EU Privacy Law EU/EEA

Ultimate Guide to GDPR Compliance: 10-Step Roadmap

A practical 10-step GDPR compliance roadmap covering lawful basis, data subject rights, breach response, and transfers. Scan your site free today.

Regulation

Regulation (EU) 2016/679 (GDPR)

Max Penalty

EUR 20 million or 4% of global annual turnover, whichever is higher

Enforcing Authority

National supervisory authorities, coordinated by the EDPB

Official Source

eur-lex.europa.eu

Executive Summary

  • The GDPR (Regulation (EU) 2016/679) has applied since May 25, 2018 to any organization processing personal data of people in the EU or EEA, wherever the organization is based.
  • The regulation is built on seven principles in Article 5, six lawful bases in Article 6, and eight data subject rights in Articles 15 to 22.
  • Top-tier violations carry fines up to EUR 20 million or 4% of global annual turnover; the largest single fine to date is EUR 1.2 billion against Meta in 2023.
  • Websites are the most visible compliance surface: cookie consent, privacy notices, and tracker behavior are what regulators and complainants check first.
  • A defensible program starts with a data inventory and lawful basis mapping, then adds rights handling, breach response, and vendor contracts.

The General Data Protection Regulation is the EU law that governs how organizations collect, use, store, and share personal data. It took effect on May 25, 2018, replaced the 1995 Data Protection Directive, and applies extraterritorially: an organization anywhere in the world is in scope if it offers goods or services to people in the EU or monitors their behavior (Article 3). This guide walks through a 10-step roadmap that compliance teams can execute in order.

RegulationRegulation (EU) 2016/679 (GDPR)
In force sinceMay 25, 2018
Max penaltyEUR 20M or 4% of global annual turnover
Enforcing authorityNational supervisory authorities, coordinated by the EDPB
Official textEUR-Lex CELEX 32016R0679

What GDPR requires

The regulation rests on seven Article 5 principles: lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability. Every obligation in the rest of the text traces back to one of these. Article 6 then requires a documented lawful basis for each processing purpose, and Articles 15 to 22 give individuals rights to access, rectify, erase, restrict, port, and object to processing of their data.

The 10-step roadmap

  1. Build a data inventory. List every system, form, and vendor that touches personal data. You cannot assign lawful bases or answer deletion requests for data you have not mapped.
  2. Assign a lawful basis per purpose. Consent, contract, legal obligation, vital interests, public task, or legitimate interests (Article 6(1)). Document the choice; switching bases later is what regulators penalize.
  3. Create your Article 30 records of processing. Controllers and processors both need them. See our ROPA template guide.
  4. Rewrite privacy notices. Articles 13 and 14 list the mandatory content: purposes, bases, recipients, retention periods, rights, and transfer safeguards.
  5. Fix website consent. Non-essential cookies and trackers need prior opt-in consent that is as easy to refuse as to give. This is the most frequently enforced violation.
  6. Operationalize data subject rights. Set up intake, identity verification, and a workflow that meets the one-month deadline.
  7. Paper your vendors. Every processor needs an Article 28 contract with the eight mandatory clauses.
  8. Prepare breach response. Article 33 gives you 72 hours to notify the supervisory authority after becoming aware of a reportable breach.
  9. Assess transfers. Data leaving the EEA needs an adequacy decision, standard contractual clauses with a transfer impact assessment, or another Chapter V mechanism.
  10. Decide whether you need a DPO and DPIAs. Article 37 makes a DPO mandatory for public bodies and for large-scale monitoring or special category processing; Article 35 requires DPIAs for high-risk processing.

Penalties and enforcement

Enforcement is real and growing. The Irish DPC fined Meta EUR 1.2 billion in May 2023 over EU-US transfers, the largest GDPR fine issued to date. Amazon received EUR 746 million from Luxembourg in 2021, LinkedIn EUR 310 million in 2024 over advertising lawful basis, and TikTok EUR 345 million in 2023 over children’s defaults. Smaller organizations are not ignored: national authorities issue hundreds of five-figure and six-figure fines each year, frequently triggered by a single complaint about a website.

Where to start

Your public website is the fastest thing to check and the first thing a complainant or regulator sees. Run a free scan to see which trackers fire before consent, what your privacy policy discloses, and where your site diverges from what GDPR expects, then work the roadmap above from the top.

Frequently Asked Questions

Does GDPR apply to US companies?

Yes, if they offer goods or services to people in the EU or monitor their behavior (Article 3). A US site that ships to EU customers or runs EU-targeted ads is in scope, and it may need an EU representative under Article 27.

What are the penalties for GDPR non-compliance?

Two tiers under Article 83: up to EUR 10 million or 2% of global turnover for issues like inadequate records or security, and up to EUR 20 million or 4% for violations of the principles, lawful basis, data subject rights, or transfer rules.

Do small businesses have to comply with GDPR?

Yes. There is no small-business exemption. The only size-based relief is the Article 30(5) partial exemption from record-keeping for organizations under 250 employees, and it falls away if processing is regular or risky.

How long do I have to answer a data subject request?

One month from receipt (Article 12(3)). You can extend by two further months for complex or numerous requests, but you must tell the requester about the extension within the first month.

Is cookie consent a GDPR requirement?

Consent standards come from GDPR Article 7, but the requirement to obtain consent before setting non-essential cookies comes from Article 5(3) of the ePrivacy Directive. Regulators apply both together, so a compliant banner must satisfy each.

Regulatory Crosswalk

UK GDPRLGPDPIPEDACCPA/CPRA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.