top.legal
Legal Operations

GDPR Compliance: A Practical 9-Step Guide for Businesses

A practical guide to GDPR compliance: what the regulation requires, who has to comply, current fines and enforcement trends, and a 9-step checklist to get and stay compliant.

AB
Published April 27, 2025·Updated July 13, 2026
9 min read
More on this topic

A practical guide to GDPR compliance: what the regulation requires, who has to comply, current fines and enforcement trends, and a 9-step checklist to get and stay compliant.

The General Data Protection Regulation (GDPR) remains the benchmark for data protection law worldwide, and its reach extends to any organisation that handles the personal data of people in the EU — wherever that organisation is based. Since it took effect in 2018 the regulation has matured, and so has enforcement: fines are larger, investigations reach smaller companies, and new pressures such as AI profiling and cross-border transfers now sit at the centre of regulators' attention.

This guide explains what the GDPR actually requires, who has to comply, how enforcement has evolved, and a practical nine-step checklist you can use to get compliant and stay that way.

What Is the GDPR?

Six focus areas of GDPR enforcement: cross-border transfers, AI-driven profiling, third-party vendor risk, the EU–US Data Privacy Framework, evolving case law, and the EU AI Act

The GDPR is the EU regulation that harmonises data protection law across all member states, strengthens individuals' rights over their personal data, and defines how organisations must collect, store, use, and share that data. "Personal data" is broad — it covers anything that can identify a person, from a name or email address to an IP address, location data, or an online identifier.

Rather than a fixed list of boxes to tick, the GDPR sets out principles: personal data must be processed lawfully and transparently, collected for specified purposes, kept to the minimum needed, held accurately, retained no longer than necessary, and protected by appropriate security. Every processing activity has to rest on a valid legal basis — consent, a contract, a legal obligation, or a legitimate interest, among others.

Since enforcement began, regulators have sharpened their focus on the areas where the most personal data is at risk: cross-border data transfers, AI-driven profiling, and third-party vendor relationships now top the list of triggers. Newer developments — the EU–U.S. Data Privacy Framework, evolving case law, and the EU AI Act — have added further layers, so GDPR compliance today is less about a static checklist and more about embedding data protection into everyday operations.

Who Has to Comply?

Two categories of organisation bound by the GDPR: EU-based organisations, and non-EU organisations offering goods or services to or monitoring people in the EU

Whether you are a SaaS startup in Berlin or a US e-commerce platform selling into the EU, the GDPR most likely applies to you. Its extraterritorial reach covers:

  • EU-based organisations, regardless of where the data is actually processed.
  • Non-EU organisations that offer goods or services to individuals in the EU, or monitor their behaviour.

The practical threshold for enforcement has also come down. Regulators increasingly pursue small and mid-sized businesses and startups — not just large enterprises — with particular attention on sectors that process sensitive data at scale, such as health tech, HR tech, and marketing technology.

What the GDPR Requires

Six core GDPR obligations: privacy by design, data subject rights, the 72-hour breach rule, appointing a Data Protection Officer, vendor accountability, and records of processing

The GDPR translates its principles into concrete obligations for how organisations handle personal data.

  • Privacy by design and default. Data protection has to be built into products and processes from the outset, not bolted on afterwards.
  • Data subject rights. Individuals can request access, rectification, erasure, restriction, objection, and data portability — and you must be able to respond within the statutory time limits.
  • Breach notification. Qualifying data breaches must be reported to the supervisory authority within 72 hours, and in higher-risk cases the affected individuals must be told as well.
  • Data Protection Officer. Appointing a DPO is mandatory where your core activities involve large-scale monitoring or the processing of special-category data such as health or biometric information.
  • Vendor accountability. Contracts with processors must define responsibilities clearly. Where a supplier processes personal data on your behalf, a data processing agreement under Article 28 is required, and shared liability is enforced more tightly than it once was.
  • Records of processing. Even small businesses must keep accurate, up-to-date records of their data processing activities (a ROPA).

GDPR penalties have grown sharply since 2018. The regulation allows fines of up to €20 million or 4% of global annual turnover, whichever is higher, and cumulative fines across the EU now run into the billions of euros. The most common grounds for enforcement are consistent year to year:

  • Lack of transparency about how data is collected and used.
  • Failure to secure personal data adequately.
  • Unlawful international data transfers.
  • Mishandled or invalid consent.

The reputational cost often outweighs the fine itself. A breach or an enforcement notice erases customer trust quickly, and increasingly it can stall deals — enterprise buyers now routinely assess a vendor's data protection posture during procurement.

Nine Steps to Achieve GDPR Compliance

A nine-step GDPR compliance roadmap: understand the law, build governance, audit your data, close the gaps, appoint a DPO, fix transfers and vendors, update policies, train your people, and monitor and document

1. Understand the Law and Keep Up to Date

The GDPR is not the only rulebook you have to follow. Staying compliant means keeping an eye on adjacent and evolving regulation — the EU AI Act, the still-pending ePrivacy Regulation, and national data protection laws — as well as rulings from bodies such as the European Data Protection Board, which shape how the GDPR is enforced in practice.

2. Develop a Governance Plan

Compliance starts with structure. Assign clear responsibilities across legal, IT, and operations, set timelines and measurable KPIs, and secure leadership buy-in. This turns data protection into an ongoing business priority rather than a one-off project.

3. Conduct Data Audits and Privacy Impact Assessments

Use a structured framework such as ISO/IEC 27701 or the NIST Privacy Framework to map where your data lives, how it is processed, and who has access. Audits surface high-risk areas — especially those involving AI — and expose weak points in third-party vendor relationships, which remain a common source of breaches.

4. Analyse Gaps and Prioritise Remediation

Turn audit findings into action. Identify where you fall short — unclear consent mechanisms, outdated retention policies, undocumented processing — then rank fixes by severity, urgency, and business impact so effort goes where the risk is greatest.

5. Appoint or Review Your Data Protection Officer

A DPO is required where large-scale monitoring or special-category data processing is a core activity. A modern DPO should understand AI and international data flows and be embedded in business decisions rather than working in isolation.

6. Reassess Data Transfers and Vendor Contracts

International transfers remain under scrutiny. Where they apply, rely on standard contractual clauses or Binding Corporate Rules. Make sure vendor contracts define breach-reporting timelines, sub-processor restrictions, and termination rights, and review them regularly as the legal position shifts.

7. Update Privacy Notices and Internal Policies

Your privacy policy should be easy to find, explain clearly what data you collect and why, and stay current as your technology stack changes. Internally, make sure policies reflect remote-work practices, bring-your-own-device risks, and emerging technologies such as AI.

8. Train Employees Regularly

People are your first line of defence. Training should help staff recognise phishing and social engineering, respond correctly to access and deletion requests, and handle AI-generated records such as chatbot logs. Role-specific, practical training retains far better than a generic annual slideshow.

9. Implement Monitoring and Documentation Systems

Build the infrastructure that makes accountability provable: maintain a Record of Processing Activities, monitor data usage, and track every subject access request and breach incident. Privacy and contract compliance tools that integrate with your existing HR, CRM, and CMS systems turn documentation from a scramble into a routine.

How to Prioritise Your Compliance Strategy

You cannot fix everything at once, so sequence the work by risk and value. Score each gap against the questions below and tackle the high-risk, high-impact items first.

Prioritisation criterionQuestions to ask
Risk levelCould this lead to a breach, an investigation, or a fine? Are we processing sensitive or large volumes of data?
Business criticalityWill non-compliance damage customer trust, delay deals, or block market expansion (especially in the EU)?
Implementation effortWhat does fixing this take — time, cost, internal alignment? Can we realistically do it now?
ReusabilityCan the solution be reused across teams or tools — standardised vendor templates, reusable training modules, shared clause libraries?

Where contracts are involved — vendor DPAs, transfer clauses, retention terms — a contract management platform helps you enforce the same standards every time, keep an audit trail, and prove compliance on demand.

See how top.legal keeps data protection clauses, DPAs, and audit trails consistent across every contract.

Book a free demo

Frequently Asked Questions

Does the GDPR apply to companies outside the EU?

Yes. The GDPR applies to any organisation that offers goods or services to individuals in the EU or monitors their behaviour, regardless of where the organisation is established. A US or UK company with EU customers is generally in scope.

What is the maximum fine for a GDPR violation?

Fines can reach up to €20 million or 4% of global annual turnover, whichever is higher, for the most serious infringements. A lower tier of up to €10 million or 2% of turnover applies to less severe breaches, such as record-keeping or notification failures.

Do small businesses have to comply with the GDPR?

Yes. There is no general small-business exemption. Even small organisations must have a lawful basis for processing, honour data subject rights, and keep records of processing activities. Some obligations, such as appointing a Data Protection Officer, only apply above certain thresholds.

When is a Data Protection Officer mandatory?

A DPO is required when an organisation's core activities involve large-scale, regular monitoring of individuals, or large-scale processing of special-category data such as health, biometric, or criminal-record data. Public authorities must also appoint one.

How long do we have to report a data breach?

A qualifying personal data breach must be reported to the relevant supervisory authority within 72 hours of becoming aware of it. Where the breach is likely to pose a high risk to individuals, they must be notified too, without undue delay.

Is GDPR compliance a one-time project?

No. Compliance is continuous. Regulations, case law, your technology stack, and your vendor relationships all change, so audits, training, and documentation have to be repeated on an ongoing basis rather than completed once.

Ready for the next step?

Book a demo with our team and see top.legal in action

More on the topic