GDPR compliance that holds under regulator scrutiny.
Data protection governance for any organisation handling EU personal data — at the size, complexity, and budget of an SMB.
Overview
Seven principles, six lawful bases, eight data-subject rights.
GDPR — Regulation (EU) 2016/679 — is built on seven core principles governing every aspect of how personal data must be handled. These are not aspirational; they are legal requirements, and supervisory authorities (the CNIL in France, the BfDI in Germany, the AP in the Netherlands, the DPC in Ireland, the Garante in Italy, the AEPD in Spain) assess compliance against them directly.
Article 3 gives GDPR extraterritorial reach: it applies to any organisation that processes personal data of EU residents in connection with offering goods or services to them, or monitoring their behaviour within the EU — regardless of where the organisation is established. A US, UK, or Australian company with EU customers or visitors is subject to GDPR.
AI systems processing personal data fall under both GDPR and the EU AI Act — including the EDPB's Opinion 28/2024 on AI models and personal data. The Article 35 DPIA process integrates cleanly with the AI Act's Article 27 Fundamental Rights Impact Assessment. Our AI Governance & Security service handles the GDPR × AI Act overlap, with ISO/IEC 42001 readiness built in.
Who GDPR applies to
Effectively: anyone processing EU residents' personal data. The signals below tend to come up first.
Any business with EU customers or website visitors
Sales to EU residents, EU-targeted marketing, or behavioural tracking of EU users — extraterritorial reach under Article 3.
Employers in the EU
HR data, payroll, recruitment, expense management, performance reviews — all GDPR-covered processing.
B2B services touching personal data
CRM, email marketing, customer support, analytics — even B2B businesses process named individuals at supplier and customer organisations.
Processors of personal data on behalf of others
SaaS providers, agencies, payroll bureaus, IT outsourcers — Article 28 obligations apply, and Data Processing Agreements are mandatory.
The principles
Seven principles every processing activity must respect.
- 01Art. 5(1)(a)
Lawfulness, fairness & transparency
Processing must have a lawful basis, be fair to data subjects, and be transparent about how their data is used.
- 02Art. 5(1)(b)
Purpose limitation
Data collected for one purpose cannot be used for a different, incompatible purpose without a new lawful basis.
- 03Art. 5(1)(c)
Data minimisation
Only collect personal data that is adequate, relevant, and limited to what is necessary for the stated purpose.
- 04Art. 5(1)(d)
Accuracy
Personal data must be accurate and kept up to date. Inaccurate data must be erased or corrected without delay.
- 05Art. 5(1)(e)
Storage limitation
Personal data must not be kept longer than necessary. Documented retention schedules are mandatory.
- 06Art. 5(1)(f)
Integrity & confidentiality
Data must be protected against unauthorised access, loss, or destruction using appropriate technical and organisational measures (Article 32).
- 07Art. 5(2)
Accountability
Organisations must be able to demonstrate compliance — not just claim it. Documentation, policies, ROPA, and records are the evidence.
Penalties & consequences
The headline numbers — and what actually triggers fines.
The headline maximum is €20 million or 4% of total worldwide annual turnover — whichever is higher — for the most serious violations (lawful basis, principles, data subject rights, international transfers). Lesser violations cap at €10 million or 2%. Failure to designate a DPO when required is itself a Tier 1 violation, independent of any breach.
For SMBs the principles that drive the most enforcement are purpose limitation (using data beyond disclosed purposes), data minimisation (collecting more than needed), and storage limitation (retaining too long). The rights that drive the most complaints are access (Subject Access Requests) and erasure (right to be forgotten). And the lawful basis most challenged by authorities is legitimate interests.
Tier 1 max fine
€20M / 4%
whichever is higher, of total worldwide annual turnover.
Tier 2 max fine
€10M / 2%
whichever is higher — for procedural and DPO-designation failures.
Breach notification
72 hours
from awareness, to your supervisory authority's portal — CNIL in France, BfDI in Germany, AP in the Netherlands, DPC in Ireland, etc.
Our approach
A six-phase GDPR compliance roadmap.
What we deliver
- GDPR readiness assessment — gap analysis against the seven principles and core articles
- Article 30 ROPA build — complete inventory of processing activities, lawful bases, data categories, retention, recipients
- Privacy notices, consent mechanisms, and data subject rights procedures (8 rights with documented timelines)
- DPIA process for high-risk processing under Article 35, with templates and review cadence
- Breach notification process — 72-hour internal escalation, CNIL/ICO notification templates, breach register
- Data Processing Agreements with third-party processors and sub-processors
- Documented retention schedule applied across all data categories
- DPO as a Service where Article 37 designation is mandatory or strategically valuable
Typical timeline
GDPR engagements run on the maturity of your starting point.
4–8 weeks
Readiness sprint
Gap analysis, ROPA, top-priority policy and notice work, breach process — enough to defend an inspection or satisfy a customer audit.
3–6 months
Full compliance program
Comprehensive policy library, all 8 data subject rights workflows, DPIA process, processor contracts, training, and ongoing review cadence.
FAQ