GDPR

GDPR: practical guides and steps

4 guides on the topic “GDPR”: legal obligations, concrete procedures, costs and deadlines.

The GDPR governs how a business collects and uses personal data. It applies as soon as a customer file, a CV or an email address comes into play. This page helps self-employed people and SMEs achieve compliance without jargon.

What is the GDPR?

The General Data Protection Regulation bears the reference 2016/679. It has applied across the European Union since 25 May 2018. You can read the official text free of charge on EUR-Lex. In Belgium, the Data Protection Authority monitors compliance.

The regulation rests on a few simple principles. You collect only the data you need. You state clearly why you process it. Finally, you keep it for a limited time. Each processing activity also needs a legal basis, such as a contract or consent.

Key GDPR obligations for a business

Even a small structure must follow several rules. Here are the main ones.

  • Keep a record of processing activities, in most cases.
  • Inform people through a clear privacy notice.
  • Answer requests for access, correction or erasure.
  • Sign an agreement with every processor that handles your data.
  • Report a data breach to the authority within 72 hours.
  • Appoint a data protection officer where the law demands it.

For a step-by-step method, read our GDPR compliance plan. Our article on personal data protection in business also explains individual rights.

Penalties and points to watch

Fines can reach EUR 20 million or 4% of worldwide annual turnover. These caps mainly target serious breaches. Yet a single customer complaint can trigger an inspection. The real risk often lies in reputational damage.

Some mistakes come up again and again. First, many businesses keep data with no time limit. Second, newsletters sometimes go out without valid consent. In addition, online tools move data outside the Union without checks. Finally, internal access rights remain too broad.

New practices also raise questions. For instance, electronic invoicing moves data about sole traders between platforms. See what electronic invoicing changes for your exchanges.

Where to start

Begin by mapping your data. List the files, the software and the people with access. Then delete what you no longer use. Finally, draft your privacy notices and processor agreements. Also appoint an internal point of contact. This person centralises customer requests and incidents. Even without an official DPO, this role stops letters going unanswered. It keeps the GDPR alive in everyday work.

GDPR compliance never ends after one project. It follows changes in your tools and your customers. To fit it into a wider strategy, consult our file on the legal protection of your business. An annual review often keeps you on track.