GDPR compliance for companies: what you need to know
GDPR fines can reach up to 4% of annual global turnover, but for most companies the real risk isn’t a record fine. It’s the loss of customer trust after a poorly handled security incident. GDPR compliance isn’t a form filled out once, it’s a set of processes a company keeps running.
What GDPR compliance means for a company
In practice, it means the company knows exactly what personal data it collects, why, for how long it keeps it, who has access to it, and what happens if a security breach occurs. Company size doesn’t matter: if it processes data belonging to employees, customers or suppliers, GDPR obligations apply.
The basics of a compliance programme
- A record of processing activities: the document describing what data is collected and for what purpose;
- Up-to-date privacy policies, aligned with the company’s actual practices;
- Data processing agreements (DPAs) with vendors and partners who access personal data;
- Breach notification procedures, with strict reporting deadlines;
- Mechanisms for exercising data subject rights (access, rectification, erasure).
The risks of non-compliance
Beyond fines from the supervisory authority, a non-compliant company risks claims from affected individuals, strained relationships with partners who require contractual compliance guarantees, and, often the most costly outcome, reputational damage after a public incident.
How a law firm for companies helps
At Sabău Avocați, our compliance & regulatory team audits existing practices, drafts the required documentation and trains internal teams. We work with our law firm for companies team on constitutive documents and contracts affected by compliance requirements, and for the company’s broader legal strategy, see also our business lawyer page.
Frequently asked questions
Does every company need a data protection officer (DPO)?
No. A DPO is mandatory only for certain categories of data controllers, for example those processing data at large scale or special categories of data. Many small companies can manage compliance without a dedicated DPO.
How long does it take to implement a GDPR compliance programme?
For a medium-sized company, between 4 and 8 weeks, depending on how complex the processes are and how well documented current practices already are.
What if we already have an undisclosed data breach?
We recommend immediate legal advice: under certain conditions, notifying the authority within 72 hours can significantly reduce the risk of penalties.