Guide · July 2026

GDPR for SMEs: the 10 things that must actually exist

Eight years after GDPR came into force, most small Greek businesses sit in the same spot: a privacy policy on the website, and little else behind it. The checklist below is what an inspection or a complaint would actually look for — in the order we would fix it.

1

Map your data

What personal data do you hold, where did it come from, where is it stored, who accesses it? One honest afternoon of mapping is the foundation of everything else.

2

Records of processing (art. 30)

The register of processing activities. The “under-250-employees” exemption is far narrower than people think — if you process customer or employee data systematically, you need it.

3

A legal basis for every use

Contract, legal obligation, legitimate interest, consent. Consent is the last resort, not the default — and marketing without a proper basis is the most common complaint trigger.

4

Privacy notices that say the truth

Your website and forms must state clearly what you collect and why. Copy-pasted policies mentioning services you do not use are evidence against you, not for you.

5

Cookies done properly

Real consent before non-essential cookies fire — the Greek DPA (ΑΠΔΠΧ) has issued specific guidance and has fined for “cosmetic” banners.

6

Contracts with your processors

Accountant, IT support, cloud, courier, email platform: whoever touches your data needs a data-processing agreement (art. 28).

7

Access control & security

Named accounts, passwords managed properly, MFA where possible, laptops encrypted, access removed when people leave. Article 32 in one sentence.

8

A breach plan (72 hours)

Know in advance who assesses, who decides, and how you notify the DPA within 72 hours. Improvising this during an incident is how deadlines get missed.

9

Answering data-subject requests

Access, erasure, portability — you have one month. You need to know where the data lives to answer at all (see point 1).

10

Training the team

Most breaches start with an email. Short, regular awareness beats a one-off seminar with a certificate of attendance.

The 3 myths that cost the most

“GDPR doesn’t apply to small businesses”

It applies from one employee up. Small size can mean lighter documentation — never exemption.

“I bought a privacy policy, I am compliant”

A policy describes compliance; it does not create it. If practice differs from the text, the text makes things worse.

“Nobody checks anyway”

The Greek DPA acts mostly on complaints — ex-employees and unhappy customers file them. Fines reach 4% of turnover or €20m, and small businesses have been fined in Greece.

Do you need a DPO?

Mandatory when your core activity involves large-scale systematic monitoring or large-scale processing of special categories (health, biometrics) — clinics, diagnostic centres and some platforms typically qualify; the average commercial SME does not. When it is needed, the role can be an external service, which is usually the practical option at small scale. Our GDPR & NIS2 services →

Want to know where you stand on the 10 points? The free assessment gives you a gap picture in plain language — and a fix order that respects your budget.

Free Assessment

Start your journey to certification

Book a free initial assessment. We will analyse your needs and recommend the optimal standard and timeline.