All articles
DATA

GDPR compliance for businesses: a practical step-by-step guide

GDPR compliance goes beyond a privacy policy. Learn the concrete steps to keep your business compliant when processing personal data.

13 Jul 2026·8 min read·Productized Team

GDPR compliance means your organisation can demonstrably show it processes personal data lawfully: you have a legitimate purpose, you document it, you respect data subjects' rights, and you can prove all of this during an audit. Not as a one-time exercise — as a continuous business process.

Most companies fall into one of two traps: publishing a privacy policy and considering the job done, or launching a frantic GDPR project after receiving a letter from the data protection authority. Neither works. GDPR compliance is not a project — it is an operational discipline. And it is far less complex than most organisations assume, provided you follow the right sequence.

The GDPR in brief.

The General Data Protection Regulation applies to any organisation that processes personal data of individuals in the EU — including companies based outside the EU that offer goods or services to EU residents. It rests on six core principles that govern lawful processing.

PrincipleWhat it means in practice
Lawfulness, fairness and transparencyYou have a valid legal basis (consent, contract, legal obligation, legitimate interest, vital interest, or public task) and you are open about how you use data.
Purpose limitationYou collect data only for a specific, explicitly stated purpose. You cannot repurpose it without a new legal basis.
Data minimisationYou process no more personal data than strictly necessary for the stated purpose.
AccuracyYou keep data correct and update it when necessary.
Storage limitationYou do not keep data longer than necessary. You set and enforce retention periods.
Integrity and confidentialityYou protect data adequately against loss, theft, or unauthorised access.

Underpinning all six principles is accountability: you are responsible for compliance and you must be able to demonstrate it. Saying you comply is not enough — you need to prove it.

Building your Records of Processing Activities.

The Records of Processing Activities (RoPA) — called a verwerkingsregister in Dutch law — is the backbone of any GDPR compliance programme. It documents every processing activity in your organisation: what personal data you process, for what purpose, on what legal basis, who has access, and how long you retain it.

Organisations with 250 or more employees are legally required to maintain a RoPA. Smaller organisations that regularly process special category data — health data, national ID numbers, criminal records — must also maintain one. Even if you fall below these thresholds, a RoPA is the single most effective tool for identifying where your compliance risks actually sit.

For each processing activity, your RoPA should capture:

  1. Name and contact details of the controller (and any representative or Data Protection Officer).
  2. Purpose of processing — as specific as possible. Not 'marketing' but 'sending email newsletters to existing customers'.
  3. Categories of data subjects (customers, employees, suppliers, website visitors).
  4. Categories of personal data (name, email address, IP address, location data).
  5. Legal basis (consent, contract performance, legal obligation, legitimate interest).
  6. Recipients or categories of recipients — including processors such as software vendors and hosting providers.
  7. Third-country transfers outside the EEA and the safeguards applied.
  8. Retention period, or the criteria used to determine it.
  9. Technical and organisational security measures.

Do not start with a blank spreadsheet. First map your business processes: HR, finance, sales, marketing, customer service, IT. For each process, identify which personal data flows through it. The RoPA fills itself from there. A realistic timeline for a company of 50 to 150 employees: two to four weeks if approached systematically.

Data subject rights.

The GDPR gives individuals concrete rights over their personal data. As a controller, you are required to honour those rights and respond to requests within one month. In complex cases you may extend by two months, but you must notify the individual of the extension within the first month.

RightWhat the individual can request
Right of access (Art. 15)A copy of which personal data you hold, for what purpose, and for how long.
Right to rectification (Art. 16)Correction of inaccurate or incomplete personal data.
Right to erasure ('right to be forgotten', Art. 17)Deletion of personal data — not absolute; other legal grounds may override this right.
Right to restriction (Art. 18)Temporary suspension of processing, for example while accuracy is disputed.
Right to data portability (Art. 20)Transfer of data in a structured, commonly used format — applies only to processing based on consent or contract.
Right to object (Art. 21)Objection to processing based on legitimate interest or direct marketing. For direct marketing, you must always stop.

Honouring these rights requires two things: a process for receiving and routing requests (who in your organisation handles them?), and the technical ability to actually fulfil them (can you locate and delete all data about a specific person?). Many companies do not know which systems hold personal data. That is a data governance problem — one we cover in depth in our article on data governance.

Responding to an access request starts with knowing where all the data lives. Organisations without a data inventory cannot correctly answer an access request — no matter how well-written their privacy policy is.

Data Protection Impact Assessments.

A Data Protection Impact Assessment (DPIA) is a mandatory risk analysis that must be completed before starting any processing activity that is likely to result in high risks to individuals' rights and freedoms. The European Data Protection Board (EDPB) has published a list of processing types that always require a DPIA.

A DPIA is required when you carry out:

  • Systematic and extensive profiling based on automated processing (including AI systems that make decisions about individuals).
  • Large-scale processing of special category data (health, biometric, religious, racial or ethnic data).
  • Systematic monitoring of publicly accessible areas on a large scale (CCTV).
  • Processing of personal data of vulnerable individuals (children, patients).
  • Combined use of datasets in ways individuals would not reasonably expect.
  • New technologies that carry privacy risks.

For AI implementations, a DPIA is almost always relevant. Systems that analyse customer behaviour, monitor employees, or make automated decisions fall squarely within DPIA requirements. We have written a dedicated step-by-step guide to DPIAs for AI tools.

At minimum, a DPIA must include a systematic description of the processing, a necessity and proportionality assessment, and an evaluation of risks to data subjects including mitigating measures. If high risks remain after the DPIA, you must consult your supervisory authority before proceeding.

Fines and enforcement.

Under the GDPR, supervisory authorities can impose fines of up to €20 million or 4% of global annual turnover — whichever is higher. Maximum fines for mid-sized businesses are rare. What you more commonly see: corrective orders, binding instructions, or an incremental penalty following a complaint or incident.

What actually triggers enforcement? Often not complex violations. Dutch supervisory authority the Autoriteit Persoonsgegevens received more than 17,000 data breach notifications from Dutch organisations in 2024. Failing to report a breach on time is a violation. Retaining personal data beyond its retention period is a violation. An incomplete RoPA discovered during an investigation counts against you.

In 2024, the Dutch Data Protection Authority received more than 17,000 data breach notifications. The most common causes: misdirected emails, lost devices, and ransomware attacks.Autoriteit Persoonsgegevens, Annual Report 2024

A data breach must be reported to the supervisory authority within 72 hours of discovery — if it is likely to result in a risk to individuals' rights and freedoms. If the breach poses a high risk, you must also notify the affected individuals directly. The 72-hour window is strict. Organisations without an incident response procedure often miss it.

Where to start.

GDPR compliance is not all-or-nothing. Three concrete steps address the majority of your risk immediately:

  1. Build a Records of Processing Activities — even a limited version immediately shows you where you stand. Two weeks' work.
  2. Set retention periods for your most sensitive datasets — customer data, HR data, email correspondence. And put a breach notification procedure in place: who decides whether an incident must be reported, and how?
  3. Run a DPIA for every system that processes personal data at scale or makes automated decisions — including AI tools deployed in the last two years.

The most effective compliance programmes we support do not start with an external adviser producing a hundred-page report. They start with an internal mapping of data flows, ownership, and risks — work we do together with your team across two to four sessions. From there, you know exactly what to prioritise.

Do you have a specific system or project where you need to know whether a DPIA is required? Or do you want an honest assessment of your current setup? Describe your situation via our contact form — we respond within one business day.