Back to Blog Next Article
July 27, 2026 Majda Skrijelj 6 min read GDPR

GDPR Compliance Checklist for SMEs in 2026:
What You Actually Need to Do

Executive Summary
  • GDPR applies to every company that processes personal data, with no exemption based on company size.
  • Six years after the regulation came into force, 60% of French SMEs remain non-compliant: CNIL enforcement has intensified, with fines for small companies starting at €3,000 via the simplified procedure.
  • There are eight core obligations that every SME must address: legal basis, privacy notices, data subject rights, processing records, data security, breach notification, processor contracts, and cookie consent.
  • Most SMEs do not need to appoint a Data Protection Officer (DPO) - but all must handle the other seven obligations.
  • Non-EU companies selling to or monitoring EU residents are subject to GDPR and must appoint an EU representative.
60%
French SMEs

remain non-compliant with GDPR six years after the regulation came into force.

€3,000
Simplified Procedure

Minimum fines for small companies under the CNIL's simplified sanction audits.

GDPR defined: GDPR (Regulation EU 2016/679) is the EU data protection framework that applies to every company processing personal data of EU residents, regardless of size, sector, or country of incorporation. It has been in force since 25 May 2018 and is enforced by national Data Protection Authorities (DPAs) in each EU member state - coordinated at EU level by the European Data Protection Board (EDPB).

GDPR Still Catches Most SMEs Off Guard

A French SME with 12 employees, a CRM, a newsletter, and a hiring pipeline is processing personal data on dozens or hundreds of individuals every day. Under GDPR (Regulation EU 2016/679), that is enough to trigger full regulatory obligations - regardless of headcount, revenue, or sector.

The CNIL confirmed in its 2025 annual enforcement report that VSEs and SMEs are no longer off the radar. Its simplified sanction procedure - designed for lower-complexity cases - allows fines to be issued faster and with less procedural overhead, with penalties reaching €20,000. According to the Themio barometer , the average cost of reactive compliance after an incident is estimated at five to fifteen times the cost of proactive preparation.

This checklist covers what your SME needs to have in place.

Who Does GDPR Apply To?

Company profile Applies? Notes
EU-incorporated company ✅ Yes Full application - regardless of size or sector
EEA company (Norway, Iceland, Liechtenstein) ✅ Yes Via EEA Agreement; same obligations as EU companies
Non-EU company with EU customers ✅ Yes Article 3(2): extraterritorial scope applies if you offer goods/services to EU residents or monitor their behaviour
Non-EU company with no EU nexus ❌ No GDPR does not apply - but verify your actual customer base
EU accession country company (Serbia, Ukraine, Albania, etc.) ⚠️ Partial Domestic GDPR-equivalent laws apply; GDPR applies directly if you serve EU residents
Size threshold None GDPR applies from a company's first employee and first customer
Sector All No sector exemption - special categories (health, HR, biometric) face stricter rules

The 8-Item GDPR Compliance Checklist

1. Establish a legal basis for every processing activity (Article 6)

GDPR requires that you identify why you are processing each category of personal data before you process it. The six legal bases are: consent, contract performance, legal obligation, vital interests, public task, and legitimate interest.

Most SMEs rely on a combination of: contract (processing a customer's data to deliver a service), legal obligation (payroll, tax records), and legitimate interest (B2B marketing, fraud prevention). Consent is required for newsletter sign-ups and non-essential cookies - and must be freely given, specific, informed, and unambiguous.

Practical action : Create a simple internal list of the main categories of personal data you process (customers, employees, prospects, suppliers) and assign a legal basis to each.

2. Publish a compliant privacy notice (Articles 13–14)

Every individual whose data you collect must receive clear information at the time of collection: who you are, why you are processing their data, how long you keep it, their rights, and whether you share it with third parties.

This applies to your website contact form, your recruitment application process, your customer onboarding flow, and your employee records.

Practical action : Review your current privacy policy or notice. Check that it lists your legal bases, your data retention periods, your data recipients (including cloud providers), and how individuals can exercise their rights. The CNIL publishes model privacy notices and generator tools at cnil.fr.

3. Set up procedures for data subject rights (Articles 15–22)

Individuals have eight rights under GDPR: access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), objection (Article 21), and rights related to automated decision-making (Articles 21–22).

You must be able to respond within 30 days . Failure to respond is a compliance violation independent of whether the underlying processing was lawful.

Practical action : Set up a dedicated email address (e.g., privacy@yourcompany.com) for rights requests, document your internal response process, and verify you can actually locate and export or delete data when asked.

4. Maintain a Record of Processing Activities — ROPA (Article 30)

Article 30 requires controllers and processors to maintain a written record of all processing activities. The Article 30(5) exemption applies only if all three conditions are met: fewer than 250 employees, processing is occasional, and it does not include special category data or data relating to criminal convictions.

In practice, most SMEs - even those with fewer than 250 employees - process employee data regularly (payroll, HR), customer data continuously (CRM, billing), and prospect data on an ongoing basis. This means most SMEs do not qualify for the exemption.

Practical action : Create a ROPA spreadsheet listing: processing activity name, purpose, legal basis, categories of data, categories of recipients, retention period, and technical/organisational security measures. This does not need to be elaborate - a well-structured spreadsheet is sufficient.

5. Implement appropriate technical and organisational security measures (Article 32)

GDPR does not specify which security measures are required - it uses a risk-based standard: measures must be "appropriate" given the nature, scope, and purposes of the processing and the risks to individuals.

For most SMEs, this means: access controls (who can see what), password policies, encryption or pseudonymisation of sensitive data, regular backups, and staff awareness of data handling rules.

Practical action : Document your current security measures in your ROPA or a separate security policy. Identify gaps against basic hygiene standards (ISO 27001 controls, CNIL guidance on SME security). Patch the highest-risk gaps first.

6. Put in place a 72-hour breach notification process (Articles 33–34)

If a personal data breach occurs - including accidental loss, ransomware, or unauthorised access - you must notify your national DPA within 72 hours of becoming aware of it (Article 33). If the breach is likely to result in high risk to individuals, you must also notify the affected individuals without undue delay (Article 34).

Most SMEs have never thought through what they would do in the first 72 hours after discovering a breach. This is a gap that carries direct regulatory exposure.

Practical action : Draft a one-page breach response protocol: who is notified internally first, who decides whether DPA notification is required, and who drafts the notification. The CNIL provides a breach notification form at notifications.cnil.fr .

7. Sign Data Processing Agreements with all your processors (Article 28)

Every third-party provider that processes personal data on your behalf - cloud storage, CRM, email platform, payroll software, HR system - is a data processor under GDPR. You must have a written Data Processing Agreement (DPA) in place with each of them.

Major providers (AWS, Google Workspace, HubSpot, Salesforce, Stripe) provide standard DPAs and accept them electronically. The risk is smaller vendors or local providers where the DPA has never been requested.

Practical action : List all your SaaS tools and data processors. Verify a DPA is in place with each. For processors based outside the EEA, check whether an adequacy decision or Standard Contractual Clauses (SCCs) are in place for the data transfer.

8. Implement a compliant cookie consent mechanism (ePrivacy Directive + GDPR)

Under the ePrivacy Directive (implemented in France as Article L.34-5 of the CPCE) and GDPR, non-essential cookies - analytics, advertising, third-party embedded content - require prior consent before being placed. Consent must be freely given: the "reject" option must be as prominent as "accept."

CNIL actively enforces cookie consent rules. Dark patterns - pre-ticked boxes, "no reject button" designs, consent buried in settings - are treated as violations.

Practical action : Audit your current cookie banner. Ensure: (1) no cookies fire before consent; (2) the reject option is visible and as easy to use as accept; (3) consent is logged and timestamped; (4) a complete cookie notice is linked from the banner.

When Do You Need a Data Protection Officer?

A DPO is required under Article 37 only in three cases: you are a public authority, you carry out large-scale systematic monitoring of individuals, or you process special category data at large scale. Most SMEs are not in any of these categories.

However, if you process health data, biometric data, or large volumes of sensitive HR data, you should assess whether you cross the large-scale threshold - the EDPB guidelines on DPO obligations are the authoritative reference.

Key Deadlines and Milestones

Obligation Deadline / Trigger Reference
Breach notification to DPA 72 hours from awareness Article 33
Response to data subject rights requests 30 days (extendable to 3 months for complex requests) Articles 12, 15–22
DPA appointment Before first data exchange with processor Article 28
Privacy notice At point of data collection Articles 13–14
DPIA requirement assessment Before starting high-risk processing Article 35
EU representative appointment (non-EU companies) Before offering services to EU residents Article 27

For Non-EU and Accession Country Companies

Non-EU companies (US, UK post-Brexit, Turkey, and others): GDPR applies under Article 3(2) if you offer goods or services to EU residents or monitor their behaviour. You must appoint an EU representative (Article 27) - a natural or legal person established in the EU, designated as your contact point for the supervisory authority and data subjects - unless your processing is occasional, involves no special category data, and presents low risk.

Serbia - EU accession status: Candidate (negotiations ongoing). Serbia's Law on Personal Data Protection (LPDP, 2018) is materially aligned to GDPR. Serbian companies exporting to EU or raising EU capital should align to GDPR now - EU buyers and investors increasingly require GDPR-level compliance as a due diligence condition.

Ukraine - EU accession status: Candidate (June 2022). Ukraine's personal data law has been revised to align with EU standards. Companies with EU clients are subject to GDPR directly; domestic alignment is accelerating as part of the accession acquis.

Albania, Montenegro, North Macedonia - All have GDPR-equivalent national laws in force. Companies in these markets exporting to the EU should treat GDPR alignment as a market access requirement, not a future obligation.

Frequently Asked Questions

Does GDPR apply to my company if I have fewer than 10 employees?

Yes. GDPR applies to any entity that processes personal data, regardless of company size. There is no headcount-based exemption. A micro-business with three employees and a customer database is fully subject to GDPR obligations.

What is the CNIL's simplified sanction procedure, and can it affect my SME?

The CNIL's simplified procedure allows it to issue fines of up to €20,000 faster and with less procedural burden than formal proceedings. It is specifically designed for lower-complexity violations - which means smaller companies and typical SME compliance failures (missing privacy notice, non-compliant cookie consent, failure to respond to a rights request) are exactly the cases it targets. In 2025, the CNIL issued 87 penalties.

Does my company need a Record of Processing Activities (ROPA) if we have fewer than 250 employees?

Probably yes. The Article 30(5) exemption requires that all three conditions are satisfied: fewer than 250 employees, processing is occasional (not systematic or regular), and no special category data is processed. Most SMEs with regular customer, employee, or prospect data do not qualify for this exemption, since their processing is continuous rather than occasional.

We are a US company with some EU customers. Does GDPR apply to us?

Yes, under Article 3(2). If you offer goods or services to EU residents - including offering a website accessible to EU customers - GDPR applies to your processing of their data. You will likely need to appoint an EU representative under Article 27 and implement the full range of GDPR obligations with respect to EU personal data.

What is the difference between a privacy policy and a privacy notice?

A privacy policy is typically the full document published on your website covering all data processing activities. A privacy notice (under Articles 13-14) is the information provided to an individual at the point their data is collected - it may be a shorter, contextual version. GDPR requires both to be clear, accessible, and accurate.

What is the deadline for notifying a data breach under GDPR?

Under Article 33 of GDPR, a personal data breach must be notified to the competent national Data Protection Authority (DPA) within 72 hours of becoming aware of it. If the breach is likely to result in high risk to the rights and freedoms of individuals, the affected individuals must also be notified without undue delay under Article 34.

Majda Skrijelj

Senior Compliance Officer currently at an international financial institution, Majda has over 20 years of experience at the intersection of governance, anti-corruption, and European regulatory risk (GDPR, AI Act).

Themio.ai automates GDPR and AI Act compliance gap analysis for EU SMEs - identifying your actual exposure across all 8 obligations in under 2 minutes, with no legal expertise required. For a detailed comparison of GDPR tooling, check out our guide on the best AI Act compliance tools . See how it works →