs with processors, your TOM, your breach records, and proof of staff training. A company that produces these quickly and consistently is in a strong position. One that cannot has no line of defence, regardless of how careful its actual practices are.
Audits are also increasingly triggered by third parties rather than regulators: enterprise clients and investors run their own data protection due diligence before signing, and they ask for the same documents. Being audit-ready is therefore not only a regulatory safeguard - it keeps deals moving.
For the step-by-step preparation, including what each authority typically requests and how to assemble it, see our dedicated guide on data protection audit preparation. The single best preparation, though, is a complete ROPA - start there.
GDPR Breaches: Fines and Personal Liability
What are the real consequences of getting this wrong?
GDPR fines reach up to €20M or 4% of worldwide annual turnover, whichever is higher. Beyond the fine, the Managing Director can be personally liable for demonstrably inadequate organisational measures (under German law: §130 OWiG, §43 GmbHG) - this is not a risk that stays neatly inside the company. And when a breach occurs, the clock is short: you have 72 hours to notify the supervisory authority (Art. 33), which is only achievable if the process exists before the incident.
The point of stating this plainly is not to alarm you - it's to size the decision. The cost of building a defensible compliance baseline is predictable and modest. The cost of being caught without one is neither. We help make sure it never comes to that. The practical move is to close the documentation gaps now, while it's a planning exercise rather than an emergency.
Common GDPR Compliance Mistakes at SMEs
Where do companies usually lose points in practice?
Most SMEs fail an audit not on intent but on the same handful of gaps. Knowing them in advance is the cheapest way to close them.
- A ROPA created once and never updated. Every new tool or vendor changes your data landscape; an outdated record is treated as no record.
- Only the website is documented. The CRM, HR system, support tool and newsletter platform all process personal data and all belong in your documentation.
- A privacy notice straight from a generator. Generic text doesn't name the tools you actually use - and a regulator notices the difference.
- Missing DPAs for obvious vendors. Hosting, email, CRM and AI tools are processors; without a signed agreement, every transfer to them is unlawful.
- TOM described too vaguely. "Appropriate measures" is a placeholder, not a control - name the encryption, the access model, the backup routine.
- No named owner. Without one person accountable for keeping documentation current, it quietly goes stale.
- AI tools left out entirely. ChatGPT or Copilot in daily use creates GDPR obligations today, and EU AI Act obligations alongside them.
Run the free compliance check to see which of these apply to you, then close them in order of risk.
Your 30-60-90-Day Path to GDPR Compliance
Can a typical SME realistically get compliant - and how fast?
Yes, with a defined plan and one person who owns it. Compliance debt that built up over years can't be cleared in a day, but a structured quarter gets a typical SME to a defensible baseline. Here is the sequence at a glance.
| Phase | Focus | Outcome |
|---|---|---|
| Days 1-30 | Map all processing; build the ROPA; review the privacy notice | You know what data lives where, and your central record exists |
| Days 31-60 | Document TOM; sign missing DPAs; define the breach process | Your security and vendor layer is evidenced |
| Days 61-90 | Run DPIAs for high-risk processing; train staff; assign ownership; close gaps | You have a maintainable, audit-ready baseline |
This is the overview. For the detailed week-by-week version with templates, follow our GDPR implementation roadmap, and download the 30-60-90-day roadmap to assign owners and dates. The next step after that is keeping it current - compliance is a process, not a project you close.
How ETHYX Helps You Stay GDPR Compliant
What do I get beyond a checklist?
ETHYX turns the checklist into a maintained system. The platform guides you through ROPA, TOM, DPA tracking and DPIAs with structured templates instead of blank pages, and flags entries for review when they fall out of date - so your data protection management doesn't decay the moment the initial project ends. Where your plan calls for it, a certified external Data Protection Officer (CIPP/E) reviews your documentation and signs off on it, giving you a credible, named point of contact for authorities and clients.
Pricing starts at €149/month for the self-serve platform; the Expert plan at €299/month adds the appointed external DPO and EU AI Act deployer documentation. If your team uses AI tools, those obligations run alongside GDPR - see EU AI Act compliance for SMEs for how the two connect. Start with the free compliance check above to see which gaps to close first.
Get Started
See where you stand, then close the gaps with a clear plan - calmly, before a client or regulator asks. The companies that can hand over complete documentation on request are the ones that keep deals and stay out of trouble.