GDPR Compliance for Businesses: Guide to Your Obligations

1. Introduction
Achieving GDPR compliance for businesses is not an administrative fashion but a legal obligation with fines of up to 20 million euros or 4% of global annual turnover, and a commercial requirement increasingly demanded by customers and suppliers. Since 2018, the General Data Protection Regulation applies directly across the European Union, and in the United Kingdom it is retained under the UK GDPR alongside the Data Protection Act 2018. However, most SMEs still treat this issue as a pending paperwork task: they do not know which obligations affect them, what deadlines they face or what economic risk they assume. This guide organizes GDPR compliance for businesses by obligations, deadlines and sanctions, with practical examples that any compliance officer can apply directly.
2. The regulatory framework of GDPR compliance for businesses
The GDPR (EU Regulation 2016/679) applies directly in all Member States and establishes the general data protection framework: principles, rights, obligations of controllers and processors, international transfers and the sanctioning regime. In the United Kingdom, the UK GDPR and the Data Protection Act 2018 maintain equivalent obligations with the Information Commissioner’s Office (ICO) as supervisory authority, which applies its own guidance on how it will calculate fines. GDPR compliance for businesses therefore requires knowing the regulation in force in each territory where you operate, because a company that only covers one jurisdiction can breach obligations in another. The guidelines of the EDPB and the national authorities interpret the articles for each sector, so a serious GDPR compliance for businesses program starts from an updated regulatory map, not from generic templates.
Who does GDPR compliance for businesses apply to?
The scope of application is very broad: any company or sole trader that processes personal data of customers, employees, suppliers or users, regardless of size, is subject to the regulation. There is no exemption based on turnover or number of employees: even a business with five workers that manages payroll or a customer database processes personal data and must comply. The first exercise of GDPR compliance for businesses is to identify all existing processing activities, even the ones nobody remembers. The ICO publishes guides, breach notification forms and decision criteria on its official portal, and its sanctioning regime in the UK is governed by Article 83 of the UK GDPR.
3. Main obligations of GDPR compliance for businesses
GDPR compliance for businesses is organized around six blocks of obligations. Reviewing them in order allows you to build a complete compliance program without forgetting any element.
3.1 Processing principles and legal bases
Every processing operation must comply with the principles of Article 5: lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality. Applying these principles is the foundation of any GDPR compliance for businesses program. In addition, each processing activity needs a legal basis under Article 6 (consent, contract, legal obligation, legitimate interest, vital interest or public interest task), which must be documented so it can be demonstrated to the authority.
3.2 Data subject rights
Data subjects have the right of access, rectification, erasure, objection, restriction of processing, portability and, where applicable, not to be subject to automated decision-making. The company must respond to these requests within one month (extendable by two more months in complex cases). Deadlines are the first area audited and the one that generates the most complaints, so automating request handling from the start of GDPR compliance for businesses is strongly recommended. Failure to meet these deadlines is one of the most common and most easily sanctionable infringements.
3.3 Records of processing, DPIAs and the DPO
The controller must maintain a Record of Processing Activities (RoPA), carry out Data Protection Impact Assessments (DPIAs) when processing entails high risk and, in the cases established by the regulation, designate a Data Protection Officer (DPO). Article 35 requires the DPIA before any high-risk processing begins, and the publication of the registry of processing activities is often the first evidence requested by clients and authorities. An incomplete RoPA is, in fact, the most frequently detected documentation infringement in GDPR compliance for businesses.
4. Obligations, deadlines and sanctions: reference table
The following table summarizes the core obligations of GDPR compliance for businesses, the associated deadlines and the sanctioning regime established by Article 83 of the GDPR. Sanctions are calculated on the global annual turnover of the group.
| Obligation (GDPR article) | What the company must do | Deadline | Maximum sanction |
|---|---|---|---|
| Breach notification (Art. 33) | Notify the supervisory authority of incidents posing a risk to rights and freedoms | 72 hours from becoming aware | 10 M EUR or 2% of turnover |
| Communication to data subjects (Art. 34) | Inform affected individuals when the breach poses a high risk | Without undue delay | 10 M EUR or 2% of turnover |
| Records of processing (Art. 30) | Maintain and update the RoPA and be able to demonstrate it | Ongoing; presented upon request | 10 M EUR or 2% of turnover |
| Security measures (Art. 32) | Apply appropriate technical and organizational measures (encryption, access control, backups) | Ongoing and proportionate to risk | 10 M EUR or 2% of turnover |
| Impact assessment (Art. 35) | Prior DPIA for high-risk processing | Before processing starts | 10 M EUR or 2% of turnover |
| Data subject rights (Arts. 15-22) | Handle access, erasure, rectification and other requests | 1 month (extendable by 2) | 20 M EUR or 4% of turnover |
| Processor contracts (Art. 28) | Sign a written contract with providers that process data | Before processing starts | 20 M EUR or 4% of turnover |
| Principles and legal bases (Arts. 5-6) | Process only with a legal basis and in line with the principles | Ongoing | 20 M EUR or 4% of turnover |
As can be seen, the more technical breaches (documentation, security, notifications) are sanctioned with the lower tier, while those that attack the essence of data subjects’ rights reach the maximum tier. The UK regime additionally publishes its enforcement actions, which damage reputation as well as the pocketbook. The full text can be consulted at EUR-Lex, the official portal of the European Union.
5. Record of Processing Activities: practical example
The RoPA is the documentary backbone of GDPR compliance for businesses. It must identify each processing activity, its purpose, the legal basis, the categories of data subjects and data, the recipients, the processors, any transfers and the retention periods, together with the security measures applied. Although the format is free, the supervisory authorities publish templates that make it easier to create. A well-structured RoPA is usually delivered in HTML or spreadsheets; the following example shows the typical structure in a table.
<!-- Record of Processing Activities (Art. 30 GDPR) -->
<table>
<thead>
<tr>
<th>Processing</th><th>Legal basis</th><th>Purpose</th>
<th>Processor</th><th>Security measures</th>
</tr>
</thead>
<tbody>
<tr>
<td>Payroll management</td><td>Art. 6.1.b GDPR (contract)</td>
<td>Employment and tax management</td>
<td>ACCOUNTING EXAMPLE LTD</td>
<td>AES-256 encryption, access control</td>
</tr>
</tbody>
</table>
Fig. 1 – Structure of a RoPA record entry in accordance with Article 30 of the GDPR.
The RoPA is not a static document: it must be updated every time a processing activity changes, a new processor is contracted or security measures are modified. Document management tools make it easier to keep the register alive and provide evidence of GDPR compliance for businesses in every audit. Client audits and supervisory inspections request it as the first piece of evidence, so keeping it up to date is the clearest sign of serious and sustained GDPR compliance for businesses.
6. Data breaches: the 72-hour notification
When a breach occurs (unauthorized access, destruction, loss or alteration of personal data), the clock starts running: breach management is the practical test of GDPR compliance for businesses and requires a documented procedure of detection, containment, risk assessment and notification. Article 33 requires notifying the supervisory authority within a maximum of 72 hours of becoming aware of the breach; if the notification is made later, the delay must be justified. In addition, if the breach poses a high risk to the rights and freedoms of individuals, it must also be communicated to the affected data subjects (Art. 34).

An effective notification procedure has five steps: confirm the incident and gather the minimum information (nature, categories and number of data subjects, measures taken); assess severity; contain the incident; document the whole process in the internal breach register; and draft the notification in line with the requirements of GDPR compliance for businesses. The following template summarizes the information required by the authority.
<!-- Data breach notification template (Art. 33 GDPR) -->
<ul>
<li>Date and time of becoming aware of the breach</li>
<li>Description of the nature of the incident</li>
<li>Categories and approximate number of affected persons</li>
<li>Categories and number of affected records</li>
<li>Measures taken and planned to mitigate it</li>
<li>Recommendations to affected individuals</li>
</ul>
Fig. 2 – Minimum content of a breach notification to the supervisory authority.
Organizations that train their staff and rehearse the notification react in hours; those that improvise, in days. The average breach detection time in SMEs remains high, and every day of delay increases the risk of an additional sanction for late notification. The ICO publishes each year the breaches notified and its enforcement decisions, a free source to calibrate the real risks of GDPR compliance for businesses. Every day of delay increases the risk of an additional sanction for late notification, and that is why internal training and an annual drill are investments that pay off in GDPR compliance for businesses far more than any template stored in a drawer.
7. Conclusion
GDPR compliance for businesses is a continuous program, not a one-off formality: documented legal bases, operational rights, an updated RoPA, proportionate security measures and a rehearsed breach notification procedure. The deadlines are strict and the sanctions, at the upper tier, can compromise the viability of a business, so GDPR compliance for businesses leaves no room for improvisation. However, the effort has immediate returns: clients and large suppliers demand evidence of compliance in their audits, and companies that demonstrate it close contracts that others lose. Privacy, in the end, is a brand asset that is built with GDPR compliance for businesses day by day.
Related articles: data protection legislation and risk analysis and risk analysis for companies with MAGERIT.
At Jaymon Security we help companies achieve GDPR compliance for businesses with practical methodologies, from risk analysis and the RoPA to breach management and relations with the supervisory authority.
Need help with GDPR compliance for businesses?
At Jaymon Security, we help organizations protect their systems. From security audits to SIEM/SOC implementation, our expert team designs custom solutions.
Contact us for a free infrastructure assessment.

