GDPR: the checklist for leaders of smaller companies
An actionable checklist for bringing a smaller company into GDPR compliance, with the real obligations and the practical priorities.
The GDPR has been in force since 2018, but many smaller companies are still in the dark. Penalties are real – including for small organisations. Here are the essential points to check, ordered by priority.
High priority: the fundamentals
Appoint a GDPR lead
Not every company is required to appoint a DPO (Data Protection Officer), but you need at least an internal lead to steer the subject. In a smaller company, that is often the business leader themselves or the head of administration.
Keep a record of processing activities
This is the central document. It lists:
- each processing activity involving personal data (payroll, CRM, newsletter, CCTV…)
- the purpose of each activity
- the categories of data collected
- the retention periods
- the recipients of the data
The CNIL, the French data protection authority, provides a free record template on its website.
Check your lawful bases
Every processing activity must rest on a lawful basis: consent, performance of a contract, legal obligation, legitimate interest. Consent is not always required – but where it is, it must be freely given, informed and withdrawable.
Medium priority: securing and informing
Update your privacy notices
The people whose data you process (customers, employees, prospects) must be informed: what data, why, for how long, what rights. Check the notices on your website, your forms and your employment contracts.
Put in place a breach management procedure
In the event of a data breach, the company has 72 hours to notify the CNIL. So you need:
- a written procedure for detecting and escalating a breach
- a pre-filled notification template
- the contact details of the lead to alert
Secure access to the data
- Apply the principle of least privilege (each person only accesses the data their role requires)
- Put multi-factor authentication in place on critical applications
- Encrypt sensitive data at rest and in transit
Low priority but mandatory
Audit your processors
Any supplier that processes data on your behalf (hosting provider, SaaS vendor, accountant) must be bound by a contract that includes GDPR clauses. Check where the data is located – transfers outside the EU require additional safeguards.
Handle individuals’ rights
Data subjects can exercise their rights: access, rectification, erasure, portability. You need an identified contact address and a procedure for responding within the legal deadline of one month.
In short
GDPR compliance is not a one-off project but continuous hygiene. Start with the record of processing activities and the privacy notices, then structure the rest progressively. The risk is not only a financial penalty: it is also the trust of your customers and partners.