Themio · Regulatory Guides

GDPR Compliance: What Every SME Actually Needs to Do

GDPR applies the moment you handle one EU resident's personal data. It doesn't exempt small businesses. This page covers what that means for a company your size, and how Themio's GDPR tool, launching this fall, keeps you covered.

GDPR at a glance

GDPR at a glance

€1.15bn

Total EU Fines in 2025

Total GDPR fines issued across the EU in 2025 (EDPB Annual Report 2025).
€487M

CNIL Fines in 2025

Fines issued by France's CNIL alone across 83 sanction decisions (CNIL Rapport annuel 2025).
No Size Exemption

Universal Application

GDPR applies to a 2-person startup the same way it applies to a 2,000-person group (Regulation (EU) 2016/679).
72 hours

Breach Notification

The mandatory deadline to notify your national authority after a personal data breach (Art. 33 GDPR).
Regulation (EU) 2016/679

What GDPR actually regulates

The General Data Protection Regulation, Regulation (EU) 2016/679, has applied since 25 May 2018 . It governs how any organization collects, stores, uses, and shares personal data belonging to people in the EU, no matter where that organization is based.

If you have EU customers, EU employees, or EU website visitors whose data you process, GDPR applies to you. That's true even if your company is registered outside the EU.

Proportionality & Scope

How GDPR obligations scale with your size

GDPR has no small-business carve-out, but what "compliant" looks like in practice depends on what you actually do with data.

1. A 5-person shop

With a customer mailing list and a website contact form, you typically need a documented lawful basis for each use of that data, a public privacy notice, and a basic process for handling a data breach or a subject-access request. Usually no Data Protection Officer.

2. A 50–200 person SME

Running regular marketing, HR, or product-analytics processing typically also needs a documented Record of Processing Activities (ROPA). The under-250-employee exemption in Art. 30(5) stops applying once processing is regular, involves special-category data, or carries real risk, so most SMEs in this range don't qualify for it. Add data-processing agreements with every vendor that touches personal data, and a systematic way to handle subject-rights requests at volume.

3. A mid-cap or consultancy

Handling client data, health data, or large-scale profiling usually crosses the threshold for a mandatory DPO (Art. 37) and needs auditable evidence of compliance, not just policies on paper.

Mandatory Pillars

Core GDPR obligations

1

Lawful basis for every processing activity (Art. 6)

Consent, contract, legal obligation, or legitimate interest, documented for each specific use case.

2

Data subject rights (Art. 12–22)

Access, rectification, erasure, portability, objection. Answer requests within one month.

3

Records of Processing Activities (Art. 30)

Mandatory once the small-organization exemption stops applying (regular processing, risky data, or HR/CRM workflows).

4

Breach notification within 72 hours (Art. 33–34)

Notify your supervisory authority within 72 hours, and affected individuals if the risk to their rights is high.

5

Data Protection Officer (Art. 37)

Required for public authorities, large-scale systematic monitoring, or large-scale special-category processing. Most micro and small businesses fall outside these triggers.

6

International transfer safeguards (Chapter V)

Standard Contractual Clauses (SCCs), or an adequacy decision, before personal data leaves the EU/EEA.

Supervision & Enforcement

Where GDPR enforcement stands in 2026

Enforcement intensified in 2025. The EDPB reports €1.15bn in fines issued across the EU. France's CNIL alone issued €487M across 83 sanction decisions after 323 inspections, and both complaints (20,150, up 10%) and breach notifications (6,167, up 9.5%) rose from 2024.

Sanctions reach companies of all sizes:

CNIL's own report says its fines reached "companies of all sizes." Its simplified sanction procedure, introduced in 2022 for less complex cases, is part of why smaller organizations now show up on the sanctions list alongside large groups.

Themio Solution

What Themio does for you

Themio turns your GDPR paperwork, privacy policy, data processing agreements, internal procedures, into a clear compliance score and a ranked list of what to fix first. You stop guessing whether your documents hold up and start working from a report you can hand to an auditor. It launches this fall.

Starter

from €49 /mo

1 user, 1 project, 10 compliance credits a month. Right for a single-scope micro-business getting its first GDPR documentation in order.

Premium

from €349 /mo

10 users, 10 projects, 200 compliance credits a month, full audit logs, SSO. For a mid-cap or consultancy that needs auditable, ongoing proof of compliance.

Join the priority waitlist today

Join the priority waitlist now and get 10 free audit credits when we launch this fall.

Intersecting Frameworks

GDPR and the AI Act: One compliance program, not two

If you use AI tools on personal data, ChatGPT, Copilot, or your own AI features, you're likely inside both GDPR and the EU AI Act at once. GDPR governs the personal data. The AI Act governs the system processing it.

Treat them as two separate compliance efforts and you end up doing the work twice, which is one reason Themio is launching GDPR and AI Act support together this fall.

Frequently Asked Questions

Frequently Asked Questions

What does Themio do for you?
You get a compliance score and a ranked list of what to fix, each one backed by the exact clause it's based on rather than a vague suggestion. Upload your privacy policy, data processing agreements, or internal procedures, and Themio checks them against GDPR's actual text. You walk away with a PDF report you can hand to an auditor, a dashboard that tracks your score over time, and a record of every check you've run.
Does GDPR apply to my small business if I'm not based in the EU?
Yes, if you offer goods or services to people in the EU or monitor their behavior (Art. 3). Your company's location doesn't matter. What matters is whose data you process.
Do I need a Data Protection Officer?
Only if you're a public authority, your core activity involves large-scale systematic monitoring, or you process special-category data like health or biometric data at scale (Art. 37). Most small and mid-sized businesses don't meet these thresholds. Check against your actual processing rather than assuming.
What happens if my SME isn't GDPR compliant?
Fines can reach €20M or 4% of global annual turnover, whichever is higher (Art. 83). 2025 enforcement shows real reach into smaller organizations: CNIL's simplified sanction procedure, introduced in 2022 for less complex cases, accounted for a meaningful share of its 83 decisions last year.
Is my company exempt from the Records of Processing Activities requirement?
Only if you have fewer than 250 employees and your processing is occasional, doesn't include special-category data, and isn't likely to risk people's rights (Art. 30(5)). Regular processing, a CRM, an HR system, ongoing marketing, takes most SMEs out of this exemption regardless of headcount.
How does CNIL enforcement in France compare to other EU authorities?
CNIL issued 83 sanctions and €487M in fines in 2025, on 323 inspections and a record 20,150 complaints. Its simplified procedure, in place since 2022, lets it move faster on straightforward cases. That's part of why smaller organizations now appear more often in its sanctions list, not just large groups.
How does GDPR relate to the EU AI Act?
They regulate different things that frequently overlap. GDPR governs personal data. The AI Act governs AI systems. If your AI tools touch personal data, you likely need to satisfy both. See our GDPR × AI Act guide .
Is Themio's GDPR tool available now?
Not yet. It launches this fall. Join the priority waitlist now for 10 free audit credits at launch and early access ahead of general availability.

Not sure where your GDPR gaps are?

Join the priority waitlist for early access and 10 free audit credits at launch.