What is GDPR?
GDPR is less a piece of paperwork than a set of conditions attached to one activity: processing personal data. Any information that identifies a person, a name, an email address, an IP address, a purchase history, falls under the regulation the moment a business collects, stores, uses or shares it. The regulation applies since May 2018 to every organisation established in the EU, and to any organisation outside the EU that processes data belonging to EU residents, with no exemption for small structures.
The confusion that costs businesses the most is treating GDPR as a one-time project with an end date. It is a standing operational requirement, closer to accounting obligations than to a website redesign. A company that was compliant at the point of a data audit two years ago and has added a new marketing tool, a new subcontractor or a new data flow since then is very likely no longer compliant, without anyone deciding that on purpose.
Why GDPR matters
Three reasons make this a real business question rather than a legal formality to delegate and forget.
- Enforcement in Belgium is real, not theoretical. The Belgian Data Protection Authority (APD) has issued fines against companies of every size, most often in the 2,000 to 100,000 euro range for SMEs, well before reaching the 20 million euro ceiling that headlines tend to quote. Warnings and formal notices are the most common outcome, but repeated or ignored ones escalate.
- Subcontractors extend the obligation, they do not remove it. A hosting provider, a CRM vendor, a marketing agency or an accounting platform that touches your customer data is a processor under GDPR, and the responsibility for having a compliant contract with each of them sits with the business that collected the data, not with the vendor.
- Compliance has become a sales requirement, not just a legal one. Larger clients and public tenders increasingly ask for proof of a processing register, a privacy policy and subcontractor contracts before signing, which turns GDPR readiness into a deal-closing document rather than a defensive one.
The uncomfortable part worth saying plainly: GDPR does not scale down its expectations for a small team, it only simplifies some of the paperwork. A five-person company that collects customer emails carries the same legal bases and breach notification duty as a five-hundred-person one, just with a lighter processing register.
How it works
Four obligations apply to essentially every business that processes personal data, regardless of size or sector.
A lawful basis for each processing activity. Consent, contract necessity, legal obligation, or legitimate interest, named and documented before data is collected, not reconstructed after the fact when someone asks.
A processing register. Companies under 250 employees only need to log processing that is regular, high risk, or involves sensitive data, which removes most of the paperwork burden for a typical SME while keeping the risky flows documented.
Individual rights, honoured on request. Access, correction, deletion and data portability, with a response expected within one month, not an indefinite queue.
Breach notification within 72 hours. To the Data Protection Authority once a breach is identified, and to the affected individuals when the risk to them is high, which means an incident response process has to exist before an incident happens, not be improvised during one.
A data protection officer is only mandatory in three cases: a public authority, an activity built around large scale systematic monitoring of individuals, or large scale processing of sensitive data. Most SMEs fall outside all three, which is often misunderstood as GDPR not applying to them at all, when only the DPO requirement is lifted.
Implementation
The order below front-loads the unglamorous mapping work, because that is where compliance projects usually fail.
- Map what data actually flows through the business. Not the policy on paper, the real tools: the CRM, the newsletter platform, the accounting software, the website forms, the payment processor. Most gaps live in tools nobody thought to include.
- Name a lawful basis for each flow, then cut what has none. Data collected without a clear basis is a liability sitting in a database, not an asset, and deleting it is usually cheaper than defending it later.
- Get a signed data processing agreement with every subcontractor that touches personal data. Hosting, CRM, email marketing, accounting, analytics. A missing contract is one of the most common findings when a company is actually audited.
- Write the privacy policy to match reality, not a template. A copied policy that lists rights the business does not actually honour is worse than no policy, because it becomes evidence of the gap.
- Build the breach response process before it is needed. Who gets notified internally, how the 72-hour clock is tracked, who drafts the notification to the Data Protection Authority. Rehearsing this once costs little and saves the exact moment when panic is most likely.
- Train the people who actually handle data day to day. Most breaches originate from an ordinary mistake, not a hack: an email sent to the wrong list, a spreadsheet shared too broadly, a laptop without encryption.
What it costs
The visible cost is close to zero, which is precisely the trap. Writing a privacy policy or drafting a register template costs little to nothing. The real cost is the work most companies skip: mapping every actual data flow, chasing down signed contracts with every subcontractor, and keeping the register current as tools change. An externalised data protection officer, when one is needed or wanted as a precaution, typically costs between 1,500 and 5,000 euros a year for an SME, a small fraction of the fine range the Belgian authority actually applies to small structures.
The cost of getting it wrong is asymmetric. A first-time, minor, corrected finding tends to draw a warning. A repeated or ignored one escalates toward the fines that make headlines. The businesses that spend the least over time are the ones that treat the mapping and documentation work as routine maintenance, not the ones that wait for an incident to start.
Conclusion
GDPR is a standing operational requirement built around one question: can this business show, for any piece of personal data it holds, why it has it, where it lives, and who else can see it. A privacy policy that nobody checks against reality answers none of that, regardless of how professional it reads.
The businesses genuinely at risk are not the ones with imperfect paperwork, they are the ones that never mapped their actual data flows and would discover the gaps only during an audit or after a breach. Mapping that flow once, honestly, is a smaller project than most companies expect and the single highest-leverage step available.

