GDPR compliance is about more than adding a cookie banner or publishing a privacy policy. It means understanding what personal data your organization processes, having a valid reason for using it, respecting people’s rights, protecting their information, and keeping evidence of the steps you’ve taken.
This GDPR compliance guide breaks those requirements into practical steps, so you can see exactly what applies to your business and where to focus first.
What does GDPR mean?
GDPR stands for General Data Protection Regulation. It is the European Union’s main data protection law and has been in effect since May 25, 2018.
Its purpose is to give people greater control over their personal data and set consistent rules for organizations that collect, use, share, or otherwise process it.
Who does GDPR apply to?
The GDPR does not only apply to businesses based in the EU.
It can apply if your organization:
– monitors the behavior of people in the EU
– is established in the EU and processes personal data
– offers goods or services to people in the EU
That means businesses based in the US, UK, and elsewhere may still have GDPR obligations if they target or monitor people in the EU.
Business size doesn’t automatically exempt you either. Smaller businesses can still fall within the GDPR depending on how they process personal data.
What counts as personal data under the GDPR?
The GDPR defines personal data broadly as information relating to an identified or identifiable person.
That includes obvious identifiers such as:
- names
- email addresses
- phone numbers
- identification numbers
It can also include less obvious data, such as IP addresses, location data, cookie identifiers, and other online identifiers that can be linked to an individual.
Personal data is not limited to information that identifies someone on its own. Information can also fall within the GDPR when a person can be identified indirectly.
The principles behind GDPR compliance
Article 5 of the GDPR sets out seven principles that should guide how personal data is handled:
– Lawfulness, fairness, and transparency: use personal data lawfully and be clear about what you are doing with it.
– Purpose limitation: collect data for specific, legitimate purposes.
– Data minimization: collect only the information you actually need.
– Accuracy: keep personal data accurate and up to date where necessary.
– Storage limitation: do not retain identifiable personal data longer than necessary.
– Integrity and confidentiality: protect personal data with appropriate security.
– Accountability: take responsibility for compliance and be able to demonstrate it.
These principles sit behind almost every practical GDPR requirement. If you’re collecting more data than you need, keeping it indefinitely, or cannot explain why a particular tool receives it, that is a sign your setup may need attention.
How to comply with GDPR: 10 practical steps
The most effective GDPR compliance strategies start with understanding your data and building repeatable processes around how it is collected, used, protected, and documented.
1. Understand what personal data you process
Start by building a clear picture of the data moving through your organization.
Look at:
– How long you keep it
– What personal data you collect
– Where it comes from
– Why you use it
– Where it is stored
– Who can access it
– Which third parties receive it
– Where it is transferred
A GDPR data mapping exercise can help you understand how personal data moves across websites, apps, systems, vendors, and teams.
Depending on your organization and processing, you may also need to maintain a Record of Processing Activities (ROPA) under Article 30.
The goal is to understand what your business actually does with personal data, not what you assume your systems collect.
2. Choose the right lawful basis
You need a valid lawful basis for each processing activity.
The GDPR provides six:
consent
performance of a contract
compliance with a legal obligation
vital interests
public task
legitimate interests
For example, if someone orders a product, you may need their address to deliver it because the processing is necessary to perform your contract with them. You generally do not need to ask for GDPR consent simply to fulfill the order.
The right lawful basis depends on the purpose and circumstances of the processing, so identify it before collecting or using the data.
3. Be transparent about how you use personal data
People should be able to understand what happens to their information.
Your privacy notice should clearly explain relevant details such as:
- what personal data you collect
- why you process it
- your legal bases
- who receives it
- how long you keep it
- relevant international transfers
- people’s GDPR rights
- how they can contact you
Your privacy information also needs to reflect what your business actually does.
A generic privacy policy won’t help much if it doesn’t align with the tools, services, trackers, vendors, and processing activities you actually use.
See our GDPR privacy policy guide and template for more detail.
4. Manage consent properly when you rely on it
When consent is your lawful basis, the GDPR sets a high standard.
Consent needs to be freely given, specific, informed, and unambiguous. It should involve a genuine choice and clear affirmative action.
That means:
- no pre-ticked boxes
- clear and specific requests
- no unnecessary bundling with other terms
- withdrawing consent should be as easy as giving it
- evidence of consent should be kept
Consent may also be relevant when websites and apps use cookies and tracking technologies, alongside the ePrivacy rules.
Where prior consent is required, your setup should do more than simply display a banner. Relevant technologies should respond to the user’s choice, and those preferences should be respected.
For practical examples, see our guide to GDPR consent forms.
5. Make it easy for people to exercise their rights
The GDPR gives individuals several rights over their personal data, including the rights to:
be informed
access their data
correct inaccurate information
request erasure in certain circumstances
restrict processing
data portability
object to certain processing
protections around certain automated decisions and profiling
Your business needs a process to recognize, assess, and respond to these requests.
For example, if someone asks what personal data you hold about them, you need to be able to find that information across relevant systems and provide an appropriate response.
Read our guide to Data Subject Access Requests (DSARs) for practical steps.
6. Keep the right records
Accountability is a core part of GDPR compliance.
Depending on your organization and processing activities, your documentation may include:
- Records of Processing Activities
- records of consent
- lawful-basis assessments
- Data Protection Impact Assessments
- processor agreements
- retention policies
- security policies and procedures
For higher-risk processing, you may need to carry out a Data Protection Impact Assessment (DPIA) before going ahead.
See our guide to Data Protection Impact Assessments for more on when one may be required.
7. Manage processors and third-party providers
Most organizations rely on other companies to process personal data.
That can include:
- hosting providers
- CRMs
- analytics platforms
- payment services
- email tools
- cloud software
Where a provider acts as your processor, Article 28 requires the relationship to be governed by a contract containing specific data protection terms.
You should also understand what the provider does with the data, where processing takes place, which subprocessors are involved, and what safeguards are in place.
Our guide to Data Processing Agreements (DPAs) explains when you need one and what it should cover.
8. Protect personal data and prepare for breaches
The GDPR requires appropriate technical and organizational measures to protect personal data.
What is appropriate depends on the nature of the data, the risks involved, and how you process it, but measures can include:
access controls
encryption where appropriate
secure authentication
backups and recovery processes
staff training
regular security reviews
processes for detecting and responding to incidents
You also need a plan for personal data breaches.
Under Article 33, certain breaches must be reported to the relevant supervisory authority within 72 hours of becoming aware of them, where feasible. In some cases, affected individuals must also be informed.
9. Check international data transfers
If personal data moves outside the European Economic Area, additional GDPR requirements may apply.
Transfers may rely on mechanisms such as:
- an EU adequacy decision
- Standard Contractual Clauses
- Binding Corporate Rules
- another applicable GDPR transfer mechanism
Do not look only at where your own organization is based. Third-party services can also result in personal data being processed or accessed in other countries.
Your vendor review and data mapping should help you identify these transfers.
10. Review your GDPR setup as your business changes
GDPR compliance isn’t a one-time project.
Your business changes as you introduce new tools, launch new products, switch vendors, enter new markets, and find new ways to use existing data. Your compliance setup needs to change with it.
Review your documentation and processes when significant changes happen, including:
- privacy notices
- consent mechanisms
- processing records
- vendor relationships
- retention periods
- international transfers
- security measures
Regular reviews help keep your setup aligned with what your business is actually doing.
Quick GDPR compliance checklist
Use these questions as a starting point:
Do you know what personal data you process and where it goes?
Does each processing activity have an appropriate lawful basis?
Does your privacy information reflect what you actually do?
Are consent and user requests handled correctly?
Are your processors, records, security measures, and transfers documented?
Do you review your setup when your business changes?
The exact requirements will depend on your organization and processing activities, so treat this as a practical framework rather than a universal checklist.
What happens if you do not comply with GDPR?
GDPR enforcement isn’t limited to fines.
Supervisory authorities can issue warnings and reprimands, order organizations to change or stop particular processing, and impose administrative fines.
For certain infringements, fines can reach €20 million or 4% of total worldwide annual turnover from the preceding financial year, whichever is higher. Other infringements fall under a lower maximum tier.
But GDPR compliance isn’t just about avoiding penalties. A stronger goal is to build data practices you understand, can explain, and can maintain as your organization changes.
GDPR FAQs
Does GDPR apply outside the EU?
Yes. Organizations outside the EU can fall within the GDPR if, for example, they offer goods or services to people in the EU or monitor their behavior there.
Do small businesses have to comply with GDPR?
Potentially, yes. There is no general small-business exemption from the GDPR. Some individual obligations have limited exemptions, but business size alone does not determine whether the regulation applies.
Do I always need consent to process personal data?
No. Consent is one of six lawful bases under the GDPR. Depending on the processing, another basis such as contractual necessity, legal obligation, or legitimate interests may be appropriate.
Do I need a cookie banner for GDPR compliance?
Not every website needs the same cookie setup.
Whether consent is required depends on the technologies you use and the applicable GDPR and ePrivacy requirements. If your site uses non-essential cookies or similar trackers that require prior consent, you will generally need a way to collect and respect that choice before those technologies are activated.
How long can I keep personal data?
There is no single GDPR retention period for every type of personal data.
Under the storage-limitation principle, identifiable personal data should be retained only for as long as necessary for the purpose for which it was collected, while also taking into account other applicable legal requirements.
Make GDPR compliance easier to manage
GDPR compliance touches everything from the data you collect and the tools you use for consent and privacy notices to vendors and internal records.
Keeping those pieces aligned can become difficult as your business grows and your setup changes.
iubenda brings key privacy and consent tools together in one platform, helping you manage legal documents, cookie and consent choices, relevant records, and your wider privacy setup from one place. Explore iubenda’s GDPR solutions.
Add a comment