Last updated: September 18, 2026
GDPR compliance means having a lawful basis for all types of personal data you process, honoring data subject rights, reporting breaches within 72 hours, appointing a DPO where required, and documenting how data moves through your business, backed by real processes, not only a policy page. It applies if your business handles personal data from anyone in the EU, and getting it wrong is expensive. This Secure Privacy GDPR compliance guide walks through what that actually requires, in plain language, so you can check your own setup against real obligations rather than playing a guessing game.
Does GDPR Apply to Your Business?
GDPR applies to your business if you process the personal data of anyone in the EU, irrespective of where the company is based. Your location is irrelevant. What matters is whose data is being processed. If you have EU customers, EU website visitors, or EU employees, GDPR's requirements apply to you already, not at some indefinite point in the future.
You must comply regardless of whether the business is a five-person startup or a global enterprise. GDPR doesn't exempt small businesses from its core obligations, though some administrative requirements scale down for smaller companies. For the fuller picture of what GDPR is and why it exists, see our complete guide to GDPR.
What GDPR Actually Requires You to Do
GDPR comes down to eight core obligations. You need a real answer for each one, not just a polished and compliant-sounding policy document.
You must have a lawful basis for every kind of data processed. Consent is a plausible reason for collecting data, but not the only one. A contract, a legal obligation, or a legitimate business interest can also justify processing in certain cases. Each processing activity should have its basis documented, because "we're a business, we need data" isn't a sufficient lawful basis.
You must honor data subject rights. Persons whose data is held can ask to see it, correct it, delete it, or get a copy in a portable format. They can also object to certain kinds of processing and ask not to be subject to automated decisions that significantly impact them. A real process for handling these requests is required, definitely not just an email address that gets queued up for ages.
You must notify authorities of a data breach within 72 hours. If personal data is exposed, lost, or accessed without authorization, the business is required to report it to its supervisory authority within 72 hours of becoming aware of it, and to notify affected individuals without undue delay if the breach poses any real risk to them. Our guide to GDPR breach response covers what should be prepared ahead of that 72-hour clock.
You must appoint a Data Protection Officer after certain thresholds. Public authorities, businesses that monitor people at scale as a core activity, and businesses that process sensitive data at scale must have a dedicated DPO. This requirement does not depend on company headcount. A ten-person company running large-scale behavioral tracking needs one; a thousand-person company that doesn't meet any of the three triggers doesn't. Even where one isn't required, someone in the organization should typically own compliance. See our full guide to the DPO requirement for how to decide whether you need one and what the role actually involves.
You must run a Data Protection Impact Assessment before starting high-risk processing. A DPIA is required every time a new activity is likely to pose an actual risk to data subject rights, e.g.: large-scale profiling or processing sensitive categories of data. It should tag the risk, weigh it against its purpose, and document what has been put into practice to mitigate it, before any processing starts.
You must keep records of processing activities. You need documentation showing what personal data you collect, the reasons for collecting it, and the parties you share it with. Regulators may ask to see these records, and failing to maintain them is a compliance failure in its own right, regardless of any other issues they may uncover.
You must build data protection into core systems, not bolt it on as an afterthought. Think default settings that protect privacy, data minimization (collecting no more than is truly needed), and security measures fitted to the risk exposed data threatens.
You must have a legal safeguard before sending EU personal data outside the EU/EEA. Exporting data to a country the European Commission hasn't recognized as offering adequate protection demands a legal mechanism; most commonly Standard Contractual Clauses (SCCs) built into the vendor contract or reliance on an adequacy decision where one exists. The EU-US Data Privacy Framework presently provides that adequacy route for certified US companies, but it remains under active legal challenge before the EU's highest court, so SCCs are the sturdier default for any US vendor relationship you're not prepared to rapidly modify.
Your GDPR Compliance Checklist
Work through these steps in sequence. Each should be backed by something concrete that can be identified directly by an auditor, rather than rationalized post-hoc.
- Map your data. Identify what personal data you collect, where you store, and who accesses it.
- Identify your lawful basis for every type of processing you practice.
- Update your privacy policy to disclose what you collect, why, and who you share it with, in layman's terms.
- Create a data subject request process with an evident intake method and a specific response timeline.
- Write a breach response plan so you're not improvising during an actual incident.
- Determine whether you need a DPO, and if you do, appoint someone with genuine authority, don't just plaster the title on an intern.
- Run a DPIA before any high-risk processing, such as large-scale profiling or sensitive data.
- Record your processing activities in a format you can hand to a regulator upon request.
- Review your vendor contracts to confirm any processor handling data on your behalf is also compliant, including SCCs for any transfer outside the EU/EEA.
- Trace the meanderings of your data, including transfers to any US vendor relying on the EU-US Data Privacy Framework, and verify that SCCs are available as a fallback.
- Train your team on what GDPR actually requires of them day to day.
- Plan a review schedule so your compliance program doesn't gradually become outdated as your business grows.
GDPR and Cookie Consent
Cookies aren't directly regulated by GDPR. That's the role of the ePrivacy Directive, which requires opt-in consent before most non-essential cookies can be placed at all. But the moment a cookie ties to an identifiable person, such as a unique ID used for analytics or ad targeting, GDPR determines how that consent must operate.
That means the same lawful-basis and consent standards from earlier in this guide apply directly to your cookie banner. Consent must be freely given, specific, informed, and just as simple to withdraw as it was to opt into. A banner with an obvious "Accept All" button and no equally visible reject option doesn't meet that bar, and it's one of the most common GDPR compliance gaps regulators cite. Pre-selected consent boxes, cookie walls that prevent access until someone agrees, and broad category descriptions such as "improve your experience" instead of stating their true purpose all run into the same problem.
You also need to keep a record of what someone consented to and when, since "we assume they agreed" isn't a defensible answer during an audit or a data subject request. A compliant implementation records consent, applies it before non-essential cookies are activated rather than afterward, and allows people to reverse their choice just as easily as they made it. See our deeper look at cookie compliance for how this plays out in practice.
Common GDPR Mistakes to Avoid
Most GDPR issues aren't dramatic events. They're small gaps that pile up until an audit or a complaint exposes them.
A privacy policy shouldn't be treated as a document you write once then set and forget forever (unless you have a dedicated CMP provider like us staying on top of things in the back end). It should reflect what's actually being done today, not what was true when it was first written. When your data practices change, your policy needs to change with them.
You should not assume a plugin or vendor tool makes you compliant automatically. Any processor handling data on your behalf still needs a contract that clearly defines its responsibilities, and you remain accountable if that processor fails to meet them.
You should not wait for a complaint before testing your breach response plan. A plan that only exists on paper often breaks down when it is actually needed. Run through it at least once a year so your team knows what to do when it counts.
Don't assume a US vendor is automatically suitable simply because its website describes itself as "GDPR compliant." Check whether the actual data flow to that vendor is covered by SCCs, an adequacy decision, or neither, because that claim on a vendor's marketing page isn't a legal safeguard by itself.
What Happens If You Don't Comply
GDPR penalties run on two tiers. Less serious violations, such as inadequate record-keeping, can result in fines of up to €10 million or 2% of global annual turnover, whichever is higher. Serious violations, like ignoring data subject rights or processing without a lawful basis, can draw fines up to €20 million or 4% of global annual turnover, whichever is higher.
Regulators can also require an organization to stop processing data altogether, which may create a greater operational disruption than the financial penalty itself. See our full breakdown of GDPR fines and penalties for the biggest fines on record and what actually causes most of them.
GDPR vs. Other Privacy Laws
GDPR compliance doesn't automatically satisfy other privacy laws, even when they appear similar at first glance. The California Consumer Privacy Act (CCPA) and its successor rules overlap in several areas, including giving individuals control over their personal data. The same is true for Brazil's LGPD, which was explicitly modeled on GDPR but isn't identical to it. If your business operates in multiple jurisdictions, start with one centralized data inventory and apply each law's particular requirements to it, instead of maintaining separate compliance programs that can gradually fall out of alignment. See our comparison of CCPA and GDPR for where the two actually diverge.
Who Actually Enforces GDPR
Each EU member state has its own data protection authority (DPA), such as France's CNIL or Ireland's Data Protection Commission, and any of them can investigate a complaint or open its own inquiry. If your business operates across multiple EU countries, GDPR's one-stop-shop mechanism designates a single lead supervisory authority, usually the DPA where your main EU establishment is based, to coordinate the investigation with the other affected countries' authorities rather than making you answer to all of them separately.
That process is changing. A new EU regulation, (EU) 2025/2518, entered into force on January 1, 2026, establishing more consistent procedures for cross-border complaints. It sets the same admissibility rules no matter which country a complaint is filed in, and it introduces binding investigation deadlines, 15 months as a baseline, with a possible 12-month extension for complex cases, to stop investigations from dragging on indefinitely. These rules apply to investigations and complaints opened from April 2, 2027 onward; matters already underway remain subject to the existing procedure.
FAQ
Do small businesses need to comply with GDPR?
Yes. GDPR applies based on whose data you process, not how big your business is. Some administrative requirements scale with size, but the core obligations don't disappear because you're small.
How long does GDPR compliance take to implement?
It depends on how much personal data you handle and how mature your current processes are. A basic compliance foundation, lawful basis documentation, a rights-request process, and a breach plan, can often be built in a few weeks. Full data mapping and vendor review usually take longer.
Do I need a lawyer to become GDPR compliant?
Not necessarily, but complex situations, like international data transfers or industry-specific processing, benefit from legal review. Most of the core checklist can be handled internally with the right documentation.
What's the difference between a data controller and a data processor?
A controller decides why and how personal data is processed. A processor handles data on a controller's behalf, under instruction, like a cloud hosting provider or an email marketing tool. Your obligations differ depending on which role you're in for a given activity.
Does GDPR's Data Protection Officer requirement depend on company size?
No. It depends on what you do with data, not how many people you employ. A small company doing large-scale behavioral monitoring or processing sensitive data at scale must appoint a DPO; a much larger company that doesn't meet those triggers doesn't have to.
Secure Privacy helps businesses handle the cookie consent banner and data-subject-request side of GDPR compliance directly, logging and enforcing consent the way this guide describes, without building that infrastructure from scratch.



