GDPR applies to organizations, not to organizations above a certain size. A five-person web shop that processes EU customer data carries the same core obligations as a bank: lawful basis, transparency, data subject rights, security, and breach notification. What differs is proportionality: the regulation and its enforcers scale expectations to the risk and scale of the processing, and several of the heaviest requirements have thresholds an SME never reaches.
| Regulation | Regulation (EU) 2016/679 (GDPR) |
|---|---|
| Max penalty | EUR 20M or 4% of global annual turnover |
| Enforcing authority | National supervisory authorities, coordinated by the EDPB |
| Official text | EUR-Lex CELEX 32016R0679 |
What scales down, and what does not
Three obligations have built-in thresholds. The DPO is mandatory only for large-scale monitoring or special category processing (Article 37), which excludes almost all SMEs outside ad tech and health. DPIAs attach to high-risk processing (Article 35), not routine operations. And Article 30(5) trims record-keeping for sub-250-employee organizations, though only for genuinely occasional processing.
Nothing else scales down. Every access request gets answered within a month. Every breach gets assessed against the 72-hour rule. Every marketing email needs a basis. Every vendor that touches personal data needs an Article 28 contract. The good news: at SME scale these are procedures, not departments.
Where SMEs actually get fined
Reading enforcement decisions across Europe shows a consistent SME pattern. Complaints, not audits, start the cases, and they cluster around: video surveillance capturing more than the business premises, marketing to people who unsubscribed or never consented, ignored or late data subject requests, and websites whose trackers fire before consent. The amounts are proportionate, typically four to five figures, but the process cost of an investigation dwarfs the fine. Prevention is dramatically cheaper.
A lean compliance sequence
- Scan your website. It is your most exposed surface and the source of most complaints. A free scan shows your trackers, cookie behavior, and policy gaps in minutes.
- Inventory your data in an afternoon. List systems, data types, purposes, and vendors in a spreadsheet. This becomes your Article 30 record.
- Publish a real privacy notice. Cover the Articles 13/14 items in plain language. Delete the template boilerplate that describes processing you do not do.
- Fix consent. Marketing lists need provable opt-ins; the website needs a banner where refusing is as easy as accepting.
- Collect your DPAs. Most SaaS vendors have a signable DPA online; an hour of work covers your stack.
- Write the breach page. One page: who decides, who notifies the authority, and the 72-hour clock. Our breach notification playbook has the details.
Revisit annually and when you add tools. For the complete requirement set, the ultimate GDPR guide covers the full roadmap.