GDPR compliance means checking that the processing operations actually carried out by a company comply with the applicable rules and, where they do not, correcting the gaps identified.
The exercise starts from the company’s practices and should make it possible to prioritise the measures to be taken.
Once those first measures are in place, they still have to be kept up to date as tools, providers or practices change.
Would you like to assess the compliance of your data processing? Cabinet Bouchara & Avocats assists companies on GDPR and data protection, from the initial audit through to implementing the necessary measures.
GDPR compliance: the essentials
- The exercise must start from the processing operations actually carried out by the company.
- The record lists the processing operations and drives the action plan. The measures must then be implemented and followed up over time.
- Gaps must be addressed according to their level of risk and how urgent they are.
- The company must keep the material needed to justify its choices and the measures it has put in place.
What does GDPR compliance involve?
GDPR compliance is not about piling up documents. A privacy policy, a cookie banner or a record do not, on their own, establish that a company is compliant.
The analysis covers the processing operations actually carried out: their purpose, their legal basis, the data collected, how long it is kept, its security, but also how individuals are informed, how they exercise their rights, relationships with providers and any transfers to third countries.
The General Data Protection Regulation (GDPR) also requires the company to be able to justify its choices and demonstrate its compliance, in the light of the measures implemented.
How do you assess your company’s level of GDPR compliance?
A GDPR audit is not limited to reading the available documents. It has to test them against actual practice.
The analysis may cover the governance of compliance, the record, the legal bases relied on, retention periods, access rights, security measures, the contracts entered into with providers and data flows to third countries.
An audit often means talking to the HR, marketing, sales, IT or product teams in order to understand how data is really used.
It is common for a company to have an up-to-date privacy policy while still keeping, for example, certain CRM data with no defined retention period.
The audit must therefore lead to an action plan. Each gap should then be matched with an action, an owner and a deadline, starting with the most significant risks.
What are the stages of a GDPR compliance programme?
Define the scope and the owner of the programme
The first step is to define precisely the scope of the audit: the entities concerned, the activities, the tools and the providers. An audit limited to the website would be incomplete if the company also handles customer files, job applications, employee data or prospecting campaigns.
The programme must also have an identified owner, a DPO or an internal contact.
Map the personal data processing
Mapping lists the processing operations linked to the company’s activities: prospecting, customers, recruitment, payroll, suppliers, advertising, AI or online services.
For each operation, the record of processing activities sets out its purpose, the data concerned, the recipients, the retention period and the main security measures.
Check lawfulness and proportionality
Each processing operation must pursue a specified purpose and rest on an appropriate legal basis. Consent is only one of the possible bases.
Under the principle of data minimisation, only the personal data necessary for the purpose pursued should be collected. Retention periods must then be set, individuals informed and able to exercise their rights (articles 5 and 6 of the GDPR).
Assess risks and data security
The analysis covers access rights, authentication, backups, confidentiality, traceability, deletion and incident handling.
These measures must match the risks the processing presents for individuals (article 32 of the GDPR).
Frame providers and data transfers
For each provider, you need to determine its role, check the applicable clauses and identify any sub-processors.
Where there is a transfer to a third country, the company must also know the flow, the destination country and the legal mechanism used to frame it (article 28 and chapter V of the GDPR).
Correct the gaps and keep the evidence
Compliance becomes real when the measures are applied: changing a form, deleting unnecessary data, setting a retention period, restricting access rights, revising a contract or training the teams.
The decisions taken, the files approved and the corrections made must also be documented and kept, so that the measures implemented can be demonstrated.
Vanessa Bouchara’s advice
“A company may have very thorough documentation and still be exposed if its teams do not apply it. The challenge is to make the internal rules match the processing operations actually carried out.”
Vanessa Bouchara, founding lawyer of Cabinet Bouchara & Avocats
Which documents demonstrate GDPR compliance?
The documents needed vary with the processing operations carried out.
| Document or procedure | Purpose |
|---|---|
| Record of processing activities | List and steer the processing operations |
| Information notices | Inform the individuals concerned |
| Data retention policy | Set retention periods and organise deletion |
| Rights request procedure | Handle the requests received |
| Processor agreements | Frame the providers |
| Data breach procedure | Organise the response to an incident |
| DPIA | Analyse certain high-risk processing operations |
| Transfer documentation | Document and frame transfers to third countries |
| Internal policies | Translate the rules into the organisation |
Which documents are needed depends on the processing operations, the risks and the organisation. Each must be kept up to date.
When must a DPO be appointed or a DPIA carried out?
Appointing a DPO is mandatory in particular for public bodies and where core activities involve regular and systematic monitoring on a large scale, or large-scale processing of special categories of data or of data relating to criminal convictions and offences (article 37 of the GDPR).
A DPIA is required where processing is likely to result in a high risk to rights and freedoms. AI, video surveillance or the use of sensitive data are among the factors that may lead to a DPIA, to be assessed in light of the characteristics of the processing and the applicable criteria (article 35 of the GDPR).
How do you maintain GDPR compliance over time?
A record drawn up once and then forgotten quickly loses its usefulness.
A new piece of software, a change of provider, a marketing campaign, a product launch, a new use of AI or a change to a retention period should all prompt a check on the consequences for existing processing operations.
The same applies after a security incident, or where a rights request reveals a difficulty in the internal procedures.
Follow-up therefore means updating the record, reviewing providers and procedures, raising awareness among the teams and building personal data protection into new projects early enough.
When should you call on a lawyer for GDPR compliance?
Some situations call for deeper legal analysis, in particular where there are complex processing operations, sensitive data, several providers or international data transfers.
Cabinet Bouchara & Avocats can then step in to review existing processing, secure contracts, frame data transfers, carry out or support a DPIA, update the documentation or train the teams.
The firm can also act as an outsourced DPO where the company’s organisation warrants it.
Would you like to take stock of your GDPR compliance?
FAQ
Does a very small business have to comply with the GDPR?
Yes. The GDPR applies as soon as a company processes personal data in the course of its business. The size of the organisation is not enough to set aside the obligations of the regulation. The measures to be put in place must, however, be assessed in light of the processing carried out, the data concerned and the risks involved.
Is the record of processing activities mandatory for every company?
Not systematically. Article 30 of the GDPR provides an exception for certain organisations with fewer than 250 employees, but that exception remains narrow. It does not apply where processing is regular, presents a risk to individuals, or involves special categories of data or data relating to criminal convictions and offences.
How long does it take to become compliant?
There is no standard duration. It all depends on the number of processing operations, the state of the existing documentation, the contracts to be reviewed and the teams to be involved. A company that already has an up-to-date record is obviously not in the same position as one that has to rebuild its entire compliance. In every case, the most sensitive points must be dealt with first.
How much does GDPR compliance cost?
The cost depends above all on the scope of the engagement. A one-off audit does not involve the same work as a full programme covering the review of processing operations, contracts, data transfers, any DPIAs or updating the documentation. The budget can therefore only be assessed once the company’s needs have been precisely identified.
Sources
- CNIL, “Bringing my organisation into compliance”
- CNIL, “GDPR: where do I start?”
- CNIL, “The record of processing activities”
- CNIL, “Documenting compliance”
- CNIL, “Personal data security guide”
- Regulation (EU) 2016/679: articles 5, 6, 28, 30, 32, 35 and 37
