Back to blogCompliance

GDPR: the most common mistakes made by SMEs

NRNicolas Renard·June 3, 2025· 11 min read

GDPR applies to any organization that processes personal data, regardless of its size. The CNIL, the French authority responsible for enforcing it, regularly points out in its inspections that compliance is not limited to a consent banner on a website, contrary to a belief widespread among many SMEs.

The most common mistakes

Two colleagues signing a document near a laptop, illustrating GDPR compliance work
  • Not keeping a record of processing activities, even though it is mandatory as soon as personal data is processed.
  • Retaining data indefinitely, with no defined retention period.
  • Confusing consent with legal basis: not every processing activity requires explicit consent.
  • Not contractually governing subprocessors who process data on the company's behalf.
  • Ignoring data subject rights (access, rectification, erasure), for lack of an internal process to handle them.
  • Having no procedure to notify a data breach.

What GDPR concretely requires

ObligationWhat it involves
Record of processing activitiesDocumenting each processing activity: purpose, data collected, retention period, recipients
Legal basisIdentifying the legal basis for each processing activity (consent, contract, legal obligation, legitimate interest)
Data securityImplementing technical and organizational measures proportionate to the risks
Data subject rightsAllowing access, rectification and erasure requests to be handled within one month
Breach notificationNotifying the data protection authority within 72 hours for a personal data breach presenting a risk

How to structure your compliance effort

  1. Map the personal data processing activities carried out by the organization.
  2. Identify high risk processing activities, which may require an impact assessment.
  3. Formalize a record of processing activities and keep it up to date.
  4. Set up a procedure to handle data subject rights requests.
  5. Train the teams who handle personal data on a daily basis.

What CNIL sanctions reveal

In its 2024 report, the CNIL issued 87 sanctions for a combined total of €55.2 million, compared with 42 sanctions totaling around €90 million in 2023 (a year marked by one isolated record fine). It also received 17,772 complaints, a record level, and 5,629 data breach notifications, up 20% year over year. Telecoms, web and social media account for 49% of complaints received, ahead of retail (19%) and the workplace sector (13%). The top ground for sanction under the simplified procedure: failure to cooperate with the CNIL during an investigation, ahead of failure to honor data subject rights.

These figures illustrate a point SMEs often underestimate: most of the CNIL's enforcement activity targets simple procedural failings that are easy to fix (no response to a complaint, missing record of processing, lack of cooperation), not headline-grabbing mass data leaks. The most spectacular sanctions, meanwhile, target players of a very different size: Meta was fined €1.2 billion by the Irish data protection authority in 2023 over non-compliant data transfers to the United States, then an additional €251 million in 2024, bringing its five-year cumulative total to €2.2 billion. In France, the CNIL fined Amazon.fr €35 million on 23 January 2024, for advertising cookies dropped without consent and excessive video surveillance of warehouse staff. These cases are a reminder that compliance is not limited to the cookie banner, precisely where many SMEs concentrate most of their effort.

GDPR Diagnostic·See a diagnostic preview

Best practices to put in place before an inspection

  • Systematically respond to every complaint or request from the CNIL within the deadline, even minor ones: failure to cooperate is the top ground for sanction under the simplified procedure.
  • Test the data breach notification procedure at least once a year, rather than discovering it does not work on the day of a real incident.
  • Audit the consent banner and the cookies actually dropped before any click, not just their formal presence.
  • Train customer-facing teams to recognize a data subject rights request, which is often phrased without precise legal wording.
  • Review the record of processing activities with every new project involving personal data, not just once a year.

GDPR penalties can reach deterrent amounts, but the CNIL focuses its inspections on the most serious or most reported failings, as it states in the control priorities it publishes each year. The most concrete risk for an SME is often not a formal inspection but a poorly handled data breach, with the resulting loss of customer trust. That angle, more tangible than an abstract threat of sanctions, is what justifies measuring the gap between current practices and the regulation's requirements, domain by domain.

Ready to assess your organization?

Try for free