The GDPR applies to any organization that collects personal data, with no size threshold. SYAGA CONSULTING helps you formalize a record of processing activities, frame your data processors, answer the GDPR questionnaires from your clients and insurers, and carry out a data protection impact assessment when required.
The GDPR has been in force since 2018, but remains largely unformalized in SMEs
As soon as an organization collects personal data (customers, employees, prospects), it is concerned. A limited exception exists for organizations with fewer than 250 employees whose processing is occasional, but it does not cover a regular commercial activity.
Many SMEs have never formalized their record, or drafted it once and never updated it since, even though their processing activities, processors and tools have changed.
A client, a bank or a cyber insurer increasingly asks its suppliers to answer a data protection questionnaire (art. 28): sub-processing, encryption, MFA, backups, logging, incident plan.
Drafting a record, framing data processors or building an impact assessment requires cross legal and technical expertise that few SMEs have in-house.
A structured method, adapted to the size and real context of your organization
Interview with the manager or the GDPR contact person. Identification of personal data processing activities (customers, employees, prospects, suppliers), the tools used and the processors already in place.
Drafting of the record of processing activities: purposes, legal bases, categories of data and data subjects concerned, recipients, retention periods, security measures.
Review or drafting of the sub-processing clauses (art. 28) with your service providers, and preparation of answers to the GDPR questionnaires sent by your clients or insurers (technical and organizational measures).
Delivery of the documents and presentation to management. If your processing falls under one of the cases provided for in art. 35(3) of the GDPR (profiling with legal effect, sensitive data on a large scale, systematic monitoring of a publicly accessible area), a data protection impact assessment (DPIA) is carried out or scoped with you.
Documents adapted to your actual organization, not generic templates
Complete record compliant with article 30 of the GDPR.
Contractual framing of your service providers within the meaning of article 28.
Carried out only when article 35(3) of the GDPR requires it, or as a precaution on request.
Preparation of answers to questionnaires sent by your clients, banks or cyber insurers.
Inventory of the measures required by article 32 of the GDPR.
The deliverables are handed over to you in directly usable formats.
The GDPR (Regulation (EU) 2016/679) structures the RGPD-Express approach
Obligation to keep a record, both on the controller side and the processor side. The exemption provided in 30.5 for organizations with fewer than 250 employees applies only to occasional processing.
Contractual framing of any processor handling data on your behalf: sufficient guarantees, mandatory clauses, further sub-processing authorized by prior written consent.
Technical and organizational measures appropriate to the risk: pseudonymization, encryption, means to ensure confidentiality and availability, procedure for regular testing and evaluation.
Mandatory only when the processing is likely to result in a high risk: systematic evaluation with legal effect, sensitive data on a large scale, or systematic monitoring of a publicly accessible area.
Each organization has a different processing scope: the price is set after the scoping session
Micro / small business, simple processing scope
SMEs with several processors and recurring questionnaires
Organization with sensitive processing or sector-specific regulation
What the text really says, translated into plain language. Each point links back to the official text.
It is the European text governing the collection and use of personal data (customers, employees, prospects...). It was adopted on 27 April 2016 and published in the Official Journal of the European Union on 4 May 2016.
The regulation entered into force twenty days after its publication, but it has only been genuinely applicable since 25 May 2018. That is the date that matters for your concrete obligations.
You must keep a list of what you do with personal data: for what purpose, with whom, how long you keep it, how you protect it. An exception exists for organizations with fewer than 250 employees, but only if the processing is occasional - a regular commercial activity does not benefit from it.
It is only mandatory in three specific situations: you are a public body, or your core activity consists of regularly and systematically monitoring individuals on a large scale, or of processing sensitive data on a large scale. Outside these cases, appointing a DPO remains optional.
If personal data is lost, stolen or exposed, you must notify the CNIL (or the competent authority) no later than 72 hours after becoming aware of it, unless the risk to individuals is negligible. You must also keep a written record of every incident.
When a data breach creates a high risk for the individuals concerned, you must inform them directly, in clear and plain language. You may be exempted from this notification if the data was encrypted or if you have already neutralized the risk.
In the event of a breach, the fine can reach up to 10 million euros (or 2% of the company's worldwide annual turnover) for the most common breaches, and up to 20 million euros (or 4% of worldwide turnover) for the most serious violations of individuals' rights - the higher amount always applies. The actual amount depends on the severity, good faith and cooperation with the authority.
The question we hear most often: "Does this really apply to me, a small business?" Short, sourced answer: yes, almost always.
The GDPR applies as soon as an organization processes, even partially in an automated way, or within a structured file, information relating to an identified or identifiable person: name, email, phone number, IP address, location data...
In practice, this covers a customer file, employee payroll, CVs received, a CCTV camera, a newsletter, a CRM or audience-measurement cookies.
The GDPR does not apply in four specific cases:
The GDPR applies as soon as your company has an establishment in the European Union, or as soon as you target individuals located there: by offering them goods or services (even free ones), or by monitoring their behaviour (profiling, tracking cookies).
The CNIL gives two telling examples: a French company that exports only to Morocco remains subject to the GDPR as soon as it processes data of individuals in the EU; a Chinese e-commerce site that delivers to France must also comply with it.
Data controller: the organization that decides why and how the data is used (your company, a municipality, an association). That is generally you.
Processor: the service provider that processes this data on your instructions (hosting provider, payroll software, marketing agency...). It also has its own obligations, distinct from yours.
Private companies
from micro-businesses to large groups, from the very first customer file or payslip
Public sector
municipalities, local authorities, government bodies, healthcare institutions
Associations, tradespeople, freelancers
regulated professions, shopkeepers, startups: no exemption based on status
No legal jargon: the 7 most common questions, a simple answer, and the official text behind each answer.
Click on a question to see the answer and its source.
No. Consent is only one option out of six. The GDPR (article 6) also allows processing when it is necessary for the performance of a contract, for compliance with a legal obligation, to protect vital interests, for a task carried out in the public interest, or for the legitimate interest of your company (for example managing the relationship with an existing customer), as long as the individual's rights do not override it.
It depends on who you are contacting:
In all cases: an identifiable sender and an easy unsubscribe link.
Generally yes, in particular if the data no longer serves any purpose, if the person withdraws their consent, or if they object without a legitimate overriding reason on your part. You may, however, refuse if you must keep the data for a legal obligation - for example an invoice that must be kept for 10 years for accounting purposes - or to defend yourself in legal proceedings.
1 month from receipt of the request. This period can be extended by 2 months if the request is complex or if you receive a large number of them, but you must inform the person of this extension within the initial month.
Yes, but not without precautions. Three possible cases: the country benefits from an official European Commission adequacy decision recognizing an adequate level of protection; failing that, your provider must offer appropriate safeguards (standard contractual clauses in most cases); or, for one-off cases only, a specific derogation applies (explicit consent, performance of a contract...).
Yes. Most cookies (personalized advertising, social media buttons...) require your visitor's prior consent, given freely, and as easy to withdraw as to give. Accepting general terms and conditions does not count as valid consent. A few technical cookies (shopping cart, authentication, language preference) are exempt from this requirement.
The CNIL generally starts with an inspection (on-site or online) followed by a formal notice to become compliant within a given deadline. Financial penalties do exist but remain proportionate to the size of the organization: the CNIL has, for example, fined small businesses between 2,000 and 20,000 euros for breaches relating to security, cookies or the right of access - far below the maximum ceilings (up to 20 million euros or 4% of worldwide turnover for the most serious breaches).
The GDPR was not born in 2018 and has not stood still since. Here, in order, is what has already happened (and still is the rule today) and what is still under discussion in Brussels - with, for each step, the official text that proves it.
The European Parliament and the Council adopt Regulation (EU) 2016/679, the GDPR. source EUR-Lex ↗
The text is published in the Official Journal of the European Union (OJ L 119, pages 1 to 88). source EUR-Lex ↗
The regulation "enters into force on the twentieth day following that of its publication" (art. 99). It exists legally, but its effective application to companies is still deferred by two years - time to get organized. source CNIL, art. 99 ↗
From this date, all organizations that process personal data of European residents must be genuinely compliant, not just "on paper". This is the date to remember. source CNIL, art. 99 ↗
Law No. 2018-493 adapts French law to the GDPR and transposes the "police-justice" directive (2016/680), building on the 1978 Data Protection Act ("loi Informatique et Libertés"). source Légifrance ↗
Order No. 2018-1125 completes the alignment of the Data Protection Act ("loi Informatique et Libertés") with the GDPR and directive 2016/680. source Légifrance ↗
Two years after it became applicable, the Commission publishes its first report: the GDPR meets its objectives, but improvements are needed (harmonization between countries, cooperation between authorities). source EUR-Lex (COM 2020) ↗
The Court of Justice of the European Union invalidates the "Privacy Shield" that governed data transfers to the United States: the US safeguards on public authorities' access to data are not considered sufficient. source EUR-Lex ↗
New model clauses for governing data transfers outside the EU enter into force, with a 15-month transition period to replace contracts already signed. source EUR-Lex (2021/914) ↗
The Commission adopts the "EU-US Data Privacy Framework" adequacy decision, which replaces the Privacy Shield invalidated in 2020 and once again secures transfers to certified US companies. source EUR-Lex (2023/1795) ↗
A sharp rise in penalties against large tech companies, but divergences persist between national authorities. The Commission recommends better support for SMEs. source EUR-Lex (COM 2024) ↗
As part of its single market simplification package, the Commission proposes extending to 750 employees (instead of 250) the exemption from keeping a full record of processing activities (art. 30), limited to "high-risk" processing. This is a proposal, not yet a text in force. source European Commission ↗
The Council and the European Parliament reach a political agreement on additional procedural rules to harmonize how national supervisory authorities cooperate during cross-border investigations. Formal adoption and publication in the Official Journal remain to be confirmed. source European Commission ↗
Timeline compiled from official sources (EUR-Lex, CNIL, Légifrance, European Commission) consulted on 18 July 2026. The last two steps are proposals or political agreements still in progress - we will update them as soon as they are formally adopted and published in the Official Journal. This is an educational summary and does not constitute legal advice.
The scary figure - "20 million euros" - is everywhere, but it does not explain how it actually works. Here, backed by official sources, is who imposes penalties, how, and for what real amounts.
or up to 2% of the company's total worldwide annual turnover (whichever amount is higher applies).
Tier applicable to "common" breaches: record of processing activities, data security, processor obligations, missing impact assessment...
or up to 4% of worldwide annual turnover (same rule, whichever amount is higher applies).
Tier applicable to the most serious breaches: absence of a legal basis, violation of individuals' rights, unlawful transfers outside the EU...
It is not the "general" CNIL that imposes penalties, but a separate, independent body: the restricted committee ("formation restreinte"), made up of 5 members and a chair different from the CNIL's own chair. It alone investigates cases and issues sanctions. The most significant decisions are made public.
Article 83 of the GDPR requires the CNIL to take several criteria into account before setting a fine, notably:
| Date | Organization | Amount | Grounds |
|---|---|---|---|
| 21/01/2019 | Google LLC | 50 M € | Lack of transparency, no valid consent for personalized advertising |
| 07/12/2020 | Amazon Europe Core | 35 M € | Cookies placed without prior consent |
| 31/12/2021 | Google LLC / Google Ireland | 150 M € | Refusing cookies made more complicated than accepting them |
| 31/12/2021 | Facebook Ireland (Meta) | 60 M € | Same grounds: refusing cookies made too difficult |
| 17/10/2022 | Clearview AI | 20 M € | Facial recognition without a legal basis, refusal to cooperate |
| 10/11/2022 | Discord Inc. | 800 000 € | Excessive data retention, insufficient security and information |
| 15/06/2023 | Criteo | 40 M € | Breaches relating to cookie consent and individuals' rights |
The CNIL also sanctions small and medium-sized organizations, but with amounts far below those imposed on international groups. From the December 2025 decisions alone, examples include: 5 000 € for a hotel management company (non-compliant video surveillance), 7 000 € and 5 000 € for two newspaper publishing companies (invalid cookies), 10 000 € for an airport freight company (unlawful video surveillance), or 20 000 € for a university (purposes not respected). At the other end of the scale, a services-sector company was fined 3.5 M € the same month for a combination of serious breaches (security, transparency, cookies). The amount follows the severity and size, not the other way around.
In Europe, each country has its own authorities. Here, for the 30 countries of the European Economic Area, is the data protection authority (your GDPR contact) and the national cybersecurity authority. Each name links to the official website.
Sources: official authority websites and the EDPB members list (edpb.europa.eu), consulted on 18 July 2026. Data protection authorities confirmed: 30/30. Cybersecurity authorities confirmed: 28/30. The "to be confirmed" notes indicate an official source not yet stabilized as of this date.
Write to us for an initial scoping session and a personalized quote, with no obligation.
Free: your score + your gaps. The detailed report and the attestation: 499 EUR excl. VAT, only if you decide to.
contact@syaga.eu