GDPR in practice: what your SME really needs to do in 2025

Beyond theory, here are the concrete actions your SME must implement to be truly GDPR compliant. GDPR, 7 years on: where are you?: In force since May 2018, GDPR is often seen as a distant administrative constraint. Yet the CNIL is intensifying SME inspections and fines are increasing. In 2024, 42% of CNIL sanctions targeted structures with fewer than 250 employees. The 5 fundamentals to check: 1) Processing register: have you documented what data you collect, why, and how long you keep it? 2) Consent: do your forms collect explicit, granular consent? 3) Sub-processors: do you have GDPR clauses in your contracts? 4) Data subject rights: can you respond to an access or deletion request within 30 days? 5) Security: is your data encrypted and backed up? GDPR and AI: the new challenge: Using AI tools adds complexity: where does data injected into ChatGPT go? Does your CRM's predictive scoring constitute profiling? The AI Act and GDPR complement each other. Tools to simplify compliance: Several open source tools facilitate compliance: online processing registers, privacy policy generators, consent solutions. At Powehi, we integrate GDPR compliance from the design stage (privacy by design).

Key takeaways

  • 42% of CNIL sanctions target SMEs
  • 5 fundamentals: register, consent, sub-processors, rights, security
  • AI complicates GDPR compliance
  • Privacy by design = native compliance
  • A GDPR audit complements the maturity diagnostic