GDPR compliance: checklist and 7 key documents
A practical GDPR guide for SMEs and the self-employed: what to do, which documents you need, and a concrete checklist to avoid sanctions.
Karoline, Dokumentkonsulent
The GDPR is not only for large companies
It is a persistent myth: "We are too small for the GDPR to apply to us." That is wrong. The GDPR applies to all businesses, organisations and self-employed people who process personal data, regardless of size.
Do you process customer data? Do you have employees? Do you use a CRM system, a newsletter or cloud storage with personal data? Then the GDPR is relevant to you.
The good news is that compliance does not require a team of lawyers. With the right documents and a basic understanding of the rules, even a solo self-employed person can become compliant in a short time.
What happens if you are not compliant?
The GDPR operates with fines of up to EUR 20 million or 4% of global turnover, which is the EU maximum. In Denmark the fines are not issued by Datatilsynet directly; Datatilsynet files a police report, and the fine is imposed by the courts. For SMEs and the self-employed the fines are typically far lower, but they can still hurt:
- Fines in the order of DKK 10,000 to 500,000 for smaller businesses are not uncommon
- Orders to stop certain processing, which can paralyse your business
- Damage to reputation, because customers and partners react
In recent years Datatilsynet has had a particular focus on, among other things, missing data processing agreements, unlawful disclosure of personal data and missing deletion routines.
The 7 most important GDPR documents for SMEs
1. Record of processing activities
You need an overview of which personal data you process, for which purposes, and who has access to it. This is your GDPR journal. It does not have to be long, but it has to exist.
What should it contain?
- Categories of data subjects (customers, employees, suppliers)
- Types of data (name, email, CPR number, etc.)
- The purpose of the processing
- Who the data is shared with, if anyone
- Deletion deadlines
2. Data processing agreement
This is the single most important document for most SMEs.
A data processing agreement must be entered into with all suppliers that process personal data on your behalf. This typically includes:
- An accounting program (for example Dinero, Billy, e-conomic)
- A payroll system
- A CRM system (for example HubSpot, Pipedrive)
- Email marketing (for example Mailchimp, Klaviyo)
- Cloud storage (for example Google Drive, Dropbox, Microsoft 365)
- Web booking systems
- A phone service with recording
If you do not have these agreements in place, you are by definition not compliant.
3. Privacy policy
If you have a website that collects data (a contact form, newsletter, cookies), you must have a privacy policy. It must explain:
- Which data you collect
- What you use it for
- Who you share it with
- How long you keep it
- What rights the data subjects have
4. Cookie policy and consent
If your website uses cookies for tracking, statistics or marketing, you must have:
- A cookie policy explaining which cookies you use
- A consent banner that obtains active acceptance (not just "by using the site you accept")
Note: cookie consent must be opt-in, not opt-out.
5. Consent texts and sign-up flows
If users sign up for your newsletter or other marketing, the consent must:
- Be voluntary and specific
- Be obtained with a clear action (a checkbox that is not pre-ticked)
- Be stored with a timestamp
6. Security policy (internal)
You do not need a 50-page IT security policy. But you must be able to document that you handle data securely. A simple internal note is enough for most SMEs:
- A password policy
- Who has access to which systems
- A procedure for a security breach (what you do and who you contact)
7. Data-breach procedure
If personal data is leaked, whether it is a hacked email, a lost USB stick or a wrong send, you must notify Datatilsynet within 72 hours if the breach entails a risk to the data subjects.
You should have an internal procedure for:
- What counts as a data breach?
- Who decides whether it is notified?
- Who notifies Datatilsynet?
GDPR checklist: are you compliant?
Use this checklist to find gaps in your GDPR compliance:
Basis for processing:
- Do you have a valid basis for each purpose (consent, contract, legal obligation, legitimate interest)?
- Is the basis documented?
Data processing agreements:
- Have you entered into data processing agreements with all relevant suppliers?
- Are the agreements signed and up to date?
Information to data subjects:
- Do you have a privacy policy on your website?
- Do you inform customers about what you do with their data?
Consent:
- Have marketing consents been obtained correctly?
- Have you stored documentation of the consent?
Deletion:
- Do you have a policy for how long you keep personal data?
- Do you actually delete data that is no longer relevant?
Cookies:
- Do you have GDPR-compliant cookie consent on your website?
- Is your cookie policy up to date?
Security:
- Is access to systems with personal data properly managed?
- Do you have a procedure for security breaches?
Record:
- Do you have a record of processing activities?
Five typical GDPR mistakes in SMEs
1. No data processing agreement with the accounting program. Dinero, Billy and e-conomic process personal data on your behalf. Without a data processing agreement you are not compliant, even if the provider is GDPR-compliant. Most software providers offer a standard data processing agreement on their website. Find it, enter into it, and save it.
2. "Consent" via a pre-ticked checkbox. A consent is only valid if it is actively given. A pre-ticked checkbox for a newsletter is invalid consent. It is one of the most frequent mistakes and easy to fix.
3. Deletion deadlines that exist only on paper. Many businesses write in the privacy policy that data is deleted after three years but do not do so in practice. Datatilsynet looks at the actual behaviour, not just at what the policy says.
4. Processing CPR numbers without a basis. CPR numbers are specially protected in Danish law and require a specific processing basis. Use them only when necessary (for example for employment, tax and pension).
5. Failure to notify a breach. Many businesses do not notify data breaches to Datatilsynet, either because they do not know they must or because they fear the consequences. Failure to notify is typically a separate breach.
The GDPR and employees
If you employ staff, you process personal data about them: pay data, sick leave, evaluations and contact details. This requires:
- That the employees are informed about the processing (typically in the employment contract or a separate privacy policy for staff)
- That you store the data securely and only for as long as necessary
- That you have a basis for especially sensitive data (for example health data on illness)
It is good practice to include information about the data processing in the employment contract or as an appendix.
When do you need a DPO?
A DPO (data protection officer) is only mandatory for certain types of business:
- Public authorities
- Businesses whose core activity is systematic monitoring on a large scale
- Businesses that process special categories of sensitive data on a large scale
Most SMEs do not need a DPO. But consider an external GDPR consultant for an initial review if you are in doubt.
Getting started
Start with the most important thing: get your data processing agreements in order with the suppliers that process data on your behalf, ensure an updated privacy policy and valid cookie consent, and introduce fixed deletion routines. That is where the risk is greatest for most SMEs, and the solution is within reach.
Related templates
This article is for general guidance only and is not individual legal advice. LegalDock documents are templates — consult a lawyer about your specific situation.