Contents
Join our newsletter
Cybersecurity tips, analyses and news delivered to your inbox every month! 
Learn more about our privacy policies.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
All articles
8
min
ISO 27701 and GDPR

How can you ensure compliance with the GDPR?

Achieving GDPR compliance means stopping viewing the regulation as an abstract legal constraint and treating it as a business project with a project manager, a timeline, and deliverables. Since 2018, the General Data Protection Regulation has governed the collection, use, and storage of personal data within the European Union, and requires every organization to be able to demonstrate at any time that it processes this data fairly, securely, and for a specific purpose. This article outlines the complete, step-by-step method for a Data Protection Officer (DPO), a Chief Information Security Officer (CISO), or a leader of a microbusiness, small business, or mid-sized company who needs to launch or relaunch this initiative.

GDPR Compliance: What You Need to Do Before Starting the Project

GDPR compliance is an ongoing process

There is no final certificate that closes the case. GDPR compliance requires constant updating of procedures, particularly through the principle of accountability: every organization must be able to demonstrate, at any time, that it has implemented the necessary measures to mitigate the risks associated with its data processing activities.

Adjusting Requirements Based on the Risk Associated with the Processing

The CNIL does not expect the same level of effort from an association that manages a membership database as it does from a group that processes health data on a large scale. The intensity of the measures to be implemented is determined by the sensitivity of the data, the volume processed, and the potential impact on the individuals concerned.

Who is required to comply?

The GDPR applies to any organization established in the European Union—or whose activities target European residents—as soon as it processes personal data, including in paper form. No company is exempt, regardless of size: a very small business that manages a customer database in Excel is subject to the GDPR just as much as a medium-sized company with multiple locations.

How long does it take to bring a company into compliance with the GDPR?

A basic compliance framework (record-keeping, disclosure notices, basic security measures) generally takes 2 to 4 months to establish for an SME. A comprehensive system—including DPO governance, personal data protection, and subcontractor agreements—typically takes 6 to 12 months, depending on the number of data processing operations and the organization’s initial level of maturity.

What is the budget based on the size of the company?

For a very small business, occasional support and simple tools are often sufficient. For a small or medium-sized business with multiple locations, the budget increases along with the complexity: the number of data processing operations, the number of subcontractors to audit, and any governance, risk, and compliance (GRC) tools that need to be deployed.

Step 1: Map and Create the Treatment Registry

Start with the registry (not the DPO)

The first common mistake is to appoint a DPO before knowing what the DPO will be responsible for overseeing. The CNIL recommends starting with a detailed inventory of personal data processing activities to assess the regulation’s actual impact on the organization.

The content required by Article 30

For each processing activity, the record must list the purposes of the processing, the categories of data and data subjects, the recipients, the retention periods, and the security measures in place.

Data Controller vs. Data Processor: What's the Difference?

The data controller determines the purposes and means of processing; the data processor acts on the data controller’s instructions. Each maintains its own record, with different content: the data processor records the categories of processing carried out on behalf of third parties, not the business purposes.

Common Pitfalls That Can Invalidate a Record During an Audit

A generic record copied from an online template, unjustified retention periods, or “overlooked” processing activities (video surveillance, time clocks, cookies) are the first issues identified by inspectors.

Step 2: Classification, Legal Basis, and Retention Period by Data Processing Activity

Choose from the 6 legal bases under the GDPR

Each processing activity must be based on one of the six legal grounds: consent, performance of a contract, legal obligation, protection of vital interests, public interest mission, or legitimate interest.

Consent or Legitimate Interest: Which Is the More Deceptive Argument?

Consent must be freely given, specific, and informed, with the right to withdraw consent at any time; legitimate interest, on the other hand, is assessed on a case-by-case basis by balancing the company’s interests against the individual’s rights. Many companies automatically rely on consent when another, legally more stable basis would be more appropriate.

Establishing Justifiable Retention Periods

Retention periods must be proportionate to the purpose: for example, 5 years for payroll data, 3 years without contact for a prospect, or 1 month for video surveillance. Distinguishing between routine, interim, and permanent archiving makes it possible to justify each retention period to a data protection officer.

What examiners look for in this certification

They verify consistency between the stated purpose, the chosen legal basis, and the actual use of the data. A discrepancy among these three is one of the most frequently penalized violations.

Step 3: Establishing Governance, the DPO, and Responsibilities

Is appointing a DPO legally required?

This applies to public agencies—those that conduct regular and systematic monitoring of individuals on a large scale, or that process sensitive or criminal data on a large scale. For other organizations, the designation remains a best practice that is strongly recommended.

Choosing Between an In-House, Shared, or Outsourced DPO

An in-house DPO is familiar with the organization but may lack an objective perspective; a shared DPO divides their time among several organizations; an outsourced DPO provides specialized expertise without a fixed payroll cost. The choice depends on the volume of data processing and the available budget.

Independence and Resources of the DPO

The data protection officer must have the necessary time, human, and material resources; be involved in all data protection matters; have no conflict of interest; and be able to report directly to management without receiving instructions regarding the performance of his or her duties.

Define responsibilities beyond the DPO

The DPO provides advice but does not make decisions alone: each department (HR, IT, marketing) must have a designated representative who enforces the rules on a day-to-day basis, with a clear chain of command in the event of an incident.

Step 4: Security, Technical and Organizational Measures

The minimum standards expected by the CNIL in 2026

Strong password policies, regular updates, tested backups, access control management, and staff awareness training form the foundation that the CNIL finds (or notes is lacking) in most of its audits.

Anonymization vs. Pseudonymization: Don't Confuse the Two

Anonymization makes re-identification impossible and removes the data from the scope of the GDPR; pseudonymization, on the other hand, remains reversible, and the data continues to be considered personal data that must be protected.

Encryption, access control, logging: the priorities

These three technical measures reduce the scope of risk in the event of a breach and make it possible to demonstrate, in the event of an audit, that proportionate measures have been implemented.

Handling a Data Breach: The 72-Hour Procedure

As soon as a security incident poses a risk to individuals’ rights and freedoms, it must be reported to the CNIL within 72 hours of the time the organization becomes sufficiently certain of its existence—not from the time the incident occurred, but from the time of its confirmed detection. The deadline includes weekends and holidays, and a partial notification followed by a subsequent update remains possible in the event of ongoing investigations.

Step 5: Oversee the supply chain, subcontractors, and transfers

Identifying Your Processors Under the GDPR

Web hosting providers, email marketing platforms, outsourced payroll tools: any service provider that processes personal data on behalf of the company is a processor within the meaning of Article 28, and must also comply with the GDPR.

The DPA: What a Contract Under Article 28 Must Include

The data processing agreement must specify the purpose and duration of the processing, security obligations, the conditions for engaging subsequent processors, and the procedures for returning or deleting the data at the end of the agreement.

Data Transfers Outside the EU

Any transfer to a country outside the European Union must be governed by an appropriate legal framework; otherwise, it constitutes a violation of the GDPR.

Standard Contractual Clauses, Adequacy Decisions, TIA

The European Commission's standard contractual clauses, adequacy decisions recognizing an equivalent level of protection, and the Transfer Impact Assessment are the three tools that should be combined depending on the recipient country.

Disclosures to Authorized Third Parties

Some public authorities may require the disclosure of documents containing personal data; such requests must be verified and documented before any disclosure takes place.

Step 6: Uphold people's rights

The 8 Rights to Teach

Access, correction, erasure, portability, objection, restriction, withdrawal of consent, and the right to establish post-mortem directives: each request must be identified, tracked, and processed according to its type.

Internal Process for Handling Requests in a Timely Manner

A one-month deadline (extendable to three months for complex requests) applies to most rights. A clear internal process—with a single point of entry, identity verification, and a formal response—prevents delays, one of the most common violations identified by the CNIL in its simplified sanctions.

Classify complex or abusive requests

A request that is manifestly unfounded or repetitive may be denied or subject to a fee, provided that the denial is supported by a rationale and documented.

Step 7: Ensuring Compliance, AIPD, Training, Review

AIPD: When to Conduct It and How to Structure the Analysis

A data protection impact assessment is required whenever data processing is likely to result in a high risk to the rights and freedoms of individuals. It describes the processing, assesses its necessity and proportionality, and then identifies the risks and measures to mitigate them.

Train the teams; the three levels of awareness to be addressed

General awareness-raising for all employees, in-depth training for teams that handle sensitive data, and specific guidance for the DPO and business point persons.

The Annual Review of the Program

Records, risk analyses, subcontractor agreements, and internal procedures must be reviewed regularly to ensure they remain aligned with changes in the business.

Preparing for a CNIL Audit

The 4 Types of Control and Their Triggers

On-site inspections, hearings by summons, online inspections, and document-based inspections may each be initiated by a complaint, a report, or a CNIL initiative.

What Auditors Prioritize

The record of processing activities, evidence of consent or the applicable legal basis, and contracts with processors are among the first documents requested.

CNIL Penalties for 2024–2025: What They Reveal About Current Priorities

In 2024, the CNIL imposed 87 penalties totaling 55.2 million euros in fines, compared to 42 penalties in 2023, reflecting a marked acceleration in its enforcement efforts. In 2025, it issued 259 decisions, including 83 sanctions totaling 486.8 million euros, with insufficient data security, failure to cooperate, and failure to respect individuals’ rights as the three main grounds for sanctions in simplified proceedings. Employee monitoring also remains a key area of focus, with six out of ten recent simplified decisions addressing this issue.

How to Conduct Yourself During and After the Inspection

Cooperation, designating a single point of contact, and documenting every interaction are essential: failure to cooperate with the CNIL is itself grounds for a separate penalty, which can sometimes be more severe than the initial violation.

Manage the project, do it yourself, gather the necessary tools, or get help

The internal capabilities needed to maintain compliance over the long term

A legal understanding of the legal framework, the ability to collaborate with IT on security matters, and an HR liaison for employee data are the three key competencies that should be maintained in-house, even with an outsourced DPO.

When a GRC Tool Delivers a Return on Investment

When there are more than a dozen processes or several subcontractors that need to be audited regularly, a governance, risk, and compliance (GRC) tool becomes cost-effective: it centralizes the registry, automates review reminders, and tracks compliance in a way that can be leveraged in the event of an audit.

Bringing a company into compliance with the GDPR is never a task you can simply check off your list—it’s an ongoing process that requires active management. If you want to ensure every step is handled properly—from maintaining the processing register to preparing for a CNIL audit—without spending months on legal research, the Feel Agile team can structure and guide your GDPR compliance efforts from start to finish.

Would you like to organize your GDPR compliance?

Get expert guidance on GDPR compliance →
More content

Our latest Blog posts