Centre de ressources  >GDPR 2026: business obligations and compliance action plan
Regulations

GDPR 2026: business obligations and compliance action plan

GDPR 2026: obligations, penalties, register, rights, subcontractors. Priorities for SMEs/mid-caps and a simple method for achieving compliance.

Julie Thomas
Publié le  
October 1, 2026
Mis à jour le  
10/1/2026
Photos de bureaux et un logo validant notre expertise EcoVadis
Sommaire
Obtenir un résumé

GDPR is still here… and it’s never been more important than in 2026. Between stricter enforcement, increasingly demanding customers, and the arrival of new rules like the AI Act and NIS2, managing personal data has shifted from an administrative burden to a real strategic advantage.

For SMEs and mid-sized companies, the question is no longer "should we do it?" but rather "how do we do it efficiently without spending months on it?" Because let’s be honest: GDPR can quickly become a headache without the right guidance.

Good news: you don’t need to be a lawyer to make progress. In this article, we offer a simple, pragmatic approach to understanding what really matters in 2026, prioritizing the actions that help you move forward quickly, and identifying the right partners to lean on when needed.

‍

GDPR: Definition, goals, and affected businesses

‍

The GDPR is a European regulation that governs all processing of personal data carried out within the European Union. Its goal: to protect individuals while holding companies accountable for how they use that data.

In practical terms, personal data is any information that can identify a person, either directly or indirectly (name, email, phone number, IP address, etc.). As soon as you handle this type of information, you fall under the scope of the GDPR.

You are affected if you:

• Have customers or prospects (CRM, email marketing, quotes…)

• Manage employees or job applicants (HR, payroll, recruitment)

• Use digital tools (websites, software, SaaS tools…)

In reality: the GDPR applies to every business, regardless of size or industry. And today, it’s no longer just a regulatory requirement: it has become a true mark of professionalism expected by your customers, partners, and stakeholders.

‍

GDPR: What you really need to master in 2026

‍

1. Identify your data processing activities

Even before talking about compliance, there is one key step: understanding exactly what you do with the data. A processing activity is any use of personal data, whether automated or not. And in reality… that covers a large part of your daily operations.

We’re talking about:

• Your CRM (managing prospects and customers)

• Your HR (recruitment, payroll, personnel management)

• Your Marketing (emailing, advertising campaigns)

• Your IT tools (logs, security, business software)

In other words: data is everywhere. And that is exactly why this first step is essential. The goal is to get a clear, structured, and comprehensive view of your usage. Who collects what? Why? Where is the data stored? Who has access to it?

Without this mapping, it’s hard to see the big picture… and even harder to stay truly compliant.

‍

2. Legal bases & information

Once your processing activities are clearly identified, it’s time for the basics. And there are no shortcuts here: GDPR is built on a foundation of non-negotiable principles.

Every data processing activity must tick several essential boxes:

• Have a clear and legitimate purpose (you don’t collect data “just in case”)

• Be based on a solid legal foundation (consent, contract, legitimate interest, etc.)

• Collect only the data that is strictly necessary

• Define a consistent retention period (not too short, not forever)

• Ensure a level of security appropriate to the risks

• Inform the individuals concerned in a clear and transparent way

Every piece of data you handle must have a reason to exist… and be treated with rigor at every stage of its lifecycle.

These principles are the heart of your compliance. If one of them is missing, your entire approach loses its foundation.

‍

3. Data subject rights

GDPR isn’t just about regulating companies; it’s primarily about empowering individuals. And you need to be ready to handle that power effectively and without friction.

In practical terms, anyone whose data you process can exercise several rights:

• The right to access their data

• The right to rectification

• The right to erasure (the famous “right to be forgotten”)

• The right to object

And this isn’t optional: you have a maximum of one month to respond to these requests. On paper, it might seem simple. In reality, without the right organization in place, these requests can quickly become time-consuming… or even critical.

The key? Anticipation.

Setting up clear internal processes, identifying the right points of contact, centralizing requests, and structuring your responses are all habits that will allow you to handle these rights seriously—without disrupting your teams.

Because beyond compliance, it also sends a strong signal to your customers: you take their data (and their rights) seriously.

‍

4. Structuring your compliance (the part that often gets people stuck)

This is usually where things get tricky. Once you’ve grasped the principles, you need to take action and structure your compliance in a concrete way. It’s an essential step… but also the most demanding one.

It involves, among other things, setting up:

• An up-to-date and usable record of processing activities (a mandatory document)

• Clear internal procedures (rights management, retention periods, etc.)

• A system for managing data breaches and incidents

• Comprehensive documentation that can demonstrate your compliance

In practice, this is often where companies slow down. Why? Because GDPR is frequently approached in a way that’s too theoretical, with few concrete benchmarks for moving to the operational stage.

The result: projects that drag on, incomplete documents… and compliance that’s difficult to manage over the long term.

The right approach is to structure things gradually, with method and pragmatism. The goal isn’t to be perfect from the start, but to be clear, consistent, and able to demonstrate your efforts.

To make your life easier, here is a GDPR checklist of the essentials to check: it lets you see where you stand in 5 minutes, then prioritize the actions that really matter.

➡️ Download the checklist for free

‍

5. Managing risks (cyber, service providers, incidents)

GDPR isn’t limited to fixed rules: it also requires a genuine risk-based approach. In other words, it’s not just about checking boxes, but about anticipating, assessing, and managing sensitive situations.

This means:

• Notifying the competent authority of any data breach within 72 hours

• Strictly managing your subcontractors (compliant contracts, sufficient guarantees)

• Secure data transfers outside the European Union using appropriate mechanisms

It’s a dimension that’s sometimes less visible… but absolutely strategic.

By 2026, with the widespread use of SaaS tools and intensifying cyber threats, risk management has become a major point of focus.

The right approach is no longer to be reactive, but to become proactive: identify weak spots, secure them in advance, and be ready to react quickly in the event of an incident.

‍

GDPR penalties and business risks

Sanctions RGPD et risques business en 2026

The GDPR provides for significant penalties for non-compliance, which can reach up to:

• A €20 million fine or 4% of total worldwide annual turnover

• Criminal penalties in certain cases

• Reputational damage that is hard to recover from

On a daily basis, risk also plays out in other ways:

• A loss of trust from your clients and partners

• Business opportunities slipping through your fingers (especially during tender processes)

• Increasingly stringent requirements from major accounts, who expect concrete guarantees

A non-compliant company can quickly find its growth held back… even without a CNIL audit.

The GDPR is therefore no longer just a regulatory constraint. It has become a sign of maturity, almost a prerequisite for doing business with peace of mind.

‍

GDPR + AI Act + NIS2: how to coordinate without getting everything mixed up

‍

In 2026, it is part of a much broader regulatory ecosystem that is constantly evolving and clearly more demanding.

Among the regulations to keep in mind:

• AI Act : regulation of artificial intelligence based on a risk-based approach

• NIS2 : significant strengthening of cybersecurity requirements

• Data Act : new rules for data access and usage

• Digital Omnibus (in progress) : a shifting framework with impacts to anticipate

The bar is being raised for everyone. Today, it’s no longer just about protecting personal data. Companies have to navigate a broader landscape that includes cybersecurity, data governance, and the use of technologies like AI.

The playing field is expanding, and so are the expectations. In this context, GDPR becomes a solid foundation upon which all new obligations that you need to anticipate are built.

‍

A pragmatic approach: moving forward without getting overwhelmed

‍

On paper, GDPR seems simple. In reality, what holds companies back is very often a lack of method: you launch initiatives in every direction, produce documents, and compliance becomes impossible to manage.

The most effective approach in 2026 is to move forward in stages, with a clear goal: being able to demonstrate consistent, prioritized compliance that is tailored to your risks.

‍

Step 1 — Define the scope and appoint a lead

First things first, designate a point person, even if part-time, and clarify:

• Which activities/entities are covered,

• Which tools are involved (CRM, HR, email, support, business software, service providers),

• What are the 2–3 priority issues (e.g., prospecting, recruitment, cybersecurity, SaaS).

‍

Step 2 — Map your data processing

The record of processing activities isn't just a file to fill out to check a box: it’s your dashboard.

The idea is to get a clear view of:

• Who collects what data,

• For what purpose,

• On what legal basis,

• Where the data is stored,

• Qui y accède,

• How long you keep them,

• Which subcontractors are involved.

Goal: a usable register, that’s easy to understand and, most importantly, easy to maintain over time.

‍

Step 3 — Prioritize based on risk

Effective compliance isn’t one-size-fits-all. You need to focus your efforts where the impact is greatest:

• Large data volumes,

• Sensitive data,

• Exposed processing activities (websites, forms, prospecting),

• Dependency on cloud/SaaS providers,

• Cyber risks / incidents.

Goal: a realistic GDPR roadmap (30 / 60 / 90 days) with high-impact actions.

‍

Step 4 — Secure the visible basics

In practice, this is often where companies get caught out: the "basics" aren't formalized or aren't being followed.

Top priorities to secure:

• Informing individuals (disclaimers, privacy policy, internal notices),

• Legal bases (and ensuring consistency between "purpose ↔ legal basis ↔ retention period"),

• Rights management (process + deadlines + tracking),

• Managing subcontractors (clauses/DPA + responsibilities),

• Breach management procedure (who does what, when, how, and proof).

Goal: quickly reduce your exposure (to sanctions, reputation damage, and business disruption).

‍

Step 5 — Establish a GDPR routine

GDPR isn't a one-off project; it's a matter of governance. Without a basic routine, everything becomes outdated.

Examples of simple routines:

• Quarterly register review,

• Biannual check-in on service providers / new tools,

• Onboarding process for new tools (GDPR "by design" check),

• Targeted awareness training (HR, marketing, sales, IT).

Goal: stay compliant without having to restart the whole project every 12 months.

‍

When to get help and why it saves time

‍

Getting help doesn't mean outsourcing everything. In reality, the fastest-moving companies often take a hybrid approach:

• In-house, you keep control and operations: you know your tools, your teams, your processes, and your business priorities.

• Externally, you rely on specialized expertise to secure the most sensitive areas and the ones that waste the most time: choosing legal bases, managing subcontractors, transfers outside the EU, drafting notices/clauses, and making decisions when in doubt.

Result: you avoid endless back-and-forth, hesitant decisions, and weak documentation. You move faster, with stronger compliance that's easier to defend if a client, partner (or the CNIL) challenges you.

‍

To go further: replay of the Altopi x Tada Conseil webinar

For a step-by-step explanation—including the terminology, key pillars, and concrete benchmarks for prioritizing—check out the replay of the webinar co-hosted with Tada Conseil.

➡️ Watch the webinar replay

‍

RGPD obligations des entreprises en 2026

‍

Your company's sustainable performance