The GDPR has been in force since 2018 — and yet many companies still haven't fully implemented it. That's rarely a question of willingness; it's usually a question of clarity: where do I start? What is actually necessary? Here's what you need to know.
Eight steps to GDPR compliance
- Status assessment. What data do you process? For what purposes? Which systems, service providers, and processes are involved? Without this overview, everything else stays superficial.
- Records of Processing Activities (RoPA). The RoPA under Art. 30 GDPR is the mandatory foundation. It documents all key processing activities and is the basis for every further measure.
- Clarifying legal bases. Every processing activity needs a legal basis. Contract, legal obligation, legitimate interest, or consent — which applies where?
- DPAs with service providers. Every processor needs a written Data Processing Agreement. Cloud, email, HR software, tax advisor — the list is usually longer than expected.
- Technical and Organizational Measures (TOMs). Passwords, encryption, access authorizations, backups — a TOM document records how you protect data.
- Website and privacy notice. A current privacy notice, correct cookie consent, and GDPR-compliant use of external services — often the most visible part of GDPR compliance.
- Training employees. Inductions, confidentiality undertakings, awareness measures — your employees are your most important data protection tool.
- Establishing processes. Data subject requests, data breach notification, DPIAs — recurring data protection tasks need clear, documented procedures.
Important: proportionality
The GDPR applies to every company — but not to the same extent for every company. A trade business with 5 employees doesn't need an ISO 27001 certificate. What it needs is a level of data protection that is proportionate to its risk and demonstrable.
In our consulting practice we regularly see two extremes: companies that have done nothing at all, and companies that have buried themselves in bureaucracy they don't actually need. We help you find the right middle ground.
Frequently asked questions about GDPR implementation
How long does a full GDPR implementation take?
This depends heavily on your starting point. For a typical SME with manageable processing activities, we plan for 4–12 weeks for the initial implementation; after that, data protection is an ongoing process.
What happens if we haven't done anything yet?
Then you should get started — as soon as possible. Supervisory authorities are increasingly reviewing SMEs too. With cooperative behavior and demonstrable effort, fines are considerably lower than in cases of neglect.
Do we need a Data Protection Officer?
Mandatory from 20 people involved in automated processing. Recommendation: often worthwhile earlier, because the DPO ensures ongoing compliance and serves as the point of contact for authorities and data subjects.
What does GDPR compliance cost?
For a small company, a solid basic structure with an external DPO is often achievable for less than €200 per month. What matters is what is actually required — not what is theoretically possible.