GDPR compliance often “looks” solved because there is a privacy policy on the website or because some template has been signed. In practice, most risk arises in operational processes: HR, sales/marketing, IT, suppliers and security incidents.
Below are the most common mistakes that recur in small and medium enterprises and startups – and what to do to correct them quickly and sensibly.
1. Unclear or wrong legal basis for processing
One of the most common mistakes in practice is trying to cover everything with “consent”, even when it is unnecessary (or the consent is invalid). Consent is only one of six possible legal bases for processing data.
Besides consent, the legal bases for processing personal data are:
- fulfilment of contractual obligations or actions prior to entering into a contract
- compliance with the controller’s legal obligations
- protection of the vital interests of the data subject or another natural person
- processing necessary for the performance of a task carried out in the public interest or the exercise of official authority
- legitimate interest
To avoid this mistake, it is necessary to map the data processing activities and determine the legal basis (contract, legal obligation, legitimate interest, consent). Consent should be used selectively and demonstrably.
2. Privacy policy not aligned with actual processes
A common mistake is a privacy policy composed as a generic text that does not describe the actual purposes, retention periods, recipients and data subject rights. Privacy policies are often created by copying and pasting templates, and they do not reflect the business or the actual activities of processing personal data.
To avoid this mistake, you should update the notices across channels (website, app, HR, etc.) and align them with records of processing.
3. No record of processing activities (ROPA)
Although not all controllers are obliged to keep a record of processing activities, in practice it has often been shown that even those who have the obligation do not keep it or keep it incorrectly.
It is recommended to keep a record of processing activities even if you are not required to under the GDPR, because it is one of the key documents with which you can demonstrate compliance.
At a minimum, it is advisable to introduce a record that includes:
- Purpose
- categories of data
- recipients
- transfers
- retention periods
- security measures.
4. Contracts with processors (Data Processing Agreement – DPA) are missing or poor
In practice, it often happens that service providers are used without a DPA or with a DPA that does not cover the obligations under the GDPR. Control of processors is particularly important because the controller has to engage only processors that provide sufficient guarantees that they implement appropriate technical and organisational measures so that processing meets the requirements of the GDPR – including processing security – and ensures protection of the rights of data subjects.
It is recommended to introduce agreements with processors, check sub‑processors and cross‑border transfers, otherwise strict penalties may apply.
5. Retention periods are not defined
Keeping personal data “forever” when not necessary is contrary to the purpose and aim of the GDPR. The Regulation emphasises that personal data should be adequate, relevant and limited to what is necessary for the purposes of processing. Therefore, it is necessary to ensure that the storage period is limited to the strict minimum.
The controller should set a deletion period or conduct periodic reviews and take reasonable steps to rectify or delete inaccurate personal data.
Although the GDPR does not prescribe specific retention periods, they are defined in separate laws depending on the category (e.g., accounting, HR).
6. Unrecognised DPIA obligation (Data Protection Impact Assessment)
A Data Protection Impact Assessment (DPIA) is a process designed to:
- describe the processing activities
- assess their necessity and proportionality
- manage risks to the rights and freedoms of individuals
The GDPR requires a DPIA to be carried out in cases of:
- fully automated decision-making, including profiling
- large-scale processing of sensitive data
- systematic monitoring of publicly accessible areas (Art. 35(3))
DPIA is also important from an accountability perspective, as it helps controllers ensure compliance with the Regulation and demonstrate that appropriate measures have been implemented. The assessment must be carried out prior to processing, in line with the principles of data protection by design and by default.
7. Data subject rights handled ad hoc and poor preparation for data breaches
When data subject requests are not properly recognised or responses are delayed, organisations act contrary to data protection rules. In such cases, individuals may turn directly to the supervisory authority and file a complaint, which may lead to an investigation and — if the complaint is justified — sanctions.
If individuals suffer damage due to processing that is not compliant with the GDPR, they are entitled to compensation for both material and non-material damage from the controller or processor. Such proceedings are conducted before competent courts.
It is strongly recommended to establish clear channels and processes for handling data subject requests and complaints, including:
- defined timelines
- proper identification procedures
- handling of exceptions
- record-keeping
- incident logs
- tracking reporting deadlines and related steps in case of a data breach