In brief: Implementing the GDPR in an SME is not a year-long project, it can be done in a few structured steps, provided you work with the reality of the business rather than against it. This roadmap draws on around 30 implementation projects since 2018, from medical practices to education providers.

Step 1: Take stock, what happens to which data?

Half a day with the right questions: which personal data enters the company (customers, employees, suppliers), where is it stored, who has access, which tools are in use? The result is the map for everything that follows.

Step 2: Create the records of processing activities

The records of processing activities (Art. 30 GDPR) are mandatory, and at the same time the most useful document of the entire project: for each processing operation, purpose, legal basis, categories, recipients and deletion periods sit in one place. Done well, it answers 80% of all questions that come up later.

Step 3: Clarify the legal bases

Most SME processing operations rest on contract (Art. 6(1)(b)), legal obligation (point (c)) or legitimate interest (point (f)). Consent is needed less often than many believe, and where it is, it must be documented and revocable.

Step 4: Put your processors under contract

Hosting, email, accounting software, cloud storage: anyone processing personal data on your behalf needs a data processing agreement (Art. 28). For providers outside the EU, check in addition: adequacy decision or standard contractual clauses.

Step 5: A privacy policy that matches the website

The most common weak point: boilerplate text describing services that don't (or no longer) exist on the website, or the other way round. The policy must reflect the actual state of affairs: services in use, purposes, legal bases, data subject rights, and the complaint route to the data protection authority.

Step 6: Technical and organisational measures (TOMs)

Encryption, access controls, backups, password rules, handling of mobile devices, documented and appropriate to the risk. For an SME, what counts is traceability, not perfection.

Step 7: Train your staff, short, specific, repeated

Most data breaches are everyday mistakes. A compact training session built around cases from your own business achieves more than any policy sitting in a binder. Since 2025/26, AI topics belong here too: what employees may enter into AI tools and what they may not, think AI Act and transparency obligations.

Conclusion

GDPR for an SME means: set it up properly once, document it leanly, update it annually. The effort is manageable, the alternative (a complaint, a data breach without processes in place, lost trust) is not.

Frequently asked questions about GDPR for SMEs

When does the GDPR apply to my company?

As soon as personal data is processed, meaning customer, employee or supplier data. There is no minimum headcount: sole traders are covered too.

Are records of processing activities mandatory for SMEs?

Yes. The records of processing activities under Art. 30 GDPR are mandatory in principle. The exemption for businesses under 250 employees almost never applies in practice, because regular processing such as customer and staff data cancels it out.

When do I need a data processing agreement?

Whenever a service provider processes personal data on your behalf, for example hosting, email, accounting software or cloud storage. The legal basis is Art. 28 GDPR; for providers outside the EU, also check an adequacy decision or standard contractual clauses.

What belongs in a website privacy policy?

The services actually in use, their purposes and legal bases, the data subject rights and the route for complaints to the supervisory authority. It must reflect the real state of the site, not boilerplate for services that are not there.

How long does GDPR implementation take in an SME?

It is not a year-long project. With a clean inventory and a few structured steps the core is achievable in a manageable time; after that, an annual update is enough.

Note: This article is a practitioner's assessment and does not constitute legal advice for an individual case.