Structured, sourced documentary assistance. This service does not constitute legal advice: the legally binding aspects require a qualified professional (lawyer, DPO or certified auditor).
REGULATION (EU) 2016/679 - GDPR

RGPD-Express
Structure your GDPR compliance

The GDPR applies to any organization that collects personal data, with no size threshold. SYAGA CONSULTING helps you formalize a record of processing activities, frame your data processors, answer the GDPR questionnaires from your clients and insurers, and carry out a data protection impact assessment when required.

4
compliance pillars covered
Art. 30
Record of processing activities
Art. 28
Framing of data processors
Art. 83
Penalties of up to 20 M EUR or 4% of worldwide turnover

The problem

The GDPR has been in force since 2018, but remains largely unformalized in SMEs

The GDPR has no size threshold

As soon as an organization collects personal data (customers, employees, prospects), it is concerned. A limited exception exists for organizations with fewer than 250 employees whose processing is occasional, but it does not cover a regular commercial activity.

📋

The record of processing activities (art. 30) is missing or outdated

Many SMEs have never formalized their record, or drafted it once and never updated it since, even though their processing activities, processors and tools have changed.

📧

Your clients and insurers send you GDPR questionnaires

A client, a bank or a cyber insurer increasingly asks its suppliers to answer a data protection questionnaire (art. 28): sub-processing, encryption, MFA, backups, logging, incident plan.

Your teams do not have time to train on the GDPR

Drafting a record, framing data processors or building an impact assessment requires cross legal and technical expertise that few SMEs have in-house.

The RGPD-Express approach

A structured method, adapted to the size and real context of your organization

1
Step 1 - Scoping

Interview and mapping of processing activities

Interview with the manager or the GDPR contact person. Identification of personal data processing activities (customers, employees, prospects, suppliers), the tools used and the processors already in place.

2
Step 2 - Record of processing activities

Formalization of the record (art. 30)

Drafting of the record of processing activities: purposes, legal bases, categories of data and data subjects concerned, recipients, retention periods, security measures.

3
Step 3 - Sub-processing and technical measures

Data processing agreements and answers to questionnaires

Review or drafting of the sub-processing clauses (art. 28) with your service providers, and preparation of answers to the GDPR questionnaires sent by your clients or insurers (technical and organizational measures).

4
Step 4 - Handover

Delivery and impact assessment if required

Delivery of the documents and presentation to management. If your processing falls under one of the cases provided for in art. 35(3) of the GDPR (profiling with legal effect, sensitive data on a large scale, systematic monitoring of a publicly accessible area), a data protection impact assessment (DPIA) is carried out or scoped with you.

What you receive

Documents adapted to your actual organization, not generic templates

📝

Record of processing activities (ROPA)

Complete record compliant with article 30 of the GDPR.

  • Sheets per processing activity (purpose, legal basis)
  • Categories of data and data subjects concerned
  • Identified recipients and processors
  • Documented retention periods
  • Controller and processor section

Data processing agreements (DPA)

Contractual framing of your service providers within the meaning of article 28.

  • Up-to-date sub-processing clauses
  • Identification of downstream sub-processors
  • Framing of transfers outside the EU where applicable
  • Security and notification obligations
🔍

Data protection impact assessment (DPIA)

Carried out only when article 35(3) of the GDPR requires it, or as a precaution on request.

  • Necessity and proportionality analysis
  • Risk assessment for data subjects
  • Measures to mitigate identified risks
  • Traceable and sourced methodology
📧

Answers to your GDPR questionnaires

Preparation of answers to questionnaires sent by your clients, banks or cyber insurers.

  • Answer template on recurring themes
  • MFA, encryption, backups, logging
  • Incident response plan
  • Data retention policy
🛡

Technical and organizational measures

Inventory of the measures required by article 32 of the GDPR.

  • Security control points related to personal data
  • Prioritized recommendations
  • Possible bridge with an existing SYAGA Audit M365 audit
📄

Documents delivered

The deliverables are handed over to you in directly usable formats.

  • Word and PDF documents
  • Ready to be signed or distributed internally
  • Support for adoption by your teams

The key articles of the GDPR

The GDPR (Regulation (EU) 2016/679) structures the RGPD-Express approach

30

Art. 30 - Record of processing activities

Obligation to keep a record, both on the controller side and the processor side. The exemption provided in 30.5 for organizations with fewer than 250 employees applies only to occasional processing.

28

Art. 28 - Processor

Contractual framing of any processor handling data on your behalf: sufficient guarantees, mandatory clauses, further sub-processing authorized by prior written consent.

32

Art. 32 - Security of processing

Technical and organizational measures appropriate to the risk: pseudonymization, encryption, means to ensure confidentiality and availability, procedure for regular testing and evaluation.

35

Art. 35 - Data protection impact assessment (DPIA)

Mandatory only when the processing is likely to result in a high risk: systematic evaluation with legal effect, sensitive data on a large scale, or systematic monitoring of a publicly accessible area.

Plans on quotation

Each organization has a different processing scope: the price is set after the scoping session

Essential

Micro / small business, simple processing scope

Quote
tailored
  • Record of processing activities (art. 30)
  • Review of existing data processing agreements
  • Answer template for simple questionnaires
  • Document delivered in Word and PDF
Request a quote

Tailored

Organization with sensitive processing or sector-specific regulation

Quote
tailored
  • Everything in Standard +
  • Data protection impact assessment (DPIA) if art. 35(3) applies
  • Scoping of transfers outside the EU
  • Support for multi-site or multi-entity organizations
Request a quote
No fixed price is shown because the actual scope of your processing activities (number of processors, sensitivity of data, questionnaires to be handled) determines the workload. A personalized quote is drawn up after the scoping interview, with no obligation.

Frequently asked questions

Is my business concerned by the GDPR?
As soon as your organization collects personal data (customer file, payroll, commercial prospecting, video surveillance...), you are concerned, whatever your size. A limited exemption exists under article 30.5 for organizations with fewer than 250 employees whose processing is occasional: it generally does not apply as soon as there is a regular commercial activity.
Do I have to carry out a data protection impact assessment (DPIA)?
No. Article 35(3) of the GDPR only requires it in specific cases: automated decision with legal or similarly significant effect on a person, large-scale processing of sensitive data, or systematic large-scale monitoring of a publicly accessible area. Outside these cases, a DPIA may be carried out as a precaution but is not a legal obligation.
One of my clients or my cyber insurer sends me a GDPR questionnaire, what should I do?
This is an increasingly frequent approach under article 28 (your client is checking the guarantees of its own processors or suppliers). SYAGA helps you structure consistent and documented answers on recurring themes: sub-processing, MFA, encryption, backups, logging and incident response plan.
Is the record of processing activities enough to be "GDPR compliant"?
No, it is one building block among others. The GDPR also covers the legal basis for each processing activity, informing the data subjects, the exercise of their rights, the security of processing (art. 32) and, where applicable, the framing of sub-processing and transfers outside the EU. RGPD-Express addresses these building blocks according to the actual scope of your organization, defined during the scoping session.
Does RGPD-Express replace legal advice?
No. RGPD-Express is an operational support tool that helps you formalize your GDPR documentation. It does not constitute legal advice and does not replace consulting a lawyer or a data protection officer for complex or contentious situations.
What makes SYAGA qualified to support me on the GDPR?
SYAGA CONSULTING has been carrying out security and compliance audits of information systems since 2009. This activity has led us to document, for our own M365 audit offering, a complete and sourced record of processing activities, data processing agreements and an impact assessment. RGPD-Express puts this same methodology at the service of your organization.

Regulatory watch - official sources

What the text really says, translated into plain language. Each point links back to the official text.

What is GDPR, exactly?

It is the European text governing the collection and use of personal data (customers, employees, prospects...). It was adopted on 27 April 2016 and published in the Official Journal of the European Union on 4 May 2016.

Since when has it applied

The regulation entered into force twenty days after its publication, but it has only been genuinely applicable since 25 May 2018. That is the date that matters for your concrete obligations.

The record of processing activities: the baseline document

You must keep a list of what you do with personal data: for what purpose, with whom, how long you keep it, how you protect it. An exception exists for organizations with fewer than 250 employees, but only if the processing is occasional - a regular commercial activity does not benefit from it.

Do you need to appoint a Data Protection Officer (DPO)?

It is only mandatory in three specific situations: you are a public body, or your core activity consists of regularly and systematically monitoring individuals on a large scale, or of processing sensitive data on a large scale. Outside these cases, appointing a DPO remains optional.

In case of a data breach: 72 hours to notify the authority

If personal data is lost, stolen or exposed, you must notify the CNIL (or the competent authority) no later than 72 hours after becoming aware of it, unless the risk to individuals is negligible. You must also keep a written record of every incident.

If the risk is high, your customers or employees must also be notified

When a data breach creates a high risk for the individuals concerned, you must inform them directly, in clear and plain language. You may be exempted from this notification if the data was encrypted or if you have already neutralized the risk.

The penalties, in plain terms

In the event of a breach, the fine can reach up to 10 million euros (or 2% of the company's worldwide annual turnover) for the most common breaches, and up to 20 million euros (or 4% of worldwide turnover) for the most serious violations of individuals' rights - the higher amount always applies. The actual amount depends on the severity, good faith and cooperation with the authority.

This watch is an educational summary drawn up from the official texts cited above (EUR-Lex and CNIL). It does not replace a legal reading of the text and does not constitute legal advice.

Who is affected by the GDPR?

The question we hear most often: "Does this really apply to me, a small business?" Short, sourced answer: yes, almost always.

Company size changes nothing about the obligation

The CNIL is explicit: "like all companies, micro-businesses and SMEs must comply with the regulation on the protection of personal data." There is no headcount or turnover threshold that exempts an organization from the GDPR.

The real trigger: processing a personal data item

The GDPR applies as soon as an organization processes, even partially in an automated way, or within a structured file, information relating to an identified or identifiable person: name, email, phone number, IP address, location data...

In practice, this covers a customer file, employee payroll, CVs received, a CCTV camera, a newsletter, a CRM or audience-measurement cookies.

The rare exceptions

The GDPR does not apply in four specific cases:

  • a strictly personal or household use (your private address book, for example)
  • activities falling outside the scope of European Union law
  • activities of Member States relating to the common foreign policy
  • processing by authorities for the prevention of criminal offences (a separate regime)

It does not matter where you are based

The GDPR applies as soon as your company has an establishment in the European Union, or as soon as you target individuals located there: by offering them goods or services (even free ones), or by monitoring their behaviour (profiling, tracking cookies).

The CNIL gives two telling examples: a French company that exports only to Morocco remains subject to the GDPR as soon as it processes data of individuals in the EU; a Chinese e-commerce site that delivers to France must also comply with it.

Two possible roles, two levels of obligations

Data controller: the organization that decides why and how the data is used (your company, a municipality, an association). That is generally you.

Processor: the service provider that processes this data on your instructions (hosting provider, payroll software, marketing agency...). It also has its own obligations, distinct from yours.

🏢

Private companies
from micro-businesses to large groups, from the very first customer file or payslip

🏛️

Public sector
municipalities, local authorities, government bodies, healthcare institutions

🤝

Associations, tradespeople, freelancers
regulated professions, shopkeepers, startups: no exemption based on status

This section is an educational summary drawn up from the official texts and pages cited above (CNIL, articles 2, 3 and 4 of the GDPR). It does not replace a legal reading of the text and does not constitute legal advice.

The questions a business owner really asks

No legal jargon: the 7 most common questions, a simple answer, and the official text behind each answer.

Click on a question to see the answer and its source.

Do I always need my customers' consent to use their data?

No. Consent is only one option out of six. The GDPR (article 6) also allows processing when it is necessary for the performance of a contract, for compliance with a legal obligation, to protect vital interests, for a task carried out in the public interest, or for the legitimate interest of your company (for example managing the relationship with an existing customer), as long as the individual's rights do not override it.

Can I contact my customers and prospects by email for marketing purposes?

It depends on who you are contacting:

  • Individuals (B2C): prior consent required (a checkbox, never pre-ticked), except to offer a similar product again to an existing customer.
  • Professionals (B2B): possible without prior consent if the message relates to their business activity, provided you have informed them and given them a simple way to opt out.

In all cases: an identifiable sender and an easy unsubscribe link.

Source: CNIL, commercial prospecting by email (page updated 10/06/2026)
A customer asks me to delete their data - am I required to comply?

Generally yes, in particular if the data no longer serves any purpose, if the person withdraws their consent, or if they object without a legitimate overriding reason on your part. You may, however, refuse if you must keep the data for a legal obligation - for example an invoice that must be kept for 10 years for accounting purposes - or to defend yourself in legal proceedings.

How long do I have to respond to a customer's request (access, deletion...)?

1 month from receipt of the request. This period can be extended by 2 months if the request is complex or if you receive a large number of them, but you must inform the person of this extension within the initial month.

Can I store my customers' data with a US cloud provider?

Yes, but not without precautions. Three possible cases: the country benefits from an official European Commission adequacy decision recognizing an adequate level of protection; failing that, your provider must offer appropriate safeguards (standard contractual clauses in most cases); or, for one-off cases only, a specific derogation applies (explicit consent, performance of a contract...).

Are my website's cookies covered by the GDPR?

Yes. Most cookies (personalized advertising, social media buttons...) require your visitor's prior consent, given freely, and as easy to withdraw as to give. Accepting general terms and conditions does not count as valid consent. A few technical cookies (shopping cart, authentication, language preference) are exempt from this requirement.

What does my company actually risk in the event of a CNIL inspection?

The CNIL generally starts with an inspection (on-site or online) followed by a formal notice to become compliant within a given deadline. Financial penalties do exist but remain proportionate to the size of the organization: the CNIL has, for example, fined small businesses between 2,000 and 20,000 euros for breaches relating to security, cookies or the right of access - far below the maximum ceilings (up to 20 million euros or 4% of worldwide turnover for the most serious breaches).

This FAQ is an educational summary drawn up from the official texts and pages cited above (CNIL). It does not replace a legal reading of the text and does not constitute legal advice.

The GDPR timeline, in plain terms

The GDPR was not born in 2018 and has not stood still since. Here, in order, is what has already happened (and still is the rule today) and what is still under discussion in Brussels - with, for each step, the official text that proves it.

Already in force today

  • The GDPR has applied in full since 25 May 2018 - this is THE date that matters for your obligations.
  • The French "Informatique et Libertés" (data protection) act was updated accordingly (2018).
  • The new standard contractual clauses for transfers outside the EU have been in place since late 2022.
  • The framework for transferring data to the United States (Data Privacy Framework) has been in force since July 2023.

Still under discussion, not yet mandatory

  • A simplification of the record of processing activities (art. 30) for organizations with fewer than 750 employees, proposed by the Commission in May 2025 - not yet a text in force.
  • A regulation to harmonize procedures between national supervisory authorities during cross-border investigations - political agreement reached in June 2025, formal adoption not yet confirmed.
  • Do not rely on these announcements to delay your compliance: the 2018 baseline remains the rule as long as nothing has been published in the Official Journal.
1
27 April 2016

The text is adopted

The European Parliament and the Council adopt Regulation (EU) 2016/679, the GDPR. source EUR-Lex ↗

2
4 May 2016

Official publication

The text is published in the Official Journal of the European Union (OJ L 119, pages 1 to 88). source EUR-Lex ↗

3
24 May 2016

Legal entry into force

The regulation "enters into force on the twentieth day following that of its publication" (art. 99). It exists legally, but its effective application to companies is still deferred by two years - time to get organized. source CNIL, art. 99 ↗

25 May 2018 - KEY DATE

The GDPR applies in full

From this date, all organizations that process personal data of European residents must be genuinely compliant, not just "on paper". This is the date to remember. source CNIL, art. 99 ↗

4
20 June 2018 (France)

French law is updated

Law No. 2018-493 adapts French law to the GDPR and transposes the "police-justice" directive (2016/680), building on the 1978 Data Protection Act ("loi Informatique et Libertés"). source Légifrance ↗

5
12 December 2018 (France)

The 1978 act is entirely rewritten

Order No. 2018-1125 completes the alignment of the Data Protection Act ("loi Informatique et Libertés") with the GDPR and directive 2016/680. source Légifrance ↗

6
24 June 2020

1st European Commission review

Two years after it became applicable, the Commission publishes its first report: the GDPR meets its objectives, but improvements are needed (harmonization between countries, cooperation between authorities). source EUR-Lex (COM 2020) ↗

7
16 July 2020

The "Schrems II" ruling

The Court of Justice of the European Union invalidates the "Privacy Shield" that governed data transfers to the United States: the US safeguards on public authorities' access to data are not considered sufficient. source EUR-Lex ↗

8
27 June 2021 → 27 December 2022

New standard contractual clauses

New model clauses for governing data transfers outside the EU enter into force, with a 15-month transition period to replace contracts already signed. source EUR-Lex (2021/914) ↗

9
10 July 2023

New EU-US framework

The Commission adopts the "EU-US Data Privacy Framework" adequacy decision, which replaces the Privacy Shield invalidated in 2020 and once again secures transfers to certified US companies. source EUR-Lex (2023/1795) ↗

10
25 July 2024

2nd European Commission review

A sharp rise in penalties against large tech companies, but divergences persist between national authorities. The Commission recommends better support for SMEs. source EUR-Lex (COM 2024) ↗

21 May 2025 (ongoing)

Proposed simplification for SMEs

As part of its single market simplification package, the Commission proposes extending to 750 employees (instead of 250) the exemption from keeping a full record of processing activities (art. 30), limited to "high-risk" processing. This is a proposal, not yet a text in force. source European Commission ↗

16 June 2025 (ongoing)

Agreement on common procedural rules

The Council and the European Parliament reach a political agreement on additional procedural rules to harmonize how national supervisory authorities cooperate during cross-border investigations. Formal adoption and publication in the Official Journal remain to be confirmed. source European Commission ↗

Timeline compiled from official sources (EUR-Lex, CNIL, Légifrance, European Commission) consulted on 18 July 2026. The last two steps are proposals or political agreements still in progress - we will update them as soon as they are formally adopted and published in the Official Journal. This is an educational summary and does not constitute legal advice.

GDPR penalties, in plain terms

The scary figure - "20 million euros" - is everywhere, but it does not explain how it actually works. Here, backed by official sources, is who imposes penalties, how, and for what real amounts.

The maximum fine is neither automatic nor the norm

The CNIL has a full scale of measures before reaching a fine, and the actual amount always depends on the severity, the size of the organization and its good faith. The official examples below show it: from 5 000 € for a small business to several tens of millions for a large repeat-offending group.

Up to 10 M €

or up to 2% of the company's total worldwide annual turnover (whichever amount is higher applies).

Tier applicable to "common" breaches: record of processing activities, data security, processor obligations, missing impact assessment...

Up to 20 M €

or up to 4% of worldwide annual turnover (same rule, whichever amount is higher applies).

Tier applicable to the most serious breaches: absence of a legal basis, violation of individuals' rights, unlawful transfers outside the EU...

Who decides? The CNIL's restricted committee

It is not the "general" CNIL that imposes penalties, but a separate, independent body: the restricted committee ("formation restreinte"), made up of 5 members and a chair different from the CNIL's own chair. It alone investigates cases and issues sanctions. The most significant decisions are made public.

What makes the actual amount vary

Article 83 of the GDPR requires the CNIL to take several criteria into account before setting a fine, notably:

  • the severity, nature and duration of the breach
  • whether it was intentional or merely negligent
  • measures already taken to reduce the damage
  • cooperation with the CNIL and prior breaches
  • the categories of data involved

Before the fine: a graduated response (article 58 of the GDPR)

  1. Warning
  2. Reprimand
  3. Formal notice
  4. Compliance order
  5. Administrative fine (art. 83)
Source: CNIL, article 58 of the GDPR (full scale of corrective measures)
Real examples of CNIL sanctions (large groups, to give an order of magnitude)
DateOrganizationAmountGrounds
21/01/2019Google LLC50 M €Lack of transparency, no valid consent for personalized advertising
07/12/2020Amazon Europe Core35 M €Cookies placed without prior consent
31/12/2021Google LLC / Google Ireland150 M €Refusing cookies made more complicated than accepting them
31/12/2021Facebook Ireland (Meta)60 M €Same grounds: refusing cookies made too difficult
17/10/2022Clearview AI20 M €Facial recognition without a legal basis, refusal to cooperate
10/11/2022Discord Inc.800 000 €Excessive data retention, insufficient security and information
15/06/2023Criteo40 M €Breaches relating to cookie consent and individuals' rights

What about a smaller organization? Proportionate amounts

The CNIL also sanctions small and medium-sized organizations, but with amounts far below those imposed on international groups. From the December 2025 decisions alone, examples include: 5 000 € for a hotel management company (non-compliant video surveillance), 7 000 € and 5 000 € for two newspaper publishing companies (invalid cookies), 10 000 € for an airport freight company (unlawful video surveillance), or 20 000 € for a university (purposes not respected). At the other end of the scale, a services-sector company was fined 3.5 M € the same month for a combination of serious breaches (security, transparency, cookies). The amount follows the severity and size, not the other way around.

Source: CNIL, list of sanctions issued (December 2025 decisions)
This section is an educational summary drawn up from the official texts and pages cited above (CNIL, articles 58 and 83 of the GDPR, official list of sanctions issued). The names cited for the major sanctions are those published by the CNIL itself in its press releases. It does not replace a legal reading of the text and does not constitute legal advice.

Your supervisory authority, by country

In Europe, each country has its own authorities. Here, for the 30 countries of the European Economic Area, is the data protection authority (your GDPR contact) and the national cybersecurity authority. Each name links to the official website.

CountryData protectionCybersecurity
GermanyBfDI - Die Bundesbeauftragte für den Datenschutz und die InformationsfreiheitBSI - Bundesamt für Sicherheit in der Informationstechnik (Federal Office for Information Security)
AustriaOsterreichische Datenschutzbehorde (DSB)CERT.at
BelgiumAutorite de la protection des donnees - Gegevensbeschermingsautoriteit (APD-GBA)Centre for Cybersecurity Belgium (CCB)
BulgariaCommission for Personal Data Protection (CPDP)CERT Bulgaria (National Cybersecurity Incident Response Team, State e-Government Agency)
CyprusOffice of the Commissioner for Personal Data Protection (Cyprus Data Protection Authority)Digital Security Authority (DSA)
CroatiaAgencija za zastitu osobnih podataka (AZOP) - Croatian Personal Data Protection AgencyNational Cyber Security Centre (NCSC-HR), operating under the Security and Intelligence Agency (SOA)
DenmarkDatatilsynetForsvarets Efterretningstjeneste (FE) - Cybersituationscenter, national CSIRT (Danish Defence Intelligence Service)
SpainAgencia Espanola de Proteccion de Datos (AEPD)INCIBE - Instituto Nacional de Ciberseguridad (Spanish National Cybersecurity Institute)
EstoniaEstonian Data Protection Inspectorate (Andmekaitse Inspektsioon)Information System Authority (RIA) - National Cyber Security Centre of Estonia (NCSC-EE), heberge CERT-EE
FinlandOffice of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)National Cyber Security Centre Finland (NCSC-FI)
FranceCNIL (Commission Nationale de l'Informatique et des Libertes)ANSSI (Agence Nationale de la Securite des Systemes d'Information)
GreeceHellenic Data Protection Authority (HDPA) - Arkhi Prostasias Dedomenon Prosopikou KharaktiraNational Cybersecurity Authority (NCSA) - Ethniki Arkhi Kyvernoasfaleias
HungaryNemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH) - Hungarian National Authority for Data Protection and Freedom of InformationNational Cyber Security Center of Hungary (NCSC-HU / NKI), operant au sein du Special Service for National Security (SSNS)
IrelandData Protection Commission (DPC)National Cyber Security Centre (NCSC-IE), incluant le CSIRT-IE
IcelandPersonuvernd (Icelandic Data Protection Authority)CERT-IS
ItalyGarante per la protezione dei dati personaliAgenzia per la Cybersicurezza Nazionale (ACN)
LatviaData State Inspectorate (Datu valsts inspekcija)CERT.LV - Cyber Incident Response Institution of the Republic of Latvia
LiechtensteinDatenschutzstelle Fürstentum LiechtensteinCSIRT.LI (Computer Security Incident Response Team Liechtenstein / National Cyber Security Unit)
LithuaniaState Data Protection Inspectorate (Valstybine duomenu apsaugos inspekcija - VDAI)National Cyber Security Centre (Nacionalinis kibernetinio saugumo centras - NKSC)
LuxembourgCommission Nationale pour la Protection des Données (CNPD)Agence nationale de la sécurité des systèmes d'information (ANSSI Luxembourg), sous le Haut-Commissariat à la protection nationale (HCPN)
MaltaOffice of the Information and Data Protection Commissioner (IDPC)CSIRTMalta (Critical Information Infrastructure Protection Unit, Ministry for Home Affairs and National Security)
NorwayDatatilsynetNSM (Nasjonal sikkerhetsmyndighet / National Security Authority) (to be confirmed)
NetherlandsAutoriteit Persoonsgegevens (AP)National Cyber Security Centre (NCSC-NL)
PolandUrząd Ochrony Danych Osobowych (UODO)CSIRT NASK (CERT Polska)
PortugalComissão Nacional de Proteção de Dados (CNPD)Centro Nacional de Cibersegurança (CNCS)
RomaniaANSPDCP - Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (National Supervisory Authority for Personal Data Processing)to be confirmed
SlovakiaUrad na ochranu osobnych udajov Slovenskej republikyNarodny bezpecnostny urad (National Security Authority) - SK-CERT / National Cyber Security Centre
SloveniaInformation Commissioner of the Republic of Slovenia (Informacijski pooblascenec)Government Information Security Office (GISO / URSIV - Urad Vlade RS za Informacijsko Varnost)
SwedenIntegritetsskyddsmyndigheten (IMY) - Swedish Authority for Privacy ProtectionNationellt cybersakerhetscenter (NCSC-SE), rattache a FRA, integre CERT-SE (CSIRT national)
CzechiaUrad pro ochranu osobnich udaju (UOOU) - Office for Personal Data ProtectionNarodni urad pro kybernetickou a informacni bezpecnost (NUKIB) - National Cyber and Information Security Agency

Sources: official authority websites and the EDPB members list (edpb.europa.eu), consulted on 18 July 2026. Data protection authorities confirmed: 30/30. Cybersecurity authorities confirmed: 28/30. The "to be confirmed" notes indicate an official source not yet stabilized as of this date.

Ready to structure your GDPR compliance?

Write to us for an initial scoping session and a personalized quote, with no obligation.

Start my free diagnostic

Free: your score + your gaps. The detailed report and the attestation: 499 EUR excl. VAT, only if you decide to.

contact@syaga.eu
RGPD-Express is an operational support tool. It does not constitute legal advice and does not replace consulting a lawyer or a data protection officer.