
Achieving GDPR compliance means stopping viewing the regulation as an abstract legal constraint and treating it as a business project with a project manager, a timeline, and deliverables. Since 2018, the General Data Protection Regulation has governed the collection, use, and storage of personal data within the European Union, and requires every organization to be able to demonstrate at any time that it processes this data fairly, securely, and for a specific purpose. This article outlines the complete, step-by-step method for a Data Protection Officer (DPO), a Chief Information Security Officer (CISO), or a leader of a microbusiness, small business, or mid-sized company who needs to launch or relaunch this initiative.
There is no final certificate that closes the case. GDPR compliance requires constant updating of procedures, particularly through the principle of accountability: every organization must be able to demonstrate, at any time, that it has implemented the necessary measures to mitigate the risks associated with its data processing activities.
The CNIL does not expect the same level of effort from an association that manages a membership database as it does from a group that processes health data on a large scale. The intensity of the measures to be implemented is determined by the sensitivity of the data, the volume processed, and the potential impact on the individuals concerned.
The GDPR applies to any organization established in the European Union—or whose activities target European residents—as soon as it processes personal data, including in paper form. No company is exempt, regardless of size: a very small business that manages a customer database in Excel is subject to the GDPR just as much as a medium-sized company with multiple locations.
A basic compliance framework (record-keeping, disclosure notices, basic security measures) generally takes 2 to 4 months to establish for an SME. A comprehensive system—including DPO governance, personal data protection, and subcontractor agreements—typically takes 6 to 12 months, depending on the number of data processing operations and the organization’s initial level of maturity.
For a very small business, occasional support and simple tools are often sufficient. For a small or medium-sized business with multiple locations, the budget increases along with the complexity: the number of data processing operations, the number of subcontractors to audit, and any governance, risk, and compliance (GRC) tools that need to be deployed.

The first common mistake is to appoint a DPO before knowing what the DPO will be responsible for overseeing. The CNIL recommends starting with a detailed inventory of personal data processing activities to assess the regulation’s actual impact on the organization.
For each processing activity, the record must list the purposes of the processing, the categories of data and data subjects, the recipients, the retention periods, and the security measures in place.
The data controller determines the purposes and means of processing; the data processor acts on the data controller’s instructions. Each maintains its own record, with different content: the data processor records the categories of processing carried out on behalf of third parties, not the business purposes.
Common Pitfalls That Can Invalidate a Record During an Audit
A generic record copied from an online template, unjustified retention periods, or “overlooked” processing activities (video surveillance, time clocks, cookies) are the first issues identified by inspectors.
Each processing activity must be based on one of the six legal grounds: consent, performance of a contract, legal obligation, protection of vital interests, public interest mission, or legitimate interest.

Consent must be freely given, specific, and informed, with the right to withdraw consent at any time; legitimate interest, on the other hand, is assessed on a case-by-case basis by balancing the company’s interests against the individual’s rights. Many companies automatically rely on consent when another, legally more stable basis would be more appropriate.
Retention periods must be proportionate to the purpose: for example, 5 years for payroll data, 3 years without contact for a prospect, or 1 month for video surveillance. Distinguishing between routine, interim, and permanent archiving makes it possible to justify each retention period to a data protection officer.
They verify consistency between the stated purpose, the chosen legal basis, and the actual use of the data. A discrepancy among these three is one of the most frequently penalized violations.
This applies to public agencies—those that conduct regular and systematic monitoring of individuals on a large scale, or that process sensitive or criminal data on a large scale. For other organizations, the designation remains a best practice that is strongly recommended.
An in-house DPO is familiar with the organization but may lack an objective perspective; a shared DPO divides their time among several organizations; an outsourced DPO provides specialized expertise without a fixed payroll cost. The choice depends on the volume of data processing and the available budget.
The data protection officer must have the necessary time, human, and material resources; be involved in all data protection matters; have no conflict of interest; and be able to report directly to management without receiving instructions regarding the performance of his or her duties.
The DPO provides advice but does not make decisions alone: each department (HR, IT, marketing) must have a designated representative who enforces the rules on a day-to-day basis, with a clear chain of command in the event of an incident.

Strong password policies, regular updates, tested backups, access control management, and staff awareness training form the foundation that the CNIL finds (or notes is lacking) in most of its audits.
Anonymization makes re-identification impossible and removes the data from the scope of the GDPR; pseudonymization, on the other hand, remains reversible, and the data continues to be considered personal data that must be protected.
These three technical measures reduce the scope of risk in the event of a breach and make it possible to demonstrate, in the event of an audit, that proportionate measures have been implemented.
As soon as a security incident poses a risk to individuals’ rights and freedoms, it must be reported to the CNIL within 72 hours of the time the organization becomes sufficiently certain of its existence—not from the time the incident occurred, but from the time of its confirmed detection. The deadline includes weekends and holidays, and a partial notification followed by a subsequent update remains possible in the event of ongoing investigations.
Web hosting providers, email marketing platforms, outsourced payroll tools: any service provider that processes personal data on behalf of the company is a processor within the meaning of Article 28, and must also comply with the GDPR.
The data processing agreement must specify the purpose and duration of the processing, security obligations, the conditions for engaging subsequent processors, and the procedures for returning or deleting the data at the end of the agreement.
Any transfer to a country outside the European Union must be governed by an appropriate legal framework; otherwise, it constitutes a violation of the GDPR.
The European Commission's standard contractual clauses, adequacy decisions recognizing an equivalent level of protection, and the Transfer Impact Assessment are the three tools that should be combined depending on the recipient country.
Some public authorities may require the disclosure of documents containing personal data; such requests must be verified and documented before any disclosure takes place.
Access, correction, erasure, portability, objection, restriction, withdrawal of consent, and the right to establish post-mortem directives: each request must be identified, tracked, and processed according to its type.
A one-month deadline (extendable to three months for complex requests) applies to most rights. A clear internal process—with a single point of entry, identity verification, and a formal response—prevents delays, one of the most common violations identified by the CNIL in its simplified sanctions.
A request that is manifestly unfounded or repetitive may be denied or subject to a fee, provided that the denial is supported by a rationale and documented.
A data protection impact assessment is required whenever data processing is likely to result in a high risk to the rights and freedoms of individuals. It describes the processing, assesses its necessity and proportionality, and then identifies the risks and measures to mitigate them.
General awareness-raising for all employees, in-depth training for teams that handle sensitive data, and specific guidance for the DPO and business point persons.
Records, risk analyses, subcontractor agreements, and internal procedures must be reviewed regularly to ensure they remain aligned with changes in the business.
On-site inspections, hearings by summons, online inspections, and document-based inspections may each be initiated by a complaint, a report, or a CNIL initiative.
The record of processing activities, evidence of consent or the applicable legal basis, and contracts with processors are among the first documents requested.
In 2024, the CNIL imposed 87 penalties totaling 55.2 million euros in fines, compared to 42 penalties in 2023, reflecting a marked acceleration in its enforcement efforts. In 2025, it issued 259 decisions, including 83 sanctions totaling 486.8 million euros, with insufficient data security, failure to cooperate, and failure to respect individuals’ rights as the three main grounds for sanctions in simplified proceedings. Employee monitoring also remains a key area of focus, with six out of ten recent simplified decisions addressing this issue.
Cooperation, designating a single point of contact, and documenting every interaction are essential: failure to cooperate with the CNIL is itself grounds for a separate penalty, which can sometimes be more severe than the initial violation.
A legal understanding of the legal framework, the ability to collaborate with IT on security matters, and an HR liaison for employee data are the three key competencies that should be maintained in-house, even with an outsourced DPO.
When there are more than a dozen processes or several subcontractors that need to be audited regularly, a governance, risk, and compliance (GRC) tool becomes cost-effective: it centralizes the registry, automates review reminders, and tracks compliance in a way that can be leveraged in the event of an audit.
Bringing a company into compliance with the GDPR is never a task you can simply check off your list—it’s an ongoing process that requires active management. If you want to ensure every step is handled properly—from maintaining the processing register to preparing for a CNIL audit—without spending months on legal research, the Feel Agile team can structure and guide your GDPR compliance efforts from start to finish.