Frequently Asked Questions
What does Themio do for you?
You get a compliance score and a ranked list of what to fix, each one backed by the exact clause it's based on rather than a vague suggestion. Upload your privacy policy, data processing agreements, or internal procedures, and Themio checks them against GDPR's actual text. You walk away with a PDF report you can hand to an auditor, a dashboard that tracks your score over time, and a record of every check you've run.
Does GDPR apply to my small business if I'm not based in the EU?
Yes, if you offer goods or services to people in the EU or monitor their behavior (Art. 3). Your company's location doesn't matter. What matters is whose data you process.
Do I need a Data Protection Officer?
Only if you're a public authority, your core activity involves large-scale systematic monitoring, or you process special-category data like health or biometric data at scale (Art. 37). Most small and mid-sized businesses don't meet these thresholds. Check against your actual processing rather than assuming.
What happens if my SME isn't GDPR compliant?
Fines can reach €20M or 4% of global annual turnover, whichever is higher (Art. 83). 2025 enforcement shows real reach into smaller organizations: CNIL's simplified sanction procedure, introduced in 2022 for less complex cases, accounted for a meaningful share of its 83 decisions last year.
Is my company exempt from the Records of Processing Activities requirement?
Only if you have fewer than 250 employees and your processing is occasional, doesn't include special-category data, and isn't likely to risk people's rights (Art. 30(5)). Regular processing, a CRM, an HR system, ongoing marketing, takes most SMEs out of this exemption regardless of headcount.
How does CNIL enforcement in France compare to other EU authorities?
CNIL issued 83 sanctions and €487M in fines in 2025, on 323 inspections and a record 20,150 complaints. Its simplified procedure, in place since 2022, lets it move faster on straightforward cases. That's part of why smaller organizations now appear more often in its sanctions list, not just large groups.
How does GDPR relate to the EU AI Act?
They regulate different things that frequently overlap. GDPR governs personal data. The AI Act governs AI systems. If your AI tools touch personal data, you likely need to satisfy both. See our
GDPR × AI Act guide
.
Is Themio's GDPR tool available now?
Not yet. It launches this fall. Join the priority waitlist now for 10 free audit credits at launch and early access ahead of general availability.