Skip to main content
Published on

GDPR: the checklist for leaders of smaller companies

An actionable checklist for bringing a smaller company into GDPR compliance, with the real obligations and the practical priorities.

The GDPR has been in force since 2018, but many smaller companies are still in the dark. Penalties are real – including for small organisations. Here are the essential points to check, ordered by priority.

High priority: the fundamentals

Appoint a GDPR lead

Not every company is required to appoint a DPO (Data Protection Officer), but you need at least an internal lead to steer the subject. In a smaller company, that is often the business leader themselves or the head of administration.

Keep a record of processing activities

This is the central document. It lists:

  • each processing activity involving personal data (payroll, CRM, newsletter, CCTV…)
  • the purpose of each activity
  • the categories of data collected
  • the retention periods
  • the recipients of the data

The CNIL, the French data protection authority, provides a free record template on its website.

Check your lawful bases

Every processing activity must rest on a lawful basis: consent, performance of a contract, legal obligation, legitimate interest. Consent is not always required – but where it is, it must be freely given, informed and withdrawable.

Medium priority: securing and informing

Update your privacy notices

The people whose data you process (customers, employees, prospects) must be informed: what data, why, for how long, what rights. Check the notices on your website, your forms and your employment contracts.

Put in place a breach management procedure

In the event of a data breach, the company has 72 hours to notify the CNIL. So you need:

  • a written procedure for detecting and escalating a breach
  • a pre-filled notification template
  • the contact details of the lead to alert

Secure access to the data

  • Apply the principle of least privilege (each person only accesses the data their role requires)
  • Put multi-factor authentication in place on critical applications
  • Encrypt sensitive data at rest and in transit

Low priority but mandatory

Audit your processors

Any supplier that processes data on your behalf (hosting provider, SaaS vendor, accountant) must be bound by a contract that includes GDPR clauses. Check where the data is located – transfers outside the EU require additional safeguards.

Handle individuals’ rights

Data subjects can exercise their rights: access, rectification, erasure, portability. You need an identified contact address and a procedure for responding within the legal deadline of one month.

In short

GDPR compliance is not a one-off project but continuous hygiene. Start with the record of processing activities and the privacy notices, then structure the rest progressively. The risk is not only a financial penalty: it is also the trust of your customers and partners.

Go further