Maurice Müller
Senior Content Manager
Maurice Müller is a journalist and content strategist with experience across print and digital media. At Formalize, he translates complex compliance and regulatory topics into clear, practical content for compliance, risk, and security professionals across Europe.
Key takeaways:
GDPR compliance covers far more than privacy notices and cookie banners: lawful processing, data subject rights, records, DPIAs, security, suppliers, and breach handling.
It applies to organizations in the EU and to organizations elsewhere that offer goods or services to people in the EU or monitor their behavior. Size alone doesn't exempt anyone.
The controller is accountable for compliance and for demonstrating it. A data protection officer advises and monitors, but doesn't carry that accountability personally.
Fines can reach €20 million or 4% of worldwide annual turnover, whichever is higher, but authorities set them case by case and have other tools, from reprimands to processing bans.
Change is coming, but most of it isn't law yet. The 72-hour breach deadline still applies, even though the Digital Omnibus proposes 96 hours.
Ask a company whether it's GDPR compliant, and the answer is usually yes. Ask it to show why a particular supplier has access to customer data, which legal basis covers last quarter's marketing campaign, or when its last data protection impact assessment (DPIA) was reviewed, and the answer can take weeks.
That second set of questions is the one that counts. The GDPR's accountability principle requires controllers to comply with its rules and to be able to demonstrate that they do. In practice, that turns the regulation from a legal text you read once into a set of processes you run every day.
What is GDPR compliance?
GDPR compliance means meeting the obligations of Regulation (EU) 2016/679 that apply to how your organization processes personal data, and keeping the evidence to show it. The regulation has applied in the EU since 25 May 2018, and also applies in Iceland, Liechtenstein, and Norway as part of the European Economic Area.
What that involves depends on what you do with personal data, but most programs cover the same ground: a legal basis for each processing activity, clear information for the people concerned, processes for their rights, a record of processing activities (RoPA), risk assessments, security measures, supplier oversight, and a way to handle breaches. It touches people, processes, technology, and documentation, which is why it rarely sits with one team alone.
Two roles shape everything else. A controller decides why and how personal data is processed. A processor processes personal data on a controller's behalf, such as a payroll provider or a cloud service. An organization may act as a controller for some activities and as a processor for others. See how Formalize's GDPR compliance software helps teams manage records, responsibilities, and evidence.
Who needs to comply with the GDPR?
The GDPR applies more widely than many organizations assume. Its territorial scope reaches well beyond the EU, and only a few activities fall outside it entirely:
Situation | Does the GDPR apply? | What to know |
|---|---|---|
Organization established in the EU that processes personal data | Yes | This applies wherever the processing itself takes place, including on servers outside the EU. |
Organization outside the EU offering goods or services to people in the EU | Yes | This applies whether the offer is paid or free. They generally have to appoint a representative in the EU, with limited exceptions. |
Organization outside the EU monitoring the behavior of people in the EU | Yes | This covers online tracking and profiling, for example. |
Processor acting on a controller's behalf | Yes | Processors have their own direct obligations, including security and record-keeping. |
Small or medium-sized enterprise | Yes | Some duties are lighter, such as the records exemption for organizations with fewer than 250 employees, but that exemption has important exceptions. |
Individual acting in a purely personal or household capacity | No | The household exemption covers private activities, not business ones. |
Company size doesn't decide whether the GDPR applies. What varies is which specific obligations apply, and that depends on the processing and its risk. A company whose core activities involve regular and systematic monitoring of people on a large scale, for example, must appoint a data protection officer and will usually need DPIAs. A small firm handling basic customer contact details usually doesn't.
GDPR compliance checklist: how to achieve and maintain compliance
Once you know the GDPR applies, the work comes down to ten steps, from mapping your data to reviewing the program over time:
1. Confirm whether and how the GDPR applies
Check your scope, identify where you act as controller and where as processor, and check whether you must appoint a data protection officer (DPO) or an EU representative.
2. Map the personal data you process
Identify which personal data you hold, where it comes from, which systems store it, who can access it, and where it goes, including transfers outside the EEA.
3. Create and maintain your record of processing activities (RoPA)
Article 30 requires a RoPA covering purposes, categories of data and people, recipients, transfers, retention periods, and security measures. Even where the small-company exemption applies, the RoPA is the backbone of everything else on this list.
4. Establish and document legal bases
Choose one of the six legal bases for each processing activity: consent, contract, legal obligation, vital interests, public task, or legitimate interests. Where you rely on legitimate interests, document the balancing test. Where you rely on consent, keep a record of it. For special categories of data, such as health data, you also need one of the conditions in Article 9.
5. Provide clear privacy information
Tell people what you do with their data, why, on which legal basis, and for how long, in language they can understand. That information is due when you collect the data, or, if you obtain it from someone else, within a month at the latest.
6. Build processes for data subject rights
People can ask to access, correct, delete, or port their data, restrict or object to processing, and challenge certain automated decisions. You have one month to respond, which can be extended by two further months for complex requests, so requests need an owner, a verification step, and a way to track the deadline.
7. Conduct DPIAs where required
A DPIA is mandatory when processing is likely to result in a high risk to individuals, such as extensive profiling with significant effects on people, or large-scale processing of sensitive data. Our guide to the data protection impact assessment (DPIA) covers when and how to run one.
8. Manage processors and third-party suppliers
Put Article 28 agreements in place, check that suppliers can meet your security requirements, approve and keep track of their sub-processors, and make sure any transfers outside the EEA rest on a valid mechanism. A structured approach to third-party management keeps this from falling apart as the supplier list grows.
9. Implement appropriate security and breach processes
Apply security measures that match the risk, and prepare for breaches before they happen. A personal data breach must be reported to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it's unlikely to result in a risk to individuals, and people must be told directly if the risk to them is high. Every breach, reported or not, must be documented in an internal log. Connecting breaches to your wider risk management shows where controls need to improve.
10. Train employees and review continuously
Train the people who handle personal data, and review the program regularly. New systems, new suppliers, and new uses of data, such as AI, are the moments when records and assessments most often fall out of date.
Turn the checklist into a working program
Bring your current RoPA, however scattered it is today. We'll show you how these ten steps look when they run as workflows, with owners and evidence attached.
What are the 7 principles of the GDPR?
Article 5 sets out seven principles that everything else builds on. The third column is where compliance becomes practical: it's what you should be able to show if someone asks.
Principle | What it means | What you should be able to show |
|---|---|---|
Lawfulness, fairness, and transparency | Process data on a valid legal basis, in ways people would reasonably expect, and tell them about it | Documented legal bases and clear privacy notices |
Purpose limitation | Collect data for specified purposes, and don't reuse it for incompatible ones | Purposes recorded per activity, and compatibility checks for new uses |
Data minimization | Collect only what the purpose actually requires | A justification for the data fields you collect |
Accuracy | Keep data correct and up to date | Processes for correcting and updating records |
Storage limitation | Keep data only as long as necessary | A retention schedule, and evidence that deletion happens |
Integrity and confidentiality | Protect data with appropriate security | Access controls, security measures, and incident records |
Accountability | Take responsibility for all of the above, and be able to demonstrate it | All of the above, kept current |
Who is responsible for ensuring GDPR compliance?
Two things are easy to mix up here: accountability and operational responsibility.
Accountability sits with the controller. The organization that decides why and how data is processed is responsible for complying with the principles and for demonstrating it. In practice, that means senior management has to make sure the right structures, resources, and responsibilities exist.
Processors have obligations of their own. They must work under a contract with the controller that meets Article 28, keep appropriate security, maintain their own records, and tell the controller about breaches without undue delay.
A DPO advises and monitors. The DPO informs the organization about its obligations, monitors compliance, advises on DPIAs, and acts as the contact point for the supervisory authority. Appointing one is mandatory in certain cases, such as for public authorities or for organizations whose core activities involve large-scale monitoring. But the DPO doesn't carry the organization's accountability personally, and shouldn't be set up as if they did.
Operational work is spread across the business. Legal and privacy teams interpret the rules, IT and security protect the systems, HR handles employee data, procurement manages suppliers, and marketing documents campaign purposes, legal bases, and consent where required. GDPR compliance works when each of these teams knows which part it owns.
The GDPR and AI: what are the compliance requirements?
Using AI doesn't suspend the GDPR. Whenever an AI system processes personal data, whether in training, in the prompts people type, or in the outputs it produces, the regulation applies in full.
A few requirements matter most:
A legal basis for each phase: Developing a model and using it are separate processing activities. The European Data Protection Board's Opinion 28/2024 confirms that legitimate interests can be a valid basis, but only after a documented three-step test, and that a model trained on personal data isn't automatically anonymous.
Purpose limitation and data minimization: Data collected for customer service doesn't automatically become training data for a new model.
Transparency: People need to know when and how AI processes their data.
DPIAs: New technologies processing personal data at scale often meet the high-risk threshold.
Automated decisions: Article 22 restricts decisions based solely on automated processing that have legal or similarly significant effects on people. Where such decisions are allowed, people have the right to human intervention and to contest the outcome.
AI vendors: An external AI provider often acts as a processor, which brings Article 28 contracts into play, and frequently international transfers too.
The EU AI Act adds its own requirements on top, rather than replacing any of these. Following the Digital Omnibus on AI, its high-risk obligations apply from 2 December 2027 for stand-alone systems and from 2 August 2028 for AI embedded in regulated products. Our AI Act page covers how the two fit together.
What are the penalties for GDPR non-compliance?
Fines get the headlines, but supervisory authorities have a wider toolkit. They can issue warnings and reprimands, order an organization to bring its processing into line, limit processing temporarily or permanently, and suspend data transfers outside the EEA. Individuals can also claim compensation for damage caused by an infringement.
When authorities do fine, Article 83 sets two maximum tiers:
Tier | Maximum fine | Typical infringements |
|---|---|---|
Lower tier | €10 million or 2% of total worldwide annual turnover, whichever is higher | Obligations such as records, security, DPIAs, and the role of the DPO |
Upper tier | €20 million or 4% of total worldwide annual turnover, whichever is higher | The core principles, legal bases, data subject rights, and international transfers |
These are ceilings, not starting points. Authorities decide case by case, looking at the nature, severity, and duration of the infringement, whether it was intentional or negligent, what the organization did to limit the damage, and how well it cooperated. A well-documented program doesn't rule out a fine, but the measures you've taken and how you cooperate are among the factors authorities weigh.
What's changing: the GDPR in 2026 and 2027
The core of the GDPR hasn't changed since 2018, but three developments are worth tracking:
New cross-border enforcement rules, from 2 April 2027: Regulation (EU) 2025/2518 harmonizes how authorities handle cross-border cases, with deadlines for investigations and clearer procedural rights for the organizations involved. It doesn't change what the GDPR requires, but it's meant to make cross-border enforcement faster.
The Digital Omnibus, still a proposal. Published by the European Commission in November 2025, it would narrow the definition of personal data, extend the breach deadline to 96 hours for high-risk breaches, introduce a single entry point for incident reporting, and clarify legitimate interests for AI. As of September 2026, it's still in first reading: the European Parliament's committees haven't voted on it, and the Council hasn't agreed its negotiating position. Until it's adopted, the current rules apply.
Transfers to the US. The EU-US Data Privacy Framework remains valid after the EU General Court upheld it in September 2025, but an appeal is pending at the Court of Justice. Pressure has grown since a US Supreme Court ruling in June 2026 on the independence of the Federal Trade Commission, the agency that enforces the framework's principles, after which the privacy organization noyb called on the Commission to withdraw it. Organizations relying on it should check that each recipient is actively certified and that its certification covers the relevant data, and know what their fallback would be.
GDPR compliance software: what it is and how to choose
GDPR compliance software helps organizations run the recurring parts of a privacy program in one place: the RoPA, DPIAs, data subject requests, supplier assessments, breach logs, and the documentation that ties them together. It doesn't make an organization compliant on its own. The decisions still belong to people, but the software makes it far easier to keep those decisions current and to show them when asked.
When comparing solutions, a few questions are more useful than a feature list:
Does it cover your actual processes, from the RoPA to breach handling, or only one piece?
Does it handle recurring work, such as review reminders, request deadlines, and supplier reassessments?
Can people outside the privacy team use it, including HR, IT, and procurement?
Can it produce evidence on request, with an audit trail of who decided what and when?
Does it work alongside your other frameworks, such as ISO 27001 or NIS2, if you manage them too?
There's no single best GDPR compliance software. The right choice depends on how many processing activities you run, how many teams are involved, and what else you need to manage. For the broader category, see our guide to compliance management software.
How Formalize supports GDPR compliance
Formalize is built for the part of GDPR compliance that never finishes: keeping the RoPA, requests, and suppliers current, and keeping the evidence together.
A RoPA with guided workflows mapped to Article 30, connected to your suppliers and sub-processors, and exportable as PDF or Excel.
Data subject requests tracked from intake to closure, with secure data handover and deletion after a set period.
Configurable supplier audits and DPIA and transfer impact assessment (TIA) workflows.
Risk and incident management, including personal data breaches, alongside frameworks such as ISO 27001 and NIS2 in the same system.
More than 8,000 organizations use Formalize's products. See pricing for the available plans.