What GDPR is and why it affects you
The General Data Protection Regulation (EU 2016/679) has been in force since May 2018 and applies to any company that processes personal data of EU citizens, regardless of size. If you charge for a service, have a website with forms, store client or employee data, or send newsletters, GDPR applies to you.
The question is not whether it applies to you, but whether you are complying. And the AEPD checks actively: in 2025 it imposed around 40 million euros in sanctions (299 resolutions), according to AEPD enforcement data.
The 7 principles you need to know
Article 5 of GDPR sets out the principles governing all data processing. You do not need to memorize them, but you do need to understand them:
- Lawfulness, loyalty and transparency: you must have a legal basis for processing data and communicate it to the user.
- Purpose limitation: you only collect data for the stated purpose; you cannot reuse it for anything else.
- Data minimisation: only strictly necessary data.
- Data accuracy: correct and up-to-date data.
- Storage limitation: you do not keep data forever; you define when to delete it.
- Integrity and confidentiality: appropriate technical security.
- Proactive accountability: you must demonstrate compliance. “I think I am doing it right” is not enough.
Documentation you need
There is no mandatory official format, but you do need to have the following in writing:
- Record of processing activities (RoPA): mandatory if you process data at a non-domestic scale. Must include what data you process, for what purpose, for how long, and with whom you share it.
- Privacy policy: accessible from your website. Must inform who you are, what data you collect, for what purpose, how long you keep it, and with whom you share it.
- Information clauses: the text you display when collecting data (e.g., in a form).
- Consent: if you process data based on consent, it must be freely given, specific, informed, and unambiguous.
- Data processor agreements: if you use third-party tools that process data on your behalf (a CRM, an email marketing service), you need a contract that obliges them to comply with GDPR.
Your concrete obligations
For an SME without a mandatory DPO, these are the immediate obligations:
- Handle data subject rights: access, rectification, erasure, restriction, objection, and portability. You have 30 days to respond.
- Notify data breaches: if there is a data breach that poses a risk to individuals’ rights, you must notify the AEPD within 72 hours and the affected individuals “without undue delay”.
- Assess whether you need a DPO: if you process data on a large scale, carry out profiling, or handle special categories (health, financial data), you do need one.
How to get started without spending weeks
You do not need a legal advisor to get started. These three steps cover 80% of what an SME needs:
- Data map: create a table with the data you collect, where you store it, what you use it for, and who has access.
- Review consent: remove emails from your list that do not have clear, documented opt-in.
- Contracts with third parties: if you use Mailchimp, HubSpot, or any SaaS that handles client data, make sure you have a signed DPA (Data Processing Agreement).
If you need help assessing your current situation, take a look at our free OSINT audit — it includes an analysis of how you handle personal data in your infrastructure and delivers a report with findings and recommendations in 72 hours.