+31 88 8040 777

GDPR checklist for SMEs

The GDPR applies to virtually every organisation that processes personal data. With this checklist you make the most important obligations concrete and demonstrable.

The GDPR (General Data Protection Regulation) requires organisations to handle personal data carefully and demonstrably. For SMEs this does not have to be complicated: with a number of basic measures you can get a long way, and at an inspection you demonstrate that you take it seriously.

The core principles of the GDPR

  • Purpose limitation: only collect data for a clear, legitimate purpose.
  • Data minimisation: keep no more than necessary, and no longer than necessary.
  • Lawfulness: ensure a valid basis (for example consent or a contract).
  • Security: take appropriate technical and organisational measures.
  • Accountability: can you demonstrate that you comply with the GDPR?

The practical checklist

  1. Do you have a record of processing activities stating which personal data you process, why and for how long?
  2. Do you have an up-to-date, understandable privacy statement on your website?
  3. Are there data processing agreements with suppliers who process data on your behalf (such as your hosting or software provider)?
  4. Do you have a process to handle data subject requests (access, correction, erasure) in a timely manner?
  5. Can you recognise a data breach and report it within 72 hours to the Dutch Data Protection Authority?
  6. Is data technically secured (access management, MFA, encryption, backups)?
  7. Do you know where your data is stored and whether it stays within the EU?
  8. Have you assessed whether you need a DPIA (data protection impact assessment) or a data protection officer?
  9. Are employees aware of how they handle personal data?

GDPR and security belong together

The GDPR requires "appropriate security" but does not specify exactly what that is. In practice, GDPR and cybersecurity overlap strongly: access management, encryption, backups and incident detection are both privacy and security measures. Whoever has their security in order has already arranged a large part of the technical side of the GDPR.

Would you like to bring GDPR and security into order together?

View our GDPR guidance