# GDPRWise - Full Knowledge Base Content > This file contains the complete knowledge base content from GDPRWise, a GDPR compliance platform for European SMEs. For a summary, see /llms.txt --- ## Security ### Access Control: Who May See Which Personal Data? URL: https://gdprwise.eu/en/kennisbank/beveiliging/access-control-personal-data/ Summary: Not everyone in your business needs access to all personal data. Good access control is one of the most important security measures under the GDPR. Key takeaways: - Give employees only access to data they truly need for their role (least privilege) - Use role-based access control: link rights to positions, not to individuals - Immediately block all access when an employee leaves - Require strong passwords and two-factor authentication (2FA) on all systems with personal data FAQ: Q: Is access control mandatory under the GDPR? A: Yes. Article 32 requires appropriate technical and organisational measures. Access control is one of the most fundamental. After a breach, one of the first questions is: who had access? Q: What if I'm a small business with only five employees? A: Access control is still relevant. Not everyone needs access to payroll or the full CRM. The scale is smaller, but the principle is the same. Q: How often should I review access rights? A: At least annually, and with every role change or departure. Schedule a quarterly review. ## The principle: least privilege The core of good access control is simple: give every person only the access they need for their work, nothing more. This is called the "least privilege" principle. Your sales team needs customer data in the CRM, but not the personnel files. Your accountant needs financial records, but not the marketing contact list. Your office manager may need both, but doesn't need admin rights on every system. ## How to implement access control ### 1. Inventory who has access to what Map per system who currently has access and what level (admin, editor, viewer). You'll likely find that many people have more access than they need. ### 2. Define roles Instead of granting rights per person, create roles: "Sales", "Finance", "HR", "Management". Each role gets access to the systems needed for that function. ### 3. Apply least privilege Review each role and ask: does this role really need this access? Remove everything that's not strictly necessary. ### 4. Use personal accounts Every person gets their own account. No shared logins. This lets you trace who did what, and easily revoke access when someone leaves. ### 5. Enforce strong authentication - Minimum 12-character passwords - Unique per system (use a password manager) - Two-factor authentication (2FA) on all systems with personal data ### 6. Block access on departure Create a checklist for employee departures: deactivate all accounts on the same day. Don't wait "until IT gets around to it". ## What to document In your security documentation, record: - Which roles exist and what access they have - How access is granted and revoked - When you last reviewed access rights - How authentication is enforced (password policy, 2FA) import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Application Register: Which Systems Process Personal Data? URL: https://gdprwise.eu/en/kennisbank/beveiliging/application-register/ Summary: An application register is an inventory of all systems and tools that process personal data in your organisation. It supports your record of processing activities and is essential during a data breach. Key takeaways: - An application register is an inventory of all systems and tools that process personal data - It supports your record of processing activities and helps you respond to data breaches - Document per system: name, vendor, data types, storage location, and processing agreement status - GDPRWise automatically detects which systems your website uses and adds them to your register FAQ: Q: Is an application register mandatory under the GDPR? A: The GDPR does not explicitly require an application register, but it does require a record of processing activities (Article 30). An application register is the practical foundation for that record. You cannot properly maintain your processing records without knowing which systems you use. Q: How many systems does an average SME have? A: More than you think. A typical SME with 10-50 employees uses 20 to 40 tools that process personal data, including email, CRM, accounting, HR software, cloud storage, marketing tools, and communication platforms. Q: Do I need a processing agreement for every system? A: For every vendor that processes personal data on your behalf (a 'processor'), you need a Data Processing Agreement. Not every tool is a processor, but most cloud services are. Your application register helps you spot where an agreement is missing. Q: How do I keep the register up to date? A: Check at least twice a year whether your register is still accurate. Make it a habit to add every new system immediately. GDPRWise sends reminders when it's time to review your register. ## What is an application register? An application register is an overview of all systems, software, and tools that process personal data in your organisation - from your CRM and accounting software to your email client and cloud storage. The difference from your record of processing activities: the processing record describes the activities (what you do with data and why). The application register describes the means (which systems you use). Together they form a complete picture. ## Why do you need one? ### 1. It supports your record of processing activities Your processing record must list which systems are involved in each processing activity. Without an application register, you'll be guessing which tools you use every time you update it. ### 2. It helps during data breaches During a data breach, you need to quickly determine which systems are affected and what data they contain. You have 72 hours to notify the supervisory authority - you don't want to spend that time figuring out which systems you have. ### 3. It makes processing agreements manageable For every vendor that processes personal data on your behalf, you need a Data Processing Agreement (DPA). Your application register shows at a glance where you already have an agreement and where one is missing. ## What to document per system | Field | Description | Example | |---|---|---| | Name | Name of the system or tool | HubSpot CRM | | Vendor | Company name of the vendor | HubSpot Inc. | | Category | Type of system | CRM | | Data types | Which personal data is processed | Name, email, phone number, interaction history | | Data subjects | Whose data is involved | Customers, leads | | Storage location | Where is data stored | EU (Frankfurt) | | Processing agreement | Is a DPA in place | Yes, signed 15-03-2024 | | Internal owner | Who manages this system | Marketing team | ## Practical example A sample register for a small business: | System | Vendor | Data types | Location | DPA | |---|---|---|---|---| | Google Workspace | Google LLC | Email, documents, calendar | EU | Yes | | Exact Online | Exact | Invoices, customer data, bank details | NL | Yes | | Mailchimp | Intuit Inc. | Email, name, behavioural data | US (SCC) | Yes | | Teamleader | Teamleader NV | Customer data, quotes, invoices | BE | Yes | | WordPress + WooCommerce | Self-hosted | Customer data, orders | NL (own hosting) | N/A | | Slack | Salesforce | Messages, files | US (SCC) | No - action needed | The Slack entry immediately reveals a missing processing agreement. That is exactly the value of the register. ## How to get started 1. **Inventory all systems.** Walk through each department and ask which tools they use. Don't forget mobile apps and free tools 2. **Check your invoices.** Your accounting records show which software you pay for 3. **Scan your website.** GDPRWise automatically detects which external services your website uses 4. **Document each system.** Fill in the fields listed above 5. **Check processing agreements.** Verify whether you have a DPA for each system ## Keeping it current Check at least twice a year whether your register is still accurate. Make it a habit to add every new system immediately and verify the processing agreement. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### CCTV and Privacy: The GDPR Rules for Business Owners URL: https://gdprwise.eu/en/kennisbank/beveiliging/cctv-privacy-gdpr/ Summary: Installing security cameras at your business? The GDPR sets strict requirements for CCTV: from signage to retention periods. This article explains what's allowed, what's required, and what mistakes to avoid. Key takeaways: - Camera footage is personal data under the GDPR as soon as individuals are identifiable - You must place a sign with specific information before people enter the monitored area - Footage may be retained for a maximum of 1 month, unless an incident has been recorded - Cameras aimed at employees as a monitoring tool are almost never allowed FAQ: Q: May I install cameras at my business? A: Yes, but you must have a valid purpose (e.g. security, theft prevention), the cameras must not film more than necessary, you must place clear signage, and you must document it in your processing register. Q: How long may I retain camera footage? A: The guideline is a maximum of 1 month. Only if an incident has been recorded (e.g. theft, break-in) may you retain the relevant footage longer, until the incident is fully resolved. Q: May I film my employees? A: Only if it is proportionate and you have informed employees in advance. Cameras must not be aimed at individual workstations as a monitoring tool. In common areas like a warehouse, it may be allowed under conditions, but never in changing rooms, toilets, or break rooms. Q: Do I need a DPIA for my cameras? A: For a small system (e.g. 2-3 cameras at the entrance), usually not. For larger installations, cameras in publicly accessible areas, or systematic employee monitoring, a DPIA is required. ## Camera footage is personal data As soon as a person is identifiable in camera footage, that footage is personal data under the GDPR. This means all GDPR rules apply: you need a legal basis, you must inform data subjects, you may not retain footage longer than necessary, and you must secure it. This applies to: - Security cameras at your business entrance - Cameras in a warehouse or workshop - Cameras on a parking lot - Camera doorbells (Ring, Nest type) The only exception is purely household use: a camera filming only your own garden, without public space or neighbours in view. ## What you must do: the basic obligations ### 1. You need a valid purpose Valid purposes for business CCTV: - **Security of persons and goods** - theft prevention, break-in detection - **Access control** - recording who enters the premises - **Workplace safety** - monitoring dangerous processes "Checking whether employees are productive" is not a valid purpose. ### 2. You must place signage Before anyone enters the monitored area, a clear sign must be visible with: - The **camera pictogram** - Your **company name and contact details** - The **purpose** of the monitoring - The **retention period** for footage - A reference to your **privacy policy** (e.g. a URL or QR code) ### 3. You must keep footage for a short period The standard retention period for CCTV footage is **maximum 1 month**. After this period, footage must be automatically overwritten or deleted. Exceptions: - **An incident has been recorded** (theft, vandalism, accident): you may retain relevant footage until fully resolved - **A competent authority requests the footage**: police or judicial authorities may request footage for an investigation ### 4. You must document it in your processing register CCTV belongs in your processing register, with purpose, categories of data subjects, retention period, security measures, and legal basis (usually legitimate interest). ## Cameras and employees: extra strict rules The basic rule: you may not film employees as a monitoring tool. **What IS allowed:** - Cameras in common areas (warehouse, production hall) for safety purposes, provided employees are informed - Cameras at the entrance for access control - Temporary cameras to investigate a specific, reported issue (e.g. repeated theft), provided proportionate **What is NOT allowed:** - Cameras aimed at individual workstations to monitor performance - Cameras in changing rooms, toilets, break rooms, or union offices - Hidden cameras without employee knowledge - Permanent, targeted monitoring of specific employees ## When do you need a DPIA? A DPIA is required for: - **Large-scale, systematic monitoring** of publicly accessible areas - **Systematic employee monitoring** via cameras - **Combination of cameras with other technology** (facial recognition, behaviour analysis) For a small business with 2-3 cameras at the entrance and warehouse, a DPIA is usually not needed. But document your considerations. ## Common mistakes - **No or incomplete signage** - the pictogram is there, but without contact details or purpose - **Retaining footage too long** - "we just let the system record until the hard drive is full" is not a policy - **Cameras aimed at the public road** - you may only film your own premises - **Not informing employees** - cameras are installed months before anyone hears about it - **Sharing footage via WhatsApp** - sending footage to colleagues after an incident is a data breach ## What should you do now? 1. **Check your signage** - is there a correct sign with all required information? 2. **Set the retention period** - configure your system to overwrite footage after maximum 30 days 3. **Add CCTV to your processing register** 4. **Inform your employees** - via the employee privacy policy 5. **Limit access** - determine who may view footage and log who has accessed it import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Code of Conduct for Privacy - Rules for Your Employees URL: https://gdprwise.eu/en/kennisbank/beveiliging/code-of-conduct/ Summary: A privacy code of conduct sets out how employees should handle personal data in their daily work. Practical guidelines you can apply immediately. Key takeaways: - A code of conduct translates the GDPR into concrete behavioural rules for daily work - Focus on situations employees actually encounter: email, phone calls, visitors, social media - Make clear that reporting mistakes is encouraged, not punished - Keep the code short and practical - maximum 2 pages that everyone understands FAQ: Q: What is the difference between a code of conduct and a security policy? A: A security policy describes technical and organisational measures at company level. A code of conduct describes expected behaviour of individual employees in their daily work. The code of conduct is the practical translation of the policy. Q: Should every employee read the code of conduct? A: Yes. Every employee who works with personal data must know the rules. Have new employees read the code as part of their onboarding and repeat the key points annually. Q: How do I enforce compliance? A: Not through penalties, but through culture. Make privacy a normal topic, lead by example, and encourage reporting. When an employee makes a mistake and reports it, that is a success, not a reason for sanctions. ## Why a code of conduct? You can have the best systems and policies, but ultimately your employees handle personal data every day. They reply to emails, call customers, share files, and use software. In all those situations, they make choices that affect the privacy of data subjects. A code of conduct translates the GDPR from abstract legislation into concrete rules for daily work. ## What should it cover? ### Handling personal data - Only collect data you truly need for your work - Do not keep data longer than necessary - Do not store personal data on USB sticks, personal folders, or unapproved tools - Delete or destroy data when you no longer need it ### Email and communication - Avoid sending personal data in unencrypted emails if not necessary - Double-check the recipient before sending, especially with sensitive information - Use BCC when emailing multiple customers - Be careful when forwarding emails that contain personal data ### Phone and conversations - Do not discuss personal data of customers or employees in public spaces - Verify the caller's identity before sharing personal data - Do not leave notes with personal data on loose papers lying around ### Visitors and the workplace - Do not leave visitors unattended in areas where personal data is accessible - Turn your screen away when sensitive information is displayed - Lock away documents when you leave your desk ### Social media - Do not share data about customers, employees, or partners on social media - Ask permission before posting photos of colleagues or customers - Be careful with information that could indirectly identify individuals ### Incidents and mistakes - Report any suspected data breach immediately, even if you caused it - Reporting mistakes is encouraged, not punished - The sooner you report, the better we can resolve it ## Tips for implementation ### Keep it short Maximum 2 pages. A code of conduct that nobody reads has no value. Focus on the situations employees encounter most often. ### Use examples Instead of "handle personal data carefully", write: "when a customer calls about their order, first verify you're speaking to the right person by asking for the order number." ### Discuss it as a team Don't just circulate the code by email. Take 30 minutes in a team meeting to walk through the key points and answer questions. ### Repeat annually Privacy awareness fades if you don't maintain it. Schedule an annual refresher, linked to your yearly privacy review. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Consider a Cyber Security Insurance URL: https://gdprwise.eu/en/kennisbank/beveiliging/cyber-insurance/ Summary: A cyber insurance covers the financial damage from a data breach or cyber attack. This article explains what a cyber insurance covers, when it makes sense, and what to look out for. Key takeaways: - A cyber insurance covers costs from a data breach or cyber attack: from forensic investigation to fines and liability - The average cost of a data breach for an SME is between 10,000 and 50,000 euros - Insurance does not replace good security - insurers require you to have basic measures in place - Check if your existing business insurance already covers cyber incidents FAQ: Q: Is a cyber insurance mandatory under the GDPR? A: No, the GDPR does not require insurance. But the law can lead to significant costs after a data breach: notification obligations, forensic investigation, notifying data subjects, potential fines and damage claims. An insurance can cover these costs. Q: What does a cyber insurance cost? A: The premium depends on your business size, sector, and risk profile. For a small SME, it often starts around 500 to 1,500 euros per year. Businesses processing sensitive data typically pay more. Q: Does my existing business insurance cover cyber incidents? A: Usually not fully. Most traditional business insurances exclude cyber risks or offer only limited coverage. Check your policy or ask your insurer. A separate cyber insurance typically offers broader coverage. ## The cost of a data breach is higher than you think A data breach or cyber attack costs an average SME between 10,000 and 50,000 euros. In some cases considerably more. These costs consist not only of a potential fine, but also forensic investigation, legal advice, notifying data subjects, reputation damage, and potentially damage claims from affected individuals. A cyber insurance can absorb a large part of these costs. It's not a miracle cure and it doesn't replace good security, but it's a sensible safety net. ## What does a cyber insurance cover? Coverage varies per insurer, but most policies cover: ### Direct costs after an incident - **Forensic investigation** - determining what happened and how - **Legal advice** - assessing notification obligation and liability - **Notification** - costs of informing data subjects and the supervisory authority - **Crisis management** - PR support and communication ### Financial damage - **Business interruption** - revenue loss when systems are unavailable - **Ransom** - some policies cover (part of) ransomware payments - **Fines** - coverage of administrative fines varies per policy and jurisdiction ### Liability - **Damage claims** - when data subjects claim damages - **Legal costs** - defence against claims ## When does it make sense? A cyber insurance is worth considering if you: - **Process personal data of customers or employees** - that applies to virtually every business - **Depend on your IT systems** - business interruption can be costly - **Process sensitive data** - medical data, financial data, national ID numbers - **Have limited IT capacity** - you can't handle everything yourself during an incident ## What to look out for - **Coverage scope** - specifically check whether fines, ransomware, and business interruption are covered - **Excess** - how much do you pay yourself? - **Exclusions** - read the fine print about what is not covered - **Prevention requirements** - most insurers require basic measures (password policy, updates, backups). Without those, your claim may be rejected - **Response services** - some policies offer 24/7 access to an incident response team ## Insurance does not replace security A cyber insurance is a safety net, not a replacement for good security. Insurers check that your basic security is in order before accepting you. And with a claim, they check whether you've met the prevention requirements. So first make sure your [basic security is in order](/en/kennisbank/beveiliging/data-security-where-to-start) and then consider whether a cyber insurance fits your risk profile. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Data Breach: What Is It and What Should You Do? URL: https://gdprwise.eu/en/kennisbank/beveiliging/data-breach-guide/ Summary: A data breach can happen to any business, from a misdirected email to a hacking attack. This article explains what a data breach is, when you must report it, and what steps to follow. Key takeaways: - A data breach is any security incident leading to loss, alteration, or unauthorised access to personal data - You must report a breach to the supervisory authority within 72 hours if there is a risk to data subjects - For high risk, you must also inform the data subjects themselves - Document every breach in your breach register, even if you decide not to report it FAQ: Q: Is a misdirected email a data breach? A: Yes, if the email contains personal data that reaches the wrong person. This is one of the most common data breaches for SMEs. Q: What if I miss the 72-hour deadline? A: Report it anyway as soon as possible and explain why the notification was delayed. A late notification with explanation is always better than no notification. Q: Must I report every data breach to the supervisory authority? A: No, only if it likely poses a risk to the rights and freedoms of data subjects. A lost USB with encrypted data may not need reporting. A leaked customer list with names and email addresses does. Q: What are the consequences of not reporting a breach? A: The supervisory authority can impose a fine of up to 10 million euros or 2% of annual turnover. Furthermore, you lose customer trust if the breach later comes to light. ## What is a data breach? A data breach (or "personal data breach") is any security incident that leads to: - **Destruction** of personal data (e.g. ransomware encrypting your database) - **Loss** of personal data (e.g. a stolen laptop, a misplaced USB stick) - **Alteration** of personal data (e.g. a hacker modifying customer records) - **Unauthorised disclosure or access** (e.g. a misdirected email, a hack of your CRM) It doesn't have to be a spectacular hacking attack. The most common data breaches for SMEs are everyday events: - An employee sends a customer list to the wrong email address - A laptop with unencrypted personnel files is stolen from a car - A former employee retains access to the CRM after leaving - Customer data is shared in a WhatsApp group with employees - A phishing email leads to leaked login credentials ## The three steps for a data breach ### Step 1: Assess the risk Not every breach needs to be reported. The crucial question is: **does this breach likely pose a risk to the rights and freedoms of the data subjects?** **Probably MUST report:** - Leaked financial data, medical records, national ID numbers - Leaked login credentials (passwords, accounts) - Personal data of vulnerable groups (children, patients) - Large numbers of data subjects - Data that could be used for identity fraud **Probably NOT required to report:** - Lost USB stick with fully encrypted data (the data is unreadable) - Brief unauthorised access where no data was copied or modified - Internal breach that was immediately resolved with no external consequences **In doubt? Report it.** An unnecessary notification has no consequences; a missed one can result in a fine. ### Step 2: Report to the supervisory authority (within 72 hours) If you decide to report, you have a maximum of **72 hours** after discovery. Not after the incident itself, but after the moment you discover it. If you need more information, you can report in phases: initial notification within 72 hours, supplementary information later. **Where to report:** | Country | Authority | How | |---------|-----------|-----| | Belgium | Data Protection Authority (GBA) | Online form at gegevensbeschermingsautoriteit.be | | Netherlands | Data Protection Authority (AP) | Breach reporting desk at autoriteitpersoonsgegevens.nl | | Germany | BfDI / State authority | Varies per state | | France | CNIL | Online form at cnil.fr | | UK | ICO | Online form at ico.org.uk | import TemplateTip from '@/components/TemplateTip.astro'; A notification form with all mandatory fields, plus a template for notifying data subjects. ### Step 3: Inform data subjects (for high risk) If the breach poses a **high risk**, you must also inform the data subjects themselves. Tell them: - What happened - Which data was involved - What you have done to resolve it - What they can do themselves (change password, be alert to phishing) ## The breach register Every data breach, even if you don't report it to the supervisory authority, must be recorded in a breach register. The authority can request this register at any time. Per incident, document: - Date of discovery and date of incident - Description of what happened - Which data and how many data subjects were affected - Consequences and measures taken - Whether you reported it to the authority (and if not, why not) - Whether you informed data subjects (and if not, why not) ## Common mistakes - **"It was just an email"** - a misdirected email with personal data is also a data breach - **Prioritising internal investigation over reporting** - start the notification within 72 hours, you can supplement with investigation results later - **Not informing data subjects at high risk** - this is a separate obligation - **Not keeping a breach register** - even unreported breaches must be documented - **Treating WhatsApp groups as secure** - sharing customer data in a WhatsApp group with employees is risky ## Prevention is better than reporting The best breach procedure is one you rarely need to use: - **Encrypt** laptops, USB sticks, and mobile devices - **Limit access** to personal data based on necessity - **Use strong passwords and 2FA** for all systems with personal data - **Train your employees** - most breaches arise from human error - **Remove accounts** of departing employees immediately - **Don't use WhatsApp** for sharing customer or personnel data import CourseTip from '@/components/CourseTip.astro'; Want to train your team to spot a data breach quickly and report it correctly? We cover it step by step in the "Spotting and reporting a breach" module of our free Security awareness course. No account needed, with a certificate. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Data Retention: How Long May You Keep Personal Data? URL: https://gdprwise.eu/en/kennisbank/beveiliging/data-retention-policy/ Summary: The GDPR requires you not to keep personal data longer than necessary. But how do you determine the right period? This article explains how to create a data retention policy with concrete examples per data type. Key takeaways: - You may not keep personal data longer than necessary for the original purpose - Some data has a legal retention obligation (e.g. 7 years for accounting documents) - A formal retention policy protects you during an inspection by the supervisory authority - Delete or anonymise data as soon as the retention period expires FAQ: Q: How long may I keep customer data? A: That depends on the purpose. Active customer data may be kept for the duration of the relationship. After the relationship ends, you only keep it if you have a legal retention obligation (e.g. invoicing data 7 years) or can demonstrate a legitimate interest. Q: Must I delete data automatically? A: The GDPR does not prescribe automatic deletion, but it is recommended. Set deletion reminders or configure your systems to automatically delete data after the set period. Q: What if I'm not sure which period to apply? A: First check if there is a legal retention obligation. If not, determine the period based on the purpose for which you process the data. Document your choice and the reason - that is the most important thing. ## Why is this important? The GDPR is clear: you may not keep personal data longer than necessary to achieve the purpose for which you collected it. Yet most businesses keep data much longer than necessary, simply because nobody ever thinks about it. The risk? During an inspection by the supervisory authority, or when a customer submits a deletion request, you must be able to explain why you still hold certain data. "We never thought about it" is not a valid answer. ## Common retention periods Below is an overview of common retention periods. Note: these are guidelines - always check the specific legislation that applies to your situation. | Data type | Legal basis | Retention period | |---|---|---| | Accounting documents (invoices, payments) | Tax legislation | 7 years | | Personnel files | Employment law | 5 years after end of employment | | Application data (unsuccessful candidates) | Legitimate interest | For a limited period after the recruitment process, based on a documented retention period. Longer retention for future vacancies requires a separate talent-pool purpose and legal basis. | | Customer data (active relationship) | Contract performance | Duration of relationship | | Customer data (after termination) | Legitimate interest | Max. 2 years | | CCTV footage | Legitimate interest | Max. 1 month (unless incident) | | Website analytics (IP addresses) | Consent / legitimate interest | Max. 26 months | | Contact form submissions | Legitimate interest | Max. 2 years after last contact | | Newsletter subscribers | Consent | Until consent is withdrawn | The recruitment row is the one employers most often get wrong, because the GDPR sets no fixed period for candidate data and the numbers circulating online come from national guidance rather than the Regulation. [How long can you keep a candidate's CV?](/en/kennisbank/hr/how-long-keep-cv) works through how to set that period, and [do you need consent to keep a candidate's CV?](/en/kennisbank/hr/consent-to-keep-cv) covers the separate talent-pool basis. ## How to create a retention policy ### Step 1: Inventory your processing activities You cannot set retention periods if you don't know what data you process. Start with your processing register - all processing activities are listed there. ### Step 2: Determine the period per activity Ask yourself per processing activity: - Is there a **legal retention obligation**? If so, that applies - If not, how long do I **really need** the data for the purpose? - Is there an **industry standard** I can follow? ### Step 3: Document your choices Record per processing activity: - Which retention period you apply - Why (legal basis or justification) - What happens when it expires (deletion, anonymisation) ### Step 4: Implement and monitor - Set reminders for checking and deleting expired data - Configure automatic deletion where possible - Check at least annually whether your policy is still current ## Common mistakes - **Keeping everything "forever"** because it's easier. This is a GDPR violation - **Not distinguishing** between active and inactive customers - **Forgetting backups**: if you delete data but it's still in a backup, you're not done - **No policy on paper**: if you haven't documented it, it doesn't exist for the supervisory authority import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Data Security - Where to Start? URL: https://gdprwise.eu/en/kennisbank/beveiliging/data-security-where-to-start/ Summary: Data security is a core requirement of the GDPR, but where do you begin? This article gives you a practical step-by-step plan to get the security of personal data in your business in order. Key takeaways: - Start with an inventory: what data do you have, where is it stored, and who has access? - Focus first on the basics: strong passwords, up-to-date software, and backups - The GDPR requires 'appropriate technical and organisational measures' - what's appropriate depends on your risk - You don't need to be an IT expert, but you must know what measures you've taken and why FAQ: Q: Do I need to do data security as a small business? A: Yes. The GDPR requires every organisation processing personal data to take appropriate security measures. What's 'appropriate' depends on the nature and scale of your processing. For a small business, the basic measures are often sufficient. Q: What are the minimum security measures I should take? A: At minimum: strong passwords on all accounts, two-factor authentication where possible, regular software updates, backups of important data, and a basic policy for who has access to what. Q: Do I need a security audit? A: It's not mandatory for most SMEs, but it can be useful. Start with the basic measures first. If you work with sensitive data or are a larger organisation, an audit is recommended. ## Security is not optional, it's an obligation The GDPR states in Article 32 that you must take "appropriate technical and organisational measures" to protect personal data. But what is appropriate? And where do you start if you don't have an IT department? The good news: for most SMEs, it's about concrete, achievable steps. You don't need to build Fort Knox, but you must handle the data you process consciously. ## Step 1: Know what you have Before you can secure anything, you need to know what you have. Make an inventory: - **What personal data** do you process? Think of customer data, personnel files, supplier data. - **Where is that data?** On your computer, in the cloud, in paper files, on USB sticks? - **Who has access?** Which employees, external parties, or tools can access the data? GDPRWise helps you with this inventory via the three dossiers (customers, personnel, third parties). That's also your starting point for security. ## Step 2: Get the basics right These measures are relevant for every business, regardless of size or sector: ### Passwords and access - Use strong, unique passwords for every account - Enable two-factor authentication (2FA) where possible - Use a password manager so you don't have to remember them ### Software and updates - Keep your operating system and software up to date - Install security updates as soon as possible - Use antivirus software and a firewall ### Backups - Make regular backups of your important data - Store backups at a different location than your work computer - Periodically test whether your backups can actually be restored ### Physical security - Lock your computer when you leave - Store paper files in lockable cabinets - Be careful with data in public places ## Step 3: Determine what's appropriate for your situation The GDPR takes a risk-based approach. The more sensitive the data and the larger the scale, the more measures you need. **Low risk** (e.g. a small webshop with only customer addresses): basic measures are usually sufficient. **Medium risk** (e.g. a business with personnel files and financial data): also consider encryption, formal access management, and an information security policy. **High risk** (e.g. a medical practice or law firm): additional measures such as a DPIA, encryption at all levels, and strict access control. ## Step 4: Document what you do It's not enough to take the measures. You must also be able to demonstrate that you've taken them. Document: - Which measures you've taken - Why you chose those measures - When you last checked them ## Start today You don't have to do everything at once. Start with step 1 and work through the list. Every measure you take makes your business safer and your compliance stronger. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Data Security for Paper Documents URL: https://gdprwise.eu/en/kennisbank/beveiliging/paper-document-security/ Summary: The GDPR doesn't only apply to digital data. Paper documents containing personal data must also be secured. This article explains the measures you need to take for physical files, contracts, and correspondence. Key takeaways: - The GDPR applies to all personal data, including paper documents, files, and correspondence - Store paper documents containing personal data in lockable cabinets or rooms - Destroy documents with a paper shredder when the retention period expires - Implement a clean desk policy so personal data doesn't lie around unattended FAQ: Q: Do I need to digitise all my paper documents? A: No, that's not required. You may keep personal data on paper, as long as you secure it adequately. Digitising can offer advantages for searchability and security, but it's not a GDPR requirement. Q: How should I destroy paper documents? A: Use a paper shredder, preferably cross-cut (DIN level P-4 or higher). Never simply throw documents with personal data in the recycling bin. For large volumes, you can engage a certified destruction company. Q: Does a data breach also apply to paper documents? A: Yes. If a folder with personnel files is stolen, lost, or accessed by unauthorised persons, that is a data breach under the GDPR. The same notification and registration obligations apply as with a digital breach. ## Don't forget your paper files Many businesses focus GDPR compliance on their digital systems, but forget that the law also applies to paper documents. A folder with employment contracts, a binder with customer data, a printout of a medical file - all fall under the GDPR. And honestly: paper documents are often less well secured than digital ones. They sit on desks, in open cabinets, or in cardboard boxes in the attic. ## Which paper documents contain personal data? More than you think: - **Personnel files** - employment contracts, payslips, sick notes, performance reviews - **Customer data** - quotes, contracts, correspondence, order forms - **Financial documents** - invoices with name/address, bank statements, tax returns - **Legal documents** - court papers, complaints, evidence - **Medical data** - patient files, prescriptions, absence records ## Practical security measures ### Storage - Store documents with personal data in **lockable cabinets or rooms** - Limit access to employees who need the data for their work - Label cabinets or folders to clarify contents and who has access ### Clean desk policy - Don't leave documents with personal data unattended on your desk - File documents when you leave your workspace, even for a short break - Don't leave incoming post with personal data open on a shared reception desk ### Destruction - Use a **paper shredder** for documents whose retention period has expired - Cross-cut shredders (DIN P-4 or higher) offer more security than strip-cut - For large volumes: engage a certified destruction company that provides a destruction certificate - Also destroy copies, drafts, and sticky notes with personal data ### Transport - Transport paper documents in locked bags or folders - Don't leave folders unattended in your car - Send documents with personal data by registered post or courier ## Don't forget to document As with digital security, you must be able to demonstrate what measures you've taken. Record: - Where paper documents are stored - Who has access - How and when they are destroyed - Which retention periods you apply import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Don't Share Personal Data via WhatsApp with Your Staff URL: https://gdprwise.eu/en/kennisbank/beveiliging/whatsapp-sharing-personal-data/ Summary: WhatsApp is not suitable for sharing customer data, addresses, or access codes with employees. This article explains why, with a real enforcement case from Finland and practical alternatives. Key takeaways: - WhatsApp is not suitable for sharing personal data with employees - A Finnish cleaning company was fined for sharing customer names, addresses, and security codes via WhatsApp - You have no control over who sees, saves, or forwards data in a WhatsApp group - Document which communication tools you use and choose a platform with business management capabilities FAQ: Q: May I use WhatsApp to share work schedules with my staff? A: Work schedules without third-party personal data (customers) are less problematic. But as soon as you share customer names, addresses, phone numbers, or other personal data via WhatsApp, you are in violation. Q: Is WhatsApp Business GDPR-compliant then? A: No, WhatsApp Business still shares metadata with Meta and does not offer business management capabilities such as remotely wiping data or access control. It is not designed as a processing tool for personal data. Q: What alternatives are there to WhatsApp? A: Use a business communication platform with management capabilities, such as Microsoft Teams, Slack, or Signal. Choose a tool where you can revoke access, wipe data, and enter into processing agreements. Q: What if an employee shares customer data via WhatsApp on their own initiative? A: As an employer, you are responsible for the processing activities your employees carry out. Train your staff, set clear rules, and provide a suitable alternative. 'I didn't know' is not a valid defence. ## WhatsApp is convenient, but not safe for personal data It's a familiar scenario: you run a cleaning company, home care organisation, or installation business. Employees need to know which customer they're visiting today. So you quickly send the name, address, phone number, and perhaps an access code via the WhatsApp group. Easy, fast, everyone has it. But under the GDPR, this is a serious problem. You're sharing customers' personal data via a platform over which your organisation has no control. ## Finnish cleaning company: fined for WhatsApp use This is not a theoretical risk. The Finnish supervisory authority handled a case against a cleaning company that used WhatsApp to share work assignments with staff. Via WhatsApp groups, customer names, addresses, phone numbers, and even home security codes were shared. The Finnish DPA ruled that the company had breached three GDPR obligations: - **Integrity and confidentiality** (Article 5(1)(f)) - personal data was shared via a channel without adequate security measures - **Privacy by design** (Article 25) - the company had not set up a privacy-friendly system for sharing assignments - **Security measures** (Article 32) - no appropriate technical and organisational measures were taken to protect the data The company received a reprimand and the order to implement a suitable system. For repeat offences, a fine is threatened. ## Why WhatsApp is unsuitable for business data The problems with WhatsApp for business use of personal data are fundamental: **No control over data.** Once you send a message in a group, every participant can forward, save, or screenshot it. You cannot remotely wipe messages from someone else's phone. **Lost or stolen phones.** If an employee loses their phone, all customer data from the WhatsApp group is exposed. You cannot remotely revoke access. **WhatsApp terms prohibit business use.** WhatsApp's terms of service do not allow sending third-party data for business purposes without additional arrangements. You cannot enter into a processing agreement with WhatsApp for this use. **Metadata goes to Meta.** WhatsApp shares metadata (who communicates with whom, when, how often) with parent company Meta. Messages within the EU have end-to-end encryption, but the metadata is not protected. **No audit trail.** You cannot demonstrate which data was shared with whom and when, or whether it was deleted. During an inspection, you cannot show you are "in control". ## What are the alternatives? You don't need to go back to pen and paper. There are plenty of suitable alternatives: - **Business communication platforms** like Microsoft Teams or Slack, where you can manage users, revoke access, and enter into processing agreements - **Signal** if you want a simple, encrypted messenger without data sharing with tech companies (though Signal also offers limited management capabilities) - **Planning software** specifically designed for field workers, with role-based access and automatic deletion - **Secure portals** where employees can view their assignments without data being stored on their personal phone The key criterion: can you as an organisation manage access, wipe data, and demonstrate you have control? ## What should you do now? 1. **Stop sharing personal data via WhatsApp.** This applies to customer names, addresses, phone numbers, security codes, and all other data traceable to a person. 2. **Choose a suitable alternative** and document why you chose this platform. 3. **Set up an internal policy** on which communication tools employees may use for which data. 4. **Train your staff.** Explain why WhatsApp is not suitable and how to use the alternative. 5. **Document this in your processing register.** Which tools do you use to share personal data? With whom? On what legal basis? import CourseTip from '@/components/CourseTip.astro'; Handling data safely, including in chat apps like WhatsApp, is covered in the "Handling data safely" module of our free Security awareness course. No account needed, with a certificate. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Encryption: Should I Encrypt My Data? URL: https://gdprwise.eu/en/kennisbank/beveiliging/encryption-gdpr/ Summary: The GDPR mentions encryption as one of the most important security measures. But what exactly is it, when is it required, and how do you approach it practically as an SME? This article provides concrete guidance. Key takeaways: - The GDPR explicitly mentions encryption as a recommended security measure in Article 32 - Encrypt laptops, external drives, and USB sticks with full disk encryption - Use TLS (https) on your website and encrypted email for sensitive data - Encrypted data that is stolen may not need to be reported as a data breach FAQ: Q: Is encryption mandatory under the GDPR? A: Not literally mandatory in all cases, but Article 32 explicitly mentions encryption as a recommended measure. For sensitive data or high risk, it is practically difficult to meet your security obligation without encryption. Q: Do I need to report a breach if encrypted data is stolen? A: Possibly not. If the data was properly encrypted and the key was not leaked, there is no risk to data subjects. The supervisory authority will likely rule that a notification is not required. However, document the incident in your breach register. Q: What encryption is sufficient for the GDPR? A: Use common, proven standards. AES-256 for storage, TLS 1.2 or higher for data traffic. Avoid outdated protocols like SSL or TLS 1.0. ## What is encryption? Encryption means converting data into an unreadable code. Only someone with the correct key can make the data readable again. Think of it as a safe: the contents are still there, but without the code you can't access them. The GDPR mentions encryption in Article 32 as one of the recommended measures to protect personal data. That makes it one of the few technical measures the law explicitly names. ## When is encryption needed? Article 32 requires you to take "appropriate technical and organisational measures", considering the state of the art, costs, and risk. Encryption is not mandatory in every situation, but in the following scenarios it is virtually unavoidable: - **Laptops and mobile devices** used outside the office - **USB sticks and external hard drives** with personal data - **Sensitive data** such as medical information, financial data, or national ID numbers - **Data sent over the internet** (forms, emails) - **Backups** stored offsite ## Three practical steps for your business ### 1. Full disk encryption on all laptops This is the easiest and most impactful step. Enable full disk encryption on every laptop and desktop that processes personal data. - **Windows:** BitLocker (built into Windows Pro and Enterprise) - **Mac:** FileVault (built into macOS) - **Linux:** LUKS It costs you nothing extra, barely slows your computer, and protects you in case of theft or loss. If a laptop with disk encryption enabled is stolen, the thief cannot access the data. ### 2. TLS on your website If your website contains forms where visitors enter personal data - contact forms, registration forms, order forms - then the traffic must be encrypted with TLS (recognisable by the padlock and "https" in the address bar). Most hosting providers offer free TLS certificates via Let's Encrypt. There is no reason not to do this anymore. ### 3. Encrypted email for sensitive data Do you send medical data, financial information, or copies of ID documents by email? Regular email is not encrypted - comparable to a postcard that anyone can read along the way. Options: - Use a secure messaging portal (many accounting and healthcare platforms offer this) - Encrypt attachments with a password and share the password via a different channel - Use S/MIME or PGP if your organisation is ready for it ## The big advantage: less reporting obligation for data breaches This is where encryption gets really interesting for business owners. If personal data is stolen or lost, you normally need to report a data breach to the supervisory authority and possibly to the data subjects. But if the data was properly encrypted and the key was not leaked, there is no real risk to the data subjects. The data is unreadable. In that case, the supervisory authority will usually rule that notification is not required. A stolen laptop with BitLocker enabled? Document it in your breach register, but chances are you don't need to report it. The same laptop without encryption? Then you have a reportable breach with all the consequences. ## Common mistakes - **Enabling encryption but not managing the key properly.** If you stick the recovery key on a post-it on the laptop, you've achieved nothing - **Only encrypting the hard drive, forgetting USB sticks.** That one USB stick with the customer database left on the train - **Thinking a password on an Excel file is "encryption".** It's not - that protection is easy to crack - **Running your website on http.** There is no excuse anymore for a website without TLS ## Start today Encryption doesn't have to be complicated. Start by enabling disk encryption on all laptops. It takes half an hour per device and immediately protects you against one of the most common data breach scenarios. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### GDPRWise and NIS2 - Cybersecurity Legislation for Businesses URL: https://gdprwise.eu/en/kennisbank/beveiliging/gdprwise-nis2/ Summary: The NIS2 directive introduces new cybersecurity requirements for businesses in the EU. GDPRWise Enterprise has a full NIS2 action list and templates built in, right on top of your GDPR work. Key takeaways: - NIS2 is a European directive requiring businesses to improve their cybersecurity - It affects more businesses than NIS1: mid-sized companies in the supply chain may also fall under it - There is significant overlap between GDPR and NIS2 in security measures and incident reporting - GDPRWise Enterprise has a full NIS2 action list and templates built in - your GDPR work counts automatically - The action list follows the Belgian CyberFundamentals framework (Basic level), a solid baseline for any SME that takes cyber and privacy seriously FAQ: Q: Does NIS2 apply to my SME? A: It depends on three things: your sector (Annex I or II of the NIS2 law), your size (at least 50 staff or annual turnover and balance sheet above 10 million euros), and whether you have an establishment in Belgium. Smaller organisations can still be indirectly affected via the supply chain. The CCB offers a NIS2 Scope Assessment Tool at atwork.safeonweb.be/nis2 that you can use to check. Q: What is the difference between GDPR and NIS2? A: GDPR focuses specifically on protecting personal data. NIS2 takes a broader view of cybersecurity and the protection of network and information systems. There is significant overlap: both require security measures, incident reporting, and risk assessment. Q: What fines can I face under NIS2? A: NIS2 fines go up to 10 million euros or 2% of global annual turnover for essential entities, and up to 7 million euros or 1.4% for important entities. Directors can also be held personally liable. ## A new cybersecurity law alongside the GDPR The NIS2 directive (Network and Information Security Directive 2) is a European law requiring businesses to get their cybersecurity in order. While the GDPR focuses on personal data, NIS2 takes a broader look at the security of your networks, systems, and services. The directive has been in effect since October 2024 and is being transposed into national legislation by EU member states. For businesses already working under the GDPR, the good news is that there is considerable overlap. ## Who falls under NIS2? Under the Belgian NIS2 law you fall **directly within scope** when you meet three criteria at the same time: 1. You provide a service listed in Annex I or Annex II of the NIS2 law (see sectors below) 2. You are at least a **medium-sized enterprise**: 50+ full-time staff, or annual turnover and balance sheet total above 10 million euros 3. You have an establishment in Belgium ### Sectors **Annex I - highly critical sectors**: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space. **Annex II - other critical sectors**: postal and courier services, waste management, manufacture of chemicals, food production and distribution, manufacturing, digital providers, research. Within these sectors, the law splits entities into **essential** (regular supervision) and **important** (supervision after incident or complaint). The cybersecurity requirements are identical for both. ### Regardless of size Some providers fall under NIS2 **automatically**, even below the 50-FTE threshold: qualified trust service providers, DNS service providers, providers of public electronic communications networks, and organisations formally designated as critical entities. ### The supply chain - why smaller SMEs should pay attention too Not directly in scope but a **supplier** to an NIS2 entity? Your customer can contractually require you to implement appropriate cybersecurity measures. The CCB explicitly recommends that non-NIS2 suppliers meet at least the **Basic level of the CyberFundamentals framework** - exactly what GDPRWise helps you with. ### How to check whether NIS2 applies to you The CCB publishes a [NIS2 Scope Assessment Tool and Quickstart Guide](https://atwork.safeonweb.be/nis2). Registration was due by 18 March 2025 (18 December 2024 for digital providers). A conformity assessment via the CyberFundamentals framework is required by 18 April 2026. ## What does NIS2 require? The core obligations: - **Risk assessment** - identify and assess risks to your network and information systems - **Security measures** - take appropriate measures based on that risk assessment - **Incident reporting** - report significant incidents within 24 hours (early warning) and submit a full report within 72 hours - **Business continuity** - ensure backups, recovery plans, and crisis management - **Supply chain security** - assess the security risks of your suppliers - **Management accountability** - management is personally responsible for cybersecurity ## The overlap with GDPR If your GDPR compliance is in order, you already have a solid foundation: | Requirement | GDPR | NIS2 | |-------------|------|------| | Risk assessment | Yes (DPIA) | Yes | | Security measures | Yes (Art. 32) | Yes | | Incident reporting | 72 hours (data breach) | 24 hours (early warning) | | Documentation | Processing register | Security policy | | Supplier management | Data processing agreements | Supply chain review | ## How does GDPRWise help? GDPRWise Enterprise has a full NIS2 action list and templates built in. You do not start from scratch: every GDPR action you have already completed counts automatically toward NIS2. ### Based on the Belgian CyberFundamentals framework Our NIS2 action list follows the [CyberFundamentals framework](https://atwork.safeonweb.be/tools-resources/cyberfundamentals-framework) published by the Centre for Cybersecurity Belgium (CCB). The framework defines four assurance levels - Small, Basic, Important, and Essential - and our action list aligns with the **Basic level**. The Basic level is designed for any organisation that wants to protect itself against common cyber risks using generally available technology. In practice, this fits most SMEs. You do not need to be formally in scope of NIS2 to benefit: every SME that takes cyber and privacy seriously should at least be working toward this baseline. The framework is internationally grounded and maps onto NIST CSF, ISO 27001/27002, IEC 62443, and CIS Critical Security Controls. ### Your GDPR work, reused No duplicate effort. GDPRWise shows exactly which controls already count twice: - **Your third-party file** documents your suppliers and their security measures - directly usable for the NIS2 supply chain security requirement - **Your security checklist** shows which technical and organisational measures you have taken - **Your data breach procedure** forms the basis for your NIS2 incident reporting process - **Your processing register** contains the inventory of systems and data flows ### NIS2-specific actions and templates Where NIS2 goes beyond GDPR, we add the actions and templates: - **Risk assessment template** - a structured document to map out network and information system risks - **Information security policy** - a formal policy that meets NIS2 requirements - **Business continuity plan** - template for backup, recovery, and crisis management - **Incident reporting procedure** - aligned with the NIS2 timelines (24h early warning, 72h report) - **Management accountability** - documentation for executive approval and training - **Periodic controls** - 2FA reviews, access management, data retention, tuned for NIS2 ### Visible progression Your compliance score grows from **Basic** to **Advanced** to **NIS2 - Robust**. You see at a glance where you stand and what still needs to happen. ### Where does NIS2 sit in GDPRWise? NIS2 capabilities are in the **Enterprise plan**, or available separately as an **add-on** to Peace of Mind. Get in touch if you want to know whether NIS2 applies to your organisation. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### How to Anonymise Data under the GDPR URL: https://gdprwise.eu/en/kennisbank/beveiliging/data-anonymization/ Summary: Anonymised data falls outside the GDPR. But true anonymisation is harder than you think. This article explains the difference between anonymisation and pseudonymisation, and how to apply it correctly. Key takeaways: - Truly anonymised data falls outside the GDPR, but the bar for anonymisation is high - Pseudonymisation is not anonymisation - pseudonymised data is still personal data - Anonymisation must be irreversible: it must be impossible to re-identify the person - Anonymisation is a good way to retain data for statistics or analysis after the retention period expires FAQ: Q: What is the difference between anonymisation and pseudonymisation? A: With pseudonymisation, you replace identifying data with a code or alias, but you store a key somewhere that can re-identify the person. With anonymisation, you remove all identifying elements so re-identification is impossible. Pseudonymisation still falls under the GDPR, anonymisation does not. Q: When should I anonymise data? A: Anonymisation is useful when you want to retain data for statistics or analysis, but the retention period for the personal data has expired. Instead of deleting the data, you anonymise it and keep it for business insights. Q: Is removing names sufficient to anonymise data? A: Usually not. Removing just names is often insufficient if the person can still be re-identified through other data in the dataset, such as address, date of birth, or unique characteristics. True anonymisation requires that no combination of remaining data can lead to re-identification. ## Anonymised data falls outside the GDPR That sounds attractive: if you properly anonymise data, it is no longer personal data and you don't need to comply with the GDPR. But there's a catch. True anonymisation is harder than most people think. ## Anonymisation vs. pseudonymisation This distinction is crucial and often confused. ### Pseudonymisation You replace identifying data with a code. Customer number 12345 instead of John Smith. But somewhere a table exists that links customer number 12345 to John Smith. As long as that link exists, it's still personal data. **Pseudonymisation is a good security measure**, but it is not anonymisation. The GDPR still applies. ### Anonymisation You remove or modify data such that it is impossible to re-identify the person, even by combining data with other sources. There is no key, no mapping table, no way back. **Anonymised data falls outside the GDPR.** You may store and use it without the restrictions of privacy legislation. ## Techniques for anonymisation ### Generalisation Replace specific values with broader categories. Instead of "32 years old" you write "30-39 years". Instead of "Amsterdam" you write "North Holland". ### Suppression Remove certain fields entirely from the dataset. No name, no address, no date of birth. ### Perturbation Add noise to the data. Change exact values to ranges or add random variation, so individual values are no longer accurate but statistical patterns remain intact. ### Aggregation Present data only as totals or averages. "42 customers from North Holland" instead of individual records. ## The pitfalls ### Re-identification through combination Even if you remove names and addresses, a combination of age, postcode, and occupation can often lead to re-identification. Research shows that with three such characteristics, more than 80% of people are uniquely identifiable. ### Small datasets The smaller the dataset, the harder anonymisation becomes. If your dataset contains only 5 customers from a particular city, an "anonymised" record containing the city is still traceable. ### The test Ask yourself: can someone with access to other public or commercial datasets re-identify the persons in my dataset? If the answer is yes or maybe, it's not truly anonymised. ## When to anonymise? The most common application is retaining data for analysis after the retention period expires. Instead of completely deleting customer data, you anonymise it and keep the statistical value. Other applications: - **Test environments** - use anonymised copies of production data for software testing - **Reports** - share trends and statistics without exposing individual data - **Research** - analyse patterns without violating individuals' privacy import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Information Security Policy - What Should It Include? URL: https://gdprwise.eu/en/kennisbank/beveiliging/information-security-policy/ Summary: An information security policy describes how your organisation protects personal data and business information. This article explains what to include, how to draft it, and how to keep it up to date. Key takeaways: - An information security policy describes the rules and measures to protect business information and personal data - The policy must be practical: employees need to understand and follow it - Start with the basics: passwords, access, clean desk, incident reporting, and device usage - Review the policy at least annually and after every security incident FAQ: Q: Is an information security policy mandatory under the GDPR? A: The GDPR requires 'appropriate technical and organisational measures.' A security policy is an organisational measure that demonstrates you take security seriously. It is not explicitly mandated, but it greatly helps in demonstrating compliance. Q: How long should the document be? A: Quality over quantity. For an SME, 2-4 pages is often sufficient. What matters most is that it is practical and actually followed. A thick document that nobody reads has no value. Q: Should employees sign the policy? A: It is recommended. By signing, employees confirm they have read the policy and agree to it. This strengthens your position if an incident occurs later. ## Why you need a security policy You can have the best technical security in place, but if your employees don't know the rules, it's like installing an alarm system and sticking the code on a post-it next to the door. An information security policy describes the rules and expectations for everyone in your organisation. It tells employees what they can and cannot do with business information and personal data. And it shows the regulator that you take security seriously. ## What should it include? ### Purpose and scope Briefly describe why the policy exists and who it applies to. Typically it covers all employees, freelancers, and interns with access to business systems or data. ### Passwords and authentication - Requirements for password strength and uniqueness - Mandatory two-factor authentication where available - Prohibition on sharing passwords - Use of a password manager ### Access control - Rights granted based on role (need-to-know) - Rights reviewed when roles change - All access revoked immediately upon departure - Periodic review of access rights ### Device usage - Rules for using company devices - BYOD policy if employees use personal devices - Mandatory disk encryption and screen lock - Rules for working on public networks (use a VPN) ### Clean desk and clear screen - Documents with personal data stored away when leaving the workstation - Screens locked when away - Confidential prints collected immediately from the printer ### Email and communication - Guidelines for sending personal data via email - When encryption is required - How to handle suspicious emails (phishing) - Use of personal email addresses for work matters ### Incident reporting - How employees should report a security incident - Who to report it to - Within what timeframe (as soon as possible) - That there are no negative consequences for reporting mistakes ### External storage and tools - Which cloud storage services are approved - Prohibition on using unapproved tools for business data - Rules for sharing files with external parties ## How to draft it 1. **Start with a template** - no need to reinvent the wheel. Use an existing template and adapt it 2. **Make it practical** - write in plain language. Avoid legal jargon 3. **Discuss it with your team** - ensure employees can provide input and ask questions 4. **Have it signed** - each employee confirms they have read and understood the policy 5. **Make it accessible** - store it somewhere everyone can find it ## Keep it alive A security policy that you write and forget has little value. Review it: - **Annually** - is it still current? - **After an incident** - does anything need tightening? - **When things change** - new tools, new employees, new ways of working? import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### List of Approved Third Countries for Data Transfers Outside the EU URL: https://gdprwise.eu/en/kennisbank/beveiliging/approved-third-countries/ Summary: The GDPR restricts transfers of personal data to countries outside the EU, unless an adequacy decision applies. Here you'll find the current list and what it means for you. Key takeaways: - Data transfers to countries with an adequacy decision are allowed without additional safeguards - The European Commission assesses whether a country offers a comparable level of protection - The United States has the EU-US Data Privacy Framework since 2023, but its durability is uncertain - To countries without an adequacy decision, you may transfer data using Standard Contractual Clauses (SCCs) FAQ: Q: What is an adequacy decision? A: An adequacy decision is a formal decision by the European Commission that a country outside the EU offers a comparable level of data protection. If a country has such a decision, you may transfer personal data to that country as if it were an EU country. Q: May I send data to the US? A: Since July 2023, the EU-US Data Privacy Framework applies for US companies that have certified themselves. You may send data to certified companies. Check at dataprivacyframework.gov whether the specific organisation is certified. Q: What if a country doesn't have an adequacy decision? A: Then you can use Standard Contractual Clauses (SCCs), a set of standard contract terms approved by the European Commission. Most large cloud providers already include these in their terms. ## Not every country offers the same protection The GDPR essentially prohibits the transfer of personal data to countries outside the European Economic Area (EEA), unless that country offers a comparable level of data protection. The European Commission assesses this per country and issues a so-called adequacy decision when the assessment is positive. For you as a business owner, this is relevant as soon as you use software or services from companies outside the EU. ## Countries with a full adequacy decision The following countries and territories have been assessed as adequate by the European Commission (as of April 2026): - **Andorra** - **Argentina** - **Canada** (for commercial organisations under PIPEDA) - **Faroe Islands** - **Guernsey** - **Israel** - **Isle of Man** - **Japan** - **Jersey** - **New Zealand** - **Republic of Korea (South Korea)** - **Switzerland** - **Uruguay** - **United Kingdom** - **United States** (via the EU-US Data Privacy Framework, only for certified organisations) You may transfer personal data to these countries without additional safeguards, provided the conditions of the specific decision are met. ## The EU-US Data Privacy Framework The adequacy decision for the United States deserves extra attention. It only applies to US organisations that have actively certified themselves via the Data Privacy Framework. You can check at [dataprivacyframework.gov](https://dataprivacyframework.gov) whether a specific company is certified. Major tech companies like Google, Microsoft, Amazon, and Meta are certified. But not every US company is. Always verify before assuming your data transfer is safe. It's worth noting that previous adequacy decisions for the US (Safe Harbor and Privacy Shield) were struck down by the European Court of Justice. The current framework may face the same fate. Keep this in mind. ## What if a country is not on the list? For countries without an adequacy decision, you need additional safeguards: ### Standard Contractual Clauses (SCCs) The most commonly used option. These are standard contract terms approved by the European Commission. You agree to them with the party in the third country. Most major software providers have already included SCCs in their processing agreements. ### Binding Corporate Rules (BCRs) For multinational companies transferring data internally between offices in different countries. Less relevant for SMEs. ### Explicit consent In exceptional cases, you may transfer data based on explicit, specified consent from the data subject. This is not a structural solution. ## What should you record? In your GDPRWise third-party dossier, you can record per supplier: - In which country the data is processed - Whether an adequacy decision applies - Which additional safeguards you have in place (SCCs, DPF certification) This makes it easy to demonstrate during an inspection that your third-country transfers are in order. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Password Policy: Best Practices for Your Business URL: https://gdprwise.eu/en/kennisbank/beveiliging/password-best-practices/ Summary: Weak passwords are one of the biggest security risks for SMEs. This article provides practical guidelines for a good password policy: password managers, 2FA, minimum length, and common mistakes. Key takeaways: - Use a password manager for your entire team, not sticky notes or shared spreadsheets - Enable two-factor authentication (2FA) on all systems containing personal data - Set a minimum password length of 12 characters and never reuse passwords - Change passwords after a data breach, not on a fixed schedule FAQ: Q: Is a password policy mandatory under the GDPR? A: The GDPR does not prescribe a specific password policy, but does require 'appropriate technical and organisational measures' (Article 32). A good password policy is one of the most basic measures. In case of a data breach due to a weak password, the supervisory authority will consider this negligence. Q: How long should a password be at minimum? A: Current guidelines from NIST and most European supervisory authorities recommend at least 12 characters. Longer is better. A passphrase of four or five random words is both strong and easy to remember. Q: Should passwords be changed regularly? A: No, not anymore. Mandatory regular changes lead to people choosing weaker passwords or using counter patterns (Password1, Password2). Only change passwords after a suspected data breach or compromise. Q: Which password manager is best for a small business? A: Bitwarden (open source, free for individual use) and 1Password (business plan from a few euros per user per month) are both good options for SMEs. Both offer team functionality and 2FA support. ## Why passwords matter A weak password is the simplest way to access personal data. No complicated hack, no advanced technique - just logging in with a guessed or stolen password. Research shows that weak or reused passwords are involved in more than 80% of successful attacks on business systems. The GDPR requires in Article 32 that you take "appropriate technical and organisational measures" to protect personal data. A good password policy is one of the cornerstones. ## The five ground rules ### 1. Use a password manager This is the most important step you can take. A password manager generates strong, unique passwords for each system and remembers them for you. Your team only needs to remember one strong master password. Good options for SMEs: - **Bitwarden** - open source, free for individual use, affordable business plan - **1Password** - user-friendly, strong business plan with team functionality No Excel files, no shared notes, no passwords in emails. ### 2. Enable 2FA everywhere Two-factor authentication (2FA) adds a second verification layer alongside your password - usually a code on your phone or a hardware key. Even if a password is stolen, an attacker cannot log in without that second factor. Enable 2FA on: - Email (Google Workspace, Microsoft 365) - CRM systems - Accounting software - Cloud storage (Google Drive, Dropbox, OneDrive) - Company social media accounts Make it mandatory, not optional. Check that everyone has actually activated it. ### 3. Minimum 12 characters The days of 8-character passwords are over. Current guidelines recommend at least 12 characters. A passphrase works excellently: four or five random words together, like "umbrella-bicycle-coffee-tuesday". Long, strong, and still memorable. With a password manager, length is no longer an issue since you don't need to remember the passwords. ### 4. Never reuse Every system gets a unique password. If you use the same password for your email, CRM, and accounting software, only one system needs to be hacked to gain access everywhere. This is exactly why a password manager is so important. Nobody can remember dozens of unique 16-character passwords, but a password manager does so effortlessly. ### 5. Change after a breach, not on a schedule The old advice to change passwords every 90 days is outdated. Research shows that mandatory regular changes lead to weaker passwords: people choose predictable patterns (January2024!, February2024!) or write the new password on a sticky note. Change passwords only when: - There has been a data breach - You suspect a password has been compromised - An employee leaves (for shared accounts) ## Common mistakes **The sticky note on the monitor.** The classic image: a strong password neatly written on a yellow note next to the screen. All effort for nothing. **The shared account.** "We all use the same login for the CRM." Result: you can't trace who did what, and when an employee leaves, everyone needs to change their password. **"Welcome123" as default password.** New employees get a default password they should change "later". Spoiler: it doesn't happen. **Passwords in WhatsApp or email.** "Can you send me the accounting system password via WhatsApp?" Those messages stay on phones that aren't encrypted, in chats that aren't cleared. **Password only, no 2FA.** A password alone is not enough. With phishing or a leaked password, the door is wide open if there's no second factor. ## How to implement it 1. **Choose a password manager** and roll it out for the entire team 2. **Enable 2FA** on all systems containing personal data 3. **Set minimum requirements**: 12 characters, unique per system 4. **Communicate the policy** clearly to your employees 5. **Check compliance** - enable mandatory 2FA where possible and verify that everyone actually uses the password manager import CourseTip from '@/components/CourseTip.astro'; These tips are covered in depth in the "Securing accounts" module of our free Security awareness course: password managers, two-factor authentication and passkeys. No account needed, with a certificate. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Periodically Check Access Controls for All Your Tools URL: https://gdprwise.eu/en/kennisbank/beveiliging/periodic-access-review/ Summary: Who has access to which data in your business? If you don't check regularly, risks accumulate. This article explains how to set up a periodic access review. Key takeaways: - Former employees, interns, and external parties often retain access longer than necessary - Schedule at least two access reviews per year across all systems - Start with your most sensitive systems: HR, financial, CRM, and email - Document your review to demonstrate active access management FAQ: Q: How often should I perform access reviews? A: The GDPR does not prescribe a specific frequency, but at least twice a year is a good guideline. For businesses with high staff turnover or external workers, quarterly is wiser. Q: What do I do if I find an old account that's still active? A: Deactivate the account immediately. If it concerns a former employee, check whether that person accessed data in the meantime. Document your finding and the action taken. Q: Which tools should I check? A: All tools where personal data is processed: CRM, accounting software, email tool, HR system, cloud storage, project management, and shared accounts for social media or analytics. ## Access you forget to revoke is a risk It's one of the most common security problems for SMEs: people who once received access to systems and still have it, even though they no longer need it. Last year's intern who can still access your CRM. The freelancer who can still access your cloud storage. The former employee whose email account is still active. Every unused access is a potential security risk and a GDPR issue. ## Why periodic checks? Access rights change continuously: - **Employees leave** - their accounts must be deactivated immediately - **Roles change** - someone moving from sales to marketing needs different access - **External parties change** - your old accountant no longer needs system access - **Tools change** - new software is added, old tools not always cleaned up - **Rights accumulate** - people gain rights but rarely lose them ## How to conduct an access review ### 1. List your tools Start with all systems and tools where personal data is processed. Prioritise the most sensitive: - HR and payroll system - Accounting software - CRM system - Email accounts - Cloud storage - Social media accounts - Analytics and advertising platforms ### 2. Check who has access per tool Log in as administrator and review the user list. For each account, ask: - Does this person still work here? - Does this person still need this access for their current role? - Is the access level correct (admin vs. regular user)? ### 3. Clean up - **Deactivate** accounts of departed employees and external parties - **Downgrade rights** where someone has too much access - **Remove** shared accounts and replace them with personal logins ### 4. Document Record when you performed the review, what you found, and what actions you took. This is your evidence of active access management. ## Make it a routine Schedule your access review in your calendar, just like you periodically update your accounting. Twice a year is a good starting point. Link it to a fixed moment, for example at the end of each half-year or after every major personnel change. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Privacy Governance Framework - Structuring Your Privacy Policy URL: https://gdprwise.eu/en/kennisbank/beveiliging/privacy-governance-framework/ Summary: A privacy governance framework brings structure to how your organisation handles personal data. Learn what it involves and how to build one step by step. Key takeaways: - A privacy governance framework defines who is responsible for what regarding data protection - It doesn't have to be complicated: for an SME, a simple framework with clear roles and processes is sufficient - The framework covers policy documents, responsibilities, incident and rights processes, and periodic reviews - GDPRWise helps you build the core of this framework through its dossiers and documents FAQ: Q: Is a privacy governance framework mandatory under the GDPR? A: The GDPR doesn't explicitly require a 'governance framework', but it does require you to demonstrate compliance (the accountability principle). A framework is the most structured way to achieve that. Q: How extensive should the framework be for a small business? A: For an SME, a simple framework is sufficient: clear responsibilities, a privacy policy, a data breach procedure, a process for data subject rights, and an annual review. For most businesses, that alone is a major step forward. Q: Who should be responsible for privacy in my company? A: That depends on your company size. In a small business, it's usually the director or owner. In a larger company, a compliance officer, HR manager, or dedicated privacy officer can fill this role. In GDPRWise, this is the GDPR Coordinator. ## Bringing structure to your privacy approach Privacy compliance is more than ticking off a checklist. It requires a structural approach: who is responsible, what processes are in place, how do you respond to incidents, and how do you keep everything up to date? A privacy governance framework answers these questions. This may sound like something only large corporations need, but even for SMEs a simple framework is valuable. It doesn't need to be a lengthy document - it just needs to make clear how your organisation handles personal data. ## The four pillars ### 1. Responsibilities Who is responsible for privacy in your organisation? - **Ultimate responsibility** - typically the director or owner. They carry the formal responsibility for GDPR compliance - **Operational responsibility** - the person managing it day to day. In GDPRWise, this is the GDPR Coordinator - **Employees** - everyone who works with personal data has a role. They need to know what is and isn't allowed - **External parties** - suppliers and partners with whom you share data must also comply with the rules ### 2. Policy documents The documents that record how your organisation handles personal data: - **Privacy statement** - informs data subjects about how you process their data - **Internal privacy policy** - describes the rules for employees - **Data breach procedure** - describes what you do in case of a security incident - **Retention policy** - determines how long you keep different types of data - **Processing register** - documents all your processing activities GDPRWise generates most of these documents automatically based on your dossiers. ### 3. Processes The procedures you follow in specific situations: - **Access requests** - how do you respond when someone wants to view or delete their data? - **Data breaches** - how do you discover, assess, and report a breach? - **New processing activities** - how do you assess whether a new tool or process is GDPR-compliant? - **Complaints** - how do you handle privacy complaints? ### 4. Review and improvement Privacy is not a one-off project: - **Annual review** - check at least once a year whether your policies and dossiers are still current - **When changes occur** - update your documentation when new tools, processes, or staff changes are introduced - **After incidents** - evaluate after every incident whether your processes need improvement - **Regulatory changes** - keep track of changes in privacy legislation. GDPRWise alerts you to these ## How to get started If you already use GDPRWise, you have much of the framework in place: 1. **Your dossiers** form the basis of your processing register 2. **Your documents** (privacy statement, DPAs) are generated automatically 3. **Your GDPR Coordinator** is your operational lead 4. **The compliance score** shows where you stand and what still needs attention What you add on top is an agreement about periodic reviews and a procedure for incidents and requests. This doesn't need to be a lengthy document - a single page with clear agreements is a solid start. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### System and Software Security - Key Principles URL: https://gdprwise.eu/en/kennisbank/beveiliging/system-software-security/ Summary: The software and systems you use form the foundation of your data security. This article covers the principles you need to apply to keep your systems secure. Key takeaways: - Keep all software up to date - most cyberattacks exploit known vulnerabilities - Apply the principle of least privilege: give users only the permissions they need - Segment your networks: your guest network should not have access to business data - Enable logging so you can trace what happened during an incident FAQ: Q: Do I need to hire an IT specialist for system security? A: That depends on your situation. You can handle the basics (updates, passwords, backups) yourself. If you have a more complex IT environment, manage your own server, or process sensitive data, professional advice is recommended. Q: How often should I update software? A: As soon as possible after an update is released, especially security updates. Enable automatic updates wherever possible. For business-critical systems, you can test updates in a staging environment first. Q: What is the single most important thing I can do right now? A: Enable automatic updates for all your software and devices. This one step prevents the majority of attacks that target SMEs. ## Your systems are your first line of defence The software you use, the devices you work on, and the network you connect to - together they form the foundation of your data security. If that foundation is weak, written policies won't help much. The GDPR requires "appropriate technical measures". The following principles cover what you should apply to your systems and software. ## Principle 1: Keep everything up to date The majority of successful cyberattacks exploit known vulnerabilities for which a patch was already available. Installing updates is the single most effective security measure you can take. - **Operating system** - enable automatic updates on all workstations and servers - **Browsers** - always use the latest version - **Business software** - schedule regular updates for your CRM, accounting, and other tools - **Firmware** - don't forget your router, printer, and other network devices - **Plugins and extensions** - outdated WordPress plugins or browser extensions are a common attack vector ## Principle 2: Least privilege Give users only the access they need for their work, nothing more. This limits the damage if an account is compromised. - Not everyone needs to be an admin - Create separate accounts for daily use and administration - Remove permissions as soon as they are no longer needed - Use groups or roles to assign permissions consistently ## Principle 3: Segment your network Keep different types of traffic separate: - **Guest network** separate from your business network - visitors and customers don't need access to your internal systems - **IoT devices** on a separate network - smart devices are often poorly secured - **Sensitive systems** behind extra protection - your HR system or financial records don't need to be reachable from every device ## Principle 4: Encryption Encrypt data both at rest and in transit: - **In transit** - use HTTPS for your website, VPN for remote workers, TLS for email - **At rest** - enable disk encryption on laptops and external storage media (BitLocker on Windows, FileVault on macOS) - **Backups** - encrypt your backups as well, especially if they are stored off-site ## Principle 5: Logging and monitoring When something goes wrong, you need to be able to trace what happened: - Enable logs on your most important systems - Retain logs long enough to investigate incidents (at least 3 months) - Periodically check for unusual activity - Ensure logs cannot be deleted by an attacker ## Principle 6: Backup and recovery A backup you can't restore is not a backup: - Make daily backups of business-critical data - Keep at least one backup offline or at a different location - Regularly test whether your backups can actually be restored - Document your recovery procedure so you don't have to improvise during a crisis ## Apply what fits your situation Not every business has the same security needs. An online shop with customer data has different priorities than a consultancy firm. But the principles above apply universally. Start with the basics and build from there. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### The Human Factor: Why Most Data Breaches Start with Your Employees URL: https://gdprwise.eu/en/kennisbank/beveiliging/human-factor-data-breaches/ Summary: 80 to 90 percent of all data breaches have a human cause. This article discusses the most common scenarios, from phishing to misdirected emails, and gives practical tips to make your team more resilient. Key takeaways: - 80 to 90 percent of all data breaches have a human cause, not a technical one - The most common scenarios are phishing, wrong email recipients, lost devices, and weak passwords - Awareness training and clear procedures are more effective than technical measures alone - A no-blame culture ensures incidents are reported faster FAQ: Q: Is security awareness training mandatory under the GDPR? A: The GDPR requires appropriate technical and organisational measures. Employee training is an organisational measure. While the law doesn't prescribe a specific programme, supervisory authorities expect it. After a breach caused by employee ignorance, the authority will ask whether training was provided. Q: How often should I train my employees? A: At least annually, and with every significant change in processes or systems. Short, frequent reminders (a monthly tip or quarterly phishing simulation) are more effective than a two-hour annual presentation. Q: What is a no-blame culture for data breaches? A: A culture where employees dare to report incidents without fear of punishment. If an employee clicks a phishing link and only reports it after three days out of fear, you lose valuable time. Quick reporting limits the damage. Q: Are simulated phishing tests allowed? A: Yes, as long as the purpose is training, not punishment. Inform employees that periodic simulations take place. Use results for targeted training, not performance reviews. ## The problem isn't in the technology You can have the best firewall, the strongest encryption, and the most expensive security software. But if an employee clicks a phishing link, sends an email to the wrong person, or leaves their laptop on the train, none of that helps. The numbers don't lie: 80 to 90 percent of all data breaches start with human action. Not brilliant hackers, but ordinary mistakes by ordinary people on a busy workday. The GDPR expects you to address this. Article 32 requires not only technical measures but also organisational ones. And training your employees is an essential part of that. ## The five most common scenarios ### 1. Phishing An employee receives an email that looks like it's from a colleague, customer, or supplier. The email contains a link to a fake login page or an attachment with malware. One click and the attacker has access to login credentials or your network. Phishing is becoming increasingly sophisticated. With AI tools, attackers can create convincing, personalised messages in perfect language. The days of bad grammar and Nigerian princes are over. ### 2. Wrong recipient One of the most common breaches for SMEs: an email with personal data sent to the wrong person. Your email program's autocomplete fills in the wrong address, or you send a CC instead of BCC to a group of customers. Simple, everyday, and yet a full data breach. ### 3. Lost or stolen devices A laptop left on the train. A phone falling from a jacket pocket on a terrace. A USB stick that goes missing at a client's office. If the device contains unencrypted personal data, you have a data breach. ### 4. Weak passwords and password reuse "Welcome123" on the CRM. The same password for business email and personal Netflix account. No two-factor authentication enabled. These are human choices that open the door for attackers. ### 5. Social engineering A phone call from "the IT department" asking for login credentials. A message from "the director" asking to make a quick payment. Social engineering plays on trust, authority, and time pressure. Untrained employees are more likely to fall for it. ## What can you do? ### Awareness training Train your employees regularly, but keep it practical and short. Nobody wants a two-hour PowerPoint about information security policy. Effective approaches: - **Short monthly tips** via email or an internal channel - **Concrete examples** from your own industry, not abstract threat scenarios - **Interactive sessions** where employees learn to recognise phishing emails - **Onboarding module** for new employees ### Simulated phishing Periodically send fake phishing emails to your employees. Not to catch them, but to train them. Those who click get immediate brief explanation about what the signals were. This is one of the most effective ways to increase awareness. ### Clear procedures Ensure employees know what to do when something goes wrong: - **Who do you report a suspicious email to?** - **What do you do if you clicked a wrong link?** - **How do you report a lost device?** - **What if you accidentally sent an email to the wrong person?** Make these procedures simple and accessible. A one-page quick guide that everyone knows is more effective than a 50-page security handbook nobody reads. ### No-blame culture This is perhaps the most important point. If employees fear punishment, they don't report incidents or report them too late. And with data breaches, every minute counts. Create a culture where mistakes may be reported without consequences. An employee who reports within five minutes that they clicked a phishing link gives you the chance to act quickly. An employee who hides it for three days out of fear makes the damage many times greater. ## The cost of doing nothing A breach notification to the authority. A fine. Loss of customer trust. Costs for recovery and investigation. A single moment of inattention can cost thousands of euros. An awareness training costs a fraction of that. Invest in your people, because they are both your biggest risk and your best defence. import CourseTip from '@/components/CourseTip.astro'; Teach your team, in short modules, how to handle data safely: strong passwords, recognising and reporting a data breach, and secure access. Want to tackle phishing specifically? Take the Recognising phishing course too. No account needed, with a certificate. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### When an Employee Leaves: How to Handle Their Email Account URL: https://gdprwise.eu/en/kennisbank/beveiliging/former-employee-email-accounts/ Summary: When someone leaves your company, you cannot simply take over or delete their work email account. A Norwegian firm learned this the hard way with a 14,700 EUR fine. Here is how to handle departing employees' accounts under the GDPR. Key takeaways: - A named work email (firstname.lastname@yourcompany.eu) is the personal data of that employee, so keeping it active after they leave is ongoing processing - Give the employee the opportunity to remove their personal content before you take over or close the account - Never access or take over a personal work email account without informing the employee first (Article 13) - Close the personal work email once the employee has left, and rely on generic addresses like info@ or sales@ for business continuity - Deactivating a mailbox is not deleting it: after a short transitional period, delete it, as the Belgian DPA confirmed in 2026 FAQ: Q: Can I just take over a departing employee's email account? A: Not without care. A named work email such as firstname.lastname@yourcompany.eu contains the employee's personal data, so accessing or taking it over is processing under the GDPR. You must inform the employee, give them the opportunity to remove personal content, and have a lawful basis. A Norwegian company that changed the password and took over an account during the notice period, without telling the employee, was fined 14,700 EUR. Q: Can I keep a former employee's email active to catch incoming customer mail? A: No, not indefinitely. The Norwegian DPA found that keeping the inbox running after the employee left was a breach of the GDPR. The correct approach is to close the personal account and steer customers to a generic address such as info@ or sales@, optionally with a temporary auto-reply pointing to the new contact. The Italian Garante said the compliant alternative is precisely an auto-reply that points senders to other addresses, without reading the incoming mail. Q: Is deactivating the mailbox enough, or do I have to delete it? A: Deactivating is not the same as deleting. In 2026 the Belgian DPA fined a company around 176,000 EUR partly because a former employee's mailbox kept existing on its servers. As long as the mailbox exists, you are still processing that person's personal data. A short transitional period of roughly a month can be justified, after which you should delete the mailbox. Q: What should I do before an employee leaves? A: Have an employee privacy policy that covers email and account use, document your offboarding process, and give the employee a clear opportunity to delete personal content from their mailbox and other tools before their access ends. Q: Why should I avoid relying on personal work email addresses? A: If a function depends on firstname.lastname@yourcompany.eu, you are tempted to keep that account alive after the person leaves, which is exactly what gets companies fined. Generic addresses like sales@ or info@ let you close personal accounts cleanly without losing business continuity. When an employee leaves your company, what do you do with their accounts? They will probably have a corporate email account issued by the firm, plus accounts on the tools you use day to day: the CRM, the HR system, and so on. Can you just delete or take over these accounts? Taking the GDPR and good privacy practice into account, you have to be more careful than you might expect. ## A 14,700 EUR lesson from Norway A Norwegian company made several mistakes handling the email account of a former employee, and it cost them 14,700 EUR in fines. It is worth understanding what went wrong. An employee ended their employment with the company. During the notice period, the employer changed the password and took over the work email account, without letting the individual know, and therefore without giving them the opportunity to delete personal content. On top of that, the account was not closed after the employee left. The former employer ignored the request to delete the email account and only set a vacation note. Asked to explain, the company argued that it needed to keep the inbox running to maintain customer relations and receive operational information until the employee had been replaced. The Norwegian data protection authority found several breaches of the GDPR: - Accessing the employee's email account and emails was unlawful. - The employer failed to inform the employee, breaching Article 13. - The employer did not discontinue the employee's email account. For these breaches, the company was fined 14,700 EUR. ## This is not a one-off Norway is not an outlier. Data protection authorities across Europe keep fining employers for exactly this, and the rulings are getting firmer. **Italy, 2023.** The Italian authority (Garante) fined a company 5,000 EUR after it kept a departed collaborator's mailbox active, read the incoming mail, and set up automatic forwarding to another employee. The employer argued it needed the account to defend itself in court. The Garante rejected that outright: the interest in defending a legal claim cannot override someone's right to data protection. It also spelled out the correct alternative, which is to set an **automatic reply that points senders to other addresses, without reading the incoming mail**. **Belgium, 2026.** The Belgian DPA fined a company roughly 176,000 EUR for keeping a former employee's mailbox active for about six months after departure. The key lesson: **deactivating a mailbox is not the same as deleting it.** As long as the mailbox keeps existing on your servers, you are still processing that person's personal data. A short transitional period (typically around one month) can be justified, but after that the mailbox has to go. ## Why a work email is personal data A named work email such as `firstname.lastname@yourcompany.eu` identifies a specific person. That makes it the personal data of that employee. Keeping the account active after they leave, reading the mail that arrives, or taking it over without notice are all forms of processing, and each needs a lawful basis and proper transparency. This is the part many businesses miss. Closing the account feels like an IT housekeeping task, but under the GDPR it is a processing decision about someone's personal data. ## Best practice for departing employees' accounts Based on the Norwegian ruling and similar cases, we recommend the following: ### 1. Put an employee privacy policy in place Make sure you have an employee privacy policy that covers the use and access of mail accounts and other accounts, so staff know in advance how their accounts are handled. ### 2. Document your internal process Write down how your company handles accounts and the handover of accounts when employment ends. A clear, repeatable offboarding process is your best protection. ### 3. Never take over a personal work email without notice Do not change the password on, or take over, a personal work email account such as `firstname.lastname@yourcompany.eu` without informing the employee first. Give them the opportunity to remove their personal content. ### 4. Close the account, and actually delete it Always discontinue a personal work email account such as `firstname.lastname@yourcompany.eu` once the employee has left the company. Do not keep it running indefinitely to catch incoming mail. Remember the Belgian lesson: deactivating is not deleting. After a short transitional period (around a month), delete the mailbox for good. ### 5. Use an auto-reply instead of reading the inbox If you need a window to redirect contacts, set an automatic reply that points senders to a generic address, without opening or forwarding the incoming mail. This is exactly the approach the Italian authority described as the compliant alternative. ### 6. Do not depend on personal work emails for business functions Do not rely solely on personal work email accounts for any function within the firm. Set up generic addresses such as `sales@yourcompany.eu` or `info@yourcompany.eu`, and ask customers to use these. That way you can close a personal account cleanly when someone leaves, without losing continuity. ## References - Norwegian DPA ruling (2021, 14,700 EUR): [Virksomhet får gebyr for innsyn i tidligere ansatts e-postkasse](https://www.datatilsynet.no/regelverk-og-verktoy/lover-og-regler/avgjorelser-fra-datatilsynet/2021/virksomhet-far-gebyr-for-innsyn-i-tidligere-ansatts-e-postkasse-og-manglende-avslutning-av-e-postkassen/) - Italian Garante decision (2023, 5,000 EUR): [Company email: the employer's right of defence in court cannot limit the worker's right to data protection](https://www.delucapartners.it/en/dlp-insights-en/company-email-the-employers-right-of-defence-in-court-cannot-limit-the-workers-right-to-the-protection-of-personal-data/) - Belgian DPA fine (2026, ~176,000 EUR): [Belgium: unlawful mailbox retention leads to EUR 176,000 fine](https://www.bakermckenzie.com/en/insight/publications/2026/05/belgium-unlawful-mailbox-retention-leads-to-eur-176000-fine) import ArticleCTA from '@/components/ArticleCTA.astro'; --- ## How GDPRWise Works ### 5 Steps to Get the Most Out of GDPRWise URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/5-steps-most-out-of-gdprwise/ Summary: A step-by-step guide for SME owners on how to use GDPRWise effectively, from the AI website scan to a published privacy policy. Five focused steps, plus a note on security and data subject rights. Key takeaways: - The AI website scan does most of the heavy lifting before you answer a single question - Refining the customer, staff, and third-party dossiers turns the scan results into your actual processing register - Generating and publishing your privacy policy is the visible output, but the dossier underneath is what makes you compliant - GDPR also requires documented security and data subject rights handling, so the work does not end at the privacy policy FAQ: Q: Do I have to follow these five steps in order? A: No. You can work in any order, and you do not have to finish everything in one session. The order below is what we recommend for most SME owners because each step builds on the previous one. Take your time and refine where needed before you generate your privacy policy. Q: What if my company has no employees? A: Still take a quick look at the staff dossier. It includes processes you may not have thought of, such as independent contractors or company officers whose personal data you process. The dossier suggests these so you do not overlook them. Q: Do I need to redo the scan when my website changes? A: On the Free Scan you can re-run the scan manually whenever you change tools, add a tracker, or launch a new page. On the Peace of Mind plan, GDPRWise rescans your site automatically, compares the findings to your existing dossier, and flags what needs your attention. Q: Is the privacy policy enough to be GDPR compliant? A: No. The privacy policy is the visible output, but GDPR also requires that you actually handle personal data securely and respect data subject rights (access, correction, deletion, portability, objection). GDPRWise documents these obligations in your dossier; carrying them out in practice is your responsibility. ## Why a structured approach helps GDPR can feel overwhelming when you read the regulation cold: 99 articles, dense legal language, no obvious starting point. GDPRWise removes most of that friction by doing the structural work for you, but you still get the most value when you walk through the platform with a plan. This is that plan. Five focused steps, plus a sixth note on security and data subject rights. You do not have to do everything in one sitting; pause, reflect, and refine where it makes sense before you press the Generate Privacy Policy button. If you are an accountant, lawyer, or IT professional offering GDPRWise to clients, we have a separate [Reseller Runbook](/en/kennisbank/hoe-gdprwise-werkt/reseller-runbook/) for you. ## Step 1 - Run the AI website scan Start with the scan. This is the entry point that did not exist in earlier versions of GDPRWise and it changes how the rest of your work feels. The scan visits your website and detects: - Cookies and trackers - Third-party scripts and embedded services - Forms that collect personal data - Signals that match your business to a sector foundation Combined with the sector foundation, the scan pre-populates your dossier so it starts roughly 60 to 70 percent complete. Tools like Google Analytics, Stripe, Mailchimp, or your booking system are recognised automatically and added as processing activities with sensible default purposes, legal bases, and retention periods. What you should do at this step: - Run the scan on your main domain - Read through what was detected and added - Note anything that looks unfamiliar or unexpected, you will confirm or correct it in the next steps The scan is not the end of the work; it is the head start. ## Step 2 - Refine your customer dossier Open **My Customer Dossier**. This is where you list the processes (the interactions with your customers) that involve personal data. The scan and sector foundation have already added the obvious ones; your job is to confirm them and add anything specific to your business. Why this matters: the customer dossier is what lets you tell your customers, in your privacy policy, exactly what data you use and why. It is also what supervisory authorities ask for first if they ever come knocking. What we recommend: - Open the software you use day to day to serve customers (CRM, invoicing, mailing, booking, support tooling) so you do not overlook anything - Confirm the suggested processes apply to you, and remove what does not - Use the **Consider adding** section at the bottom: it lists processes that are common in your sector and that the scan might not have detected - Add the legal basis and retention period if not already filled in by the foundation You are not trying to write a perfect document. You are trying to capture the reality of how your business handles customer data. ## Step 3 - Complete your staff dossier Open **My Staff Dossier**. This works the same way as the customer dossier, but for the personal data of people working in or for your business: employees, freelancers, contractors, and company officers. Even if you have no employees on payroll, do not skip this step. The dossier suggests processes around independent contractors, accountants, board members, and other people whose data you handle. It is easy to forget that paying a freelancer also means processing their personal data. What you should cover here: - Payroll and HR systems - Recruitment and applications - Access control and IT usage (logins, monitoring, devices) - CCTV if you use it - Contractor and supplier contacts when they involve personal data The staff dossier produces a separate Staff Privacy Policy that you give to your team, alongside the customer privacy policy that you publish on your website. ## Step 4 - Document your third-party data sharing Open **My Third-Party Dossier**. Most SME owners share more personal data than they realise: with accountants, lawyers, suppliers, payment providers, hosting companies, email marketing platforms, booking tools, helpdesk software, and so on. Whenever those tools store data on their servers, you are sharing personal data with that third party. This is another area where the AI scan does work for you. Every cookie, tracker, third-party script, and embedded service the scan detected on your website points to a third party that already receives data from you: Google (Analytics, Maps, reCAPTCHA), Meta (Pixel), Stripe, Mailchimp, Hotjar, your chat widget, your CDN, and so on. GDPRWise pre-fills the third-party dossier with these findings so you do not have to remember every script your developer added to your site. GDPR requires that: - Each instance of sharing personal data is documented - Both parties agree to handle the data in a GDPR-compliant way (usually via a data processing agreement, also called a DPA) What to do here: - Review the third parties the scan added from your website (cookies, trackers, embeds, hosted scripts) and confirm they apply - Add the off-website third parties the scan cannot see: your accountant, your bank, payroll provider, suppliers, freelancers, and any offline data flows - Cross-check against your customer and staff dossiers to make sure every process that involves an external party has its third party listed - Where applicable, let GDPRWise send a request to the third party asking them to agree to a standard data sharing agreement; this satisfies the documentation requirement without you having to draft contracts manually We have a dedicated knowledge base article on managing the third-party dossier; see [Managing your Third-Party Dossier](/en/kennisbank/hoe-gdprwise-werkt/third-party-dossier/). ## Step 5 - Generate and publish your privacy policy Once your three dossiers reflect the reality of what your business actually does, go to the **GDPR Documents** section and generate your privacy policy. This is the moment the work pays off: a tailored, audit-ready document that mirrors your dossiers exactly. A few things to know: - When you change something in a dossier later, the **Generate Privacy Policy** button turns orange to remind you that a new version is due. Previous versions are kept for you, one click away. - If we update the underlying template because of a regulatory change, we tell you. You decide when to regenerate. - We also recommend generating your **processing register** and walking through it with a colleague to validate accuracy and completeness. If a supervisory authority ever contacts you, this is most likely the first document they will ask for. Then publish: - Place the privacy policy on your website at a stable URL - Link to it from your footer, your contact form, your checkout, and your account-creation flow - Reference it in your communications so prospective customers can read it before they decide to share data with you The preview of the document includes guidance on where and how to publish, and a separate article on [publishing your privacy policy](/en/kennisbank/hoe-gdprwise-werkt/publish-privacy-policy/) walks through the practical placement. A nice optional step: send a short note to your existing customers letting them know you have a new and improved privacy policy. They will appreciate the transparency, and you can always give GDPRWise a small mention. ## Step 6 (bonus) - Security and data subject rights We promised five steps, and steps 1 to 5 cover the documentation side of GDPR. But the regulation also requires two things that documents alone do not solve: - **Security** - your business must actually handle personal data securely. Encryption, access control, secure backups, password hygiene, vendor due diligence. Your generated privacy policy states that your business does these things; make sure that is true. - **Data subject rights** - GDPR gives individuals rights to access, correct, delete, and port their personal data, and to object to certain processing. You need a procedure for handling these requests within the legal time limits. The GDPRWise dossier and policy capture the commitments. Carrying them out in practice is your responsibility. Our knowledge base covers both areas in depth, and if you would like external help, we are happy to point you to qualified partners. ## A quick recap | Step | What you do | Where in GDPRWise | |---|---|---| | 1 | Run the AI website scan | Free Scan / discovery | | 2 | Refine customer processes | My Customer Dossier | | 3 | Add staff processes | My Staff Dossier | | 4 | Document third-party sharing | My Third-Party Dossier | | 5 | Generate and publish privacy policy | GDPR Documents | | 6 | Implement security and rights handling | Knowledge base, your operations | You do not have to be perfect on the first pass. Most SME owners come back to their dossiers two or three times in the first month, and that is exactly how the platform is designed to be used. The goal is a dossier that reflects the reality of your business; everything else flows from that. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Create Complete GDPR Documentation with GDPRWise URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/gdpr-documentation-tool/ Summary: All your GDPR documentation in one place: processing register, privacy policies, cookie report, action list, and breach procedures. Built from your actual data. Key takeaways: - Your complete GDPR dossier is generated from one scan and a set of targeted questions - The three-layer model ensures nothing is missed: sector data, scan results, and your answers combined - Export everything as PDF or Excel and share with your accountant, auditor, or legal adviser - Peace of Mind keeps all documentation current through continuous monitoring and automatic updates FAQ: Q: Can I use GDPRWise documentation during an audit by the supervisory authority? A: Yes. The dossier is structured to meet the documentation requirements under the GDPR. You can export the complete dossier or individual components and present them during an inspection. The professional formatting and clear structure make it easy for inspectors to review. Q: How long does it take to create a complete GDPR dossier? A: The scan takes about 2 minutes. Answering the guided refinement questions takes 15 to 30 minutes depending on your business. After that, your complete dossier is ready. Compare that to weeks of manual work or expensive consultancy projects. Q: What if my business changes after I create the dossier? A: With the Free Scan, you get your complete dossier and all documents at no cost. With Peace of Mind, GDPRWise monitors your website continuously and flags changes automatically. New tools, updated scripts, or changed forms are detected and your documentation is updated accordingly. ## The documentation challenge The GDPR is, at its core, a documentation obligation. You need to prove that you handle personal data correctly. Not just claim it - prove it. With documents, registers, policies, and procedures that a supervisory authority can review at any time. For large organisations with legal departments, this is manageable. For small and mid-sized businesses, it is the single biggest obstacle to compliance. You know you should have a processing register. You know your privacy policy needs updating. You know you should document your cookie situation. But putting all of that together, in the right format, covering all the right fields? That is where most SMEs get stuck. GDPRWise solves this by generating your complete GDPR documentation from a single starting point: your website scan. ## Everything in one place Your GDPRWise dossier is not a single document. It is a structured collection of everything you need to demonstrate compliance. Here is what it includes and why each component matters. ### Processing register (ROPA) The record of processing activities is the foundation of your GDPR documentation. It lists every activity involving personal data, from website analytics to payroll administration. GDPRWise generates your register automatically. The scan detects website-based processing. The sector foundation adds industry-standard activities. The guided refinement fills in internal and offline processing. Every entry includes purpose, legal basis, data categories, recipients, retention periods, and security measures. The result is a register that meets the requirements of Article 30 GDPR (also known as the AVG in Dutch legislation), ready for export and presentation. ### Customer privacy policy Your privacy policy tells visitors and customers what data you collect, why, and what their rights are. GDPRWise generates this based on your actual processing activities, not from a generic template. Because the policy is built from scan results and your answers, it accurately describes what happens on your website. When your site uses Google Analytics, the policy says so. When your contact form collects phone numbers, the policy mentions it. No gaps, no fiction. ### Staff privacy policy Most businesses overlook this one entirely. The GDPR requires you to inform your employees about how you process their personal data. Payroll, HR files, sick leave, CCTV, GPS tracking, IT monitoring - all of these require transparency. GDPRWise generates a dedicated staff privacy policy based on your answers about HR practices. This document is ready to include as an appendix to employment contracts. It is one of GDPRWise's unique features: very few tools on the market generate an employee-facing privacy policy. ### Cookie report The cookie report provides a detailed inventory of all cookies and trackers active on your website. For each cookie, you see the name, origin, category (functional, analytical, marketing), lifespan, and whether consent is required. This report is the basis for your cookie banner configuration and your cookie policy. You know exactly what to disclose and what to block until consent is given. ### Action list Not everything can be automated. Some items require you to take action: conclude a processing agreement with a supplier, set a retention period for a specific data category, adjust your cookie banner, or brief your staff on the data breach procedure. The action list captures these items, prioritised by impact. Each action includes a description, the priority level, and guidance on how to resolve it. You can assign actions to colleagues and track completion within the platform. ### Breach procedures Your dossier includes a data breach management section with a breach register, notification templates, and communication templates for affected individuals. These are tailored to your sector and your specific processing activities. When a breach occurs, you don't start from scratch. You open GDPRWise, log the incident, and follow the guided procedure. Everything is documented in the format the supervisory authority expects. ### Compliance score The compliance score is a percentage showing how far along you are. It is based on the completeness of your register, the status of your privacy policies, your cookie situation, and the number of resolved action items. The score is not a legal guarantee, but a practical indicator. It helps you prioritise and track progress over time. ## How the three-layer model ensures completeness The reason GDPRWise can generate all this documentation reliably is the three-layer model. **Sector foundation** provides the baseline. Every industry has standard processing activities, typical tools, and common data flows. GDPRWise maintains pre-built foundations for dozens of sectors, giving you a strong starting point regardless of your technical knowledge. **AI scan results** add the specifics. The scan detects exactly what is happening on your website: which scripts load, which cookies are placed, which forms collect data. These findings are translated into register entries, policy sections, and cookie report lines. Items confirmed by the scan are labelled "Detected" so you know they are verified. **Guided refinement** completes the picture. Targeted questions address processing that happens outside your website: employee data, client records, partner data sharing, physical security. Items based on your answers are labelled "Needs review" until you confirm them. Together, these three layers ensure completeness. Nothing is missed. ## Export, share, and present Every component of your dossier can be exported individually or as a complete package. **PDF export** produces professionally formatted documents with clean layout, clear headings, and structured tables. Ready to hand to a supervisory authority inspector, include in an audit package, or send to your legal adviser. **Excel export** gives you editable spreadsheets for internal use. Your accountant can review the processing register. Your IT team can check the cookie report. Your HR manager can verify the staff privacy policy. ## Keeping documentation current The biggest risk with GDPR documentation is not creating it - it is letting it become outdated. A processing register from 2023 that doesn't mention the tools you added in 2025 is worse than no register at all. It suggests you don't monitor your compliance. GDPRWise addresses this at two levels: **Free Scan.** Your initial scan and complete dossier are free, with no account or credit card required. You get a full AI scan, complete dossier, all documents, a compliance score, and a 2-week free trial to explore the platform. **Peace of Mind subscription (EUR 29/month, yearly billing).** GDPRWise monitors your website continuously. When a new script appears, a cookie changes, or a form is added, you receive a notification. The platform shows exactly what changed and what documentation needs updating. You review, approve, and your dossier is current again. Peace of Mind also tracks regulatory changes so your documentation reflects current expectations. ## From scattered files to a single source of truth Most SMEs have GDPR documentation scattered across different locations. A privacy policy drafted by a lawyer two years ago. A processing register started in Excel but never finished. A cookie banner installed without proper documentation. GDPRWise brings all of this into one structured, maintained, and exportable dossier. You know where everything is. You know it is current. And you can prove it to anyone who asks. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Data Breach Management with GDPRWise URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/data-breach-management/ Summary: How GDPRWise helps you manage data breaches: breach register, notification templates, 72-hour deadline tracking, and documentation for the supervisory authority. Key takeaways: - Your GDPRWise dossier includes a breach register and ready-to-use notification templates - Step-by-step guidance walks you through the 72-hour notification deadline - The breach register documents everything the supervisory authority may request - Peace of Mind keeps your breach procedures current as regulations and your business evolve FAQ: Q: Do I have to report every data breach to the supervisory authority? A: No. You must report a breach only if it poses a risk to the rights and freedoms of the affected individuals. However, you must document every breach in your breach register, regardless of whether you report it. GDPRWise helps you assess the risk and decide whether notification is required. Q: What happens if I miss the 72-hour notification deadline? A: Late notification can lead to fines and increased scrutiny from the supervisory authority. If you do miss the deadline, you must explain the reason for the delay. GDPRWise sends alerts and provides a step-by-step process so you can act within the required timeframe. Q: Does GDPRWise replace a Data Protection Officer for breach management? A: GDPRWise is a tool, not a DPO. It provides the templates, register, and guidance you need to handle breaches correctly. If your organisation is required to appoint a DPO, you still need one. But for most SMEs without a DPO, GDPRWise gives you the structure and documentation to manage breaches confidently. ## Why data breach management matters for every SME A data breach doesn't have to be a Hollywood-style hack. A lost laptop, an email sent to the wrong person, or an unprotected customer list shared via a public link - these are the incidents that happen to small and mid-sized businesses every day. Under the GDPR (also known as the AVG in Dutch legislation), you are required to handle these situations correctly and document them properly. The problem most SMEs face is not a lack of good intentions. It is a lack of preparation. When a breach occurs, you need to act fast. The GDPR gives you just 72 hours to notify the supervisory authority if the breach poses a risk. Without a procedure in place, those 72 hours disappear quickly. GDPRWise gives you the tools to be prepared before a breach happens, and to respond correctly when it does. ## What's in your breach management toolkit Your GDPRWise dossier includes a complete data breach management section. It is not a theoretical manual - it is a practical set of tools you can use the moment something goes wrong. ### Breach register Every data breach must be documented, even if you don't report it to the supervisory authority. The breach register in GDPRWise captures: - What happened (description of the incident) - When it was discovered and by whom - Which personal data was affected - How many individuals were impacted - What measures you took to contain the breach - Whether you reported it and why (or why not) This register is exactly what the supervisory authority will ask for during an inspection. Having it in order shows that you take your responsibilities seriously. ### Notification templates If a breach needs to be reported, you need to provide specific information to the supervisory authority. GDPRWise includes ready-to-use templates that guide you through what to include: - The nature of the breach - The categories and approximate number of affected individuals - The likely consequences - The measures taken or proposed to address the breach You fill in the specifics of your incident, and the template ensures you don't miss any mandatory fields. No need to figure out the legal requirements on the spot. ### Communication templates for affected individuals When a breach poses a high risk to the people whose data was compromised, you must inform them directly. This is often the part that causes the most stress. What do you say? How do you say it? GDPRWise provides clear, professional communication templates. They are written in plain language, not legal jargon, so the people you notify actually understand what happened and what they should do. ## The 72-hour deadline, step by step The 72-hour window for reporting a data breach to the supervisory authority is one of the most well-known GDPR requirements, and one of the most stressful. Here is how GDPRWise helps you meet it. **Step 1: Log the breach immediately.** As soon as you discover or suspect a breach, open GDPRWise and log it in the breach register. Record what you know so far, even if details are incomplete. **Step 2: Assess the risk.** GDPRWise asks targeted questions to help you determine whether the breach poses a risk. What type of data was involved? How many people? Was the data encrypted? Based on your answers, you get a clear recommendation: report or document only. **Step 3: Contain and mitigate.** Document the immediate steps you're taking - revoking access, changing passwords, informing your IT provider. This is part of your obligation and GDPRWise prompts you to record it. **Step 4: Notify if required.** If notification is needed, GDPRWise generates the notification using the template, pre-filled with the details you've already entered. You review, adjust if needed, and submit to the supervisory authority. **Step 5: Inform affected individuals.** If the risk is high, use the communication template to notify the people involved. GDPRWise helps you determine whether this step is necessary. **Step 6: Evaluate and improve.** After the incident, document what you learned and what you'll change to prevent recurrence. This evaluation is logged in your dossier. ## How the three-layer model helps you prepare GDPRWise uses a three-layer approach to build your dossier, and this applies to breach management too. **Sector foundation.** Your industry comes with pre-built breach scenarios. A dental practice faces different risks than an online shop. GDPRWise pre-fills common breach types and response steps relevant to your sector. **AI scan results.** The scan detects the tools and scripts running on your website. If you use a CRM that stores customer data, or a newsletter tool that holds email lists, those systems become part of your breach response plan. You know where to look when something goes wrong. **Guided refinement.** Through targeted questions, GDPRWise identifies additional systems and processes - employee records, paper files, partner integrations. Items marked "Detected" are confirmed by the scan. Items marked "Needs review" require your input to ensure completeness. The result: a breach management procedure that actually matches your business, not a generic checklist from the internet. ## Peace of Mind keeps your procedures current Businesses change. You adopt new tools, collect new types of data, or expand into new services. Your breach management procedures need to reflect those changes. With Peace of Mind, GDPRWise's continuous monitoring subscription, your dossier stays up to date. When a rescan detects changes, like a new third-party script or an additional form collecting data, your breach response documentation is flagged for review. You don't have to remember to update it manually. Peace of Mind also ensures your procedures align with the latest regulatory guidance. When the supervisory authority publishes updated breach reporting requirements, your templates reflect those changes. ## Documentation that holds up during an inspection The supervisory authority can inspect your breach management at any time, not just when a breach occurs. They want to see: - That you have a breach register (even if it's empty, which just means no breaches occurred) - That you have a procedure in place for detecting, reporting, and handling breaches - That your staff knows what to do GDPRWise provides all of this in a professional, structured format. You can export your breach register and procedures as PDF, ready to hand over to an inspector, your accountant, or a legal adviser. ## A breach doesn't have to be a crisis The difference between a breach that becomes a crisis and one that becomes a footnote in your register is preparation. When you know what to do, who to contact, and where to document it, you can respond calmly and correctly. GDPRWise won't prevent data breaches from happening. No tool can. But it gives you the structure, templates, and guidance to handle them professionally and meet your legal obligations without panic. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Employee Privacy Policy: What You Must Tell Your Staff URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/employee-privacy-policy/ Summary: As an employer, you process a lot of personal data about your staff. The GDPR requires you to inform employees about what you process and why. This article explains what an employee privacy policy must contain and when to hand it over. Key takeaways: - An employee privacy policy is mandatory and separate from your website privacy policy - Hand it over at the start of employment, ideally as an appendix to the employment contract - Cover all processing activities: payroll, HR files, CCTV, GPS tracking, sick leave, and access badges - GDPRWise generates an employee privacy policy automatically based on your employee dossier FAQ: Q: Is an employee privacy policy mandatory? A: Yes. The GDPR requires you to inform every data subject about how you process their personal data. Employees are data subjects, so you must inform them just as you do customers. A dedicated employee privacy policy is the standard way to do this. Q: When should I hand over the employee privacy policy? A: At the start of employment, as an appendix to the employment contract. This way the employee knows from day one which data you process. If the policy changes later, you must inform employees again. Q: Can I use consent as a legal basis for processing employee data? A: In most cases, no. Consent in an employment relationship is rarely considered 'freely given' due to the power imbalance. Preferably use performance of the employment contract, legal obligation, or legitimate interest as your legal basis. Q: Do I need a separate policy for temporary workers and freelancers? A: Temporary workers fall under the policy of the staffing agency. For freelancers who process personal data on your behalf, you need a processing agreement. If you process freelancers' data yourself (e.g., invoicing details), you must inform them. ## Why a separate employee privacy policy? Most businesses have a privacy policy on their website, aimed at customers and visitors. But as an employer you also process a large amount of personal data about your own staff, and the GDPR requires you to inform them just as thoroughly. It is worth recognising that the personal data you gather on staff is often far more detailed and sensitive than what you collect on customers. Think of salary information, family composition, pension details, performance reviews, medical absences, disciplinary records, and biometric data like fingerprints for access control. This makes the employee privacy policy not just a compliance formality, but a genuinely important document for your team. An employee privacy policy (also called an employee privacy notice or internal privacy policy) is the document that does this. It is entirely separate from your website privacy policy and focuses specifically on processing related to the employment relationship. ## When to hand it over The right moment is **at the start of employment**. Include the employee privacy policy as an appendix to the employment contract. This way the employee knows from day one which data you process, why, and what rights they have. If you update the policy later, for example because you introduce CCTV or start using a new HR system, you must inform all employees of the change. ## What must it include? An employee privacy policy contains broadly the same sections as a website privacy policy, but tailored to the employment relationship. ### 1. Who is the data controller? Your company name, address, and contact details. If you have a Data Protection Officer (DPO), include their contact information as well. ### 2. What data do you process? Be specific. As an employer you typically process: - **Identification data**: name, address, date of birth, national ID number - **Payroll**: bank details, pay slips, tax information - **HR files**: employment contract, evaluations, training records, warnings - **Sick leave**: absence reports, duration of absence (note: you may not record medical details) - **Access control and badges**: who enters or leaves the building and when - **CCTV**: if you have cameras in the workplace - **GPS tracking**: if you track the location of company vehicles - **IT usage**: log data, email usage, internet usage (if you monitor this) ### 3. Why do you process the data? State the purpose per data category. Examples: - Payroll: performance of the employment contract and legal obligations - CCTV: security of property and employee safety - GPS tracking: route planning and efficiency management - Badges: access control and compliance with working time regulations ### 4. What is the legal basis? The most common legal bases for employee data: - **Performance of the employment contract** (payroll, contract management) - **Legal obligation** (tax filings, social security) - **Legitimate interest** (CCTV, IT security) Consent is almost never suitable in an employment context, because an employee cannot truly refuse "freely." ### 5. With whom do you share the data? List all parties with access: - Payroll provider or social secretariat - Occupational health service - Insurer - IT vendors with access to HR systems - Government authorities (tax authority, social security) ### 6. Retention periods Describe per data type how long you keep it: - Payroll data: legal retention obligation of 7 years - Employee file: up to 5 years after end of employment - CCTV footage: maximum 1 month (unless an incident occurred) - GPS data: a few weeks, depending on the purpose ### 7. Employee rights Employees have the same rights as other data subjects: access, rectification, erasure, restriction, portability, and objection. State how they can exercise these rights and who to contact. ## Already have a policy? Check it in two minutes If you already have an employee privacy policy, for example from an HR provider, you can test how well it covers these points. Our free [Staff Policy Checker](/en/staff-privacy-policy-checker/) grades your PDF or Word file against 12 GDPR checks, from controller scope and legal bases to retention periods and employee rights, and shows exactly what is missing. No account needed. ## How GDPRWise handles this for you When you work through the employee dossier in GDPRWise, you're asked about your HR processes, CCTV, GPS tracking, and IT policies. Based on your answers, GDPRWise automatically generates an employee privacy policy that you can include as an appendix to the employment contract. Does your situation change? Update your answers and the document is automatically refreshed. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Free Staff Policy Checker: 12 GDPR Checks on Your Employee Privacy Policy URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/free-staff-policy-checker/ Summary: Upload your staff privacy policy as a PDF or Word file and get a graded report against 12 GDPR checks, with verbatim quotes from your own document as evidence. Free, no account needed. Key takeaways: - The free Staff Policy Checker grades your employee privacy policy against 12 GDPR checks in about two minutes - Every verdict is backed by verbatim quotes from your own document, so you see exactly what the assessment is based on - Your document is not stored; email addresses and phone numbers are replaced with pseudonyms before the analysis starts - You can download the full graded report as a PDF to share internally - It is an automated AI review, not legal advice; for a guaranteed-complete policy, GDPRWise generates one from your actual situation FAQ: Q: Is the Staff Policy Checker really free? A: Yes. Upload your document and you get the full report with all 12 checks, without an account or credit card. There is a daily limit on free checks per visitor to keep the tool available for everyone. Q: What happens to my document? A: The file itself is not stored. The checker extracts the text, replaces email addresses and phone numbers with pseudonyms before the analysis starts, and keeps only the graded report. Q: Is the verdict legal advice? A: No. It is an automated review by AI against 12 GDPR checks. It shows where your policy stands strong and where the gaps are, but it does not replace advice from a lawyer or DPO for complex situations. Q: My policy failed. Now what? A: The report shows per check what is missing. You can fix your document yourself, or let GDPRWise generate a complete staff privacy policy based on your actual HR situation, together with your privacy policy, processing register and the rest of your GDPR file. Every employer must inform staff about how their personal data is processed. Most businesses have a decent privacy policy on their website, but the staff version is often forgotten, outdated, or an unfilled template from an HR provider. The free [Staff Policy Checker](/en/staff-privacy-policy-checker/) tells you in two minutes where your document actually stands. ## How it works Upload your staff privacy policy as a PDF or Word file (.docx, 5 MB max), that is all. The checker extracts the text, replaces email addresses and phone numbers with pseudonyms, and grades the document against 12 GDPR checks. For each check you get a verdict (pass, warning or fail), a short explanation, and verbatim quotes from your own text as evidence. No generic checklist advice: you see exactly which sentence in your document does or does not cover a requirement. The full report is usually on screen within two minutes, and you can download it as a PDF to share internally. ## The 12 checks The checks cover what a staff privacy policy must contain under the GDPR: 1. **Controller and scope**: who is responsible, and who the policy applies to 2. **Categories of personal data**: which employee data you process 3. **Processing purposes**: why you process each category 4. **Legal bases**: the correct basis per purpose (consent rarely works in employment) 5. **Special categories of data**: health data, and the stricter rules around them 6. **Recipients and processors**: payroll provider, insurers, IT vendors 7. **Transfers outside the EEA**: where data goes and under which safeguards 8. **Retention periods**: how long each category is kept 9. **Employee rights**: access, rectification, erasure, objection, and how to exercise them 10. **Security and contact point**: measures taken and who to contact 11. **Clarity and readability**: can a non-lawyer understand it 12. **Finished and consistent document**: a real policy, not a template with blanks For the background on each of these requirements, read our guide on [what an employee privacy policy must contain](/en/kennisbank/hoe-gdprwise-werkt/employee-privacy-policy/). ## What the verdict means No issues at all: **pass**. Warnings but no fundamental gaps: **pass with warnings**. If a core check fails, such as legal bases or employee rights, the overall verdict is **fail**. It remains an automated assessment by AI, not legal advice; treat it as a structured second pair of eyes, not a court-proof certificate. ## What happens to your document The document is not stored. Before the analysis starts, email addresses and phone numbers are replaced with pseudonyms, so they never reach the AI model in readable form. Only the graded report is kept, which is why quotes in your report may show pseudonyms instead of the original contact details. ## When a checker is not enough A checker tells you what is wrong with the document you have. It cannot write the document you need. If your policy fails, or you do not have one yet, GDPRWise generates a complete staff privacy policy from your actual HR situation: your systems, your CCTV and tracking choices, your retention periods. It is generated together with your privacy policy, processing register and the rest of your GDPR file, so the documents never contradict each other. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### GDPR Awareness for Small Teams - How GDPRWise Helps URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/gdpr-training-small-teams/ Summary: Small teams need practical GDPR awareness, not corporate training programmes. GDPRWise provides free courses with certificates, staff privacy policies, role-based access, and sector-specific context. Key takeaways: - The staff privacy policy from GDPRWise is a practical awareness tool, not just a legal document - Team roles let you assign compliance actions to the right people without overwhelming everyone - Sector-specific dossier content helps staff understand why GDPR matters to their specific work - The knowledge base provides plain-language guidance your team can reference anytime - Three free short courses with certificates (GDPR essentials, security awareness, phishing) - privacy and security go hand in hand FAQ: Q: Does GDPRWise replace formal GDPR training? A: For many small teams, yes. GDPRWise includes free short courses with certificates: GDPR essentials for SMEs, security awareness, and recognising phishing. In heavily regulated sectors you may still need dedicated programmes, but the courses, the staff privacy policy, sector-specific context, assigned actions, and knowledge base together give your team documented training and a practical understanding of what the GDPR means for their daily work. Q: Can I assign different responsibilities to different team members? A: Yes. GDPRWise supports team roles so you can invite colleagues and assign specific actions to the right people. Your office manager might handle the employee privacy policy, while your marketing lead handles the cookie report. Each person sees only their relevant tasks. Q: What if my team has no privacy knowledge at all? A: That is exactly who GDPRWise is designed for. The platform guides your team step by step, with plain-language explanations for every question and action. No legal background needed. ## Small teams don't need corporate training programmes When large companies talk about GDPR training, they mean annual e-learning modules, classroom sessions, quizzes, and certificates. That works when you have a dedicated compliance department and hundreds of employees. For a team of 3, 10, or 25 people, it is overkill. What small teams actually need is practical awareness: understanding what personal data they handle in their daily work, what the basic rules are, and who to ask when something comes up. They do not need to memorise the difference between Article 6(1)(a) and 6(1)(f). They need to know that customer email addresses cannot be shared freely, that a data breach must be reported, and that old files should not be kept forever. GDPRWise is a compliance tool first, but it also includes free short courses your team can take in the browser, with a certificate at the end. And the way the platform itself works naturally builds the kind of awareness that matters for small teams. ## The staff privacy policy as an awareness tool The [employee privacy policy](/en/kennisbank/hoe-gdprwise-werkt/employee-privacy-policy) is one of the most underrated GDPR documents. Most businesses think of it as a legal requirement, something to file away and forget. For small teams, it can be much more useful than that. When you hand a new employee their staff privacy policy, you are telling them: - What personal data the company collects about them (payroll, HR files, badges, CCTV, IT usage) - Why the company collects it - Who has access - How long it is kept - What rights they have This is awareness in its most practical form. The employee understands immediately that the company takes privacy seriously, that there are rules about handling personal data, and that those rules apply internally as well as externally. GDPRWise generates the employee privacy policy automatically based on your answers about HR processes. You do not have to draft it from scratch. And because it is specific to your business, not a generic template, it actually reflects how your team operates. ## Team roles keep compliance manageable In a small business, GDPR compliance should not fall on one person's shoulders entirely. But it also should not be everyone's responsibility in equal measure. That is a recipe for nothing getting done. GDPRWise supports [team roles](/en/kennisbank/hoe-gdprwise-werkt/team-roles-management) that let you distribute compliance actions across your team. You invite colleagues to the platform and assign them the tasks that match their role. Some practical examples: - **The business owner** oversees the dossier, reviews the compliance score, and makes decisions on processing activities - **The office manager** handles the employee privacy policy, manages access permissions, and tracks action items - **The marketing lead** reviews the cookie report, checks which trackers are active, and ensures the privacy statement on the website is current - **The IT contact** reviews third-party scripts, verifies security measures, and handles data processor agreements Each person sees their assigned actions and the relevant context. They do not need to navigate the entire dossier or understand every compliance requirement. They just need to handle their part. ## Sector-specific context makes it relevant Generic GDPR training fails small teams because it feels abstract. "Personal data includes any information relating to an identified or identifiable natural person" means nothing to a receptionist at a dental practice. GDPRWise takes a different approach. The three-layer dossier model starts with a sector-specific foundation. When your team works through the platform, everything is framed in the context of your industry. A dental practice sees questions about patient records, appointment data, and insurance processing. An accounting firm sees questions about client financial data, tax filings, and bookkeeping records. A retail shop sees questions about customer loyalty programmes, online orders, and delivery tracking. This sector framing helps team members understand why GDPR matters to their specific work. It is not an abstract regulation. It is about the patient files they open every day, the client data they handle every week, or the customer orders they process every shift. ## The knowledge base as a reference library Not everything can be covered in the dossier workflow itself. Sometimes a team member needs to look something up: what to do when a customer asks for their data, how long invoices should be kept, or whether that new marketing tool needs a processing agreement. The GDPRWise [knowledge base](/en/kennisbank) is written specifically for this purpose. Every article: - Uses plain language, not legal jargon - Explains why the rule exists, not just what it says - Provides practical examples relevant to small businesses - Includes templates and checklists where useful Your team can search the knowledge base whenever a question arises. Over time, this builds a level of awareness that no annual training session can match, because it is tied to real situations as they happen. ## Free courses: privacy and security go hand in hand There is no privacy without security. The GDPR says so itself: integrity and confidentiality is one of its core principles (Article 5(1)(f)). A team that spots a phishing mail and locks down its accounts protects personal data more effectively than any policy document on its own. That is why GDPRWise offers free short courses, built for exactly the small teams this article is about. No account needed, plain language, and a certificate at the end of each course: - **[GDPR essentials for SMEs](/en/course/gdpr-essentials-for-smes)** - the privacy side: personal data, data minimisation, transparency and data subject rights, in seven short modules plus a final exam. - **[Security awareness](/en/course/security-awareness)** - the security side: passwords, 2FA and passkeys, access to systems, handling data safely, and spotting and reporting a breach. - **[Recognising phishing](/en/course/recognising-phishing)** - the most common way things go wrong in practice: inspecting emails, smishing, and what to do at work when a message smells wrong. The certificates give you something formal training often promises but rarely delivers for small teams: simple, documented evidence that your people have actually been trained. ## Building a privacy-aware culture without bureaucracy The GDPR (also referred to as AVG in Dutch) requires organisations to implement "appropriate technical and organisational measures." For small teams, the organisational part often boils down to culture: does your team know the basics, and do they act on them? GDPRWise helps build that culture through five mechanisms: 1. **The staff privacy policy** sets the tone from day one. Every employee knows the company takes privacy seriously. 2. **Team roles and assigned actions** make compliance a shared responsibility, not a burden for one person. 3. **Sector-specific context** connects the abstract regulation to daily work, making it tangible. 4. **The knowledge base** provides answers to questions as they come up in practice. 5. **The free courses** turn awareness into documented training, certificate included. None of this requires booking a training room, creating PowerPoint slides, or scheduling time away from productive work. It integrates into how your team already operates. ## When you do need formal training There are situations where structured training makes sense, even for small teams. If your business processes sensitive data (health records, financial data, children's data), if you have a Data Protection Officer, or if you operate in a highly regulated sector, some form of documented training may be expected. For heavyweight, sector-specific programmes, GDPRWise is the foundation rather than the replacement. But the free courses already give you documented training with certificates, and a team that uses the platform, has reviewed its sector-specific dossier, and has taken the courses will get far more out of any formal programme than a team starting from zero. The combination of practical tools and targeted knowledge is what turns GDPR from a compliance checkbox into something your team actually understands and applies. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### GDPR Compliance for SMEs - Why GDPRWise Is the Smart Choice URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/sme-gdpr-compliance/ Summary: SMEs face the same GDPR rules as large corporations but with fewer resources. GDPRWise bridges that gap with AI-powered scanning and a three-layer dossier model. Key takeaways: - SMEs must meet the same GDPR requirements as large corporations, with no exceptions for size - GDPRWise uses AI scanning and a three-layer dossier model to deliver complete compliance in hours - The platform includes a staff privacy policy, a requirement most SME tools overlook entirely - Start free with the Free Scan, then upgrade to Peace of Mind (EUR 29/month) for continuous monitoring FAQ: Q: Do SMEs really need to comply with the GDPR? A: Yes. The GDPR applies to any organisation that processes personal data, regardless of size. There is no exemption for small businesses. Supervisory authorities actively enforce against SMEs, and fines can reach up to 4% of annual turnover. Q: How long does it take to get GDPR compliant with GDPRWise? A: The AI scan takes about 2 minutes. Building your complete dossier, including answering targeted questions and reviewing flagged items, typically takes a few hours spread over one or two sessions. Q: Do I need legal or technical knowledge to use GDPRWise? A: No. The platform is designed for business owners without legal or IT expertise. The AI scan handles the technical detection, sector dossiers provide the legal framework, and the guided refinement asks plain-language questions. ## Same rules, fewer resources The GDPR (also known as the AVG in Dutch) does not distinguish between a 5-person accounting firm and a multinational bank. Both must document their data processing activities, publish a privacy policy, manage cookies and trackers correctly, and respond to data subject requests within 30 days. The rules are identical. The difference is resources. Large companies have legal teams, compliance officers, and dedicated budgets. Most SMEs have none of that. The business owner handles compliance alongside sales, operations, and everything else. Hiring a privacy consultant typically costs between 2,000 and 5,000 EUR, with no guarantee that the documents stay current once the engagement ends. That is the gap GDPRWise was built to close. Not by simplifying the rules, but by making the process of meeting them dramatically faster, more affordable, and easier to maintain. ## How GDPRWise works for SMEs The platform follows a three-layer approach designed specifically for businesses that need solid compliance without a legal department. ### Layer 1: AI-powered website scan You enter your website URL and GDPRWise scans it automatically. Within 2 minutes, the scanner detects your cookies, trackers, third-party scripts, forms, and data collection points. It also identifies your sector, which determines the foundation for your dossier. Every finding is labelled with a confidence level. "Detected" means the system is highly certain about the finding. "Needs review" means the item requires your input to confirm or adjust. This transparency means you always know what has been verified automatically and what still needs your attention. ### Layer 2: Sector-specific foundation Based on your detected sector, GDPRWise loads a pre-built sector dossier. This dossier already contains the processing activities, legal bases, and retention periods that are standard for your industry. A physiotherapy practice gets different defaults than an e-commerce shop or a recruitment agency. This is where GDPRWise saves you the most time. Instead of starting from a blank page, you start with a dossier that already covers 60-80% of your situation. You refine from there, rather than building from scratch. ### Layer 3: Guided refinement The platform asks you targeted questions about your specific situation. Do you use CCTV? Do you process health data? Do you share customer data with partners? Based on your answers, the dossier is refined and completed. The questions are in plain language, not legal jargon. You do not need a law degree to answer them. And you can complete them at your own pace - save your progress and return whenever you have time. ## What makes GDPRWise different from other tools Several features set GDPRWise apart from generic compliance templates and competing platforms. ### Staff privacy policy included Most GDPR tools focus exclusively on your website and customer-facing privacy. But as an employer, you also process personal data about your own staff: payroll, contracts, sick leave, access badges, and potentially CCTV or GPS data. The GDPR requires you to inform employees about this processing, typically through a separate [employee privacy policy](/en/kennisbank/hoe-gdprwise-werkt/employee-privacy-policy). GDPRWise generates this employee privacy policy automatically as part of your dossier. This is a requirement that many SMEs overlook entirely, and that most competing tools simply do not cover. ### Complete dossier, not just a checklist Your GDPRWise dossier includes a [processing register, privacy statement, cookie report, action list, and compliance score](/en/kennisbank/hoe-gdprwise-werkt/what-is-in-dossier). These are the actual documents you need if a supervisory authority asks for evidence of compliance. Not a checklist of tips, but ready-to-use documentation. ### Multilingual support GDPRWise supports Dutch, French, English, and German. For Belgian businesses operating across language regions, or for companies with international customers, this means your privacy documentation can match the language of your audience without manual translation. ### Continuous monitoring Privacy compliance is not a one-time project. Your website changes, new tools are added, employees join and leave. With the Peace of Mind subscription, GDPRWise periodically rescans your website, compares the results to your previous scan, and flags any changes. A new tracker appeared after a website update? You will know about it before a regulator does. ## Pricing that fits SME budgets GDPRWise offers two options: **Free Scan** gives you the full AI scan, the complete three-layer dossier, all documents, and the compliance score - at no cost. No account or credit card needed. You keep the result. This works well for businesses with stable websites that do not change frequently. **Peace of Mind** (EUR 29/month, yearly billing) adds continuous monitoring, automatic rescans, update notifications, and ongoing access to the latest sector dossier updates. For businesses that want to stay compliant without having to remember to check manually, this is the practical choice. Both options cost a fraction of what a consultant charges, and you get a working dossier the same day, not after weeks of back-and-forth. ## The bottom line for SMEs You do not get a discount on GDPR obligations because your business is small. But you also do not need to spend thousands of euros or weeks of your time to meet those obligations. GDPRWise gives you the same quality of compliance documentation that larger companies produce, at a price and speed that makes sense for an SME. The AI scan tells you exactly where you stand. The three-layer dossier gets you to compliance in hours. And the continuous monitoring option makes sure you stay there. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### GDPR for Sole Traders and Freelancers in Belgium: the Free Route URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/affordable-gdpr-solution-belgium/ Summary: Sole traders, freelancers and micro-businesses in Belgium do not need a consultant budget. Here is how you become GDPR compliant the free way, step by step, and the minimum you actually need. Key takeaways: - Even a sole trader or freelancer who processes personal data falls under the GDPR - the size of your business does not release you from the obligation - For most solo entrepreneurs and micro-SMEs a paid subscription or consultant is simply not needed - The Free Scan from GDPRWise delivers a complete dossier at no cost and without a credit card - Paying only becomes worthwhile once your website changes regularly or you work with many third-party tools FAQ: Q: Do I have to comply with the GDPR as a sole trader or freelancer? A: Yes. The GDPR applies to every business that processes personal data, regardless of size. If you keep a customer list, send invoices, run a newsletter or have a website with a contact form, you process personal data. A sole trader with no staff falls under it just as much as a company with fifty employees. Q: Can I really become GDPR compliant for free in Belgium? A: Yes. The Free Scan from GDPRWise gives you a complete dossier - processing register, privacy policy, cookie report and action list - at no cost and without a credit card. For a solo entrepreneur or micro-SME with straightforward processing activities, that is often all you need. Q: When do I need more than the free solution? A: Paying becomes worthwhile once your situation gets busy: a website that changes regularly, many third-party tools, or the wish to never think about compliance again. Then Peace of Mind (EUR 29 per month) adds continuous monitoring. As long as your situation is stable, the free route is enough. ## For the smallest businesses with the smallest budget If you run a sole trader business, freelance, or have a micro-company with a handful of people, GDPR compliance quickly sounds like a problem for bigger companies. It is not. The regulation makes no exception for size, and most solo entrepreneurs process more personal data than they realise: a customer list, invoices, a newsletter, a website with a contact form. The good news is that you do not need a 2,000 EUR consultant for this, and not even a paid subscription. For the smallest businesses there is a free route. This article shows what it looks like, step by step, and what the minimum is that you actually need. ## Why small does not mean exempt A stubborn misconception: "I am too small, the GBA really is not looking at me." The Belgian Data Protection Authority (GBA, in French APD) has in recent years issued fines to sole traders, local shops and small service providers. Enforcement also often starts not with an inspection, but with a complaint: a customer asking what data you hold on them, or a former employee wanting to make a point. The minimum that every Belgian micro-business processing personal data needs to have in order: - A **processing register** that describes which data you process, why, and how long you keep it - A **privacy policy** on your website that informs customers about their rights - A **cookie overview** if your website uses cookies or trackers That looks manageable, and for a small business it is, provided you do not have to start from a blank page. ## The free route, step by step Here is how you become compliant as a solo entrepreneur or micro-SME without spending a euro: ### Step 1: scan your website (2 minutes) Enter your website URL in the [Free Scan](/en/kennisbank/hoe-gdprwise-werkt/how-scan-works). The scanner automatically detects your cookies, tracking scripts, forms and third-party services, and recognises your sector. You do not have to look anything up by hand. ### Step 2: let the sector foundation do the heavy lifting Based on your detected sector, GDPRWise loads a pre-built dossier with the processing activities that are typical for your type of business. A freelance graphic designer, a self-employed bookkeeper and a web shop sole trader each start from a different, fitting foundation instead of an empty document. ### Step 3: answer a few targeted questions The platform asks you a short series of questions in plain language. Do you work alone or do you have a single employee? Do you use a newsletter tool? Do you process payments through an external provider? For a small business this is done in half an hour to an hour. ### Step 4: download your dossier You receive a complete dossier: processing register, privacy policy, cookie report, an [employee privacy policy](/en/kennisbank/hoe-gdprwise-werkt/employee-privacy-policy) if you have someone on your payroll, and an action list. No account or credit card needed, including a 2-week free trial. ### Step 5: publish and done Place your privacy policy on your website, set up your cookie banner based on the cookie report, and work through the action list. For a stable micro-business, that puts you in order. ## When free is enough - and when it is not The free route is sufficient for most solo entrepreneurs and micro-SMEs, because their processing activities are straightforward and stable. You own your dossier and can update it manually whenever something changes. Paying only becomes worthwhile in specific cases: - **Your website changes regularly.** New pages, new plugins or a new marketing script can introduce new cookies. Peace of Mind (EUR 29 per month) rescans automatically and warns you. - **You work with many third-party tools.** The more external services you use, the greater the chance that something changes without you noticing. - **You simply do not want to think about it anymore.** Some entrepreneurs are happy to pay a small amount for the certainty that their documentation stays current without manual work. As long as your situation is stable, there is no reason to pay. If your business grows or becomes more dynamic, the step to a subscription is small and the cost is low. For a full cost comparison of all routes, see [what GDPR compliance costs for a Belgian SME](/en/kennisbank/hoe-gdprwise-werkt/affordable-gdpr-belgium). ## Multilingual, also for the solo entrepreneur Even as a sole trader you may serve customers in several languages in Belgium. GDPRWise supports Dutch, French, German and English, so you can generate your privacy policy in the language your customers expect, all from the same free dossier. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### GDPR With No In-House Expertise: How Small Firms Cope URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/gdprwise-best-for-small-firms/ Summary: Small firms carry the same GDPR obligations as a corporation, but without a DPO, an IT team, or a lawyer. Here is how GDPRWise stands in for the four roles a small firm is missing. Key takeaways: - A small firm has the same GDPR obligations as a corporation, but none of the specialist roles that make compliance manageable - Compliance quietly depends on four roles a small firm rarely has: a data mapper, a privacy lawyer, a DPO, and a technical auditor - GDPRWise substitutes for each of those four roles, so an owner-operator can become compliant without hiring anyone - The Free Scan delivers a complete dossier at no cost, built from your answers about how your business actually works FAQ: Q: Do I need any GDPR knowledge to use GDPRWise? A: No. GDPRWise is designed for business owners without a legal or privacy background. The AI scan detects what matters on your website, sector templates provide the foundation, and targeted questions guide you through the rest. You never have to figure out what applies to you on your own. Q: I have no IT person and no lawyer. Can I still get compliant? A: Yes, that is exactly who the tool is built for. GDPRWise substitutes for the four roles a small firm usually lacks: it maps your data with an AI scan, supplies the legal reasoning through sector dossiers, plays the DPO role with a guided action list and monitoring, and audits your website technically for cookies and trackers. You provide knowledge of your own business; the platform provides the expertise. Q: What is the difference between the Free Scan and Peace of Mind? A: The Free Scan gives you a complete GDPR dossier at no cost. No account or credit card needed. The Peace of Mind plan (EUR 29/month, yearly billing) adds continuous monitoring: automatic rescans, change detection, and regulatory updates so your dossier stays current. ## The same obligations, none of the staff The GDPR (also known as AVG in Dutch) does not scale its requirements to the size of your business. A small firm with six people faces the same core obligations as a corporation with six thousand: a processing register, a lawful basis for every activity, a privacy statement, a staff privacy policy, and the ability to respond when someone asks what data you hold. The difference is not the obligations. It is who handles them. A large company has a data protection officer, an IT department, and access to legal counsel. A small firm has an owner who already does sales, operations, and payroll, and now compliance too. That is the real small-firm problem: not the rules themselves, but having nobody to delegate them to. ## The four roles compliance quietly assumes If you look at what actually gets a company compliant, it depends on four specialist roles working together. A small firm rarely has any of them. Here is what each role does, and where the gap opens up. **The data mapper** works out every activity where the business touches personal data, from the CRM to payroll to the CCTV over the till. In a corporation this is weeks of interviews. In a small firm, nobody has the time or the overview to do it properly. **The privacy lawyer** assigns a lawful basis and a retention period to each of those activities, and knows which special categories, like health data, need extra safeguards. Small firms almost never have this knowledge in the building. **The data protection officer** turns all of that into an ongoing routine: what to fix first, what to document, what to watch when something changes. Without this role, compliance becomes a one-off panic instead of a steady state. **The technical auditor** inspects what the website actually does: which cookies it drops, which trackers load, which third-party scripts a plugin quietly added. Most owners have no way to see this. Miss these roles and the typical result is a privacy statement copied off another site and nothing behind it, which is exactly the gap an inspector or a complaint exposes. ## How GDPRWise stands in for each role GDPRWise is built to fill those four gaps, so an owner-operator can reach the same result without hiring anyone. - **In place of the data mapper**: the [AI scan](/en/kennisbank/hoe-gdprwise-werkt/how-scan-works) reads your website in two minutes and, combined with a pre-built sector foundation, lays out your likely processing activities before you answer a single question. - **In place of the privacy lawyer**: the sector dossiers carry the lawful bases, retention periods, and safeguards that are standard for your industry, so the legal reasoning is already done and you confirm rather than research it. - **In place of the DPO**: a prioritised action list and a compliance score tell you what to do next, and Peace of Mind monitoring watches for changes so compliance stays a routine, not a project. - **In place of the technical auditor**: the scan detects every cookie, tracker, and third-party script, each labelled "Detected" or "Needs review", so you see exactly what your site is doing. The one thing the platform cannot supply is knowledge of your own business, which is why the [guided refinement](/en/kennisbank/hoe-gdprwise-werkt/what-is-in-dossier) asks you plain questions: do you have employees, do you use CCTV, do you transfer data abroad. You bring the facts; GDPRWise brings the expertise. ## The role most small firms forget entirely There is a fifth gap worth naming on its own: your obligations as an employer. The GDPR does not only cover customer data. If you have staff, you process their data too, from payroll and contracts to sick leave and badge logs, and you must inform them how. That means a separate [staff privacy policy](/en/kennisbank/hoe-gdprwise-werkt/employee-privacy-policy), distinct from the one on your website. This is not optional, yet most small firms do not have one, precisely because no role in the business was ever responsible for it. GDPRWise generates it automatically from your answers about HR processes, so the gap closes without you needing to know it existed. ## What "done" looks like without hiring anyone Work through GDPRWise and you end up with what a four-person compliance team would have produced: a complete processing register covering customers, employees, and third parties, a tailored privacy statement, a cookie report, a staff privacy policy, an action list, and a compliance score. You can export it all, share it with your accountant, or present it in an audit. The **Free Scan** delivers this at no cost, no account or credit card required, and the dossier is yours to keep. **Peace of Mind** (EUR 29/month, yearly billing) adds the ongoing DPO-style monitoring for firms that would rather not think about it again. Not sure which tool fits your situation first? Start with our [selection framework for the best small-business GDPR tool](/en/kennisbank/hoe-gdprwise-werkt/best-gdpr-tool-small-business). import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### GDPRWise vs Cookiebot: Cookie Consent Alone Is Not GDPR Compliance URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/gdprwise-vs-cookiebot/ Summary: Cookiebot excels at cookie scanning and consent management, but GDPR compliance requires much more. See how GDPRWise covers the full scope - from processing register to staff privacy policy. Key takeaways: - Cookiebot handles cookie consent well but does not cover the full scope of GDPR requirements - GDPRWise delivers a complete GDPR dossier including processing register, privacy policies, and breach procedures - A staff privacy policy is included as standard in GDPRWise - something Cookiebot does not offer - The three-layer dossier model means you start with a sector foundation, not a blank template FAQ: Q: Can I use Cookiebot and GDPRWise together? A: Yes. Some businesses use Cookiebot for consent banner management and GDPRWise for the rest of their GDPR dossier. However, GDPRWise includes a cookie report as part of the dossier, so most small businesses find they do not need a separate consent tool. Q: Does GDPRWise replace Cookiebot? A: GDPRWise covers a much broader scope than Cookiebot. It includes cookie scanning as part of its AI-powered website scan, plus processing registers, privacy policies, staff privacy policy, breach procedures, and compliance scoring. Whether you still need Cookiebot depends on how advanced your consent banner requirements are. Q: Is Cookiebot enough for GDPR compliance? A: No. Cookie consent is one requirement under GDPR, but the regulation covers much more: a processing register, privacy policies, data breach procedures, data processing agreements, and staff data handling. Cookiebot addresses the cookie part but not these other obligations. ## Quick summary Cookiebot (now part of Usercentrics) is a well-known cookie scanning and consent management platform. It handles consent banners, cookie categorisation, and consent logging across 47+ languages. GDPRWise takes a different approach: it scans your entire website with AI and builds a complete GDPR dossier covering processing registers, privacy policies, staff privacy policy, breach procedures, and ongoing monitoring. If your only need is a cookie banner, Cookiebot does that well. If you need actual GDPR compliance, the two tools serve very different purposes. ## What Cookiebot does Cookiebot has built a strong reputation in the consent management space. Its core function is straightforward: it scans your website for cookies, categorises them, and provides a consent banner that lets visitors accept or reject cookie categories. The platform logs every consent decision, which is useful for demonstrating that you obtained valid consent. The cookie scanning technology is solid. Cookiebot crawls your pages, identifies first-party and third-party cookies, and maps them to known services. The resulting cookie declaration can be embedded on your website, giving visitors a transparent overview of what data is being collected through cookies. International coverage is another strength. Cookiebot supports over 47 languages and is used across many countries. If you operate websites in multiple regions, the multi-language consent banner is a genuine advantage. Pricing sits at approximately 30 to 90 euros per month depending on the number of pages on your website. For a tool that focuses specifically on cookie consent, this is a recurring cost that adds up over time. Cookiebot targets businesses of all sizes, from small websites to enterprise operations with thousands of pages. ## What Cookiebot does not cover Cookie consent is one piece of the GDPR puzzle. The regulation requires significantly more. Here is what Cookiebot does not provide: - **Processing register (ROPA)** - the core document listing all your data processing activities, legal bases, retention periods, and security measures. This is what a supervisory authority asks for during an audit. - **Customer privacy policy generation** - a tailored privacy policy reflecting your specific processing activities, not a generic template. - **Staff privacy policy** - a separate document informing employees how their personal data is processed. This is a legal requirement that many businesses overlook entirely. - **Data breach procedures** - documented steps for detecting, reporting, and handling data breaches within the required 72-hour window. - **Compliance scoring** - an overview of where you stand and what still needs attention. - **Action tracking** - a prioritised list of remaining steps to reach full compliance. - **GDPR dossier** - a complete package of documentation that covers all GDPR obligations in one place. This is not a criticism of Cookiebot. It was never designed to cover these areas. But it means that choosing Cookiebot still leaves you with most of the GDPR work ahead of you. ## What GDPRWise does differently ### Full GDPR scope beyond cookies GDPRWise was built to cover the full breadth of GDPR requirements for small and medium businesses. Where Cookiebot focuses on one specific obligation (cookie consent), GDPRWise produces a complete dossier that includes your processing register, customer privacy policy, staff privacy policy, cookie report, action list, breach procedures, and compliance score. The result is a single platform that addresses everything a supervisory authority would expect to see during an inspection. You do not need to piece together separate tools for consent, documentation, and monitoring. ### AI-powered scanning and the three-layer dossier The GDPRWise process starts with an AI-powered website scan. Within two minutes, the scanner analyses your website and detects cookies, trackers, forms, third-party scripts, and even your business sector. This goes well beyond cookie detection - it maps your entire data collection landscape. The scan feeds into a three-layer dossier model: 1. **Sector foundation** - pre-built documentation for your industry, covering typical processing activities, legal bases, and retention periods. Your dossier starts 60 to 70 percent complete. 2. **AI scan results** - your specific website findings layered on top, with confidence labels ("Detected" or "Needs review") so you know exactly where your input is needed. 3. **Guided refinement** - business-level questions (not legal jargon) that fill in what the scan cannot detect, like employee data processing or CCTV usage. This approach means you are never starting from scratch. The combination of sector knowledge and AI detection produces a dossier that is already substantially complete before you answer a single question. ### Staff privacy policy This is a requirement that catches many businesses off guard. Under GDPR, you must inform your employees about how you process their personal data. That means a separate privacy policy covering payroll, CCTV, access control, company vehicles, IT usage, and any other employee-related processing. Cookiebot does not offer this. Most cookie consent tools do not, because it falls outside their scope entirely. GDPRWise includes staff privacy policy generation as a standard feature. During the guided refinement, you answer questions about your HR processes, and the platform generates a document you can provide to employees as an appendix to their employment contract. ## Side-by-side comparison | Feature | GDPRWise | Cookiebot | |---|---|---| | Cookie scanning | Yes (part of AI scan) | Yes (core feature) | | Consent banner | Via cookie report | Yes (core feature) | | Consent logging | No | Yes | | Processing register (ROPA) | Yes | No | | Customer privacy policy | Yes (tailored) | No | | Staff privacy policy | Yes | No | | Data breach procedures | Yes | No | | Compliance scoring | Yes | No | | Action tracking | Yes | No | | Sector-specific foundations | Yes | No | | AI-powered website scan | Yes (full site analysis) | Yes (cookies only) | | Continuous monitoring | Yes (Peace of Mind plan) | Yes (monthly scans) | | Multi-language support | NL, FR, DE, EN | 47+ languages | | Pricing model | One-off or subscription | Monthly subscription | ## When Cookiebot might be the right choice If your primary need is a polished consent banner with advanced customisation options and you already have the rest of your GDPR documentation handled through a lawyer or consultant, Cookiebot is a capable choice. Its consent management is mature, well-tested, and widely recognised. Larger organisations that operate websites in many languages may also benefit from Cookiebot's extensive language support. If you need consent banners in 20+ languages and already maintain your GDPR dossier through other means, Cookiebot specialises in exactly that. ## When GDPRWise is the better fit For most small and medium businesses, the challenge is not just cookie consent - it is the entire GDPR obligation. You need a processing register, privacy policies, breach procedures, and documentation that holds up during an audit. Handling these separately through different tools, templates, and consultants is time-consuming and expensive. GDPRWise addresses this by producing a complete dossier in a single workflow. The AI scan analyses your website, the sector foundation provides a head start, and the guided refinement fills in the rest. Most business owners complete the process in one to three hours. The inclusion of a staff privacy policy is particularly relevant. Many businesses are unaware they need one, and it is often the first gap a supervisory authority identifies. Having it built into the standard dossier means one less blind spot in your compliance. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### GDPRWise vs CookieYes: Full GDPR Compliance vs Cookie Consent Only URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/gdprwise-vs-cookieyes/ Summary: A fair comparison of GDPRWise and CookieYes. CookieYes handles cookie consent well, but GDPR requires far more. See where each tool fits and which one covers your full compliance needs. Key takeaways: - CookieYes is a solid cookie consent tool, but cookie consent is only one piece of the GDPR puzzle - GDPR compliance requires a processing register, privacy policies, staff data documentation, and breach procedures - none of which CookieYes provides - GDPRWise delivers a complete GDPR dossier through AI scanning, sector foundations, and guided refinement - If you only need a cookie banner, CookieYes is a reasonable choice. If you need full GDPR compliance, GDPRWise covers the rest FAQ: Q: Does CookieYes make me GDPR compliant? A: CookieYes helps with one aspect of GDPR: cookie consent. It does not provide a processing register, privacy policy generation, staff privacy policy, data breach procedures, or any of the other documentation the GDPR requires. A cookie banner alone does not make you compliant. Q: Can I use CookieYes and GDPRWise together? A: Technically yes, but there is no need. GDPRWise includes cookie scanning and detection as part of its broader website scan. Your cookie inventory becomes part of your complete GDPR dossier, so you do not need a separate cookie tool. Q: Is GDPRWise more expensive than CookieYes? A: CookieYes focuses only on cookies and costs approximately 8 to 50 euros per month. GDPRWise covers your entire GDPR compliance and offers a Free Scan (complete dossier at no cost) and a Peace of Mind subscription (EUR 29/month for continuous monitoring). The scope is fundamentally different, so a direct price comparison is not meaningful. ## Quick summary CookieYes is one of the most affordable cookie consent tools on the market. It handles cookie scanning, consent banners, and consent logging reliably, and it integrates with WordPress and Shopify. If your only concern is managing cookies on your website, CookieYes does that job well. But GDPR compliance involves far more than cookies. A processing register, privacy policies, staff data documentation, data breach procedures, compliance scoring - none of these are part of CookieYes. GDPRWise was built to cover the full scope of GDPR, starting with an AI-powered website scan and ending with a complete, audit-ready dossier. This article compares both tools fairly so you can decide which one fits your situation. ## What CookieYes does CookieYes is a dedicated cookie consent platform. It is popular among small website owners and developers because of its low price point (approximately 8 to 50 euros per month) and straightforward setup. Here is what CookieYes covers: - **Cookie scanning** - it crawls your website and identifies the cookies being placed on visitors' devices - **Consent banner** - a customisable banner that asks visitors for consent before cookies are set - **Consent logging** - it records when and how visitors gave or withdrew consent, which is useful for demonstrating compliance with cookie rules - **Google Consent Mode v2** - certified integration with Google's consent framework, so your analytics and ad tools respect visitor choices - **IAB TCF 2.3** - certified support for the Transparency and Consent Framework used in programmatic advertising - **CMS integrations** - plugins for WordPress, Shopify, and other popular platforms - **Non-technical UI** - designed so website owners without development skills can set up and manage their cookie banner For its specific purpose, CookieYes is a competent tool. It does what it promises, at a price that is accessible for small businesses. ## What CookieYes does not cover Cookie consent is one requirement under GDPR. It is not the whole regulation. Here is what CookieYes does not provide: - **Processing register (ROPA)** - the record of all personal data processing activities in your organisation. This is the first document a supervisory authority asks for during an audit. - **Privacy policy generation** - a tailored privacy policy that reflects your actual data processing, not a generic template. - **Staff privacy policy** - a separate document informing employees about how their personal data is processed (payroll, access control, CCTV, IT usage). - **GDPR dossier** - the complete set of documentation that proves your organisation takes data protection seriously. - **Data breach procedures** - documentation of what happens when a data breach occurs, who is responsible, and how you notify the supervisory authority within 72 hours. - **Compliance scoring** - a measurement of where you stand and what gaps remain. - **Action tracking** - a prioritised list of steps you still need to take to reach full compliance. These are not optional extras. They are core GDPR obligations. A cookie banner without the underlying documentation is like locking the front door while leaving every window open. ## What GDPRWise does differently ### GDPR is much more than cookies The GDPR is a regulation with 99 articles covering how organisations collect, process, store, and protect personal data. Cookie consent falls under a small part of that scope, primarily linked to the ePrivacy Directive. GDPRWise treats cookies as one element of a much larger picture. The platform's AI scanner detects cookies and trackers, yes, but it also identifies third-party scripts, data collection forms, embedded services, and other processing activities happening on your website. Each finding feeds into your processing register and privacy documentation. When you use GDPRWise, cookie compliance is handled as part of the process. You do not need a separate tool for it. ### Complete dossier from one scan GDPRWise uses a three-layer approach to build your dossier: 1. **Sector foundation** - pre-built documentation for your industry, covering typical processing activities, legal bases, and retention periods. Your dossier starts 60 to 70 percent complete before you answer a single question. 2. **AI scan results** - findings from your website are layered on top, adding the specific tools, cookies, and data flows that apply to your site. 3. **Guided refinement** - business-language questions fill in what the scan cannot detect. Do you have employees? Do you use CCTV? Do you transfer data outside the EU? The result is a complete GDPR dossier: processing register, customer privacy policy, staff privacy policy, cookie report, action list, and compliance score. Everything a supervisory authority expects to see, produced in one session. ### Continuous compliance, not just a banner A cookie banner is static once you set it up. CookieYes does rescan cookies periodically, which is useful. But GDPR compliance is broader than cookies, and it changes over time. You add new tools to your website, hire staff, change suppliers, or start processing a new type of personal data. GDPRWise's Peace of Mind plan rescans your website automatically and compares changes to your existing dossier. If a new tracker appears or a third-party script changes, you get a notification. Your compliance score updates accordingly, and the action list tells you exactly what to address. Free Scan users can trigger a rescan manually whenever their situation changes. This is the difference between maintaining a banner and maintaining compliance. ## Side-by-side comparison | Feature | CookieYes | GDPRWise | |---|---|---| | Cookie scanning | Yes | Yes (part of broader scan) | | Consent banner | Yes | Generates cookie report for your banner | | Consent logging | Yes | Not applicable (different approach) | | Google Consent Mode v2 | Yes | Not applicable | | IAB TCF 2.3 | Yes | Not applicable | | Processing register (ROPA) | No | Yes | | Customer privacy policy | No | Yes (tailored to your processing) | | Staff privacy policy | No | Yes | | Data breach procedures | No | Yes | | Compliance scoring | No | Yes | | Action tracking | No | Yes | | Complete GDPR dossier | No | Yes | | Third-party script detection | Limited (cookies only) | Yes (scripts, forms, trackers, embeds) | | Sector-specific foundations | No | Yes | | Continuous monitoring | Cookie rescans | Full website rescans with dossier comparison | ## When CookieYes might be the right choice CookieYes is a reasonable choice if: - You already have your GDPR documentation handled (through a consultant, DPO, or another tool) and you only need a cookie consent solution - Your website is your only concern, and you do not process personal data in other ways - You need IAB TCF 2.3 certification specifically for programmatic advertising - You want the cheapest possible cookie banner and nothing else If your GDPR documentation is already complete and maintained, adding CookieYes for cookie management is a perfectly valid approach. ## When GDPRWise is the better fit GDPRWise is the better fit if: - You need to comply with the GDPR as a whole, not just the cookie consent requirement - You do not have a processing register, privacy policies, or staff data documentation yet - You want a single platform that covers everything instead of combining multiple tools - You want to go from zero to audit-ready in a single session - You have employees and need a staff privacy policy - You want compliance monitoring that goes beyond cookies - You prefer answering business questions over filling in legal templates Most small and medium businesses fall into this category. Cookie consent is important, but it is one item on a longer checklist. GDPRWise handles the full list. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### GDPRWise vs iubenda: Why a Privacy Policy Generator Is Not Enough URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/gdprwise-vs-iubenda/ Summary: Comparing GDPRWise and iubenda side by side. iubenda generates privacy policies and cookie banners. GDPRWise builds a complete GDPR dossier from an AI website scan. See which approach fits your business. Key takeaways: - iubenda is strong at generating privacy policies, cookie policies, and consent banners across 30+ languages - GDPRWise treats the privacy policy as an output of compliance work, not the starting point - GDPRWise includes a processing register, compliance score, staff privacy policy, and action list - none of which iubenda provides - If you only need a privacy policy and cookie banner, iubenda may be sufficient. If you need full GDPR compliance, GDPRWise covers more ground FAQ: Q: Is iubenda enough for GDPR compliance? A: iubenda covers privacy policies, cookie policies, terms and conditions, and consent banners very well. However, full GDPR compliance requires more: a processing register, staff privacy policy, data breach procedures, and documented security measures. iubenda does not provide these, so you would need additional tools or manual work to fill the gaps. Q: Can I use iubenda and GDPRWise together? A: Technically yes, but there is overlap. GDPRWise generates a privacy policy as part of its dossier output, so you would not need iubenda's policy generator. Some businesses use iubenda's consent banner alongside GDPRWise's dossier, though GDPRWise's scan detects and documents consent requirements as well. Q: Which tool is cheaper? A: iubenda starts at approximately 3.49 euro per month for basic plans. GDPRWise offers a Free Scan (complete dossier at no cost) and a Peace of Mind plan (EUR 29/month for continuous monitoring). The scope is different: iubenda covers document generation, while GDPRWise covers the full compliance dossier. Comparing price without comparing scope can be misleading. ## Quick summary iubenda and GDPRWise solve different problems. iubenda generates legal documents - privacy policies, cookie policies, terms and conditions - and provides a consent management platform. GDPRWise scans your website with AI, builds a complete GDPR dossier including a processing register, and produces your privacy policy as the result of that compliance work. If your only goal is a professional-looking privacy policy and a cookie banner, iubenda does that well. If you need a complete GDPR dossier that would hold up during an audit by a supervisory authority, GDPRWise covers significantly more ground. This article walks through what each tool does, where they differ, and which situations favour one over the other. ## What iubenda does iubenda has earned its reputation as a reliable privacy policy and cookie policy generator. With over 150,000 customers and support for more than 30 languages, the platform has carved out a clear position in the market. Here is what iubenda does well: - **Privacy policy generation** - attorney-drafted, automatically updated legal text that adapts to the services you use (Google Analytics, Stripe, Mailchimp, etc.) - **Cookie policy generation** - a detailed cookie policy that categorises cookies by type and purpose - **Terms and conditions generator** - pre-built clauses for common business models - **Consent management platform (CMP)** - a cookie banner with IAB TCF 2.2 support, covering consent collection and preference management - **Multi-language support** - policies available in 30+ languages out of the box The pricing is accessible, starting at approximately 3.49 euro per month for basic plans and scaling up to around 90 euro per month for more comprehensive packages. For businesses that need a quick, professional privacy policy and a compliant cookie banner, iubenda delivers. The attorney-drafted language is a genuine advantage over free generators that produce generic text. ## What iubenda does not cover The gap in iubenda's offering becomes visible when you measure it against the full scope of GDPR requirements. A privacy policy is one piece of GDPR compliance, but the regulation demands considerably more. iubenda does not provide: - **Processing register (ROPA)** - the record of processing activities that every data controller must maintain under Article 30 - **Staff privacy policy** - a separate document informing employees how their personal data is processed - **GDPR dossier compilation** - a structured, audit-ready collection of all compliance documentation - **Compliance scoring** - a measurement of where you stand and what gaps remain - **Action tracking** - a prioritised list of steps to close compliance gaps - **Guided compliance workflow** - a step-by-step process that translates business questions into legal documentation - **Data breach procedures** - documented protocols for handling personal data breaches - **Website scanning beyond cookies** - detection of forms, third-party scripts, trackers, and sector identification This is not a criticism of iubenda. The tool does what it promises. But the scope of what it promises is narrower than what GDPR compliance actually requires. ## What GDPRWise does differently GDPRWise was designed around a fundamentally different premise: compliance is the goal, and the privacy policy is a byproduct of that work. ### Policy as output, not starting point iubenda starts with the policy. You select the services you use, and it generates a privacy policy based on your selections. The document is the product. GDPRWise reverses this sequence. The starting point is an AI-powered scan of your website that detects cookies, trackers, forms, third-party scripts, and your business sector. From there, you work through a guided process that maps out your processing activities, legal bases, retention periods, and security measures. Your privacy policy is generated at the end, as a natural output of the compliance work you have already completed. The result is a policy that accurately reflects your documented processing activities, not a policy based on checkboxes. This distinction matters during an audit. A supervisory authority does not just want to see a privacy policy on your website. They want to see that the policy matches your actual data processing, supported by a documented register and underlying compliance work. ### Complete dossier from scan GDPRWise builds a three-layer dossier: 1. **Sector foundation** - pre-built processing activities, legal bases, and security measures for your industry, loaded automatically after the scan identifies your sector 2. **AI scan results** - your specific cookies, trackers, forms, and scripts integrated into the dossier with confidence labels 3. **Guided refinement** - business questions (not legal questions) that fill in what the scan cannot detect: employees, CCTV, data transfers, and more The output is a complete dossier containing a processing register, customer privacy policy, staff privacy policy, cookie report, action list, and compliance score. Every component is exportable as PDF or Excel. iubenda does not offer this type of structured, layered dossier. Its output is individual documents, not an integrated compliance package. ### Staff privacy policy GDPR requires you to inform employees about how you process their data. This means a separate privacy policy covering payroll, HR records, CCTV, access control, company devices, and similar processing activities. iubenda does not generate staff privacy policies. Many businesses are unaware this requirement exists until they are asked about it during an audit. GDPRWise includes the staff privacy policy as a standard part of every dossier. During the guided refinement, the platform asks about your HR processes and generates the document based on your answers. It is not an add-on or premium feature. ## Side-by-side comparison | Feature | iubenda | GDPRWise | |---|---|---| | Privacy policy generation | Yes, attorney-drafted | Yes, as dossier output | | Cookie policy | Yes | Yes, from scan data | | Terms and conditions | Yes | No | | Consent banner (CMP) | Yes, IAB TCF 2.2 | No | | AI website scanning | No | Yes | | Processing register (ROPA) | No | Yes, auto-generated | | Staff privacy policy | No | Yes, included | | Compliance score | No | Yes | | Action list | No | Yes | | Guided compliance workflow | No | Yes | | Data breach procedures | No | Yes | | Sector-based dossier foundation | No | Yes | | Languages | 30+ | 4 (EN, NL, FR, DE) | | Pricing model | Monthly subscription | Free Scan or EUR 29/month subscription | ## When iubenda might be the right choice iubenda fits well when your needs are focused on document generation rather than full compliance: - You need a privacy policy and cookie banner quickly, and you are confident the rest of your GDPR obligations are handled separately - You operate in many languages and need policies in languages that GDPRWise does not yet support - You primarily need terms and conditions alongside your privacy policy - You want a dedicated consent management platform with IAB TCF 2.2 support - Your budget is very limited and you only need the basics iubenda is a solid product in its category. For privacy policies and consent management specifically, it has a mature, well-maintained platform. ## When GDPRWise is the better fit GDPRWise makes more sense when you want to actually achieve GDPR compliance, not just produce a privacy policy: - You need a complete GDPR dossier that would satisfy a supervisory authority during an audit - You want your privacy policy to accurately reflect documented processing activities, not a best-guess checkbox selection - You have employees and need a staff privacy policy - You want to understand your compliance gaps through a compliance score and action list - You prefer to start from an AI scan of your actual website rather than selecting services from a list manually - You want a processing register without building one from scratch The choice often comes down to scope. If a privacy policy is the destination, iubenda gets you there efficiently. If the privacy policy is one piece of a larger compliance picture, GDPRWise covers more of that picture in a single tool. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### GDPRWise vs OneTrust: Right-Sized GDPR for SMEs vs Enterprise Overhead URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/gdprwise-vs-onetrust/ Summary: OneTrust is the enterprise gold standard for compliance, but it is wrong-sized for small businesses. See how GDPRWise delivers SME-focused GDPR compliance without the enterprise price tag or complexity. Key takeaways: - OneTrust is a leading enterprise GRC platform, but its pricing starts around $10,000/year with implementation fees on top - GDPRWise was built specifically for SMEs, not scaled down from an enterprise product - Setup takes hours with GDPRWise versus months of implementation with OneTrust - You do not need a dedicated compliance team to use GDPRWise - the AI scanner and guided refinement do the heavy lifting FAQ: Q: Is OneTrust overkill for a small business? A: For most small businesses, yes. OneTrust is designed for enterprises with dedicated compliance teams, budgets of $10,000 to $42,000 per year, and months available for implementation. SMEs typically need a complete GDPR dossier without that overhead. GDPRWise delivers exactly that. Q: Can GDPRWise do everything OneTrust does? A: No, and that is the point. OneTrust covers AI governance, third-party vendor risk, and other enterprise concerns that most SMEs do not have. GDPRWise focuses on what small businesses actually need: a processing register, privacy policies, staff privacy policy, cookie report, and compliance monitoring. Q: How much cheaper is GDPRWise compared to OneTrust? A: OneTrust typically costs $10,000 to $42,000 per year, plus implementation fees of $10,000 to $50,000. GDPRWise offers a Free Scan (complete dossier at no cost) and a Peace of Mind subscription (EUR 29/month), both at a fraction of that cost. The savings are significant enough to make OneTrust impractical for most SMEs. ## Quick summary OneTrust is the enterprise gold standard for governance, risk, and compliance. It serves global organisations like Adobe, Samsung, and Aetna with a comprehensive platform covering privacy automation, AI governance, consent management, and third-party vendor risk. For a small or medium business looking at GDPR compliance, however, OneTrust is fundamentally wrong-sized. Its pricing starts around $10,000 per year, implementation takes months, and you need a dedicated compliance team to operate it. GDPRWise was built specifically for SMEs: a complete GDPR dossier in hours, at a fraction of the cost, with no compliance team required. ## What OneTrust does OneTrust is a modular governance, risk, and compliance (GRC) platform that covers virtually every aspect of organisational compliance. Its product suite includes privacy automation, consent and preference management, data use governance, AI governance, tech risk and compliance, and third-party vendor risk management. The platform serves large enterprises that operate across multiple jurisdictions and need to coordinate compliance across departments, teams, and vendors. OneTrust handles data mapping at scale, automates subject access requests across complex systems, manages vendor assessments, and provides reporting dashboards for compliance officers and legal teams. OneTrust has earned its reputation. It is used by some of the world's largest organisations to manage compliance programmes that span continents, thousands of vendors, and millions of data subjects. For that use case, it is genuinely excellent. ## Why SMEs consider OneTrust When small business owners search for GDPR tools, OneTrust appears at the top of many lists and review sites. It has strong brand recognition and a comprehensive feature set that looks impressive on paper. Business owners see the long list of capabilities and think: this must be the most thorough option. Some SMEs also encounter OneTrust through enterprise clients or partners who use it. When a larger company mentions their compliance platform, it is natural to wonder whether the same tool would work for your business. The logic seems sound: if it is good enough for Samsung, it must be good enough for my 15-person company. ## What makes OneTrust wrong-sized for small businesses The issue is not that OneTrust is a bad product. It is that it was designed for a completely different scale of business. Using OneTrust for a small business is like hiring a construction crew to hang a picture frame - the expertise is real, but the fit is wrong. ### Pricing that assumes enterprise budgets OneTrust pricing typically ranges from $10,000 to $42,000 per year, depending on the modules you need. On top of that, implementation fees run from $10,000 to $50,000. That means your first year could cost $20,000 to $90,000 before you process a single document. For a small business with 5 to 50 employees, that budget could cover several years of complete GDPR compliance through a right-sized tool. The mismatch is not about value for money in absolute terms - OneTrust delivers value for enterprises - but about proportionality. An SME does not need, and cannot justify, enterprise-level spending on compliance tooling. ### Complexity designed for compliance teams OneTrust assumes you have dedicated compliance professionals operating the platform. The interface, workflows, and terminology are designed for DPOs, privacy officers, and legal teams. Features like automated vendor risk assessments, cross-jurisdictional data mapping, and AI governance modules are powerful but irrelevant for a business that needs a processing register, privacy policies, and a cookie report. For a business owner without a compliance background, OneTrust's dashboard can be overwhelming. The platform offers so many options that finding the path to a basic GDPR dossier requires significant time and expertise. ### Implementation measured in months Enterprise platforms require enterprise-style implementation. OneTrust deployments typically take two to six months, involving configuration workshops, data mapping exercises, integration with internal systems, staff training, and ongoing calibration. Implementation consultants are often required. A small business owner cannot afford to spend months on compliance setup. The business needs to keep running, and GDPR compliance should not become a full-time project. ## What GDPRWise does differently ### Built for SMEs from the ground up GDPRWise was not created by stripping features from an enterprise product. It was designed from scratch for small and medium businesses. Every decision - from the interface to the pricing to the workflow - reflects the reality that an SME owner has limited time, no compliance background, and a modest budget. The platform uses a three-layer dossier model. A pre-built sector foundation covers the processing activities typical for your industry, getting your dossier 60 to 70 percent complete before you answer a single question. The AI scan adds your specific website findings on top. Then guided refinement asks targeted business questions - not legal ones - to fill in the rest. You answer questions about how your business works. GDPRWise translates your answers into proper GDPR documentation. No legal training required. ### AI scanning replaces a compliance team Where OneTrust assumes you have a team to operate the platform, GDPRWise uses AI to do the work that team would handle. The website scanner analyses your site in about two minutes, detecting cookies, trackers, forms, third-party scripts, and your business sector. Each finding carries a confidence label. "Detected" means the scan verified it with high certainty. "Needs review" means the platform wants your confirmation. You focus only on items that require your input, while everything the scan verified is already documented. The result is a workflow where one business owner, in one session, can produce the same documentation that would otherwise require a compliance officer working with an enterprise platform over several weeks. ### Hours, not months The GDPRWise process works in a single session: 1. **Scan**: 2 minutes 2. **Review results**: 10-15 minutes 3. **Guided refinement**: 30-90 minutes 4. **Review dossier**: 15-30 minutes Total: one to three hours. Your complete dossier - processing register, customer privacy policy, staff privacy policy, cookie report, action list, and compliance score - is ready the same day. Compare that to a two-to-six-month OneTrust implementation. ## Side-by-side comparison | Feature | GDPRWise | OneTrust | |---|---|---| | Target audience | SMEs (1-250 employees) | Enterprises (500+ employees) | | Annual cost | Free Scan or Peace of Mind (EUR 29/month) | $10,000-$42,000/year | | Implementation cost | Included | $10,000-$50,000 | | Time to first dossier | 1-3 hours | 2-6 months | | Compliance team required | No | Yes | | Processing register (ROPA) | Yes | Yes | | Customer privacy policy | Yes | Yes | | Staff privacy policy | Yes (included) | Via additional modules | | Cookie scanning | Yes | Yes | | AI governance | No | Yes | | Third-party vendor risk | No | Yes | | Data use governance | No | Yes | | AI-powered website scanning | Yes | Limited | | Three-layer dossier model | Yes | No | | Guided refinement (business questions) | Yes | No | | Export as PDF/Excel | Yes | Yes | | Continuous monitoring | Yes (Peace of Mind) | Yes | ## When OneTrust is the right choice OneTrust is the right choice when your organisation has the scale and complexity to justify it. If you have hundreds or thousands of employees, operate across multiple jurisdictions, manage a large vendor ecosystem, need AI governance capabilities, or have a dedicated privacy team to operate the platform, OneTrust delivers genuine value. Enterprises with complex data flows, subject access request volumes in the thousands, and regulatory obligations spanning multiple frameworks (GDPR, CCPA, LGPD, and others) benefit from OneTrust's comprehensive scope. If your annual compliance budget is six figures and you have the team to match, OneTrust is a proven platform. ## When GDPRWise is the better fit For small and medium businesses that need GDPR compliance without enterprise overhead, GDPRWise covers the ground that actually matters. Most SMEs need a processing register, privacy policies for customers and staff, a cookie report, and an action plan. They need it done in hours, not months. They need to understand the process without a compliance background. And they need it at a price that makes sense for a business with 5 to 50 employees. GDPRWise handles that entire journey. The AI scan gives you a clear picture of your website setup. The sector foundation gives you a head start. The guided refinement turns your business answers into proper documentation. And the staff privacy policy closes a gap that most SMEs do not even know exists. If you have been looking at OneTrust and feeling unsure about the price, the implementation timeline, or the complexity, that feeling is telling you something. You do not need an enterprise platform. You need a tool that was built for businesses like yours. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### GDPRWise vs Privacy Zeker: Automated Dossier vs Manual Guidance URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/gdprwise-vs-privacy-zeker/ Summary: A fair comparison of GDPRWise and Privacy Zeker (Zeker). Learn how automated scanning and dossier generation differ from manual guidance and templates, and which approach fits your business. Key takeaways: - Privacy Zeker offers expert helpdesk access and e-learning - strong for organisations that prefer human guidance - GDPRWise automates website scanning and dossier generation - strong for businesses that want fast, scan-based results - Privacy Zeker focuses on the Netherlands; GDPRWise supports NL, EN, FR, and DE - Both platforms aim to make GDPR accessible to non-experts, but they take fundamentally different approaches FAQ: Q: Is Privacy Zeker a good GDPR tool? A: Yes. Privacy Zeker has over 120,000 customers in the Netherlands and provides solid guidance documents, e-learning modules, and access to an expert helpdesk. It works well for organisations that prefer step-by-step manual guidance with human support. Q: What does GDPRWise do that Privacy Zeker does not? A: GDPRWise provides automated website scanning that detects cookies, trackers, and third-party scripts. It auto-generates a three-layer dossier based on scan results and your business sector. It also includes a staff privacy policy and supports four languages. Privacy Zeker does not offer automated scanning or AI-powered dossier generation. Q: Can I switch from Privacy Zeker to GDPRWise? A: Yes. You can start with a free GDPRWise website scan to see what the platform detects. Your existing documentation from Privacy Zeker can inform the guided refinement step, so nothing is wasted. ## Quick summary Privacy Zeker (also known as Zeker) and GDPRWise both help businesses achieve GDPR compliance, but they take very different approaches. Privacy Zeker provides manual guidance documents, e-learning modules, and access to a human expert helpdesk. GDPRWise uses AI-powered website scanning to detect your actual setup and auto-generates a three-layer dossier based on the results. This article compares both platforms fairly, so you can decide which approach fits your situation. ## What Privacy Zeker does Privacy Zeker is a Netherlands-focused GDPR guidance platform with over 120,000 customers. It combines software with human expertise, and its core offering includes: - **Guidance documents** - step-by-step instructions and templates that walk you through GDPR requirements - **E-learning modules** - training content that helps you and your team understand privacy obligations - **Expert helpdesk** - access to privacy professionals who can answer your questions directly - **Manual compliance workflows** - structured processes for documenting your data processing activities - **Breach register** - a tool for recording and managing data breaches - **Certificate of compliance** - documentation that demonstrates you have followed their compliance process This is a solid set of features, particularly the expert helpdesk. For organisations that want human guidance throughout the process, having direct access to privacy experts is genuinely valuable. The e-learning component also helps build internal knowledge, which pays off long-term. Privacy Zeker's pricing sits at approximately 19 to 29 euros per month, depending on the plan. ## What Privacy Zeker does not cover Despite its strengths, there are areas that Privacy Zeker does not address: - **No automated website scanning** - you do not get an automated analysis of your cookies, trackers, third-party scripts, or forms. You need to identify these manually or use a separate tool. - **No AI-powered dossier generation** - your dossier is built by hand using templates. There is no automatic pre-population based on your website or sector. - **No staff privacy policy** - the platform focuses on customer-facing privacy. Employee data processing documentation is not included as a standard deliverable. - **No cookie scanning** - identifying and categorising cookies on your website requires separate tooling. - **No sector-specific dossier templates** - while guidance is provided, there are no pre-built dossier foundations tailored to specific industries. - **No scan-based compliance scoring** - your compliance status is based on self-assessment rather than automated detection. These gaps matter most for businesses that lack the time or technical knowledge to fill in the blanks manually. ## What GDPRWise does differently ### Automated scanning vs manual guidance The most fundamental difference is the starting point. With Privacy Zeker, you begin with guidance documents and fill in your information step by step. With GDPRWise, you begin with a website scan. The GDPRWise scan runs in about two minutes and detects your cookies, third-party scripts, trackers, forms, and data collection points automatically. It also identifies your business sector. This means your dossier starts with real data from your actual website, not a blank template you need to complete from scratch. This matters because most small business owners do not know exactly which cookies their website places, which third-party scripts are loaded, or how many tracking pixels are active. The scan removes that guesswork. Privacy Zeker's approach requires you to gather this information yourself. If you know your technical setup well, that works. If you do not, you may end up with incomplete documentation. ### Dossier generation vs template-based approach GDPRWise builds your dossier in three layers. The first layer is a pre-built sector foundation - a dossier template for your industry that covers the typical processing activities, legal bases, and retention periods. The second layer adds your scan results on top. The third layer is a guided refinement where you answer business questions (not legal ones) to fill in what the scan cannot detect. The result is a complete dossier that includes a processing register, customer privacy policy, staff privacy policy, cookie report, action list, and compliance score - all generated from your actual data. Privacy Zeker provides templates and guidance to help you build documentation manually. This gives you more control over every detail, but it also means more time and effort. You are the one writing and assembling the documents. ### Multilingual and cross-border Privacy Zeker is primarily focused on the Netherlands, with content and support in Dutch. This works perfectly if your business operates exclusively in the Netherlands. GDPRWise supports Dutch, English, French, and German. You can generate your privacy policy in one language for your website and another for internal use. This makes it a natural fit for businesses that operate across Belgium, the Netherlands, Germany, or serve international customers. ## Side-by-side comparison | Feature | Privacy Zeker | GDPRWise | |---|---|---| | Automated website scanning | No | Yes - AI-powered, 2-minute scan | | Dossier generation | Manual with templates | Auto-generated three-layer model | | Staff privacy policy | Not included | Included as standard | | Cookie scanning and categorisation | Not included | Included in scan | | Compliance scoring | Self-assessment | Scan-based automated score | | Sector-specific foundations | Not available | Pre-built for dozens of industries | | Expert helpdesk | Yes - human experts | Not included | | E-learning modules | Yes | Not included | | Breach register | Yes | Not included | | Certificate of compliance | Yes | Not included | | Languages | Primarily Dutch | NL, EN, FR, DE | | Pricing model | Subscription (~19-29/month) | Free Scan (EUR 0) or Peace of Mind (EUR 29/month, yearly) | | Customer base | 120,000+ in NL | Growing across NL, BE, DE | ## When Privacy Zeker might be the right choice Privacy Zeker is a reasonable choice if: - You want direct access to human privacy experts for questions and advice - Your team benefits from structured e-learning about GDPR - You operate exclusively in the Netherlands and only need Dutch-language support - You prefer manual control over every document and workflow - You value a certificate of compliance from a platform with a large established user base - You have the time and knowledge to identify your website's cookies and trackers manually The expert helpdesk is Privacy Zeker's strongest differentiator. If human guidance is important to your organisation, that feature alone can justify the subscription. ## When GDPRWise is the better fit GDPRWise is likely the better fit if: - You want your website scanned automatically to detect cookies, trackers, and scripts - You prefer a dossier that is generated from your actual data rather than assembled from blank templates - You need a staff privacy policy as part of your compliance documentation - You operate in multiple countries or languages (NL, BE, DE, or international) - You want a compliance score based on automated detection, not self-assessment - You want to complete your dossier in hours rather than weeks - You want to start with a free scan and only pay when you need continuous monitoring The automated scanning and dossier generation save significant time, particularly for businesses without dedicated privacy staff. Starting with real data instead of an empty template reduces the risk of gaps in your documentation. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### GDPRWise vs Termly: Document Generator with a Scanner vs Complete GDPR Dossier URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/gdprwise-vs-termly/ Summary: Comparing GDPRWise and Termly side by side. Termly generates legal documents and scans cookies. GDPRWise builds a complete GDPR dossier from an AI website scan. See which approach fits your business. Key takeaways: - Termly is a US-based platform that generates privacy policies, cookie banners, and other legal documents, with a built-in cookie scanner - GDPRWise treats the privacy policy as an output of compliance work, not the starting point, and builds a full Article 30 processing register from a website scan - Termly does not provide a processing register, staff privacy policy, compliance score, or prioritised action list - If you mainly need legal documents and a cookie banner, Termly may be sufficient. If you need a full GDPR dossier that holds up under audit, GDPRWise covers more ground FAQ: Q: Is Termly enough for full GDPR compliance? A: Termly handles the document side well: privacy policy, cookie policy, terms and conditions, DPA, and a consent banner. Full GDPR compliance also requires a processing register under Article 30, a staff privacy policy, documented data breach procedures, and security measures. Termly does not produce these, so you would need to fill those gaps with another tool, a consultant, or manual work. Q: Termly has a cookie scanner. Is that the same as the GDPRWise scan? A: Termly's scanner classifies cookies on your website. The GDPRWise scan goes wider: it detects cookies, third-party scripts, embedded services, data collection forms, and your business sector, then feeds all of that into your processing register and dossier. The scanner is the entry point to a full compliance build, not just a cookie inventory. Q: Can I use Termly and GDPRWise together? A: Technically yes, but there is overlap. GDPRWise generates a privacy policy, cookie report, and consent guidance as part of its dossier output, so Termly's policy generator and cookie banner would duplicate work already covered. Most businesses pick one approach rather than running both in parallel. Q: Which is more affordable? A: Termly offers a free tier with limits and paid plans in the low double digits per month. GDPRWise offers a Free Scan that produces a complete dossier at no cost, plus a Peace of Mind plan (EUR 29/month) for continuous monitoring. The scope is different: Termly focuses on document generation, GDPRWise covers the full compliance dossier. Comparing price without comparing scope can be misleading. ## Quick summary Termly and GDPRWise both touch the privacy and GDPR space, but they solve different problems. Termly generates legal documents (privacy policy, cookie policy, terms, DPA) and runs a cookie consent banner backed by a cookie scanner. GDPRWise scans your website with AI, builds a complete GDPR dossier including an Article 30 processing register, and produces your privacy policy as the result of that compliance work. If your goal is a polished privacy policy plus a cookie banner across multiple jurisdictions, Termly does that competently. If your goal is a complete GDPR dossier that would hold up during an audit by a supervisory authority, GDPRWise covers significantly more ground. This article walks through what each tool does, where they overlap, and which situations favour one over the other. ## What Termly does Termly is a US-based privacy compliance platform with a strong document generation suite. It serves a broad international audience and supports multiple privacy regimes (GDPR, CCPA, CPRA, LGPD, and others). Here is what Termly does well: - **Privacy policy generation** - automatically updated legal text that adapts to the services and integrations you select - **Cookie policy and cookie banner** - a consent management platform with IAB TCF support and Google Consent Mode v2 integration - **Cookie scanner** - crawls your website, classifies the cookies it finds, and feeds them into the banner and policy - **Terms and conditions, EULA, disclaimers, return policies** - a wider set of legal templates than most competitors offer - **DPA generator** - a Data Processing Agreement template you can use with your processors - **DSAR webform** - a basic intake form for handling data subject access requests - **Multi-jurisdiction coverage** - documents adapt to GDPR, CCPA, CPRA, VCDPA, and other regional rules - **Auto-updates** - templates change when laws change, and your published documents update with them Pricing starts with a free tier (limited features), with paid plans in the low double digits of euros per month for small sites, scaling up for larger businesses and agencies. For businesses that want a complete document suite plus a cookie banner under one roof, Termly is a credible choice. ## What Termly does not cover The gap appears when you measure Termly against the full scope of GDPR. A privacy policy and a cookie banner are two pieces of GDPR compliance; the regulation demands considerably more. Termly does not provide: - **Processing register (ROPA)** - the Article 30 record of processing activities that every controller must maintain. This is the first document a supervisory authority asks for during an audit. - **Staff privacy policy** - a separate document informing employees how their personal data is processed (payroll, access control, CCTV, IT usage) - **GDPR dossier compilation** - a structured, audit-ready collection of all compliance documentation in one place - **Compliance scoring** - a measurement of where you stand and what gaps remain - **Action tracking** - a prioritised list of steps to close compliance gaps - **Sector-specific foundations** - pre-built documentation for your industry covering typical processing activities, legal bases, and retention periods - **Guided compliance workflow** - a step-by-step process that translates business questions into legal documentation - **Documented data breach procedures** - protocols for handling personal data breaches and notifying the supervisory authority within 72 hours This is not a criticism of Termly. The tool delivers what it promises. But the scope of what it promises is narrower than what GDPR compliance actually requires for a controller in the EU. ## What GDPRWise does differently GDPRWise was designed around a different premise: compliance is the goal, and the privacy policy is a byproduct of that work. ### Policy as output, not starting point Termly starts with the policy. You answer questions about the services you use, and it generates a privacy policy and cookie banner. The documents are the product. GDPRWise reverses the sequence. The starting point is an AI-powered scan of your website that detects cookies, trackers, third-party scripts, forms, embedded services, and your business sector. From there, you work through a guided process that maps out your processing activities, legal bases, retention periods, and security measures. Once that is in place, the privacy policy writes itself from your dossier. ### Scanner that does more than cookies Termly's scanner classifies cookies. The GDPRWise scan goes wider. It detects: - Cookies and trackers (the same ground Termly covers) - Third-party scripts and embedded services - Forms that collect personal data - Sector signals that match your business to a documentation foundation Each finding feeds into your processing register and privacy documentation, not just a cookie banner. ### Complete dossier from one scan GDPRWise uses a three-layer approach to build your dossier: 1. **Sector foundation** - pre-built documentation for your industry, covering typical processing activities, legal bases, and retention periods. Your dossier starts 60 to 70 percent complete before you answer a single question. 2. **AI scan results** - findings from your website are layered on top, adding the specific tools, cookies, scripts, and data flows that apply to your site. 3. **Guided refinement** - business-language questions fill in what the scan cannot detect. Do you have employees? Do you use CCTV? Do you transfer data outside the EU? The result is a complete GDPR dossier: processing register, customer privacy policy, staff privacy policy, cookie report, action list, and compliance score. Everything a supervisory authority expects to see, produced in one session. ### Continuous compliance, not just document refresh Termly's auto-updates keep your published documents in step with regulatory changes. That is genuinely useful. But your own situation also changes: you add new tools to your website, hire staff, change suppliers, or start processing a new type of personal data. Document templates do not catch those. GDPRWise's Peace of Mind plan rescans your website automatically and compares changes to your existing dossier. If a new tracker appears or a third-party script changes, you get a notification. Your compliance score updates accordingly, and the action list tells you exactly what to address. Free Scan users can trigger a rescan manually whenever their situation changes. This is the difference between maintaining documents and maintaining compliance. ## Side-by-side comparison | Feature | Termly | GDPRWise | |---|---|---| | Privacy policy generator | Yes | Yes (generated from your dossier) | | Cookie policy generator | Yes | Yes (part of cookie report) | | Terms and conditions, EULA, disclaimer | Yes | Not in scope | | Consent banner (IAB TCF, Google Consent Mode v2) | Yes | Generates cookie report for your banner | | Cookie scanner | Yes (cookies only) | Yes (cookies, scripts, forms, embeds, sector) | | DPA generator | Yes | Included as part of dossier | | DSAR webform | Yes (basic intake) | Documented procedures in dossier | | Processing register (ROPA, Article 30) | No | Yes | | Staff privacy policy | No | Yes | | Data breach procedures | No | Yes | | Compliance scoring | No | Yes | | Action tracking | No | Yes | | Sector-specific foundations | No | Yes | | Complete GDPR dossier | No | Yes | | Continuous monitoring | Document auto-updates | Full website rescans with dossier comparison | | Primary regulatory focus | Multi-jurisdiction, US-led | EU-first, GDPR-native | ## When Termly might be the right choice Termly is a reasonable choice if: - You need a broad set of legal documents (privacy policy, cookie policy, terms, EULA, disclaimer) under one roof - You need to publish documents that adapt to multiple jurisdictions, including US states - You already have your processing register and internal GDPR documentation handled, and you only need policies and a cookie banner - You want IAB TCF support specifically for programmatic advertising - A consent banner with a cookie scanner is the main thing you are buying If your GDPR documentation is already complete and maintained, adding Termly for documents and consent is a perfectly valid setup. ## When GDPRWise is the better fit GDPRWise is the better fit if: - You need to comply with GDPR as a whole, not just publish a privacy policy and a cookie banner - You do not have a processing register, staff privacy policy, or breach procedures yet - You want a single platform that covers everything instead of combining multiple tools - You want to go from zero to audit-ready in a single session - You have employees and need a staff privacy policy - You want compliance monitoring that goes beyond document templates - You prefer answering business questions over filling in legal templates - You operate primarily in the EU and want a GDPR-native tool rather than a US-led platform with EU support bolted on Most small and medium businesses fall into this category. Polished documents matter, but they sit on top of a wider compliance picture. GDPRWise builds that picture first, then produces the documents from it. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Generate a Free Cookie Policy Based on a Real Scan URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/free-cookie-policy-generator/ Summary: Most cookie policy generators work from a questionnaire, so they guess at your cookies. GDPRWise scans your website, detects every cookie actually being set, and generates a cookie policy with provider, purpose, retention period and classification per cookie. Free with a free account. Key takeaways: - A cookie policy based on a questionnaire is rarely correct: most site owners do not know which cookies their website sets - GDPRWise scans your website like a real visitor and detects every cookie actually being set - Every detected cookie is automatically enriched with provider, purpose, retention period and classification - The scan is free and requires no account; you generate and publish the full cookie policy with a free account - Periodic rescans keep your published cookie policy current automatically FAQ: Q: What does the cookie policy generator cost? A: The website scan is free and requires no account or credit card. To generate, publish and export the full cookie policy you create a free GDPRWise account. That costs nothing either. Q: Why is a scan better than a questionnaire? A: Because a questionnaire assumes you know which cookies your website sets. In practice, tag managers, chat widgets, embeds and pixels add cookies nobody in your organisation is aware of. A scan measures what actually happens, so your policy describes reality instead of an estimate. Q: In which languages can I generate my cookie policy? A: GDPRWise generates your documents in multiple languages, including English, Dutch, French and German. Useful for websites that serve several language versions. Q: How does my cookie policy stay current? A: GDPRWise rescans your website periodically. When new cookies, trackers or third parties appear, your dossier is updated and your cookie policy is regenerated. If you publish the policy via the embed snippet, the latest version is automatically live on your website. A cookie policy should describe which cookies your website sets, with the provider, purpose, retention period and classification for each cookie. See our overview of [what exactly must be in a cookie policy](/en/kennisbank/verplichtingen/cookie-policy-requirements/). The only question is: where does that information come from? ## The problem with classic generators Most free cookie policy generators work from a questionnaire. Do you use Google Analytics? Do you have a Facebook pixel? Tick what applies, and out comes a text. That model has one fundamental problem: **it assumes you know which cookies your website sets.** And most site owners do not, through no fault of their own: - The marketing colleague added a campaign tag through Google Tag Manager last year. - The web agency installed a chat widget that sets cookies. - A single embedded YouTube video brings Google tracking cookies along. - The booking plugin drops a pixel nobody ever consciously chose. The result: a neatly formatted cookie policy that lists cookies you do not have, and stays silent about cookies you do set. Such a policy is worse than no policy, because it proves in writing that your disclosure does not match reality. And with that, the consent your cookie banner collects is not validly informed either. ## How GDPRWise does it differently: scanning instead of asking GDPRWise flips the approach. Instead of interrogating you, our scanner visits your website like a real visitor and records what happens: 1. **Detection.** The scan visits your website and records every cookie that gets set: first-party and third-party, session and persistent cookies, analytics pixels and social embeds. 2. **Enrichment.** Every detected cookie is matched against our cookie database and automatically completed with provider, purpose, retention period and classification, exactly the metadata a GDPR-compliant cookie policy requires. 3. **Generation.** From the completed cookie table, GDPRWise generates a full cookie policy, including the explanations of what cookies are, how visitors withdraw consent and how changes are communicated. 4. **Publication.** Publish the policy via a snippet that updates automatically, export it as a dated and versioned PDF, or link to it from your cookie banner. The scan is free and requires no account. To generate, publish and export the full policy, you create a free account. ## The biggest advantage: your policy keeps being right Generating a cookie policy is one thing; keeping it current is the real work. Websites change constantly, and every change can introduce new cookies. That is why GDPRWise does not stop after the first scan. We rescan your website periodically. When new cookies, trackers or third parties appear, we alert you, your dossier is updated and your cookie policy is regenerated. If you use the embed snippet, the current version is automatically live on your website, without you having to think about it. Compare that to the classic model: a static document that starts ageing the day you publish it. ## More than just a cookie policy The cookie policy is one document out of your GDPR dossier. The same scan that detects your cookies also maps your forms, third-party services and systems, and so forms the basis for your privacy policy and processing register. Everything is generated from the same source, so your documents never contradict each other. Also read [how the scan works exactly](/en/kennisbank/hoe-gdprwise-werkt/how-scan-works/). import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Generate Your Processing Register from Your GDPRWise Dossier URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/auto-generate-ropa/ Summary: Your processing register (ROPA) is assembled from everything in your GDPRWise dossier - customer processes, staff processes, and third parties. Manage your dossier, then generate and export your register. Key takeaways: - Your processing register is generated from your complete GDPRWise dossier, not just the scan - Customer processes, staff processes, and third parties all feed into the register automatically - The register includes all mandatory fields: purposes, legal bases, data items, recipients, retention period etc. - Export as PDF for the supervisory authority FAQ: Q: What exactly is a record of processing activities? A: A record of processing activities (ROPA) is an overview of all activities in which you process personal data. It is mandatory under the GDPR and the supervisory authority can request it at any time. Think of: customer data in your CRM, employee files, website analytics, and email newsletters. Q: Can GDPRWise detect processing activities that don't happen on my website? A: The automatic scan detects processing on your website. Additionally, GDPRWise asks targeted questions about your business operations so that activities like HR administration, customer files, and supplier management are also included in the register. Q: Can I customize the generated register? A: Yes, everything is editable. You can modify processing activities, add new ones, change retention periods, and update recipients. The generated register is a starting point you can refine as needed. Q: In what formats can I export the register? A: You can export as a professionally formatted PDF, ready to present to the supervisory authority, an auditor, or your accountant. ## Your dossier is your register The record of processing activities (ROPA) is one of the most important documents under the GDPR. The supervisory authority can request it at any time, and you need it to demonstrate that you know which personal data you process and why. The problem? Most business owners don't know where to start. Which processing activities do I have? Which data belongs to each? What are the correct legal bases? GDPRWise takes a different approach. Instead of asking you to build a register from scratch, you manage your GDPR dossier - customer processes, staff processes, and third parties - and GDPRWise assembles the register from that data. The register is an output of your dossier, not a separate exercise. ## Where the data comes from Your processing register draws from three sources within GDPRWise: **Customer dossier.** Every business process you document that touches customer data becomes a line in your register. Your CRM, email marketing, order processing, contact forms, website analytics - each one is a processing activity with its purpose, legal basis, and data categories. **Staff dossier.** Payroll, HR administration, sick leave tracking, performance reviews, access management - these are processing activities too, and they belong in your register. Many businesses forget this part entirely. **Third-party dossier.** Every external service that processes personal data on your behalf is recorded as a recipient in the relevant processing activities. Your hosting provider, email tool, CRM platform, accountant - they all appear in the register as recipients of data. The website scan contributes by detecting third parties, cookies, and trackers connected to your site. But the scan is a starting point, not the whole picture. The real completeness comes from managing your dossiers. ## What the register contains Each processing activity in your generated register includes the mandatory Article 30 fields: - **Purpose** - why do you process this data? (e.g., "sending newsletters") - **Legal basis** - on what legal ground may you do this? (e.g., consent, legitimate interest, contract) - **Categories of personal data** - which data do you process? (e.g., email address, name, IP address) - **Categories of data subjects** - whose data is it? (e.g., customers, website visitors, employees) - **Recipients** - with whom do you share the data? (e.g., Mailchimp, Google Analytics) - **Retention period** - how long do you keep the data? - **Security measures** - how do you protect the data? All of this is drawn from what you have already documented in your dossiers. No duplicate data entry. ## Generate and export When you are ready, go to the GDPR documents screen and generate your processing register. The export is a professionally formatted PDF that you can present to the supervisory authority, an auditor, or share with your accountant. The PDF always reflects the current state of your dossiers. Update a process, add a third party, or change a retention period in your dossier, then regenerate - and your register is current. ## Keep it current Your processing register is only valuable if it reflects reality. As your business changes - new tools, new processes, new staff activities - update your dossiers in GDPRWise and regenerate the register. Because the register is assembled from your dossiers, keeping it current is not a separate task. It is a natural result of maintaining your dossier. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### How Does the GDPRWise Scan Work? URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/how-scan-works/ Summary: Curious what happens when GDPRWise scans your website? This article explains how the scan works, what it detects and what results you get within 2 minutes. Key takeaways: - The scan automatically checks your website for cookies, forms, fields, trackers, third-party scripts etc. - Within seconds you get an overview of all GDPR relevant assets found - Based on your industry sector, items are incorporated in the appropriate sections in your GDPR dossier - You get full guest access to the GDPRWise app to review, enrich and take your GDPR dossier forward - No account needed - enter your URL and the scan does the rest FAQ: Q: How long does the GDPRWise scan take? A: The scan is done within 2 minutes. You enter your website URL, the scan runs automatically and you receive your results immediately. Q: Do I need to install anything to run the scan? A: No, you don't need to install anything. The scan works entirely externally. You enter your URL and GDPRWise does the rest. Q: Is the scan free? A: Yes, your first scan is completely free. You receive an overview of all findings, the risk assessment and the recommendations without any cost. Q: Can the scan slow down or disrupt my website? A: No. The scan simulates a normal website visit and has no impact on your website's performance or availability. ## Enter your URL and the scan does the rest The GDPRWise scan is designed to give you a clear picture of your website's privacy situation within 2 minutes. No complicated installations, no technical knowledge required. You enter your website address, click start, and our scanner gets to work. The scan simulates a normal website visit and analyses everything happening in the background. Think of the scripts being loaded, the cookies being placed and the data being collected through forms. That is exactly what the GDPR has strict requirements for. ## What does the scan detect? The scanner currently checks six key areas as outlined below, but is constantly being refined and extended. **Cookies and storage** Which cookies are being placed? Are they functional cookies or tracking cookies? Are they placed before or after consent? The scan maps every cookie, including its origin and purpose. **Third-party scripts** Does your website load scripts from external parties like Google Analytics, Facebook Pixel, HubSpot or Hotjar? Every external script that may process personal data is detected and reported. **Forms and data collection** Do you have contact forms, newsletter sign-ups or quote requests? The scan checks whether these forms collect data and whether they reference your privacy policy. **Trackers and tracking pixels** Many websites contain invisible tracking pixels that monitor visitor behaviour. The scan makes these visible, even if you didn't know they were there. **Social platform links** Does your website link to Instagram, LinkedIn, Facebook, Pinterest or other social platforms? These links are relevant for your privacy policy and may involve data sharing with those platforms. The scan detects all social platform connections on your site. **Email host detection** Where is your email hosted? Google Workspace, Microsoft 365 or another provider? Your email host processes personal data on your behalf, which means it belongs in your processing register. The scan identifies your email hosting provider from your domain's mail records. ## What do you get as a result? The scan does not just hand you a list of findings. It builds you a complete GDPR dossier. ### Your industry sector is detected Based on your website content, GDPRWise identifies your industry sector. This matters because every sector has specific GDPR requirements - a medical practice handles different data than a web agency or a retail shop. The detected sector is used to load the right sector profile as the foundation for your dossier. ### A full GDPR dossier, not just a report GDPRWise takes the sector profile and enriches it with your scan results. Cookies found on your site are added to the cookie section. Third-party scripts are mapped to the processing register. Forms are linked to data collection purposes. Social platform connections and your email host are incorporated where they belong. The result is an as-complete-as-possible GDPR dossier tailored to your business, not a generic checklist or a raw list of findings. ### Guest access to the GDPRWise app After the scan, you get full guest access to the GDPRWise app to view your dossier. No email required, no account needed. You can browse through every section, see what has been filled in automatically and what still needs your input. Items the scan detected with high confidence are marked as "Detected". Items that need your verification or additional context are marked as "Needs review", so you always know where to focus. ### Share with colleagues or create an account You can share your guest access URL with colleagues so they can review the dossier too. When you are ready to take things further, you can create an account and enter the free trial period. Everything you have reviewed as a guest carries over, nothing is lost. ## The scan is not a one-off The first scan gives you a picture of your website on a single day. Websites do not stay still. A developer adds a chat widget, a plugin update introduces a new cookie, a marketing campaign drops in a new pixel, and the dossier you built is quietly out of date. That is why the scan runs again. Later scans are compared against the dossier you already have, so you do not get a second report to read from scratch. You get the difference: what is new, what disappeared, and what changed, each with the action it calls for. Your documents are regenerated from the updated dossier. You can trigger a rescan yourself at any time, which is worth doing after a redesign, a platform migration, or a plugin update. Quarterly rescans and change alerts are part of the Peace of Mind subscription. See [how GDPRWise keeps your compliance up to date](/en/kennisbank/hoe-gdprwise-werkt/automatic-compliance-updates/) for the full picture. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### How GDPRWise Keeps Your GDPR Compliance Up to Date Automatically URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/automatic-compliance-updates/ Summary: GDPR compliance is not a one-time task. GDPRWise monitors your website continuously, detects changes, and keeps your dossier current without manual effort. Key takeaways: - GDPRWise rescans your website every quarter and compares findings against your existing dossier - Changes to cookies, trackers, or third-party scripts are flagged immediately with clear action items - The Peace of Mind subscription includes continuous monitoring so your dossier never goes stale - Regulatory updates relevant to your sector are surfaced in the platform, not buried in legal newsletters FAQ: Q: How often does GDPRWise rescan my website? A: With the Peace of Mind plan, GDPRWise rescans your website every quarter. You can also trigger a manual rescan at any time, for example after a website redesign or when you add new functionality. Q: What happens when the scan detects a change? A: The platform compares the new scan results against your existing dossier and flags any differences. New cookies, removed scripts, or changed forms are highlighted with clear labels. You see exactly what changed and what action is needed. Q: Does this work if I change my website provider or CMS? A: Yes. The scan works externally by visiting your website like a normal user. It does not depend on a specific CMS, hosting provider, or plugin. Switching platforms does not affect the monitoring. ## Compliance is never "done" Many business owners treat GDPR compliance as a one-time project. Complete the documentation, tick the box, move on. The reality is different. Your website changes. Your tools change. Your team changes. And the regulations themselves evolve. Consider what can happen in a typical year for a small business: - Your web developer adds a new analytics tool or chat widget - You install a WordPress plugin that sets cookies you did not know about - A third-party service you use changes its data processing practices - A new employee joins and you start processing their personal data - The supervisory authority publishes new guidance on a topic relevant to your sector Each of these events can make your carefully built GDPR dossier incomplete or inaccurate. If you are not monitoring for these changes, you may not notice until a complaint is filed or an inspection arrives. ## How most businesses handle updates (or don't) Be honest: when was the last time you reviewed your privacy policy? If you are like most SME owners, it was the day you published it. The same goes for the processing register, the cookie report, and the employee privacy policy. The problem is not negligence. It is that manual review requires time, knowledge, and motivation. You would need to: 1. Rescan your website manually or hire someone to do it 2. Compare the results with your existing documentation 3. Identify what changed 4. Figure out what the change means for your compliance 5. Update the relevant documents Most businesses skip this entirely until something forces them to act, like a data subject complaint, a regulatory letter, or a security incident. By that point, catching up is stressful and costly. ## Continuous monitoring with GDPRWise GDPRWise solves this problem by automating the monitoring loop. Instead of relying on you to remember to check, the platform does it for you. ### Automatic rescans With the Peace of Mind subscription, GDPRWise rescans your website every quarter. The same AI scanner that created your initial dossier runs again, checking for: - New cookies or changes to existing ones - Third-party scripts that were added or removed - New forms collecting personal data - Changes to consent mechanisms You can also trigger a rescan manually at any time. After a website redesign, a plugin update, or a migration to a new platform, a quick rescan confirms whether your compliance posture changed. ### Dossier comparison This is where the real value lies. The new scan results are not just presented as a standalone report. They are **compared against your existing dossier**. The platform shows you: - **New findings** - a cookie or tracker that was not there before, highlighted so you can review it - **Removed items** - something that was in your previous scan is no longer detected, which may mean a script was removed or a service was discontinued - **Changed items** - a cookie that changed its behaviour, duration, or category Each change comes with a clear label and a recommended action. You do not have to figure out the implications yourself. GDPRWise tells you what changed and what to do about it. ### Confidence labels carry forward Every finding in your dossier has a confidence label. Items marked "Detected" were identified with high certainty by the AI scanner. Items marked "Needs review" require your confirmation. When a rescan detects changes, the same labelling system applies. A new tracking cookie is flagged as "Detected" with an action to update your cookie report. A potential new data processing activity is flagged as "Needs review" with a targeted question for you to answer. You always know what is certain and what needs your input. ## Regulatory updates that matter to you Laws and enforcement priorities change. The European Data Protection Board issues new guidelines. National authorities publish sector-specific recommendations. Court rulings create new precedents. Keeping up with all of this as a small business owner is unrealistic. You do not have time to read every regulatory newsletter, and even if you did, you might not know which changes affect your specific situation. GDPRWise tracks regulatory developments and surfaces the ones relevant to your sector and your dossier. If the Belgian GBA publishes new guidance on cookie consent that affects how you handle analytics cookies, GDPRWise flags it in your dashboard with a clear explanation and the recommended update to your documentation. This is not a generic news feed. It is filtered, contextualised information tied directly to your compliance posture. ## What the Peace of Mind plan includes The Peace of Mind subscription is designed for businesses that want compliance to run in the background without constant manual attention. It includes: - **Quarterly rescans** - your website is monitored every quarter without any action from you - **Change detection and comparison** - every rescan is compared to your dossier, with changes clearly flagged - **Regulatory updates** - relevant legal changes are surfaced with actionable guidance - **Dossier updates** - when changes are detected, you can update your dossier directly from the notification - **Audit trail** - every scan, change, and update is logged, creating a history that demonstrates ongoing compliance effort For businesses where the website changes frequently, where multiple people manage the site, or where compliance is simply too important to leave to memory, Peace of Mind removes the risk of your dossier going stale. ## The Free Scan: still ahead of most If continuous monitoring is not what you need right now, the Free Scan still gives you a solid foundation. You receive a complete GDPR dossier based on your initial scan and guided questions - at no cost. You can trigger manual rescans whenever you choose and update your dossier yourself. The key difference is that the initiative is on you. There are no automatic rescans, no change detection alerts, and no regulatory update notifications. For businesses with a stable website and straightforward data processing, this may be perfectly sufficient. ## Why "set and forget" is a compliance risk The GDPR requires you to demonstrate ongoing compliance, not just initial compliance. Article 5(2) places the burden of proof on you as the data controller. If the supervisory authority asks how you maintain your documentation, "we did it once two years ago" is not a reassuring answer. Continuous monitoring creates an audit trail that shows you actively maintain your compliance posture. Scan dates, detected changes, actions taken, and dossier updates are all logged. This is exactly the kind of evidence regulators want to see. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### My Sector Is Not Listed - What Now? URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/sector-not-listed/ Summary: GDPRWise offers sector-specific profiles, but not every sector is listed. No problem: you can start with a general profile and adapt it to your situation. Key takeaways: - Select 'I am none of the above' if your sector is not listed - You will start with a general profile containing the most common processing activities - You can add, remove, or adjust processes to match your situation - GDPRWise regularly expands the list of supported sectors FAQ: Q: Am I missing anything by starting with a general profile? A: No. The general profile contains all processing activities that apply to most businesses. You only miss the sector-specific suggestions, but you can add processes specific to your industry yourself. Q: Can I switch to a sector profile later if my sector is added? A: You can contact the support team to adjust your profile. Any work you have already done in your dossiers is preserved. Q: Which sectors are supported? A: GDPRWise supports retail, hospitality, construction, healthcare, legal services, accountancy, education, and IT services, among others. The list grows regularly. ## Sector profiles make it easier, but are not required When you create your GDPRWise account, you select the sector your business operates in. Based on that, the platform suggests processing activities typical for your industry. A hospitality business gets different suggestions than a construction company or a web shop. But not every sector is listed. That does not mean you cannot use GDPRWise. ## Start with the general profile If you cannot find your sector, select the option **"I am none of the above"**. You will start with a general profile containing the most common processing activities, such as customer management, invoicing, newsletters, HR administration, and third parties. From that general profile you can: - **Remove processes** that do not apply to your business - **Add processes** specific to your sector - **Edit descriptions** so they accurately reflect what you do ## How do you know which processes to add? A good way to start: walk through your workday and consider for each activity whether personal data is involved. - Do you use specific software for your profession? Add it as a processing activity. - Do you collect data not on the standard list? Document it. - Do you handle sensitive data such as health information or criminal records? These deserve extra attention. Our article on [which processes to document](/en/kennisbank/hoe-gdprwise-werkt/which-processes-to-document) can help you with this. ## The sector list is regularly expanded GDPRWise regularly adds new sectors based on user feedback. If you believe your sector should be included, let us know via the contact form. The more we know about your industry, the better we can tailor the suggestions. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Need Help? How to Find Answers in GDPRWise URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/help-support/ Summary: Stuck in GDPRWise or have a question about the GDPR? Here are all the ways to get help: knowledge base, in-app guidance, contact form and more. Key takeaways: - The knowledge base contains guides, templates and explanations about GDPRWise and the GDPR - The app provides contextual guidance and tips at every step - The support team is reachable via the contact form for specific questions - You don't need to be a privacy expert - GDPRWise guides you step by step FAQ: Q: How quickly does the support team respond? A: We aim to respond within one business day. For urgent questions about compliance or deadlines, we try to be faster. Q: Can I reach support by phone? A: Currently we offer support via the contact form and email. This allows us to answer your question carefully and refer you to the right knowledge base article when needed. Q: I don't understand a GDPR term, where can I find an explanation? A: The knowledge base contains articles on all important GDPR concepts, from records of processing to legal basis. Use the search function or browse by category. ## You don't have to figure it out alone GDPR compliance can feel overwhelming, especially without a legal background. That's why GDPRWise is built to guide you at every step. But sometimes you need a little extra help. Here's how to find it. ## Knowledge base You're reading an article from it right now: the GDPRWise knowledge base. Here you'll find: - **Guides** on how GDPRWise works, step by step - **GDPR explanations** in plain language, without legal jargon - **Templates** you can use right away, such as a processing agreement or data breach procedure - **Sector-specific information** for industries like hospitality, retail, construction and healthcare Use the search function to quickly find the right article, or browse the categories. ## In-app guidance Inside the GDPRWise app, you get contextual help at every step: - **Field-level explanations** - each input field includes a note explaining what is expected - **Example answers** - many questions show a sample answer so you know what to enter - **Tips and warnings** - the platform alerts you when you skip something or when extra attention is needed - **Links to the knowledge base** - the app directs you to the relevant article for more background ## Contact form Can't find your answer in the knowledge base or in-app help? Get in touch via the contact form on the website. The support team is happy to help with: - Questions about how to fill something in - Unclear GDPR obligations - Technical issues with the platform - Feedback or suggestions for improvement We typically respond within one business day. ## You don't need an expert to get started GDPRWise is built for business owners who are not privacy experts. The scan, the dossiers and the documents are designed so you can work through them independently. The help is there for when you get stuck, not because you need it to begin. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Publishing Your Privacy Policy: Website, E-commerce and Social Media URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/publish-privacy-policy/ Summary: Your privacy policy is ready, but where do you publish it? This article explains step by step how to place your privacy policy on your website, e-commerce platforms like Shopify and WooCommerce, and social media. Key takeaways: - Place a link to your privacy policy in the footer of every page on your website - E-commerce platforms like Shopify and WooCommerce have dedicated fields for your privacy policy - Social media pages on Facebook and Instagram offer a field for your privacy policy URL - Check at least annually whether your privacy policy is still current and correctly linked everywhere FAQ: Q: Do I need to put my privacy policy on every page of my website? A: No, you don't need the full text on every page. But you must display a link to your privacy policy on every page, for example in the footer. This way visitors can always find it. Q: Do I need to link my privacy policy in my webshop checkout? A: Yes. At checkout you process personal data such as name, address and payment details. A link to your privacy policy at checkout is mandatory, ideally with a checkbox where the customer confirms they have read the policy. Q: How do I keep my privacy policy up to date across all platforms? A: The easiest approach is to host your privacy policy at a fixed URL on your own website and link to that URL everywhere. When you update the text, it is automatically current everywhere. ## Your privacy policy is ready - now what? You've drafted your privacy policy (or had GDPRWise generate it). Great, but a document sitting on your computer has no value. The GDPR requires that data subjects can easily find your privacy policy. Below you'll learn exactly where and how to publish it. ## On your website The most obvious place, and the most important one. **Footer link on every page.** Place a link labelled "Privacy Policy" in the footer of your website. The footer appears on every page, so visitors can always reach your policy regardless of where they are. **Dedicated page.** Create a dedicated page (for example `/privacy-policy`) and place the full text there. Use a clear URL that you can also share on other platforms. **Forms and checkout.** Wherever visitors enter personal data (contact form, newsletter sign-up, checkout), a link to your privacy policy must be present. For forms, a reference like "View our privacy policy" is sufficient. For checkout, a checkbox is recommended. ### Always up to date with GDPRWise embed The hardest part of publishing your privacy policy is not the initial placement, it is keeping it current. Every time you add a tool, change a processor, or update your data practices, your privacy policy needs to reflect that. Manually downloading, editing, and re-uploading is tedious and error-prone. GDPRWise solves this with three embed options that always serve the latest version of your privacy policy. On the **GDPR Documents** page, open your privacy policy and click **Embed**. A dialog opens where you choose a method and copy the code: import AppEmbedMock from '@/components/kb/AppEmbedMock.astro'; You make changes in your dossier, click "Generate new version" in GDPRWise, and your website automatically displays the updated policy. No re-uploading, no forgetting. **Script embed (recommended).** Paste a small script snippet into your website's privacy policy page. The script fetches the latest version of your policy from GDPRWise and displays it directly on your page. Visitors stay on your website and see the policy as part of your site, styled to match your design. This is the recommended option because it keeps visitors on your site and always reflects the most recent version without any manual intervention. **Direct link.** Link to a standalone hosted page on GDPRWise. This is useful if you cannot embed scripts on your website, for example on platforms with limited customisation. The link always resolves to the latest generated version. **PDF link.** Link to a downloadable PDF of your privacy policy. Ideal for email footers, contracts, or legal archives where you need a document format. The PDF link also always points to the latest version. **How it works in practice:** 1. Build your dossier in GDPRWise (customer, staff, and third party data) 2. Generate your privacy policy from the GDPR documents screen 3. Choose your embed method and copy the code or URL 4. Paste it into your website once 5. Whenever your dossier changes, regenerate the policy in GDPRWise - your website updates automatically No need to touch your website code again after the initial setup. ## On e-commerce platforms ### Shopify Go to **Settings > Legal**. There you'll find a field for your Privacy Policy. Paste your text or link to your page. Shopify automatically displays the policy in your shop's footer and at checkout. ### WooCommerce Go to **Settings > Privacy** in your WordPress dashboard. Select your privacy policy page. WooCommerce automatically shows a link at checkout and on the registration form. ### Other platforms Most e-commerce platforms (Lightspeed, Magento, BigCommerce) offer similar options. Look in the settings for "Legal" or "Privacy Policy". ## On social media ### Facebook Go to your **business page > About > More Info**. There you'll find a "Privacy Policy" field where you can enter your privacy policy URL. This is especially important if you run Facebook ads or use lead forms. ### Instagram As a business profile, Instagram allows you to add a privacy policy URL via your Facebook business page (since they share the same Meta Business Suite). Make sure the link is filled in there. ### LinkedIn On your LinkedIn company page, you can add your privacy policy URL in the company information. This is relevant if you collect personal data via LinkedIn, for example through Lead Gen Forms. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Reorder and Organise Processes in GDPRWise URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/reorder-processes/ Summary: You can rearrange the order of your processing activities by dragging them in the compact view. Useful for grouping or prioritising processes logically. Key takeaways: - Switch to the compact view to drag and drop process cards - Drag processes up or down to change their order - The order is saved automatically and reflected in your processing register - Group related processes together for a clearer dossier FAQ: Q: Does the order of processes affect my compliance? A: No. The order is purely for your own overview. Whether you sort by alphabet, priority, or department, it makes no difference to your compliance score or processing register. Q: Can I group processes by department? A: There is no dedicated grouping feature, but you can order processes so that related ones appear together. Many users place all HR-related processes next to each other, for example. Q: Does dragging work on my phone? A: The compact view and drag feature work best on a desktop or tablet. On a small screen it is harder to move cards around. ## Customise the order of your processes Once you have entered multiple processing activities in GDPRWise, you may want to organise them logically - all customer-related processes together, or the highest-risk processes at the top. ## How it works Go to one of your dossiers (customers, personnel, or third parties) and switch to the **compact view**. In this view you see all your process cards in a collapsed list, without the full details. From the compact view you can pick up any process card and drag it up or down to the desired position. The new order is saved automatically. ## When is reordering useful? - **After adding new processes** - new processes appear at the bottom of the list but may belong elsewhere - **When preparing your processing register** - a logical order makes the register clearer for a supervisory authority - **When handing over to a colleague** - a logical structure helps when someone else takes over your dossier The order you set is carried over into your generated documents, so it is worth taking a moment to arrange things. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Reseller Runbook: Get the Most out of GDPRWise as a Professional URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/reseller-runbook/ Summary: Are you an accountant, lawyer, or IT professional? GDPRWise offers a reseller programme that lets you provide GDPR compliance as a service to your clients. Key takeaways: - GDPRWise provides the platform free of charge for professionals who want to help their clients with GDPR compliance - You can create and manage client accounts from your own reseller environment - The platform does the heavy lifting - you provide the personal guidance and advice - Ideal for accountants, lawyers, IT professionals, and consultants who want to offer GDPR as an additional service FAQ: Q: Do I need to be a GDPR expert to become a reseller? A: You don't need to be a certified privacy expert. GDPRWise guides both you and your clients step by step. However, a basic understanding of the GDPR is important so you can advise your clients properly. Q: What does the reseller programme cost? A: The platform is available free of charge for professionals. Contact us via the contact form for the current terms and pricing structure. Q: Can I offer the platform under my own brand? A: Contact the GDPRWise team to discuss white-label or co-branding options. ## Offer GDPR compliance as a service As an accountant, lawyer, or IT professional, you regularly receive questions from clients about the GDPR. "Do we need to handle that too?" "What if we have a data breach?" "What about those processing agreements?" These are questions your clients struggle with but never get round to. GDPRWise lets you offer GDPR compliance as a service to your clients. The platform does the heavy lifting: the scan, the dossiers, the documents. You provide the personal guidance and advice. ## Who is the reseller programme for? The programme is designed for professionals who already have a trusted relationship with SME owners: - **Accountants and bookkeepers** - you know your clients' financial situation and which tools they use - **Lawyers and legal advisors** - you can place GDPR obligations in the right legal context - **IT professionals and MSPs** - you manage the systems and know where data is stored - **Consultants and advisors** - you already help clients with operations and can add GDPR as an extra service ## How does it work in practice? ### 1. Set up your reseller environment After signing up, you get access to an environment where you can create and manage client accounts. An overview shows which clients have started, how far they have progressed, and which actions are still open. ### 2. Start with the scan For each client you begin with a website scan. This immediately provides a concrete picture of their privacy situation. With that report in hand, you can start the conversation about next steps. ### 3. Guide your clients through the dossiers GDPRWise suggests the right processing activities per sector. You help your client fill in the dossiers, answer questions, and make the right choices. The platform then generates all required documents. ### 4. Deliver the documents The processing register, the privacy policy, the processing agreements - everything is generated automatically based on the dossiers. You review and deliver to your client. ## Why it works GDPR compliance is a task that many SME owners keep putting off. Too complicated, too time-consuming, too unclear. By offering it as a service, you remove the barrier. The client does not have to figure out what needs to happen - you guide the process and the platform does the rest. This creates value on both sides: your client is compliant, and you have an additional service that strengthens your existing relationship. ## Get started Contact us via the website contact form to sign up for the reseller programme. We will discuss the options and help you get started. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Team and Roles: Who Does What in GDPRWise? URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/team-roles-management/ Summary: GDPRWise uses three roles: Account Owner, GDPR Coordinator, and Dossier Coordinator. Learn what each role entails, who should have which role, and how to invite team members. Key takeaways: - GDPRWise has three roles: Account Owner (subscription and invitations), GDPR Coordinator (leads the GDPR process), and Dossier Coordinator (external support) - In smaller businesses, the Account Owner and GDPR Coordinator are often the same person - You can invite your accountant or legal advisor as Dossier Coordinator so they can work directly in the right dossier - Inviting team members takes just a few clicks from your account settings FAQ: Q: Can one person hold multiple roles? A: Yes. In smaller businesses the owner is often both Account Owner and GDPR Coordinator. You can combine both roles without issues. Q: Can my accountant log in to GDPRWise? A: Yes, you can invite your accountant as Dossier Coordinator. This role gives access to the third-party dossier or personnel dossier, depending on your settings. This way your accountant can contribute directly without emailing data back and forth. Q: How many people can I invite? A: There is no limit on team members. You can invite as many people as you need, each with their own role and access level. ## You do not have to do everything alone GDPR compliance is not a one-person job. Perhaps you want your office manager to fill in the personnel dossiers, or your accountant to review the third-party dossier. GDPRWise makes this possible with a simple role system. There are three roles, each with their own responsibilities and access level. ## The three roles explained ### Account Owner The Account Owner is the person who created the GDPRWise account, usually the business owner or director. This role has full access: manage the subscription, invite team members, view all dossiers, and download documents. There is always exactly one Account Owner per business account. ### GDPR Coordinator The GDPR Coordinator leads the GDPR process. In smaller businesses this is often the same person as the Account Owner. In larger businesses it could be an office manager, compliance officer, or HR staff member. **What can the GDPR Coordinator do?** - Fill in and manage all three dossiers (customers, personnel, third parties) - Generate and download documents (processing register, privacy policy, DPAs) - Track the compliance score and assign actions to team members This person does not need to be a privacy expert - GDPRWise guides every step - but it helps if they know your business processes well. ### Dossier Coordinator The Dossier Coordinator is intended for external support, such as your accountant, lawyer, or external privacy advisor. **What can the Dossier Coordinator do?** - Access specific dossiers you open for them - Add and edit information and leave comments - No access to subscription management or other dossiers Ideal for someone you want to involve temporarily or partially. Your accountant does not need to see your entire account, just the dossier they can help with. ## Who gets which role? Here are some practical guidelines: | Person | Recommended role | |--------|-----------------| | Business owner / director | Account Owner | | Office manager / HR staff | GDPR Coordinator | | Accountant | Dossier Coordinator (third-party dossier) | | Lawyer / legal advisor | Dossier Coordinator (specific dossier) | | IT partner | Dossier Coordinator (third-party dossier) | | External privacy advisor | GDPR Coordinator or Dossier Coordinator | In a small business you are probably both Account Owner and GDPR Coordinator. That is perfectly fine. ## How to invite someone Inviting a team member takes three steps: 1. Go to **Settings** in your GDPRWise dashboard 2. Click **Team** and then **Invite team member** 3. Enter the email address, choose the role, and optionally select the specific dossiers you want to grant access to The invitee receives an email with a link to log in or create an account. Once they accept the invitation, they can start working right away. ## Change or revoke roles You can change or revoke roles at any time from your team settings. Removed team members immediately lose access, but their contributions in the dossiers are preserved. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### The Best GDPR Tool for Small Businesses URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/best-gdpr-tool-small-business/ Summary: Which GDPR tool is best for a small business? A selection framework with the six criteria that matter, plus an honest comparison of GDPRWise against enterprise platforms, cookie tools, and consultants. Key takeaways: - The best GDPR tool for a small business scores on six criteria: automation, breadth of the dossier, ease of use, price, ongoing maintenance, and whether it covers staff data, not just customers - Enterprise platforms like OneTrust and TrustArc are built for organisations with a compliance team; for a business with 5 to 50 people they are overbuilt and overpriced - Cookie and consent tools cover the visible front end but do not produce the processing register an auditor asks for first - GDPRWise pairs AI scanning with sector dossiers and a staff privacy policy in a tool designed for small businesses, not multinationals FAQ: Q: What should I look for when choosing a GDPR tool for a small business? A: Six things: does it automate the heavy work (scanning your site) or make you fill in everything by hand? Does it produce a complete dossier, including the processing register and a staff privacy policy, not just a privacy statement? Is it usable without legal or technical knowledge? Does the price fit a small-business budget? Does it keep your dossier current after the first setup? And does it cover employee data as well as customer data? GDPRWise is built around exactly these six criteria. Q: Isn't an enterprise tool like OneTrust the safest choice? A: For a multinational with an in-house privacy team, yes. For a small business, no. Those platforms are priced and designed for large organisations, with annual licences running into the thousands or tens of thousands, and they need expertise to operate. For a business with 5 to 50 people you pay for complexity you will never use. Q: Do cookie consent tools make me GDPR compliant? A: Only partly. Tools like Cookiebot or iubenda handle the cookie banner and sometimes a privacy statement, but they do not build the processing register or the staff privacy policy that a supervisory authority asks for first. They cover the visible front end, not the full dossier. ## There is no single "best" GDPR tool, only a best tool for your situation "What is the best GDPR tool?" is the wrong question. A multinational with a legal department, a fast-growing scale-up, and a bakery with eight employees have completely different needs. The platform that is perfect for one is a waste of money for the other. For a small business, the better question is: which tool delivers a complete, correct GDPR dossier without requiring you to become a privacy expert, at a price that fits your size? This article gives you a concrete framework to answer that, and shows where GDPRWise is, and is not, the right choice. ## The six criteria that actually matter When you judge a GDPR tool as a small business, these six things make the difference. ### 1. Automation The biggest cost difference between tools is how much work they take off your plate. Does the tool ask you to enter every cookie and script by hand, or does it scan your website and detect them automatically? Automation is not just faster, it is more accurate, because you do not forget anything. ### 2. Breadth of the dossier A privacy statement alone does not make you compliant. A supervisory authority expects a complete dossier: a processing register, a cookie report, a [staff privacy policy](/en/kennisbank/hoe-gdprwise-werkt/employee-privacy-policy), and an action list. Check whether the tool delivers all of it, or only the easy part. ### 3. Ease of use without expertise A small business owner is not a privacy lawyer. The best tool asks questions about how your business works, not about legal bases and data subject categories, and translates your answers into proper documentation for you. ### 4. Price that fits a small business A tool that costs thousands per year is built for a different kind of customer. For a small business, the price should be proportional to the size of your company, not the size of the vendor. ### 5. Ongoing maintenance Compliance is not a one-time task. Your website changes, you add a tool, regulations shift. The best tool keeps your dossier current after the first setup, instead of handing you a snapshot that is out of date within six months. ### 6. Coverage of staff data, not just customers Most tools focus only on customer-facing privacy. But if you have employees, you process their data too, from payroll to CCTV. A tool that ignores this leaves a real gap in your compliance. ## The options side by side Hold the common compliance paths up against these six criteria and a clear picture emerges. **Enterprise platforms (OneTrust, TrustArc, Usercentrics)** score high on breadth but are built for large organisations with an in-house privacy team. The price and complexity are out of proportion for a small business. See our comparison [GDPRWise vs. OneTrust](/en/kennisbank/hoe-gdprwise-werkt/gdprwise-vs-onetrust). **Cookie and consent tools (Cookiebot, iubenda, Termly)** do part of the job well, the cookie banner and sometimes a privacy statement, but they do not produce a complete dossier. They cover the visible front end, not the processing register and staff policy an inspector asks for first. See [GDPRWise vs. iubenda](/en/kennisbank/hoe-gdprwise-werkt/gdprwise-vs-iubenda) and [GDPRWise vs. Termly](/en/kennisbank/hoe-gdprwise-werkt/gdprwise-vs-termly). **A privacy consultant** delivers quality and tailoring, but at a typical 2,000 to 5,000 EUR per project, and usually without ongoing maintenance unless you sign a retainer. The right choice for complex situations; an expensive one for a standard small business. **Doing it yourself with free templates** scores zero on automation, sector knowledge, and maintenance. It is free in euros but expensive in hours and risk. ## Where GDPRWise scores on the six criteria GDPRWise is built specifically for the small business that wants a good score on all six criteria, without an enterprise budget. - **Automation**: the [AI scan](/en/kennisbank/hoe-gdprwise-werkt/how-scan-works) analyses your website in two minutes and detects cookies, trackers, forms, and third-party scripts, each with a confidence label. - **Breadth**: a [complete dossier](/en/kennisbank/hoe-gdprwise-werkt/what-is-in-dossier) with a processing register, privacy statement, cookie report, staff privacy policy, action list, and compliance score. - **Ease of use**: you answer plain-language business questions; the platform handles the legal translation. - **Price**: start free with the Free Scan; Peace of Mind is EUR 29 per month, priced for a small business and not for a multinational. - **Maintenance**: Peace of Mind periodically rescans your website and flags changes, so your dossier stays current. - **Staff data**: a staff privacy policy is included as standard, not sold as an add-on. ## When GDPRWise is not the right choice Staying honest is part of a good framework. GDPRWise is not the best choice if you are a large organisation with complex, large-scale processing of sensitive data, international transfers to high-risk countries, or an in-house DPO team that needs an enterprise platform with advanced workflows. In those cases a OneTrust or a specialised law firm fits better. For the vast majority of small businesses, companies with 5 to 50 employees and predictable processing activities, that level of complexity is unnecessary. That is precisely the group GDPRWise is built for. For the specifics of what compliance involves at that scale, see our guide to [GDPR compliance for SMEs](/en/kennisbank/hoe-gdprwise-werkt/sme-gdpr-compliance). ## Getting started The fastest way to judge the best tool for your situation is simply to try it. The Free Scan gives you a complete dossier at no cost and no credit card, so you can see for yourself whether it meets your six criteria. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### The Best GDPR Tool for Small Businesses in Belgium URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/best-belgian-gdpr-tool/ Summary: Which GDPR tool is the right choice for a Belgian small business? A selection framework with the criteria that actually matter, plus where GDPRWise stands apart from consultants and enterprise tools. Key takeaways: - The best GDPR tool for a Belgian SME scores on six criteria: multilingual support, sector knowledge, automation, dossier completeness, price and ongoing maintenance - Enterprise platforms like OneTrust are built for large organisations with a DPO team; for a business of 5 to 50 employees they are too expensive and too complex - A consultant delivers quality but no ongoing maintenance, and typically costs EUR 2,000 to 5,000 per engagement - GDPRWise combines AI scanning, Belgian sector dossiers and multilingual documentation in a tool designed specifically for small businesses FAQ: Q: What should I look for when choosing a GDPR tool for my Belgian business? A: Watch for six things: does the tool support Dutch and French (and German if you operate in the East Cantons)? Does it know your sector? Does it automate the heavy lifting or do you still have to fill in everything yourself? Does it deliver a complete dossier (processing register, privacy policy, cookie report, employee policy)? Does the price fit an SME budget? And does it keep your documentation current after the first time? GDPRWise is built around exactly these six criteria. Q: Isn't an enterprise tool like OneTrust or TrustArc the safest choice? A: For a multinational with an in-house privacy team, yes. For a Belgian SME, no. Those platforms are priced and designed for large organisations: annual licences run into the thousands or tens of thousands of euros and you need expertise to operate them. For a business of 5 to 50 employees, you are paying for complexity you will never use. Q: Does GDPRWise meet Belgian-specific GDPR requirements? A: Yes. GDPR is a European regulation that applies directly in Belgium. GDPRWise generates documentation that meets the requirements enforced by the Belgian Data Protection Authority (GBA/APD), including the processing register, the privacy policy and the cookie documentation. ## There is no "best" GDPR tool - there is a best tool for your situation "What is the best GDPR tool?" is the wrong question. A multinational with a legal department, a growing scale-up and a bakery with eight employees have completely different needs. The platform that is perfect for one is a waste of money for another. For a Belgian small or medium-sized business, the better question is: which tool delivers a complete, correct GDPR dossier in the languages I need, at a price that fits my size, without my having to become a privacy expert? This article gives you a concrete selection framework to answer that question, and shows where GDPRWise is and is not the right choice. ## The six criteria that actually matter When you assess a GDPR tool for a Belgian SME, these are the six things that make the difference. ### 1. Multilingual support Belgium has three official language communities. Your privacy policy has to be in a language your customers understand, your employee policy in the language of your staff. A tool that only offers English, or only Dutch, forces you into translation work or into documentation that does not match your audience. The best choice supports at least Dutch and French natively, not as a translation layer bolted on afterwards. ### 2. Sector knowledge GDPR obligations vary widely by industry. A physiotherapy practice processes health data (a special category), a webshop processes payment data, a construction firm keeps site logs. A tool that starts with a blank page leaves the hard thinking to you. A tool with pre-built sector dossiers starts from the processing activities that are typical for your industry. ### 3. Automation The biggest cost difference between tools is how much work they take off your plate. Does the tool ask you to enter every cookie and every script by hand? Or does it scan your website and detect them automatically? Automation is not only faster, it is also more accurate, because you forget nothing. ### 4. Dossier completeness A privacy policy on its own does not make you compliant. The GBA/APD expects a complete dossier: a processing register, a cookie report, an [employee privacy policy](/en/kennisbank/hoe-gdprwise-werkt/employee-privacy-policy) and an action list. Check whether the tool delivers all of it, or only the easy part. ### 5. A price that fits an SME A tool that costs thousands of euros a year is built for a different kind of customer. For an SME, the price has to be proportionate to the size of the business, not to the size of the supplier. ### 6. Ongoing maintenance Compliance is not a one-off task. Your website changes, you add a tool, the rules shift. The best tool keeps your dossier current after the first time, instead of handing you a snapshot that is out of date within six months. ## The options side by side Line up the common compliance paths against these six criteria and a clear picture emerges. **Enterprise platforms (OneTrust, TrustArc, Usercentrics)** score high on completeness but are built for large organisations with an in-house privacy team. The price and complexity are out of proportion for an SME. See also our comparison [GDPRWise vs. OneTrust](/en/kennisbank/hoe-gdprwise-werkt/gdprwise-vs-onetrust). **Cookie and consent tools (Cookiebot, iubenda)** do part of the job well, namely the cookie banner and sometimes a privacy policy, but they do not deliver a complete dossier. They cover the visible front end, not the processing register and employee policy that an inspector asks for first. See [GDPRWise vs. iubenda](/en/kennisbank/hoe-gdprwise-werkt/gdprwise-vs-iubenda). **A privacy consultant** delivers quality and tailored work, but at EUR 2,000 to 5,000 per engagement, and usually without ongoing maintenance unless you sign a retainer. The right choice for complex situations; an expensive solution for a standard SME. **Doing it yourself with free templates** scores zero on automation, sector knowledge and maintenance. It is free in euros but expensive in hours and risk. ## How GDPRWise scores on the six criteria GDPRWise is designed specifically for the Belgian SME that wants a good score on all six criteria, without an enterprise budget. - **Multilingual support**: native support for Dutch, French, English and German. You generate your documents in the language your customers and staff expect, and switch without losing your progress. - **Sector knowledge**: pre-built sector dossiers for the industries most common among Belgian SMEs, from retail and hospitality to healthcare, construction and professional services. - **Automation**: the [AI scan](/en/kennisbank/hoe-gdprwise-werkt/how-scan-works) analyses your website in two minutes and detects cookies, trackers, forms and third-party scripts, each with a confidence label. - **Completeness**: a [complete dossier](/en/kennisbank/hoe-gdprwise-werkt/what-is-in-dossier) with a processing register, privacy policy, cookie report, employee privacy policy, action list and compliance score. - **Price**: start free with the Free Scan; Peace of Mind costs EUR 29 per month, priced for an SME and not for a multinational. - **Ongoing maintenance**: Peace of Mind periodically rescans your website and alerts you to changes, so your dossier stays current. ## When GDPRWise is not the right choice Staying honest is part of a good selection framework. GDPRWise is not the best choice if you are a large organisation with complex, large-scale processing of sensitive data, international transfers to high-risk countries, or an in-house DPO team that needs an enterprise platform with advanced workflows. In those cases, a OneTrust or a specialised law firm is a better fit. For the vast majority of Belgian SMEs, businesses with 5 to 50 employees and predictable processing activities, that level of complexity is unnecessary. GDPRWise is built for exactly that group. ## The Belgian context is built in The GBA (Gegevensbeschermingsautoriteit), in French the APD (Autorite de protection des donnees), enforces GDPR within Belgium and has grown steadily more active towards small businesses in recent years. The "we are too small to be noticed" argument no longer holds. Every business that processes personal data has to have its documentation in order. In its knowledge base and sector dossiers, GDPRWise takes Belgian-specific points of attention into account, from the enforcement priorities of the GBA/APD to the overlaps with Belgian labour law around camera surveillance and employee monitoring. The result is a dossier that matches what a Belgian inspector expects to see. ## Getting started Want to assess the best tool for your situation? The fastest way is simply to try it. The Free Scan gives you a complete dossier at no cost and without a credit card, so you can see for yourself whether it meets your six criteria. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### The Best GDPR Tool for Small Businesses in Belgium and the Netherlands URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/gdpr-tool-belgium-netherlands/ Summary: GDPRWise works for both Belgian and Dutch small businesses. Same GDPR, different supervisory authorities, one platform that covers both markets. Key takeaways: - Belgium and the Netherlands both fall under the GDPR (AVG in Dutch), but have different supervisory authorities - GDPRWise covers both markets with sector dossiers relevant to Belgian and Dutch business practices - Full Dutch-language support means both Flemish and Dutch business owners work in their own language - One platform, one dossier, one price - whether you operate in Belgium, the Netherlands, or both FAQ: Q: Is the GDPR the same in Belgium and the Netherlands? A: Yes. The GDPR (known as AVG in Dutch) is an EU regulation that applies identically in both countries. The difference is in enforcement: Belgium has the GBA (Gegevensbeschermingsautoriteit), while the Netherlands has the AP (Autoriteit Persoonsgegevens). Both enforce the same rules. Q: Can I use one GDPRWise dossier if I have customers in both countries? A: Yes. Your GDPR obligations are based on what data you process and how, not on which country your customers are in. A single GDPRWise dossier covers your processing activities regardless of whether your customers are Belgian, Dutch, or from elsewhere in the EU. Q: Does GDPRWise account for Dutch-specific rules like the UAVG? A: The platform covers the GDPR, which is the primary regulation. Where the Dutch UAVG (Uitvoeringswet AVG) adds specific national provisions, such as the processing of national ID numbers, the sector dossiers reflect these requirements. ## One regulation, two countries, different enforcement Belgium and the Netherlands share the same privacy regulation. The GDPR, known as AVG (Algemene Verordening Gegevensbescherming) in Dutch, applies identically in both countries. The rules about processing personal data, obtaining consent, maintaining a processing register, and informing data subjects are exactly the same whether you are based in Antwerp or Amsterdam. Where the two countries differ is in enforcement. Belgium has the GBA (Gegevensbeschermingsautoriteit, or APD in French). The Netherlands has the AP (Autoriteit Persoonsgegevens). Both authorities enforce the same GDPR rules, but they have different priorities, different fine levels, and different approaches to enforcement. For small businesses operating in Belgium, the Netherlands, or both, this creates a practical challenge: you need a GDPR tool that understands these nuances without requiring you to become an expert on either authority. ## Why most tools fall short for both markets Many GDPR tools on the market are either too generic or too country-specific: **Generic international tools** provide templates that cover the GDPR broadly but miss the practical details. They do not account for the Belgian social secretariat system, the Dutch BSN (citizen service number) rules, or the differences in how each country handles sector-specific processing. **Country-specific tools** focus on one market only. A Dutch AVG tool may not consider Belgian employment law practices. A Belgian tool may ignore the Dutch UAVG (Uitvoeringswet AVG) and its specific provisions on national identification numbers and healthcare data. GDPRWise bridges this gap by offering a platform that works for both markets, with sector dossiers that account for the specific business practices in each country. ## How GDPRWise covers both markets ### AI-powered scanning works everywhere The GDPRWise website scan is not country-specific. It analyses your website and detects cookies, trackers, third-party scripts, and forms regardless of whether your domain ends in .be, .nl, or anything else. The scan identifies what your website does technically, and that is the same whether you are based in Ghent or Groningen. Within two minutes, you get a complete overview of your website's privacy situation, including which tools process personal data and what risks they present. ### Sector dossiers for both regions The three-layer dossier model is where the cross-border advantage becomes clear: **Layer 1 - Sector foundation**: GDPRWise maintains pre-built dossier foundations for dozens of industries. These foundations cover the common processing activities for each sector. A physiotherapy practice in Belgium processes largely the same types of data as one in the Netherlands, so the foundation applies to both. Where there are differences, such as the way employee data processing is structured around Belgian social secretariats versus Dutch payroll providers, the dossier accounts for these variations through the guided refinement questions. **Layer 2 - AI scan results**: Your specific website findings are layered on top, regardless of your location. The scan detects the actual tools and trackers on your site. **Layer 3 - Guided refinement**: The platform asks targeted business questions to fill in the gaps. These include questions about your country-specific setup, such as whether you use a Belgian social secretariat or a Dutch payroll provider, ensuring the dossier matches your actual situation. ### Full Dutch-language support Both Flemish business owners in Belgium and Dutch business owners in the Netherlands want to work in their own language. GDPRWise offers full Dutch-language support, from the scan interface to the generated documents. Your privacy policy, processing register, and cookie report can all be generated in Dutch. This means your customers, employees, and the supervisory authority all receive documentation in the language they expect. The platform also supports French (relevant for Wallonia and Brussels), German, and English, making it suitable for multilingual Belgian businesses as well. ## Belgian GBA vs. Dutch AP: what you need to know While the GDPR rules are identical, the enforcement landscape differs in a few important ways: ### Fines and enforcement style The Dutch AP has historically focused on large-scale data processing and big technology companies, though it has increasingly turned its attention to smaller organisations. The Belgian GBA has been active across the board, including actions against small businesses and local organisations. Both authorities can impose fines of up to 20 million EUR or 4% of global annual turnover for the most serious violations. In practice, fines for SMEs are much lower, but they can still be painful for a small business. ### National implementation laws Each country has a national law that complements the GDPR: - **Belgium**: the Data Protection Act of 30 July 2018 - **Netherlands**: the UAVG (Uitvoeringswet Algemene Verordening Gegevensbescherming) These laws fill in areas where the GDPR gives member states discretion, such as the age of consent for children, the processing of national identification numbers, and specific provisions for journalism and research. GDPRWise accounts for these differences. When you indicate your country during setup, the sector dossier and generated documents reflect the relevant national provisions. ## Cross-border businesses If you run a business that serves customers in both Belgium and the Netherlands, such as a web shop that ships to both countries or a consultancy with clients on both sides of the border, you do not need separate dossiers. Your GDPR obligations are based on what personal data you process and how you process it, not on the nationality of your data subjects. A single GDPRWise dossier covers all your processing activities. The one consideration is your supervisory authority. Generally, your main establishment determines which authority has primary jurisdiction. If your company is registered in Belgium, the GBA is your lead authority. If you are registered in the Netherlands, the AP takes that role. This does not affect your dossier contents, but it is useful to know in case of complaints or inquiries from a data subject. ## Free for SMEs on both sides of the border Belgian and Dutch SMEs share a common challenge: GDPR compliance sounds expensive. Consultants in both countries charge similar rates, typically 2,000 to 5,000 EUR for a basic dossier. GDPRWise offers two options designed for small business budgets: **Free Scan** gives you a complete dossier at no cost. Full AI scan, sector dossier, guided refinement, all generated documents, and export capabilities. No account or credit card needed. **Peace of Mind** (EUR 29/month, yearly billing) adds continuous monitoring. Periodic rescans, change detection, regulatory update alerts, and priority support. Ideal if you want to stay compliant without having to remember to check. Both options work identically for Belgian and Dutch businesses. There is no country surcharge or separate pricing structure. ## Getting started takes minutes Whether you are a Belgian frituur owner or a Dutch web developer, the process is the same: 1. Enter your website URL and run the free scan 2. Review the results and create your account 3. Answer the guided business questions 4. Review and export your completed dossier The entire process typically takes one to three hours. Your dossier, including processing register, privacy policy, cookie report, employee privacy policy, and action list, is ready to use the same day. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### The Best GDPR Tool for SMEs in Flanders URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/best-gdpr-tool-flanders/ Summary: Flemish SMEs want GDPR documentation in natural Dutch and a tool that knows the Flemish economy. Here is how GDPRWise scores on Dutch-language documentation and the sectors that form the backbone of Flanders. Key takeaways: - Flemish SMEs need GDPR documentation in natural Dutch, not translated from English templates - GDPRWise covers the sectors that carry the Flemish economy: retail, construction, healthcare, hospitality, professional services and manufacturing - The entire experience is natively Dutch, from the scan to the generated documents - A Flemish business owner can complete the full dossier in a single session FAQ: Q: Can I use GDPRWise entirely in Dutch? A: Yes. The entire platform - the scan, the questions, the generated documents - is natively available in Dutch, not as a translation of an English product. Your privacy policy, processing register, and all other documents are generated in natural Dutch, ready to use without translation. Q: Does GDPRWise cover sectors typical for Flanders? A: Yes. GDPRWise maintains sector dossiers for industries common among Flemish SMEs, including retail, construction and trades, healthcare, hospitality, professional services, and manufacturing. Each dossier contains the processing activities, legal bases, and retention periods standard for that sector. Q: How quickly can I complete my GDPR dossier? A: The AI scan takes 2 minutes. The full dossier, including answering the targeted questions and reviewing flagged items, can be completed in a single session of a few hours. Most Flemish business owners finish within one afternoon. ## Dutch-language compliance for Flemish business owners If you run an SME in Flanders, you know the GDPR (in Dutch also called the AVG, the Algemene Verordening Gegevensbescherming). You know you have to comply with it. Maybe you even tried to read the regulation itself and gave up somewhere around article 30. The reality for most Flemish business owners is simple: you need proper documentation, but you do not have the time, the budget, or the legal expertise to draft it yourself. English-language tools feel foreign, generic templates do not fit, and hiring a consultant is hard to justify for a business with 3, 10, or 25 employees. Two things make the biggest difference for a Flemish SME: documentation in natural Dutch, and a tool that genuinely knows your sector. Those are the two points this article focuses on. ## Why native Dutch matters more than it seems Privacy documentation needs to be in a language your customers understand, your employees can read, and your accountant can work with. When your bakery's privacy policy reads like it was written by a London law firm, it does not inspire confidence. GDPRWise is not an English platform with a Dutch translation bolted on top. The Dutch-language experience is native and spans the whole journey, from your first scan to your completed dossier. Your privacy policy, processing register, employee privacy policy, and cookie documentation are all generated in clear, professional Dutch, immediately usable without a translation round. That not only saves time, it also keeps your documents correct: a translated privacy policy easily introduces errors in legal terms that carry a different meaning in Dutch. ## Sector dossiers for the Flemish economy The biggest time difference between tools comes down to whether you start with a blank page or with a dossier that already knows your sector. Based on your detected sector, GDPRWise loads a pre-built dossier with the processing activities, legal bases, and retention periods that are standard for your industry. For Flemish SMEs, it covers the sectors that form the backbone of the regional economy: **Retail and e-commerce** - Customer databases, loyalty cards, online shops, payment processing, delivery services. From a local shop in Ghent to a webshop that serves all of Belgium. **Construction and trades** - Subcontractor management, site access logs, project documentation, company vehicle tracking. The strongly represented Flemish construction sector has specific processing patterns that the dossier understands. **Healthcare and care providers** - Patient records, appointment scheduling, health data, referral letters, electronic prescriptions. Health data is a special category under the GDPR and requires extra safeguards that the sector dossier covers. **Hospitality and food service** - Reservations, customer reviews, staff scheduling, delivery platforms. From a restaurant in Antwerp to a hotel on the coast. **Professional services** - Accountants, lawyers, architects, consultants. Client files, financial data, and professional correspondence, with the correct legal bases and retention periods. **Manufacturing** - Supplier data, production records, quality management systems, logistics. Tailored to the processing typical for production-oriented Flemish businesses. This sector foundation means you start with a dossier that already covers 60 to 80 percent of your situation. You refine and finish it, rather than building everything yourself. The [AI scan](/en/kennisbank/hoe-gdprwise-werkt/how-scan-works) adds your specific technical findings to that, and a short series of targeted questions tunes the whole thing to your business. ## Complete your dossier in one session A practical advantage for the busy Flemish business owner: the whole process fits in a single session. The AI scan takes 2 minutes, the guided refinement usually 1 to 3 hours, depending on the complexity of your business. So you can block an afternoon, sit down with a cup of coffee, and walk away with a [complete GDPR dossier](/en/kennisbank/hoe-gdprwise-werkt/what-is-in-dossier): your processing register, a publication-ready privacy policy, a cookie report, an employee privacy policy, a prioritised action list, and a compliance score. Of course you can save your progress and come back later, but the point is that going from zero to compliant in an afternoon is realistic. Try getting that from a consultant. ## Start free, upgrade affordably GDPRWise is priced for small businesses, not for enterprises. The **Free Scan** gives you the full package at no cost: AI scan, complete dossier, all documents, and your compliance score, no account or credit card, including a 2-week free trial. **Peace of Mind** (EUR 29 per month, billed annually) adds ongoing monitoring: periodic rescans and an alert the moment something changes on your website. Flemish SMEs that want to tick the GDPR box properly without draining their budget or their calendar find in GDPRWise the practical choice: a Dutch-language tool that knows their sector, automates the heavy lifting, and delivers a complete dossier in hours rather than weeks. Still weighing up tools? Then take a look at the [selection framework for the best Belgian GDPR tool](/en/kennisbank/hoe-gdprwise-werkt/best-belgian-gdpr-tool). import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### The Best Tool for Creating Your Privacy Policy URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/best-tool-privacy-policies/ Summary: GDPRWise generates privacy policies based on your actual website scan. Customer-facing and staff policies, hosted option, and continuous monitoring included. Key takeaways: - Your privacy policy is generated from your actual scan results, not a generic template - GDPRWise creates both a customer-facing and a staff privacy policy - The hosted privacy policy option gives you a live URL that's always current - Continuous monitoring flags changes so your policy never becomes outdated FAQ: Q: Is a privacy policy generator as good as a lawyer-drafted policy? A: A generic lawyer-drafted policy can miss specifics about your actual data processing. GDPRWise scans your website and tailors the policy to what you actually do. The result is often more accurate than a template from a lawyer who hasn't reviewed your website. For complex or high-risk situations, you can always have a legal professional review the generated policy. Q: What is the difference between a customer privacy policy and a staff privacy policy? A: A customer-facing privacy policy informs website visitors and customers about how you handle their data. A staff privacy policy informs your employees about how you process their personal data, covering payroll, HR files, CCTV, and similar activities. Both are mandatory under the GDPR, but they cover different data subjects and processing activities. Q: Can I host my privacy policy on my own website instead of using the hosted option? A: Yes. You can export your privacy policy and place it on your own website. The hosted option is a convenience feature: GDPRWise gives you a URL that always shows the latest version of your policy. You can link to it from your website footer, forms, and social media profiles. ## The problem with most privacy policy tools Search for "privacy policy generator" and you'll find dozens of tools. Most of them work the same way: you answer a long questionnaire, check some boxes, and get a generic document that vaguely describes your situation. The result reads like a legal template because that is exactly what it is. These generators don't know what actually happens on your website. They don't know which cookies your site places, which third-party scripts are loaded, or what data your forms collect. You're left guessing, and a privacy policy based on guesses is a liability, not a protection. GDPRWise takes a fundamentally different approach. It starts by scanning your website to detect what you actually process, and then generates a privacy policy that matches reality. ## How GDPRWise creates your privacy policy The process follows the same three-layer model that powers your entire GDPRWise dossier. ### Scan-based detection When you enter your URL, GDPRWise's AI-powered scanner examines your website. It detects: - **Cookies and local storage** - every cookie placed on visitors' browsers, categorised by type and purpose - **Third-party scripts** - Google Analytics, Meta Pixel, HubSpot, Hotjar, and any other external services loading on your pages - **Forms and data collection** - contact forms, newsletter sign-ups, booking forms, checkout pages - **Trackers and pixels** - invisible tracking mechanisms that monitor visitor behaviour Each finding becomes a concrete entry in your privacy policy. If Google Analytics is active, your policy states that you use Google Analytics, explains what data it collects, and references the correct legal basis. Not vague boilerplate - specific facts about your website. ### Sector-specific context Your industry determines many of the processing activities that happen outside your website. A physiotherapy practice processes health data. An e-commerce shop processes payment and shipping data. A recruitment agency processes candidate CVs. GDPRWise pre-fills these sector-specific elements so your privacy policy covers your full range of processing activities, not just what happens online. ### Your answers fill the gaps Some details only you can provide. Do you share data with specific partners? How long do you retain customer records? Do you transfer data outside the EU? GDPRWise asks targeted questions and integrates your answers directly into the policy text. Items marked "Detected" are backed by scan evidence. Items marked "Needs review" require your confirmation. You always know which parts of your policy are verified and which need a closer look. ## Not just for customers: the staff privacy policy Here is where GDPRWise differs from every other privacy policy tool on the market. Most generators only create a customer-facing website privacy policy. But the GDPR also requires you to inform your employees about how you process their personal data. As an employer, you handle sensitive information: payroll details, personnel files, sick leave records, performance evaluations, and potentially CCTV footage or GPS tracking data. Your employees are data subjects, and they have the same right to transparency as your customers. GDPRWise generates a dedicated staff privacy policy alongside your customer-facing one. Through the guided refinement process, you answer questions about your HR practices, and the platform produces a professional employee privacy policy that covers: - Identification and payroll data - HR administration and personnel files - Sick leave and absence registration - Access control and badge systems - CCTV and camera surveillance - GPS tracking of company vehicles - IT monitoring and email policies This staff privacy policy is ready to use as an appendix to your employment contracts. It is a document most SMEs don't have but are legally required to provide. ## The hosted privacy policy Once your privacy policy is generated, you have two options for publishing it. **Export and self-host.** Download the policy as a formatted document and place it on your own website. You have full control over the look and feel. **Use the hosted URL.** GDPRWise provides a hosted version of your privacy policy at a permanent URL. You link to this URL from your website footer, contact forms, social media profiles, and email signatures. When your policy is updated, the hosted version reflects the changes automatically. The hosted option is particularly useful for businesses that list their privacy policy in multiple places: website, Facebook page, Instagram profile, Google Business listing, newsletter footer. Instead of updating the text in five locations, you update it once in GDPRWise and the hosted URL serves the current version everywhere. ## Always up to date, not just at launch A privacy policy is not a "set it and forget it" document. When you add a new marketing tool, switch email providers, or install a chat widget, your policy needs to reflect those changes. Most businesses forget, and their privacy policy quietly becomes inaccurate. With GDPRWise's continuous monitoring (available through the Peace of Mind subscription), your website is rescanned periodically. When the scan detects a new third-party script, an additional cookie, or a changed form, you are notified. The platform shows you exactly what changed and suggests updates to your privacy policy. You review the changes, approve them, and your policy is current again. The hosted version updates immediately. No manual comparison of old and new scan results, no digging through your website to figure out what changed. ## What makes a good privacy policy? Beyond the legal requirements, a good privacy policy is one that people can actually understand. GDPRWise generates policies in clear, readable language, not dense legal paragraphs. Your policy includes: - **Who you are** - your identity as the data controller, with contact details - **What data you collect** - broken down by category, with specific examples - **Why you collect it** - the purpose for each type of processing - **The legal basis** - consent, contract, legitimate interest, or legal obligation, explained in plain terms - **Who receives the data** - named third parties and processors - **How long you keep it** - retention periods per data category - **Your visitors' rights** - access, rectification, erasure, portability, and how to exercise them - **Cookie information** - aligned with your cookie report and consent settings - **How to file a complaint** - with the supervisory authority All of this is structured in a way that both humans and regulators can follow. ## The bottom line A privacy policy should describe what you actually do with personal data. Not what a template assumes you do. GDPRWise scans your website, detects your processing activities, and generates a policy that matches your real situation. It creates both a customer-facing and a staff privacy policy. And it keeps both current through continuous monitoring. That is the difference between a compliance checkbox and a document you can stand behind. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### The Easiest GDPR Platform for Business Owners Without Prior Knowledge URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/easiest-gdpr-platform/ Summary: No legal or technical background? GDPRWise uses AI-powered scanning and plain language to guide you through GDPR compliance in a single session. Key takeaways: - No legal or technical knowledge required - the AI scan does the heavy lifting for you - Everything is written in plain language, not legal jargon - Confidence labels tell you exactly what's verified and what needs your input - Most business owners complete their full dossier in a single session FAQ: Q: Do I need to understand GDPR law to use GDPRWise? A: No. The platform translates legal requirements into everyday business questions. You answer questions about your business, not about the law. GDPRWise handles the legal framework behind the scenes. Q: How long does it take to get my GDPR dossier? A: Most business owners finish in a single session of one to three hours. The AI scan runs in minutes, and the guided refinement phase asks targeted questions that are quick to answer. Q: What if I don't know the answer to a question? A: Confidence labels mark every item as either Detected (verified by the scan) or Needs review (requires your input). You can skip items you're unsure about and return to them later without losing progress. ## GDPR compliance should not require a law degree Most GDPR platforms assume you already know what a "record of processing activities" is, or that you can tell a legitimate interest from a consent obligation. That is a problem when you are a bakery owner, a physiotherapist, or a web designer who simply wants to comply with the rules. GDPRWise was built specifically for business owners who have zero prior knowledge of privacy law. The platform handles the legal complexity for you, so you can focus on running your business. ## How the AI scan removes the guesswork The first step is entering your website URL. Within two minutes, the GDPRWise scanner analyses your site and detects: - **Cookies and storage** - which cookies are placed and whether they are functional, analytical, or tracking - **Third-party scripts** - tools like Google Analytics, Facebook Pixel, or chat widgets that process visitor data - **Forms and data collection** - contact forms, newsletter sign-ups, and booking forms - **Trackers and pixels** - invisible tracking elements you may not even know about The scan also detects your sector automatically. A dental practice gets different default processing activities than an online shop, because the types of personal data you handle are fundamentally different. This means you do not have to figure out which processing activities apply to your business. The platform already knows, and it presents a tailored starting point based on what it found. ## Three layers that build your dossier GDPRWise uses a three-layer model to create your complete GDPR dossier: ### Layer 1: Sector foundation Every industry has common processing activities. A hairdresser keeps appointment books and customer preferences. An accountant handles financial data for clients. A recruitment agency processes CVs and references. GDPRWise has pre-built sector dossiers that cover these common activities. When the scan detects your sector, the platform loads the relevant foundation automatically. You start with a dossier that is already 60 to 70 percent complete, not a blank page. ### Layer 2: AI scan results The website scan adds specifics that are unique to your situation. Maybe you use Mailchimp for newsletters, or your site loads a Google Maps embed on the contact page. These findings are layered on top of the sector foundation, creating a dossier that reflects your actual setup. ### Layer 3: Guided refinement The final layer is where you come in. But instead of being asked legal questions like "What is your legal basis for processing?", the platform asks business questions: - Do you have employees? - Do you use CCTV cameras at your premises? - Do you send marketing emails to customers? These are questions any business owner can answer. GDPRWise translates your answers into the correct legal documentation behind the scenes. ## Confidence labels: know exactly where you stand One of the biggest frustrations with other GDPR tools is uncertainty. You fill in a form and you are never sure if you did it correctly. GDPRWise solves this with confidence labels on every item in your dossier: **Detected** means the platform found this through the scan and is confident it is correct. For example, if the scan detected Google Analytics on your website, the corresponding processing activity is marked as Detected. You do not need to do anything. **Needs review** means the platform suspects something may apply but needs your confirmation. For example, if you selected "healthcare" as your sector, the platform might flag "processing of medical records" as Needs review, because it cannot verify this from a website scan alone. This two-tier system means you spend your time only on items that actually need your attention. Everything else is already handled. ## Plain language throughout Every screen, every question, and every generated document in GDPRWise uses plain language. The platform avoids legal jargon wherever possible, and where a legal term is unavoidable, it includes a short explanation. Your privacy policy is generated in language your customers can actually understand. Your processing register uses clear descriptions instead of abstract legal categories. Even the action recommendations use everyday words. This is not just a design choice. The GDPR itself requires that privacy information is provided in "clear and plain language." GDPRWise takes that principle seriously, both for the documents it generates and for the platform you use to create them. ## Complete in a single session Traditional GDPR compliance projects stretch across weeks or months. You schedule meetings with a consultant, exchange emails, wait for drafts, and review documents you barely understand. With GDPRWise, the typical workflow looks like this: 1. **Run the scan** - 2 minutes 2. **Review the scan results** - 10 to 15 minutes 3. **Answer the guided questions** - 30 to 60 minutes 4. **Review your completed dossier** - 15 to 30 minutes Most business owners finish everything in a single session. Your complete dossier, including the processing register, privacy policy, cookie report, and action list, is ready to use immediately. ## Staff privacy policy included Many business owners do not realise that GDPR compliance includes informing your own employees about how you process their data. This requires a separate privacy policy for staff, covering topics like payroll processing, CCTV, and HR files. GDPRWise is one of the few platforms that includes an [employee privacy policy](/en/kennisbank/hoe-gdprwise-werkt/employee-privacy-policy) as a standard part of the dossier. During the guided refinement, the platform asks about your HR processes and automatically generates the document. No extra cost, no extra effort. ## No technical setup required There is nothing to install, configure, or integrate. GDPRWise is a web-based platform. You enter your website URL and start working on your dossier immediately. The scan runs externally, so it does not affect your website in any way. You do not need to ask your web developer for access or install a plugin. Everything happens through the GDPRWise platform itself. ## Keep it up to date effortlessly GDPR compliance is not a one-time task. Your website changes, you add new tools, you hire staff. With the Peace of Mind subscription, GDPRWise rescans your website periodically, compares results with your existing dossier, and flags any changes. Did a new tracking script appear on your site? The platform will notify you. Did you remove a form? The corresponding processing activity is flagged for review. This means your dossier stays current without you having to remember to check it manually. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Upgrading to a Paid Account: What Do You Get? URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/upgrade-paid-account/ Summary: The free scan gives you the overview. A paid account gives you complete documents, processing agreements, compliance monitoring, and more. Here's exactly what's included. Key takeaways: - The free scan shows your privacy situation; the paid account gives you the tools to fix it - You get complete, downloadable documents: processing register, privacy statement, cookie report, and processing agreements - Compliance monitoring keeps your dossier up to date and alerts you to regulatory changes - No credit card required upfront - payment is by invoice FAQ: Q: What can I do with the free account? A: The free scan gives you a full overview of your website's privacy situation: which cookies, trackers, and scripts are active, a risk assessment, and concrete recommendations. You see exactly where you stand, but generating and downloading documents requires a paid account. Q: Do I need to provide a credit card to start? A: No. You can run the free scan without payment details. If you decide to upgrade, you pay by invoice. No automatic charges, no surprises. Q: Can I cancel monthly? A: Yes, there is no lock-in. You can cancel your subscription at any time. You keep access to your documents until the end of your billing period. Q: Is there a trial period for the paid account? A: The free scan is effectively your trial. You see exactly what GDPRWise can do for you before deciding to upgrade. No surprises. ## The free scan shows you where you stand With the free GDPRWise scan, you get a clear picture of your privacy situation within minutes. You see which cookies and trackers are active on your website, the associated risks, and what needs attention. That overview is valuable, but it's only the beginning. The question is: what do you do with that information? You could figure it all out manually, download templates from the internet, and hope they're legally correct. Or you let GDPRWise handle it for you. ## What you get with a paid account ### Complete, downloadable documents The paid account automatically generates all the documents you need for GDPR compliance: - **Processing register** - a full record of all processing activities, ready to present to the supervisory authority - **Privacy statement** - tailored to your specific situation, not a generic template - **Cookie report** - detailed overview of all cookies with classification and purpose - **Policy documents** - data breach procedure, retention policy, and more All documents can be downloaded as PDF or Excel and used immediately. ### Generate processing agreements For every third party that processes personal data on your behalf, you need a data processing agreement (DPA). GDPRWise generates these automatically based on your third-party dossier. You can send them directly to your processors or register that you've already received a DPA from them. ### Compliance monitoring Your GDPR situation is not static. Your website changes, you start using new tools, new employees join. The paid account keeps track: - **Periodic rescans** - GDPRWise scans your website regularly and alerts you when something has changed - **Compliance score tracking** - follow your progress over time and see which areas need attention - **Dossier management** - your dossiers are automatically updated based on new scans ### Regulatory alerts Privacy legislation keeps evolving. New guidelines, supervisory authority rulings, changes in national law - the paid account keeps you informed. You receive a notification when something changes that is relevant to your situation, with an explanation of what it means and what you may need to adjust. ### Personalised action list Your dashboard shows a prioritised action list based on your specific situation. Not a generic checklist, but concrete steps you can assign to colleagues, complete, and tick off. Including links to the relevant knowledge base articles. ## No surprises GDPRWise works with a straightforward model: - **No credit card upfront** - you start free and decide afterwards - **Payment by invoice** - no automatic charges - **No long-term contract** - you can cancel monthly - **Full access** - all features included, no hidden add-ons You pay for a complete platform that helps you become and stay GDPR-compliant. Not for individual documents or per-feature upgrades. ## From overview to action The free scan gives you the insight. The paid account gives you the means to act on it. Start with the scan, review your results, and decide if you're ready to take the next step. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### What Does GDPR Compliance Cost for a Belgian SME? URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/affordable-gdpr-belgium/ Summary: An honest cost breakdown of GDPR compliance in Belgium: what a consultant charges, the hidden costs of doing it yourself, and how GDPRWise brings the bill down to an SME budget. Key takeaways: - A consultant engagement for a Belgian SME typically costs EUR 2,000 to 5,000, built from 15 to 25 billable hours at EUR 100 to 200 per hour - Doing it yourself looks free but costs dozens of hours of your own time and carries the risk of an incomplete dossier - The biggest hidden cost is maintenance: a dossier goes out of date the moment your website or tooling changes - GDPRWise replaces the billable hours with AI scanning and sector dossiers, putting a complete dossier within reach of any SME budget FAQ: Q: How much does GDPR compliance typically cost for a Belgian SME? A: Privacy consultants in Belgium typically charge between EUR 2,000 and 5,000 for a basic GDPR dossier. Larger or more complex businesses can expect quotes of EUR 10,000 or more. That figure is mostly billable hours: 15 to 25 hours at EUR 100 to 200 per hour. GDPRWise delivers the same compliance output by automating those hours. Q: Are there hidden costs to GDPR compliance? A: Yes, two in particular. The first is your own time in a do-it-yourself approach, which easily runs into dozens of hours. The second is maintenance: a dossier a consultant delivers today is out of date the moment you add a new cookie, tool, or employee. Ongoing consultant advice is billed separately, often as a retainer of EUR 200 to 500 per month. Q: What is the payback period of a paid GDPR tool? A: Do the math: a single consultant engagement of EUR 2,000 equals more than five years of Peace of Mind with GDPRWise (EUR 29 per month). The moment you would need to hire a consultant for an update, the tool has already paid for itself. And the Free Scan delivers a complete dossier at no cost at all. ## The real question: what does compliance cost? Many Belgian SMEs put off GDPR compliance for a simple reason: they do not know what it will cost, and they fear the worst. That is fair, because the figures that circulate vary widely. This article breaks the costs open, shows where the money goes, and helps you make a choice that fits your budget. There are broadly three paths to compliance, each with a very different price tag: hiring a consultant, doing it yourself, or using a tool. We look at all three. ## Path 1: the consultant - where the EUR 2,000 to 5,000 comes from The standard advice is: hire a privacy consultant. The price is not arbitrary, it is built from billable hours. Here is what a typical engagement looks like: | Phase | What the consultant does | Time | |---|---|---| | Intake meeting | Getting to know your business, processes, and IT systems | 2-3 hours | | Data mapping | Identifying every processing activity involving personal data | 4-6 hours | | Legal analysis | Determining legal basis, retention periods, and risk per activity | 3-5 hours | | Document drafting | Writing the processing register, privacy statement, and cookie policy | 4-8 hours | | Review cycle | Going through drafts with you and adjusting them | 2-3 hours | That adds up to 15 to 25 hours. At a rate of EUR 100 to 200 per hour, the arithmetic is simple, and the total lands between EUR 2,000 and 5,000. For more complex businesses with many processing activities, it climbs to EUR 10,000 or more. The quality is usually good, and for complex situations a consultant is the right choice. But for a standard SME with five to fifteen employees, you are mostly paying for time, not for something a good tool cannot also deliver. ## Path 2: doing it yourself - free in euros, expensive in hours The internet is full of free GDPR templates. On paper, this is the cheapest path. In practice, there are two hidden costs. **Your own time.** Building a processing register alone requires you to map every activity where you handle personal data, from customer files and payroll to CCTV footage and newsletter sign-ups. For each of them you determine the legal basis and the retention period. Count on dozens of hours, and that is time that does not go into your business. **The risk of errors.** Without guidance, most business owners give up halfway, or they deliver a dossier with gaps. An incomplete dossier is a risk that only becomes visible when a complaint or an inspection lands, exactly the wrong moment to find out. ## Path 3: a tool - the billable hours automated A GDPR tool like GDPRWise replaces the most expensive parts of the consultant engagement with technology. It is useful to see which phase is taken over by which technology: - **Intake and data mapping** are handled by the [AI website scan](/en/kennisbank/hoe-gdprwise-werkt/how-scan-works). In two minutes it detects your cookies, trackers, forms, and third-party scripts, and identifies your sector. - **The legal analysis** is built into the sector dossiers, which hold the common legal bases and retention periods for each industry. - **The document drafting** is automated: your [complete dossier](/en/kennisbank/hoe-gdprwise-werkt/what-is-in-dossier) is generated based on the scan and your answers. - **The review cycle** is replaced by confidence labels, so you only spend time on the items that need your confirmation. The 15 to 25 billable hours disappear. What remains is a couple of hours of your own time to answer the targeted questions. ## The hidden cost everyone forgets: maintenance The biggest misconception about GDPR costs is that it is a one-off expense. It is not. A dossier is a snapshot. The moment your website changes, you switch to a new CRM, an employee joins, or your marketing agency drops in a new script, your documentation falls behind reality. With a consultant, that means a new assignment or an ongoing retainer of EUR 200 to 500 per month. With a do-it-yourself approach, it means you have to remember to update everything yourself, which in practice rarely happens. This is where a tool earns its money. The GDPRWise Peace of Mind plan (EUR 29 per month, billed annually) periodically rescans your website, compares the results with your existing dossier, and warns you when something changes. Maintenance that costs hundreds of euros a month with a consultant runs automatically here. ## The payback period, laid out Put the figures side by side and the choice becomes arithmetic: | Option | Upfront cost | Ongoing | Maintenance included | |---|---|---|---| | Consultant | EUR 2,000 - 5,000 | EUR 200 - 500/month (retainer) | Only with retainer | | Doing it yourself | EUR 0 (dozens of hours) | Your time | No | | GDPRWise Free Scan | EUR 0 | EUR 0 | No | | GDPRWise Peace of Mind | EUR 0 | EUR 29/month | Yes | A single consultant engagement of EUR 2,000 equals more than five years of Peace of Mind. The moment you would need to call a consultant back for an update, the tool has already paid for itself. ## Affordable does not mean incomplete A lower price raises the question of whether you are giving something up. That is not the case here. The GDPRWise dossier meets the same GDPR requirements as a dossier a consultant builds. The processing register follows the same structure, the privacy statement covers the same mandatory elements. The difference is not in the result, but in how it is produced: technology instead of billable hours. For most Belgian SMEs, from a bakery to an IT consultancy, the GDPR requirements are clearly defined and predictable. That is exactly the kind of business for which an affordable tool is the logical choice. Want to know which tool suits you best first? Then read our [selection framework for the best Belgian GDPR tool](/en/kennisbank/hoe-gdprwise-werkt/best-belgian-gdpr-tool). import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### What If You Don't Know Whether Your Data Is Stored in the EU? URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/data-storage-location/ Summary: The GDPR requires you to document where personal data is stored. But what if you're not sure? GDPRWise helps you find out and record it correctly. Key takeaways: - The GDPR requires you to document whether personal data is stored inside or outside the EU - Most major software vendors publish their storage location in their privacy policy or DPA - If data is processed outside the EU, additional safeguards like Standard Contractual Clauses are needed - GDPRWise helps you record per third party where data is stored FAQ: Q: Am I allowed to use software that stores data outside the EU? A: Yes, but additional conditions apply. The vendor must provide appropriate safeguards such as Standard Contractual Clauses (SCCs) or an adequacy decision. Most major vendors (Google, Microsoft, Mailchimp) already have this in place. GDPRWise helps you verify and document this per party. Q: How do I find the storage location of my software? A: Check the vendor's privacy policy or DPA (data processing agreement). The server region is often explicitly stated there. You can also contact the vendor's support team to ask. Q: What if I really can't find out? A: Document in GDPRWise that the location is unknown and that you've contacted the vendor. It's better to be honest about uncertainty than to make an incorrect assumption. If the vendor can't provide clarity, consider an alternative. ## Why storage location matters The GDPR sets strict requirements for transferring personal data to countries outside the EU. When you use software that stores data on servers in the United States, India, or another non-EU country, additional rules apply. This doesn't mean you can't use those tools. But you need to know where the data is stored and document what safeguards are in place. ## How to find out where your data is stored Most software vendors publish their storage location. Here's where to look: ### 1. The data processing agreement (DPA) If you have a DPA with the vendor, it almost always states in which region data is processed. Major vendors like Google, Microsoft, and Amazon publish their DPA on their website. ### 2. The vendor's privacy policy Under headings like "Data transfers" or "International data transfers," you'll typically find whether data leaves the EU and what safeguards apply. ### 3. Direct contact If you can't find it, email the vendor asking: "Is the personal data we process through your service stored on servers within the EU?" Most vendors are required to give you a clear answer. ## What if data is stored outside the EU? That's fine as long as appropriate safeguards are in place. The most common safeguard is **Standard Contractual Clauses (SCCs)**, a set of standard contract terms approved by the European Commission. Major cloud vendors have already incorporated these into their terms. Additionally, some countries have an **adequacy decision**. The European Commission has determined that these countries provide a comparable level of protection. Transferring data to those countries is permitted without extra safeguards. ## Recording it in GDPRWise In your third-party dossier, you can specify per party: - Whether data is stored inside or outside the EU - In which country the servers are located - Which safeguard applies (SCCs, adequacy decision, or other) GDPRWise warns you if you add a party without a storage location, so you won't forget to fill it in. ## Practical rules of thumb - **European vendors** usually store data in the EU, but verify to be sure - **American vendors** often process data (also) in the US, but typically offer SCCs - **Not sure?** Document your uncertainty and contact the vendor. Honesty in your dossier is always better than an assumption import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### What's in Your GDPRWise Dossier? URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/what-is-in-dossier/ Summary: Your GDPRWise dossier contains everything you need to manage and demonstrate GDPR compliance. From the process definitions, personal data items, and your third parties to your compliance actions & score. Key takeaways: - Customer dossier allows you to manage all business processes that touch on customer data - Staff dossier allows you to manage all business processes that touch on staff data - Third party dossier lists all personal data processes where third parties are involved - Generate your GDPR documents like privacy policy or register from the GDPR documents screen - Check your dashboard for all the must-do actions to reach a base GDPR compliance level FAQ: Q: Can I use the dossier as evidence during an audit by the supervisory authority? A: Yes. The dossier is structured to meet the documentation requirements under the GDPR. You can export the complete dossier or individual components and present them during an audit. Q: Is the dossier automatically updated? A: The dossier is updated whenever you rescan or make changes. GDPRWise also sends reminders when it's time to review your dossier. Q: What if I can't answer all the questions right away? A: No problem. You can fill in your dossier step by step. The compliance score shows your progress and the action list indicates which steps are still open. Q: Can I share the dossier with my accountant or legal adviser? A: Yes. You can export the complete dossier or individual components as PDF or Excel and share them with anyone. ## Everything you need to manage and demonstrate GDPR compliance Your GDPRWise dossier contains everything you need to manage and demonstrate GDPR compliance. From the process definitions, personal data items, and your third parties to your compliance actions & score. ## 1. Customer dossier The customer dossier is where you manage all business processes that touch on customer data. Think of your CRM, email marketing, order processing, customer support, website analytics, and contact forms. For each process, the dossier captures: - What the process does and why (purpose and legal basis) - Which personal data items are involved (names, emails, payment details, etc.) - How long you retain the data - What security measures are in place GDPRWise pre-fills the customer dossier based on your industry sector and scan results. You review, adjust, and enrich it with your specific business context. ## 2. Staff dossier The staff dossier covers all business processes that touch on employee and staff data. Payroll, HR administration, sick leave tracking, performance reviews, access management, CCTV, company devices - these all involve personal data that falls under the GDPR. Many business owners focus only on customer data and forget that staff data is equally regulated. In fact, the data you gather on staff is often far more detailed and sensitive than what you collect on customers - salary information, family composition, pension details, performance reviews, medical absences, and more. The staff dossier ensures you have this covered, including a staff privacy policy that informs your employees about how their data is processed. import TemplateTip from '@/components/TemplateTip.astro'; Learn why a separate staff privacy policy is mandatory and what it must contain. ## 3. Third party dossier The third party dossier lists all personal data processes where third parties are involved. Every external service that processes personal data on your behalf needs to be documented: your hosting provider, email service, CRM platform, payment processor, accountant, cloud storage, analytics tools, and more. For each third party, the dossier tracks: - What data they process and why - Where they are located (EU or outside) - Whether a processing agreement (DPA) is in place - The type of relationship (processor, joint controller, independent controller) This overview is essential for your processing register and helps you identify where processing agreements are missing. Learn how to add, review, and manage the third parties that process personal data on your behalf. ## 4. GDPR documents From the GDPR documents screen you can generate the official documents you need for compliance. These are built from the data in your customer, staff, and third party dossiers, so they accurately reflect your actual situation. Documents you can generate include: - **Privacy policy** - tailored to your processing activities, ready to place on your website - **Processing register** - the formal Article 30 register, exportable as PDF or Excel - **Staff privacy policy** - an employee-facing document explaining how you handle their data - **Cookie policy** - based on the cookies and trackers detected by your scan These are not generic templates. They are generated from your dossier data, so they match what you actually do. How to generate, customise, and publish your privacy policy directly from GDPRWise. ## 5. Dashboard and compliance actions Your dashboard gives you a clear overview of where you stand and what still needs to be done. It shows your compliance score and a prioritised list of must-do actions to reach a base GDPR compliance level. Each action includes: - A description of what needs to happen - The priority level - A link to guidance in the knowledge base Typical actions: conclude a processing agreement with a third party, complete a missing process definition, set retention periods, or review flagged items from your scan. The compliance score is not a legal guarantee, but a practical indicator. It helps you track progress, focus on what matters most, and demonstrate to auditors that you are actively managing your compliance. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Which Processes Should You Document? URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/which-processes-to-document/ Summary: GDPRWise suggests sector-specific processes that you confirm, adjust, or supplement. Learn which processes belong in your customer, employee, and third-party dossiers and how to work through them step by step. Key takeaways: - GDPRWise automatically suggests sector-specific processes - you just confirm or adjust them - Processes are divided across three dossiers: customers, employees, and third parties - Start with the dossier you know best and work your way through step by step - Open your actual tools (CRM, accounting, email) to check which data you really process FAQ: Q: What is the difference between a process description and a purpose? A: A process is a concrete activity involving personal data, such as sending newsletters. The purpose describes why you do it, for example to inform customers about new products. In GDPRWise, you fill in both for each processing activity. Q: How many processes does a typical SME need to document? A: It varies by sector, but most SMEs end up with 10 to 25 processing activities across the three dossiers. GDPRWise suggests the most common processes for your sector, so you don't have to figure out what should be on the list. Q: Can I add processes later? A: Yes, you can add, adjust, or remove processes at any time. Your dossiers are living documents that grow with your business. ## You don't have to figure out what to document on your own The GDPR requires you to record which personal data you process and why. That sounds like a huge task, but it's manageable. GDPRWise does the heavy lifting: based on your sector and business type, the platform automatically suggests a list of relevant processing activities. You just confirm what you actually do, adjust where needed, and add any processes that are missing. ## Three dossiers, three perspectives GDPRWise divides your processing activities across three dossiers. Each dossier looks at your data processing from a different angle: ### Customer dossier Everything related to personal data of your customers and prospects: - **Quotes and invoices** - names, addresses, VAT numbers, payment details - **CRM and customer management** - contact details, communication history, notes - **Newsletters and marketing** - email addresses, preferences, open and click behaviour - **Customer service** - tickets, complaints, chat conversations - **Website and analytics** - IP addresses, cookie data, form submissions ### Employee dossier Data about your employees, applicants, and any freelancers: - **Payroll** - bank details, payslips, tax information - **HR management** - employment contracts, evaluations, sick leave - **Recruitment** - CVs, cover letters, assessment results (see the [recruitment GDPR checklist](/en/kennisbank/hr/recruitment-gdpr-checklist)) - **Access management** - login credentials, badges, time registration - **Internal communication** - email, internal messages, team chats ### Third-party dossier All parties outside your business with whom you share data: - **Accountant** - financial data of customers and employees - **Software vendors** - CRM, email tool, cloud storage, analytics - **External service providers** - lawyer, insurer, occupational health service - **Social media and advertising** - data shared via pixels and integrations ## How does it work in practice? When you open a dossier in GDPRWise, you immediately see a list of suggested processes typical for your sector. A hospitality business gets different suggestions than an accounting firm or an online shop. For each process, you fill in: - Which data you process - Why you do it (the purpose) - The legal basis - How long you retain the data GDPRWise helps you at every step with example answers and explanations. No legal knowledge required. ## Practical tips to get started **Start with what you know.** Most business owners begin with the customer dossier, because they know it best. Complete that dossier before moving on to the next. **Open your actual tools.** Log in to your CRM, accounting software, and email tool. Check which data is actually stored there. That gives you a much better picture than trying to recall everything from memory. **Don't try to do everything at once.** You can save a dossier and come back later. Plan two or three short sessions instead of one long afternoon. After the first session, you'll have the rhythm and it gets faster. **Not sure if a process belongs?** Include it. It's better to document one process too many than one too few. You can always remove it later. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Which Tool Gets GDPR Done Quickly and Affordably? URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/gdpr-quickly-cheaply/ Summary: Need GDPR compliance fast and without breaking the bank? GDPRWise delivers a complete dossier in hours, at a fraction of consultant fees. Key takeaways: - The AI scan analyses your website in 2 minutes, detecting cookies, trackers, scripts, and forms automatically - The three-layer dossier model means you refine rather than build from scratch, cutting hours of manual work - The Free Scan delivers a complete dossier at no cost, while Peace of Mind adds continuous monitoring - A complete GDPR dossier costs a fraction of the 2,000-5,000 EUR that consultants typically charge FAQ: Q: How fast can I get my GDPR dossier with GDPRWise? A: The AI scan takes 2 minutes. The full dossier, including answering targeted questions and reviewing flagged items, typically takes a few hours. Most business owners complete it in a single session. Q: Do I need a subscription to use GDPRWise? A: No. The Free Scan gives you a complete dossier at no cost, with no account or credit card needed. Peace of Mind (EUR 29/month, yearly billing) is a subscription that adds continuous monitoring, rescans, and change detection. There is no obligation to subscribe. Q: Is a cheap GDPR tool actually good enough? A: Affordable does not mean low quality. GDPRWise uses AI scanning and sector-specific dossiers maintained by privacy experts. The output - processing register, privacy policy, cookie report - meets the same standards that a consultant would deliver. ## The two problems with GDPR compliance Ask any SME owner about GDPR and you will hear the same two complaints: it takes too long, and it costs too much. Both are valid. Traditional compliance routes, whether through a consultant or a DIY approach, are slow and expensive. A privacy consultant charges 2,000 to 5,000 EUR for an initial assessment, and the project typically stretches over several weeks of meetings, document reviews, and email exchanges. Going the DIY route means spending days reading legal texts, downloading template after template, and still not being sure you covered everything. The question is not whether you need GDPR compliance. That is not optional. The question is: which tool gets you there quickly and affordably, without cutting corners on quality? ## Speed: from scan to dossier in hours GDPRWise is built around a single principle - minimise the time between "I need to get this done" and "it's done." Here is what that looks like in practice. ### 2-minute AI scan You enter your website URL and the [AI scanner](/en/kennisbank/hoe-gdprwise-werkt/how-scan-works) does its work. Within 2 minutes, you receive a complete overview of: - Every cookie your website places, categorised by type and purpose - All third-party scripts loading in the background (analytics, marketing, chat widgets, payment providers) - Forms collecting personal data, from contact forms to checkout pages - Tracking pixels and invisible data collection points The scan also detects your business sector, which forms the starting point for your dossier. No questionnaires, no manual input, no waiting. Enter the URL, click start, get results. ### Three-layer dossier: less manual work This is where most of the time savings come from. Instead of building your GDPR documentation from scratch, GDPRWise uses a three-layer model: **Layer 1 - Sector foundation**: Based on your detected sector, the platform loads a pre-built dossier containing the processing activities, legal bases, and retention periods standard for your industry. A dental practice gets different defaults than a web agency or a plumbing company. This foundation already covers 60-80% of what you need. **Layer 2 - AI scan results**: Your scan findings are layered on top of the sector foundation. The cookies, trackers, and scripts detected on your actual website are mapped to the relevant sections of your dossier automatically. No manual entry needed for anything the scanner found. **Layer 3 - Guided refinement**: The platform asks you targeted questions about the remaining gaps. Do you process employee data? Do you share data with partners abroad? Do you use CCTV? These questions fill in the details that neither the sector dossier nor the scan can determine automatically. Every finding and every dossier entry carries a confidence label. "Detected" means the system confirmed it with high certainty. "Needs review" means it requires your input. You spend your time only on items that genuinely need human judgement, not on data entry the AI already handled. The result: a [complete dossier](/en/kennisbank/hoe-gdprwise-werkt/what-is-in-dossier) with processing register, privacy policy, cookie report, employee privacy policy, action list, and compliance score. Produced in hours, not weeks. ### Complete in one session Most GDPRWise users complete their entire dossier in a single session. Block an afternoon, work through the questions, review the flagged items, and you walk away with everything documented. Of course, you can pause and return at any time, but the process is designed to be completable in one sitting. Compare that to a consultant engagement: introductory call, questionnaire, follow-up meeting, draft review, another round of comments, final delivery. Typically 3 to 6 weeks before you have your documents. ## Cost: a fraction of consultant fees Let's talk numbers. The market for GDPR compliance services breaks down roughly like this: **Privacy consultants**: 2,000 to 5,000 EUR for an initial assessment and documentation package. Ongoing retainer agreements run 200 to 500 EUR per month. Updates after changes to your website or business cost extra. **Law firms**: even more expensive. Most SMEs cannot justify these fees for privacy compliance work. **DIY with free templates**: technically free, but the hidden cost is your time. Expect to spend days researching, downloading templates from various sources, filling them in, and still wondering if you missed something. The result is often incomplete or outdated. **GDPRWise Free Scan**: completely free. Full AI scan, complete three-layer dossier, all documents generated, compliance score included. No account, no credit card, no hidden costs. You keep everything. **GDPRWise Peace of Mind** (EUR 29/month, yearly billing): a subscription that adds continuous monitoring. Periodic rescans compare your current website to the previous state and flag changes. New cookie appeared? Plugin added a tracker? You get notified. Your dossier stays current without you having to remember to check. The Free Scan is ideal if you want to get compliant and your website does not change frequently. Peace of Mind makes sense if your website evolves regularly or if you simply want the peace of mind (hence the name) that comes from knowing someone is watching. ## Quality: affordable does not mean low quality A common concern: if a tool is cheap and fast, is it actually good enough? Will a supervisory authority accept the documentation? The answer is yes, and here is why. **Sector dossiers are maintained by privacy experts**. The foundation of your dossier is not generated by AI alone. The sector-specific content, including processing activities, legal bases, and retention periods, is curated and maintained by professionals. The AI handles detection and assembly; the expertise is baked into the structure. **The output matches what consultants deliver**. Your processing register, privacy policy, cookie report, and employee privacy policy contain the same elements and meet the same standards that a consultant's deliverables would. The difference is the delivery method, not the quality. **Confidence labels keep you honest**. Items the AI is certain about are marked "Detected." Items that need your attention are marked "Needs review." You are never left guessing whether something was properly verified. **The compliance score shows gaps**. Your [dossier includes a compliance score](/en/kennisbank/hoe-gdprwise-werkt/what-is-in-dossier) that highlights exactly where you stand and what still needs work. No false sense of completeness. ## The practical choice GDPR compliance does not have to be a months-long project or a four-figure expense. With GDPRWise, the timeline is hours and the cost is a fraction of the alternatives. The AI scan handles the technical detection, the sector dossier provides the expert foundation, and the guided refinement fills in your specifics. You get the same documentation a consultant would produce, at a price that makes sense for a small business, and fast enough that you can knock it out in an afternoon. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Why GDPRWise Is the Easiest Way to Create Your Processing Register URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/records-of-processing-ropa/ Summary: GDPRWise generates your record of processing activities automatically using a three-layer model: sector foundation, AI scan, and guided refinement. Key takeaways: - The three-layer model builds your register from sector data, scan results, and your targeted answers - Confidence labels show which entries are verified and which still need your review - Export your register as PDF or Excel, ready for auditors or the supervisory authority - Continuous monitoring detects changes and flags updates to keep your register current FAQ: Q: Is a processing register mandatory for my business? A: Under the GDPR, a record of processing activities is mandatory for organisations with 250+ employees. However, smaller organisations must also keep one if they regularly process personal data, process sensitive data, or if the processing could pose a risk. In practice, this applies to nearly every SME that has a website, customers, or employees. Q: What is the difference between the auto-generated ROPA and a manual spreadsheet? A: A manual spreadsheet requires you to know the GDPR requirements, identify all your processing activities, and fill in every field correctly. GDPRWise does the heavy lifting: it detects activities via your scan, pre-fills sector-specific entries, and uses confidence labels to show what's certain and what needs your input. The result is more complete and takes a fraction of the time. Q: Can I add processing activities that the scan doesn't detect? A: Yes. The guided refinement step asks about offline and internal processing, such as HR administration, paper files, or partner data sharing. You can also manually add activities at any time. The register is always editable. ## The processing register problem The record of processing activities, often called the ROPA, is one of the GDPR's most fundamental requirements. The supervisory authority can request it at any time, and you are expected to have it ready. Not "soon," not "we're working on it" - ready. For most SMEs, this is where GDPR compliance stalls. Creating a processing register from scratch means you need to identify every activity that involves personal data, determine the legal basis for each, list the data categories, define retention periods, and document security measures. Even if you know what the GDPR requires, translating that into a complete register is tedious and error-prone. That is exactly why GDPRWise built its three-layer model. Instead of starting from a blank spreadsheet, you start with a register that is already 80% complete. ## How the three-layer model works GDPRWise generates your processing register through three complementary layers. Each layer adds detail and accuracy. ### Layer 1: Sector foundation Every industry has common processing activities. A dental practice processes patient records and appointment data. An online retailer processes orders, payment details, and shipping addresses. An accountancy firm processes client financial records. GDPRWise maintains pre-built sector foundations for dozens of industries. When you select your sector, the platform pre-fills the processing activities that are standard for your type of business. Each activity comes with the purpose, legal basis, data categories, typical retention periods, and common recipients already filled in. This is not guesswork. These foundations are built from regulatory guidance, sector-specific codes of conduct, and practical experience with thousands of businesses. ### Layer 2: AI scan results When you scan your website, GDPRWise detects the actual tools, scripts, and data collection points active on your site. Google Analytics? That is a processing activity. A contact form collecting names and email addresses? Another one. A newsletter sign-up via Mailchimp? Added to the register. The AI scan translates each finding into a concrete register entry with the relevant details filled in. You don't have to figure out that "Google Analytics loads a _ga cookie" means "you process IP addresses and browsing behaviour of website visitors for the purpose of web analytics, with consent as the legal basis." GDPRWise does that translation for you. ### Layer 3: Guided refinement Your website tells part of the story, but not the full picture. You probably also process personal data offline or through internal systems: employee records in your HR software, customer files in your CRM, invoices in your accounting system. GDPRWise asks targeted questions to identify these additional activities. The questions are specific to your sector and the findings from your scan. A restaurant gets questions about reservation systems and CCTV. A consultancy firm gets questions about client files and project data. You are not asked about things that don't apply to you. Your answers are translated into register entries, completing the picture. ## Confidence labels: know what's verified One of the biggest frustrations with auto-generated documents is uncertainty. "Is this correct? Can I trust it? Do I need to check everything?" GDPRWise addresses this with confidence labels on every entry in your register: **Detected** - This processing activity was identified by the scan with high certainty. The tool, data type, and purpose are confirmed. You can trust this entry without further action. **Needs review** - This entry is based on your sector foundation or your answers, but requires verification. Perhaps the retention period is a default that may not match your specific policy, or the recipients list may need updating. These labels give you clarity. You know exactly where to spend your time and where the register is already solid. Instead of reviewing hundreds of fields, you focus only on the items that need your attention. ## What your register contains Every processing activity in your register includes the fields required under Article 30 of the GDPR: - **Purpose of processing** - why you process this data (e.g., "managing customer orders") - **Legal basis** - on what ground the processing is permitted (e.g., contract performance, legitimate interest, consent) - **Categories of personal data** - what data is involved (e.g., name, email, payment details) - **Categories of data subjects** - whose data it is (e.g., customers, employees, website visitors) - **Recipients** - who receives the data (e.g., payment processor, email marketing platform, accountant) - **Retention periods** - how long you keep the data - **Security measures** - how the data is protected - **Transfers to third countries** - whether data leaves the EU/EEA GDPRWise fills in as much as possible automatically. Where the platform is uncertain, it provides suggestions with explanations so you can make an informed choice. ## Export in professional formats Your register needs to be shareable. The supervisory authority may request it. Your accountant might need it. An auditor could ask for it during a certification process. GDPRWise lets you export your register in two formats: - **PDF** - A professionally formatted document, structured and clearly laid out. Ready to present to an inspector or include in your compliance documentation. - **Excel** - An editable spreadsheet, useful for internal collaboration, further analysis, or integration with other management systems. Both exports always reflect the latest version of your register, including all customizations you've made. ## Keeping it current with continuous monitoring A processing register is not a one-time document. When you add a new tool to your website, switch payment providers, or start a new marketing campaign, your register needs updating. With the Peace of Mind subscription, GDPRWise rescans your website periodically and compares the results with your existing register. New processing activities show up as suggestions. Discontinued activities are flagged for removal. Changes to existing tools or scripts are highlighted. You receive a clear overview of what changed and what needs your attention. No need to remember to review your register manually. No risk of it becoming outdated without you noticing. ## Why this matters for your business The processing register is not just a compliance checkbox. It is the document that proves you understand your own data flows. When a customer asks what data you have about them, the register tells you where to look. When you evaluate a new tool, the register helps you assess the privacy impact. When something goes wrong, the register shows the supervisory authority that you had your house in order. Creating that register should not take weeks of manual work. With GDPRWise's three-layer model, confidence labels, and continuous monitoring, you get a complete, accurate, and maintainable register in a fraction of the time. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Your Dossiers Are Complete - What's Next? URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/dossiers-completed-what-next/ Summary: You've worked through your customer, employee, and third-party dossiers on GDPRWise. Congratulations, you're ahead of 90% of SME owners. This article explains what steps to take next to finalize your compliance. Key takeaways: - Completing your dossiers is the hardest part; what remains are concrete, manageable actions - Your dashboard shows exactly which steps are still needed, sorted by priority - You don't have to do everything at once - spread the actions over weeks or months - Each action includes explanations and links to relevant knowledge base articles FAQ: Q: How long does it take to complete the actions after filling in the dossiers? A: It depends on your situation, but most SME owners can complete the key actions within 2-4 weeks if they spend a few hours per week on it. You don't have to do everything at once. Q: What if I don't know how to carry out a specific action? A: Each action on your dashboard includes an explanation and a link to the relevant knowledge base article. For more complex tasks (like a DPIA), you can follow the step-by-step guide or contact our support team. Q: Do I need to update the dossiers periodically? A: Yes. GDPRWise sends you reminders when it's time to review your dossiers, typically annually or when relevant regulatory changes occur. ## You've already done the hardest part Working through your customer, employee, and third-party dossiers may have felt like a big task. But know this: **you're now ahead of 90% of SME owners in Belgium and the Netherlands.** Most businesses have no idea what personal data they process, let alone have it documented. What you now have: - An overview of all personal data you process - The purposes and legal bases per processing activity - A picture of which third parties have access to the data - The foundation for your record of processing activities That's significant. But a few more steps are needed to complete your compliance. ## Your dashboard shows exactly what to do next After completing your dossiers, GDPRWise automatically generates a **personalized action list** on your dashboard. These aren't generic recommendations - they're concrete steps based on your specific situation. Each action has: - A **priority label** (high, medium, low) so you know where to start - A **brief explanation** of why this step is needed - A **link to the knowledge base** with full details and templates - The option to **assign the action** to a colleague or team member Typical actions you may encounter: - **Check processing agreements** - have you signed DPAs with all processors you've listed? - **Update your privacy policy** - does your privacy policy still match the processing activities you've documented? - **Set retention periods** - each processing activity needs a defined retention period - **Document security measures** - what technical and organizational measures have you taken? - **Conduct a cookie audit** - if your website places cookies, you need to map them ## You don't have to do everything at once Compliance isn't an exam you must pass in one go. It's an ongoing process. And the good news: the most urgent steps are often the quickest. **Week 1-2: the basics** - Check if your processing agreements are in order (do you have a DPA with your accountant, email tool, cloud storage?) - Update your privacy policy **Week 3-4: security and procedures** - Document your security measures - Draft a procedure for handling data breaches - Set up a register for data subject requests **Month 2+: the details** - Set retention periods for all processing activities - Conduct a cookie audit - Train your employees on the basics ## Each action includes guidance You don't need to be a privacy expert to complete the actions. Each step links to the relevant knowledge base article with: - A clear explanation in plain language - Practical real-world examples - Downloadable templates where needed - Common mistakes to avoid ## What happens next? GDPRWise continues to support you, even after completing your actions: - **Periodic reminders** - you'll receive a notification when it's time to review your dossiers - **Regulatory changes** - if there are relevant changes to the GDPR or national legislation, you'll get an update - **New processing activities** - when you start using a new tool or launch a new process, you can easily add it to your dossiers - **Audit trail** - you automatically track when you completed each action, useful during an inspection Most importantly: you're not on your own. Have a question about a specific action? Our support team is happy to help. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Your Third-Party Dossier: When External Services Process Personal Data URL: https://gdprwise.eu/en/kennisbank/hoe-gdprwise-werkt/third-party-dossier/ Summary: Most of the time you are just using a service, but the sharing of personal data is a side effect. Your third-party dossier maps all external services where third parties are involved in personal data processing. Key takeaways: - Most SMEs share personal data with 10 to 30 external parties - often more than they realise - Think in four categories to check completeness: professional services, online tools, social media, and hosting - The platform generates data processing agreements (DPAs) you can send directly to your processors - You don't have to map all third parties at once - work category by category FAQ: Q: What is a data processing agreement and do I need one? A: A data processing agreement (DPA) is a mandatory contract between you and every party that processes personal data on your behalf. Think of your accountant, your CRM provider, or your email tool. GDPRWise generates these agreements automatically. Q: How do I know which parties process personal data? A: GDPRWise helps you find out. The website scan automatically detects external tools and scripts. The platform also asks targeted questions about your business operations, so parties like your accountant, occupational health service, or cloud storage provider are included. Q: What if a third party refuses to sign a processing agreement? A: Most major software vendors already have a standard DPA available. Smaller parties may be less familiar with the requirement. GDPRWise generates a professional agreement you can share, making it easy for both sides. ## You share more data than you think Ask yourself: how many external parties have access to personal data from your customers, employees, or website visitors? Most business owners guess three or four. In reality, the average SME shares data with 10 to 30 parties. Your accountant sees customer details. Your email tool processes email addresses. Your CRM stores contact history. Your website sends data to Google Analytics. Your hosting provider has access to server logs. And that's before considering your occupational health service, insurer, or invoicing tool. Under the GDPR, you are responsible for what all those parties do with the data. That starts with knowing who they are. ## The scan gets you started The GDPRWise scan automatically discovers third parties that have an integration with your website. CRM tools, social media integrations, form providers, advertising platforms, analytics services, chat widgets - if they connect to your site, the scan picks them up and adds them to your third-party dossier. This gives you a solid starting point. But not all third parties are connected to your website. Your accountant, insurer, or occupational health service won't show up in a website scan. To help you find those, think in four categories and check each one for completeness. ## Four categories to check for completeness ### 1. Professional service providers Parties you hire for specific tasks that involve personal data: - **Accountant** - sees financial records, payslips, VAT numbers - **Lawyer or legal adviser** - receives case files in disputes - **Occupational health service** - processes employee health data - **Insurer** - receives personnel and business data ### 2. Online tools and software The digital tools you use daily that store or process data: - **CRM system** - customer data, contact history, notes - **Email tool** - email addresses, open and click behaviour, lists - **Accounting software** - invoice data, customer and supplier details - **Project management** - task descriptions, team communication - **Cloud storage** - documents, files, backups ### 3. Social media and advertising Platforms where you share data, often without realising it: - **Facebook and Instagram** - pixels, custom audiences, lead forms - **LinkedIn** - company page analytics, ad targeting - **Google Ads** - conversion tracking, remarketing, keyword data - **TikTok and YouTube** - pixels, analytics, ad campaigns ### 4. Hosting and infrastructure The technical foundation your business runs on: - **Web hosting provider** - server logs, IP addresses, email traffic - **IT administrator** - access to systems and data ## GDPRWise generates your processing agreements For every third party that processes personal data on your behalf, you need a data processing agreement (DPA). This is a legal requirement. GDPRWise makes it simple: the platform automatically generates a professional DPA you can send directly to the party in question. Each generated agreement covers all mandatory elements: - Which data is processed - The purpose of the processing - The security measures expected - What happens when the relationship ends Many major software vendors already have their own DPA. GDPRWise also helps you request and register those in your dossier. ## Build your dossier step by step You don't need to map all third parties at once. Work category by category: 1. **Start with your online tools** - check your email tool, CRM, and accounting software to note which parties they are 2. **Add your professional service providers** - accountant, lawyer, occupational health service 3. **Check your website** - GDPRWise automatically detects many external scripts and tools 4. **Don't forget hosting** - your web host and IT administrator almost always process data For each party, record which data they process, why, and whether you already have a DPA. GDPRWise tracks which agreements are still missing and sends you reminders. It's not complicated and it doesn't have to be done all at once. The most important thing is to start. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ## HR & Recruitment ### Can AI Automatically Reject a Job Applicant? URL: https://gdprwise.eu/en/kennisbank/hr/ai-automatic-rejection/ Summary: Article 22 GDPR is a prohibition in principle, not a right candidates have to invoke. What that means before you switch on automated rejection. Key takeaways: - Article 22 is a prohibition in principle: you need an exception before you deploy, not after a candidate complains - A human who clicks confirm without real authority does not take the decision outside Article 22 - An AI score that in practice determines the outcome can be the automated decision, even with a human at the end - Recruitment AI is high-risk under the EU AI Act, with those obligations applying from 2 December 2027 FAQ: Q: When is a rejection decision solely automated? A: When no meaningful human involvement exists. If software scores every applicant and rejects everyone below a threshold without anyone reviewing those candidates, the decision is automated. So is a decision where a reviewer clicks confirm without examining the application, without the information needed to judge it, or without real authority to change the outcome. Q: Can automated rejection ever be lawful? A: Only under one of the three exceptions in Article 22(2): necessity for entering into a contract, authorisation in Union or Member State law, or the candidate's explicit consent. In recruitment none of the three is easy to establish, and all of them require the safeguards in Article 22(3). Our practical advice to employers is to keep a real human decision in the process instead. Q: Does adding a human to the process solve the problem? A: Not by itself. Following the CJEU's SCHUFA judgment, where an automated score effectively determines the outcome and the human adds no genuine assessment, the processing stays within Article 22. The test is whether the human has the information, the authority and the time to reach a different conclusion. Q: What must candidates be told? A: Where Article 22 applies, Articles 13(2)(f) and 14(2)(g) require you to tell candidates about the automated decision-making at the point of collection, including meaningful information about the logic involved and the significance and envisaged consequences. Article 15(1)(h) repeats this on an access request. A generic statement that technology may be used in recruitment is not enough. Q: How do I check for discriminatory outcomes? A: Test whether the criteria are relevant to the job and whether the system produces unfair outcomes for particular groups. Historical recruitment data reflects historical bias, and a model trained on that data reproduces those patterns. GDPR compliance does not replace employment equality law. An employer receives 1,000 applications. Software scores each CV and automatically rejects everyone below a certain threshold. Efficient? Certainly. Lawful? Almost never, without work you have to do first. ## Article 22 is a prohibition, not a complaint procedure This is the point employers most often get wrong. Article 22(1) GDPR is frequently read as a right: the candidate may object to a fully automated decision, and until they do, the employer can proceed. That reading is wrong. In its judgment in **SCHUFA (C-634/21, 7 December 2023)**, the Court of Justice held that Article 22(1) lays down a **prohibition in principle** on decisions based solely on automated processing that produce legal effects or similarly significantly affect a person. The individual does not have to invoke anything for the prohibition to apply. For an employer, the practical consequence is concrete: you cannot switch on automated rejection and wait to see whether a candidate objects. You need to establish, before deployment, that one of the exceptions in Article 22(2) applies and that the safeguards are in place. Rejection for a job clearly counts as significantly affecting the person, so there is no useful argument to be had about the threshold. The [rights candidates have around automated decisions](/en/kennisbank/rechten-en-verzoeken/automated-decision-making-rights) sit on top of that prohibition; they do not replace it. ## What does "solely automated" mean? The question is whether meaningful human involvement exists. If software gives every applicant a score and rejects everyone below 70% with nobody reviewing them, the decision is automated. That case is easy. The harder case is the one most recruitment tools actually create: the system produces a ranking or a score, and an HR employee makes the formal decision. SCHUFA matters here too. The Court held that producing the score can itself be the decision covered by Article 22 where the party using it draws strongly on that score to determine the outcome. Applied to recruitment: if the AI ranking effectively decides who is invited and the human contributes no genuine assessment, inserting that human does not take the processing outside Article 22. Ask three questions about your reviewer: - Do they see the underlying application, or only the score? - Do they have the authority to reach a different conclusion? - Do they have the time to do so across the volume of applications you send them? If the honest answer to any of these is no, treat the process as solely automated. ## When can it be lawful? Article 22(2) provides three exceptions, and only three: - **Necessary for entering into or performing a contract** between the candidate and the employer. Necessity is a strict test; that you receive a high volume of applications and would prefer to filter them cheaply is a business convenience, not a necessity. - **Authorised by Union or Member State law**, which must lay down suitable safeguards. This varies by country and is rare in recruitment. - **The candidate's explicit consent.** Consent in an employment or recruitment relationship is difficult to make freely given, because the candidate is not in a position to refuse without cost. Where you do rely on the first or third exception, Article 22(3) requires safeguards: at minimum the right to obtain human intervention, to express a point of view and to contest the decision. If the processing involves special category data, Article 22(4) restricts it further. Our practical position for employers: do not build a recruitment process that depends on establishing an Article 22 exception. Build one where a person genuinely makes the decision, and use the tooling to prepare that decision rather than to make it. ## Candidates need to be told Where Article 22 applies, transparency is not optional and not generic. Articles 13(2)(f) and 14(2)(g) require you to tell candidates that automated decision-making takes place, and to provide meaningful information about the logic involved and the significance and envisaged consequences of the processing. Article 15(1)(h) requires the same information again if the candidate makes an access request. "Technology may be used in our recruitment process" does not meet that standard. Explain what the system assesses, what role its output plays and how a candidate can ask for a human to look again. Where this belongs is set out in [what a candidate privacy notice should contain](/en/kennisbank/hr/candidate-privacy-notice). ## What does the AI Act add? The EU AI Act classifies AI systems used to filter applications or evaluate candidates as high-risk under Annex III. High-risk systems carry a substantial framework: risk management, data governance, documentation, logging, transparency, human oversight, accuracy, robustness and cybersecurity, with obligations depending on whether you are a provider or a deployer. Regulation (EU) 2026/1744 deferred the application date for these standalone high-risk systems from 2 August 2026 to 2 December 2027. That moves your AI Act deadline. It changes nothing about your GDPR position: Article 22 applies today. How the two frameworks sit together is covered in [GDPR and the AI Act in recruitment](/en/kennisbank/hr/gdpr-ai-act-recruitment). ## Watch for discriminatory outcomes A system can look neutral and still disadvantage particular groups. Historical recruitment data reflects historical bias, and a model trained on that data reproduces those patterns. Test whether your criteria are genuinely relevant to the job and whether the system produces unfair outcomes. GDPR compliance does not replace employment equality law. A tool can be documented, transparent and lawful under Article 22 and still expose you to a discrimination claim. ## Human oversight has to be real A reviewer who adds something to the process: - Understands what the system does and what it does not measure - Has access to the underlying application, not just the output - Can question and override the result - Has the time and the authority to make an independent assessment - Is not measured on how fast they clear the queue "Computer says no" is not oversight. ## Treat automated rejection as high-risk governance Automated evaluation of candidates falls squarely within Article 35(3)(a), so a [Data Protection Impact Assessment](/en/kennisbank/verplichtingen/dpia-guide) is the starting point rather than an afterthought. Involve privacy, HR, legal, security and AI governance before deployment, not after the first complaint. GDPRWise helps organisations document processing activities and assess privacy risks, providing the GDPR foundation needed before higher-risk recruitment technologies are introduced. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Can You Check a Candidate's LinkedIn Profile? URL: https://gdprwise.eu/en/kennisbank/hr/checking-candidate-linkedin/ Summary: A public LinkedIn profile is still personal data. Checking one during recruitment is often defensible, but only when the information you use is genuinely relevant to the vacancy. Key takeaways: - Public LinkedIn information remains personal data - Reviewing professional information may be justifiable when it is relevant to the vacancy - Do not collect more information than you need - Be transparent about obtaining candidate information from external sources where required FAQ: Q: If a LinkedIn profile is public, can I use it however I like? A: No. Information published online is not GDPR-free. If you view, record, compare or otherwise use identifiable information from a candidate's profile as part of recruitment, you are processing personal data and you still need a purpose, a legal basis and appropriate transparency. Q: Is checking LinkedIn different from checking Facebook or Instagram? A: Potentially. A professional networking profile is created specifically to present professional experience, skills and career information, so a candidate may be more likely to expect a potential employer to look at it than at their holiday photographs. That expectation is not unlimited, and it does not extend to their private life. Q: The CV and the LinkedIn profile do not match. What should I do? A: Do not automatically assume dishonesty. Online profiles can be outdated, incomplete or inaccurate. If the discrepancy matters to the decision, give the candidate an opportunity to explain it. Q: Can I take screenshots of a candidate's profile? A: Saving or copying information creates additional processing, so ask whether you really need it. If a hiring manager only needs to verify a particular professional fact, storing a complete copy of the profile may be unnecessary. LinkedIn is designed for professional networking, so checking a candidate's profile may feel like a natural part of recruitment. But a public profile is still personal data, and the GDPR still applies. The key question is not simply whether you *can see* the information, but whether you have a legitimate reason to use it in your recruitment decision. ## Public does not mean GDPR-free A common misconception is that information published online can be used for any purpose. That is not how the GDPR works. If you view, record, compare or otherwise use identifiable information from a candidate's LinkedIn profile as part of recruitment, you are processing personal data. You therefore still need a purpose, [legal basis](/en/kennisbank/verplichtingen/gdpr-legal-bases) and appropriate transparency. ## Is LinkedIn different from private social media? Potentially. A professional networking profile is created specifically to present professional experience, skills and career information. A candidate may therefore be more likely to expect a potential employer to review their LinkedIn profile than [their holiday photographs on Instagram or private posts on Facebook](/en/kennisbank/hr/social-media-screening-applicants). But that expectation is not unlimited. ## Keep the check relevant Focus on professional information that genuinely relates to the vacancy. For example: - Employment history - Professional qualifications - Skills - Published professional work - Relevant industry experience Avoid turning a simple professional check into an investigation of the candidate's private life. ## What if you find inconsistent information? Suppose the CV says the candidate worked somewhere for five years, while LinkedIn says three. Do not automatically assume dishonesty. Online profiles can be outdated, incomplete or inaccurate. If the discrepancy matters, give the candidate an opportunity to explain it. ## Can you save information from LinkedIn? Saving or copying information creates additional processing. Ask whether you really need screenshots, exported profiles or notes about everything you found. If a hiring manager only needs to verify a particular professional fact, storing a complete copy of the profile may be unnecessary. ## Tell candidates where information may come from Where the GDPR requires it, your [candidate privacy information](/en/kennisbank/hr/candidate-privacy-notice) should explain that recruitment data may be obtained from professional networking platforms or other public professional sources. Transparency is particularly important if online research forms a systematic part of your recruitment procedure. ## Create a consistent rule Without guidance, one hiring manager may check only LinkedIn while another searches every candidate across multiple platforms. A simple recruitment policy can define: - Which sources may be checked - At what stage - For which roles - What information is relevant - What may be recorded - Who may perform the check GDPRWise helps employers document recruitment activities and [the sources of personal data they use](/en/kennisbank/hoe-gdprwise-werkt/which-processes-to-document), making online candidate checks part of a controlled process. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Can You Contact Former Candidates About a New Vacancy? URL: https://gdprwise.eu/en/kennisbank/hr/contact-former-candidates/ Summary: A new vacancy opens and you remember a strong candidate from last year. Whether you can email them depends on why you still hold their data and what you told them at the time. Key takeaways: - A previous application does not automatically justify keeping candidate data forever - Contacting someone about future vacancies is a separate recruitment purpose - A properly managed talent pool makes future contact easier to justify - Consider both GDPR and any rules that apply to the communication channel you use FAQ: Q: Do I need consent to contact a former candidate about a new role? A: Not necessarily. If the candidate consented to being kept for future vacancies, that consent covers the approach. If you rely on legitimate interests instead, the approach is covered as long as it stays within the balancing assessment you documented and the candidate has not objected. What you cannot do is contact someone whose data you should already have deleted. Q: The application should have been deleted, but I still have the CV. Can I use it? A: The fact that you happen to still have a copy is not a good reason to use it. If your retention policy said the file should have gone, the sensible response is to delete it rather than build a new contact on it. Data that was legitimately retained in a talent pool for future vacancies is a different situation. Q: Does it matter which vacancy I contact them about? A: Yes. If someone applied for a senior accounting position, contacting them about another accounting role may make sense. Using an old CV to send broad promotional recruitment messages about unrelated jobs is different. The closer the new contact is to the purpose and expectations under which the data was retained, the easier it is to explain. Q: Is GDPR the only rule that applies to the email itself? A: No. Depending on the country, the type of message and the channel used, electronic communications and direct marketing rules may also apply. Do not assume that a GDPR legal basis automatically answers every question about sending emails or messages. A new vacancy opens and you remember someone who applied last year. They were a strong candidate, so sending them a quick email seems harmless. Whether you can do that depends on why you still hold their data and what the candidate was told when it was collected. ## Why do you still have the candidate's details? This is the first question. If the original application should already have been deleted under your [retention policy](/en/kennisbank/beveiliging/data-retention-policy), the fact that you happen to still have a copy is not a good reason to use it. If the candidate was legitimately retained in a [talent pool for future vacancies](/en/kennisbank/hr/gdpr-compliant-talent-pool), the situation is different. ## What did you tell the candidate? Transparency matters. If you told the candidate that you would keep their details for a defined period and might contact them about suitable future vacancies, a relevant approach is more likely to match their expectations. If the candidate applied for one specific role years ago and heard nothing further, an unexpected recruitment message may be harder to justify. ## Do you need consent? Not necessarily, and by the time a vacancy opens the question is usually already answered. If the candidate agreed to be kept for future vacancies, that consent covers the approach, and it holds until they withdraw it. If your pool runs on legitimate interests, the approach is covered as long as it stays inside the balancing assessment you documented and the candidate has not objected. The decision belongs at the point you decide to keep someone, not at the point you want to email them. [Do you need consent to keep a candidate's CV?](/en/kennisbank/hr/consent-to-keep-cv) sets out both routes. ## Keep the contact relevant If someone applied for a senior accounting position, contacting them about another accounting role may make sense. Using an old CV to send broad promotional recruitment messages about unrelated jobs is different. The closer the new contact is to the purpose and expectations under which the data was retained, the easier it is to explain. ## Give candidates control Make it easy for candidates to say they do not want future recruitment contact. If they object or withdraw consent where applicable, update your systems so that they are not contacted again on the same basis. ## Check the communication rules The GDPR is not the only law that can matter when sending electronic communications. Depending on the country, the type of message and the channel used, electronic communications and direct marketing rules may also apply. Do not assume that a GDPR legal basis automatically answers every question about sending emails or messages. ## Build future contact into the process The best time to decide how former candidates will be contacted is not when a new vacancy appears. Create a talent-pool process in advance, including purpose, legal basis, transparency, retention and opt-out handling. Recording it in your [processing register](/en/kennisbank/hoe-gdprwise-werkt/records-of-processing-ropa) keeps the decision visible to everyone who recruits. GDPRWise helps employers document recruitment and talent-pool activities so future candidate contact is based on a defined process rather than an old CV found in an inbox. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Can You Keep CVs of Unsuccessful Candidates for Future Vacancies? URL: https://gdprwise.eu/en/kennisbank/hr/keep-cvs-future-vacancies/ Summary: Keeping rejected candidates' CVs for future openings is a separate purpose under the GDPR. Here is how to be transparent, pick a legal basis and set a retention period. Key takeaways: - Future recruitment is a separate purpose, so it needs its own decision rather than inertia. - Future recruitment should be treated as a separate purpose from the original application. - Tell candidates clearly if you want to retain their details for future vacancies. - Set a defined retention period and keep talent-pool information accurate. FAQ: Q: Can I keep a rejected candidate's CV for a future vacancy? A: Yes, provided you treat it as what it is: a new purpose, separate from assessing the candidate for the job they applied for. That means telling them, choosing a legal basis, keeping only what you need and setting an end date. What you cannot do is leave the file where it is and decide later. Q: Do I always need consent to keep an unsuccessful CV? A: No. You have two workable routes: ask the candidate for consent, which is usually simplest for a smaller employer, or rely on legitimate interests with a documented balancing assessment and a clear route to object. Both are accepted. Choose one before you keep the file, not afterwards. Q: What should I tell candidates about retaining their details? A: Explain why you want to retain their information, what you will keep, how long you will keep it, who can access it and how they can exercise their GDPR rights. Avoid vague statements that would allow you to retain applications forever. Q: Do I need to keep the whole recruitment file in the talent pool? A: Usually not. Interviewers' internal comments, old assessments and other material collected for the first vacancy may not be necessary merely to contact the candidate about a new opportunity. Apply data minimisation to the talent pool itself. You interview a strong candidate, but someone else is a better fit for the current vacancy. Six months later, another position opens. Can you simply retrieve the old CV and contact them? Yes, if you set it up properly. Keeping unsuccessful candidates for future recruitment is a separate purpose, and the work is in deciding that deliberately rather than discovering it later. ## The original application has a purpose When a candidate applies for a particular job, the immediate purpose is clear: assess whether they are suitable for that vacancy. Once the recruitment procedure is complete, that purpose largely ends. Keeping the candidate's information because another suitable vacancy might arise later is a new or additional purpose. That does not automatically make it unlawful. It means you need to manage it properly, in the same way you would manage [how long you keep a candidate's CV](/en/kennisbank/hr/how-long-keep-cv) after the procedure closes. ## Be transparent Candidates should know if their information may be retained for future recruitment. Explain: - Why you want to retain it - What information you will keep - How long you will keep it - Who can access it - How candidates can exercise their GDPR rights Avoid vague statements that allow you to retain applications forever. ## Do you always need consent? No. Two legal bases work here. **Consent** is usually the simplest for a smaller employer: ask the candidate at the point of rejection whether you may keep their details for future vacancies. **Legitimate interests** works too, provided you carry out and record a balancing assessment, tell candidates clearly and let them object. What matters is that you pick one before you keep the file. [Do you need consent to keep a candidate's CV?](/en/kennisbank/hr/consent-to-keep-cv) sets out both routes and when each one fits. ## Set an expiry date A useful talent pool has a lifecycle. A CV that was highly relevant three years ago may now contain an old job title, outdated skills and obsolete contact details. Set a retention period. At the end of it, either delete the information or, where appropriate, ask whether the candidate wants to remain in the talent pool. Your [data retention policy](/en/kennisbank/beveiliging/data-retention-policy) is the natural place to record that period. ## Keep only useful information You may not need the entire original recruitment file. Interviewers' internal comments, old assessments and other material collected for the first vacancy may not be necessary merely to contact the candidate about a new opportunity. Apply data minimisation to the talent pool itself. ## Make leaving easy Candidates should have a simple way to tell you that they no longer want to be considered for future vacancies. When someone objects or withdraws consent where consent is your basis, ensure the request reaches all relevant systems. ## A talent pool is a database, not a folder If your "talent pool" is simply an inbox containing years of old applications, it is time to organise it. Define the purpose, legal basis, retention period, access rights and deletion process, and treat it as [a real processing activity in its own right](/en/kennisbank/hr/gdpr-compliant-talent-pool). GDPRWise helps employers document recruitment and talent-pool processing separately, so that each activity has a clear purpose, legal basis and retention rule. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Can You Screen Applicants' Social Media Profiles? URL: https://gdprwise.eu/en/kennisbank/hr/social-media-screening-applicants/ Summary: Searching a candidate's name takes seconds and can reveal far more than a CV. That is exactly why social media screening creates GDPR and discrimination risks for employers. Key takeaways: - Public social media information is still protected by the GDPR - Only screen information that is genuinely relevant and necessary for the job - Social profiles can reveal sensitive information that should not influence recruitment - Avoid systematic screening without a clear policy, purpose and legal basis FAQ: Q: The post is public, so why can't I use it? A: Being able to see a post does not mean an employer is free to collect and use it for any purpose. The GDPR still requires lawful, fair and transparent processing, so you need a purpose, a legal basis and appropriate transparency before a public post becomes part of a hiring decision. Q: What makes social media screening riskier than checking a CV? A: Personal social media can reveal health, religion, political opinions, trade union activity, sexual orientation, family circumstances and ethnic background. Some of these are special categories of personal data under the GDPR and may also relate to characteristics protected by anti-discrimination law. Once a hiring manager has seen the information, it is difficult to demonstrate it played no role in the decision. Q: Can I ask a candidate for access to their private profile? A: No. Attempting to gain access to information the candidate has deliberately kept private is particularly intrusive and may breach applicable laws and platform rules. Do not ask candidates to provide passwords or accept connection requests merely so you can inspect private content. Q: How can I reduce the risk if screening is genuinely justified? A: Consider having a designated person perform the screening and pass only job-relevant findings to the decision-maker. This can help reduce the decision-maker's exposure to irrelevant sensitive information. It does not remove your GDPR obligations, but it is a useful organisational safeguard. It takes seconds to search a candidate's name online. Facebook, Instagram, TikTok, X and other platforms may reveal far more than a CV ever would. That is exactly why social media screening creates GDPR and discrimination risks. ## "It's public" is not enough If a candidate has made a post publicly visible, you may technically be able to see it. That does not mean an employer is free to collect and use it for any purpose. The GDPR still requires [lawful, fair and transparent processing](/en/kennisbank/verplichtingen/gdpr-legal-bases). ## Why social media screening is risky Personal social media can reveal information about: - Health - Religion - Political opinions - Trade union activity - Sexual orientation - Family circumstances - Ethnic background Some of these are special categories of personal data under the GDPR. They may also relate to characteristics protected by employment and anti-discrimination law. Once a hiring manager sees this information, it can be difficult to demonstrate that it played no role in the decision. ## Is the information relevant? Suppose you are hiring an accountant. Pictures from a candidate's holiday are unlikely to tell you whether they can do the job. A professional public statement directly relevant to a role may present a different situation, but employers should still assess necessity and proportionality. The test should not be: **"Can we find something?"** It should be: **"Do we have a legitimate and necessary reason to look for this information?"** ## Don't ask for passwords or private access Attempting to gain access to information the candidate has deliberately kept private is particularly intrusive and may breach applicable laws and platform rules. Do not ask candidates to provide passwords or accept connection requests merely so you can inspect private content. ## If you screen, create rules first Define: - Which roles justify screening - Which platforms may be checked - At what stage screening occurs - What information is relevant - Who performs the screening - What may be recorded - How candidates are informed Consistency also reduces the risk that individual hiring managers conduct their own uncontrolled searches. Where you do screen, your [candidate privacy information](/en/kennisbank/hr/candidate-privacy-notice) should say so. ## Separate relevant from irrelevant information Where screening is genuinely justified, consider having a designated person perform it and pass only job-relevant findings to the decision-maker. This can help reduce exposure to irrelevant sensitive information. It does not remove your GDPR obligations, but it can be a useful organisational safeguard. Limiting who can open the screening results, in the same way you apply [access control to other personal data](/en/kennisbank/beveiliging/access-control-personal-data), reinforces it. ## Social media screening should be exceptional, not automatic A routine search of every candidate's private online life is difficult to reconcile with data minimisation. Professional recruitment should remain focused on whether a person can perform the job. A [check of professional networking information](/en/kennisbank/hr/checking-candidate-linkedin) is usually easier to justify than a sweep of private profiles. GDPRWise helps organisations document recruitment processes and identify where personal data comes from, including external and public sources. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Can You Use ChatGPT or Other AI Tools to Review CVs? URL: https://gdprwise.eu/en/kennisbank/hr/chatgpt-cv-screening/ Summary: Pasting a candidate's CV into an AI tool is personal data processing. What to check about the provider, how much to upload, and where the real risk starts. Key takeaways: - A CV remains personal data when it is uploaded to an AI tool - Check the provider's terms, data use, retention, security and transfer arrangements before uploading real applications - Share only the data needed for the task - Be much more cautious when AI influences ranking, shortlisting or rejection FAQ: Q: Is uploading a CV to ChatGPT a GDPR issue? A: Yes. A CV is personal data, and uploading it to an AI service is a disclosure of that data to a technology provider. Treat it as processing that needs a purpose, a legal basis and appropriate contractual and security arrangements, not as a neutral productivity shortcut. Q: Does removing the candidate's name make the CV anonymous? A: No. Removing the filename or the name still leaves employment history, education, location and other details that identify the person. That is pseudonymisation, not anonymisation: it reduces risk, but the data stays personal data and the GDPR still applies in full. Q: Is the consumer version of an AI tool the same as the business version? A: Often not. Retention, model training, security measures and the availability of appropriate data processing terms can differ between consumer and business versions of the same AI service. Establish which product and account type you are actually using before uploading candidate data. Q: Can I use AI to rank candidates instead of just summarising CVs? A: Ranking is not equivalent to summarising. Scoring, ranking or rejecting candidates introduces additional concerns including fairness, transparency, automated decision-making and potentially the high-risk AI system rules under the EU AI Act. Assess that use case separately. AI tools can summarise a CV in seconds, compare experience with a job description or help identify relevant skills. That can be attractive when an employer receives hundreds of applications. But copying candidate CVs into an AI tool is still personal data processing. Before doing it, employers need to understand what happens to that information. ## What are you asking the AI to do? There is a major difference between: - Improving the wording of a generic recruitment email - Summarising a candidate's CV - Comparing a CV with job criteria - Ranking candidates - Recommending who should be interviewed - Automatically rejecting applicants The closer the tool gets to making or determining the recruitment decision, the greater the legal and practical risk. Letting the system decide on its own takes you into [automated rejection territory](/en/kennisbank/hr/ai-automatic-rejection). ## A CV contains personal data Removing the filename does not anonymise a CV. The document may contain: - Name - Email address - Telephone number - Employment history - Education - Location - Photograph - Professional memberships - Other information that identifies the person It may even contain sensitive information the candidate chose to include. Treat the upload as a disclosure of personal data to a technology provider. ## Check the AI provider first Before using any AI service with candidate data, establish: - Which product or account type you are using - What contractual terms apply - Whether submitted data is retained - Whether it may be used for model training or improvement - Where processing takes place - Which subprocessors are involved - What security measures are available - Whether appropriate data processing terms are offered - How deletion works These answers can differ between consumer and business versions of the same AI service. The same questions apply to [any AI tool that touches personal data](/en/kennisbank/verplichtingen/ai-tools-privacy-gdpr), not only recruitment tools. ## Minimise what you upload If you only want help identifying skills, do you need to provide the candidate's name, address, photograph and contact details? Probably not. Where possible, remove information that is unnecessary for the task. Remember that pseudonymisation reduces risk but leaves the information as personal data, fully within the GDPR. ## Don't blindly trust the output AI can make mistakes, misunderstand experience or generate conclusions that are not supported by the CV. Recruitment decisions should not be based on an assumption that an AI-generated summary is accurate. A human reviewer should be able to verify the relevant source information and challenge the output. ## Ranking is different from summarising Using AI to create a neutral summary can already involve GDPR obligations. Using it to score, rank or reject candidates introduces additional concerns, including fairness, transparency, automated decision-making and potentially the high-risk AI system rules under the EU AI Act. Do not treat these use cases as equivalent. ## Create an internal AI rule Employees should know whether they are allowed to paste candidate data into public or generative AI tools. A simple [AI acceptable use policy](/en/kennisbank/verplichtingen/ai-acceptable-use-policy) can define: - Approved AI tools - Permitted recruitment uses - Information that may not be uploaded - Required human review - Security requirements - Escalation for higher-risk uses Without such a rule, hiring managers may create "shadow AI" processes without HR or management knowing. ## Review the tool before the CV The practical rule is simple: **do not test an AI recruitment workflow with real candidate data before you have assessed the tool.** GDPRWise helps organisations map third parties and processing activities so new AI tools can be assessed as part of the existing GDPR compliance framework rather than introduced informally. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Candidate Privacy Notices: What Should They Contain? URL: https://gdprwise.eu/en/kennisbank/hr/candidate-privacy-notice/ Summary: A candidate privacy notice explains how you handle personal data during recruitment. Here is every section Articles 13 and 14 require, from legal bases to retention periods and transfers. Key takeaways: - A candidate privacy notice should reflect your real recruitment process - Explain purposes, legal bases, data sources, recipients, retention periods and candidate rights - Include relevant information about recruitment agencies, software and international transfers - Review the notice whenever your recruitment process changes FAQ: Q: Can I use a generic privacy notice template for candidates? A: A template can be a starting point, but the notice has to describe what actually happens in your recruitment process. If you introduce a new applicant tracking system, AI screening tool, assessment provider or talent pool, check whether the notice still describes reality. Q: Do I need to name a specific retention period in the notice? A: Where possible, state concrete retention periods. Where that is not possible, explain the criteria you use to determine them. Wording such as 'your data will be kept as long as necessary' is legally familiar but not very helpful on its own. Q: What should the notice say about international transfers? A: Recruitment software is often cloud-based. If applicant data is transferred outside the EEA, explain this and provide the information the GDPR requires about the transfer mechanism or safeguards. Do not assume that software used through a European website stores all data in Europe. Q: Should the candidate privacy notice also cover employees? A: No. A candidate privacy notice is intended for the recruitment process. Once a candidate becomes an employee you will process considerably more data for different purposes, so a separate Staff Privacy Policy works better than one document trying to cover both. A candidate privacy notice explains how your organisation handles personal data during recruitment. It is the document that carries your transparency obligations under Articles 13 and 14 GDPR. This article covers **what** the notice has to contain. For the equally important question of **when** the candidate has to receive it and how to get it in front of them, see [when and how to inform candidates](/en/kennisbank/hr/candidate-privacy-information). The notice should describe what actually happens in your recruitment process, not what a generic template assumes happens. ## The elements at a glance Articles 13 and 14 set out what has to be in there. In a recruitment context that comes down to: | Element | Article 13 (candidate gives you the data) | Article 14 (data from an agency or platform) | | --- | --- | --- | | Your identity and contact details | Required | Required | | DPO contact details, if you have one | Required | Required | | Purposes of the processing | Required | Required | | Legal basis for each purpose | Required | Required | | Your legitimate interests, where relied on | Required | Required | | Categories of data you process | Not required | Required | | Source of the data | Not applicable | Required | | Recipients or categories of recipients | Required | Required | | Transfers outside the EEA and safeguards | Required | Required | | Retention period or the criteria for it | Required | Required | | Candidate rights, including objection and withdrawal | Required | Required | | Right to complain to a supervisory authority | Required | Required | | Whether providing data is obligatory and the consequences | Required | Not applicable | | Automated decision-making, logic, significance and consequences | Required where applicable | Required where applicable | If you receive candidates through both routes, one notice covering the wider Article 14 set is simpler than maintaining two. ## Start with who you are Candidates need to know which organisation is responsible for their personal data. Include your organisation's identity and contact details. If you have appointed a data protection officer, include their contact details as well. This sounds obvious, but it becomes important when recruitment is handled through a group company, external recruiter or shared recruitment platform. ## Explain what data you process Describe the categories of applicant data you use. Depending on your process, this could include: - Identification and contact information - CV and application information - Employment and education history - Interview notes - Assessments and test results - References - Information from professional profiles - Communications with the candidate - Information required before employment begins Avoid vague wording such as "we may process any information necessary". The starting point is deciding [which applicant data you actually need](/en/kennisbank/hr/applicant-data-what-to-collect). ## Explain why you use it Candidates should understand the purposes of the processing. Typical purposes include: - Managing applications - Assessing suitability for a vacancy - Communicating with candidates - Organising interviews and assessments - Checking references where appropriate - Preparing an employment offer or contract - Complying with legal obligations - Defending or responding to recruitment-related claims - Keeping candidates in a talent pool, where applicable Different purposes may rely on different legal bases. ## State the legal bases Do not simply write "we process your data in accordance with the GDPR". Identify the [legal bases](/en/kennisbank/verplichtingen/gdpr-legal-bases) that actually apply. In recruitment these are usually steps taken at the candidate's request before entering into a contract, legitimate interests, a legal obligation, or consent where you keep details for future vacancies. Where you rely on legitimate interests, Articles 13(1)(d) and 14(2)(b) require you to name the interest, not just the basis. If you process special category data, an additional Article 9(2) condition is required and the notice should reflect it. ## Where does the data come from? Not all applicant information comes directly from candidates. Where you obtain information from recruiters, references, professional networks or other sources, Article 14(2)(f) requires you to say so, including whether it came from a publicly accessible source. This matters most in exactly the situations candidates do not expect: a referral from a current employee, a profile found on a professional network, a reference approached before the candidate was told. ## Who receives the data? Explain who may access or receive candidate data. This can include: - HR staff - Hiring managers - Relevant interviewers - Group companies - Recruitment agencies - Applicant tracking systems - Assessment providers - IT and cloud providers [Access should still be limited](/en/kennisbank/beveiliging/access-control-personal-data) to people who need the information. ## Explain retention periods "Your data will be kept as long as necessary" may be legally familiar, but it is not very helpful on its own. Where possible, state concrete [retention periods](/en/kennisbank/hr/how-long-keep-cv). Where that is not possible, explain the criteria used to determine them. If unsuccessful candidates can join a talent pool, explain that separately. ## International transfers Recruitment software is often cloud-based. If applicant data is transferred outside the EEA, explain this and provide the information required by the GDPR about the transfer mechanism or safeguards. Do not assume that software used through a European website necessarily stores all data in Europe. ## Explain candidate rights Candidates have the following rights, and the notice should name them: - Access - Rectification - Erasure - Restriction - Objection - Data portability in applicable situations - Rights relating to certain automated decisions Explain how candidates exercise those rights, with a working address or form rather than a general company mailbox, and state that they may lodge a complaint with the competent supervisory authority. Where you rely on consent for anything, say that it can be withdrawn at any time and that withdrawal is as easy as giving it. ## What happens when the candidate becomes an employee? A candidate privacy notice is intended for the recruitment process. Once a candidate becomes an employee, your organisation will normally process considerably more personal data and for different purposes. We therefore recommend having a separate [Staff Privacy Policy](/en/kennisbank/hoe-gdprwise-werkt/employee-privacy-policy) that explains how you process personal data during the employment relationship. The candidate privacy notice and Staff Privacy Policy should complement each other, rather than trying to cover both recruitment and employment in a single document. ## Keep it accurate A privacy notice is not a document you write once and forget. If you introduce a new applicant tracking system, AI screening tool, assessment provider or talent pool, check whether your notice still describes reality. The best candidate privacy notice is not the longest one. It is the one that accurately explains your actual recruitment process. GDPRWise helps organisations connect their documented processing activities with the privacy information they need to provide, making it easier to keep recruitment documentation consistent. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Do You Need Consent to Keep a Candidate's CV? URL: https://gdprwise.eu/en/kennisbank/hr/consent-to-keep-cv/ Summary: Consent is not required to process applicant data for the vacancy itself. For keeping a CV afterwards you have two workable routes, and this is how to choose between them. Key takeaways: - You do not automatically need consent to process a CV for the vacancy the candidate applied for. - Every processing purpose needs an appropriate legal basis. - Keeping a CV for future vacancies is a separate purpose with two workable legal bases: consent or legitimate interests. - If you use consent, it must be genuine and candidates must be able to withdraw it. FAQ: Q: Do I need consent to process a CV for the job someone applied for? A: Not automatically. Processing information necessary to take steps at the candidate's request before entering into an employment contract may provide the relevant legal basis for parts of the recruitment process. Other activities may rely on another basis, such as legitimate interests or a legal obligation. Q: Why can asking for unnecessary consent be a problem? A: Consent must be freely given, specific, informed and unambiguous, and it must be possible to withdraw it. If you tell a candidate that processing their CV is based on consent but you could not realistically continue the recruitment procedure once they withdraw it, consent was probably not the appropriate basis in the first place. Q: What happens if a candidate withdraws consent? A: Deleting them from one mailing list may not be enough. Check your applicant tracking system, HR inboxes, shared folders, recruitment spreadsheets and external recruitment platforms. Your process should ensure the withdrawal reaches every system concerned. Q: Is consent the right basis for a talent pool? A: It is one of two workable routes, and usually the simplest for an SME: ask the unsuccessful candidate whether you may keep their details for future vacancies. Legitimate interests is equally available, provided you carry out and document a balancing test, tell candidates clearly and let them object. Both are accepted; what is not acceptable is keeping the CV without deciding which one you rely on. "Please tick this box to consent to us processing your CV." Many recruitment forms use wording like this. But under the GDPR, consent is not automatically required every time you process applicant data. In fact, asking for consent when another legal basis is more appropriate can make your recruitment process unnecessarily complicated. ## Processing the current application A candidate sends you a CV because they want you to consider them for a job. Processing information necessary to take steps at the candidate's request before entering into an employment contract may provide the relevant legal basis for parts of the recruitment process. Other activities may rely on another legal basis, such as legitimate interests or a legal obligation. The [six legal bases in the GDPR](/en/kennisbank/verplichtingen/gdpr-legal-bases) each carry their own conditions, so it pays to compare them before you decide. The point is that **GDPR compliance does not mean asking for consent for everything**. ## Why can unnecessary consent be a problem? Consent has strict requirements. It must be: - Freely given - Specific - Informed - Unambiguous It must also be possible to withdraw consent. If you tell a candidate that processing their CV is based on consent but you could not realistically continue the recruitment procedure after they withdraw that consent, you should ask whether consent was really the appropriate basis in the first place. ## What about keeping the CV after rejection? Two different things happen after a rejection, and they need separating. **Short retention tied to the procedure itself.** You may keep certain information for a limited period to deal with questions or claims arising from the recruitment decision. That rests on your legitimate interest in defending claims, and it runs for as long as such a claim is realistically possible, not indefinitely. See [how long you can keep a CV](/en/kennisbank/hr/how-long-keep-cv). **Keeping the CV to approach the candidate about future vacancies.** This is a new purpose, unrelated to the job they applied for, and it needs its own legal basis. ## The two routes for a talent pool There are two legal bases that work here. The European Data Protection Board accepts both, depending on the circumstances. Pick one deliberately and write it down. ### Route 1: consent Usually the simplest option for an SME. At the point of rejection you ask the candidate a plain question: may we keep your details to contact you about future vacancies? What makes it work: - The candidate can say no at no cost, because the procedure they applied for is over. That is what makes the consent freely given, which is often hard to achieve elsewhere in an employment context. - Ask separately from anything else, with no pre-ticked box, and record the answer and its date. - Article 7(3) requires withdrawal to be as easy as giving consent. An unsubscribe link or a named mailbox in every message is enough; a written request to head office is not. - When consent is withdrawn, the basis for keeping the record disappears. Delete it. ### Route 2: legitimate interests Equally available under Article 6(1)(f), and often the better fit if you recruit continuously and want to build a real pool rather than chase individual permissions. What it requires: - A balancing assessment, carried out **before** you start and written down: your interest in filling future roles efficiently, whether keeping the data is necessary to do that, and whether it overrides the candidate's interests and reasonable expectations. - Clear information at the point of rejection that you intend to keep their details, why, and for how long. - A working route to object under Article 21. An objection to this processing has to be honoured; there is no balancing exercise left to run once someone says no. - Restraint on scope. A recent applicant for a role you recruit for regularly sits comfortably inside their expectations. A five-year-old CV used to send unrelated openings does not. ### Choosing between them | | Consent | Legitimate interests | | --- | --- | --- | | Best for | Occasional hiring, small candidate volumes | Continuous recruitment, a maintained pool | | Work up front | A clear question and a record of the answer | A documented balancing assessment | | Candidate control | Withdrawal, which ends the processing | Objection, which you must honour | | Main risk | People decline, so the pool stays small | The assessment was never actually done | Neither route survives the thing employers do most often, which is to keep the CV and decide later. ## If you ask for consent, do it properly Avoid: - Pre-ticked boxes - Consent hidden inside general terms - Combining several unrelated purposes into one consent - Saying that consent cannot be withdrawn - Keeping the data indefinitely after consent Explain the talent-pool purpose separately from the application itself, and give the candidate a clear yes or no. ## Withdrawal must work in practice If a candidate withdraws consent, deleting them from one mailing list may not be enough. Check whether their information also exists in: - Your applicant tracking system - HR inboxes - Shared folders - Recruitment spreadsheets - External recruitment platforms Your process should ensure the withdrawal reaches the systems concerned. The same discipline applies when someone [asks you to erase their data](/en/kennisbank/rechten-en-verzoeken/right-to-erasure) altogether. ## Choose the legal basis before writing the privacy notice Do not start with a consent checkbox and work backwards. First identify the processing activity and purpose. Then determine the appropriate legal basis. Then make sure your [candidate privacy notice](/en/kennisbank/hr/candidate-privacy-notice) accurately explains it. GDPRWise helps organisations document the purposes and legal bases behind HR and recruitment processing, making it easier to avoid "consent for everything" compliance. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### GDPR and the AI Act in Recruitment: How Do They Work Together? URL: https://gdprwise.eu/en/kennisbank/hr/gdpr-ai-act-recruitment/ Summary: Recruitment AI can fall under both the GDPR and the EU AI Act. The two frameworks overlap but do not do the same thing, and complying with one is not enough. Key takeaways: - The GDPR protects personal data and applies whenever recruitment AI processes personal data - The AI Act regulates AI systems according to their risk and role in the AI value chain - Certain recruitment and candidate-selection AI systems are classified as high-risk - Employers need to assess both frameworks before deploying recruitment AI FAQ: Q: Does complying with the GDPR mean I comply with the AI Act? A: No. The two frameworks overlap but do not do the same thing. The GDPR focuses on the processing of personal data, while the AI Act regulates AI systems by risk and by the role of the organisation. One assessment can inform another, but do not assume a GDPR DPIA automatically fulfils every AI Act requirement. Q: Is every use of AI in HR high-risk? A: No. The classification depends on the intended purpose and functionality of the system, and the AI Act contains relevant distinctions and exceptions that must be assessed carefully. Using a general AI tool to improve the grammar of a vacancy is not the same as deploying a system intended to rank candidates. Q: Am I a provider or a deployer under the AI Act? A: A company that develops and places an AI recruitment system on the market may be a provider, while an employer that uses an AI system under its authority will often be a deployer. Organisations can take on different or additional responsibilities, for example when substantially modifying a system or using it in ways that affect its intended purpose. Q: When do the AI Act obligations actually apply? A: The high-risk obligations covering recruitment and employment AI were due to apply from 2 August 2026, but Regulation (EU) 2026/1744, the Digital Omnibus on AI, deferred that date to 2 December 2027. The Article 50 transparency obligations were not deferred and have applied since 2 August 2026, and the GDPR applies in full regardless of the AI Act timetable. Employers using AI in recruitment may need to comply with two major EU legal frameworks at the same time: the GDPR and the AI Act. They overlap, but they do not do the same thing. Complying with one does not automatically mean you comply with the other. ## What does the GDPR regulate? The GDPR focuses on the processing of personal data. For recruitment AI, that means questions such as: - What candidate data is processed? - Why is it processed? - What is the [legal basis](/en/kennisbank/verplichtingen/gdpr-legal-bases)? - Is the data necessary? - How long is it kept? - Who receives it? - Is it transferred internationally? - Are candidates properly informed? - Is a Data Protection Impact Assessment required? - Are automated decision-making rules relevant? These obligations can apply whether the technology is called "AI" or not. ## What does the AI Act regulate? The AI Act regulates AI systems and imposes different rules depending on the type of system and the role of the organisation using or supplying it. Certain AI systems intended for recruitment or selection of natural persons are classified as **high-risk**. This includes certain systems used to analyse and filter job applications and evaluate candidates. Annex III point 4 is broader than hiring alone. It also reaches AI used for promotion and termination decisions, task allocation, and monitoring or evaluating the performance of workers. An employer that clears its recruitment tools but runs an AI performance or monitoring tool has not finished the exercise. High-risk systems are subject to detailed requirements. ## Is every use of AI in HR high-risk? No. The classification depends on the intended purpose and functionality of the system, and the AI Act contains relevant distinctions and exceptions that must be assessed carefully. Using a general AI tool to improve the grammar of a vacancy is not the same as deploying an AI system intended to rank candidates. Start with the [actual use case](/en/kennisbank/hr/ai-in-recruitment) rather than the label "AI". ## Provider or deployer? Your obligations under the AI Act depend partly on your role. A company that develops and places an AI recruitment system on the market may be a provider. An employer that uses an AI system under its authority will often be a deployer. However, organisations can take on different or additional responsibilities in certain circumstances, for example when substantially modifying a system or using it in ways that affect its intended purpose. Do not assume the vendor carries every compliance obligation. Under the GDPR, the vendor's role should also be recorded in your [Third Party Dossier](/en/kennisbank/hoe-gdprwise-werkt/third-party-dossier). ## Where do the GDPR and AI Act overlap? Both frameworks care about responsible processing and meaningful control, but they approach it differently. Important overlapping areas include: - Data quality - Transparency - Risk assessment - Human oversight - Security - Documentation - Accountability - Fairness and potential bias One assessment can inform another, but do not assume a [GDPR DPIA](/en/kennisbank/verplichtingen/dpia-guide) automatically fulfils every AI Act requirement. ## Automated decisions under the GDPR Recruitment AI can also trigger Article 22 GDPR where a decision is based solely on automated processing and produces legal effects or similarly significantly affects the candidate. This analysis remains necessary even if the AI system is also regulated as high-risk under the AI Act. ## Timing matters The AI Act entered into force in 2024 and applies according to a phased timetable, and that timetable moved in 2026. The high-risk obligations for the standalone Annex III systems that cover recruitment and employment were originally due to apply from 2 August 2026. The Digital Omnibus on AI, Regulation (EU) 2026/1744, deferred that date to **2 December 2027**. Systems embedded in products already covered by EU product safety law move to 2 August 2028. That deferral does not empty the calendar. The Article 50 transparency obligations were not postponed and have applied since 2 August 2026, so if candidates interact with a recruitment chatbot or receive AI-generated content, those duties are live now. The GDPR applies in full throughout, independently of the AI Act timetable. The practical reading for employers: you have until December 2027 to meet the high-risk requirements for recruitment AI, and no extra time at all on transparency or on anything the GDPR already required. ## Build one governance process Instead of creating separate silos for privacy and AI, employers can create one intake process for recruitment technology. Before a new tool is approved, ask: 1. What does it do? 2. Does it process personal data? 3. What GDPR requirements apply? 4. Is it an AI system under the AI Act? 5. What is its risk classification? 6. What role does our organisation have? 7. What assessments and documentation are required? 8. What human oversight is in place? GDPRWise helps organisations build the GDPR side of this governance by mapping processing activities, data, legal bases, providers and privacy risks in a structured way. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### How Do You Create a GDPR-Compliant Talent Pool? URL: https://gdprwise.eu/en/kennisbank/hr/gdpr-compliant-talent-pool/ Summary: A talent pool is not permission to keep every CV you have ever received. Here is how to define its purpose, legal basis, retention period, access rules and deletion process. Key takeaways: - Define the talent pool as a separate recruitment purpose. - Tell candidates clearly how their information will be used. - Pick one of the two available legal bases, document it, and set a retention period. - Keep the pool relevant, secure and up to date. FAQ: Q: What makes a talent pool GDPR-compliant? A: A clear purpose, an appropriate legal basis, transparent information for candidates, a defined retention period, accurate records, controlled access and a working deletion process. In short, treat it as a documented processing activity rather than a folder of old CVs. Q: What data belongs in a talent pool? A: Usually a limited record: name, contact details, relevant experience, skills, preferred roles, location or availability, the CV and the date the candidate entered the pool. Detailed interview comments or assessments from an old vacancy are often not necessary. Q: Which legal basis should I use for a talent pool? A: Either consent or legitimate interests. Consent is usually simplest for an SME: ask the candidate at rejection. Legitimate interests suits continuous recruiters, but requires a documented balancing assessment and a working route to object. Document which one you rely on and make sure your privacy information says the same thing. Q: How long can candidates stay in the pool? A: Talent pools should not be permanent archives. Choose a period that makes sense for your recruitment needs, and at the end of it either delete the candidate or, where appropriate, ask whether they want to remain. Regular review also improves the quality of your recruitment data. A good candidate does not always arrive at the right moment. A talent pool allows employers to stay in touch with promising people and contact them when a suitable vacancy appears. From a GDPR perspective, however, a talent pool is not simply permission to keep every CV you have ever received. ## Define what the talent pool is for Start with a clear purpose. For example: > To retain details of potentially suitable candidates so that we can contact them about relevant future vacancies. That is much clearer than keeping applicant data "for HR purposes". A clear purpose also helps determine what information you actually need. ## Decide what data belongs in the pool You probably do not need the entire original recruitment file. A useful talent-pool record might contain: - Name - Contact details - Relevant experience - Skills - Preferred roles - Location or availability - CV - Date the candidate entered the pool Detailed interview comments or assessments from an old vacancy may not be necessary. ## Choose the legal basis Two bases work for a talent pool: consent, or legitimate interests with a documented balancing assessment. Consent tends to suit occasional hiring; legitimate interests suits an employer recruiting continuously. [Do you need consent to keep a candidate's CV?](/en/kennisbank/hr/consent-to-keep-cv) works through both, including what each one costs you in practice. Two things matter whichever you choose. Record the decision and the reasoning behind it, and make sure your privacy information says the same thing you decided. A pool built on consent that a notice describes as legitimate interests fails on both. ## Tell candidates what will happen Candidates should know: - That they are being included in a talent pool - Why their data is being retained - What information you keep - How long you keep it - Who can access it - Whether third-party recruitment systems are involved - How they can exercise their GDPR rights If you rely on consent, explain how it can be withdrawn. ## Set a retention period Talent pools should not be permanent archives. Choose a period that makes sense for your recruitment needs. At the end of that period, delete the candidate or, where appropriate, ask whether they want to remain in the pool. Regular review also improves the quality of your recruitment data. ## Keep information accurate People change jobs, move, gain qualifications and change career direction. If you keep candidate information for a longer period, provide a way to update it and consider periodic checks. An outdated talent pool is both a privacy problem and a poor recruitment tool. ## Control access A talent pool can contain hundreds or thousands of CVs. Access should be limited to staff who genuinely need it for recruitment. Use appropriate authentication, permissions and [access control measures](/en/kennisbank/beveiliging/access-control-personal-data). Avoid circulating CVs through informal email chains when a controlled recruitment system is available. ## Make deletion easy If someone no longer wants to be in the pool, your organisation should be able to find and remove their information. That means knowing where copies are stored and how external recruitment providers handle deletion requests. ## Treat your talent pool as a real processing activity Document its purpose, data categories, legal basis, recipients, retention and security measures in your [records of processing activities](/en/kennisbank/hoe-gdprwise-werkt/records-of-processing-ropa). GDPRWise helps organisations map these elements in a structured way, so a talent pool becomes a managed recruitment process rather than a forgotten folder of old CVs. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### How Long Can You Keep a Candidate's CV? URL: https://gdprwise.eu/en/kennisbank/hr/how-long-keep-cv/ Summary: The GDPR does not set one universal retention period for CVs. This article explains how long you may keep applications during and after recruitment, and how to document your retention rules. Key takeaways: - The GDPR does not set one universal retention period for CVs - Keep a CV only for as long as it is necessary for the purpose for which you hold it - Retention after a recruitment procedure may be justified for a limited period, including where needed in relation to possible claims - Keeping a CV for future vacancies is a separate purpose and should be managed accordingly FAQ: Q: Is two years the correct retention period for a CV? A: No. You will often see specific periods suggested online, but the GDPR itself does not say that every employer may keep every unsuccessful candidate's CV for a fixed number of months or years. Retention should be justified by purpose and, where relevant, national law. Q: Do I have to delete a rejected candidate's file immediately? A: Not necessarily. There may be a legitimate reason to retain certain information for a limited period, for example to answer questions about the recruitment process or to establish, exercise or defend legal claims. The appropriate period depends partly on applicable national employment and anti-discrimination rules. Q: Can I keep an unsuccessful CV for future vacancies? A: Possibly, but this is a different purpose. The candidate gave you their CV to apply for a particular vacancy, so keeping it for future opportunities turns the file into part of a talent pool. Be transparent about that purpose and set an appropriate retention period rather than converting every application into a permanent database. Q: Where do forgotten copies of CVs usually sit? A: Deleting a candidate from your recruitment platform may not remove all copies. CVs also live in HR inboxes, hiring managers' email accounts, shared drives, downloads folders, recruitment agency portals, interview notes, spreadsheets and AI or assessment tools. Your retention policy should cover the whole recruitment process. Employers often accumulate CVs. Some belong to current applicants, others to people who applied months or years ago. Under the GDPR, however, CVs cannot simply be stored indefinitely. There is no single GDPR retention period that applies to every CV. The correct period depends on why you are keeping it. ## During the recruitment procedure While a vacancy is open, retaining applications is straightforward: you need them to assess candidates and manage the recruitment process. This can include the CV, cover letter, interview notes, assessments and communications. Once the recruitment process ends, however, the original purpose changes or disappears. ## What happens after rejection? You do not have to delete every unsuccessful candidate's file the minute the vacancy is filled. There may be a legitimate reason to retain certain information for a limited period, for example to answer questions about the recruitment process or establish, exercise or defend legal claims. That reasoning rests on one of the [six legal bases](/en/kennisbank/verplichtingen/gdpr-legal-bases), so record which one you rely on. The appropriate period depends partly on applicable national employment and anti-discrimination rules. This is why organisations should set retention periods with their own legal context in mind rather than copying an arbitrary number from the internet. ## Can you keep the CV for future vacancies? Possibly, but this is a different purpose. The candidate originally gave you their CV to apply for a particular vacancy. Keeping it because you want to contact them about future opportunities turns the file into part of a talent pool. Be transparent about that purpose in your [candidate privacy notice](/en/kennisbank/hr/candidate-privacy-notice) and determine an appropriate retention period. Do not convert every unsuccessful application automatically into a permanent talent database. ## Is two years always the correct period? No. You will often see specific periods suggested online, but the GDPR itself does not say that every employer may keep every unsuccessful candidate's CV for a fixed number of months or years. Retention should be justified by purpose and, where relevant, national law. A multinational organisation may therefore need different practical retention rules in different countries. ## What about spontaneous applications? The same principles apply. If someone sends you a CV without applying for a particular vacancy, decide what you are going to do with it. If you want to retain spontaneous applications for future vacancies, tell candidates how the process works and how long their information will be kept. ## Don't forget copies Deleting a candidate from your recruitment platform may not remove all copies. CVs can also be stored in: - HR inboxes - Hiring managers' email accounts - Shared drives - Downloads folders - Recruitment agency portals - Interview notes - Spreadsheets - AI or assessment tools Your retention policy should cover the whole recruitment process, in the same way a [data retention policy](/en/kennisbank/beveiliging/data-retention-policy) covers the rest of your organisation. ## Automate deletion where possible Retention policies only work if they are implemented. Applicant tracking systems often allow organisations to set deletion or review dates. Use these functions where appropriate instead of relying on someone to remember to clean up old applications manually. ## Document your retention rules For recruitment, define at least: - How long active applications are retained - How long rejected applicant files are retained after the procedure - How long talent-pool information is retained - When retention periods are reviewed - Who is responsible for deletion GDPRWise helps organisations document retention periods as part of their [processing activities](/en/kennisbank/hoe-gdprwise-werkt/records-of-processing-ropa), making it easier to turn "we don't keep data too long" into an actual rule. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Recruitment & GDPR: A Practical Checklist for Employers URL: https://gdprwise.eu/en/kennisbank/hr/recruitment-gdpr-checklist/ Summary: A step-by-step GDPR checklist for recruitment, from defining what applicant data you need through to deleting it, covering privacy information, providers, screening, talent pools and AI. Key takeaways: - Know what applicant data you collect and why. - Give candidates clear privacy information. - Control access, providers and retention. - Review AI and online screening before using them. FAQ: Q: Where should an employer start with recruitment GDPR? A: Start before the vacancy opens. Define which applicant data is actually necessary, remove unnecessary questions from your application forms, and identify the purposes and the appropriate legal basis for each of them. Make sure recruitment appears in your record of processing activities and that you have set retention periods. Q: What has to be in candidate privacy information? A: It should explain the purposes and legal bases, the relevant data sources, the recipients or categories of recipients, retention periods, international transfers where relevant, and candidate rights. Where automated decision-making is relevant, cover that too. Make the information available at the point where personal data is collected. Q: What should we check before using an AI tool in recruitment? A: Approve the tool before any candidate data is uploaded, and check what the provider does with submitted data. Minimise or pseudonymise where you can, assess the automated decision-making risks, check whether the AI Act applies and whether the system counts as high risk, and consider whether a DPIA is required. Human oversight has to be meaningful, and outputs should be tested for accuracy and bias. Q: What needs to happen when a recruitment procedure ends? A: Start the relevant retention period and delete the information when it expires. Deletion has to include email inboxes and local copies, and data held in external systems where required. Keep talent-pool data separate from ordinary rejected applications, and periodically test whether the deletion actually happens. Recruitment does not need a separate privacy department. But employers do need a repeatable process for handling CVs, interviews, recruitment platforms, talent pools and candidate rights. Use this checklist to review your recruitment process from the first application to final deletion. ## Before opening the vacancy - [ ] Define which applicant data is actually necessary. - [ ] Remove unnecessary questions from application forms. - [ ] Identify the purposes of the processing. - [ ] Identify the appropriate legal basis for each purpose. - [ ] Check whether special category or criminal-offence data may be involved. - [ ] Make sure recruitment is included in your record of processing activities. - [ ] Define retention periods. If you are unsure where the line sits, start with [what personal data you can collect from job applicants](/en/kennisbank/hr/applicant-data-what-to-collect) and record the result in your [record of processing activities](/en/kennisbank/hoe-gdprwise-werkt/records-of-processing-ropa). ## Candidate privacy information - [ ] Have a candidate privacy notice. - [ ] Make it available when personal data is collected. - [ ] Explain the purposes and legal bases. - [ ] Explain relevant data sources. - [ ] Identify recipients or categories of recipients. - [ ] Explain retention periods. - [ ] Cover international transfers where relevant. - [ ] Explain candidate rights. - [ ] Cover relevant automated decision-making where applicable. The structure of a [candidate privacy notice](/en/kennisbank/hr/candidate-privacy-notice) follows directly from these points. ## During recruitment - [ ] Limit access to people involved in the recruitment process. - [ ] Store applications in approved systems. - [ ] Avoid unnecessary copies of CVs. - [ ] Keep interview notes professional and relevant. - [ ] Verify important information rather than relying on assumptions. - [ ] Avoid collecting sensitive information without a lawful and necessary reason. - [ ] Have a process for candidate GDPR requests. Applicants can exercise the same [data subject rights](/en/kennisbank/rechten-en-verzoeken/gdpr-data-subject-rights) as anyone else, so the handling process has to cover recruitment data. ## Recruitment agencies and software - [ ] Identify all recruitment providers. - [ ] Determine their privacy role. - [ ] Put required data protection terms in place. - [ ] Check where candidate data is processed. - [ ] Review international transfers. - [ ] Check security and access controls. - [ ] Know how data can be deleted when retention periods expire. Where a provider acts as your processor, a [data processing agreement](/en/kennisbank/verplichtingen/processing-agreement) with the mandatory elements is required. ## LinkedIn and social media - [ ] Define whether online screening is permitted. - [ ] Limit checks to relevant sources and information. - [ ] Avoid unnecessary investigation of candidates' private lives. - [ ] Do not seek access to deliberately private profiles. - [ ] Tell candidates about external data sources where required. - [ ] Avoid recording irrelevant sensitive information. The rules differ between [checking a candidate's LinkedIn profile](/en/kennisbank/hr/checking-candidate-linkedin) and broader [social media screening](/en/kennisbank/hr/social-media-screening-applicants), so decide in advance which is allowed in your process. ## Talent pools - [ ] Treat future recruitment as a defined purpose. - [ ] Choose and document the appropriate legal basis. - [ ] Tell candidates how the talent pool works. - [ ] Set a retention period. - [ ] Keep information accurate. - [ ] Make opting out or withdrawing consent easy where applicable. - [ ] Delete expired records. Building a [GDPR compliant talent pool](/en/kennisbank/hr/gdpr-compliant-talent-pool) deliberately is far easier than trying to justify one after the fact. ## AI in recruitment - [ ] Approve AI tools before candidate data is uploaded. - [ ] Check what the provider does with submitted data. - [ ] Minimise or pseudonymise data where possible. - [ ] Assess automated decision-making risks. - [ ] Check whether the AI Act applies and whether the system is high-risk. - [ ] Ensure human oversight is meaningful. - [ ] Consider whether a DPIA is required. - [ ] Test outputs for accuracy and potential bias. Both [AI in recruitment](/en/kennisbank/hr/ai-in-recruitment) and the [DPIA requirement](/en/kennisbank/verplichtingen/dpia-guide) deserve a proper look before a tool goes live. ## When the candidate is hired - [ ] Review the recruitment file. - [ ] Transfer only information that remains necessary. - [ ] Apply appropriate employment retention rules. - [ ] Delete unnecessary recruitment data. - [ ] Update access rights. - [ ] Provide staff privacy information. This is the moment to work out [what happens to applicant data when a candidate becomes an employee](/en/kennisbank/hr/applicant-data-becomes-employee) and to hand over your [employee privacy policy](/en/kennisbank/hoe-gdprwise-werkt/employee-privacy-policy). ## When the recruitment procedure ends - [ ] Start the relevant retention period. - [ ] Delete information when the period expires. - [ ] Include email inboxes and local copies. - [ ] Remove data from external systems where required. - [ ] Keep talent-pool data separate from ordinary rejected applications. - [ ] Periodically test whether deletion actually happens. If you have not fixed the periods yet, decide [how long you can keep a candidate's CV](/en/kennisbank/hr/how-long-keep-cv) first. ## Make the checklist repeatable GDPR compliance works best when these steps are built into the recruitment process rather than checked once a year. GDPRWise helps employers map recruitment and other HR processing activities, document retention and legal bases, manage providers and generate the privacy documentation that supports a repeatable compliance process. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### The Most Common GDPR Mistakes in Recruitment URL: https://gdprwise.eu/en/kennisbank/hr/recruitment-gdpr-mistakes/ Summary: Fourteen recruitment privacy mistakes employers make most often, from keeping every CV forever to pasting candidate data into AI tools, and what to do instead. Key takeaways: - Recruitment data should not be collected or kept "just in case". - Consent is not the answer to every recruitment processing activity. - Informal tools and copies are often where retention and security fail. - New recruitment technology should be assessed before real candidate data is used. FAQ: Q: Is consent the right legal basis for recruitment? A: Not for everything. Consent is one GDPR legal basis, not a universal recruitment checkbox. Parts of the recruitment process may rely on steps taken at the candidate's request before entering into a contract, on legitimate interests, on legal obligations or on another appropriate basis. Choose the basis according to the purpose. Q: Can we keep rejected CVs in case a suitable role comes up? A: Not by default. Keeping rejected candidates because you might call them someday creates an additional processing purpose. If you want a talent pool, create one deliberately, with a legal basis, transparency, a retention period and a deletion process. Q: What is wrong with searching every candidate on social media? A: Public does not mean unprotected. Social media searches can expose hiring managers to sensitive and irrelevant information, and they create both privacy and discrimination risks. Limit online checks to situations where they are justified and job-relevant. Q: Can we rely on an AI screening score? A: An algorithmic score is an output, not a guarantee of truth or fairness. Check the accuracy, relevance and bias of the score, and check the role of the human decision-makers. Fully automated significant decisions may trigger specific GDPR rules. Most recruitment privacy problems are not caused by sophisticated technology. They come from ordinary habits: old CVs in inboxes, unnecessary questions, informal social media searches and candidate data copied into new tools without anyone checking the consequences. Here are the mistakes employers should look for first. ## 1. Keeping every CV forever An inbox containing ten years of applications is not a talent pool. Define why applicant data is retained and for how long. When the purpose and justified retention period end, delete the data. If you have never set the periods, work out [how long you can keep a candidate's CV](/en/kennisbank/hr/how-long-keep-cv) before anything else. ## 2. Asking for too much information Application forms often accumulate questions over time. If nobody can explain why a piece of information is necessary for the recruitment decision, remove the question. Data minimisation starts before the candidate clicks "Submit". ## 3. Using consent for everything Consent is one GDPR legal basis, not a universal recruitment checkbox. Parts of the recruitment process may rely on steps taken at the candidate's request before entering into a contract, legitimate interests, legal obligations or another appropriate basis. Choose the legal basis according to the purpose. The [six GDPR legal bases](/en/kennisbank/verplichtingen/gdpr-legal-bases) each fit different parts of a hiring process. ## 4. Having no candidate privacy notice A website privacy statement about customers and cookies does not explain recruitment. Candidates need relevant information about how their application data is processed, which is what a dedicated [candidate privacy notice](/en/kennisbank/hr/candidate-privacy-notice) is for. ## 5. Creating an accidental talent pool Keeping rejected candidates because "we might call them someday" creates an additional processing purpose. If you want a talent pool, create one deliberately with a legal basis, transparency, retention period and deletion process. ## 6. Searching every candidate on social media Public does not mean unprotected. Social media searches can expose hiring managers to sensitive and irrelevant information and create both privacy and discrimination risks. Limit online checks to situations where they are justified and job-relevant. The same reasoning applies to [screening applicants' social media profiles](/en/kennisbank/hr/social-media-screening-applicants). ## 7. Letting CVs spread everywhere A candidate sends one CV. A week later it exists in six email inboxes, two downloads folders and a shared drive. Use controlled systems and limit unnecessary copies. ## 8. Forgetting recruitment agencies and software Candidate data may be processed by recruiters, applicant tracking systems, assessment providers, cloud services and other suppliers. Know who receives the data and put the appropriate arrangements in place, starting with a [data processing agreement](/en/kennisbank/verplichtingen/processing-agreement) where the provider acts as your processor. ## 9. Pasting CVs into AI tools without checking Generative AI makes it extremely easy to upload personal data to a new provider. Before using real CVs, understand the provider's terms, retention, training practices, security, transfers and deletion options. The questions to ask are the same ones covered in [using ChatGPT or AI tools to review CVs](/en/kennisbank/hr/chatgpt-cv-screening). ## 10. Treating AI scores as objective facts An algorithmic score is an output, not a guarantee of truth or fairness. Check accuracy, relevance, bias and the role of human decision-makers. Fully automated significant decisions may trigger [specific GDPR rules on automated decision-making](/en/kennisbank/rechten-en-verzoeken/automated-decision-making-rights). ## 11. Moving the entire recruitment file into HR Once the candidate becomes an employee, review what information is still needed. Do not automatically keep every interview note, assessment and old recruitment record for the duration of employment. ## 12. Writing a retention policy but never deleting anything A policy that says "CVs are deleted after X months" does not help if no system or person actually performs the deletion. Test the process. ## 13. Giving too many people access Not everyone in the organisation needs access to every application. Use role-based access and review permissions when recruitment ends. ## 14. Ignoring candidate rights Applicants are data subjects too. Your organisation should be able to deal with access, rectification, erasure, objection and other applicable GDPR requests relating to recruitment data. ## Turn good intentions into a process Most recruitment GDPR mistakes are manageable once recruitment is treated as a defined processing activity rather than a collection of emails and informal habits. GDPRWise helps organisations document recruitment, retention, providers and privacy information in one structured compliance process. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Using AI in Recruitment: What Employers Need to Know URL: https://gdprwise.eu/en/kennisbank/hr/ai-in-recruitment/ Summary: AI can draft vacancies, summarise CVs and rank applicants, but it does not shift your GDPR responsibilities. What employers must check before deploying recruitment AI. Key takeaways: - Using AI does not transfer your GDPR responsibilities to the AI provider - Understand what candidate data enters the system and what the provider does with it - AI used to filter applications or evaluate candidates is classified as high-risk under the AI Act, with those obligations applying from 2 December 2027 - Human oversight must be meaningful, not merely a rubber stamp FAQ: Q: Does using an AI tool make the provider responsible for GDPR compliance? A: No. As the employer you decide why and how candidate data is processed, so you remain responsible under the GDPR. The provider typically acts on your instructions, which is exactly why you need to check its terms, retention and security arrangements before uploading anything. Q: Is every use of AI in recruitment high-risk under the AI Act? A: No. The AI Act classifies systems by what they are intended to do. Certain AI systems intended for recruitment or candidate selection, for example to analyse and filter applications or evaluate candidates, are classified as high-risk. Using a general tool to improve the wording of a vacancy is a different situation. Q: Do I need a DPIA before using AI in recruitment? A: Depending on the nature and risk of the processing, a Data Protection Impact Assessment may be required under the GDPR. Carry out the assessment before deployment rather than after complaints arrive. AI Act compliance may require additional risk management, documentation and human oversight measures on top of that. Q: What counts as meaningful human oversight? A: A reviewer who genuinely examines the application, understands the system's limitations and has the authority to reach a different outcome. Adding a person at the end of the process does not solve the problem if that person simply accepts the algorithm's recommendation. Following the Court of Justice's SCHUFA judgment, where the automated output is effectively decisive and the human adds no genuine assessment, the processing stays inside Article 22. AI can help employers write job descriptions, summarise CVs, rank applicants, schedule interviews and support hiring decisions. But recruitment involves decisions that can have a major impact on people's lives. That makes AI in recruitment an important area for both the GDPR and the EU AI Act. ## Start with the use case "Using AI in recruitment" can mean very different things. Examples include: - Drafting a vacancy - Summarising CVs - Extracting skills from applications - Ranking candidates - Analysing tests - Screening video interviews - Recommending candidates - Automatically rejecting applications The risk depends heavily on what the system actually does. Using AI to improve the wording of a vacancy is very different from allowing an algorithm to decide who gets an interview. ## What personal data enters the AI system? Before using an AI tool, identify the information you intend to provide. A CV may contain names, addresses, work history, education and other personal information. It may also contain photographs or sensitive information volunteered by the candidate. Apply data minimisation. If the task can be performed without identifiable candidate data, consider whether you need to upload the full CV at all. The same question applies when you [paste a CV into a general AI assistant](/en/kennisbank/hr/chatgpt-cv-screening). ## What does the provider do with the data? Ask: - Is candidate data retained? - For how long? - Is it used to train or improve models? - Who can access it? - Where is it processed? - Are subprocessors involved? - Can the data be deleted? - What contractual protections apply? Do not assume that because an AI tool is well known, it is automatically suitable for confidential recruitment data. Where the provider processes candidate data on your behalf, you will normally also need a [data processing agreement](/en/kennisbank/verplichtingen/processing-agreement). ## Add the AI provider to your Third Party Dossier If an external AI provider processes candidate data, make sure the provider is included in your [Third Party Dossier](/en/kennisbank/hoe-gdprwise-werkt/third-party-dossier). Document what the provider does, which personal data it receives, where the data is processed, whether subprocessors are involved and which contractual and data transfer arrangements apply. This ensures that the AI tool is treated like any other external provider processing personal data and does not become an undocumented part of your recruitment process. ## GDPR automated decision-making The GDPR contains specific rules concerning decisions based solely on automated processing that produce legal effects or similarly significantly affect individuals. A fully automated decision to reject a job applicant can therefore raise serious issues. Whether a particular process falls within these rules depends on how the system and human involvement actually work. Adding a person at the end of the process does not solve the problem if that person simply accepts the algorithm's recommendation. Where the automated output is effectively decisive and the human adds no genuine assessment, the processing remains within Article 22 GDPR. See [can AI automatically reject a job applicant?](/en/kennisbank/hr/ai-automatic-rejection) for what that means in practice. ## The AI Act matters too The EU AI Act regulates AI systems according to risk. Certain AI systems intended to be used for recruitment or selection, for example to analyse and filter applications or evaluate candidates, are classified as **high-risk** under the Act. High-risk status brings substantial obligations under the AI Act, and which of them fall on you depends on whether your organisation acts as provider, deployer or in another regulated role. On timing: these high-risk obligations were due to apply from 2 August 2026, but Regulation (EU) 2026/1744 deferred that date to 2 December 2027 for the standalone Annex III systems that cover recruitment. The Article 50 transparency obligations were not deferred and apply now. See [GDPR and the AI Act in recruitment](/en/kennisbank/hr/gdpr-ai-act-recruitment) for how the two frameworks fit together. ## Bias and accuracy AI systems can reproduce or amplify patterns in the data and criteria they use. An employer should therefore consider: - Whether the criteria are job-relevant - Whether outputs are accurate - Whether particular groups may be disadvantaged - How errors can be detected - How candidates can challenge decisions - Whether human reviewers understand the system's limitations GDPR accuracy and fairness principles remain relevant even when the processing is performed by software. ## Assess before you deploy Depending on the nature and risk of the processing, a [Data Protection Impact Assessment](/en/kennisbank/verplichtingen/dpia-guide) may be required under the GDPR. Do the assessment before deployment, not after complaints arrive. AI Act compliance may require additional risk management, documentation, human oversight and other measures. ## AI should support a controlled recruitment process The right question is not "Can AI save us time?" It is: **Can we use this particular system for this particular recruitment task in a lawful, transparent and controlled way?** GDPRWise helps organisations map the personal data, providers, purposes and risks involved in their processing activities, providing a structured GDPR foundation when new tools such as AI are introduced. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### What GDPR Documents Does an Employer Need? URL: https://gdprwise.eu/en/kennisbank/hr/employer-gdpr-documents/ Summary: The GDPR documentation employers actually need for HR and recruitment: processing records, privacy notices, retention rules, processor agreements, breach and rights procedures, and DPIAs. Key takeaways: - A privacy notice alone is not a complete GDPR compliance programme. - Employers should document their HR and recruitment processing activities. - Contracts, retention rules, security procedures and rights-handling processes may all be required. - The exact documentation depends on what your organisation actually does. FAQ: Q: Are small employers exempt from keeping a record of processing activities? A: No. Article 30(5) exempts organisations with fewer than 250 employees only where the processing is occasional, poses no risk to individuals and involves no special category or criminal conviction data. Recruitment, payroll and personnel administration are ongoing rather than occasional, and HR files routinely contain health or other special category data, so the exemption does not reach them. Almost every employer needs an HR record. Q: Is one retention period enough for all HR documents? A: No. Payroll records, unsuccessful applications, performance records and access logs may have very different legal and operational retention requirements. Define how long each category of HR information is kept rather than applying a single period across the board. Q: Do we need a data processing agreement with every HR supplier? A: You need one where the provider acts as your processor, and it has to contain the mandatory elements. First determine the role of each provider, because not every third party is necessarily your processor. Typical candidates include payroll providers, HR software, recruitment platforms, cloud services, benefits providers and training platforms. Q: When does an employer need a DPIA? A: A DPIA is required where processing is likely to result in a high risk to individuals' rights and freedoms. In an employment context that can apply to certain monitoring, biometric systems, large-scale sensitive-data processing, or higher-risk AI and profiling uses. Assess the requirement before implementing the processing. Employers process personal data every day: recruitment files, payroll information, absence records, evaluations, access logs, training records and much more. GDPR compliance is therefore not just about having an employee privacy notice. Employers need documentation that reflects how staff and candidate data is actually processed. ## 1. Record of processing activities Your record of processing activities is one of the central GDPR documents. For HR, it can cover processes such as: - Recruitment - Personnel administration - Payroll - Time registration - Absence management - Performance management - Training - Benefits - IT and access management - Workplace security - Termination and offboarding For each activity, document relevant information such as purposes, categories of data, data subjects, recipients, transfers, retention and security measures as required. The structure of a [record of processing activities](/en/kennisbank/hoe-gdprwise-werkt/records-of-processing-ropa) is the same for HR as for anything else. Small organisations regularly assume they are exempt. They are usually not. Article 30(5) lifts the record-keeping obligation for employers with fewer than 250 employees only where **all three** of the following hold: the processing is occasional, it is unlikely to result in a risk to individuals, and it involves no special category or criminal conviction data. HR fails the first condition on its own. Recruitment, payroll and personnel administration run continuously, not occasionally. Add sick leave records or anything else touching health, and the third condition fails too. In practice, if you employ people you need an HR record of processing, whatever your headcount. ## 2. Candidate privacy notice Applicants need information about what happens to their personal data during recruitment. The notice should cover the recruitment process, including relevant data sources, purposes, legal bases, recipients, retention periods, transfers and candidate rights. ## 3. Employee privacy notice Employees need appropriate information about staff data processing. This usually goes much further than recruitment and can include payroll, benefits, absence, performance, IT use, security and other employment processes. A full [employee privacy policy](/en/kennisbank/hoe-gdprwise-werkt/employee-privacy-policy) sets out each of those. ## 4. Retention policy or schedule Define how long different categories of HR information are kept. Do not use one retention period for every document. Payroll records, unsuccessful applications, performance records and access logs may have very different legal and operational retention requirements. A [data retention policy](/en/kennisbank/beveiliging/data-retention-policy) is where those differences get written down. ## 5. Data processing agreements Employers often use external service providers to process staff data. Examples include: - Payroll providers - HR software - Recruitment platforms - Cloud services - Benefits providers - Training platforms Where a provider acts as your processor, the GDPR requires an appropriate [data processing agreement](/en/kennisbank/verplichtingen/processing-agreement) containing the mandatory elements. First determine the role of each provider; not every third party is necessarily your processor. ## 6. Data breach procedure and register HR data can be involved in data breaches. Examples include: - A payslip sent to the wrong person - A lost laptop containing employee files - An HR account compromised by phishing - A spreadsheet with staff data shared with the wrong recipients Have a procedure for identifying, assessing and escalating incidents. Document personal data breaches as required, including relevant facts, effects and remedial action. ## 7. Data subject rights procedure Candidates, employees and former employees can exercise GDPR rights. Your organisation should know who handles requests, how identity is verified where necessary, where information is searched and how deadlines are monitored. ## 8. Legitimate interest assessments Where you rely on legitimate interests for processing that requires a balancing assessment, documenting that assessment is good accountability practice. This is particularly useful where processing could affect employees' or candidates' privacy expectations. ## 9. Data Protection Impact Assessments A DPIA is required where processing is likely to result in a high risk to individuals' rights and freedoms. In an employment context, this may become relevant for certain monitoring, biometric systems, large-scale sensitive-data processing or higher-risk AI and profiling uses. Assess the requirement before implementing the processing. ## 10. Security and access documentation HR information is often sensitive even where it is not legally classified as special category data. Document appropriate measures for: - Access control - Authentication - Confidentiality - Backups - Device security - Offboarding - Incident response Policies should match what actually happens in your systems. ## 11. International transfer documentation If HR or recruitment providers process personal data outside the EEA, assess the transfer mechanism and maintain the required documentation. Cloud software can create international transfers even when your organisation operates only in Europe. ## 12. AI governance documentation If you use AI in recruitment or employment, additional documentation may be needed under both GDPR and the EU AI Act. Start by documenting the use case, data involved, provider, purpose, legal basis, risks and human oversight. Higher-risk systems may require significantly more. ## Do you need all of these documents? Not every employer needs every document in exactly the same form. The correct approach is to start with your real processing activities and determine which documentation follows from them. A five-person business using a payroll provider and basic recruitment process will not have the same compliance file as an international employer using biometrics, monitoring and AI recruitment. But both need to know what personal data they process and why. ## Build the documents from the processing GDPR documentation should be the output of understanding your organisation, not a pile of disconnected templates. GDPRWise helps organisations map their HR and other processing activities and use that information to build and maintain the documentation their GDPR compliance requires. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### What Happens to Applicant Data When the Candidate Becomes an Employee? URL: https://gdprwise.eu/en/kennisbank/hr/applicant-data-becomes-employee/ Summary: Hiring someone does not make every piece of recruitment data necessary for the rest of their employment. Review the file, transfer what is still needed and delete the rest. Key takeaways: - Review the recruitment file when a candidate becomes an employee - Transfer only information that remains necessary for the employment relationship or another justified purpose - Delete recruitment information that no longer needs to be retained - Give the new employee appropriate privacy information about staff data processing FAQ: Q: Can I just move the whole application folder into the personnel file? A: No. Recruitment and employment are different purposes. During recruitment you process information to assess whether someone should be hired; once they are an employee your purposes change to payroll, personnel administration, benefits and similar matters. Some recruitment information remains relevant and some does not, so the file needs a review rather than a bulk transfer. Q: What can usually move to the personnel file? A: Depending on the role and applicable law, this might include identification and contact information, qualifications relevant to the job, employment history where still necessary, information used to prepare the contract, evidence of required professional credentials and relevant recruitment correspondence. Lawful collection during recruitment does not by itself justify permanent retention. Q: What should I look at deleting? A: Consider whether you still need interviewers' informal notes, old candidate rankings, rejected draft assessments, information about other vacancies, unnecessary copies of the CV, information collected from online searches and test data that has served its purpose. Some material may still need to be retained for a defined period, for example in connection with possible claims, but that does not mean it belongs in the permanent employee file. Q: Does the candidate privacy notice still cover the new employee? A: Do not assume it does. Candidates should have received information about recruitment processing, while employees need information about processing during employment: payroll, absence administration, IT systems, access control, performance management, training, benefits and other staff processes. The candidate signs the contract. Recruitment is finished. It may be tempting to move the entire application folder into the employee's personnel file and leave it there. Under the GDPR, hiring someone does not automatically make every piece of recruitment data necessary for the rest of their employment. ## Recruitment and employment are different purposes During recruitment, you process information to assess whether someone should be hired. Once they become an employee, your purposes change. You now need information for matters such as: - Payroll - Personnel administration - Benefits - Work planning - Performance management - Training - Legal and regulatory obligations - Workplace security Some recruitment information remains relevant. Other information does not. Treating the two as [separate processing activities in your register](/en/kennisbank/hoe-gdprwise-werkt/records-of-processing-ropa) makes the distinction easier to maintain. ## What can move to the personnel file? Depending on the role and applicable law, this might include: - Identification and contact information - Qualifications relevant to the job - Employment history where still necessary - Information used to prepare the contract - Evidence of required professional credentials - Relevant recruitment correspondence The fact that information was collected lawfully during recruitment does not automatically justify permanent retention. ## What should be reviewed? Consider whether you still need: - Interviewers' informal notes - Old candidate rankings - Rejected draft assessments - Information about other vacancies - Unnecessary copies of the CV - Information collected from online searches - Test data that has served its purpose Some material may still need to be retained for a defined period, for example in connection with possible claims. That does not mean it belongs in the permanent employee file, and your [retention policy](/en/kennisbank/beveiliging/data-retention-policy) should say where it lives and for how long. ## Update the privacy information Candidates should have received [information about recruitment processing](/en/kennisbank/hr/candidate-privacy-notice). Employees need information about the processing that takes place during employment. This may cover payroll, absence administration, IT systems, access control, performance management, training, benefits and other staff processes, which is what a [staff privacy policy](/en/kennisbank/hoe-gdprwise-werkt/employee-privacy-policy) is for. Do not assume the candidate privacy notice covers everything that happens after hiring. ## Update access rights Recruitment files may be accessible to interviewers or external recruiters who no longer need access once the process ends. Review permissions when the candidate is hired. The principle remains the same: personal data should be accessible only to people who need it for their role. ## Keep the transition controlled A useful onboarding step is: 1. Identify which recruitment data is still required. 2. Transfer or retain it for the appropriate purpose. 3. Apply the correct retention period. 4. Delete unnecessary copies. 5. Update system permissions. 6. Provide the employee privacy information. GDPRWise helps organisations distinguish between recruitment and staff processing activities, making it easier to manage personal data throughout the employee lifecycle. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### What Personal Data Can You Collect from Job Applicants? URL: https://gdprwise.eu/en/kennisbank/hr/applicant-data-what-to-collect/ Summary: Under the GDPR, applicant data must be relevant and necessary for recruitment. This article explains what you may ask candidates, what to avoid, and how to design an application form around necessity. Key takeaways: - You may collect personal data that is relevant and necessary for recruitment - Avoid asking for sensitive or private information unless there is a clear legal reason - Publicly available information is still personal data and remains protected by the GDPR - Review application forms regularly and remove questions you cannot justify FAQ: Q: Can I ask job applicants for a photograph? A: You can, but you should first consider whether seeing the candidate is genuinely necessary to assess their ability to do the job. In many recruitment processes it is not. Requiring unnecessary photographs also increases the risk that irrelevant characteristics influence your decision. Q: What should I do if a candidate sends me more information than I asked for? A: Candidates often include marital status, children, hobbies or medical details you never requested. You do not automatically need to use that information simply because it was supplied. Keep the recruitment decision focused on information that is relevant to the vacancy. Q: Can I collect applicant data from recruitment agencies or professional networks? A: Yes, but the GDPR still applies. You need a lawful reason for collecting and using the information and, where required, you must tell the candidate that you obtained personal data from another source. Q: Which applicant data counts as sensitive under the GDPR? A: Health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, certain biometric data, and sex life or sexual orientation. Processing this information generally requires an additional legal justification, so ordinary recruitment should avoid it. Criminal convictions and offences are subject to their own specific restrictions. Recruitment naturally requires information about candidates. But that does not mean an employer can collect any information that might be interesting or useful. Under the GDPR, applicant data must be relevant and necessary for the recruitment process. The basic rule is simple: **only collect what you genuinely need to assess the candidate and manage the application.** ## What information do employers normally need? For most vacancies, an employer will need fairly standard information, such as: - Name and contact details - Employment history - Education and qualifications - Professional skills and experience - Languages - Information contained in a CV or cover letter - Interview notes and assessments - Availability and, where relevant, salary expectations The exact information you need depends on the position. A driving licence may be relevant for a delivery driver. It is probably not relevant for an office job where driving is never required. This is the GDPR principle of **data minimisation** in practice. ## Can you ask for any information that might help you choose? No. Recruitment can easily become a process of collecting information "just in case". The GDPR requires a more disciplined approach. Before requesting information, ask: **Do we genuinely need this information to assess whether the candidate is suitable for this position or to comply with a legal requirement?** If the answer is no, don't collect it. ## Be careful with sensitive information Some personal data receives additional protection under the GDPR. This includes information about: - Health - Racial or ethnic origin - Political opinions - Religious or philosophical beliefs - Trade union membership - Genetic data - Certain biometric data - Sex life or sexual orientation Processing this information generally requires an additional legal justification on top of one of the [six legal bases](/en/kennisbank/verplichtingen/gdpr-legal-bases). In ordinary recruitment, employers should therefore avoid requesting sensitive information unless it is genuinely necessary and legally permitted. Information about criminal convictions and offences is also subject to specific restrictions. ## What about photographs? A photograph is personal data when a person can be identified from it. Before making a photograph mandatory, consider whether seeing the candidate is actually necessary for assessing their ability to perform the job. In many recruitment processes, it is not. Requiring unnecessary photographs can also increase the risk that irrelevant characteristics influence recruitment decisions. ## What if candidates provide too much information themselves? Candidates sometimes include information you never requested: marital status, children, hobbies, photographs, medical information or other private details. You do not automatically need to use that information simply because the candidate supplied it. Keep the recruitment decision focused on information relevant to the vacancy. ## Can you collect information from other sources? Applicant data does not always come directly from the applicant. You may receive information from: - Recruitment agencies - Professional networking platforms - References - Public professional registers - Assessment providers - Background-check providers The GDPR still applies. You must have a lawful reason for collecting and using the information and, where required, tell the candidate that you obtained personal data from another source. Your [candidate privacy notice](/en/kennisbank/hr/candidate-privacy-notice) is the natural place to explain this. ## Design your application process around necessity A useful exercise is to review every field in your application form. For each question, ask: 1. Why do we ask this? 2. Do we actually use the answer? 3. Is it necessary at this stage? 4. Could we request it later if the candidate is selected? Information needed to prepare an employment contract, for example, belongs at the offer stage rather than on the application form every candidate fills in. ## Document what you collect and why Do not decide what candidate data to collect on a case-by-case basis without documenting it. Your organisation should have a clear overview of the personal data used in recruitment, the purpose for which each type of data is collected, the applicable legal basis, who has access to it and how long it is retained. We recommend documenting this as part of your [records of processing activities](/en/kennisbank/hoe-gdprwise-werkt/records-of-processing-ropa). This should include your recruitment processing activities and the individual data items you use. Once a candidate becomes an employee, this should connect with your staff dossier and [Staff Privacy Policy](/en/kennisbank/hoe-gdprwise-werkt/employee-privacy-policy), which cover the broader processing of personal data during employment. ## Keep recruitment data under control Collecting less information makes GDPR compliance easier. It also reduces the amount of personal data that can be lost, misused or accessed by the wrong person. GDPRWise helps organisations document recruitment and other HR processing activities, including the categories of personal data they use and the reasons for processing them. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### When and How Should You Inform Candidates About the Use of Their Personal Data? URL: https://gdprwise.eu/en/kennisbank/hr/candidate-privacy-information/ Summary: Timing is where recruitment transparency goes wrong. When to give candidates privacy information for direct and indirect collection, and how to deliver it so it actually reaches them. Key takeaways: - Data collected directly from the candidate: inform them at the moment you collect it - Data received from an agency or platform: one month is the outer limit, not the deadline you will usually meet - First contact with the candidate and first disclosure to a recipient both come earlier and both override the month - The recruitment agency's own privacy notice does not discharge your obligation as controller FAQ: Q: When exactly do I have to give candidates privacy information? A: When you collect personal data directly from a candidate, Article 13 requires the information at the time the data is obtained. In practice that means the candidate privacy notice is linked from the application form or the vacancy page, visible before they submit. Q: What if I receive a CV from a recruitment agency instead of the candidate? A: Article 14 gives you three deadlines and the earliest one wins: within a reasonable period and at the latest one month after you receive the data; at the latest at your first communication with the candidate; or at the latest when you first disclose the data to another recipient. In recruitment you almost always contact the candidate well within the month, so the first communication is the real deadline. Q: Does the recruitment agency's privacy notice cover my obligations too? A: No. The agency informs candidates about what it does with their data. You are responsible for explaining what your organisation does with that data as controller. Put that split in writing in your arrangement with the agency, and check which of you is a controller for which processing. Q: Is my general website privacy statement enough for recruitment? A: Usually not. A statement written for customers and website visitors does not explain how you handle applications. Candidates need recruitment-specific information, reachable in one click from where they apply rather than buried several layers into your site. Most employers eventually write a candidate privacy notice. Far fewer get it to the candidate at the right moment, which is the part the GDPR is specific about. This article covers **when** you have to inform candidates and **how** to deliver that information. For the contents of the document itself, see [what a candidate privacy notice should contain](/en/kennisbank/hr/candidate-privacy-notice). ## Data you collect from the candidate When the candidate gives you their data directly, by filling in your application form, emailing their CV or applying through your careers page, Article 13 applies. The rule is simple: the information must be provided **at the time the data is obtained**. Not in the rejection email, not when the candidate asks. In practice this means the [candidate privacy notice](/en/kennisbank/hr/candidate-privacy-notice) is linked from the application form itself and is visible before the candidate presses send. ## Data you receive from somewhere else When a recruitment agency, a job board, a professional platform or a referrer sends you a candidate's data, Article 14 applies instead. It sets **three deadlines, and the earliest one that occurs is your deadline**: | Trigger | Deadline | | --- | --- | | Receipt of the data | Within a reasonable period, at the latest one month | | First communication with the candidate | At the latest at that first communication | | First disclosure to another recipient | At the latest when you first disclose | The one-month period is the outer limit. It is not a grace period, and in recruitment it is almost never the deadline that actually applies, because you contact the candidate or forward their file long before a month has passed. ### What this looks like in practice An agency sends you three CVs on Monday. On Wednesday you email one of those candidates to invite them for an interview. That Wednesday email is your first communication. The privacy information has to reach the candidate **with that email or before it**, not within a month of Monday. In practical terms: include the link in the interview invitation, or send the notice as a separate message first. Now suppose that on Tuesday, before contacting anyone, you forward all three CVs to a hiring manager in a sister company that acts as a separate controller. That is a disclosure to another recipient, and it pulls your deadline forward to Tuesday for all three candidates, including the two you never contact. The workable rule for a recruitment team: **inform the candidate as soon as their file lands in your system**, and you will never need to work out which trigger came first. ### The exceptions are narrower than they look Article 14(5) removes the obligation where the candidate already has the information, where providing it proves impossible or would involve disproportionate effort, or where obtaining or disclosing the data is laid down by law. Do not lean on disproportionate effort. You have the candidate's contact details, you intend to use them, and sending a link costs nothing. Where the agency has genuinely already given the candidate your identity and your purposes, document that rather than assuming it. ## What if a recruitment agency sends you the CV? The agency's privacy notice does not discharge your obligation. The agency explains what **it** does with candidate data. You are responsible for explaining what **your organisation** does with it once you act as controller. Settle two things in your arrangement with the agency: - Who is controller for which processing, and whether any part of it makes you joint controllers - Whether the agency will hand candidates your notice on your behalf, and how you evidence that it happened If the agency processes data on your instructions rather than its own, your [data processing agreement](/en/kennisbank/verplichtingen/processing-agreement) should reflect that. ## How to deliver the information The obligation is to provide the information, not to bury it somewhere it could theoretically be found. What works: - A link on the application form and the vacancy page, visible before submission - A link in the automatic acknowledgement your applicant tracking system sends - A link in the interview invitation, which doubles as the Article 14 trigger for agency candidates - A layered notice: a short summary with the essentials, linking through to the full document What does not work: a general website privacy statement written for customers, a notice reachable only through the site footer and three further clicks, or a PDF sent after the process is over. Whichever route candidates take into your organisation, the information they receive should be the same. Check your application page, your email templates, your recruitment platform and your agency arrangements together. ## Make it readable A candidate privacy notice is not improved by sounding like a statute. Candidates should be able to work out what you use, why, who receives it, how long you keep it and what rights they have, without a second reading. Plain language and a logical structure do more for compliance here than length. ## Say something specific about AI If automated systems are used anywhere in your selection, transparency stops being a formality. Articles 13(2)(f) and 14(2)(g) require meaningful information about the logic involved, and about the significance and envisaged consequences, where [automated decision-making](/en/kennisbank/rechten-en-verzoeken/automated-decision-making-rights) within Article 22 takes place. Even where the system stops short of that, tell candidates what it does. A screening tool that a candidate discovers only after rejection is a complaint waiting to happen. ## Candidates who become employees The information you give during recruitment explains the application process. Once someone is hired you process considerably more data, for different purposes. Keep them separate. A [Staff Privacy Policy](/en/kennisbank/hoe-gdprwise-werkt/employee-privacy-policy) covers the employment relationship, and the candidate notice stays focused on recruitment. New joiners should receive the staff policy at the start of employment, not be left with the recruitment notice. import TemplateTip from '@/components/TemplateTip.astro'; Upload your current staff privacy policy and see which GDPR elements are missing before your next hire starts. GDPRWise helps organisations generate and maintain privacy documentation based on the personal data processing activities they have documented, including HR and recruitment. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### When Should Applicant Data Be Deleted? URL: https://gdprwise.eu/en/kennisbank/hr/when-delete-applicant-data/ Summary: Recruitment creates data faster than most organisations delete it. Here is how to decide when applicant data must go, and where the forgotten copies usually hide. Key takeaways: - Delete applicant data when it is no longer necessary for the purpose for which you hold it. - Different parts of the recruitment file may have different retention periods. - A retention policy is not enough unless deletion actually happens. - Remember copies in email, shared drives and external recruitment tools. FAQ: Q: Is there a fixed moment when applicant data must be deleted? A: No. There is no single moment at which every piece of applicant data must always be deleted. Ask why you still hold it: during recruitment you need it to assess candidates, afterwards you may retain some information for a limited period for a legitimate reason, and when no valid purpose remains the data should be deleted or irreversibly anonymised. Q: Does the whole recruitment file have the same retention period? A: Not necessarily. A recruitment file can contain a CV, cover letter, interview notes, test results, reference information, correspondence, identity documents and internal scoring sheets. Do not assume that because one item needs to be retained, the entire file must remain intact. Q: What happens to the file of a candidate we hire? A: Some recruitment data becomes relevant to the employment relationship, but that does not mean the complete recruitment file should automatically become part of the permanent personnel file. Transfer what is needed and delete what no longer serves a purpose, subject to any justified retention requirements. Q: Why do deletion processes usually fail? A: Because organisations think only about the central HR system. If your official system deletes candidates after a year but hiring managers keep copies in inboxes, shared drives, spreadsheets or agency portals, your retention policy is not actually working. Recruitment creates data quickly: CVs, interview notes, emails, assessments and candidate profiles. Without a deletion process, these files can remain scattered across an organisation for years. The GDPR requires personal data to be kept no longer than necessary. That means recruitment needs an end-of-life process as well as an application process. ## Start with the purpose There is no single moment at which every piece of applicant data must always be deleted. Ask why you still hold it. During recruitment, you need information to assess candidates and manage the procedure. Afterwards, some information may be retained for a limited period for a legitimate reason, including where necessary in relation to possible claims. Our guide on [how long you can keep a candidate's CV](/en/kennisbank/hr/how-long-keep-cv) works through that window in more detail. If a candidate joins a properly managed talent pool, relevant information may be kept for that separate purpose. When no valid purpose remains, the data should be deleted or irreversibly anonymised. ## Not every document needs the same retention period A recruitment file can contain many things: - CV - Cover letter - Interview notes - Test results - Reference information - Email correspondence - Identity documents - Internal scoring sheets Do not assume that because one item needs to be retained, the entire file must remain intact. Apply data minimisation throughout the retention period. ## What about the successful candidate? When someone is hired, some recruitment data will become relevant to the employment relationship. That does not mean the complete recruitment file should automatically become part of the permanent personnel file. Transfer information that is needed and delete information that no longer serves a purpose, subject to any justified retention requirements. There is [a separate decision to make at the moment an applicant becomes an employee](/en/kennisbank/hr/applicant-data-becomes-employee). ## Where is applicant data hiding? Deletion often fails because organisations think only about the central HR system. Check: - Individual email inboxes - Shared HR mailboxes - Hiring managers' folders - Shared drives - Applicant tracking systems - Recruitment agency portals - Assessment platforms - Spreadsheets - Downloaded CVs - AI tools used during recruitment If your official system deletes candidates after a year but managers keep copies indefinitely, your retention policy is not working. ## Use deletion triggers Useful triggers include: - Vacancy closed - Candidate rejected - Candidate hired - Post-recruitment retention period expired - Talent-pool period expired - Candidate withdraws consent where applicable - Candidate successfully exercises a [right to erasure](/en/kennisbank/rechten-en-verzoeken/right-to-erasure) where the legal conditions are met Automation can help, but it should be configured correctly and tested. ## Document responsibility Someone should know who is responsible for implementing the retention schedule. A practical [recruitment retention policy](/en/kennisbank/beveiliging/data-retention-policy) identifies: - The categories of information - The relevant purposes - The retention periods or criteria - The systems concerned - The person or team responsible - The deletion or anonymisation method GDPRWise helps organisations record retention periods for their processing activities and keep recruitment data management connected to the wider GDPR compliance process. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ## Misconceptions ### Misconception: GDPR Is a Passing Trend That Will Blow Over URL: https://gdprwise.eu/en/kennisbank/misvattingen/gdpr-passing-trend/ Summary: Some business owners are waiting it out, hoping GDPR will disappear or be weakened. But GDPR is permanent European legislation and similar laws are being introduced worldwide. Waiting only makes it more expensive. Key takeaways: - GDPR is a European regulation with direct effect, not temporary policy that can be weakened - Enforcement gets stricter every year: total fines grew from $400 million in 2019 to over $4 billion cumulative in 2024 - More than 150 countries have now introduced or are preparing similar privacy legislation - The longer you wait, the bigger the gap between what you do and what you should be doing FAQ: Q: Can the GDPR be abolished? A: Technically any law can be amended, but abolishing GDPR would require unanimous agreement of all EU member states. The political will for that is completely absent. On the contrary, the EU is working on stricter digital rules such as the AI Act and the Digital Services Act. Q: Is GDPR enforcement actually getting stricter? A: Yes. The total amount of GDPR fines grows every year. Supervisory authorities are getting more budget and staff. Moreover, more complaints are being filed by citizens who know their rights. Q: Do other countries also have something like GDPR? A: Yes. Brazil has the LGPD, Canada is working on a renewed privacy law, many US states have their own privacy laws (California, Virginia, Colorado), and countries like Japan, South Korea, and India have introduced comparable legislation. ## The misconception "GDPR is just another regulation that will be watered down or forgotten. If I wait long enough, the whole thing will blow over." We've heard this since 2018. And every year, the opposite happens: enforcement gets stricter, fines get higher, and more countries introduce their own versions of GDPR. ## GDPR is not going away The GDPR is a European regulation, not a directive. That means it has direct effect in all EU member states without needing national implementation. It cannot be weakened by individual countries, and amending it requires consensus among all 27 member states. There is zero political appetite to weaken privacy protection. If anything, the direction is towards **more** regulation: - The **AI Act** (2024) adds strict rules for artificial intelligence and automated decision-making - The **Digital Services Act** imposes new obligations on online platforms - The **Data Act** regulates access to and use of data generated by connected products - The **ePrivacy Regulation** (in progress) will replace the current cookie directive with stricter rules ## Enforcement is accelerating The numbers tell the story: - **2019**: approximately $400 million in total GDPR fines across Europe - **2020**: $300 million - **2021**: $1.3 billion - **2022**: $2.9 billion (cumulatively) - **2023**: $4.2 billion (cumulatively), including Meta's record $1.2 billion fine The trend is clear and irreversible. Supervisory authorities are getting more budget, more staff, and more experience. The initial "grace period" where authorities were lenient is long over. ## The world is following Europe's lead GDPR is not a European quirk. It has become the global template for privacy legislation: - **Brazil**: LGPD (in effect since 2020) - **California**: CCPA/CPRA (in effect, with more states following) - **Canada**: renewed privacy law (in progress) - **India**: Digital Personal Data Protection Act (2023) - **Japan, South Korea, Australia**: comparable frameworks - **Africa**: Kenya, South Africa, Nigeria have introduced privacy laws More than **150 countries** now have some form of data protection legislation. The direction is global convergence towards GDPR-like standards. ## The cost of waiting Every year you wait, the gap between where you are and where you need to be grows wider: - **More data accumulates** without proper documentation - **New tools and services** are added without processing agreements - **Employee turnover** means nobody knows what data is where - **The risk of a complaint** grows as consumers become more privacy-aware Getting compliant today costs less than getting compliant next year, because there's less to clean up. ## What should you do? Accept that GDPR is a permanent fixture of the business landscape, just like tax obligations and employment law. The sooner you treat it as business-as-usual rather than a temporary inconvenience, the less it costs and the more benefit you get from it. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Misconception: GDPR Is About Cookies URL: https://gdprwise.eu/en/kennisbank/misvattingen/gdpr-is-about-cookies/ Summary: Many business owners think GDPR is mainly about cookies. But cookies are just a small part. GDPR covers all personal data you process, in any form. Key takeaways: - GDPR covers all personal data you process, not just cookies on your website - Cookies partly fall under the ePrivacy Directive, not directly under the GDPR - Your customer database, personnel files, and supplier lists all fall under the GDPR - A cookie banner alone does not make you GDPR compliant FAQ: Q: Don't cookies fall under GDPR then? A: Partly. Cookies that process personal data fall indirectly under the GDPR, but the consent requirement for cookies comes from the ePrivacy Directive. The GDPR itself is much broader: it covers all processing of personal data, online and offline. Q: What else falls under the GDPR? A: Everything involving personal data processing: customer data in your CRM, personnel files, payroll administration, supplier contacts, email lists, camera footage, and yes, also cookies that can identify individuals. Q: Isn't a cookie banner enough for GDPR compliance? A: No. A cookie banner is a good start for your website, but GDPR compliance also requires a processing register, processing agreements with your processors, data breach procedures, and much more. ## The misconception "We've sorted our cookie banner, so we're GDPR compliant now." This is one of the most common misconceptions we encounter. And it's easy to see why: when GDPR came into effect in 2018, the most visible change for most people was the flood of cookie pop-ups on every website. So in many people's minds, GDPR became synonymous with cookies. But GDPR is not about cookies. Cookies are just one tiny piece of a much bigger puzzle. ## What GDPR actually covers The GDPR - General Data Protection Regulation - regulates how organisations process personal data. All personal data. In any form. Through any channel. That includes: ### Your customer data - Names, addresses, phone numbers in your CRM - Order history and purchase behaviour - Customer service tickets and correspondence - Newsletter subscription lists ### Your employee data - Employment contracts and salary information - Sick leave records - Performance reviews - Application materials from rejected candidates ### Your supplier data - Contact persons at your suppliers - Contract details with personal information - Payment records with individual names ### Your website data - Contact form submissions - Analytics data (IP addresses, browsing behaviour) - And yes, cookies - but as one item among many ## Where the cookie confusion comes from The consent requirement for cookies actually comes from the **ePrivacy Directive** (also known as the "cookie law"), not from the GDPR itself. The GDPR comes into play when cookies process personal data, but the cookie consent mechanism is a separate legal requirement. So when people say "GDPR = cookies", they're conflating two different laws. And in the process, they forget about 95% of what the GDPR actually requires. ## What a cookie banner does (and doesn't do) A properly configured cookie banner does: - Ask for consent before placing non-essential cookies - Offer a real choice (accept, refuse, or customise) - Block tracking scripts until consent is given A cookie banner does NOT: - Create a processing register - Generate processing agreements with your data processors - Set up a procedure for handling data subject requests - Document how you handle employee data - Establish a data breach notification procedure ## What you actually need for GDPR compliance 1. **Processing register** - a complete overview of all data processing activities 2. **Privacy policy** - a clear explanation of what you do with personal data 3. **Processing agreements** - contracts with every party that processes data on your behalf 4. **Data subject rights procedure** - how you handle access, deletion, and correction requests 5. **Data breach procedure** - what you do when something goes wrong 6. **Legal basis** - a valid reason for each type of data processing 7. **Data retention policy** - how long you keep data and when you delete it A cookie banner is important, but it's item 8 on a list of 8. Don't confuse the appetiser for the main course. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Misconception: GDPR Only Applies to Cloud Data URL: https://gdprwise.eu/en/kennisbank/misvattingen/gdpr-only-cloud-data/ Summary: Many businesses think the GDPR only applies to digital data in the cloud. But the GDPR covers all personal data - including paper files, local systems, and handwritten notes. Key takeaways: - The GDPR applies to personal data in any form: digital, on paper, handwritten, or verbally recorded - Paper personnel files, customer cards, and handwritten appointment books all fall under the GDPR - Local files on your computer or server are just as GDPR-relevant as data in the cloud - The form in which you store data doesn't matter - what matters is that it's personal data FAQ: Q: Do paper files really fall under the GDPR? A: Yes, if they form part of a filing system or are intended to be included in one. A structured folder with customer data or personnel files in a binder falls under the GDPR. Q: Does the GDPR also apply to data on my local computer? A: Absolutely. It doesn't matter whether data is in the cloud, on a local server, or on your laptop. If it's personal data that you process in a business context, it falls under the GDPR. Q: What should I do with old paper archives? A: Inventory what personal data they contain, determine whether you still need it, and destroy what is no longer necessary. What you keep must be secured - for example in a locked cabinet with limited access. ## The misconception "We moved everything to the cloud, so we're covered by GDPR. The data on our local server and in our filing cabinets? That's not GDPR territory." This misconception arises from the association between GDPR and technology. Because GDPR is often discussed in the context of websites, cookies, and cloud services, many business owners conclude that it only applies to digital data in the cloud. But the GDPR is technology-neutral. ## What the law actually says The GDPR applies to the processing of personal data "wholly or partly by automated means" AND to "non-automated processing of personal data which form part of a filing system". That last part is crucial. A filing system is any structured set of personal data that is accessible according to specific criteria. Your filing cabinet with customer files ordered alphabetically? That's a filing system. Your desk drawer with personnel contracts sorted by department? Filing system. ## Where personal data actually lives in your business ### On paper - Personnel files in binders - Customer cards or order forms - Signed contracts with names and addresses - Notes from meetings with personal details - Business cards collected at events ### On local systems - Spreadsheets on your computer - Documents on your local server - Email stored locally (Outlook PST files) - Scanned documents on shared drives ### In the cloud - CRM system - Cloud email (Gmail, Outlook 365) - Accounting software - HR platforms ### In less obvious places - WhatsApp messages on company phones - Voice recordings from customer service - CCTV footage - GPS data from company vehicles The GDPR covers all of these. The medium doesn't matter - the content does. ## What you need to do ### 1. Inventory everything Don't just map your digital systems. Include paper archives, local files, and non-obvious data sources in your processing register. ### 2. Secure paper files Store paper documents with personal data in locked cabinets. Limit access to those who need it. Shred documents when the retention period expires. ### 3. Don't forget local devices Encrypt laptops and external drives. Password-protect local files with personal data. Include local systems in your backup strategy. ### 4. Clean up old archives Check old paper files and local archives. If you're storing personal data you no longer need, destroy it securely. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Misconception: GDPR Only Applies to Large Companies URL: https://gdprwise.eu/en/kennisbank/misvattingen/gdpr-only-large-companies/ Summary: A persistent misconception is that the GDPR only applies to large companies. The truth: GDPR applies to every organisation that processes personal data, regardless of size. This article explains what that means for you. Key takeaways: - GDPR applies to every organisation that processes personal data, from freelancer to multinational - Even if you only have 2 employees and a customer list of 50 people, you fall under GDPR - There are some exemptions for small organisations, such as not being required to appoint a DPO, but the core obligations apply to everyone - Processing personal data is broader than you think: an email list, personnel file, or customer database already counts FAQ: Q: Does GDPR also apply to a freelancer? A: Yes. If as a freelancer you process personal data of clients, suppliers, or contacts, you fall under the GDPR. This applies even if you just maintain a customer list in Excel or store email addresses. Q: Are there really no exceptions for small businesses? A: There are some reliefs. Organisations with fewer than 250 employees only need to maintain a processing register if the processing is non-incidental - which in practice applies to virtually every business. And you don't always need to appoint a Data Protection Officer (DPO). But the core obligations apply to everyone. Q: Does a charity or foundation also have to comply with GDPR? A: Yes. Every organisation that processes personal data falls under the GDPR, including associations, foundations, and non-profit organisations. If you have a membership list, you process personal data. ## The misconception "GDPR is only for big tech companies, right? There are just five of us, that doesn't apply to us." This is perhaps the most widespread misconception about the GDPR. And it's understandable how it arose: the news always features fines for Google, Meta, or Amazon. From this, many business owners conclude that GDPR is a problem for the big players, not for SMEs. But the text of the law is crystal clear. ## What the law actually says Article 2 of the GDPR describes its scope. The regulation applies to the processing of personal data, wholly or partly by automated means, and to the non-automated processing of personal data which forms part of a filing system or is intended to form part of a filing system. Nowhere does it say: "only if you have more than X employees" or "only if your turnover exceeds Y." **Every organisation that processes personal data falls under the GDPR.** Full stop. ### What counts as processing personal data? Processing is a broad concept. It includes: - **Collecting** personal data (a contact form on your website) - **Storing** personal data (a customer list in Excel or your CRM) - **Using** personal data (sending a newsletter) - **Sharing** personal data (passing customer data to your accountant) - **Retaining** personal data (personnel files in your cabinet or on your server) If you do even one of these things - and virtually every business does - you fall under the GDPR. ## What does this mean concretely for small businesses? ### What you MUST do Regardless of your business size, you are required to: 1. **Have a legal basis** for every processing of personal data (consent, contract, legal obligation, legitimate interest, etc.) 2. **Be transparent** about what you do with personal data (privacy policy) 3. **Enter into processing agreements** with parties that process data on your behalf 4. **Respond to requests** from data subjects (access, deletion, rectification) within 30 days 5. **Report data breaches** to the supervisory authority within 72 hours if there is a risk to data subjects 6. **Maintain a processing register** (in practice required for virtually every business) ### Where you DO get relief There are some reliefs for smaller organisations: - You don't always need to appoint a **Data Protection Officer (DPO)**, unless your core activity consists of processing special categories of data or large-scale monitoring - A **Data Protection Impact Assessment (DPIA)** is only required for high-risk processing - **Documentation requirements** may be proportionate to your business size But note: these reliefs concern specific additional requirements. The core obligations apply to everyone. ## Real examples This is not theory. Supervisory authorities across Europe actively enforce against small organisations: - **Greece (2023)**: a small employer received a fine of **$8,000** for installing cameras without adequately informing employees - **Spain (2023)**: a local gym was fined **$7,000** for sharing members' health data without consent - **Italy (2022)**: a small webshop received a fine of **$10,000** for not honouring a deletion request - **Poland (2024)**: a sole trader received a fine of **$4,500** for lacking a processing register The supervisory authorities have repeatedly emphasised that business size does not exempt you from the GDPR. ## Why this is actually an opportunity Instead of seeing GDPR as a burden that doesn't apply to you, you can look at it differently. As a small business, you have an advantage: you probably process less personal data than a large company, which means your compliance is simpler. Most SMEs can get their GDPR basics in order in **a few weeks**. No month-long projects, no expensive consultants. Just get the basics right: ### 1. Map what you process Make a list of all personal data you process: customers, employees, suppliers, website visitors. That is your processing register. ### 2. Arrange your agreements Enter into processing agreements with your accountant, email provider, CRM vendor, and other processors. ### 3. Inform your customers and employees Draft a privacy policy that matches what you actually do. Not a copied document from the internet, but a clear explanation of your processing activities. ### 4. Make a plan for requests and incidents Know what to do when a customer asks for access or deletion. Know what to do in case of a data breach. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Misconception: I Don't Have Any GDPR Data URL: https://gdprwise.eu/en/kennisbank/misvattingen/i-have-no-gdpr-data/ Summary: Every business processes personal data. Customer names, email addresses, personnel files, supplier contacts - they are all personal data that fall under the GDPR. This article shows why you also have GDPR data. Key takeaways: - Every business processes personal data, even a sole trader without employees - Customer names, email addresses, phone numbers, and invoice data are all personal data - Data about suppliers, business contacts, and applicants also falls under the GDPR - The definition of personal data is very broad: anything that can identify a person FAQ: Q: Are business email addresses also personal data? A: Yes. An email address like john.smith@company.com contains a name and is therefore personal data. Even a generic address like info@company.com can be personal data if you know who is behind it. Q: I'm a freelancer with no employees. Do I also have GDPR data? A: Yes. You have clients whose details you maintain (name, address, email, bank account for invoices). You have suppliers or clients with contact details. And you probably have a mailing list or contact list. These are all personal data. Q: Are company names also personal data? A: A company name in itself is not. But the contact person at that company, with name, email, and phone number, is personal data. And for sole traders, the business name is often the same as the owner's name. Q: What if I only work B2B? A: Even in B2B you process personal data. The contact persons at your customers and suppliers are natural persons. Their names, email addresses, and phone numbers are personal data that fall under the GDPR. ## The misconception "I don't have any personal data. I'm a plumber/consultant/builder - I don't collect data like Facebook does." This misconception comes from the association between "data" and big tech. When people hear "personal data", they think of databases with millions of records, user profiles, and behavioural tracking. That feels very far from a small business with a handful of clients. But the definition of personal data is much broader than most people realise. ## What is personal data? Personal data is any information that can directly or indirectly identify a natural person. That includes: ### The obvious - Full name - Home address - Phone number - Email address - Date of birth - National ID number or social security number ### The less obvious - IP address - Location data - Customer number (if it can be linked to a name) - Photos of identifiable people - Voice recordings - Vehicle registration plates - CCTV footage ## Where you have personal data (and probably don't realise it) ### Your phone - Contacts with names, numbers, and email addresses - WhatsApp conversations with customers - Photos from job sites with identifiable people - Call history ### Your computer - Email inbox with customer correspondence - Spreadsheets with customer or supplier lists - Invoices with names, addresses, and bank details - Quotes with contact information ### Your accounting - Invoices with customer names and addresses - Bank statements showing payment details - VAT returns with client information - Salary records for employees ### Your website - Contact form submissions - Newsletter sign-ups - Analytics data (IP addresses, browsing behaviour) - Customer reviews with real names ### Your physical workspace - Business cards in a drawer - Notes with customer details - Personnel files in a cabinet - Signed contracts ## The bottom line If you run a business, you process personal data. There are virtually no exceptions. A plumber who saves customer addresses for quotes processes personal data. A consultant who keeps a contact list processes personal data. A builder who photographs completed work with identifiable neighbours in the frame processes personal data. The GDPR doesn't care about the volume. Whether you have 10 records or 10 million, the same rules apply. ## What to do about it Don't panic. Having personal data is normal and necessary for running a business. The GDPR doesn't prohibit processing personal data - it just requires you to do it responsibly: 1. **Know what you have** - make an inventory of the personal data you process 2. **Have a reason** - ensure you have a valid legal basis for each processing activity 3. **Be transparent** - tell people what you do with their data 4. **Keep it safe** - take reasonable security measures 5. **Don't keep it forever** - delete data you no longer need import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Misconception: If the Authorities Aren't Interested in Me, I'll Never Get in Trouble URL: https://gdprwise.eu/en/kennisbank/misvattingen/authorities-not-interested/ Summary: Many business owners think they're safe as long as the supervisory authority doesn't come knocking. But 89% of all GDPR enforcement starts with a citizen complaint, not an inspection. This article explains why waiting is a risky strategy. Key takeaways: - 89% of GDPR enforcement starts with a citizen complaint, not an inspection by the supervisory authority - A dissatisfied customer, former employee, or competitor can file a complaint with just a few clicks - The supervisory authority is obliged to handle every complaint, even if you're a small business - Proactively getting your affairs in order is many times cheaper than putting out fires afterwards FAQ: Q: Can anyone just file a complaint about my business? A: Yes. Any person whose data you process can file a complaint with the supervisory authority. This can be done online, via a simple form. The threshold is deliberately kept low. Q: What happens when a complaint is filed against me? A: The supervisory authority contacts you and asks for an explanation. You must then be able to demonstrate that you comply with GDPR: a processing register, processing agreements, privacy policy, etc. If you can't? An investigation may follow and possibly a fine. Q: Are there many complaints filed? A: Yes. The Dutch Data Protection Authority received over 25,000 privacy complaints in 2023. The Belgian Data Protection Authority receives thousands of reports annually. The number of complaints increases every year. ## The misconception "The supervisory authority has never contacted me. As long as they don't come knocking, I'm fine." Many business owners reason this way. And it's understandable: if nobody has ever contacted you about GDPR, it feels like a non-issue. But this reasoning has a dangerous blind spot. ## 89% starts with a complaint The majority of GDPR enforcement doesn't start with a supervisory authority deciding to investigate your business. It starts with someone who files a complaint. That someone can be: - **A customer** who asks to see their data and doesn't get a response - **A former employee** who discovers their personnel file was shared with a third party - **A website visitor** who notices tracking cookies are placed without consent - **A competitor** who reports that your privacy policy doesn't match reality - **A newsletter recipient** who never gave consent to receive your emails Filing a complaint is easy. In most EU countries, it's an online form that takes 10 minutes to fill out. The supervisory authority is then obliged to look into it. ## What happens after a complaint When the supervisory authority receives a complaint: 1. **They contact you** and ask for your side of the story 2. **They request documentation**: your processing register, privacy policy, processing agreements 3. **They assess** whether you comply with the GDPR 4. **If you don't comply**, they can issue a warning, an order to comply, or a fine The key question is not whether the supervisory authority will come to you proactively. The question is: can you demonstrate your compliance when they do come, triggered by a complaint? ## The complaint landscape is growing The number of privacy complaints grows every year: - The Dutch DPA received **25,000+ complaints** in 2023 - The Belgian DPA processes **thousands** of complaints annually - The French CNIL received over **16,000 complaints** in 2023 - The Irish DPC, responsible for many tech companies, saw a **30% increase** in complaints year over year Consumers are becoming more privacy-aware. They know their rights. And they use them. ## The hidden costs of a complaint Even if a complaint doesn't result in a fine, it costs you: - **Time**: preparing documentation, writing responses, attending meetings - **Money**: legal advice if the case is complex - **Stress**: the uncertainty of an ongoing investigation - **Reputation**: if the complaint becomes public or the data subject shares their experience Compare that to the cost of getting your basics in order: a few hours of work and a modest investment in tools. The math is simple. ## What should you do? Don't wait for the supervisory authority to come to you. Get your basics in order now: - **Processing register**: document what data you process and why - **Privacy policy**: inform your customers and website visitors - **Processing agreements**: contracts with parties that process data on your behalf - **Request procedure**: know how to respond when someone asks about their data - **Data breach procedure**: know what to do when something goes wrong These are not complex, expensive projects. They're basic business hygiene that protects you when a complaint comes in. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Misconception: My Website Is GDPR Compliant, So My Business Is Too URL: https://gdprwise.eu/en/kennisbank/misvattingen/website-compliant-means-business-compliant/ Summary: A cookie pop-up and privacy policy on your website don't make your business GDPR compliant. Real compliance goes much further than your website. This article explains what you're missing. Key takeaways: - A cookie pop-up and privacy policy on your website are just the tip of the iceberg - GDPR requires you to map all personal data, not just what's on your website - You probably share personal data with more parties than you think (accountant, payroll provider, insurer) - A copied privacy policy from the internet can make things worse if it doesn't match your business FAQ: Q: Isn't a cookie banner enough then? A: No. A cookie banner only handles consent for cookies on your website. GDPR covers all personal data you process, including outside your website: customer data, personnel files, supplier contacts, and so on. Q: What else do I need to do besides my website? A: You need to create a processing register of all activities involving personal data, enter into processing agreements with your processors, create a privacy policy that matches your actual processing, and set up procedures for data breaches and data subject requests. Q: Can't I just copy a privacy policy from the internet? A: That's risky. If the privacy policy doesn't match what your business actually does, it can work against you during an inspection. The supervisory authority will see that you have a document that doesn't match reality. ## The misconception "We've got our website sorted - cookie banner installed, privacy policy published. GDPR? Done." This is one of the most common - and most dangerous - misconceptions about the GDPR. Your website is the most visible part of your data processing, but it's just the tip of the iceberg. ## What your website covers (and what it doesn't) Your website compliance typically includes: - A cookie consent banner - A privacy policy page - Secure forms (HTTPS) - Google Analytics or tracking tools configured with consent That's important, but it covers perhaps **10-15%** of your total GDPR obligations. ## What you're probably missing ### Your customer data outside the website - CRM system with customer records - Email correspondence with clients - Invoices with personal details - Customer service logs ### Your employee data - Employment contracts - Salary and tax records - Sick leave administration - Performance reviews - Application materials ### Your third-party sharing - Accountant (sees financial and personal data) - Payroll provider (processes salary data) - IT provider (has access to your systems) - Cloud storage (stores your files) - Email tool (processes subscriber data) For each of these, you need a **processing agreement** (DPA). Without it, you're not compliant, regardless of how perfect your website is. ### Your procedures - How do you handle an access request from a customer? - What do you do when you discover a data breach? - How long do you retain different types of data? - Who in your organisation is responsible for privacy? ### Your documentation - Processing register (overview of all data processing activities) - Data retention policy - Data breach procedure - Employee privacy policy ## The danger of a copied privacy policy Many businesses copy a privacy policy from another website or use a free template without customisation. This can actually make things worse: - If the policy mentions processing activities you don't do, it looks like you haven't thought about it - If the policy omits processing activities you do perform, it fails to inform your data subjects - A supervisory authority will compare what your policy says with what you actually do - discrepancies are a red flag ## A complete picture Think of GDPR compliance as a building. Your website is the facade - it's what people see first. But behind the facade, you need: - **Foundation**: processing register and legal bases - **Walls**: processing agreements with all your data processors - **Roof**: procedures for data breaches and data subject requests - **Interior**: employee training and awareness - **Maintenance**: regular reviews and updates A beautiful facade on a building without walls doesn't pass inspection. ## What to do 1. **Start with your website** - yes, get the cookie banner and privacy policy right 2. **But don't stop there** - map all your data processing, not just what happens online 3. **Check your third parties** - do you have processing agreements with everyone who handles data on your behalf? 4. **Set up procedures** - know what to do when someone asks about their data or when something goes wrong 5. **Document everything** - your processing register is the backbone of your compliance import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Misconception: Small Businesses Don't Get GDPR Fines URL: https://gdprwise.eu/en/kennisbank/misvattingen/small-business-no-gdpr-fine/ Summary: The idea that GDPR fines are only for tech giants is wrong. Smaller fines for SMEs are being issued more frequently, and complaints from customers or employees pose an even greater risk than the fine itself. Key takeaways: - Supervisory authorities across Europe are increasingly issuing fines to small and medium-sized businesses - The biggest risk for SMEs is not the mega-fine, but complaints from customers and employees that cost time, money, and reputation - A fine of $5,000 to $25,000 is relatively just as painful for an SME as million-euro fines are for large companies - When a complaint comes in, you must be able to demonstrate that you have the basics in order, otherwise the case escalates FAQ: Q: What is the lowest GDPR fine ever issued? A: Fines have been issued from as low as a few hundred euros. In Hungary, Romania, and Poland, fines of $500 to $2,000 have been imposed on small businesses. It's not about the amount, but the signal and the associated costs. Q: What does it cost if a customer files a complaint, even if I don't get fined? A: Even without a fine, a complaint procedure easily costs dozens of hours of administration, communication with the supervisory authority, and possibly legal advice. Plus the stress and reputation risk if it becomes public. Q: Do supervisory authorities consider my business size when determining fines? A: Yes. The GDPR requires fines to be proportionate. A small business won't receive the same fine as a multinational. But a fine of $10,000 can be just as impactful for a freelancer or small SME. ## The misconception "I'm just a small business. The supervisory authority has better things to do than fine me. Those GDPR fines are for Google and Facebook, not for me." It's a logical thought. You read in the news about billion-euro fines for Meta and Amazon. Why would the supervisory authority bother with your bakery, webshop, or consultancy? But reality is more nuanced - and more dangerous than you think. ## It's not just about the mega-fines The big fines make the news. Meta's $1.2 billion fine in 2023 was in every newspaper. But beneath that is an iceberg of smaller fines you never see in the news: - In **Germany**, the Lower Saxony supervisory authority issued a fine of **$12,500** to a small business that had no processing register - In **Spain**, a dental practice received a fine of **$5,000** for sending marketing emails without consent - In **Romania**, a small webshop was fined **$3,000** for not responding to an access request - In **Belgium**, the GBA imposed a fine of **$15,000** on an SME that used personal data for a purpose other than what it was collected for These are not incidents. According to the GDPR Enforcement Tracker, more than **2,100 fines** have been issued in Europe since 2018, and a significant portion involves businesses with fewer than 50 employees. ## The fine is not your biggest risk Here's where it gets really interesting. For most SMEs, the fine itself is not the biggest problem. It's the associated costs and consequences: ### Customer complaints When a customer files a complaint with the supervisory authority (the GDPR deliberately makes this easy), you must respond. That costs you: - **Time**: you must provide documents, give explanations, answer questions - **Money**: you may need legal advice - **Stress**: an investigation by the supervisory authority is unpleasant for any business owner ### Employee complaints Former employees who discover their data hasn't been processed correctly are a growing source of complaints. Especially when the departure wasn't entirely smooth. ### Reputation damage If a customer discovers you handle personal data carelessly, you lose trust. In a time when consumers are increasingly privacy-aware, that can cost you customers. ## Proportionate, but not painless The GDPR requires fines to be "effective, proportionate, and dissuasive". This means supervisory authorities consider your business size. A freelancer won't receive the same fine as Amazon. But proportionate does not mean painless: - A fine of **$5,000** is a significant blow for a sole trader - A fine of **$25,000** can represent a quarter's profit for an SME with 10 employees - The **administrative costs** of an investigation come on top of that And remember: the supervisory authority can also impose a **penalty payment**. That means you must stop a certain violation, and for every day you don't, you pay an amount. That adds up quickly. ## What you should do ### 1. Stop comparing yourself to Google The question is not whether you'll get the same fine as a tech giant. The question is whether you have the basics in order when a complaint comes in. ### 2. Get the basics right The most common violations by small businesses are surprisingly simple: - No processing register - No processing agreements with processors - Not responding to data subject requests (access, deletion) - Marketing emails without valid consent These are all things you can sort out in a few weeks. ### 3. Think about the customer, not the fine The best motivation for GDPR compliance is not fear of a fine. It's your customers' trust. Customers increasingly choose businesses that are transparent and careful with their data. ### 4. See it as business hygiene Just like you keep your bookkeeping in order and take out insurance, GDPR compliance is part of good business practice. It's not a luxury, it's a necessity. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ## News ### 12-Year-Old Girl Takes on Tech Giant TikTok Over Children's Data URL: https://gdprwise.eu/en/kennisbank/nieuws/tiktok-lawsuit-children-data/ Summary: A 12-year-old British girl was granted permission to file a class-action lawsuit against TikTok for collecting children's data without consent. What does this mean for businesses working with children's data? Key takeaways: - A British court granted a 12-year-old girl permission to file a class-action lawsuit against TikTok - The case revolves around collecting children's data without valid parental consent - The GDPR sets extra strict requirements for processing children's personal data - Businesses offering services to children must obtain consent from parents or guardians FAQ: Q: At what age can children give consent themselves under the GDPR? A: The GDPR sets the threshold at 16, but member states may lower it to a minimum of 13. In the Netherlands and Belgium, the threshold is 16. Below that age, parental or guardian consent is required. Q: Does this only apply to social media platforms? A: No. Every organisation processing children's personal data must take extra care. This applies to schools, sports clubs, webshops selling products to children, apps for children, and any other service aimed at minors. Q: What does TikTok risk? A: The class-action claim represents millions of children in the UK and the EU. The potential damages run into the billions. Additionally, multiple European supervisory authorities have already fined TikTok for similar violations. ## David vs. Goliath A judge at the UK High Court granted a 12-year-old girl, who may proceed anonymously, permission to file a class-action lawsuit against TikTok. The claim: the social media platform collects children's personal data on a massive scale without valid parental consent. The case represents millions of children in the UK and the EU who have used TikTok. It is one of the largest privacy cases ever filed on behalf of minors. ## What did TikTok do wrong? The core of the complaint is that TikTok: - **Collected children's data without parental consent** - children could create and use an account without any verification of parental consent - **Collected more data than necessary** - location data, device information, browsing behaviour, and biometric data (facial recognition in videos) - **Shared data with third parties** - advertisers and other parties gained access to children's data - **Provided insufficient transparency** - the privacy terms were not understandable for children or their parents ## Why this matters This case is significant for several reasons: ### Children receive extra protection The GDPR considers children as vulnerable data subjects who deserve extra protection. Article 8 sets specific rules for processing children's data, including the obligation to obtain parental consent. ### Class actions are becoming more common Until recently, privacy lawsuits were mainly between individuals and companies. Class actions make it possible to act on behalf of large groups of data subjects, enormously increasing the financial risks for violators. ### Supervisory authorities are watching Besides this lawsuit, multiple European supervisory authorities have taken action against TikTok. The Irish DPC imposed a fine of EUR 345 million, and the Italian authority temporarily blocked the processing of Italian users' data. ## The lesson for businesses You do not need to be a tech giant to deal with this issue. If your business offers services to children or processes minors' data, stricter rules apply: - **Age verification** - check whether users are old enough to give consent themselves - **Parental consent** - for children under 16 (in NL and BE), you need consent from a parent or guardian - **Understandable information** - your privacy notice must be understandable for the target audience - **Minimal data collection** - do not collect more than strictly necessary, especially with children - **No profiling** - profiling children for marketing purposes is not permitted in most cases Think of: sports clubs with youth members, schools with student data, webshops with products for children, apps used by minors, and events where children participate. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### B2B Marketplace Participants: Prepare for GDPR Enforcement URL: https://gdprwise.eu/en/kennisbank/nieuws/b2b-marketplace-enforcement/ Summary: The EDPB has issued guidelines on joint controllership for marketplaces. What does this mean if you operate through a B2B platform? Key takeaways: - The EDPB has clarified that marketplace participants can be joint controllers under GDPR - Both the platform and participants are responsible for GDPR compliance - B2B businesses operating through platforms must ensure their own compliance - Joint controllership requires a formal agreement between the parties FAQ: Q: What is joint controllership? A: When two or more parties jointly determine why and how personal data is processed, they are joint controllers. On a marketplace, both the platform and the seller determine how customer data is processed. Both parties share responsibility. Q: Do I need an agreement with the platform? A: Yes. Under joint controllership, the GDPR requires that the parties set out in an agreement who is responsible for what. Most major platforms address this in their terms and conditions. ## The EDPB provides clarity The European Data Protection Board (EDPB) has issued guidelines on the concept of controller under the GDPR. A key element: the clarification of joint controllership on online marketplaces. The example cited by the EDPB is clear: when a platform and its participants jointly determine how customer data is processed, they are joint controllers. This applies to B2C marketplaces, but equally to B2B platforms. ## What does this mean for B2B businesses? If you sell products or offer services through a B2B platform - such as bol.com business, Amazon Business, or a sector-specific marketplace - you may be a joint controller with that platform. This has concrete consequences: ### 1. You share responsibility If something goes wrong with customer personal data on the platform, you as a participant can be held accountable - not just the platform. ### 2. You need an agreement The GDPR requires joint controllers to set out in an agreement who is responsible for what. Check whether the platform's terms cover this. ### 3. Your own compliance must be in order The platform may impose requirements on your privacy policy, processing register, and security measures. Without these in place, you could be excluded from the platform. ## The trend is clear The direction of European regulation is unmistakable: businesses cannot hide behind platforms. Everyone in the chain involved in processing personal data bears responsibility. For B2B businesses operating through platforms, the advice is: ensure your own GDPR compliance is solid, and verify what arrangements the platform makes regarding joint controllership. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Court Takes Website Offline Over Non-Compliant Privacy Policy URL: https://gdprwise.eu/en/kennisbank/nieuws/court-website-offline-privacy/ Summary: A German court ordered a website to be taken offline because its privacy policy did not meet GDPR requirements. A warning for every business with a website. Key takeaways: - A German court forced a website owner to take the site offline due to a non-compliant privacy policy - A missing or inadequate privacy policy can be considered an unfair commercial practice - Competitors can take you to court if your privacy policy is not in order - A correct privacy policy is a basic requirement that many business owners underestimate FAQ: Q: Could this happen in the Netherlands or Belgium too? A: Yes. While the specific legal basis varies by country, competitors and advocacy organisations can also take action in the Benelux against businesses with a non-compliant privacy policy. The GDPR applies in all EU countries. Q: What must my privacy policy include at a minimum? A: The GDPR requires that you inform visitors about: who you are, what data you process, why, on what legal basis, how long you retain it, with whom you share it, what rights data subjects have, and how they can file a complaint. ## The case A German court issued a striking ruling: an organisation was required to take its website completely offline because the privacy policy did not meet GDPR requirements. If the site was not taken offline, the organisation faced a fine of 250,000 euros. The case was brought by a competitor who characterised the inadequate privacy policy as an unfair commercial practice. ## Why this matters This ruling shows that the risk of a non-compliant privacy policy extends beyond fines from the supervisory authority. Competitors and advocacy organisations can hold you accountable through civil law for your privacy shortcomings. This means you face risk not only from the data protection authority, but also from ordinary courts. ## The lesson for business owners ### Your privacy policy is not a formality Many business owners treat their privacy policy as a box-ticking exercise. But it is a legal document that must accurately reflect how you handle personal data. A generic template from the internet that has not been tailored to your specific situation is not sufficient. ### Competitors are watching In a competitive market, there are parties actively looking for violations by competitors. A missing or inadequate privacy policy is an easy target. ### The consequences can be far-reaching Having to take a website offline means: no online sales, no leads, no visibility. For many businesses, this is an existential problem. ## What should you do? Review your privacy policy. Is it a generic template, or does it actually reflect how your business handles personal data? GDPRWise generates a privacy policy based on your specific situation, so you can be sure all required elements are included. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Doctor Fined for Online Registration Form URL: https://gdprwise.eu/en/kennisbank/nieuws/doctor-online-form-fine/ Summary: A doctor was fined because his online registration form collected medical data without adequate security or valid consent. What went wrong and what can you learn from it? Key takeaways: - Medical data is special category data under the GDPR and requires extra protection - A standard contact form on your website is not suitable for collecting health data - You need a valid legal basis, and for health data the requirements are stricter - Security of online forms is your responsibility, even when using a third-party tool FAQ: Q: Can I collect health data via an online form? A: Only if you meet strict conditions: you have a valid legal basis (often explicit consent), the form is adequately secured (TLS, encrypted storage), you inform the data subject via a privacy notice, and you do not retain the data longer than necessary. Q: What is special category data? A: The GDPR distinguishes ordinary personal data (name, email, address) from special categories: health data, genetic data, biometric data, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, and trade union membership. Stricter rules apply to these categories. Q: Does this only apply to doctors? A: No. Any organisation collecting sensitive data through online forms faces the same risk: physiotherapists, psychologists, coaches, gyms requesting health declarations, HR departments collecting medical information from applicants. Q: What should I check on my own forms? A: Check whether your website uses TLS (https), whether form data is stored encrypted, whether you display a privacy notice before the form is submitted, whether you have a valid legal basis, and whether you have set a retention period. ## What happened? A general practitioner in Belgium offered an online registration form on his website for new patients. The form asked for name, address, date of birth, and contact details, but also for medical history, current medication, and allergies. The problem? The form was a standard website form without adequate security. Data was sent and stored unencrypted. There was no privacy notice linked to the form. And no explicit consent was requested for processing health data. The supervisory authority discovered the situation after a patient complaint and imposed a fine. ## Why this is so problematic ### Special category data Health data falls under the GDPR's "special category data." Article 9 prohibits processing this data unless a specific exception applies. For a doctor, that exception exists within the treatment relationship, but all security requirements must still be met. An online form collecting health data without adequate security violates multiple GDPR principles at once: - **Integrity and confidentiality** (Article 5(1)(f)) - the data was not adequately secured - **Transparency** (Article 5(1)(a)) - the patient was not properly informed about the processing - **Security** (Article 32) - no appropriate technical measures were in place ### It was not about the amount of data This was not a major breach involving thousands of records. It was about how sensitive data was collected: via an unsecured form, without consent, without transparency. The authority emphasised that the sensitivity of the data demands higher security standards. ## The lessons ### 1. Know your data Understand which data you collect via your website. A contact form with name and email is very different from a form asking about medical conditions or allergies. As soon as you collect health data or other special categories, stricter rules apply. ### 2. Secure your forms Every online form collecting personal data must at minimum: - Be hosted on a website with TLS (https) - Store data encrypted - Have access controls on stored data - Not forward data via unsecured email For sensitive data, additional requirements apply: encrypted storage, restricted access, and preferably a secure patient portal rather than an open web form. ### 3. Inform and obtain consent Attach a privacy notice to your form. Explain: - Which data you collect and why - How long you retain the data - With whom you share the data - How the data subject can exercise their rights For special category data, you often need explicit consent. A pre-ticked checkbox is not sufficient. ### 4. Use the right tools A standard contact form plugin is not designed for collecting medical data. Consider: - A secure patient portal - A form tool that meets GDPR requirements for sensitive data - A form that encrypts data locally before submission Also check where the data ends up. Is it stored with a third party? In which country? Do you have a data processing agreement? ## Not just for doctors This case involved a doctor, but the lesson applies to everyone collecting sensitive data through online forms: - **Physiotherapists and psychologists** offering intake forms online - **Gyms** asking for health declarations via their website - **HR departments** requesting medical information from applicants - **Coaches and therapists** with online intake questionnaires - **Insurers** handling health declarations digitally The message is clear: if you collect sensitive data via your website, make sure security and transparency are in order. ## Check your own forms Take a critical look at your website. Which forms do you have? What data do you collect? Where is it stored? Is the connection secure? Do you have a privacy notice? These are questions you can answer today. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Email Tracking Under Scrutiny: Is Your Organisation Prepared? URL: https://gdprwise.eu/en/kennisbank/nieuws/email-tracking-pixels-cnil/ Summary: The French regulator CNIL clarifies that tracking pixels in emails often require prior consent under the ePrivacy rules. What does that mean for your newsletters and email marketing? Key takeaways: - The CNIL clarifies that a tracking pixel in an email often falls under the European ePrivacy rules - For such tracking, prior consent from the recipient may be required - The recommendation comes from France, but is based on European law and may be followed by other regulators - Many organisations do not realise their email platform activates open tracking and click tracking by default FAQ: Q: What is a tracking pixel in an email? A: A tracking pixel is an invisible 1x1 image loaded inside an email. As soon as the recipient opens the email, the image is fetched from a server. This lets the sender register whether, when and sometimes from which device or location an email was opened. Q: Is a read receipt the same as a tracking pixel? A: No. A read receipt is sent by the recipient themselves, deliberately, from Outlook or another email client. A tracking pixel records automatically and usually without the recipient knowing. That distinction matters legally. Q: Does this recommendation apply outside France? A: The recommendation is from the French CNIL, but it rests on the European ePrivacy Directive and the GDPR. It is therefore quite possible that other European regulators will follow a similar approach. If you operate in the EU, it is wise to prepare in good time. ## Email tracking is under scrutiny Many businesses use software such as Mailchimp, HubSpot, Brevo, ActiveCampaign or Microsoft Dynamics to send newsletters and commercial emails. These emails often contain invisible tracking techniques that register whether a recipient has opened an email, when that happened and sometimes even from which device or location. These so-called **tracking pixels** have recently drawn growing attention from European privacy regulators. ## Why does this matter? The French privacy regulator CNIL has recently [published a recommendation](https://www.cnil.fr/fr/recommandation-pixel-suivi-courriels) clarifying that a tracking pixel in an email often falls under the European ePrivacy rules. That means such tracking may, in principle, require the recipient's prior consent. Although this recommendation comes from France, it is based on European law (the ePrivacy Directive and the GDPR). It is therefore not unthinkable that other European regulators will follow the same approach. For businesses operating in the EU, it is wise to prepare for this in good time. ## What should you check? We recommend verifying: - whether your organisation uses software that performs open tracking or click tracking; - whether this tracking is enabled by default; - which personal data is collected; - what this data is used for; - whether this data is linked to individual people; - whether the tracking is used for marketing automation, lead scoring or profiling; - which external providers gain access to this data. Many organisations are unaware that their email platform activates these features by default. ## A read receipt is not the same as tracking An important distinction has to be made between: - a voluntary read receipt that a recipient can send themselves from Outlook or another email client; and - an invisible tracking pixel that automatically registers when an email is opened. The first only happens when the recipient chooses it. The second usually happens without the recipient being aware of it. ## What can you already do now? You do not necessarily have to overhaul all of your email marketing immediately. It is, however, wise to: - check your email platform for active tracking; - assess whether this tracking is genuinely necessary; - evaluate whether consent is required for it; - update your privacy documentation if needed; - record the processing in your record of processing activities. Those who already understand this processing today will find it much easier to respond to future guidance or inspections. **Source:** CNIL, [Pixels de suivi dans les courriers electroniques: la CNIL publie ses recommandations](https://www.cnil.fr/fr/recommandation-pixel-suivi-courriels) (recommendation, 2026). import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### EU Research: Millions of Small Businesses Fail to Comply with GDPR URL: https://gdprwise.eu/en/kennisbank/nieuws/eu-research-sme-non-compliant/ Summary: A European study of over 700 small businesses reveals widespread unawareness of data security and only superficial GDPR compliance. What are the findings and what can you do? Key takeaways: - About half of the surveyed small businesses do not fully understand GDPR requirements - Many SME owners do not know which security tools they need - Compliance with core obligations like the processing register and privacy notice is low - The lack of compliance is mainly due to a lack of knowledge, not unwillingness FAQ: Q: Why do so many small businesses fail to comply with the GDPR? A: The research points to three main causes: lack of knowledge about what the GDPR requires, the perception that it is too complex or expensive, and the absence of accessible tools. GDPRWise was built to remove exactly these barriers. Q: Can I get fined as a small business? A: Yes. Supervisory authorities also fine small businesses, especially following complaints from data subjects or data breaches that are not properly reported. ## The findings A European study of 716 small business leaders paints a concerning picture of GDPR compliance among SMEs. The key findings: ### Lack of knowledge About half of the surveyed entrepreneurs do not fully understand GDPR requirements. Many business owners do not know what a processing register is, what rights data subjects have, or when they must report a data breach. ### Only superficial compliance Among businesses that have taken action, compliance remains shallow. Many have placed a privacy notice on their website but have not sorted out the underlying documentation: no processing register, no data processing agreements, no retention policy. ### Unawareness of security tools A significant portion of respondents do not know which security measures they should take. Encryption, two-factor authentication, and access control are concepts many SME owners cannot place. ### The problem is knowledge, not unwillingness An important nuance: the research shows that most entrepreneurs want to comply with the law but do not know how. The problem is not unwillingness - it is unawareness. ## What does this mean for you? If you recognise yourself in the findings above, you are not alone. But the fact that millions of businesses are non-compliant does not make it any less important to get your own house in order. Supervisory authorities are aware of the problem and are intensifying enforcement aimed at SMEs. Businesses that take action now are ahead. Those that wait are at risk. ## The solution is accessibility The research confirms what GDPRWise has had as its mission from the start: GDPR must be so accessible that no one has an excuse not to do it. No expensive consultants, no legal jargon, no weeks-long processes. Just a tool that guides you step by step. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### EU Wants Platforms to Play an Active Role in Privacy Compliance URL: https://gdprwise.eu/en/kennisbank/nieuws/platforms-active-role-privacy/ Summary: The European Commission expects online marketplaces to actively verify whether their participants comply with the GDPR. What does this mean for businesses selling through platforms? Key takeaways: - The EU expects online platforms to verify whether their participants comply with the GDPR - The Digital Services Act imposes additional obligations on platforms regarding transparency and enforcement - If you sell through a platform, your own privacy policy must be in order - Platforms may refuse or remove participants for non-compliance with privacy rules FAQ: Q: Am I responsible for my own GDPR compliance when selling through a platform? A: Yes. The platform facilitates the transaction, but as a seller you are the data controller for your customers' personal data. You need your own privacy notice and must meet all GDPR obligations. Q: Can a platform remove me if my privacy policy is not in order? A: Yes, and it is happening more often. Platforms themselves become liable if they allow participants who do not comply. They therefore have an interest in excluding non-compliant sellers. ## Platforms under pressure The European Commission is putting increasing pressure on online marketplaces and platforms to play an active role in ensuring privacy compliance by their participants. The combination of the GDPR and the Digital Services Act (DSA) creates a framework where platforms can no longer claim they are "just an intermediary." ## What does this mean in practice? Online marketplaces and platforms are expected to: - **Verify privacy policies** of sellers and providers using their platform - **Provide transparency** about how data is shared between platform and participants - **Exclude or remove non-compliant participants** in cases of repeated violations - **Set clear terms** about privacy compliance in their platform rules ## The impact on sellers If you sell through an online marketplace, webshop platform, or comparison site, you will encounter this more and more. Platforms increasingly ask for: - A link to your privacy notice - Proof that you have a processing register - Information about how you handle customer data - A data processing agreement Businesses without these in order risk being denied access to the platform. ## The broader context This development is part of a broader European policy to make the digital economy safer. The DSA imposes obligations on platforms around content moderation, transparency, and user protection. The GDPR complements this on personal data. For SME owners, the message is clear: GDPR compliance is not just a legal obligation - it is increasingly a commercial necessity. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### GDPR and Real Estate: What Landlords Need to Know URL: https://gdprwise.eu/en/kennisbank/nieuws/gdpr-real-estate-rental/ Summary: The GDPR also applies to landlords, including private individuals with multiple properties. A Spanish landlord was fined EUR 1,200 for failing to inform a tenant. This article explains what you need to arrange. Key takeaways: - The GDPR applies to landlords as soon as they structurally process tenant personal data - The household exemption only applies to purely personal activities, not when renting out multiple properties - A Spanish landlord was fined EUR 1,200 for failing to inform a tenant about data processing - Only collect data you truly need for the rental agreement and do not retain it longer than necessary FAQ: Q: Does the GDPR apply to me if I only rent out one apartment? A: It depends. If you rent out a single property as a purely personal activity, you may fall under the household exemption. But as soon as you rent out multiple properties, use a property manager, or treat it as a business activity, the GDPR applies fully. Q: What data may I collect from a tenant? A: Only what is necessary for the rental agreement and legal obligations: name, address, contact details, identity document (for verification, not copying), income details (for screening), and bank details (for rent payments). You may not ask for medical data, religion, or political preferences. Q: How long may I retain tenant data? A: Data of active tenants may be retained for the duration of the rental agreement. After the contract ends, only keep what is legally required (e.g., financial records for tax purposes, up to 7 years). Delete all other data. Q: Do I need a privacy notice as a landlord? A: Yes, if the GDPR applies to you, you must inform tenants about what data you process, why, and how long you retain it. This can be a simple document attached to the rental agreement. ## GDPR in the rental sector: no exception As a landlord, you work with personal data daily. Name, address, income details, copy of identity documents, bank details - you collect it all. And that means the GDPR applies to you. Yet many landlords, especially private ones, assume the GDPR does not apply to them. "I'm not a business," they say. Or: "I only have two apartments." But the GDPR does not distinguish between large and small. It distinguishes between personal and professional. ## The Spanish case: EUR 1,200 fine for a landlord In 2022, the Spanish supervisory authority (AEPD) fined a private landlord EUR 1,200. The reason: the landlord collected personal data from a tenant (identity document, proof of income, bank details) without informing the tenant about the processing. Specifically, the following was missing: - **No information** about the purpose of data processing - **No mention** of the legal basis - **No information** about the retention period - **No reference** to the tenant's rights (access, correction, deletion) The landlord simply should have attached a short privacy document to the rental agreement. That would have taken half an hour. The fine cost EUR 1,200. This is not an isolated case. Supervisory authorities across Europe are increasingly looking at the real estate sector, precisely because many landlords are unaware of their obligations. ## The household exemption: when does it apply? The GDPR has a "household exemption" (Article 2(2)(c)). It states that the GDPR does not apply to processing by an individual for purely personal or household activities. But when is renting "purely personal"? **Possibly exempt:** - You rent out a room in your own home to a housemate - You occasionally rent out a holiday home to family or friends **Not exempt:** - You structurally rent out multiple properties to third parties - You work with an estate agent or property manager - You advertise on platforms like Rightmove, Zillow, or Immoweb - You maintain a structured administration of tenants and payments The rule of thumb: as soon as your rental activity has an organised character, the GDPR applies. Renting out 10 apartments? No discussion. Renting out 1 via a platform? Probably also applies. ## What data may you collect? The data minimisation principle (Article 5 GDPR) stipulates that you may only collect data necessary for the purpose. For rentals, this means: ### Allowed - **Name and contact details** - needed for the rental agreement - **Identity document** - for identity verification (view, do not copy unless legally required) - **Income details** - for assessing whether the tenant can afford the rent (payslips, employment contract) - **Bank details** - for collecting rent - **Rental history/references** - relevant for tenant assessment ### Not allowed - **Medical data** - not relevant for rental - **Religion, political preference, sexual orientation** - special categories you may never ask for - **Social media profiles** - not necessary for the rental agreement - **Criminal record** - private landlords may not request this - **Excessive copying** - a full file with all bank statements from the past 5 years is disproportionate ## What do you need to arrange as a landlord? ### 1. Inform your tenants Attach a short privacy document to the rental agreement. State: - What data you collect and why - The legal basis (usually: performance of the rental agreement) - How long you retain the data - The tenant's rights (access, correction, deletion) - Your contact details for privacy enquiries ### 2. Limit what you collect Only ask for what you truly need. A payslip to verify income? Fine. All bank statements from the past year? Excessive. ### 3. Set retention periods - **During the rental agreement:** all data needed for performance - **After the rental agreement ends:** financial records up to 7 years (tax legislation), delete all other data - **Rejected prospective tenants:** delete data within 4 weeks, unless a longer period has been agreed ### 4. Secure the data Do not store tenant files in an unsecured folder on your desktop. Use at minimum: - Password protection on digital files - Restricted access (only you and possibly your property manager) - A locked cabinet for paper files ### 5. Be careful with property platforms If you use an external platform or agent that has access to tenant data, you may need a data processing agreement. Check whether the platform already offers one in its terms and conditions. ## Summary: the three major landlord mistakes 1. **Not informing** - not telling tenants what you do with their data (precisely the mistake from the Spanish case) 2. **Collecting too much** - requesting everything "just in case" when it is not necessary 3. **Never deleting** - retaining tenant files for years after the contract ends None of these mistakes is difficult to prevent. A short privacy document, a conscious selection of data, and an annual cleanup are enough to get the basics in order. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Hotel Guest Passports and ID Cards: Do's and Don'ts Under GDPR URL: https://gdprwise.eu/en/kennisbank/nieuws/hotel-guest-passports-id-cards-gdpr/ Summary: Scanning and copying hotel guest passports and ID cards is a sensitive topic under GDPR. This article explains what hoteliers can and cannot do, with real enforcement examples and fines. Key takeaways: - Hotels may record identity data, but copying or scanning passports is generally not allowed - The Spanish data protection authority has fined hotels for unnecessarily storing photos and document numbers - Only record the data required by law: name, date of birth, nationality, and check-in/check-out dates - Do not retain guest identity data longer than legally required and ensure adequate security FAQ: Q: Can a hotel copy my passport? A: In most EU countries, no. Hotels may note the information required by local law (name, date of birth, nationality), but making a full copy or scan of the passport goes beyond what is necessary under GDPR. Q: What data can a hotel record at check-in? A: Hotels may record the data prescribed by local law. Typically: full name, date of birth, nationality, document number, and check-in and check-out dates. Biometric data such as passport photos are not necessary. Q: What if a hotel scans my passport anyway? A: You can file a complaint with the national data protection authority (e.g., the ICO in the UK). Hotels that systematically scan passports without a legal basis risk a fine. Q: How long can a hotel keep my data? A: Only as long as local law requires. In most EU countries, this is 1 to 3 years. After that, the data must be deleted. ## The problem: hotels collecting too much data You arrive at a hotel. At the front desk, you are asked to hand over your passport or ID card. The receptionist scans the document, makes a copy, or enters all the data, including your photo and national ID number. This is a scenario millions of travellers know. But is it allowed under GDPR? The short answer: **no, usually not.** Hotels have a legal obligation to register certain guest data, but copying or scanning the entire identity document almost always goes beyond what the law requires. ## What does the law say? Most EU member states require hotels to register guest data; this is known as the police registration requirement (*Meldepflicht* in Germany, *fiche de police* in France, *ficha de policia* in Spain). The exact requirements vary by country, but typically include: - **Full name** of the guest - **Date of birth** - **Nationality** - **Type and number** of the identity document - **Check-in and check-out dates** That's it. No passport photo. No national ID number. No full scan of your passport. ## Enforcement: fines for hotels The Spanish Data Protection Authority (AEPD) has fined several hotels for violations related to guest identity data: **Hotel in Barcelona - EUR 30,000 fine** The hotel routinely made copies of passports at check-in and stored them digitally. The AEPD ruled this violated the principle of **data minimisation** (Article 5(1)(c) GDPR): the hotel collected more data than necessary for the purpose. **Hotel chain in Madrid - EUR 45,000 fine** The chain kept scanned passports for up to 5 years after the stay, while Spanish law prescribes a retention period of 3 years. Furthermore, the scans were not adequately secured; employees had unrestricted access. **Hotel in Mallorca - warning** The hotel only copied the number and name, but also stored the nationality in an unsecured Excel file accessible to all employees via a shared folder. The AEPD issued a warning requiring the hotel to fix the security within 3 months. ## Do's and don'ts for hoteliers ### What you SHOULD do - **Record the legally required data**: name, date of birth, nationality, document number, stay dates - **Visually check the identity document**: you may view the document to verify the information - **Inform guests** why you need the data (legal obligation) and how long you will keep it - **Secure the data**: access control, encryption, limited access for staff - **Delete data** after the legal retention period expires - **Train your staff**: front desk employees must know which data they can and cannot record ### What you should NOT do - **Make copies or scans** of passports or ID cards without a legal basis - **Store passport photos or biometric data** - **Record national ID numbers** (or equivalents) unless local law explicitly requires it - **Keep data longer** than the law prescribes - **Store guest data in unsecured systems** (Excel files on shared folders, unencrypted USB drives) - **Use data for marketing** without explicit consent ## By country: what is required? | Country | Legal basis | Required data | Retention period | |---------|-----------|---------------|-----------------| | Belgium | Royal Decree 23/10/2020 | Name, date of birth, nationality, document nr, stay dates | 1 year | | Netherlands | Municipal Act art. 438 | Name, address, date of birth, nationality, document nr | 1 year | | Germany | Bundesmeldegesetz par.29 | Name, date of birth, nationality, document nr, arrival date | 1 year | | Spain | Ley de Seguridad Ciudadana | Name, date of birth, nationality, document nr, stay dates | 3 years | | France | Code de la securite interieure | Name, date of birth, nationality, document nr | 6 months | | United Kingdom | Immigration Act 2016 | Name, nationality, document nr, check-in/check-out | 1 year | ## What should you do as a hotelier? 1. **Review your current procedure**: are you making copies or scans? Stop, unless you have a specific legal basis 2. **Update your check-in form**: only collect the legally required fields 3. **Delete old scans and copies**: if you have stored digital copies of passports, delete them 4. **Secure your guest register**: use a secure system with access control, not a shared Excel file 5. **Inform your guests**: a short privacy notice at reception or in the confirmation email is sufficient 6. **Set retention periods**: configure your system to automatically delete data after the legal retention period import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### How Not to Respond to a Bad Review: GDPR Lessons URL: https://gdprwise.eu/en/kennisbank/nieuws/bad-review-response-gdpr/ Summary: A business responded to a negative online review by disclosing the customer's personal data. This resulted in a GDPR fine. What can you learn from this? Key takeaways: - Never respond to a negative review by disclosing the customer's personal data - Sharing customer data in a public response is a GDPR violation, even if the review is unjustified - Keep review responses general and professional, refer to a private conversation for details - Train your team to never use customer information in public communication FAQ: Q: Am I allowed to respond to a negative review at all? A: Yes. You can give a professional reply, share your side of the story, and invite the customer to get in touch. What you must not do is disclose the customer's personal data: no names, no purchase history, no medical information, no financial details. Q: What if the customer is lying in their review? A: Even then, you may not make personal data public. You can respond in general terms ('We do not recognise this account') and invite the customer for a private conversation. If the review is demonstrably false or defamatory, you can ask the platform to remove it. Q: Does this apply to all types of reviews? A: Yes. Whether it concerns Google Reviews, Trustpilot, Facebook, Yelp, or an industry-specific platform: disclosing personal data in a response is a GDPR violation, regardless of the platform. Q: Can a customer complain to the supervisory authority about my response to a review? A: Yes. If you disclose personal data in a public response, the customer can file a complaint with the national supervisory authority. This can trigger an investigation and a fine. ## What happened? A business received a negative review on an online platform. The customer complained about the service and gave a low rating. Nothing unusual so far - this happens to every business. But the owner responded emotionally. In their public reply, they mentioned details about the customer's purchase, the reason for the visit, and in some cases even health-related information. The intention was to refute the complaint and "tell their side of the story." The result: a complaint to the supervisory authority and a fine for violating the GDPR. ## Why is this a GDPR violation? Personal data collected in the course of your services - purchase history, medical information, financial details, contact data - may only be used for the purpose for which it was collected. Publicly disclosing that data in response to an online review is not part of that purpose. Specifically, this violates several GDPR principles: - **Purpose limitation** (Article 5(1)(b)) - you use the data for a purpose other than what it was collected for - **Integrity and confidentiality** (Article 5(1)(f)) - you make confidential data public - **Legal basis** (Article 6) - you have no valid legal basis to share personal data publicly If health data is involved, you also violate Article 9, the prohibition on processing special categories of personal data without a specific exception. ## It does not matter if the customer is wrong This is where many business owners stumble. "But the customer is lying! I want to show what really happened!" That is understandable. But the GDPR makes no exception for situations where the customer is wrong. You received the personal data in a confidential context (the customer relationship), and you may not use it to defend yourself publicly. Even if the review is unjustified, exaggerated, or outright false: disclosing personal data in your response is not allowed. ## How should you respond to a negative review? ### Rule 1: Keep it general Respond professionally and in general terms. Do not mention specific details about the customer, the purchase, or the service. **Not:** "This person came in on 15 March for treatment X and only paid 50 euros, which was already a discount." **Instead:** "We regret that your experience did not meet your expectations. We take every complaint seriously." ### Rule 2: Refer to a private conversation Invite the customer to get in touch so you can discuss the situation privately. "We would like to discuss this with you personally. You can reach us at [email/phone]." ### Rule 3: Never share medical or financial details Especially if you work in healthcare, coaching, or financial services: never reveal any indication of the reason for the visit, the diagnosis, the treatment, or the amount. ### Rule 4: Limit who responds Appoint one or two people responsible for responding to reviews. Make sure they are trained. An angry employee responding impulsively can commit a GDPR violation in just a few sentences. ## What if it has already happened? If you have already posted a response that contains personal data: 1. **Remove or edit the response immediately** to delete all personal data 2. **Document the incident** in your data breach register, since unauthorised disclosure of personal data is a data breach 3. **Assess whether you need to report it** to the supervisory authority (depending on the nature and sensitivity of the disclosed data) 4. **Contact the data subject** to inform them about what happened ## Train your team Make sure that everyone who communicates on behalf of your business - whether it concerns reviews, social media, or customer service - knows that customer data must never be used in public communication. Include it in your GDPR awareness training: - What can and cannot be said in public responses? - Who should you contact if you are unsure? - Who is responsible for managing online reviews? import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Over 75% of Belgian Websites Risk Being Taken Offline URL: https://gdprwise.eu/en/kennisbank/nieuws/belgian-websites-risk-offline/ Summary: An analysis shows that the vast majority of Belgian websites do not meet GDPR requirements for privacy policies. What does this mean and how can you avoid problems? Key takeaways: - Over 75% of Belgian websites do not fully comply with GDPR requirements - Most common issues: missing or incomplete privacy policy, cookies without consent - After a recent court ruling, the risk of enforcement through civil proceedings has increased - A free website scan shows within 2 minutes what issues your website has FAQ: Q: How do I know if my website is GDPR-compliant? A: The quickest way: have your website scanned by GDPRWise. The scan checks for cookies without consent, missing privacy policies, trackers, and forms without a reference to your privacy policy. Q: What are the most common violations on websites? A: Cookies placed before consent, a missing or incomplete privacy policy, Google Analytics or Facebook Pixel without consent, and contact forms without a link to the privacy policy. ## An alarming figure An analysis of Belgian websites shows that over 75% do not fully comply with GDPR requirements. This ranges from entirely missing privacy policies to placing tracking cookies without consent. It is not just small businesses. Medium-sized companies, associations, and even government institutions have shortcomings. ## The most common issues ### No or incomplete privacy policy Many websites have no privacy policy at all, or an outdated template that does not reflect the actual situation. The GDPR requires you to inform visitors about what data you collect, why, and for how long. ### Cookies without consent Tracking cookies from Google Analytics, Facebook Pixel, advertising networks, and other external services are placed on many websites before the visitor has given consent. This is a direct violation. ### Forms without a privacy reference Contact forms, newsletter sign-ups, and quote requests collect personal data. Without a reference to the privacy policy, the visitor misses the information they are entitled to. ### Outdated information Websites that once drafted a privacy policy but never updated it. New tools, new cookies, new processing activities - the privacy policy quickly falls behind reality. ## The risk is increasing After recent court rulings where websites had to be taken offline due to privacy violations, the risk is no longer theoretical. Competitors, consumers, and advocacy organisations can take action. ## What can you do? The first step is simple: scan your website. GDPRWise automatically detects cookies, trackers, forms, and scripts, and shows you exactly where the problems are. From there, you can take targeted action. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Photos of People on Instagram and Social Media: What Does the GDPR Say? URL: https://gdprwise.eu/en/kennisbank/nieuws/instagram-photo-gdpr/ Summary: Can you post photos of employees, customers, or events on Instagram or other social media? This article explains when it is and is not allowed under the GDPR, with practical examples and enforcement cases. Key takeaways: - A photo of a recognisable person is personal data under the GDPR - For a portrait photo of a specific person, you almost always need explicit consent - For group photos at a public event, you may be able to rely on legitimate interest - Data subjects always have the right to object and request deletion FAQ: Q: Can I post photos from a company event on Instagram? A: It depends. For atmosphere shots and group photos at an event, you may be able to rely on legitimate interest, provided you inform participants in advance. For close-ups or portraits of individuals, you need explicit consent. Q: Do I need consent for employee photos on the company website? A: Yes. Employee consent must be 'freely given,' which is difficult in an employment relationship due to the power imbalance. Make sure employees can genuinely refuse without negative consequences. Q: What if someone asks to have a photo removed afterwards? A: If the processing is based on consent, the data subject can always withdraw it. You must then remove the photo. With legitimate interest, the data subject can object, and you must weigh whether your interest outweighs theirs. Q: Do different rules apply to photos of children? A: Yes, stricter rules apply to children. You need consent from a parent or guardian, and supervisory authorities are particularly strict about violations involving children's data. ## A photo is personal data It may sound surprising, but as soon as a person is recognisable in a photo, that photo is personal data under the GDPR. It does not matter whether it is a professional portrait or a quick snapshot on your phone. Recognisable = personal data = GDPR applies. This applies to: - Photos of employees on your company website or LinkedIn page - Photos of customers or visitors on Instagram, Facebook, or TikTok - Photos of participants at events, trainings, or workshops - Photos of people in your newsletter or marketing material You post a photo of the team outing, an atmosphere shot from your open day, or an Instagram post of a satisfied customer. But is that just allowed? ## When it is allowed: the two main legal bases ### 1. Consent (Article 6(1)(a)) The most obvious legal basis. You ask the person in the photo for consent before posting. Sounds simple, but there are caveats: - Consent must be **specific**: "I consent to this photo being posted on the Instagram account of company X" - Consent must be **freely given**: with employees this is tricky due to the employment relationship; they must genuinely be able to refuse without consequences - Consent is **withdrawable**: if someone later says "I want that photo removed," you must delete it - Oral consent is valid, but **written consent is provable** and strongly recommended ### 2. Legitimate interest (Article 6(1)(f)) In some cases, you can post photos based on legitimate interest, without explicit consent. This typically applies to: - **Group photos at a public event** where participants could reasonably expect to be photographed - **Atmosphere shots** where individuals are not the focus - **News coverage** of a public event However, you must always conduct a **balancing test**. Your interest (promoting your event) must outweigh the privacy interest of the photographed persons. And you must inform participants in advance that photos will be taken. ## The difference: group photo vs. portrait This distinction is crucial in practice: **Group photo at a public event.** You organise a networking drinks and take an overview shot of the room. Individual persons are not the focus. You have communicated in advance that photos will be taken. Legitimate interest can be a valid legal basis here. **Portrait of a specific person.** You take a close-up of a visitor at your stand and post it on Instagram with the caption "our customers are enthusiastic!" Here the person is the focus. You need explicit consent. The rule of thumb: the more recognisable and central the person in the image, the stronger the requirement for consent. ## Enforcement: this is not a theoretical risk Supervisory authorities have already taken action against careless use of photos: **Greek telecom company - EUR 150,000 (HDPA, 2020).** The Greek authority fined a telecom company that posted staff photos on its website without valid consent. Employees indicated they had not agreed, or that consent was not freely given due to management pressure. **Spanish fitness centre - EUR 10,000 (AEPD, 2022).** A fitness centre posted photos of members on Instagram without consent. When a member requested removal, it took weeks for the centre to respond. ## Practical do's and don'ts ### What you SHOULD do - **Inform in advance** that photos will be taken, e.g., with a sign at the event entrance - **Ask for explicit consent** for portrait photos and close-ups - **Record consent**, preferably in writing or via a digital form - **Respond promptly** when someone requests removal of a photo - **Be extra careful with photos of children** - always obtain consent from a parent or guardian ### What you should NOT do - **Post photos without any legal basis** - neither consent nor legitimate interest - **Assume that presence automatically means consent** for close-ups on social media - **Use employee photos after they leave** without checking whether consent still applies - **Ignore removal requests** or respond too late - **Tag photos with names** without consent; this links the photo to an identifiable profile ## What should you arrange now? 1. **Inventory** which photos of people you have on social media and your website 2. **Check** whether you have a valid legal basis for each photo 3. **Create a photo policy** covering when you photograph, how you request consent, and how you handle removal requests 4. **Train your staff** responsible for social media 5. **Document** your processing of photos in your processing register import ArticleCTA from '@/components/ArticleCTA.astro'; --- ## Rights & Requests ### Access Request Received - What Now? Step by Step URL: https://gdprwise.eu/en/kennisbank/rechten-en-verzoeken/access-request-received/ Summary: A customer or employee wants to know what personal data you hold about them. That is an access request. This article explains step by step how to respond correctly, from identity verification to providing the data. Key takeaways: - You have a maximum of one month to respond to an access request - Always verify the requester's identity before providing data - You must provide not only the data itself but also information about how you process it - The first request is free - you may only charge for excessive requests FAQ: Q: Can an access request come in by email? A: Yes. An access request does not need to be in any particular form. It can come by email, letter, phone, or even verbally. If someone asks 'what data do you have about me?', that is an access request. Q: Do I have to provide all data? A: You must provide all personal data you process about the data subject, unless providing it would harm the rights and freedoms of others. Think of data about third parties in the same file - you may redact those. Q: What if I cannot find the data? A: If after a thorough search you cannot find any data, inform the requester that you do not process personal data about them. Document your search in case the requester files a complaint. Q: May I ask why someone is making an access request? A: No. The data subject does not need to give a reason. The right of access is unconditional. ## Recognising an access request An access request (also known as DSAR - Data Subject Access Request) is the most common request you can receive as a business owner. A customer, employee, applicant, or website visitor asks you to tell them what personal data you hold about them. The request does not need to be formal. "What data do you have about me?" in an email is already an access request. You do not need a form for it. ## Step 1: Register the request Note down immediately: - **Who** is making the request - **When** you received it (the one-month deadline starts now) - **Through which channel** it came in - **What exactly is being asked** import TemplateTip from '@/components/TemplateTip.astro'; Keep track of every request in a register: who, when, what was asked, and how it was handled. ## Step 2: Verify the identity Before providing data, you must be certain that you are communicating with the right person. Otherwise you risk a data breach by giving data to the wrong person. **How to verify?** - If the person already has an account with you: have them confirm the request through that account - If you know the person (e.g. an employee): a confirmation via the known email address is sufficient - For unknown persons: ask for a copy of an ID document. Ask the requester to redact the national ID number and photo - you don't need those Don't take more than necessary: the identity check must be proportionate. A standard letter asking the requester to confirm their identity. ## Step 3: Collect the data Search all your systems where personal data of the requester may be stored: - **CRM system** - customer data, notes, communication history - **Email system** - correspondence with the person - **Accounting** - invoices, payment data - **HR system** - if it concerns a (former) employee - **Website** - form submissions, account data - **Paper files** - contracts, correspondence Be thorough. If you miss data later, the requester may file a complaint. ## Step 4: Prepare your response Your response must contain the following information: ### The data itself A copy of all personal data you process about the data subject. ### Additional information - **Processing purposes** - why you process the data - **Categories of data** - what types of data you hold - **Recipients** - with whom you have shared the data - **Retention period** - how long you retain the data - **Rights** - the data subject has the right to rectification, erasure, restriction, and objection - **Right to complain** - the data subject can file a complaint with the supervisory authority - **Source** - if you did not obtain the data from the data subject themselves, where it came from A ready-to-use response that contains all mandatory information elements. ## Step 5: Send the response - **Deadline** - within one month of receiving the request - **Extension** - for complex requests you may extend by two months, but inform the requester within the first month - **Format** - if the request was made electronically, provide the data in a common electronic format (PDF, Excel) - **Cost** - the first request is free. For repeated or manifestly excessive requests, you may charge a reasonable fee - **Secure** - send the data through a secure channel, not as an unencrypted email attachment ## Step 6: Document Record how you handled the request: when received, when answered, what data was provided, which systems were searched. This is your evidence if the data subject later files a complaint. ## Common pitfalls - **Responding too late** - a month passes quickly. Register the request immediately and start the same day - **Forgetting data** - search all systems, not just your CRM - **No identity check** - providing data to the wrong person is a data breach - **Redacting too much** - you may redact data of third parties, but not the requester's own data import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Automated Decision-Making and Profiling: What Are the Rules? URL: https://gdprwise.eu/en/kennisbank/rechten-en-verzoeken/automated-decision-making-rights/ Summary: Article 22 GDPR gives individuals the right not to be subject to decisions based solely on automated processing. This article explains when the rules apply, the exceptions, and what your business needs to do in practice. Key takeaways: - People have the right not to be subject to decisions based solely on automated processing that produce legal or significant effects - Profiling alone is not prohibited - it is the solely automated decision that triggers Article 22 - Even when automated decisions are allowed, you must offer safeguards like human intervention - If you use AI tools to make decisions about people, you likely need a human in the loop FAQ: Q: Does using ChatGPT to draft a response count as automated decision-making? A: No. If a human reviews and sends the response, the decision is not solely automated. The tool assists, but a person makes the final call. Article 22 does not apply here. Q: What about automated email filtering that blocks messages? A: Standard spam filtering generally does not produce legal or similarly significant effects. However, if your system automatically blocks important correspondence and prevents someone from accessing a service, it could fall under Article 22. Q: Do I need a DPIA for every AI tool I use? A: Not for every tool. A DPIA is required when processing is likely to result in a high risk to individuals. Systematic profiling with significant effects, large-scale automated decision-making, or processing sensitive data with AI typically require one. ## What is automated decision-making? Automated decision-making is when a system makes a decision about a person without any meaningful human involvement. Think of software that automatically rejects a loan application based on a credit score, or an algorithm that filters out job candidates before anyone reviews their CV. Article 22 GDPR gives individuals the right **not to be subject to a decision based solely on automated processing** - including profiling - that produces legal effects or similarly significant effects concerning them. The key words are "solely" and "legal or similarly significant effects." Both conditions must be met for Article 22 to apply. ## Profiling vs automated decision-making These two concepts are related but different. **Profiling** is the automated analysis of personal data to evaluate certain aspects of a person - their work performance, economic situation, health, personal preferences, reliability, behaviour, or location. **Automated decision-making** is acting on that analysis without human intervention. Profiling alone is not prohibited under Article 22. You can use analytics to segment your customers or score leads. The restriction kicks in when you use that profiling to make a decision that has legal or significant effects - and no human is meaningfully involved. ## When does Article 22 apply? Article 22 applies when **all three conditions** are met: 1. The decision is based **solely on automated processing** (no meaningful human review) 2. The processing includes **profiling or automated analysis** 3. The decision produces **legal effects** or **similarly significant effects** | Scenario | Solely automated? | Significant effect? | Article 22 applies? | |---|---|---|---| | Loan application auto-rejected by credit scoring algorithm | Yes | Yes - denied access to credit | **Yes** | | AI screens CVs and auto-rejects candidates | Yes | Yes - denied job opportunity | **Yes** | | Insurance premium set entirely by risk profiling algorithm | Yes | Yes - financial impact | **Yes** | | Fraud detection auto-blocks a bank account | Yes | Yes - denied access to funds | **Yes** | | Product recommendation engine suggests items | Yes | No - no legal or significant effect | **No** | | AI screens CVs, but a recruiter makes the final hiring decision | No | N/A - human in the loop | **No** | | Content personalisation on a website | Yes | No - no significant effect | **No** | | ChatGPT drafts a letter that a person reviews and sends | No | N/A - human makes the decision | **No** | ## Three exceptions where automated decisions are allowed Even when Article 22 would normally apply, automated decision-making is permitted in three cases: ### 1. Necessary for a contract The automated decision is necessary to enter into or perform a contract with the individual. For example, an instant credit decision for an online purchase where manual review would make the service impractical. ### 2. Authorised by law EU or member state law explicitly allows the automated decision-making. The law must include suitable safeguards for the individual's rights. ### 3. Based on explicit consent The individual has given explicit consent to the automated decision-making. This must be specific, informed, and freely given - not buried in general terms and conditions. ## Required safeguards - even with exceptions Even when one of the three exceptions applies, you must still provide these safeguards: - **Right to human intervention** - the individual can ask for a person to review the decision - **Right to express their point of view** - they can explain their situation - **Right to contest the decision** - they can challenge the outcome You also cannot use automated decision-making based on special categories of data (health, ethnicity, political opinions, etc.) unless you have explicit consent or a substantial public interest basis with appropriate safeguards. ## When is a DPIA required? A Data Protection Impact Assessment (DPIA) is required when automated decision-making creates a high risk. This typically includes: - **Systematic profiling** with significant effects on individuals - **Large-scale automated processing** of personal data - **Combining datasets** in ways individuals would not reasonably expect - Processing **sensitive data** through automated systems If you are using AI tools to evaluate, score, or categorise people, a DPIA is almost certainly required. ## What this means for your business in practice If you run an SME and use AI tools or automated systems, here is what to check: **Step 1: Map your automated processes** List every tool or system that makes decisions about individuals. Include hiring tools, credit checks, fraud detection, customer scoring, and any AI-powered automation. **Step 2: Check if a human is meaningfully involved** A human "in the loop" only counts if they genuinely review the decision and have the authority to change it. Rubber-stamping an algorithm's output is not meaningful human review. **Step 3: Assess the effects** Does the automated process produce legal effects (denied a contract, terminated a service) or similarly significant effects (financial impact, denied an opportunity)? If yes and no human is involved, Article 22 applies. **Step 4: Implement safeguards** For any process where Article 22 applies: - Add genuine human review before final decisions - Create a process for individuals to contest decisions - Document your legal basis (contract, law, or explicit consent) - Inform individuals that automated decision-making is taking place - Include this information in your privacy policy **Step 5: Consider a DPIA** If the processing involves profiling with significant effects, conduct a DPIA before you start. ## Common mistakes - **Assuming "a human clicks approve" is meaningful review** - the person must actually assess the case, not just confirm the system's recommendation - **Forgetting to inform people** - your privacy policy must explain automated decision-making, the logic involved, and the potential consequences - **Using AI tools without considering Article 22** - if an AI tool makes decisions about people for you, the GDPR obligations still apply to your business - **Ignoring profiling transparency** - even when Article 22 does not apply, you still need to be transparent about profiling in your privacy policy under Articles 13 and 14 import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Data Subject Request Mistakes That Cost SMEs Fines URL: https://gdprwise.eu/en/kennisbank/rechten-en-verzoeken/data-request-mistakes-fines/ Summary: Six common mistakes SMEs make when handling data subject requests, with real enforcement examples and practical advice on how to avoid them. From ignoring requests to panic-deleting data. Key takeaways: - Ignoring a data subject request is the single most expensive mistake an SME can make - The 30-day deadline starts when you receive the request, not when you verify identity - The first request is always free - charging a fee is almost never justified - Incomplete responses are as risky as no response at all FAQ: Q: What is the maximum fine for mishandling a data subject request? A: Violations of data subject rights can result in fines of up to EUR 20 million or 4% of annual global turnover, whichever is higher. In practice, SME fines typically range from EUR 1,000 to EUR 50,000, but they add up quickly with repeat offences. Q: Can I be fined even if I eventually respond to the request? A: Yes. If you respond after the one-month deadline without a valid extension, you are in violation. Supervisory authorities have fined organisations for late responses even when the response itself was complete. Q: What should I do if I realise I made a mistake handling a request? A: Act immediately. Contact the data subject, correct the error, and document what happened. Proactive remediation is viewed favourably by supervisory authorities and can reduce potential fines. ## The cost of getting it wrong Data subject requests are where GDPR compliance meets reality. You can have the best privacy policy in the world, but if you mishandle a request from a real person, that is when complaints are filed and fines are issued. Supervisory authorities across Europe consistently enforce data subject rights. For SMEs, the fines are not the millions you read about in headlines, but they are painful enough: EUR 5,000 here, EUR 15,000 there, plus legal costs and reputational damage. Here are six mistakes that keep coming back in enforcement decisions, and how to avoid each one. ## Mistake 1: Ignoring requests entirely **What happened:** A German company received an access request by email. They did not respond at all. The requester complained to the state data protection authority. The company was fined EUR 10,000. This is not an isolated case. The Spanish AEPD regularly issues fines for unanswered requests, often in the range of EUR 2,000 to EUR 10,000. The pattern is always the same: someone asks for their data, the company does nothing, the person complains. **What they should have done:** Respond to every request, even if you believe it is unfounded. If you cannot comply, explain why in writing. **Lesson:** No response is always the wrong response. ## Mistake 2: Missing the 30-day deadline **What happened:** A Belgian company received an erasure request. They acknowledged it, started working on it, but only completed the deletion after 47 days. The Belgian GBA found that the late response violated the GDPR, regardless of the fact that the deletion was eventually carried out. The deadline trap is common: companies receive a request, start identity verification, and only then begin the actual work. By the time they respond, the month has passed. **What they should have done:** Register the request on day one and start the clock immediately. Set a reminder at two weeks and at three weeks. If the request is complex, inform the requester of a two-month extension within the first month. **Lesson:** The clock starts when the request arrives, not when you start working on it. ## Mistake 3: Charging fees when not allowed **What happened:** A dental practice charged a patient EUR 25 for providing a copy of their medical records in response to an access request. The patient complained. The supervisory authority ruled that the first access request must be provided free of charge, and the practice was ordered to refund the fee and received a warning. Under the GDPR, the first request is free. You may only charge a "reasonable fee" for requests that are "manifestly unfounded or excessive" - for example, if the same person submits the same access request every week. In practice, this threshold is almost never met. **What they should have done:** Provide the data free of charge. Only consider charging if the request is clearly repetitive and excessive, and document your reasoning. **Lesson:** Almost never charge. When in doubt, it is free. ## Mistake 4: Demanding excessive identification **What happened:** A company asked a customer to provide a full, unredacted passport copy before processing their access request. The customer had an account and was emailing from the registered email address. The Dutch AP criticised the company for disproportionate identification requirements, noting that the customer could have been verified through their existing account. Excessive identification is a double problem: it violates the principle of data minimisation (you are collecting more data than needed) and it creates a barrier that discourages people from exercising their rights. **What they should have done:** Verify identity through the existing account. If the customer is emailing from their registered email, that is usually sufficient. Only request ID documents for unknown persons, and always allow redaction of unnecessary fields. **Lesson:** Proportionate verification only. Use what you already have. ## Mistake 5: Providing incomplete responses **What happened:** An Austrian company responded to an access request by providing data from their CRM system. However, they failed to include email correspondence, paper files, and data held by a third-party processor on their behalf. The Austrian DSB found the response incomplete and issued a fine. This mistake is often not intentional. Companies search their main database and forget about emails, cloud storage, paper archives, backup systems, and data held by processors. **What they should have done:** Search all systems where personal data may be stored. Create a checklist: - CRM and customer databases - Email systems (search by name and email address) - Accounting and invoicing software - HR systems (for employee requests) - Cloud storage (Google Drive, Dropbox, OneDrive) - Paper files and archives - Data held by processors (hosting providers, email marketing tools, analytics) - Backup systems **Lesson:** Search everywhere. An incomplete response is nearly as bad as no response. ## Mistake 6: Deleting data you should have retained **What happened:** A company received an erasure request and, in a panic, deleted everything - including invoices they were legally required to retain for seven years, correspondence related to an ongoing dispute, and records needed for tax purposes. When the tax authority later asked for those records, they could not produce them. The right to erasure is not absolute. You must assess each category of data before deleting: | Data type | Delete? | |---|---| | Marketing preferences, newsletter subscriptions | Yes, delete | | CRM notes with no legal basis | Yes, delete | | Invoices within retention period | No, legal obligation to retain | | Data related to ongoing disputes or claims | No, legitimate interest to retain | | Employment records within mandatory retention | No, legal obligation to retain | | Contract data within statutory retention period | No, legal obligation to retain | **What they should have done:** Assess each dataset individually. Delete what should be deleted, retain what you are legally required to keep, and explain to the requester exactly what was deleted and what was retained (and why). **Lesson:** Do not panic-delete. Assess first, then act. ## How to get it right Every one of these mistakes is preventable with a clear process. If you have not set one up yet, start with our step-by-step guide to building a data subject request process. It covers everything from designating a contact point to documenting your response. The pattern across all six mistakes is the same: they happen when there is no process, no register, and no templates. Fix those three things and you fix the problem. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### GDPR Data Subject Rights: The Complete Guide for Business Owners URL: https://gdprwise.eu/en/kennisbank/rechten-en-verzoeken/gdpr-data-subject-rights/ Summary: The GDPR gives individuals 8 rights over their personal data. As a business owner, you must handle these requests correctly, within one month, free of charge, and well documented. This guide explains each right and what you need to do. Key takeaways: - Data subjects have 8 rights under the GDPR; you must respond to each request within one month - You may not charge for the first request, unless it is manifestly unfounded or excessive - Always verify the identity of the requester before providing or deleting data - Keep a register of all received requests and how you handled them - GDPRWise automatically generates response templates for each type of request FAQ: Q: How long do I have to respond to a data subject request? A: You have a maximum of one month after receiving the request. For complex or multiple requests, you may extend this by two months, but you must inform the requester within the first month about the delay. Q: Can I charge a fee for an access request? A: In principle, no. You may only charge a reasonable fee if the request is manifestly unfounded or excessive, for example with repeated requests. You must be able to justify this. Q: Can I refuse a request for deletion? A: Yes, in certain cases. You may refuse a deletion request if the data is needed for a legal obligation, for exercising the right to freedom of expression, or for establishing or exercising legal claims. Q: Do I need to verify the identity of the requester? A: Yes. You are required to verify the requester's identity before providing, modifying, or deleting data. For example, ask for a copy of an ID document (and redact the national ID number and photo). Q: What if I have already shared the data with third parties? A: If you have shared personal data with recipients (such as processors), you must also inform them about the rectification, deletion, or restriction, unless this is impossible or involves disproportionate effort. ## The 8 rights at a glance The GDPR (General Data Protection Regulation) gives every person whose data you process - customers, employees, website visitors - a set of rights. As a business owner, you are required to take every request seriously and handle it correctly. These are the 8 rights: 1. **Right to information** - know which data you process and why 2. **Right of access** - receive a copy of their data 3. **Right to rectification** - have incorrect data corrected 4. **Right to erasure** - have data deleted ("right to be forgotten") 5. **Right to restriction** - temporarily stop processing 6. **Right to data portability** - receive data in a readable format 7. **Right to object** - object to certain types of processing 8. **Right regarding automated decision-making** - not be subject to purely automated decisions ## Before you start: the ground rules Regardless of which right someone invokes, the same ground rules always apply: **Deadline:** you have a maximum of **one month** to respond. For complex requests, you may extend this once by two months, but you must inform the requester within the first month about the delay and the reason. **Costs:** the first request is always **free**. You may only charge a reasonable fee if the request is manifestly unfounded or excessive (think of someone submitting the same request every week). **Identity verification:** always verify the requester's identity **before** providing or modifying data. Ask for a copy of an ID document, but redact the national ID number and photo - you don't need that information. **Registration:** keep a register of all received requests, the date, the type of right, and how you handled them. The supervisory authority can request this register. ## 1. Right to information **What it means:** people have the right to know which data you process, why, how long you retain it, who you share it with, and what rights they have. This right is "proactive" - you must actively provide this information, not just when someone asks. **How to arrange this:** - Publish a clear privacy policy on your website - Inform customers when collecting data (signup forms, contracts) - Always mention: the purpose, the legal basis, the retention period, and the rights of the data subject **Common mistake:** a privacy policy that nobody understands. Write in plain language, not legal jargon. ## 2. Right of access **What it means:** someone can ask you for a copy of all personal data you process about them. This is the most common request, known as a "subject access request" or DSAR (Data Subject Access Request). **How to respond:** 1. Verify the requester's identity 2. Collect all data you have about this person, across all systems (CRM, email, accounting, HR) 3. Send an overview with: which data, for what purpose, from whom received, with whom shared, how long retained 4. Deliver this in an understandable format (e.g. PDF) **Deadline:** within one month. **Note:** you must not include data of other persons. If a file also contains data about third parties, redact it. ## 3. Right to rectification **What it means:** if personal data is inaccurate or incomplete, the data subject can request correction or completion. **How to respond:** 1. Check whether the data is indeed inaccurate 2. Correct it in all your systems 3. Have you shared the data with third parties (e.g. a processor)? Inform them about the change as well 4. Confirm the correction in writing to the requester **Practical tip:** many systems allow customers to update their own data (think of an account page). That is the easiest route. ## 4. Right to erasure ("right to be forgotten") **What it means:** people can ask you to delete their personal data. This is not an absolute right - there are exceptions. **When you must delete:** - The data is no longer needed for the original purpose - The data subject withdraws consent (and there is no other legal basis) - The data subject rightfully objects - The data was processed unlawfully **When you may refuse:** - The data is needed for a **legal obligation** (e.g. fiscal retention requirement of 7 years) - For exercising the right to **freedom of expression** - For establishing or exercising **legal claims** **How to respond:** 1. Verify the identity 2. Assess whether an exception applies 3. Delete the data from all systems, including backups (where reasonable) 4. Inform any recipients of the data 5. Confirm the deletion or explain why you refuse ## 5. Right to restriction of processing **What it means:** the data subject can ask you to temporarily stop processing. This is a kind of "pause button" - you keep the data but may no longer actively use it. **When this right applies:** - The accuracy of the data is disputed (during verification) - The processing is unlawful, but the data subject does not want deletion - You no longer need the data, but the data subject does (for a lawsuit) - The data subject has objected and you are assessing whether your grounds outweigh theirs **In practice:** mark the data as "restricted" in your system. You may only process it with the data subject's consent, or for legal claims. ## 6. Right to data portability **What it means:** the data subject can request the data they provided themselves in a structured, commonly used, and machine-readable format, and to transfer that data to another organisation. **When this right applies:** - The processing is based on consent or a contract - The processing is automated (not on paper) **Format:** use a common format such as CSV, JSON, or XML. Not PDF - that is not machine-readable. **Note:** this right only applies to data that the data subject **themselves** provided. Derived data (analyses, scores, profiles) is not covered. ## 7. Right to object **What it means:** the data subject can object to the processing of data, particularly when you process on the basis of legitimate interest or for direct marketing. **For direct marketing:** the objection is always valid. You **must** immediately stop processing data for marketing purposes. No discussion possible. **For legitimate interest:** you must assess whether your interests outweigh the rights of the data subject. If not, you must stop the processing. **How to respond:** 1. Is it about direct marketing? Stop immediately 2. Is it about legitimate interest? Make an assessment and document it 3. Inform the data subject about your decision ## 8. Right regarding automated decision-making and profiling **What it means:** people have the right not to be subject to a decision based solely on automated processing (including profiling) if that decision significantly affects them. **When this is relevant:** - You use an algorithm to automatically reject credit applications - You make automatic price discrimination based on profiles - You automatically select applicants without human assessment **For most SME business owners:** this right is rarely relevant. If you don't make fully automated decisions that significantly affect people, you don't need to worry about this much. **If it is relevant:** ensure there is always an option for human intervention, and inform data subjects that they have this right. ## Response templates We have created ready-to-use email templates for the most common requests. Copy them, adjust your company details, and send. - [Template: access request confirmation](/en/kennisbank/sjablonen/template-dsar-confirmation) - [Template: deletion confirmation](/en/kennisbank/sjablonen/template-deletion-confirmation) - [Template: deletion refusal](/en/kennisbank/sjablonen/template-deletion-refusal) - [Template: rectification confirmation](/en/kennisbank/sjablonen/template-rectification-confirmation) ## What should you do now? A checklist to get your obligations in order: - Ensure your privacy policy is up to date and mentions all rights - Set up a procedure for receiving and handling requests - Appoint someone responsible for handling requests - Use our response templates as the basis for your own responses - Set up a register for received requests - Train your employees - they must know how to recognise a request and forward it - Test your procedure: how quickly can you retrieve all data about one person from all your systems? import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### How to Set Up a Data Subject Request Process URL: https://gdprwise.eu/en/kennisbank/rechten-en-verzoeken/data-subject-request-process/ Summary: A step-by-step guide to building a reliable process for handling GDPR data subject requests. From designating a contact point to documenting every step, this article covers everything an SME needs to handle requests correctly and on time. Key takeaways: - Designate one clear contact point for all data subject requests - Any form of request counts - email, phone, verbal, or social media - Register every request immediately and set deadline reminders - Document everything as evidence for the supervisory authority FAQ: Q: Does a data subject request have to be in writing? A: No. A request can come in any form - email, phone call, social media message, letter, or even verbally. If someone asks you to delete their data during a phone call, that is a valid request. Q: Who should be the contact point for data subject requests? A: Ideally one person or a dedicated email address (such as privacy@yourcompany.com). This avoids requests getting lost in a general inbox. Make sure at least one backup person knows the process. Q: What if we receive a request in a language we do not speak? A: You are expected to handle requests from your data subjects. If you serve customers in multiple countries, you should be able to process requests in the languages you operate in. Use translation tools if needed, but do not ignore the request. Q: Do we need special software to manage data subject requests? A: No. A spreadsheet or simple register works fine for most SMEs. What matters is that you have a consistent process and that every request is tracked from receipt to completion. ## Why you need a process Most SMEs handle their first data subject request in a panic. Someone emails asking "what data do you have about me?" and nobody knows who should respond, what to check, or when the deadline is. That is how mistakes happen, and mistakes lead to complaints and fines. A clear, written process prevents this. It does not need to be complicated. Nine steps, a shared register, and a few templates are enough. ## Step 1: Designate a contact point Choose one person or one email address that receives all data subject requests. This could be privacy@yourcompany.com, your office manager, or yourself if you are a small team. The key rule: requests must not arrive in a general inbox where they get buried. Everyone in your organisation should know where to forward a request the moment it comes in. Make sure there is a backup. If the contact person is on holiday, someone else must check for incoming requests. ## Step 2: Recognise a request A data subject request does not come on a special form. It can arrive through any channel: - **Email** - "Please send me all data you have about me" - **Phone** - "I want my account deleted" - **Social media** - a direct message asking to stop processing their data - **Letter** - a formal written request - **Verbally** - during a meeting or at your front desk Any variation of "what data do you have?", "delete my data", "stop processing my information", or "correct my details" counts as a formal request under the GDPR. Train your team to recognise these and escalate immediately. ## Step 3: Register immediately The moment a request comes in, log it in your request register. Record: - **Who** is making the request (name, contact details) - **When** you received it (this is when the clock starts) - **Through which channel** it arrived - **What type of request** it is (access, erasure, rectification, restriction, portability, objection) - **Deadline** (one month from receipt) import TemplateTip from '@/components/TemplateTip.astro'; Track every request in a central register: who, when, what type, deadline, and outcome. ## Step 4: Verify identity Before you act on a request, you must confirm you are dealing with the right person. Giving data to the wrong person is a data breach. Apply proportionate verification: | Situation | Verification method | |---|---| | Known customer with an account | Ask them to confirm via their account or known email | | Known employee or contact | Confirmation from their known email address is sufficient | | Unknown person | Ask for a copy of ID, with photo and national ID number redacted | Never ask for more identification than necessary. A full passport copy for a newsletter unsubscribe is disproportionate. A standard letter asking the requester to confirm their identity in a proportionate way. ## Step 5: Assess the request Determine which right is being invoked and whether you can comply: - **Which right?** Access, erasure, rectification, restriction, portability, or objection? - **Can you fully comply?** In most cases, yes. - **Are there grounds for (partial) refusal?** Legal retention obligations, rights of others, manifestly excessive requests? - **Partial compliance?** You may need to delete some data while retaining other data you are legally required to keep. If you need to refuse, you must explain why and inform the requester of their right to complain to the supervisory authority. ## Step 6: Set deadline reminders You have one month from the date of receipt. Not from verification, not from when you started working on it - from receipt. Set two reminders: - **At two weeks** - check progress. Is identity verified? Have you started collecting data? - **At three weeks** - the response should be nearly ready. If it is not, consider whether you need an extension. If the request is complex, you may extend the deadline by two months. But you must inform the requester of this extension within the first month, explaining why. ## Step 7: Respond Always respond in writing, even if the request came in by phone. Your response should clearly explain: - **What you did** - which data you provided, corrected, or deleted - **Why** - the legal basis for your actions (or your reason for refusal) - **Their rights** - the right to complain to the supervisory authority Use response templates to ensure you cover all mandatory elements: A ready-to-use response template for access requests that includes all mandatory information elements. For other request types, use the appropriate template: deletion confirmation, deletion refusal, or rectification confirmation. Each template ensures you include the legally required information. ## Step 8: Document everything Your file for each request should contain: - The original request (or a summary if it was verbal) - Identity verification records - Your internal notes on which systems were searched - The response you sent - Dates of every step This is your evidence if the data subject complains to the supervisory authority. Without documentation, it is your word against theirs. ## Step 9: Set up an escalation path Not every request is straightforward. Define in advance: - **Who decides on refusals?** The contact person should not refuse requests alone. - **When to consult a lawyer?** If a request involves complex legal retention, competing rights, or potential litigation. - **When to contact your DPO?** If you have a Data Protection Officer, they should be involved in non-routine cases. - **What if you are unsure about the request type?** When in doubt, treat it as a valid request and seek advice. Write this escalation path down. When a difficult request comes in at 4 PM on a Friday, you do not want to figure this out under pressure. ## Putting it all together Your process fits on one page: 1. Request comes in - forward to contact point 2. Register in the request register 3. Verify identity 4. Assess the request 5. Collect data or take action 6. Prepare response using template 7. Send response within one month 8. Document everything 9. Close the case in the register Print this out, share it with your team, and walk through it once. The first real request will go smoothly. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Refusing a Data Subject Request - When Is It Allowed? URL: https://gdprwise.eu/en/kennisbank/rechten-en-verzoeken/refusing-data-subject-request/ Summary: Not every data subject request needs to be granted. But you may only refuse if you have a valid reason. This article explains when refusal is allowed and how to communicate it correctly. Key takeaways: - You may refuse a request if it is manifestly unfounded or excessive, but you must be able to justify it - A legal retention obligation takes precedence over a deletion request - When refusing, you must inform the data subject of the reason and their right to file a complaint - Document every refusal carefully - the burden of proof is on you FAQ: Q: What is a 'manifestly unfounded' request? A: A request is manifestly unfounded if it is clearly not intended to exercise the data subject's privacy rights, but to hinder or pressure your organisation. In practice, this is rare and difficult to prove. Q: What is an 'excessive' request? A: A request is excessive if the same person repeatedly makes the same request in a short period without any relevant changes. A second access request after three months is not excessive. A daily access request may be. Q: What if I refuse wrongly? A: The data subject can file a complaint with the supervisory authority. If the authority rules that you refused wrongly, you risk a fine and must still comply with the request. ## You don't always have to say yes The GDPR gives data subjects strong rights, but those rights are not absolute. There are situations where you may decline a request. However, it is important that you do so correctly: with a valid reason, within the deadline, and with proper communication. ## Grounds for refusal ### 1. Manifestly unfounded request A request that is clearly not submitted to exercise privacy rights, but to hinder you. This is a high threshold. You must be able to demonstrate that the request serves no reasonable purpose. In practice, this rarely occurs. Be cautious with this ground - supervisory authorities do not accept it readily. ### 2. Excessive request If the same person repeatedly makes the same request in a short period without relevant changes. For an excessive request, you have two options: - Charge a **reasonable fee** for the administrative costs - **Refuse** the request ### 3. Legal retention obligation For deletion requests: if you are legally required to retain the data (fiscal retention obligation, employment law deadlines), you may not delete. This is not a refusal in the sense of "I don't want to", but "I cannot without breaking the law". ### 4. Rights of third parties For access requests: if providing data would harm the rights and freedoms of other persons. Think of files containing data about multiple people. You may redact the data of third parties. ### 5. Legal claims If you need the data for the establishment, exercise, or substantiation of a legal claim. As long as a legal dispute is ongoing, you may retain relevant data. ### 6. Identity not verified If you cannot verify the requester's identity, you may refuse the request until the identity is confirmed. Ask for additional information and pause the deadline until you receive it. ## How to refuse correctly ### Always respond Even when refusing, you must respond within one month. Not responding is not a refusal - it is a violation. ### Substantiate your decision Explain on which ground you refuse. "We see no reason to comply with your request" is insufficient. Name the specific exception that applies. ### Inform about rights State in your response that the data subject: - May **file a complaint** with the supervisory authority (include the name and contact details) - May **appeal** to the courts ### Document Save your assessment: which request, which ground for refusal, what considerations you made. This is your file if the supervisory authority asks questions. ## An example > *A former customer asks you to delete all their data. You check your systems and find:* > - *Invoices with their name and address (fiscal retention obligation: 7 years)* > - *CRM notes and communication history (no retention obligation)* > - *An outstanding invoice (needed for legal claim)* > > *Your response: "We have deleted your CRM notes and communication history. We retain your invoicing data for [X] more years based on our fiscal retention obligation. We retain data related to the outstanding invoice until the claim is settled."* That is a correct, transparent, and well-substantiated response. import TemplateTip from '@/components/TemplateTip.astro'; A professional response that substantiates the refusal with the specific legal ground, and informs the data subject of their right to complain. ## The burden of proof is on you This is important: if a data subject files a complaint with the supervisory authority, you must demonstrate that your refusal was justified. The data subject does not need to prove that their request was justified. So always ensure you have proper documentation. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Right to Data Portability: What You Need to Provide URL: https://gdprwise.eu/en/kennisbank/rechten-en-verzoeken/right-to-data-portability/ Summary: A customer wants their data in a format they can take to another provider. This is a data portability request. This article explains what data to include, what format to use, and how to handle it step by step. Key takeaways: - Data portability only applies to data the person provided to you, not data you derived or inferred - You must provide data in a structured, commonly used, machine-readable format like CSV or JSON - Only data processed on the basis of consent or contract is covered - You have one month to respond, same as other data subject rights FAQ: Q: Do I need to build an export feature? A: There is no legal obligation to build a self-service export tool. However, if you receive portability requests regularly, having an automated export function saves time and reduces errors. A simple CSV export from your database is usually sufficient. Q: What format should I use? A: The GDPR does not prescribe a specific format. It must be structured, commonly used, and machine-readable. CSV is the most practical choice for most businesses. JSON and XML are also acceptable. PDF is not machine-readable and does not qualify. Q: Can the customer ask me to send data directly to a competitor? A: Yes, under Article 20(2) the data subject can request that you transmit the data directly to another controller. However, this only applies where it is technically feasible. If there is no standard interface or API, you may explain that direct transfer is not technically possible and provide the data to the individual instead. Q: How is this different from an access request? A: An access request covers all personal data you hold, including your own notes and analysis. Portability only covers data the person provided, and only when processing is based on consent or contract. Access can be in any readable format (PDF is fine). Portability must be machine-readable. ## Recognising a data portability request A data portability request is when someone says: "Give me my data so I can take it to another provider." It is different from a regular access request. The goal is not just to see the data, but to reuse it elsewhere. The request does not need to use the words "data portability." If a customer writes "I want to export my data" or "send my data to [other company]", that counts as a portability request. ## Step 1: Register the request As with any data subject request, log it immediately: - **Who** is making the request - **When** you received it (the one-month deadline starts now) - **Through which channel** it came in - **What exactly is being asked** - do they want the data themselves, or do they want you to send it directly to another controller? import TemplateTip from '@/components/TemplateTip.astro'; Keep track of every request in a register: who, when, what was asked, and how it was handled. ## Step 2: Check whether portability applies This is where portability gets specific. It only applies when **all three conditions** are met: 1. **The data was provided by the data subject.** This includes data they actively gave you (name, email, uploaded files) and data generated by their activity (purchase history, usage logs, location data). It does not include data you created yourself, such as internal notes, risk assessments, or analysis. 2. **Processing is based on consent or contract.** If you process the data on the basis of legitimate interest, legal obligation, or public interest, portability does not apply to that data. 3. **Processing is carried out by automated means.** Paper-only files are excluded, but in practice almost all processing today is automated. If these conditions are not met, you do not need to comply with a portability request. You may still need to handle it as a regular access request instead. ## Step 3: Determine what to include and exclude This is where most businesses get confused. Use this table as a guide: | Data type | Include in portability? | Why? | |---|---|---| | Name, email, address provided by the customer | Yes | Provided by the data subject | | Purchase history, order data | Yes | Generated by the data subject's activity | | Uploaded photos or documents | Yes | Provided by the data subject | | Usage logs, click behaviour | Yes | Observed data from their activity | | Your internal notes about the customer | No | Created by you, not provided by them | | Credit score or risk profile you calculated | No | Derived/inferred data | | Data processed under legitimate interest only | No | Wrong legal basis for portability | | Employee data processed for legal obligations | No | Wrong legal basis for portability | When in doubt, ask yourself: did this data come from the person, or did we create it? If you created it, it stays out of the portability response. ## Step 4: Prepare the data in the right format The format is what sets portability apart from an access request. The GDPR requires the data to be: - **Structured** - organised in a logical way, not a raw database dump - **Commonly used** - a format that other businesses and software can handle - **Machine-readable** - software can process it automatically **Acceptable formats:** - CSV (simplest and most widely supported) - JSON (good for structured, nested data) - XML (more verbose, but acceptable) **Not acceptable:** - PDF (not machine-readable) - Scanned documents - Screenshots For most small and medium businesses, a CSV file is the best choice. It can be opened in Excel, imported into other systems, and is easy to generate. ## Step 5: Check for direct transfer requests The data subject may ask you to send the data directly to another controller - for example, a competitor. Under Article 20(2), you must do this **where technically feasible**. In practice, "technically feasible" means: - There is a standard API or data exchange protocol available - The receiving controller has a system that can accept the transfer If no standard interface exists, you are not required to build one. Inform the data subject that direct transfer is not technically feasible and provide the data to them directly instead. ## Step 6: Send the response - **Deadline** - within one month of receiving the request - **Extension** - for complex requests, you may extend by two months, but inform the requester within the first month - **Cost** - providing the data is free - **Secure delivery** - use a secure channel, especially if the data contains sensitive information ## Portability vs. access request - key differences | | Access request (Art. 15) | Portability request (Art. 20) | |---|---|---| | **Scope** | All personal data you hold | Only data provided by the data subject | | **Legal basis** | Applies regardless of legal basis | Only consent or contract | | **Format** | Any readable format (PDF is fine) | Must be machine-readable (CSV, JSON) | | **Direct transfer** | Not applicable | Yes, if technically feasible | | **Derived data** | Must include | Must not include | If you receive a portability request, check whether the person might also want a broader access request. Sometimes customers use the wrong term but actually want to see everything you hold about them. ## Common pitfalls - **Providing a PDF** - this does not meet the machine-readable requirement for portability - **Including too much** - adding your internal notes or analysis to a portability response goes beyond what is required - **Including too little** - forgetting usage data or transaction history that the person generated through their activity - **Confusing legal bases** - check per data category whether processing is based on consent or contract before excluding data import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Right to Erasure: When Must You Delete Data? URL: https://gdprwise.eu/en/kennisbank/rechten-en-verzoeken/right-to-erasure/ Summary: A customer asks you to erase their data. Do you always have to comply? The right to erasure has limits. This article explains when you must delete and when you may refuse. Key takeaways: - The right to erasure is not absolute - there are situations where you may and even must refuse - You may refuse if you have a legal retention obligation, such as for accounting documents - When deleting, you must also inform parties with whom you shared the data - Always document your decision, whether you delete or refuse FAQ: Q: Do I also have to delete backups? A: In principle yes, but if deletion from backups is technically impossible or disproportionately difficult, you may leave the data until the backup is overwritten according to the normal schedule. Just make sure the data is not restored during a restore. Q: What if the data is in a contract? A: If you need the data for the performance of an ongoing contract, you may refuse the deletion request for the duration of that contract. After the contract ends, that ground expires and you must delete the data, unless another exception applies. Q: Can a former employee request deletion of all their data? A: A former employee can submit a deletion request, but you don't have to delete everything. Personnel files often have a legal retention obligation (2-7 years depending on the document type). Data without a retention obligation must be deleted. ## What is the right to erasure? Under **Article 17 of the GDPR**, every individual has the right to ask an organisation to erase their personal data. The right is also known as the **right to be forgotten**, and in practice you will see the same request called a **data erasure request** or **data deletion request**, all of which mean the same thing. This is one of the [8 data subject rights under the GDPR](/en/kennisbank/rechten-en-verzoeken/gdpr-data-subject-rights). It sounds simple, but in practice it is one of the trickiest rights to handle correctly, because the right is not absolute. There are situations where you must delete, situations where you may refuse, and situations where you are even obliged to refuse. > **In short:** you have **one month** to respond. You must delete when the data is no longer needed, consent is withdrawn, or processing was unlawful. You may refuse when a legal retention obligation, a legal claim, or another GDPR exception applies. Always document the decision and inform any recipients. ## Data erasure vs. data deletion: same thing? Yes. The GDPR uses "erasure" in the official English text, but "data deletion" and "data erasure" are used interchangeably in everyday language and in most national supervisory authority guidance. Both refer to the right under Article 17. ## When you must delete You are obliged to delete data when: - **The data is no longer needed** for the purpose for which you collected it. The customer relationship has ended and you have no other purpose. - **The data subject withdraws consent** and there is no other legal basis. If you process data based on consent and it is withdrawn, you must delete. - **The data subject objects** to processing based on legitimate interest, and your interest does not outweigh theirs. - **The data was processed unlawfully.** If you had no valid legal basis for collecting the data. - **A legal obligation** requires you to delete. ## When you may refuse You may refuse a deletion request if the data is needed for: ### Legal retention obligation Accounting documents must be retained for 7 years. Personnel files have their own retention periods. As long as a legal retention obligation is in effect, you may not delete. ### Exercise of legal claims If you need the data to pursue a legal dispute or defend against a claim, you may retain it. ### Public health Data needed for reasons of public interest in the area of public health. ### Archiving in the public interest Data kept for archiving, scientific or historical research, or statistical purposes. ### Freedom of expression If deletion would hinder the exercise of the right to freedom of expression and information. ## How to handle a deletion request ### 1. Register and verify Just like with an access request: register the request, verify the identity, and note the date. ### 2. Assess per dataset Check per category of data whether you have grounds to retain: | Data | Retention obligation? | Action | |------|----------------------|--------| | Invoices with name/address | Yes (7 years fiscal) | Refuse, explain why | | CRM notes | No | Delete | | Email correspondence | Possibly (ongoing dispute) | Assess per case | | Newsletter address | No (consent withdrawn) | Delete | | Personnel file | Partially (2-7 years) | Assess per document | ### 3. Inform third parties If you have shared the data with other parties (processors, recipients), you must also inform them that the data must be deleted. ### 4. Respond within one month Inform the data subject about your decision: - **If deleting**: confirm which data you have deleted - **If (partially) refusing**: explain which data you are retaining and on what grounds import TemplateTip from '@/components/TemplateTip.astro'; Confirm to the data subject which data you have deleted and which parties you have informed. Substantiate why you (partially) refuse a deletion request, with reference to the legal ground. ### 5. Document Record what you have deleted, what you have retained, and why. This is your evidence in case of a complaint. ## The pitfall of partial deletion In practice, the answer to a deletion request is rarely "delete everything" or "delete nothing". Usually it is: delete part and retain part with a valid reason. That is fine, but communicate it clearly to the data subject. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Right to Object: When Customers Say Stop URL: https://gdprwise.eu/en/kennisbank/rechten-en-verzoeken/right-to-object/ Summary: A customer objects to how you process their data. Depending on the type of objection, you may have to stop immediately or you may be able to refuse. This article explains the two types of objection, when each applies, and what to do step by step. Key takeaways: - A direct marketing objection is absolute - you must stop immediately with no exceptions - A legitimate interest objection requires a balancing test - you can refuse if your grounds override - Unsubscribing from a newsletter counts as exercising the right to object - After a successful objection you must stop processing, but retention for legal purposes may still be allowed FAQ: Q: Does unsubscribing from a newsletter count as an objection? A: Yes. Clicking an unsubscribe link is exercising the right to object to direct marketing under Article 21(2). You must stop sending marketing emails to that person immediately. This is the most common form of objection in practice. Q: What if I process data for multiple purposes? A: An objection applies to the specific purpose the person objects to. If you process their data for marketing and for contract performance, an objection to marketing means you stop the marketing but can continue processing for contract performance. Evaluate each purpose separately. Q: Do I need to delete data after an objection? A: Not necessarily. An objection means you must stop the specific processing the person objected to. You may still retain the data if you have another legal basis for keeping it - for example, a legal retention obligation or ongoing contract. However, if there is no other purpose, you should also erase the data. Q: Can I ask the person why they are objecting? A: For direct marketing, no - the right is absolute and no reason is needed. For legitimate interest objections, the person should describe their particular situation, but you cannot require a detailed justification. Even a brief reason is sufficient to trigger the balancing test. ## Two very different types of objection The right to object under Article 21 GDPR covers two situations that work very differently in practice. Getting them mixed up is one of the most common mistakes businesses make. **Type 1: Direct marketing objection (Article 21(2))** This is an absolute right. When someone objects to direct marketing, you must stop. No exceptions, no balancing test, no discussion. This includes profiling related to direct marketing. **Type 2: Legitimate interest objection (Article 21(1))** This is not absolute. When someone objects to processing based on legitimate interest (or public interest), you can continue processing if you demonstrate compelling legitimate grounds that override the interests of the data subject. This requires a balancing test. Knowing which type you are dealing with is the first thing to determine. ## Step 1: Register the objection As with any data subject request, log it immediately: - **Who** is objecting - **When** you received the objection (the one-month deadline starts now) - **Through which channel** it came in - **What they object to** - which processing activity or purpose import TemplateTip from '@/components/TemplateTip.astro'; Keep track of every request in a register: who, when, what was asked, and how it was handled. ## Step 2: Determine the type of objection Ask yourself: is the person objecting to **direct marketing**, or to **another type of processing**? **Signs of a direct marketing objection:** - "Stop sending me emails" - "Unsubscribe me from your newsletter" - "I don't want promotional messages anymore" - Clicking an unsubscribe link **Signs of a legitimate interest objection:** - "Stop recording me on CCTV" - "Stop monitoring my work activities" - "I don't want you to share my data with partners for fraud analysis" - "Stop processing my data for [specific purpose other than marketing]" If you are unsure, ask the person to clarify which processing activity they object to. But do not use this as a delay tactic. ## Step 3A: Handle a direct marketing objection If the objection is about direct marketing, the process is straightforward: 1. **Stop immediately.** Remove the person from all marketing lists. This includes email, postal mail, SMS, phone calls, and targeted advertising. 2. **No balancing test needed.** You cannot argue that your marketing interests override their objection. 3. **Confirm.** Inform the person that their objection has been processed and they will no longer receive marketing communications. 4. **Profiling too.** If you use profiling to target marketing (segmentation, personalised offers), stop that profiling for this person as well. 5. **Keep a suppression list.** Add the person to a suppression list so they are excluded from future campaigns. This is not the same as deleting their data - you need to remember not to contact them. The deadline is immediate, but in practice you should confirm within one month. ## Step 3B: Handle a legitimate interest objection If the objection is about processing based on legitimate interest, the process requires more work: 1. **Pause processing if possible.** While you assess the objection, consider pausing the processing activity if feasible. This is not strictly required, but it shows good faith. 2. **Conduct a balancing test.** Weigh your legitimate interest against the person's interests, rights, and freedoms. Consider: - How important is this processing for your business? - What is the impact on the person? - Are there less intrusive alternatives? - Did the person provide specific reasons related to their situation? 3. **Document your decision.** Write down your reasoning, whether you accept or refuse the objection. 4. **Inform the person.** Communicate your decision with a clear explanation. You can refuse the objection **only if** you demonstrate compelling legitimate grounds that override the data subject's interests. "We always do it this way" is not a compelling ground. ## Comparing the two types | | Direct marketing (Art. 21(2)) | Legitimate interest (Art. 21(1)) | |---|---|---| | **Trigger** | Person objects to marketing | Person objects to processing based on legitimate interest | | **Can you refuse?** | No, never | Yes, if you have compelling grounds | | **Balancing test needed?** | No | Yes | | **Response deadline** | Immediately (confirm within one month) | Within one month | | **What to do** | Stop all marketing to this person | Conduct balancing test, then decide | | **Reason required from the person?** | No | They should describe their particular situation | ## Common scenarios ### Scenario 1: Customer objects to email marketing **Type:** Direct marketing (absolute right) **Action:** Remove from all marketing lists immediately. Add to suppression list. Confirm. ### Scenario 2: Customer objects to CCTV in your shop **Type:** Legitimate interest objection **Action:** Conduct a balancing test. Security interests may override, but consider whether the person has a specific reason (e.g. they are a domestic abuse victim and fear being located). Document your decision. ### Scenario 3: Employee objects to workplace monitoring **Type:** Legitimate interest objection **Action:** Conduct a balancing test. Consider the necessity of the monitoring, whether less intrusive alternatives exist, and the employee's specific situation. In many cases, broad monitoring will be difficult to justify. ### Scenario 4: Customer objects to profiling for personalised pricing **Type:** Legitimate interest objection (if based on legitimate interest) or direct marketing (if the pricing is part of a marketing strategy) **Action:** Determine the legal basis first, then follow the appropriate process. ## What happens after a successful objection Once an objection is accepted: - **Stop the processing** that the person objected to - **Do not delete automatically.** You may still need to retain the data for other purposes (contract performance, legal obligations, defence of legal claims) - **Document** what processing was stopped and when - **Check downstream.** If you shared the data with processors or other controllers for the objected purpose, inform them of the objection ## Step 4: Document everything Record your full handling of the objection: when received, what type, what decision was made, the reasoning, and when the person was informed. This is your evidence if the data subject files a complaint with the supervisory authority. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Right to Rectification: Correcting Personal Data URL: https://gdprwise.eu/en/kennisbank/rechten-en-verzoeken/right-to-rectification/ Summary: A customer or employee says their data is wrong and wants it fixed. This article explains step by step how to handle a rectification request under the GDPR, from verifying the correction to informing recipients. Key takeaways: - You have one month to respond to a rectification request - Always verify the requester's identity before making changes - After correcting data, you must inform all recipients who received the incorrect data - Rectification includes both correcting inaccurate data and completing incomplete data FAQ: Q: Can I refuse a rectification request? A: Only in rare cases. If you can demonstrate that the data is actually accurate, you may refuse. Document your reasoning and inform the requester of their right to complain to the supervisory authority. Q: What if I disagree with the correction? A: If the accuracy of the data is disputed, the data subject can request restriction of processing while you investigate. You should assess the evidence on both sides and make a reasonable decision. If you refuse, explain your reasoning. Q: Do I need to correct data in backups? A: Backups are a grey area. You do not need to retroactively alter every backup, but you should ensure that if a backup is ever restored, the corrected data replaces the inaccurate version. Document your backup policy for these situations. ## What is a rectification request? Under **Article 16 of the GDPR**, every person has the right to have inaccurate personal data corrected without undue delay, often called the right to **data rectification**. They also have the right to have incomplete data completed. This right is one of the [8 data subject rights under the GDPR](/en/kennisbank/rechten-en-verzoeken/gdpr-data-subject-rights). In practice, a rectification request often looks simple: "My last name is spelled wrong in your system" or "You still have my old address." Handling it properly, however, requires a clear process. > **In short:** you have **one month** to correct inaccurate data after a valid request. Verify identity, correct the data in every system, inform any recipients (Article 19), and confirm the change in writing to the data subject. ## How fast must you respond? Article 12(3) sets the deadline at **one month** from receipt of the request. For complex or numerous requests you may extend this once by up to two further months, but you must inform the data subject within the first month and explain why. For a straightforward correction (a typo, an updated address), one month is generous. Most organisations resolve simple rectification requests within a few working days. ## Common rectification scenarios | Scenario | What to do | |---|---| | Typo in name | Correct in all systems, usually no proof needed | | Outdated address | Ask for confirmation of new address, update everywhere | | Wrong email address | Verify via the correct email, update all lists | | Incomplete data | Add the missing information (e.g. missing middle name) | | Name change after marriage | Reasonable to ask for supporting document | | Disputed factual data | Assess the evidence, consider restriction while investigating | ## Step 1: Register the request As soon as the request comes in, note down: - **Who** is making the request - **When** you received it (the one-month deadline starts now) - **Through which channel** it came in - **What data** they say is incorrect - **What the correct data** should be import TemplateTip from '@/components/TemplateTip.astro'; Use this template to confirm receipt of the rectification request and communicate the correction to the data subject. ## Step 2: Verify the identity Before changing any data, make sure the request comes from the right person. If someone impersonates a customer and changes their email address, that is a data breach. **How to verify:** - If the person has an account: have them confirm through that account - If you know the person (e.g. an employee): confirmation via the known email address is sufficient - For unknown persons: ask for a copy of an ID document with the national ID number and photo redacted ## Step 3: Verify the correction is accurate This step is often overlooked. Before making the change, check that the new data is actually correct. **Practical examples:** - For an address change, you could ask for a recent utility bill or official document - For a name change (e.g. after marriage), a marriage certificate or updated ID is reasonable - For a simple typo, the context usually makes it obvious You do not need to demand proof for every minor correction. Keep it proportionate. A typo in a first name does not need the same level of evidence as changing an entire identity record. ## Step 4: Make the correction Update the data in **all systems** where the incorrect data is stored: - **CRM system** - customer records, notes - **Email marketing** - mailing lists, contact details - **Accounting** - invoices, payment records - **HR system** - if it concerns an employee - **Website** - account profiles, form data - **Paper files** - contracts, printed correspondence Be thorough. If you correct data in your CRM but forget the mailing list, you are still processing inaccurate data. ## Step 5: Inform recipients (Article 19) This is the step most organisations miss. Under Article 19, you must notify every recipient to whom you disclosed the incorrect data, unless this proves impossible or involves disproportionate effort. **Think about:** - Partners or processors who received the data - Third parties you shared it with (e.g. a delivery service with the wrong address) - Other group companies that have a copy You must also inform the data subject about these recipients if they ask. ## Step 6: Respond to the data subject Send a clear response within one month: - Confirm which data was corrected - Explain what you changed and in which systems - Mention that recipients have been informed (or explain why not) ## What if the data came from a third party? If you did not collect the data yourself but received it from another source, you still need to correct it. You should also inform the source about the inaccuracy so they can correct their own records. If you cannot verify the accuracy of the new data because you rely on the original source, explain this to the data subject and consider restricting processing of the disputed data until it is resolved. ## Frequently asked questions **Can I refuse a rectification request?** Only if you can demonstrate the data is actually correct. For example, if a customer claims their date of birth is wrong but your records match their original ID verification, you may refuse. Always document your reasoning and inform the requester of their right to complain to the supervisory authority. **What if I disagree with the correction?** If the accuracy of the data is in dispute, the data subject can request restriction of processing while you investigate. Assess the evidence fairly. If you still refuse after investigation, explain why in writing. **Do I need to correct data in backups?** You do not need to alter every historical backup retroactively. However, you should ensure that if a backup is restored, the corrected data overwrites the inaccurate version. Document your approach to backup corrections in your data processing procedures. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Right to Restriction of Processing: When and How URL: https://gdprwise.eu/en/kennisbank/rechten-en-verzoeken/right-to-restriction/ Summary: A customer says 'stop using my data while we sort this out.' This article explains step by step how to handle a restriction request under the GDPR, including the four legal grounds and practical implementation. Key takeaways: - Restriction means you can store the data but not process it further - There are four specific grounds under Article 18 where restriction applies - You must inform the data subject before lifting a restriction - You have one month to respond to a restriction request FAQ: Q: What is the difference between restriction and erasure? A: With erasure, the data is deleted permanently. With restriction, the data is kept but you cannot use it. Restriction is often used when the data may still be needed - for example, during a dispute about accuracy or when the data subject needs it for legal claims. Q: Can I still back up restricted data? A: Storage is explicitly allowed during restriction. Backing up restricted data as part of normal storage operations is generally acceptable. However, you must not use the backup data for any processing purpose beyond mere storage. Q: What if I accidentally process restricted data? A: This is a potential data breach. Document what happened, assess the risk to the data subject, and notify them. If the risk is high, you may need to notify the supervisory authority within 72 hours. Review your technical controls to prevent it from happening again. ## What is restriction of processing? Under Article 18 of the GDPR, a data subject can ask you to restrict the processing of their personal data. This means you can still **store** the data, but you cannot **use** it - no sending, no analysing, no sharing, no decision-making based on it. Think of it as putting data in a locked drawer. It is still there, but nobody touches it until the situation is resolved. ## When does the right apply? There are exactly four grounds under which a data subject can request restriction. You must apply restriction if any of these situations applies. ### Ground 1: Accuracy is contested The data subject says the data is incorrect and you need time to verify. During that verification period, the data must be restricted. **Example:** A customer claims their date of birth in your system is wrong. While you check your original records, you restrict processing of that data. ### Ground 2: Processing is unlawful, but no deletion wanted The processing is unlawful (e.g. no valid legal basis), but the data subject prefers restriction over erasure. **Example:** You collected email addresses without proper consent. Instead of requesting deletion, a customer says "keep my data but don't use it until you have my consent." ### Ground 3: Data needed for legal claims You no longer need the data for your original purpose, but the data subject needs it to establish, exercise, or defend legal claims. **Example:** A former employee asks you to keep their performance records even though your retention period has expired, because they need the records for an ongoing employment dispute. ### Ground 4: Objection pending verification The data subject has objected to processing under Article 21, and you are verifying whether your legitimate grounds override theirs. **Example:** A customer objects to your direct marketing profiling. While you assess whether your legitimate interest overrides their objection, you restrict the profiling. ## Step 1: Register the request As soon as the request comes in, note down: - **Who** is making the request - **When** you received it (the one-month deadline starts now) - **Through which channel** it came in - **Which ground** applies (or let the data subject explain their reason) - **Which data** should be restricted import TemplateTip from '@/components/TemplateTip.astro'; Keep track of every request in a register: who, when, what was asked, and how it was handled. ## Step 2: Verify the identity Before restricting data, confirm you are dealing with the right person. The same verification rules apply as with other data subject requests: - Account holders: confirm through their account - Known persons: confirmation via known email - Unknown persons: request a redacted copy of an ID document ## Step 3: Implement the restriction This is where it gets practical. You need to ensure that the data is stored but not processed in any other way. Here are concrete approaches: | Method | How it works | |---|---| | Flag in CRM | Add a "restricted" flag or status to the record so staff know not to use it | | Separate folder | Move the data to a restricted-access folder or database table | | Access restriction | Remove processing permissions for the record, keeping only read access for authorised staff | | System block | If your system supports it, block the record from being included in mailings, reports, or automated processes | **What you must stop doing:** - Sending marketing or communications using the data - Including the data in analyses or reports - Sharing the data with third parties - Making any decisions based on the data **What you can still do:** - Store the data - Process it with the data subject's consent - Process it for legal claims - Process it to protect the rights of another person - Process it for important public interest reasons ## Step 4: Inform recipients (Article 19) Just like with rectification and erasure, you must notify any recipients who received the data that processing is now restricted, unless this is impossible or involves disproportionate effort. ## Step 5: Respond to the data subject Send a clear response within one month: - Confirm that the restriction has been applied - Explain which data is affected - Describe how you have implemented the restriction - If you refuse (in whole or in part), explain why and inform them of the right to complain to the supervisory authority ## When to lift the restriction This is critical: you **must inform the data subject before lifting the restriction**. You cannot simply start processing the data again without telling them. The restriction can be lifted when: - The accuracy dispute is resolved and the data is confirmed correct - The unlawful processing issue is resolved (e.g. consent is obtained) - The legal claims for which the data was kept are concluded - Your verification of the Article 21 objection is complete Always notify the data subject in advance. Give them a reasonable opportunity to respond before you resume processing. ## Common implementation challenges **CRM systems without restriction flags** Many standard CRM systems do not have a built-in "restricted" status. Workarounds include: - Adding a custom field or tag - Moving the record to a separate "restricted" list - Adding a note to the record with clear instructions for staff **Automated processes** Check whether any automated workflows (email sequences, reporting, data syncs) include the restricted data. You may need to create exclusion rules or manually remove the record from automated processes. **Shared databases** If multiple departments or systems access the same data, make sure all of them respect the restriction. A restriction in your CRM is useless if the marketing team can still pull the data from a shared database. ## Frequently asked questions **What is the difference between restriction and erasure?** With erasure, the data is permanently deleted. With restriction, the data is kept but you cannot use it. Restriction is useful when the data may still be needed - for example, during a dispute about accuracy, or when the data subject needs the data for legal claims. **Can I still back up restricted data?** Storage is explicitly allowed during restriction. Including restricted data in regular backups as part of normal storage operations is generally acceptable. However, you must not actively use backup data for any processing purpose beyond storage. **What if I accidentally process restricted data?** This is a potential data breach. Document what happened, assess the risk to the data subject, and inform them. If the risk is high, you may need to notify the supervisory authority within 72 hours. Review your technical controls to prevent recurrence. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ## Templates ### GDPR-Compliant Footer for Your Business Emails URL: https://gdprwise.eu/en/kennisbank/sjablonen/template-email-footer/ Summary: Every business email you send should include a link to your privacy policy. This article explains why, what to include, and gives you a ready-to-use template. Key takeaways: - The GDPR requires you to inform data subjects about how you process their data, including during email correspondence - A link to your privacy policy in your email footer is the simplest way to fulfil this information obligation - The footer doesn't need to be long - a short text with a link is sufficient - Don't forget to also add a privacy reference to your newsletter emails and automated messages FAQ: Q: Is a privacy link in my email footer mandatory? A: The GDPR requires you to inform data subjects about the processing of their personal data. An email address is personal data. By including a link to your privacy policy in your footer, you fulfil this obligation in a simple way. Q: Should every employee use the same footer? A: It's recommended. Set a standard footer for the entire organisation via your email system. That way you're sure every outgoing email contains the correct reference. Q: Does this also apply to personal emails? A: No, the GDPR applies to business processing of personal data. Personal emails fall under the 'household exception'. But as soon as you email on behalf of your company, it's a business processing activity. ## Why a privacy reference in your email? Every time you send a business email, you process personal data: the recipient's email address, and often also name, company, and other contact details. The GDPR requires you to inform data subjects about how you process their data. The simplest way to do this: a short reference to your privacy policy in your email footer. It takes five minutes to set up and covers an important part of your information obligation. ## The template Here is a ready-to-use template you can customise for your business: ### Option 1: Minimal ``` [Company name] respects your privacy. Read our privacy policy: [link to privacy policy] ``` ### Option 2: Standard ``` --- This message may contain confidential information and is intended solely for the addressee. If you have received this message in error, please notify us and delete the message. [Company name] processes personal data in accordance with the GDPR. More information: [link to privacy policy] ``` ### Option 3: Comprehensive ``` --- [First name Last name] | [Position] [Company name] [Address] | [Phone] | [Website] We value your privacy. [Company name] processes personal data in accordance with the General Data Protection Regulation (GDPR). Read our privacy policy at [link to privacy policy]. If you no longer wish to receive communications from us, please contact us at [email address]. ``` ## What to look out for ### The link must work Sounds obvious, but regularly check that the link to your privacy policy still works. A dead link is worse than no link. ### Update when things change If you move your privacy policy to a different URL, also update your email footer. This is often forgotten. ### Set it up centrally Configure the footer centrally in your email system (Microsoft 365, Google Workspace) so every employee automatically gets the correct footer. ### Don't forget automated emails Besides your regular emails, you probably also send: - **Confirmation emails** from orders or sign-ups - **Invoice emails** from your accounting software - **Newsletters** from your email tool - **Notifications** from your CRM or helpdesk All these emails should include a reference to your privacy policy. For newsletters, an unsubscribe link is also mandatory. ## A small effort with big impact Setting up a GDPR-compliant email footer takes five minutes. It shows you take privacy seriously, informs your contacts about their rights, and protects you in case of a complaint. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Template: Confirmation That Data Has Been Corrected URL: https://gdprwise.eu/en/kennisbank/sjablonen/template-rectification-confirmation/ Summary: Someone requested correction of personal data and you have carried it out? Use this template to confirm the correction, including notification to third parties. Key takeaways: - Always confirm in writing that you have corrected the data - Inform third parties if you shared the incorrect data with them - Make a backup of the current data before correcting FAQ: Q: Do I need to inform third parties about the correction? A: Yes, if you shared the incorrect data with recipients (e.g. processors), you must inform them about the correction, unless this is impossible or involves disproportionate effort. Q: What if I don't consider the data incorrect? A: If you believe the data is correct, explain this with reasons to the requester. The data subject can then file a complaint with the supervisory authority. import CopyBlock from '@/components/CopyBlock.astro'; ## When to use this template Use this template after someone has asked for correction of incorrect personal data and you have made the change. **Tip:** always make a backup of the current data before correcting. Many software packages allow the user to update data themselves via the web interface - that's the easiest route. **Before correcting:** always first verify the [requester's identity](/en/kennisbank/sjablonen/template-identity-verification). ## Template with third-party notification Use this version if you have previously shared the data with third parties. ## Template without third-party notification ## Considerations - Respond within one month. For complex or numerous requests, you may extend the deadline to three months, provided you inform the requester - Check that you haven't missed any systems; personal data often exists in both electronic and paper files - Save a copy of your response in your [request register](/en/kennisbank/sjablonen/template-request-register) import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Template: Confirmation That Data Has Been Deleted URL: https://gdprwise.eu/en/kennisbank/sjablonen/template-deletion-confirmation/ Summary: Someone requested deletion of personal data and you have carried it out? Use this template to confirm the deletion, including notification to third parties. Key takeaways: - Always confirm in writing that you have deleted the data - Warn that deletion may affect access to your service - Inform third parties if you have shared the data with them FAQ: Q: Do I also need to delete backups? A: In principle yes, as far as technically feasible and reasonable. If data is in backups that you cannot selectively modify, document this and delete the data when the backup expires. Q: Do I need to inform third parties? A: Yes, if you have shared the personal data with recipients (such as processors), you must inform them about the deletion, unless this is impossible or involves disproportionate effort. import CopyBlock from '@/components/CopyBlock.astro'; ## When to use this template Use this template after you have received, assessed, and carried out a deletion request. You are confirming that the data has been erased. **Before deleting:** always first verify the [requester's identity](/en/kennisbank/sjablonen/template-identity-verification). And check whether you are legally required to retain the data. If so, use the [refusal template](/en/kennisbank/sjablonen/template-deletion-refusal). ## Template with third-party notification Use this version if you have previously shared the data with third parties (processors, partners). ## Template without third-party notification Use this version if you have not shared the data with third parties. ## Checklist before sending - Check that you have deleted the data in all systems (not just the database, also email, backups, paper files) - If you're not sure which systems you have, consult your processing register - Save a copy of your response in your [request register](/en/kennisbank/sjablonen/template-request-register) import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Template: Cookie Audit for Your Website URL: https://gdprwise.eu/en/kennisbank/sjablonen/template-cookie-audit/ Summary: The GDPR requires you to know which cookies your website places and why. Use this template to map your cookies and get your cookie policy in order. Key takeaways: - You must know which cookies your website places before asking for consent - Many cookies don't come from you but from third parties (Google Analytics, Facebook Pixel, chat widgets) - Without a cookie audit, your cookie banner doesn't match reality and you risk a fine - Repeat the audit at least annually or after every major website change FAQ: Q: How do I know which cookies my website places? A: Open your website in an incognito window, open the browser developer tools (F12), go to the Application > Cookies tab. You'll see all cookies being placed. Additionally, use a scanner (like GDPRWise) to detect hidden trackers and third-party cookies. Q: Do I need to document first-party cookies too? A: Yes. All cookies must be documented in your cookie policy, both first-party (your own cookies) and third-party (cookies from external services). Q: How often should I do a cookie audit? A: At least once a year, and after every significant change to your website (new tools, plugins, tracking scripts). Websites change continuously and cookies can be added unnoticed. Q: What if I find cookies I don't recognise? A: Look up the cookie name in a cookie database (such as cookiedatabase.org) or contact your website developer. Unknown cookies often come from plugins, ad networks, or analytics tools installed at some point. ## Why a cookie audit? Your cookie banner asks visitors for consent to cookies. But if you don't know exactly which cookies your website places, that consent doesn't match reality. And a cookie banner that doesn't match reality is worse than no cookie banner. Supervisory authorities actively check cookie compliance. The French CNIL imposed fines up to 150 million euros on large tech companies for cookie violations in 2022. For SMEs, fines are smaller, but the risk is real. ## Step 1: Inventory your cookies Use the template below to document each cookie. | Cookie name | Type | Party | Purpose | Duration | Consent? | |-------------|------|-------|---------|----------|----------| | `_ga` | Analytics | Third-party (Google) | Visitor statistics | 2 years | Yes | | `_gid` | Analytics | Third-party (Google) | Session identification | 24 hours | Yes | | `_fbp` | Marketing | Third-party (Facebook) | Facebook Pixel tracking | 3 months | Yes | | `PHPSESSID` | Functional | First-party | Session ID cart/login | Session | No | | `cookie_consent` | Functional | First-party | Remembers cookie choice | 1 year | No | | *[name]* | *[type]* | *[party]* | *[purpose]* | *[duration]* | *[yes/no]* | ## Step 2: Categorise your cookies The GDPR and ePrivacy Directive distinguish four categories: **Strictly necessary (no consent required)** Cookies essential for the website to function. Examples: session cookies, shopping cart cookies, cookie preferences. **Functional (consent recommended)** Cookies that provide extra functionality but are not strictly necessary. Examples: language preference, chat widget status. **Analytics (consent required)** Cookies that measure visitor behaviour. Examples: Google Analytics, Hotjar, Matomo (unless configured without cookies). **Marketing (consent required)** Cookies for advertising purposes and tracking. Examples: Facebook Pixel, Google Ads remarketing, LinkedIn Insight Tag. ## Step 3: Check your cookie banner After the audit, check that your cookie banner: - **Lists all cookies** in the correct category - **Offers a real choice**: "Accept" and "Refuse" equally prominent, no dark patterns - **Only places cookies after consent**: non-essential cookies may only be activated after the visitor gives consent - **Remembers the choice**: a visitor who refuses must not be asked again on every visit - **Contains a link** to your full cookie policy ## Step 4: Repeat regularly Websites change continuously. A new WordPress plugin, a chat widget, a social media share button - they can all place cookies without you knowing. Schedule your cookie audit: - **Annually** as a minimum - **After every major website change** (new tools, redesign, new marketing campaign) - **After a report or complaint** from a visitor import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Template: Data Breach Notification to the Supervisory Authority URL: https://gdprwise.eu/en/kennisbank/sjablonen/template-breach-notification/ Summary: A data breach must be reported to the supervisory authority within 72 hours. Use this template to report quickly and correctly, with all required information. Key takeaways: - A data breach must be reported to the supervisory authority within 72 hours of discovery - Not every breach needs to be reported - only if there is a risk to data subjects' rights - If the risk is high, you must also inform the data subjects themselves - Document every breach in your breach register, even if you don't report it FAQ: Q: When must I report a data breach? A: You must report a data breach to the supervisory authority if it is likely to pose a risk to the rights and freedoms of data subjects. Think of: loss of customer data, unauthorised access to personnel files, or a phishing attack where login credentials were compromised. Q: What if I don't make the 72-hour deadline? A: Report it anyway as soon as possible and explain why the notification was delayed. A late notification with explanation is always better than no notification. Q: Do I also need to inform the data subjects? A: Only if the breach poses a high risk to their rights and freedoms. For example, leaked financial data, medical records, or login credentials. For encrypted data that was leaked, the risk is generally lower. Q: Where do I report a data breach? A: To the supervisory authority in the country where your main establishment is located. In the UK, this is the ICO. In the EU, each country has its own authority. import CopyBlock from '@/components/CopyBlock.astro'; ## When must you report a data breach? A data breach is any breach of security that leads to the destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to personal data. Examples: - An employee sends a file with customer data to the wrong email address - Your laptop with unencrypted personnel files is stolen - A hacker gains access to your CRM system - A USB drive with customer data goes missing - A ransomware attack encrypts your database **Not every breach needs to be reported.** You only report to the supervisory authority if the breach is likely to pose a risk to the rights of the data subjects. In doubt? Report it. An unnecessary notification has no consequences; a missed one does. ## Step 1: Notification to the supervisory authority (within 72 hours) ## Step 2: Notification to data subjects (for high risk) If the breach poses a **high risk** to data subjects, you must also inform them directly. ## Step 3: Document in your breach register Every data breach must be recorded in a breach register, even if you decide not to report it to the supervisory authority. The authority can request this register. Document per incident: - Date of discovery and date of incident - Description of the breach - Categories and numbers of data subjects and data - Consequences and measures taken - Whether you reported it to the authority (and if not, why not) - Whether you informed data subjects (and if not, why not) ## Where to report | Country | Authority | Method | |---------|-----------|--------| | Belgium | Data Protection Authority (GBA) | Online form at gegevensbeschermingsautoriteit.be | | Netherlands | Data Protection Authority (AP) | Breach reporting desk at autoriteitpersoonsgegevens.nl | | Germany | BfDI / State authority | Varies per state | | France | CNIL | Online form at cnil.fr | | UK | ICO | Online form at ico.org.uk | ## Common mistakes - **Reporting too late** because you want to investigate internally first - start the notification within 72 hours, you can supplement later - **Not reporting because it was "just" an email** - a misdirected email with personal data is a data breach - **Not informing data subjects** at high risk - this is a separate obligation alongside the authority notification - **Not keeping a breach register** - even breaches you don't report must be documented import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Template: Data Processing Agreement (DPA) URL: https://gdprwise.eu/en/kennisbank/sjablonen/template-dpa/ Summary: A data processing agreement is mandatory with every party that processes personal data on your behalf. Use this template as a basis, customise it for your situation, and sign it with your processors. Key takeaways: - You need a data processing agreement with every party that processes personal data on your behalf - Think of your accountant, email tool, cloud storage, payroll provider, and website host - Without a processing agreement, you risk a fine of up to 10 million euros or 2% of annual turnover - Many large processors (Google, Microsoft, Mailchimp) offer standard DPAs that you can accept online FAQ: Q: With whom do I need a processing agreement? A: With every external party that processes personal data on your behalf. Common examples: your accountant, email marketing tool (Mailchimp, ActiveCampaign), cloud storage (Google Workspace, Microsoft 365), payroll provider, website host, and CRM system. Q: What if my processor already has a standard DPA? A: Many large parties like Google, Microsoft, and Mailchimp offer standard processing agreements that you can accept online. Check that their DPA meets GDPR requirements and save a copy. Q: Can I use the same processing agreement for all my processors? A: The basic structure is the same, but you must fill in the specific details per processor: which data is processed, for what purpose, and what security measures apply. Q: What if my processor refuses to sign a DPA? A: Then you may not engage that party for processing personal data. Find an alternative processor who is willing to sign a processing agreement. import CopyBlock from '@/components/CopyBlock.astro'; ## When do you need a processing agreement? As soon as you have personal data processed by an external party, you are required to enter into a data processing agreement (also called DPA - Data Processing Agreement). This is not optional - it is a legal requirement under Article 28 of the GDPR. Many business owners think this only applies to large companies or complex IT systems. But if you have an accountant who has access to your customer data, or if you use Mailchimp for your newsletter, you already need a processing agreement. ### Common processors for SMEs - **Accountant** - has access to customer and employee data - **Email marketing** (Mailchimp, ActiveCampaign, Sendinblue) - stores email addresses and behavioural data - **Cloud storage** (Google Workspace, Microsoft 365, Dropbox) - stores files that may contain personal data - **Website host** (various providers, Cloudflare) - processes IP addresses and sometimes form data - **CRM system** (HubSpot, Salesforce, Teamleader) - contains customer data - **Payroll provider** - processes employee data - **Booking platform** (Booking.com, own booking system) - customer and payment data ## The template The template below covers the minimum requirements of Article 28 GDPR. Customise it with your own business details and the specific processing details. ## How to use this template 1. **Fill in your own details** and those of the processor 2. **Be specific** about the purpose, type of data, and categories of data subjects - "data processing" is too vague 3. **Inventory sub-processors** - ask your processor which third parties they engage 4. **Check transfers** - does your processor process data outside the EU? Then additional safeguards are needed 5. **Have both parties sign** and keep a copy ## Processors that already have a standard DPA Many large platforms offer their own processing agreement. You don't need to use this template then, but check that their DPA covers the GDPR requirements: - **Google Workspace** - DPA available via Admin Console - **Microsoft 365** - DPA part of service terms - **Mailchimp** - DPA available on their website - **HubSpot** - DPA available via account settings - **Stripe** - DPA part of service terms - **AWS / Azure / Google Cloud** - DPAs available per service Always save a copy of the signed or accepted DPA. ## Common mistakes - **Not having a DPA** with your accountant or payroll provider - these are processors - **Using a generic template** without customising it for the specific processing - **Forgetting sub-processors** - if your processor uses Zendesk for support, Zendesk is a sub-processor - **Forgetting transfers outside the EU** - many cloud services process data in the US - **Not updating the DPA** when the processing changes import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Template: Data Subject Request Register URL: https://gdprwise.eu/en/kennisbank/sjablonen/template-request-register/ Summary: Keep track of all GDPR requests you receive in a register. This template helps you document what you received, when, and how you responded. Key takeaways: - You are required to document all received requests - The supervisory authority can request your register at any time - Always record the type of request, the date, and the handling status - Keep the register separate from the personal data itself FAQ: Q: Am I required to keep a request register? A: The GDPR requires you to demonstrate that you handle requests correctly (accountability). A request register is the most practical way to do this. Q: How long should I keep the register? A: There is no specific period prescribed, but it is advisable to keep the register for at least 3 years, so that you can demonstrate how you acted in case of an inspection or complaint. ## Why a request register? All organisations must inform data subjects about their GDPR rights and have the right processes in place to handle requests promptly. It is important to correctly document each received request: - The supervisory authority can request your register at any time - In case of a complaint, you can demonstrate that you responded correctly and on time - You keep oversight of which requests are still open ## The template We have created a ready-to-use Google Sheets template that you can copy and use directly: **[Open the request register in Google Sheets](https://docs.google.com/spreadsheets/d/10CMmJGM35S3QuQBza8tp9SWPgmrCLMcVEIA8F-kbC-M/edit?usp=sharing)** Make a copy via *File > Make a copy* and fill in a row for each received request. ## What information to record For each request, you should record at minimum: - **Date of receipt** - this determines your deadline (one month) - **Type of request** - access, deletion, correction, restriction, portability, objection - **Name and contact details** of the requester - **Whether identity was verified** - and how (ID copy, logged-in account, etc.) - **Date of your response** - to prove you responded within the deadline - **Result** - handled, refused (with reason), or referred - **Any notes** - specifics, e.g. "2-month extension requested" ## Tips - Keep the register **separate** from the personal data itself - Set a reminder for requests that are still open - Use the [response templates](/en/kennisbank/sjablonen/template-dsar-confirmation) to respond quickly and correctly import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Template: Identity Verification for a GDPR Request URL: https://gdprwise.eu/en/kennisbank/sjablonen/template-identity-verification/ Summary: Not sure if a request is really from the right person? Use this template to verify the requester's identity before sharing or deleting data. Key takeaways: - Always verify identity before sharing, correcting, or deleting data - Offer alternatives if the requester doesn't want to send an ID copy - You may ask them to redact the national ID number and photo - Delete the ID copy immediately after verification FAQ: Q: Must I always ask for an ID copy? A: Not necessarily. If you can verify identity in another way (e.g. via a logged-in account or a previously verified email address), that is also sufficient. An ID copy is an option, not a requirement. Q: What if the requester doesn't want to send an ID? A: That's understandable. Offer alternatives such as verification via a logged-in account, answering security questions, or a video call. The goal is reasonable certainty, not a perfect match. import CopyBlock from '@/components/CopyBlock.astro'; ## When to use this template Before responding to an access request, deletion request, or correction request, you must ensure that the request is genuinely from the right person. Otherwise you risk sharing data with someone who has no right to it. Use this template as your first response when you cannot verify the requester's identity based on the available information. ## The template ## Alternative verification methods Not everyone wants to send an ID copy, and they don't have to. Other options: - **Logged-in account** - if the request comes via a logged-in customer portal, identity is already verified - **Verified email address** - if the request comes from an email address already in your system - **Security questions** - ask questions that only the data subject can answer - **Video call** - for sensitive requests, a brief video call may help The goal is **reasonable certainty**, not a perfect match. Choose the method appropriate to the risk. ## Important - Delete the ID copy **immediately after verification** - do not retain it - Never ask for more information than necessary for verification - Verification should not unreasonably delay the request; try to confirm within a week import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Template: Refusing Deletion (Legal Retention Obligation) URL: https://gdprwise.eu/en/kennisbank/sjablonen/template-deletion-refusal/ Summary: You cannot fulfil a deletion request because you are legally required to retain the data? Use this template to refuse correctly. Key takeaways: - You may refuse a deletion request if you have a legal retention obligation - Always clearly explain why you cannot fulfil the request - State when the data will be deleted - Inform the requester of their right to file a complaint with the supervisory authority FAQ: Q: When may I refuse a deletion request? A: You may refuse if the data is needed for a legal obligation (e.g. fiscal retention), for exercising the right to freedom of expression, or for establishing or exercising legal claims. Q: Must I state the reason for refusal? A: Yes, you must clearly explain why you cannot fulfil the request and on which legal basis you retain the data. import CopyBlock from '@/components/CopyBlock.astro'; ## When to use this template Use this template when someone requests deletion of personal data, but you cannot delete the data due to a legal obligation. Think of: - **Fiscal retention obligation** (7 years for accounting documents) - **Employment law retention obligation** (personnel files) - **Legal reporting obligations** (e.g. anti-money laundering regulations) You may only retain the data that you are legally required to keep. Data that you do not need to retain must still be deleted. ## The template ## Tips when refusing - Always mention the **specific law** that imposes the retention obligation, not just "legal obligation" - State **when** the data will be deleted - If you can delete part of the data, do so and confirm with the [deletion confirmation template](/en/kennisbank/sjablonen/template-deletion-confirmation) - Always point out the right to file a complaint with the supervisory authority - Save a copy of your response in your [request register](/en/kennisbank/sjablonen/template-request-register) import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Template: Response to an Access Request URL: https://gdprwise.eu/en/kennisbank/sjablonen/template-dsar-confirmation/ Summary: Someone is asking for access to their personal data? Use this ready-to-use template to respond correctly. Copy, fill in your details, and send. Key takeaways: - Always verify the requester's identity first - You have a maximum of one month to provide the complete overview - Always include a copy of your privacy policy - The first request must always be processed free of charge; only for repeated or excessive requests may you charge a reasonable fee FAQ: Q: How quickly must I respond to an access request? A: You must provide a complete overview within one month of receipt. It is advisable to confirm receipt as soon as possible. Q: Do I have to provide all data? A: Yes, you must provide an overview of all personal data you process about the data subject, across all systems. Redact data of other persons if it appears in the same file. import CopyBlock from '@/components/CopyBlock.astro'; ## When to use this template When you receive a request for access to personal data (an "access request" or DSAR), you must provide the requester with an overview of all personal data you hold about them. **Before you respond:** always verify first whether the request is genuinely from the right person. Use our [identity verification template](/en/kennisbank/sjablonen/template-identity-verification) if in doubt. ## The template ## Checklist before sending - Check that you have searched all systems (CRM, email, accounting, HR, paper files) - Include an overview of the processed data, or as an attachment - Always include a copy of your privacy policy - State for which purposes you process the data - Redact data of other persons if it appears in the same file - Save a copy of your response in your [request register](/en/kennisbank/sjablonen/template-request-register) Need more context? Read our [complete guide to data subject rights](/en/kennisbank/rechten-en-verzoeken/gdpr-data-subject-rights). import ArticleCTA from '@/components/ArticleCTA.astro'; --- ## GDPR Obligations ### 10 Reasons to Get Your GDPR in Order Now URL: https://gdprwise.eu/en/kennisbank/verplichtingen/10-reasons-gdpr-now/ Summary: Procrastination on GDPR is understandable but risky. Here are 10 concrete reasons why it's wise to act now, not tomorrow. Key takeaways: - Supervisory authorities are becoming more active and increasingly targeting SMEs - A data breach without preparation costs more time, money, and reputation than prevention - GDPR compliance is increasingly a prerequisite in business relationships - It is less work than you think, especially with the right tools FAQ: Q: I've done nothing about GDPR for years and nothing happened. Why start now? A: Supervisory authorities are stepping up enforcement, including towards SMEs. The risk also grows as your business becomes more digital and processes more data. It's a matter of when, not if. Q: How much can a fine cost for a small business? A: Fines for SMEs range from a few thousand to tens of thousands of euros. The Belgian GBA and the Dutch AP regularly fine small businesses, often for missing a privacy policy or failing to report a data breach. ## Still haven't started? Here are 10 reasons to do it now We get it. You have a business to run and GDPR isn't at the top of your priority list. But here are 10 concrete reasons why it's wise to take action now. ## 1. Supervisory authorities are becoming more active In the first years after 2018, supervisory authorities focused on large companies. That has shifted. The Dutch AP, the Belgian GBA, and other European regulators are increasingly targeting SMEs. Spot checks, sector investigations, and complaint handling are on the rise. ## 2. A data breach could happen tomorrow You don't need to be hacked for a data breach. A misdirected email, a lost laptop, an employee forwarding customer data to a personal email address - these are all data breaches. Without preparation, that costs you days of crisis management. ## 3. Customers are becoming more aware Consumers increasingly know their rights. They read privacy policies, request access to their data, and file complaints with regulators. A business without a privacy policy stands out - and not in a good way. ## 4. It's a requirement in B2B More and more businesses require their suppliers to demonstrate GDPR compliance. Without a processing agreement or privacy policy, you miss business opportunities. ## 5. Your website is your business card A website without a cookie banner, without a privacy policy, or with trackers running without consent - that's not just a violation but also a bad first impression. ## 6. Employees have rights too The GDPR doesn't only apply to customer data. Your employees also have a right to privacy. Personnel files, sick leave records, access credentials - all of this must be managed correctly. ## 7. Fines are avoidable A fine of 5,000 or 10,000 euros is a significant hit for a small business. The cost of compliance is a fraction of that, especially with a tool like GDPRWise. ## 8. It's less work than you think Most SME owners overestimate how much work GDPR compliance takes. With the right approach and tools, you can get the basics in order in a few hours. Not weeks - hours. ## 9. You protect yourself and your customers GDPR compliance isn't just an obligation; it's also a way to protect your business and your customers. Good security, clear agreements, and transparent communication prevent problems. ## 10. It gives you peace of mind Perhaps the most important reason: once your GDPR is in order, you can stop worrying about it. No fear of a letter from the regulator, no panic during an incident, no awkward questions from customers. ## Ready to get started? You don't need to finish everything today. But start. The free scan is a good starting point: within 2 minutes you'll know where you stand. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### AI Tools and Privacy: What Should You Watch Out For? URL: https://gdprwise.eu/en/kennisbank/verplichtingen/ai-tools-privacy-gdpr/ Summary: ChatGPT, Copilot, Midjourney - more and more businesses use AI tools. But what personal data goes in? Who is the processor? And do you need a processing agreement? This article explains the GDPR implications. Key takeaways: - Everything you enter into an AI tool may be used to train the model, unless you explicitly disable that - If you enter personal data into an AI tool, that is processing under the GDPR - Italy temporarily banned ChatGPT in 2023 over privacy violations - a warning for all of Europe - You need a processing agreement with your AI provider if you process personal data through the tool FAQ: Q: Can I enter customer data into ChatGPT? A: That is risky. If you enter personal data (names, emails, complaints, medical information), you are processing that data through a third party. You then need a processing agreement with OpenAI, you must include it in your processing register, and you must inform the data subjects. The safest advice: do not enter identifiable personal data. Q: Is OpenAI a processor under the GDPR? A: With the free version of ChatGPT, OpenAI is often a (joint) controller, as they may use data for training. With the Enterprise or API version, OpenAI acts as a processor and a DPA is available. Always check the specific terms of your subscription. Q: Do I need to include AI tools in my processing register? A: Yes, if you process personal data through those tools. Document which tool you use, what data goes in, the purpose, the legal basis, and whether there is a processing agreement. Q: Can I use AI to evaluate job applications? A: Only under strict conditions. Automated decision-making about individuals falls under Article 22 of the GDPR. Applicants have the right not to be subject to a decision based solely on automated processing. You need a DPIA and must guarantee human intervention. ## AI is everywhere, including your business More and more businesses use AI tools in their daily work. ChatGPT for writing emails, Copilot for generating code, Midjourney for images, or AI features in their CRM to analyse customer data. Convenient, but from a GDPR perspective there are serious implications. The core question is simple: what data goes into the AI tool, and what happens to it? And if you process personal data through any external AI tool, you must also disclose that tool in your privacy policy and your processing register. ## Five everyday scenarios in your business The risk is not theoretical. These are the situations we see every day: 1. **ChatGPT for professional emails.** You paste a draft that contains names, addresses, a description of a customer's situation, or a quote into ChatGPT to have it rewritten or polished. 2. **Microsoft Copilot in Outlook or Office.** Copilot summarises an email thread or drafts a reply based on emails that contain client, partner, supplier, or staff personal data. 3. **AI extensions on contact forms.** A plugin auto-sends submissions from your website's contact form into a CRM or ticketing tool, with AI rewriting or classifying the contents along the way. 4. **AI chatbots on your website.** A chatbot answers customer-service questions and stores the conversation, including any personal data the visitor entered. 5. **SaaS marketing tools.** A marketing platform uses AI to generate personalised content based on customer profile data already in your account. Each of these is a processing activity under the GDPR. Each requires you to know which provider is involved, what data goes in, and on what basis you are processing it. ## What makes AI tools different? With traditional software (your accounting system, your CRM), you know fairly precisely where your data is and what happens to it. With AI tools, that is different: - **Training data.** Many AI models use user input to improve the model. What you enter may be processed in ways you don't expect. - **Opacity.** You don't know exactly how the model handles your data. Where is it stored? For how long? Who has access? - **Servers outside the EU.** Most major AI providers (OpenAI, Google, Microsoft) process data on US servers. That constitutes a transfer of personal data to a third country. ## Case study: Italy bans ChatGPT In March 2023, the Italian supervisory authority (Garante) temporarily banned ChatGPT. The reasons: - **No valid legal basis** for collecting and processing personal data to train the model - **No age verification**, allowing minors access without protection - **No transparency** towards users about what happened to their data - **No mechanism** for data subjects to exercise their rights (access, deletion) OpenAI made adjustments (clarified privacy policy, option to disable training data, added age verification) and ChatGPT was reinstated. But the signal was clear: AI tools must comply with the same GDPR rules as any other software. European supervisory authorities have since established a joint taskforce specifically for ChatGPT and similar AI services. This is not a one-off incident - it is the start of structural enforcement. ## The three questions you must ask ### 1. What personal data goes in? Be honest: do you sometimes paste a customer complaint email into ChatGPT to draft a response? Do you paste CVs into an AI tool for a summary? Do you enter customer names and email addresses? As soon as you enter identifiable personal data, that is processing under the GDPR. It doesn't matter that you "just quickly" wanted something rewritten. ### 2. Who is the processor? The role allocation under the GDPR is important: - **Controller** (you): you determine the purpose and means of processing - **Processor** (the AI provider): processes data on your behalf With the free version of ChatGPT, OpenAI is partly a joint controller, as they may use your input for model training. With ChatGPT Enterprise or the API version, OpenAI acts as a processor and offers a Data Processing Agreement (DPA). This distinction is crucial. With a processor, you have control via a processing agreement. With a joint controller, the situation is more complex and you have less grip on what happens with the data. ### 3. Is there a processing agreement? If you use an AI tool commercially and send personal data through it, you need a processing agreement (DPA). Check: - Does the provider offer a DPA? (Enterprise versions of ChatGPT, Copilot, and Claude do) - Where is the data processed? (EU or US?) - Can the provider use the data for training? (If so, they are not a pure processor) - What security measures are in place? ## Practical do's and don'ts ### What you CAN do - **Use AI for generic tasks** that don't require personal data: text suggestions, translating standard texts, brainstorming marketing ideas - **Anonymise data** before entering it: replace names with "Customer A", remove email addresses and phone numbers - **Choose a business subscription** with a DPA if you use AI structurally (ChatGPT Enterprise, Microsoft Copilot for Business, Claude for Work) - **Disable training data** where possible; in ChatGPT you can indicate in settings that your data may not be used for training - **Disclose AI tools in your privacy policy** and add them to your Third Parties Dossier so customers know which providers process their data - **Prefer European AI tools** where capability is comparable. EU-based providers reduce third-country transfer complexity. Mistral.ai is an example of a powerful European alternative - **Document** your AI usage in your processing register - **Create an internal AI policy** that tells employees which tools they may use and what data they may or may not enter. Read our practical guide on [creating an AI acceptable use policy](/en/kennisbank/verplichtingen/ai-acceptable-use-policy) ### What you should NOT do - **Paste customer data** into the free version of ChatGPT or similar tools - **Have CVs summarised** by an AI tool without a DPA - **Enter medical or financial data** into any AI tool without strict safeguards - **Make automated decisions** about individuals (e.g. screening applicants) without human intervention and without a DPIA - **Assume it's safe** because "everyone uses it" - popularity is not a legal basis ## EU AI Act: transparency and risk analysis The GDPR is not the only law in play. The EU AI Act adds two requirements that matter in everyday practice. ### Tell users when they are interacting with AI Article 50 of the AI Act requires that, when people communicate directly with an AI system, this is made clear in the interface at the moment of interaction. A chatbot on your website must explicitly tell the visitor that they are talking to an AI bot, not a human agent. The same applies to AI-generated content shown to users: it must be identifiable as AI-generated. This is a transparency obligation independent of the GDPR; you owe it even if no personal data is involved. ### AI risk analysis for automated decisions If you use AI to make and communicate decisions automatically without human intervention, for example automatic creditworthiness scoring, automatic discount or offer granting, or automatic shortlisting of job applicants, you have two parallel obligations: - A **DPIA** under the GDPR, because the processing involves automated decision-making about individuals. - An **AI risk analysis** under the AI Act, plus a published policy on how the system is governed. Both must be done, and both must be documented. They are not interchangeable. ## What should you do now? 1. **Inventory** which AI tools you and your employees use 2. **Assess** per tool whether personal data goes in 3. **Check** whether a DPA is available and whether training data can be disabled 4. **Document** AI usage in your processing register 5. **[Create an internal AI policy](/en/kennisbank/verplichtingen/ai-acceptable-use-policy)** with clear guidelines for employees 6. **Consider a DPIA** if you use AI for profiling, automated decision-making, or large-scale data processing ## Building your own AI models? If you train or fine-tune your own AI models on personal data, the privacy picture is more complex than third-party tooling. You become the controller for the model itself, with extra obligations around training-data lawfulness, model outputs, and rights of data subjects whose data was used. Reach out to us via the scan below if that's where you are - it warrants a longer conversation than this article can give. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Business Page on Social Media: What Does the GDPR Say? URL: https://gdprwise.eu/en/kennisbank/verplichtingen/social-media-business-page-gdpr/ Summary: Do you have a business page on Facebook, Instagram or LinkedIn? You are a joint controller with the platform for visitor data. Learn what this means and what you need to do. Key takeaways: - As the administrator of a business page, you are a joint controller with the platform for visitor data - This was confirmed by the European Court of Justice in the Wirtschaftsakademie ruling (2018) - You must add privacy information to your business page and be aware of the Insights data the platform collects - You cannot avoid your responsibility by claiming the platform handles everything FAQ: Q: Am I responsible for what Facebook does with visitor data? A: Partly. You are a joint controller with Facebook (Meta) for personal data collected through your business page. Facebook has drafted an addendum for this (Page Insights Controller Addendum). It divides responsibilities, but does not relieve you of your own obligations. Q: Do I need to delete my business page to be GDPR-compliant? A: No. You may have a business page, but you must be aware of your responsibilities. Add privacy information to your page, include the business page in your processing register and inform visitors about the data processing. Q: Does this also apply to LinkedIn and Instagram? A: Yes. The European Court ruling concerns the principle of joint controllership for business pages on social media. This applies to any platform that provides statistics about your page visitors, including LinkedIn and Instagram. Q: What are Insights and why are they relevant? A: Insights are the statistics platforms provide about your page visitors: demographics, reach, interactions. To generate those statistics, the platform processes personal data of visitors. Because you receive and benefit from those statistics, you share responsibility for that processing. ## A business page is a processing activity You have a page on Facebook, Instagram or LinkedIn. That makes sense - that is where your customers are. But what many business owners do not realise: by creating and managing that business page, you share responsibility for the personal data the platform collects from your visitors. The GDPR is clear about this, and the European Court of Justice confirmed it in 2018. ## The Wirtschaftsakademie ruling In June 2018, the European Court of Justice ruled in the Wirtschaftsakademie Schleswig-Holstein case (C-210/16) that the administrator of a Facebook business page is a joint controller with Facebook for the processing of visitors' personal data. Why? Because as a page administrator you: - **Deliberately choose a platform** that processes personal data to generate statistics - **Set parameters** that determine what data is collected (target audience, demographic filters) - **Benefit from the statistics** (Insights) the platform provides about your visitors - **Influence the processing** by creating and configuring your page The fact that you do not have technical access to the raw personal data is irrelevant. You benefit from it and you helped initiate the processing. ## What does "joint controller" mean? Article 26 of the GDPR requires joint controllers to agree on who fulfils which GDPR obligations. The major platforms have drafted documents for this: - **Facebook/Instagram (Meta):** Page Insights Controller Addendum - **LinkedIn:** Joint Controller Addendum for Page Insights These documents place most of the operational responsibility with the platform. But they do not fully relieve you. As a page administrator, you remain obliged to: 1. Inform visitors about the data processing 2. Include the processing in your processing register 3. Have a legal basis for your part of the processing ## What should you do in practice? ### 1. Privacy information on your page Add information about the processing of personal data to your business page. On Facebook, you can do this in the "About" section or via a link to your privacy policy. On LinkedIn, you can include a link to your privacy policy in the company profile. At a minimum, state: - That you are a joint controller with the platform - Where visitors can find your privacy policy - How visitors can contact you with privacy questions ### 2. Update your processing register Include your social media business pages in your processing register. Per page: - **Purpose:** business communication, marketing, customer service - **Data categories:** visitor statistics, interaction data, messages - **Legal basis:** legitimate interest (business communication and marketing) - **Joint controller:** Meta / LinkedIn / platform - **Reference to the Controller Addendum** of the platform ### 3. Update your privacy policy State in your general privacy policy that you manage business pages on social media and that you are a joint controller with the platform. Refer to the platform's privacy policy for the details of their processing. ### 4. Be mindful with Insights The Insights data you receive is anonymised or aggregated - you do not see individual profiles. But the fact that the platform generates those statistics based on personal data makes you partly responsible. Be aware of this and do not use Insights data for purposes not documented in your processing register. ## Common mistakes - **No privacy information** on the business page - **Not including the business page** in the processing register - **Thinking the platform handles everything** - the platform handles its own obligations, not yours - **Not treating customer messages via social media** as processing of personal data - when a customer sends you a private message with personal information, you are processing personal data ## No reason to panic A business page on social media is not a problem as long as you know your obligations. You do not need to delete your page. You do not need to draft complicated contracts, because the platforms have already prepared the addenda. You mainly need to be transparent toward your visitors and ensure your processing register is complete. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Common Objections to Getting Started with GDPR URL: https://gdprwise.eu/en/kennisbank/verplichtingen/gdpr-objections/ Summary: No time, too complicated, too small, not relevant - we hear it all the time. Here are the most common objections to GDPR compliance and why they do not hold up. Key takeaways: - Most objections to GDPR stem from misunderstandings about what the law requires - GDPR compliance does not have to be complicated or expensive, especially for SMEs - Delay increases the risk without removing the obligation - Getting the basics in order takes less time than most business owners think FAQ: Q: I really have no time. How much time does it take at minimum? A: With GDPRWise you can complete the free scan in 2 minutes. Filling in your files takes most business owners 2-4 hours spread over a few sessions. That is a small investment for something that protects you legally. Q: Isn't the GDPR only for digital businesses? A: No. The GDPR applies to every organisation that processes personal data, whether digitally or on paper. A construction company with a staff register processes personal data. A hairdresser with a client list processes personal data. ## "I'll deal with it later" We hear it every day. Business owners who know they need to do something about GDPR, but keep finding reasons to postpone. That is understandable - there are always more urgent matters. But the objections we hear rarely hold up. Here are the most common ones. ## "I don't have time for it" This is by far the most common objection. And it is understandable: you have a business to run. But GDPR compliance does not have to be a weeks-long project. With the right tools, you can get the basics in order in a few hours. The free scan takes 2 minutes. You fill in the files at your own pace. Ask yourself: how much time would it cost if you had to report a data breach unprepared? ## "It's too complicated" GDPR legislation is indeed complex, but that does not mean compliance has to be. For most SMEs, it comes down to concrete, understandable steps: document what you process, inform your customers, secure your data, and respond correctly to requests. GDPRWise translates those steps into simple questions you can answer without legal expertise. ## "My business is too small" The GDPR does not differentiate based on company size. A freelancer with a customer list falls under it just as much as a multinational. The difference lies in the scope of your obligations, not in their existence. ## "Nobody has ever come to check on me" That may be true, but the risk is growing. Supervisory authorities are conducting random checks more frequently, and most enforcement starts with complaints from data subjects. A dissatisfied customer or former employee can file a complaint, and then you need to have your affairs in order. ## "I don't process personal data" Nearly impossible. If you have a customer list, store an email address, maintain personnel files, have a contact form on your website, or send invoices with personal details, you process personal data. ## "My IT supplier handles that" Your IT supplier can help with technical security, but the responsibility for GDPR compliance lies with you as the data controller. You can outsource the execution, but not the responsibility. ## "It costs too much money" That might have been true when expensive consultants were your only option. With tools like GDPRWise, you can get compliant for a fraction of the cost of a fine, a consulting report, or legal proceedings. ## "I'll wait until I really have to" You already have to. Since May 2018. Every day you wait is another day of risk. Start small, start today. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Cookies and Consent: What Do You Need to Know? URL: https://gdprwise.eu/en/kennisbank/verplichtingen/cookies-consent-guide/ Summary: Placing cookies without valid consent is one of the most common GDPR violations. This article explains which cookies require consent, how to set up a correct cookie banner, and which mistakes to avoid. Key takeaways: - Only strictly necessary cookies may be placed without consent - Analytical and marketing cookies always require prior, active consent - A cookie banner with only 'Accept' is a dark pattern and not GDPR-compliant - The French supervisory authority CNIL issued fines up to 150 million euros for cookie violations in 2022 FAQ: Q: Can I use Google Analytics without cookie consent? A: No. Google Analytics places analytical cookies that require consent. You may only collect data after the visitor has actively agreed. An alternative is a cookieless analytics tool, but even then you must verify that no cookies are placed. Q: What are strictly necessary cookies? A: Cookies essential for your website to function, such as session cookies for a shopping cart, login cookies, and the cookie that remembers the visitor's cookie choice. These may be placed without consent. Q: How often should I update my cookie banner? A: After every website change that introduces new cookies: a new plugin, analytics tool, chat widget, or social media integration. Do a full cookie audit at least annually. Q: What if a visitor refuses cookies? A: Then you may only place strictly necessary cookies. The website must function normally without analytical or marketing cookies. You may not block or disadvantage the visitor for refusing. ## What are cookies exactly? Cookies are small text files that a website places on a visitor's device. They are used for various purposes: from remembering a shopping cart to tracking browsing behaviour for advertisements. Under the GDPR and the ePrivacy Directive, strict rules apply to when you may place cookies. The problem: many business owners place a cookie banner on their website and think that settles it. But a banner alone is not enough. What matters is that you ask for the right consent, at the right time, for the right cookies. ## Three categories of cookies Not all cookies are equal. The legislation distinguishes three main categories, and different rules apply to each. ### 1. Strictly necessary cookies (no consent needed) These are cookies without which your website cannot function. Think of: - Session cookies for a shopping cart or login status - The cookie that stores the visitor's cookie choice - Security cookies (e.g. CSRF tokens) These may be placed without consent, but you must still list them in your cookie policy. ### 2. Analytical cookies (consent required) Cookies that measure visitor behaviour, such as Google Analytics, Hotjar, or Matomo (with default settings). Even if you only use the data internally, you need prior consent. **Note:** some analytics tools offer a "cookieless mode". Always verify that no cookies are actually placed, as the name can be misleading. ### 3. Marketing cookies (consent required) Cookies used for advertising, retargeting, and building visitor profiles. Examples: - Facebook Pixel (`_fbp`) - Google Ads remarketing - LinkedIn Insight Tag - Other advertising networks Marketing cookies are the most strictly regulated. Consent must be specific, informed, and active. ## What does a correct cookie banner look like? A GDPR-compliant cookie banner meets these requirements: **No cookies loaded in advance.** Non-essential cookies may only be placed after the visitor actively gives consent. That means: no Google Analytics, no Facebook Pixel, no marketing scripts until the visitor clicks "Accept". **Offer a real choice.** The visitor must be able to refuse just as easily as accept. Both buttons must be equally prominent. A large green "Accept all" button next to a small grey "More info" link is not a real choice. **Ask consent per category.** The visitor must be able to choose which categories of cookies are placed. Accepting analytical cookies must be separate from marketing cookies. **Remember the choice.** A visitor who refuses must not be asked again on every page visit. Store the choice (ironically, in a strictly necessary cookie). **Make consent revocable.** There must be a way to change the cookie choice later, for example via a link in the footer. ## The "accept all" dark pattern One of the most common mistakes is a cookie banner that strongly steers towards "accept all". The French supervisory authority CNIL has seriously addressed this issue. In 2022, the CNIL fined Google (150 million euros) and Facebook (60 million euros) because their cookie banners made refusing cookies unnecessarily difficult. Accepting took one click, but refusing required multiple steps through submenus. This does not only apply to tech giants. The CNIL and other supervisory authorities also look at smaller websites. The principle is simple: if "Refuse" is not as easy as "Accept", the consent is not valid. Specifically: if your banner has an "Accept all" button, there must be an equally prominent "Refuse all" button next to it. Not hidden somewhere in a submenu. ## Common mistakes - **Loading cookies before consent.** Google Analytics runs before the visitor has made a choice. This is a direct violation. - **Offering only "Accept".** No refuse option, or it is hidden behind multiple clicks. - **Inaccurate cookie banner.** The banner mentions three cookies, but a scan reveals twenty. This happens when no cookie audit has been performed. - **Pre-ticked checkboxes.** Categories that are set to "on" by default. That is not active consent. - **No cookie policy.** A banner exists, but nowhere an explanation of which cookies you place and why. - **Cookie wall.** Blocking the website until the visitor accepts cookies. This is not permitted in most EU countries. ## Do a cookie audit The first step towards correct cookie compliance is knowing which cookies your website places. Open your website in an incognito window, open the developer tools (F12), and check the Application > Cookies tab. You will probably be surprised by what you find. import TemplateTip from '@/components/TemplateTip.astro'; Systematically map all cookies: which cookie, from whom, for what purpose, how long active, and whether consent is required. ## What should you do now? 1. **Inventory** all cookies on your website with a cookie audit 2. **Categorise** them as strictly necessary, analytical, or marketing 3. **Check** that your cookie banner asks for correct, active consent per category 4. **Ensure** that non-essential cookies only load after consent 5. **Make** refusing as easy as accepting 6. **Repeat** the audit after every website change and at least annually import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Direct Marketing and GDPR: What Is and Isn't Allowed? URL: https://gdprwise.eu/en/kennisbank/verplichtingen/direct-marketing-gdpr/ Summary: Can you simply email your customers? The GDPR sets clear rules for direct marketing: when you need consent, when the soft opt-in suffices, and how to respect the right to object. Key takeaways: - Transactional emails (order confirmations, invoices) do not require marketing consent - Newsletters and promotional emails always require prior consent - For existing customers, an exception applies: the soft opt-in for similar products or services - The right to object to direct marketing is absolute - you must stop immediately when someone objects FAQ: Q: May I email existing customers about a new product? A: It depends. If the new product is similar to what the customer previously bought, you can use the soft opt-in. If it's a completely different product category, you need new consent. A working unsubscribe link must always be present. Q: Do I need consent for every email to customers? A: No. Transactional emails such as order confirmations, invoices, and service notifications do not require marketing consent. They fall under the legal basis of 'performance of a contract'. Only promotional and commercial messages require consent or a soft opt-in. Q: Does a newsletter always require consent? A: Yes. A newsletter is by definition direct marketing. You need prior, freely given, and unambiguous consent. A pre-ticked checkbox does not count. And the recipient must be able to easily unsubscribe in every newsletter. Q: What is the difference between the GDPR and the ePrivacy Directive for email marketing? A: The GDPR governs the processing of personal data. The ePrivacy Directive specifically regulates electronic communications, including email marketing. Both apply and you must comply with both. ## Not all emails are equal The GDPR makes an important distinction that many business owners overlook: not every email you send is marketing. And not every marketing email requires consent. But if you get it wrong, you risk a complaint to the supervisory authority or, worse, a fine. Let's keep it clear. There are three types of emails you send as a business, and different rules apply to each. ## Transactional emails: just send them Order confirmations, invoices, shipping notifications, password resets, appointment reminders - these are transactional emails. They are necessary for performing a contract or delivering a service. **You do not need marketing consent for these.** The legal basis is "performance of a contract" (Article 6(1)(b) GDPR). Your customer expects these messages because they are part of the service you provide. Note: the moment you add a promotional block to a transactional email ("Check out our new collection!"), it becomes a hybrid message. The supervisory authority may treat it as marketing. ## Newsletters and promotions: always consent Want to send a newsletter? A promotional email? An event invitation? Then you need prior consent. No exceptions. That consent must meet the GDPR requirements: - **Freely given** - no pre-ticked checkboxes, no mandatory sign-up as a condition for a service - **Specific** - the person knows what they are consenting to - **Unambiguous** - an active action, such as ticking a checkbox or clicking a confirmation link (double opt-in) - **Documented** - you must be able to demonstrate when and how someone gave consent And every newsletter must contain a working unsubscribe link. Not hidden at the bottom in grey type, but clearly visible. ## The soft opt-in: exception for existing customers This is the rule many business owners don't know but are happy to learn about. If someone is already your customer, you may email them about similar products or services without asking for new consent. This is called the soft opt-in. The conditions are: 1. **You obtained the email address in the context of a sale** - the customer bought something or used a service 2. **You promote similar products or services** - an accountant may email clients about a new tax service, but not about an unrelated side project 3. **The customer could object when the email address was collected** - you offered an opt-out at the point of purchase 4. **Every email includes an unsubscribe option** - the customer can say "stop" with every message **Example:** an online shop selling sportswear may email existing customers about new sportswear. But not about a completely different product line, such as furniture. ## The right to object: absolute for direct marketing This is where the GDPR is particularly strict. Article 21(2) gives data subjects an absolute right to object to processing for direct marketing. No balancing test, no exceptions. When someone says "stop sending me marketing", you stop. Immediately. Not after the next campaign, not at the end of the month. Right away. This also applies if you email based on legitimate interest or the soft opt-in. It does not matter which legal basis you use: once someone objects to direct marketing, it's over. ## Practical rules of thumb | Situation | Consent needed? | |-----------|----------------| | Sending an order confirmation | No | | Emailing an invoice | No | | Service notification about an active contract | No | | Newsletter to new contacts | Yes | | Promotional email to existing customer (similar product) | No (soft opt-in) | | Promotional email to existing customer (different product) | Yes | | Cold email to prospects | Yes | | Webinar invitation to your mailing list | Yes | ## Common mistakes - **No unsubscribe link** in commercial emails - **Pre-ticked checkboxes** on sign-up forms - **No record** of when and how consent was given - **Interpreting the soft opt-in too broadly** by emailing about completely different products - **Ignoring or delaying** objection requests ## Document your marketing activities Direct marketing belongs in your records of processing activities. Record which marketing channels you use, which legal basis you apply per channel, how you collect and register consent, and how you handle unsubscriptions. This way you can immediately demonstrate compliance during an audit or complaint. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Don't Try to Outsmart the GDPR URL: https://gdprwise.eu/en/kennisbank/verplichtingen/dont-outsmart-gdpr/ Summary: Creative workarounds for the GDPR don't work and can cost you more than simply becoming compliant. This article explains which shortcuts to avoid. Key takeaways: - Creative avoidance schemes are eventually exposed - Supervisory authorities are familiar with the most common tricks and punish them more severely - Honest, basic compliance is cheaper and more effective than complex avoidance - If you follow the intent of the law, you're almost always fine FAQ: Q: Can I avoid the GDPR by establishing my business outside the EU? A: No. The GDPR applies to any organisation that processes personal data of people in the EU, regardless of where the business is located. A US company offering services to European customers falls under it just the same. Q: Is a generic consent checkbox sufficient? A: No. Consent must be specific, informed, and freely given. A pre-ticked checkbox or an all-or-nothing choice does not meet GDPR requirements. Q: Can I keep personal data if I anonymise it? A: Truly anonymised data falls outside the GDPR. But real anonymisation is harder than most people think. Pseudonymisation (encrypting with a retained key file) is not anonymisation and still falls under the law. ## Shortcuts that don't work We see it regularly: business owners who think a clever scheme will get them out of GDPR compliance. That's understandable - the law feels like a burden. But the reality is that creative avoidance costs you more than honest compliance. Here are the most common tricks and why they don't work. ## "I'll just put up a cookie banner" A cookie banner is not a magic bullet. If the banner isn't properly configured, non-essential cookies already load before consent is given, or the choice isn't genuinely free (for example, no clear reject button), it doesn't comply. Supervisory authorities don't look at the banner itself but at what happens technically. ## "I'll have everyone sign a blanket consent" A broad, generic consent ("I agree to the processing of my data") doesn't qualify. Consent must be specific per purpose, informed, and freely given. You cannot bundle everything into a single checkbox. ## "I'll store the data on a server outside the EU" The GDPR follows the data, not the server. If you process data of people in the EU, it doesn't matter where you store it. The law applies. ## "I just won't call it personal data" It doesn't matter what you call it. If the data can be directly or indirectly linked to a person, it's personal data. A customer number that can be linked to a name is personal data. An IP address is personal data. ## "I'll have a processor do it, then I'm not responsible" Outsourcing is possible, but not the responsibility. As a data controller, you remain responsible for what happens to the data, even if you outsource the processing. You must have a data processing agreement and maintain oversight. ## "I have a privacy policy, so I'm compliant" A privacy policy is a start, but it's only one of many obligations. Without a records of processing activities, without security measures, without data processing agreements, and without a process for data breaches and access requests, you're not compliant. ## What does work Follow the intent of the law: - Be transparent about what you do with data - Don't collect more than necessary - Secure what you have - Respect the rights of data subjects - Document your choices It's less work than most avoidance schemes, and it actually works. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### DPIA: When Is a Data Protection Impact Assessment Required? URL: https://gdprwise.eu/en/kennisbank/verplichtingen/dpia-guide/ Summary: A DPIA (Data Protection Impact Assessment) is only mandatory for high-risk processing. This article explains when you need one, when you don't, and how to carry one out. Key takeaways: - A DPIA is only mandatory for processing that poses a high risk to the rights and freedoms of individuals - Most SMEs do not need a DPIA for their standard processing activities - The supervisory authority publishes a list of processing operations that require a DPIA - A DPIA is not a one-off document but must be updated when the processing changes FAQ: Q: Is a DPIA mandatory for my SME? A: Probably not for your standard processing (customer management, payroll, accounting). A DPIA becomes mandatory when you carry out high-risk processing, such as large-scale profiling, systematic monitoring, or large-scale processing of special category data. Q: What happens if I don't carry out a DPIA when it's required? A: The supervisory authority can impose a fine. In practice, it's also a risk for your organisation: without a DPIA you haven't mapped the risks and may be taking insufficient measures. Q: Can I carry out a DPIA myself? A: Yes, the GDPR does not prescribe a specific format. You can carry out a DPIA yourself using a template. For complex processing, it is advisable to seek advice from a privacy specialist. Q: How long does a DPIA take? A: That depends on the complexity of the processing. A simple DPIA for a single processing activity can be completed in a few hours. For complex systems, it can take weeks. ## What is a DPIA? A DPIA (Data Protection Impact Assessment) is an assessment of the risks that a particular processing of personal data poses to the individuals concerned. The GDPR requires this in Article 35 for processing that poses a high risk to the rights and freedoms of natural persons. In plain language: you assess in advance whether a processing activity could cause problems for the people whose data you process, and what you do to mitigate those risks. ## When is a DPIA mandatory? The GDPR names three situations where a DPIA is always required: **1. Systematic and extensive profiling with significant effects** Think of: a bank that automatically decides on credit applications based on profile data, or an insurer that calculates premiums based on extensive behavioural analysis. **2. Large-scale processing of special categories of data** Special categories include health data, biometric data, data on race or religion, and criminal records. A hospital managing patient records falls under this. An SME that happens to know an employee is diabetic does not. **3. Large-scale, systematic monitoring of publicly accessible areas** The classic example is an extensive CCTV system in a shopping centre or city centre. Additionally, supervisory authorities publish lists of processing operations that require a DPIA. These typically include: - Use of biometric data for identification - Merging databases from different sources - Systematic monitoring of employees - Large-scale processing of data from vulnerable persons (children, elderly, patients) ## When do you NOT need a DPIA? Most SMEs carry out standard processing that does not pose a high risk. A few examples: - **Customer management in a CRM** - you store contact details and order history. No special categories, no profiling. No DPIA needed. - **Payroll and HR administration** - name, address, salary data, contracts. Standard processing. No DPIA needed. - **Sending newsletters** - email addresses with consent. No DPIA needed. - **Accounting and invoicing** - billing data for customers and suppliers. No DPIA needed. - **A few security cameras** at your premises, as long as it's not large-scale and systematic. Usually no DPIA needed (but for larger installations, see our [guide on CCTV surveillance](/en/kennisbank/beveiliging/cctv-privacy-gdpr)). The rule of thumb: if you process data in a way comparable to what thousands of other SMEs also do, you're unlikely to need a DPIA. ## How do you carry out a DPIA? If you do need a DPIA, follow these steps: ### Step 1: Describe the processing Document: - Which personal data you process - The purpose - The legal basis (e.g. legitimate interest, consent) - Who has access - How long you retain the data - Which technology you use ### Step 2: Assess necessity and proportionality Ask yourself: - Is this processing truly necessary for the purpose? - Can I achieve the purpose with less data or a less intrusive method? - Is the retention period no longer than necessary? ### Step 3: Identify the risks Look at the risks from the perspective of the data subject, not your own organisation. Consider: - What if the data leaks? How bad is that for the data subject? - What if the data is inaccurate? What are the consequences? - Do data subjects have sufficient control over their data? ### Step 4: Determine measures For each risk, determine which measures you take to mitigate it: - Technical measures (encryption, access control, pseudonymisation) - Organisational measures (training, procedures, contracts) - Limitations on the processing itself (less data, shorter retention period) ### Step 5: Document and maintain Record everything in a document. A DPIA is not a one-off exercise; you must update it when the processing changes, when new risks arise, or when the technology changes. ## Practical advice for SMEs - **Check the supervisory authority's list** - see whether your processing operations appear on the mandatory DPIA list - **Start with your records of processing activities** - if those are in order, you can quickly see which operations may require a DPIA - **Use a template** - you don't need to reinvent the wheel. Supervisory authorities provide templates - **Seek advice if in doubt** - if you're unsure whether you need a DPIA, it's wiser to carry one out than to ignore it import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### DPO: What Is a Data Protection Officer and Do You Need One? URL: https://gdprwise.eu/en/kennisbank/verplichtingen/dpo-guide/ Summary: A DPO (Data Protection Officer) is a mandatory role under the GDPR, but not for everyone. This article explains when you do and don't need one, and what SMEs should arrange in practice. Key takeaways: - Most SMEs do not need a DPO, but you should designate someone responsible for GDPR - A DPO is mandatory if you process special category data on a large scale or systematically monitor individuals - A DPO can be internal or external, but must be able to work independently - No DPO needed? Then at minimum ensure a GDPR contact point within your organisation FAQ: Q: Is a DPO mandatory for my SME? A: Probably not. A DPO is only mandatory if your core activity consists of large-scale processing of special categories of personal data, or of systematic and large-scale monitoring of individuals. Most SMEs don't fall under this. Q: What does an external DPO cost? A: An external DPO typically costs between 500 and 2,000 euros per month, depending on the scale and complexity of your processing. For most SMEs this is not necessary and an internal GDPR contact point suffices. Q: Can I be the DPO of my own company? A: As a managing director, you cannot be your own DPO because the DPO must independently oversee the processing activities. A DPO may not receive instructions on how to carry out their role, and that's difficult when you're also the boss. Q: What if I don't need a DPO but still want to arrange something? A: Designate someone internally as GDPR contact point. This person doesn't need to be a specialist, but should know where your records of processing activities are, how data subject requests are handled, and what to do in case of a data breach. ## What is a DPO? A DPO (Data Protection Officer) is someone within an organisation who oversees compliance with the GDPR. The DPO is the contact point for the supervisory authority and for the individuals whose data you process. It is a formal role established in GDPR Articles 37 to 39. Important: the DPO is not responsible for GDPR compliance. That responsibility lies with the organisation itself. The DPO advises, monitors, and flags issues, but is not personally liable if something goes wrong. ## When is a DPO mandatory? The GDPR requires a DPO in three situations: **1. Government bodies and public organisations** Every public authority that processes personal data must appoint a DPO. No exceptions. **2. Large-scale, systematic monitoring of individuals** This applies when your core activity consists of systematic and large-scale observation of individuals. Think of: - CCTV surveillance companies that provide monitoring for multiple clients - Companies that track online behaviour on a large scale for advertising purposes - Security companies that systematically monitor individuals **3. Large-scale processing of special categories of data** Special categories include health data, biometric data, data on race or ethnicity, political opinions, religious beliefs, and criminal records. Examples: - Hospitals and healthcare institutions - Laboratories performing genetic tests - Insurers processing health data on a large scale ## When do you NOT need a DPO? Most SMEs fall outside the three categories above. A few examples: - **A construction company with 25 employees** processes employee and customer data, but that's not the core activity and it's not large-scale. No DPO needed. - **An online shop with 10,000 customers** processes names, addresses, and order history. These are ordinary personal data, not special categories, and the core activity is sales, not data processing. No DPO needed. - **An accounting firm with 5 employees** processes financial data of clients. Although sensitive, this is not a "special category" in the GDPR sense. No DPO needed. - **A small marketing agency** that manages campaigns for clients. Unless you profile on a large scale, no DPO needed. The key terms are "core activity" and "large scale". If you process personal data in support of your actual business activity (and nearly every business does), that's not your core activity. ## What does a DPO actually do? If you do need a DPO (or voluntarily appoint one), these are the tasks: - **Inform and advise** the organisation and employees on GDPR obligations - **Monitor** GDPR compliance, including assigning responsibilities, awareness, and training - **Advise** on DPIAs (Data Protection Impact Assessments) - **Act as contact point** for the supervisory authority - **Act as contact point** for data subjects with questions or complaints about their data A DPO can be internal (an employee) or external (a hired specialist). In both cases: - The DPO must be able to work **independently** and may not receive instructions on how to perform their role - The DPO may not have a **conflict of interest** - the CEO, HR manager, or IT manager cannot also be the DPO - The DPO must receive **sufficient resources and access** to carry out their work ## No DPO needed? Here's what you SHOULD arrange Not needing a formal DPO doesn't mean you have nothing to do. Your organisation must: 1. **Designate a GDPR contact point** - someone internally who knows how GDPR documentation is organised and can handle data subject requests 2. **Maintain records of processing activities** - this is mandatory for virtually every organisation 3. **Publish a privacy policy** - so customers and employees know how you process their data 4. **Have a data breach procedure** - so you can respond within 72 hours 5. **Conclude data processing agreements** - with every party that processes data on your behalf The difference is that you don't need a formally appointed, independent officer. But someone has to do the work. ## Practical: how to arrange this? **If you DO need a DPO:** - Internal: appoint an employee with privacy law knowledge. Ensure they have sufficient time and budget - External: hire a DPO-as-a-service. Costs range from 500 to 2,000 euros per month - Register the DPO with the supervisory authority **If you DON'T need a DPO:** - Designate someone internally as GDPR contact person - Ensure this person has basic GDPR knowledge - Document who it is and what their responsibilities are - Use a tool like GDPRWise to maintain records of processing activities and documentation import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Fingerprint Scans for Attendance Tracking: Is It Allowed Under the GDPR? URL: https://gdprwise.eu/en/kennisbank/verplichtingen/fingerprint-attendance/ Summary: More businesses are considering biometric systems for time tracking. But fingerprints are special category data under the GDPR. Is it permitted, and if so, under what conditions? Key takeaways: - Fingerprints are biometric data and fall under the strictest category of the GDPR - Processing biometric data is prohibited by default, unless a specific exception applies - Employee consent is rarely considered 'freely given' in an employment relationship, making it an invalid legal basis - Less intrusive alternatives such as badges or PIN codes are almost always available FAQ: Q: What exactly is biometric data? A: Biometric data refers to physical, physiological, or behavioural characteristics that can uniquely identify a person. Fingerprints, facial recognition, iris scans, and voice recognition are all biometric data. Q: Can I use fingerprint scans if all my employees agree? A: In theory, consent can be a legal basis, but in an employment relationship, consent is rarely 'freely given' due to the power imbalance. An employee may feel pressured to agree. Supervisory authorities therefore rarely accept consent as a valid basis for biometric processing in the workplace. Q: Are there situations where biometric time tracking is allowed? A: In very specific situations, such as high-security environments or legal requirements, it may be justified. But for ordinary time tracking, less intrusive alternatives are almost always available. A DPIA is mandatory in any case. ## Biometric data: the strictest category Fingerprints are biometric data. Under the GDPR, biometric data falls into the category of "special categories of personal data", alongside health data, religious beliefs, and ethnic origin. Processing this category of data is prohibited unless a specific exception applies. This makes the threshold for using fingerprint scans for something as routine as attendance tracking extremely high. ## Why consent usually doesn't work The most obvious exception is "explicit consent". But in an employment relationship, consent is problematic. The GDPR requires consent to be freely given, meaning the data subject must be able to refuse without negative consequences. In an employer-employee relationship, that freedom rarely exists. An employee who refuses to provide their fingerprint may fear consequences for their position. Supervisory authorities in multiple EU countries have ruled that consent in an employment context is not a valid basis for biometric processing. ## Case law In the Netherlands, the Amsterdam court ruled in 2019 that an employer could not mandate a fingerprint system for time tracking. The court found that less intrusive alternatives were available (badges, PIN codes) and that biometric processing was not proportionate. This ruling sets a clear direction: if an alternative achieves the same goal without biometric data, a fingerprint scan is not permitted. ## When it may be allowed There are situations where biometric access control can be justified: - **High-security environments** - data centres, laboratories, military facilities - **Legal requirements** - where legislation mandates biometric identification - **Essential security** - where no alternative provides a comparable level of security Even in these cases, a Data Protection Impact Assessment (DPIA) is mandatory, and you must demonstrate that the processing is necessary and proportionate. ## Alternatives that work For the vast majority of businesses, sufficient alternatives exist: - **Badges or access cards** - simple, affordable, and privacy-friendly - **PIN codes** - no biometric data involved - **Digital clock systems** - logging in via an app or computer - **Combinations** - badge plus PIN code for added security These alternatives achieve the same goal without the legal risks of biometric processing. ## What if you already use a fingerprint system? If you already use a biometric system for time tracking, assess whether you have a valid legal basis. If not, switch to an alternative. Delete the stored biometric data and document the change. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### GDPR - Where to Start? A Practical Starting Point URL: https://gdprwise.eu/en/kennisbank/verplichtingen/gdpr-where-to-start/ Summary: You know you need to do something about the GDPR, but where do you begin? This article gives you a clear step-by-step plan to go from zero to compliant, without hiring a lawyer. Key takeaways: - Start with an inventory: which personal data do you process and why? - You don't have to do everything at once - work step by step, starting with the essentials - A free website scan gives you an immediate, concrete starting point - GDPR compliance is not a one-off project but an ongoing process FAQ: Q: How long does it take to become GDPR-compliant? A: That depends on your company size and complexity. Most SME owners can get the basics in order within 2-4 weeks by spending a few hours per week. With GDPRWise it goes faster because the platform does the heavy lifting. Q: Do I need to hire a lawyer or consultant? A: For most SMEs, that's not necessary. GDPRWise guides you step by step and generates the documents you need. For complex situations (e.g., large-scale processing of sensitive data), legal advice may be wise. Q: Can I ignore the GDPR as a small business? A: No. The GDPR applies to every organisation that processes personal data, regardless of size. The risk is real: supervisory authorities also fine small businesses, and customers or employees can file complaints. ## You've decided to get your GDPR compliance in order That is already the most important step. Many business owners postpone it because it seems complicated, but the truth is it's manageable when you approach it systematically. You don't need to be a legal expert and you don't have to do everything at once. If your business has just started and you want the absolute smallest version of GDPR to get going, read the [GDPR minimum for a small business](/en/kennisbank/verplichtingen/gdpr-minimum-transparency-first). It distils GDPR into five day-one must-do's grounded in transparency, before you layer in the broader steps below. ## Step 1: Know what you have Before you can organise anything, you need to know which personal data you process. Make an inventory: **Customer data** - who are your customers, what data do you have, where is it stored? **Employee data** - employment contracts, payslips, sick leave records, evaluations **Suppliers and partners** - which external parties have access to personal data? **Website** - which cookies, trackers, and forms collect data? The quickest way to start: let GDPRWise scan your website. Within 2 minutes you have a concrete overview of what is happening on your site. ## Step 2: Document your processing activities The GDPR requires you to maintain a record of processing activities. That sounds complex, but it is essentially an overview of: - What data you process - Why you process it - On what legal basis - How long you keep the data - With whom you share it GDPRWise helps you build this register automatically through three dossiers: customers, personnel, and third parties. ## Step 3: Prepare your documents You need several key documents: - **Privacy policy** - informs your customers and website visitors about how you handle their data - **Data processing agreements** - contracts with parties that process data on your behalf - **Internal policy** - rules for employees about handling personal data GDPRWise generates these documents automatically based on your dossiers. ## Step 4: Secure your data Take appropriate security measures: - Strong passwords and two-factor authentication - Keep software up to date - Make backups - Limit access to those who need it It doesn't need to be complicated. Start with the basics. ## Step 5: Keep it up to date GDPR compliance is not a one-off project. Your business changes, your tools change, regulations change. Schedule periodic reviews: - Check your dossiers at least annually - Update your documentation when things change - Keep track of regulatory developments GDPRWise helps with compliance monitoring and regulatory alerts. ## Start today The most important thing: start. You don't have to finish everything today. But the longer you wait, the greater the risk. Begin with the scan, build your dossier step by step, and work towards full compliance. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### GDPR and Children: Extra Rules for Minors' Personal Data URL: https://gdprwise.eu/en/kennisbank/verplichtingen/gdpr-children-data/ Summary: The GDPR sets additional requirements for processing children's personal data. This article explains the rules, when parental consent is needed, and what this means for schools, sports clubs, and online platforms. Key takeaways: - The GDPR considers children a vulnerable group deserving extra protection - For online services, parental consent is required for children under 13 to 16, depending on the EU country - Communication about data processing must be written in child-friendly language - An exception exists for preventive and counselling services offered directly to children FAQ: Q: At what age can children give their own consent? A: This varies by EU country. The GDPR sets the maximum at 16 years, but member states may lower it to a minimum of 13. In the Netherlands the limit is 16, in Belgium it's 13. Q: Does this only apply to online services? A: The consent age from Article 8 applies specifically to 'information society services' (online services). But the general GDPR principle that children deserve extra protection applies to all processing. Q: Does a sports club need parental consent for membership registration? A: Membership registration can often rely on contractual necessity or legitimate interest. But for posting photos on the website or sending a newsletter, you do need (parental) consent. Q: What if a child lies about their age? A: You must make 'reasonable efforts' to verify age, taking into account available technology. A simple checkbox 'I am over 16' is insufficient if you know your target audience mainly consists of children. ## Children deserve extra protection The GDPR is clear: children are a vulnerable group. They are less aware of the risks and consequences of sharing their personal data. This is why additional rules apply when you process data of minors. This is relevant to more organisations than you might think: schools, sports clubs, childcare centres, youth organisations, online platforms, webshops with children's products, and even businesses that send newsletters to mailing lists that include minors. ## Parental consent: when and up to what age? Article 8 of the GDPR states that offering "information society services" (i.e. online services) to children requires the consent of a parent or guardian. The GDPR sets the maximum at 16 years, but allows member states to lower this to a minimum of 13. In practice, this means: | Country | Age limit | |---------|-----------| | Netherlands | 16 years | | Belgium | 13 years | | Germany | 16 years | | France | 15 years | | Spain | 14 years | | Ireland | 16 years | | Sweden | 13 years | | Italy | 14 years | **Note:** these age limits apply specifically to consent as a legal basis for online services. The broader principle that children deserve extra protection always applies. ## Enforcement: fines for mishandling children's data Supervisory authorities take violations involving children's data very seriously: **TikTok - EUR 345 million (Ireland, 2023).** The Irish DPC fined TikTok EUR 345 million for insufficiently protecting the privacy of minor users. Children's profiles were public by default, and the "Family Pairing" feature had flaws that allowed non-parents to link children's accounts. **Instagram/Meta - EUR 405 million (Ireland, 2022).** The Irish DPC fined Meta for making teenagers' email addresses and phone numbers public on Instagram, and for setting business accounts as the default for minors. These are not amounts reserved for tech giants alone. The message is clear: supervisory authorities consider the protection of children's data a priority. ## What should you do if you process children's data? ### 1. Determine whether you work with children's data Check whether your audience (partially) consists of minors. Consider: - Membership registration of a sports club or youth organisation - Student administration of a school - Registrations for a summer camp or after-school activity - A webshop with toys or children's clothing - An app or online service used by children ### 2. Check your legal basis If you use consent as a legal basis, you need parental consent for children below the national age limit. If you use a different basis (e.g. contractual necessity for a school enrolment), the parental consent requirement of Article 8 does not apply, but the duty of extra care does. ### 3. Verify age You must make "reasonable efforts" to check whether someone is old enough to consent on their own, and whether consent actually comes from a parent or guardian. What is "reasonable" depends on the risk and available technology. A checkbox is not enough if you know your audience mainly consists of children. ### 4. Communicate in child-friendly language The GDPR requires that information about data processing is understandable for the target audience. If you target children, your privacy policy must be written in simple, clear language that children can understand. Legal jargon is not sufficient. ### 5. Limit data processing The principle of data minimisation applies even more strictly to children. Collect only what you truly need. Avoid profiling and automated decision-making based on children's data. ## Exception: preventive and counselling services Article 8 contains an important exception: the parental consent requirement does not apply to "preventive or counselling services offered directly to a child." Think of helplines for abuse, children's hotlines, or online health information services. This exception prevents children who need help from being blocked by a consent requirement involving the parent who may be the problem. ## Practical tips for sports clubs, schools, and youth organisations - **Membership registration:** only collect what you truly need (name, date of birth, parent's contact details) - **Photos and videos:** always obtain parental consent before posting children's photos on your website or social media - **Newsletters:** do not send marketing emails to children without parental consent - **Sharing data with third parties:** sign data processing agreements with sponsors, photographers, or other parties - **Retention periods:** do not retain children's data longer than necessary; delete data of former members import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### GDPR Checklist for SMEs: 3 Parts, 13 Steps URL: https://gdprwise.eu/en/kennisbank/verplichtingen/gdpr-checklist-sme/ Summary: A practical, ticked-off-able GDPR checklist for SMEs. Thirteen items grouped by priority, with templates and tools, no legal jargon. Key takeaways: - Thirteen concrete checks, ordered by priority - the first five cover the basics most regulators look for - Most SMEs can get the basics in order in two to four weeks at a few hours per week - You don't need a DPO, a DPIA, or an external consultant for the basics; you do need discipline and the right templates - Compliance is an ongoing operation, not a one-off project - the last three checks keep it that way FAQ: Q: How long does it take to become GDPR-compliant? A: Most SMEs can complete the first five steps (privacy coordinator, processing register, customer privacy policy, processor agreements, cookie consent) in two to four weeks at a few hours per week. With GDPRWise the technical work shrinks to about 15 minutes; the rest is your own validation and rollout. Q: Do I need a DPO (Data Protection Officer)? A: Most SMEs don't. A DPO is required if your core activity involves large-scale, regular and systematic monitoring of individuals, or large-scale processing of special category data. Otherwise, designate an internal Privacy Coordinator instead - same single point of contact, no formal DPO obligations. Q: How much does GDPR compliance cost? A: For most SMEs the cost is mainly time, not money. With tools like GDPRWise you can automate the documentation for a manageable monthly fee. The expensive route - hiring a privacy lawyer or full-time DPO - is rarely necessary for an SME. Q: What if I serve customers outside the EU, or operate in multiple EU countries? A: If you're based outside the EU but offer goods or services to people in the EU, GDPR Article 27 requires you to appoint an EU-based representative. If you operate in multiple EU member states, your lead supervisory authority is the one in the country where your main establishment (or main decision-making about processing) is located. import TemplateTip from '@/components/TemplateTip.astro'; import ArticleCTA from '@/components/ArticleCTA.astro'; ## How to use this checklist This is a thirteen-step checklist that an SME owner or office manager can work through without legal training. The items are ordered by priority. The first five are the basics every regulator will look for. The next four are operational essentials. The last four keep your compliance posture alive over time. If you've just started your business and the thirteen steps feel like too much for day one, start with the [GDPR minimum for a small business](/en/kennisbank/verplichtingen/gdpr-minimum-transparency-first), a leaner five-step foundation grounded in transparency. Once those are in place, come back here to layer in the rest. You don't have to do all thirteen at once. Most SMEs can finish the first five in two to four weeks at a few hours per week, then layer the rest in. ## Part 1 - The basics (steps 1 to 5) ### Step 1: Designate a Privacy Coordinator **The check:** one named person inside your organisation owns GDPR. This isn't a formal Data Protection Officer (DPO) role - that's reserved for organisations doing large-scale monitoring or processing special category data on a large scale. For most SMEs, "Privacy Coordinator" is the right title: same single point of contact, no formal DPO obligations, no independence requirements. The coordinator's job is to keep this checklist green, take incoming privacy questions and complaints, and own the relationship with your supervisory authority if anything goes wrong. - [ ] A named Privacy Coordinator is designated and reachable on a dedicated email (e.g. `privacy@yourcompany.com`). - [ ] Their role is documented and known to the rest of the team. Do you actually need a DPO? Read [DPO: what is a Data Protection Officer and do you need one?](/en/kennisbank/verplichtingen/dpo-guide). ### Step 2: Maintain a GDPR processing register (ROPA) **The check:** a single document listing every activity in which you process personal data. This is the first thing your supervisory authority will ask for if they come knocking. It's also your own master inventory: if you don't know what data you process, you can't comply with anything else on this list. For each processing activity, record: - Purpose (why you're processing the data) - Legal basis (consent, contract, legal obligation, vital interests, public interest, or legitimate interests) - Data categories (names, emails, financial, health, etc.) - Data subjects (customers, employees, suppliers, prospects) - Recipients / third parties (your accountant, CRM provider, hosting, etc.) - Retention period - Security measures Keep separate sections for activities where you are the **controller** versus where you are a **processor** for someone else. Read [Records of processing activities](/en/kennisbank/hoe-gdprwise-werkt/records-of-processing-ropa) for the full structure. - [ ] Processing register exists and lists every activity touching personal data. - [ ] Controller and processor activities are recorded separately. - [ ] Annual review date is in the calendar. ### Step 3: Have a tailored customer privacy policy **The check:** a privacy policy on your website, written for your business specifically. The GDPR is explicit about this: vague boilerplate, copy-pasted policies, or legalese that doesn't reflect what you actually do are non-compliant. The policy must describe **your** processes, **your** legal bases, **your** processors. A compliant SME privacy policy covers: 1. Who you are (controller, contact email, address). 2. The processing activities you run (mirroring your register at a high level). 3. The legal basis for each. 4. Categories of data and recipients (including platforms like Mailchimp, Stripe, Google Workspace). 5. Retention periods. 6. International data transfers, if any. 7. Data subject rights and how to exercise them. 8. Complaint route to your supervisory authority. Publish it as a top-level link in the footer of every page on your site. Don't bury it inside terms and conditions. Don't copy a policy from another company's site. Read [Drafting a privacy policy](/en/kennisbank/verplichtingen/privacy-policy-guide) for the full guide. - [ ] Customer privacy policy is published. - [ ] Linked from the footer of every page. - [ ] Reflects what you actually do (no boilerplate). - [ ] Includes data subject rights and complaint route. ### Step 4: Sign data processing agreements (DPAs) with every processor **The check:** a signed processing agreement with every external party that handles personal data on your behalf. If you don't have a DPA with a processor, you are not legally allowed to send them personal data. That's true even if the processor is a household name like Google or Microsoft - the obligation is on you to have the agreement in place. Typical SME processors: - Email and marketing platform (Mailchimp, ActiveCampaign, Brevo, etc.) - CRM (HubSpot, Pipedrive, Salesforce, etc.) - Cloud storage and office (Google Workspace, Microsoft 365) - Web hosting and CDN - Payment processor (Stripe, Mollie, Adyen) - Payroll and accounting - Customer support tools Most major SaaS vendors publish a standard DPA you can sign electronically. For smaller suppliers, send your own. A ready-to-use processing agreement you can send to any processor that doesn't already have its own. - [ ] Every processor in your register has a signed DPA on file. - [ ] DPAs are stored centrally and findable. ### Step 5: Implement cookie consent (if you set cookies) **The check:** a cookie banner that asks for consent **before** any non-essential cookies are set, and gives a real reject option. Cookies that can identify a visitor process personal data. Under GDPR plus the ePrivacy Directive, you need consent before setting them - and the consent must be informed, freely given, and as easy to reject as to accept. Common failure modes regulators fine: - Cookies set on page load, before any banner is shown. - "Accept" button styled prominently while "Reject" is hidden or harder to find. - Pre-ticked boxes. - "By using this site you accept cookies" - that's not consent, it's a notice. Test your own site: open it in a private window, decline cookies, and check the developer-tools cookie list. If anything non-essential is there, your consent flow is broken. A quieter option: don't use non-essential cookies at all. Plenty of SMEs run perfectly well without third-party tracking. Read [Cookies and consent: what you need to know](/en/kennisbank/verplichtingen/cookies-consent-guide) for the full picture. Spreadsheet template to inventory every cookie on your site, classify it (essential / functional / marketing / tracking), and decide which to keep. - [ ] No non-essential cookie is set before consent. - [ ] Reject is as prominent as accept. - [ ] Cookie inventory exists, with purpose and retention per cookie. ## Part 2 - Operations (steps 6 to 9) ### Step 6: Operationalise data subject rights **The check:** a documented procedure for handling rights requests, with templates and a register. People whose data you process can ask for access, rectification, erasure, restriction, portability, or to object to processing. You have **one month** to respond (extendable to three months for complex cases). Missing the deadline is a regulator favourite for fines. What you need in place: - A monitored inbox where requests land (often the `privacy@` address from step 1). - A documented internal process: who triages, who fulfils, who signs off. - Templates for the standard responses. - A register so you can prove you handled past requests within the deadline. Read [GDPR data subject rights](/en/kennisbank/rechten-en-verzoeken/gdpr-data-subject-rights) for the full nine rights. Standard responses for access, rectification, and erasure requests, plus a request register. - [ ] Privacy inbox is monitored. - [ ] DSAR procedure is documented. - [ ] Response templates and register are ready. ### Step 7: Breach procedure and 72-hour reporting **The check:** a documented procedure that gets you from "something went wrong" to a regulator notification inside 72 hours. A breach isn't only a hacker. It includes a colleague emailing client data to the wrong recipient, a lost USB stick, a stolen laptop, accidental deletion, or a misconfigured backup that leaked records. You need: - An internal breach log (every incident, regardless of whether it's reportable). - A clear test for what is reportable to the regulator (likely to result in a risk to the rights and freedoms of the affected individuals) and what is reportable to the data subjects themselves (high risk). - Contact details for your supervisory authority pre-filled in the procedure - no scrambling at hour zero. - Notification templates ready to go. Read [Personal data breach: what to do](/en/kennisbank/beveiliging/data-breach-guide). Notification form for the supervisory authority and a template for notifying affected data subjects. - [ ] Breach procedure is documented and known to the team. - [ ] Internal breach log exists. - [ ] Notification templates are pre-filled with your supervisory authority's details. ### Step 8: Direct marketing - source disclosure and opt-out **The check:** every direct marketing email or SMS includes a working opt-out, and you can prove where the recipient's data came from. GDPR plus ePrivacy add two requirements that catch SMEs out: 1. **Source disclosure.** You must be able to tell a recipient where their personal data came from (signed up on your site, scraped from a public list, bought from a partner, etc.). That implies a process for capturing source on every list import and signup. 2. **Opt-out in every message.** A working "unsubscribe" link in every direct marketing email. Most marketing platforms (Mailchimp, Brevo, etc.) handle this by default, but check. Once someone unsubscribes, they must stop receiving similar messages - permanently. Re-subscribing them later because they re-entered another funnel is a fine. Read [Direct marketing under GDPR](/en/kennisbank/verplichtingen/direct-marketing-gdpr). - [ ] Every marketing email has a one-click unsubscribe. - [ ] Source-of-data is captured for every list entry. - [ ] Suppression list is honoured across tools (CRM, marketing platform, ad audiences). ### Step 9: Have a separate staff privacy policy **The check:** a dedicated privacy policy for employees and contractors, separate from the customer one. The data you process about staff (payroll, performance, sickness, evaluations, time tracking) is very different from customer data. It also tends to be the source of most GDPR complaints when an employment relationship breaks down. A dedicated staff policy gives you cover. What to include: - HR systems and what they hold. - Performance, sickness, and evaluation records. - Monitoring (email, internet, building access, cameras) and on what legal basis. - Retention - how long after someone leaves you keep their record. - Their rights and how to exercise them. Read [Employee privacy policy: what to tell your staff](/en/kennisbank/hoe-gdprwise-werkt/employee-privacy-policy). Recruitment sits before this and needs its own treatment: see the [recruitment GDPR checklist](/en/kennisbank/hr/recruitment-gdpr-checklist). - [ ] Staff privacy policy exists and is given to every new joiner. - [ ] Linked or attached to the employment contract. - [ ] Reviewed annually. ## Part 3 - Higher care (steps 10 to 13) ### Step 10: Special category data check **The check:** you have explicitly identified whether you process any special category data, and if so, on which lawful basis. GDPR Article 9 prohibits processing the following unless one of nine specific exceptions applies: - Racial or ethnic origin - Political opinions - Religious or philosophical beliefs - Trade union membership - Genetic or biometric data - Health data - Data about sex life or sexual orientation Most SMEs don't process any of this on purpose. But you might be touching it without realising: a sickness absence record (health), a dietary preference for an event (potentially religion), a uniform-fit measurement (potentially health), a CV with a photo (potentially racial origin). Walk through your processing register and flag anything that touches the list above. For each, document the lawful exception (most often: explicit consent, employment-law obligation, or vital interests). If you can't identify one, stop the processing. - [ ] Each entry in the processing register is checked for special category data. - [ ] Where present, the Article 9 exception is documented. ### Step 11: Review security practices **The check:** the security measures behind each system in your processing register are documented and adequate. There is no privacy without security. The supervisory authority and a fined company will assess "appropriate" relative to the data sensitivity, the state of the art, and the cost - so an SME does not need bank-grade security, but does need defensible basics. Walk through your register, system by system. For each, check: **Physical security** - For cloud-hosted SaaS: rely on the provider's certifications (ISO 27001, SOC 2). Save evidence in your DPA file. - For self-hosted equipment: lock the server room, the filing cabinet, the office. Read [Paper document security](/en/kennisbank/beveiliging/paper-document-security) for documents that aren't on a screen. **System and software security** - Latest security patches applied. - Strong passwords enforced; two-factor authentication where the system supports it. - Access on a need-to-know basis; review who has access twice a year. - Read [Periodic access review](/en/kennisbank/beveiliging/periodic-access-review). **Data security** - Encryption at rest and in transit on every system holding personal data. - Backups exist, are encrypted, and have been tested with a real restore. - Read [Information security policy: what should it include](/en/kennisbank/beveiliging/information-security-policy). **Vendor security** - DPA on file (covered in step 4). - For high-sensitivity processors, sub-processor list reviewed. - [ ] Each system in the register has a documented security review. - [ ] Backups are tested at least annually with a real restore. - [ ] Access reviews are scheduled. ### Step 12: Privacy awareness training and code of conduct **The check:** every staff member who handles personal data has done basic privacy awareness training in the last twelve months. The human factor is the most consistent source of breaches: phishing, BCC-vs-CC mistakes, attachments to the wrong recipient, weak passwords, sharing accounts, taking unencrypted laptops home. None of those are technical failures. They're training failures. A defensible SME training programme: - Annual privacy and security awareness session for all staff (online, 30-60 minutes). - Onboarding session for new joiners before they touch personal data. - A code of conduct that everyone signs, covering privacy, security, and ethical behaviour. Read [The human factor in data breaches](/en/kennisbank/beveiliging/human-factor-data-breaches) and [Privacy and ethics: code of conduct](/en/kennisbank/beveiliging/code-of-conduct). - [ ] Training is done annually and on onboarding. - [ ] Attendance is tracked and stored. - [ ] Code of conduct is signed by every staff member. ### Step 13: International considerations and annual review **The check (if applicable):** if you serve EU customers from outside the EU, or operate in multiple EU countries, you've sorted the cross-border specifics. **You're outside the EU but sell into it:** Article 27 requires an EU-based representative. The cheapest path is a commercial Article 27 representative service. **You operate in multiple EU countries:** identify your **lead supervisory authority** - the one where your main establishment (or main decision-making about processing) is located. That authority leads on any cross-border issue under the one-stop-shop mechanism. **Cross-border data transfers:** if you transfer personal data outside the EU/EEA, document the transfer mechanism (adequacy decision, Standard Contractual Clauses, Binding Corporate Rules) for each. Read [Approved third countries for non-EU data transfer](/en/kennisbank/beveiliging/approved-third-countries). **The annual review:** once a year, walk back through every check in this article and confirm it is still up-to-date, accurate, and complete. New tools, new staff, new processes and new sub-processors creep in over the year - the annual review is what keeps the checklist truthful instead of aspirational. Pay particular attention to these four items, where drift is most common: - [ ] **Processing register re-walked** - every entry verified, new processing activities added, retired ones removed. - [ ] **Every linked policy is still accurate** - customer privacy policy, staff privacy policy, cookie policy, internal procedures. - [ ] **Security review re-run per system** - patches, access review, backup-restore test, encryption status. - [ ] **Staff training refreshed** - everyone has done the annual session; new joiners onboarded; signed code of conduct on file. And the cross-border specifics: - [ ] Article 27 representative is in place if you sell into the EU from outside. - [ ] Lead supervisory authority is identified for cross-border operations. - [ ] International transfers are documented per system. - [ ] Annual review date is in the calendar for next year. ## Master checklist (compact version) Print this page or copy the below into your tracker. **Documentation** - [ ] Privacy Coordinator designated, `privacy@` mailbox active - [ ] Processing register (ROPA) complete - [ ] Customer privacy policy published, footer-linked - [ ] Staff privacy policy issued to every joiner - [ ] DPAs signed with every processor - [ ] Cookie inventory and consent flow validated **Operations** - [ ] DSAR procedure and templates ready - [ ] Breach procedure and 72-hour-ready notification templates - [ ] Direct marketing: source captured, opt-out works, suppression honoured - [ ] Special category data identified and lawfully justified **Security and people** - [ ] System-by-system security review documented - [ ] Backups tested with real restore - [ ] Annual privacy and security training done by every staff member - [ ] Code of conduct signed - [ ] Article 27 representative if outside-EU - [ ] Annual review date in calendar ## Common myths and what you don't actually need

lightbulb Don't fall for these

GDPR is often made out to be heavier than it is for SMEs. Some of what you've heard is myth, and some of what gets sold to you isn't actually required. The list below clears both up.

Common SME misconceptions

  • "GDPR only applies to big companies." It applies to anyone processing personal data, regardless of size. Read why.
  • "Small businesses never get fined." They do, and the fines scale with what an SME can pay. Read more.
  • "GDPR is just about cookies." Cookies are one slice; the obligations cover all personal-data processing. Read more.
  • "I don't have any personal data." If you have customers, staff, or suppliers, you almost certainly do. Read more.
  • "The authorities aren't interested in me." Most enforcement starts with a complaint from an individual, not a proactive audit. Read more.

What you can skip (as an SME)

  • A formal DPO - unless you do large-scale monitoring or large-scale special-category processing. The Privacy Coordinator from step 1 covers the rest.
  • A DPIA for routine processing - only required for new high-risk processing (large-scale systematic monitoring, large-scale special-category data, automated decisions with legal effect).
  • An expensive consultant - the basics are handleable in-house with the right templates and tools.
  • A privacy lawyer on retainer - your supervisory authority's website has SME-focused guidance, and a one-off legal review at year-end is plenty.
--- ### GDPR Compliance in 4 Steps - Graphic Sector URL: https://gdprwise.eu/en/kennisbank/verplichtingen/gdpr-graphic-sector/ Summary: Print shops, design agencies, and prepress companies process more personal data than they realise. This article explains how to get your GDPR compliance in order step by step. Key takeaways: - Graphic companies process personal data through client files, printed materials with personal data, and digital proofs - Personalised print work (mailings, invoicing) often contains large volumes of third-party personal data - You need a data processing agreement with clients who provide you personal data for print work - Digital proofs and files with personal data must be deleted after the job is completed FAQ: Q: Am I a processor or a controller as a print shop? A: Usually you are a processor: you process personal data on behalf of your client (e.g. printing personalised mailings). For your own client and employee data, you are the controller. The distinction determines your obligations. Q: Do I need to delete files with personal data after printing? A: Yes, unless your client explicitly asks you to keep them for reprinting. Set a retention period and communicate it with your client. After the period expires, delete the files. ## Personal data in the graphic sector As a graphic company, you work with client files every day. Many of those files contain personal data: address lists for mailings, personalisation for invoices, business cards with contact details, annual reports with employee photos. On top of that, you have your own client and employee data. The GDPR definitely applies to you. ## Step 1: Map your processing activities Identify which personal data you process: **As a controller (your own data):** - Client data: contact persons, billing details, quote history - Employee data: employment contracts, payslips, sick leave records - Supplier data: contacts at paper suppliers, freelancers **As a processor (your clients' data):** - Address lists for personalised mailings - Files with personal data for printed materials (certificates, diplomas, badges) - Photos and images featuring identifiable individuals ## Step 2: Arrange your data processing agreements If you process personal data on behalf of clients, you are a processor. You need a data processing agreement (DPA) with every client that provides personal data. The agreement covers: - What data you process and why - How you secure the data - What you do with the data after the job - How you handle data breaches GDPRWise generates these agreements automatically. ## Step 3: Secure your systems and files Graphic companies work with large files that are often exchanged via FTP, WeTransfer, or email. Ensure: - **Secure file transfer** - use encrypted connections - **Access control** - not every employee needs access to every client file - **Deletion after delivery** - establish a policy for deleting client files after the job - **Backup policy** - backups containing personal data must also be purged after the retention period ## Step 4: Document and maintain Create your processing register, publish a privacy policy, and train your employees on handling personal data. Schedule an annual review to keep everything up to date. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### GDPR Compliance in 4 Steps - Legal Sector URL: https://gdprwise.eu/en/kennisbank/verplichtingen/gdpr-legal-sector/ Summary: Lawyers and legal advisors process sensitive personal data as a core activity. This article explains how legal professionals can get GDPR compliant step by step. Key takeaways: - Lawyers process highly sensitive personal data: criminal records, health data, financial information - Professional secrecy does not exempt you from GDPR obligations, but it does influence how you fulfil them - Case file security is crucial: both digital and physical - You are the data controller for your client files, not merely a processor FAQ: Q: Does professional secrecy override the GDPR? A: Professional secrecy and the GDPR exist alongside each other. Professional secrecy protects the confidentiality of the client relationship. The GDPR regulates how you handle personal data. In practice, they reinforce each other: both require careful handling of sensitive information. Q: Do I need to carry out a DPIA? A: If you process special categories of personal data on a large scale (such as criminal records), a DPIA is mandatory. Many law firms fall into this category. ## Sensitive data as daily business Lawyers and legal advisors inherently process highly sensitive personal data. Criminal case files, medical reports in personal injury cases, financial data in bankruptcy proceedings, family details in divorce cases - it is the core of your work. This makes GDPR compliance non-optional. It is a fundamental part of the duty of care you already have as a legal professional. ## Step 1: Map your processing activities **Client files:** - Contact details of clients and opposing parties - Court documents containing personal data of third parties - Financial data (in debt collection, bankruptcy, divorce) - Criminal records (in criminal cases) - Medical data (in personal injury cases) **Office operations:** - Employee and intern personnel data - Invoicing and debtor administration - Client escrow account administration **Digital tools:** - Website with contact form - Email communication with clients - Document management system ## Step 2: Strengthen your file security Given the sensitivity of the data you process, security requirements are higher: - **Encryption** of digital case files and email communication - **Physical security** of paper files in locked rooms - **Strict access control** - only involved staff members have access to a file - **Secure communication** with clients (secure portals, encrypted email) - **Destruction** of files after the retention period expires ## Step 3: Prepare your documentation - **Privacy policy** specific to your practice - **Processing register** covering all processing activities - **Processing agreements** with IT suppliers, cloud storage providers, external secretarial services - **Retention policy** per file type (professional rules prescribe minimum retention periods) - **Data breach procedure** including the role of professional secrecy in reporting ## Step 4: Train your team Staff, secretaries, and interns must know how to handle confidential data. This goes beyond professional secrecy: it also covers digital hygiene, clean desk policy, and recognising phishing attempts. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### GDPR Compliance in 4 Steps - Real Estate Sector URL: https://gdprwise.eu/en/kennisbank/verplichtingen/gdpr-real-estate-sector/ Summary: Estate agents, landlords, and property managers process personal data of tenants, buyers, and sellers. This article explains how real estate professionals can get GDPR compliant step by step. Key takeaways: - Real estate professionals process substantial personal data: from identity documents to financial details of tenants and buyers - Copies of identity documents may only be retained if there is a legal basis for doing so - Tenant files often contain sensitive information such as income data that requires extra protection - After a tenancy agreement ends, data must be deleted unless a retention obligation applies FAQ: Q: May I keep a copy of a tenant's identity document? A: Only if you have a legal basis for it. When signing a tenancy agreement, you may verify identity, but keeping a copy is only permitted if the law requires it. Consider recording only the necessary details rather than keeping a full copy. Q: How long may I keep data of former tenants? A: After the tenancy agreement ends, you only keep data as long as there is a legal or statutory interest (e.g. outstanding claims or tax obligations). Set a retention period per data type. ## Personal data is at the heart of real estate Real estate transactions revolve around people and their data. As an estate agent, landlord, or property manager, you process personal data daily: identity documents of buyers and tenants, financial data for creditworthiness checks, tenancy agreements with personal details, and often photographs of residents. The GDPR sets requirements for how you handle this data. ## Step 1: Map your processing activities **Tenants and buyers:** - Identity data: name, address, date of birth, copy of identity document - Financial data: proof of income, bank details, rental history - Tenancy agreements and annexes - Communication history **Sellers and landlords:** - Ownership details and land registry information - Contact details and communication - Financial data related to the sale **Business operations:** - Personnel data of your own employees - Website with contact form and property search function - CRM system with contacts ## Step 2: Clean up your files Real estate offices often keep more data than necessary, and for longer than permitted: - **Delete copies of identity documents** for which you no longer have a legal basis - **Clean up former tenant files** after the retention period expires - **Remove data of rejected tenant candidates** after the selection process is completed - **Tidy your CRM** - contacts with whom you no longer have a relationship ## Step 3: Prepare your documentation - **Privacy policy** for your website and office - **Processing register** covering all processing activities - **Processing agreements** with your CRM provider, accountant, and IT partner - **Retention policy** per file type - **Information for tenants** about which data you collect and why ## Step 4: Train your team and maintain Staff who manage tenant files must know which data they may request, how long to retain it, and how to respond to access requests. Schedule an annual refresher and combine it with file clean-up. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### GDPR Minimum: Transparency First, Then Grow Into the Rest URL: https://gdprwise.eu/en/kennisbank/verplichtingen/gdpr-minimum-transparency-first/ Summary: The honest, smallest version of GDPR for a business that just started: what transparency actually requires, the five must-do's, and how to mature as you grow. Key takeaways: - The overriding GDPR requirement for an SME is to be transparent with people about what you do with their data, and to only do what you said you'd do. - Five must-do's cover the day-one minimum: know your data, name a privacy coordinator, publish a tailored privacy policy that names them, train the staff who handle personal data, and get cookies right (or skip them). - The minimum is the same for every SME; the depth scales with your size, partners, and revenue. - Start with transparency and the foundation checklist below; layer in DSAR procedures, breach drills, staff training and DPIA only when your risk profile says so. FAQ: Q: What does a small business need to do to be GDPR compliant? A: Five things, all grounded in transparency. Build three core dossiers (customers, staff, third parties) organised by business process, so you know what data you hold and why. Designate a Privacy Coordinator with a privacy@ inbox. Publish a tailored privacy policy on your website that reflects those dossiers and names the coordinator. Give the people who handle personal data a basic privacy and security awareness session. And get cookies right, or skip them entirely. That's the minimum. DPAs, breach drills and DSAR procedures come next as the business grows. Q: I just started a SaaS. What's the GDPR minimum I need? A: Five things: an inventory of the personal data you hold across customers, staff and third parties; a named Privacy Coordinator reachable on privacy@yourcompany.com; a tailored privacy policy on your website that reflects what you actually do and names the coordinator; basic privacy and security awareness training for any staff who handle personal data; and either no non-essential cookies or a working consent flow. That covers transparency, which is the principle the rest of GDPR rests on. DPAs with your vendors come next, as the business grows. Q: Do I need a Data Protection Officer (DPO) as a startup? A: Almost certainly not. A formal DPO is only required if your core activity is large-scale, regular monitoring of individuals, or large-scale processing of special category data (health, biometrics, religion, etc.). For everyone else, designate an internal Privacy Coordinator: same single point of contact, no formal DPO obligations. Q: Do I need a privacy policy if I don't have customers yet? A: If your website collects any personal data, including a contact form, a newsletter signup, an analytics cookie, or a support chat widget, then yes. The moment data leaves the visitor's browser and reaches you or a third party, the visitor has the right to know who, why, and on what basis. Publish the policy before you publish the marketing site. Q: Can I just skip cookies? A: Yes, and for many new businesses it's the better call. No non-essential cookies means no cookie banner, no consent management platform, no recurring audit overhead, and one fewer thing for a regulator to look at. Privacy-respecting analytics (server-side, IP-anonymised, or cookieless tools) give you most of the visibility without the compliance tax. Q: When does the minimum stop being enough? A: When your risk profile grows. More customers means more potential rights requests, so you need a documented DSAR procedure. More staff means a separate staff privacy policy and basic training. More vendors and partners means active DPA management and a sub-processor list. More revenue means you become a more attractive target for both attackers and complaints. The full SME checklist (13 steps) is the next level up; this article covers the minimum to start. import TemplateTip from '@/components/TemplateTip.astro'; import ArticleCTA from '@/components/ArticleCTA.astro'; ## The one idea that makes GDPR make sense If you just started a business and you're reading about GDPR for the first time, you probably picked up a vague sense that there is a lot of paperwork, some fines, and some cookie banners. That picture is mostly noise. The signal is simpler. GDPR has one core idea: **be transparent with people about what you do with their data, and only do what you said you'd do**. Everything else, the registers, the policies, the agreements, the rights, the breach reporting, all of it, is plumbing that exists to make that one idea real. If you internalise that, the minimum gets a lot less intimidating. You don't need a privacy lawyer. You don't need a consultant. You don't need a DPO. You need to be honest, in writing, with the people whose data you hold, and you need to be able to keep that promise when something goes wrong. This article gives you the smallest, honest version of GDPR for a brand-new business. Five must-do's grounded in transparency, a day-one checklist, a short guide to what shifts depending on the type of business you run, and a map for how to mature as you grow. ## The minimum, in five must-do's These five cover what transparency actually requires on day one. Each one is something a regulator, a customer, or an angry ex-employee can ask you to produce, and you should be able to produce it without scrambling. ### 1. Know what data you hold (three core dossiers) You can't be transparent about something you haven't catalogued. Before you write a privacy policy or sign anything, you need an honest answer to: which personal data flows into my business, why, and from whom? Split it into three dossiers. Each dossier is organised by **business process**, and the data items live inside the processes that use them. That ordering matters: a process is what gives the data its purpose, legal basis and retention, so capturing the process first is what makes the rest of GDPR fall into place. 1. **Customer Dossier.** The processes you run to find, sell to and serve customers (onboarding, billing, support, marketing, account management), and the data items each one touches: names, emails, addresses, billing data, support tickets, account data. 2. **Staff Dossier.** The processes you run to hire, pay and manage staff (recruitment, employment, payroll, sickness, evaluations, time tracking, offboarding), including contractors and freelancers, and the data each process uses. 3. **Third Party Dossier.** The processes that touch people at suppliers, partners and prospects (procurement, vendor management, partner enablement, prospecting), and the personal data those processes hold (the accountant's bookkeeper, the agency's client contact, the vendor's account manager). For each process, capture: what it does, why you do it (purpose), on what legal basis (consent, contract, legal obligation, legitimate interest), which data items it uses, how long they're kept, and who else sees them (your hosting provider, your email tool, your accountant). GDPRWise builds these three dossiers for you through a guided setup that starts with the processes and pulls the data items in from there; you can also do it on a spreadsheet if you prefer. What matters is that the process-level register exists before the policy does. ### 2. Name a Privacy Coordinator GDPR transparency includes being reachable. People whose data you hold have the right to ask questions, file complaints, and exercise rights (access, rectification, deletion, portability). They need to know who to write to, and that name belongs in the privacy policy you publish in step 3. You don't need a formal DPO. For almost every SME, a **Privacy Coordinator** is enough: one named person inside the business who owns GDPR. Their job is to keep the dossiers current, take incoming privacy questions, and own the relationship with your supervisory authority if anything goes wrong. Set up `privacy@yourcompany.com` and monitor it. Put both the coordinator's name and the address in the privacy policy and the website footer. ### 3. Publish a tailored privacy policy The privacy policy is the promise. It tells visitors, customers, and staff what you do with their data, who handles it, and what they can do about it. The two failure modes are equally common. The first is having no policy at all. The second is copying one from another business and slapping your name on it. A regulator can read both your policy and your actual processing, and if they don't match, the policy is worse than useless. A compliant policy reflects **your** dossiers: your processing activities, your legal bases, your vendors, your retention periods, your contact details, and the Privacy Coordinator from step 2. It lives at a top-level URL, linked from the footer of every page on your site, never buried inside terms and conditions. If you've done steps 1 and 2, GDPRWise generates the policy from your dossiers with the coordinator pre-filled. Read [Drafting a privacy policy](/en/kennisbank/verplichtingen/privacy-policy-guide) for the full structure. ### 4. Train the staff who handle personal data A policy on the website is only as good as the people executing it day to day. The most consistent source of breaches is not hackers; it is staff: phishing clicks, BCC-vs-CC mistakes, attachments sent to the wrong recipient, weak or shared passwords, unencrypted laptops taken home, client data pasted into the wrong chat window. For a new business, the minimum is short and cheap: - Anyone who handles customer, staff, or third-party data goes through a basic privacy and security awareness session before they touch real data. - The same session is refreshed once a year. - New joiners get it during onboarding. It doesn't need to be a formal LMS rollout. A 30 to 60 minute walkthrough covering phishing, password hygiene, two-factor authentication, safe handling of personal data, and what to do when something goes wrong is enough at this stage. Track attendance so you can prove it later. Read [The human factor in data breaches](/en/kennisbank/beveiliging/human-factor-data-breaches) for the full picture of why this matters and what a defensible programme looks like. ### 5. Get cookies right, or skip them Cookies that can identify a visitor process personal data. Under GDPR plus the ePrivacy Directive, you need informed consent **before** any non-essential cookie is set, and rejecting must be as easy as accepting. The honest minimum has two acceptable shapes: - **Skip non-essential cookies entirely.** No third-party analytics with cookies, no marketing pixels, no embeds that drop trackers on page load. You get no banner, no consent platform, no audit overhead. For a new business this is often the smartest call. Read [Privacy-respecting analytics alternatives](/en/kennisbank/verplichtingen/privacy-analytics-alternatives). - **Run a real consent flow.** Nothing fires before consent, Reject is as prominent as Accept, no pre-ticked boxes, no dark patterns. Read [Cookies and consent: what you need to know](/en/kennisbank/verplichtingen/cookies-consent-guide). The unacceptable shape: cookies firing on page load, a banner that only has Accept, or copy that says "by using this site you accept cookies". Regulators fine all three regularly. ## "But I run a ..." — minimum by business type The five must-do's are universal. The traps are different depending on what you sell. **SaaS startup.** You are a processor for your customers' data and a controller for your own users. That means two-sided DPAs: you sign DPAs with your vendors (the controller-to-processor side), and your customers will ask **you** to sign their DPA (the processor-to-sub-processor side). Publish a public DPA on your site or in your terms. Make your hosting region clear (EU vs US matters to enterprise buyers). Maintain a sub-processor list and notify customers when it changes. **Webshop or e-commerce.** Your traffic-and-conversion stack is the danger zone: tag managers, ad pixels, abandoned-cart trackers, recommendation engines, and payment fraud tools all set cookies and ship data to third parties. Audit every script. Marketing consent (newsletter, retargeting) is a separate basis from the order itself; capture each one explicitly. Your retention policy needs to cover order history, accounting requirements, and warranty periods, which often conflict; document the longest applicable period per data category. **B2B services, consultancy, accounting, bookkeeping.** Most of your data is other people's people: your client's customers, employees, suppliers. That makes you a processor for almost everything you touch. Your minimum is heavier on DPAs (one with every client, not just every vendor), and on access control (which staff member sees which client's records). Accountants and bookkeepers in particular have a legal retention obligation that overlaps with GDPR retention rules; document the legal basis (legal obligation) for the long retention, and don't let it bleed into other uses. **ZZP or freelancer.** GDPR applies even with no employees and one client. The minimum is the same five steps but lighter. Your three dossiers might fit on a single page each. Your privacy policy can be short. Your DPAs are mostly the standard ones from your SaaS vendors. The one trap: don't store client data in personal cloud drives or personal email; a clean separation between personal and professional accounts is the cheapest security control you have. **Marketing or design agency.** You're often the processor and your client is the controller, which inverts who answers data subject requests. Your contracts with clients should make that explicit. Tools-of-the-trade (Figma, Canva, Mailchimp, ad platforms) each need a DPA. Asset libraries and old project folders are silent retention liabilities; schedule deletion when an engagement ends. ## The day-one foundation checklist Print this or paste it into your tracker. If every box below is ticked, you have an honest, defensible GDPR minimum. **Know your data** - [ ] Customer dossier complete (categories, purpose, legal basis, retention, recipients) - [ ] Staff dossier complete (even if it's just you) - [ ] Third-party dossier complete (suppliers, partners, prospects) **Be reachable** - [ ] Privacy Coordinator named internally - [ ] `privacy@yourcompany.com` mailbox active and monitored - [ ] Coordinator's role documented and known to the team **Tell people about it** - [ ] Tailored customer privacy policy published - [ ] Privacy Coordinator named in the policy - [ ] Linked from the footer of every page - [ ] Reflects the dossiers, not boilerplate - [ ] Includes data subject rights and complaint route to your supervisory authority **Train the team** - [ ] Everyone who handles personal data has done a basic privacy and security awareness session - [ ] Attendance tracked and stored - [ ] Refresh scheduled annually and built into onboarding **Cookies** - [ ] Either: no non-essential cookies, confirmed in a private window with dev-tools open - [ ] Or: consent flow validated (nothing fires before consent, Reject as prominent as Accept, no pre-ticked boxes) That's the foundation. Five must-do's, sixteen checks. ## Growing into more compliance as you grow The minimum above is enough to start. It is not enough forever. As your business grows, your risk profile shifts, and a few additional steps stop being optional. **More customers** means more potential rights requests, so you need a documented Data Subject Access Request (DSAR) procedure with templates and a register, not an ad-hoc reply each time. **More staff** means a separate staff privacy policy (different from the customer one), a signed code of conduct, and the awareness training from step 4 formalised into something you can prove (attendance lists, completion records, a refresh cycle). **More vendors and partners** means signed Data Processing Agreements (DPAs) with every external party that handles personal data on your behalf: hosting, email, CRM, analytics, payments, accountant, support tools. Most SaaS vendors publish a DPA you can sign in two minutes; for smaller suppliers, send your own. Once you have a few, you also need a register telling you which DPAs you have, which need renewal, and which sub-processors changed last quarter. Read [Data processing agreements](/en/kennisbank/verplichtingen/processing-agreement). **More revenue and more data** means you're a bigger target. Annual security reviews per system, real backup-restore tests, periodic access reviews (who can see what, and do they still need to), and a documented breach procedure that gets you from "something went wrong" to a regulator notification inside 72 hours. **Higher-risk processing** (large-scale monitoring, special category data like health or biometrics, automated decisions with legal effect) means a Data Protection Impact Assessment (DPIA), and possibly a formal DPO. The full [GDPR Checklist for SMEs](/en/kennisbank/verplichtingen/gdpr-checklist-sme) walks through the thirteen steps that cover this maturity ladder. Treat this article as the foundation; treat the checklist as the destination. ## A word on what you don't need yet A formal DPO. A privacy lawyer on retainer. A consultant engagement. A DPIA for routine processing. An ISO 27001 audit. A six-month implementation project. What you do need: an honest catalogue of what data you hold, a policy that reflects it, one human reachable to answer questions, signed agreements with your vendors, and a clean cookie story. That's the minimum. Start there, grow into the rest. --- ### GDPR Register: Do I Need One? URL: https://gdprwise.eu/en/kennisbank/verplichtingen/gdpr-register-do-i-need-one/ Summary: Yes, almost every business does. The 'fewer than 250 employees' exemption rarely applies in practice. Here's what the register must contain and how to start. Key takeaways: - Almost every business needs a GDPR register (Records of Processing Activities), the moment you have one customer, one staff member, or one supplier whose data you handle - The 'fewer than 250 employees' exemption sounds generous but rarely applies, since the exceptions catch nearly all real-world processing - There is no official template, but a national supervisory authority can ask to see your register at any time - GDPRWise generates the register automatically once your dossier is filled in, no Excel sheets required FAQ: Q: Does my one-person company need a GDPR register? A: Yes, if you process any personal data, customer emails, supplier contacts, or even just your own personal data through business systems, the register obligation applies. The size of your company does not change the rule, only the way you keep the record. Q: I have fewer than 250 employees, am I exempt? A: Almost certainly not. The Article 30(5) GDPR exemption only applies if your processing is occasional, does not involve special categories (health, biometric, etc.), and is not likely to risk people's rights. In practice, every business that processes customer or staff data on a regular basis falls outside the exemption. Q: What format does the register need to be in? A: There is no mandatory format. Excel, Word, a database, or a tool like GDPRWise are all acceptable. What matters is that the register is current, complete, and can be shown to a supervisory authority on request. Q: Who is allowed to see my register? A: Your national data protection authority can request it during an inspection or after a complaint. Internally, your DPO (if appointed) and anyone responsible for compliance should have access. It does not need to be public. ## The short answer Yes. If you process personal data of customers, staff, or suppliers, you need a GDPR register, also called Records of Processing Activities or RoPA. This is required by **Article 30 of the GDPR**, and the obligation kicks in the moment you have your first customer, supplier, or employee. ## The "fewer than 250 employees" myth Article 30(5) appears to exempt organisations with fewer than 250 employees. In practice, the exemption rarely applies because it has three carve-outs, and almost all businesses fall into at least one: - **The processing is more than occasional.** Sending invoices to repeat customers, paying staff every month, storing supplier contacts, all of these are regular activities, not occasional ones. - **You process special categories of data.** Health information, biometric data, data about minors, or anything covered by Article 9 disqualifies you. - **The processing could risk individual rights.** Customer profiling, marketing automation, employee monitoring, and similar activities all fall in this bucket. In reality, the exemption was designed for very narrow cases such as a one-off charity drive. If you operate a real business with regular customers and employees, assume the register applies to you. ## What the register must contain Per Article 30(1), the register must list every processing activity with: - **Who:** whose data you process (customers, staff, suppliers, partners) - **What:** the categories of personal data (name, email, address, payment info, etc.) - **Why:** the purpose of the processing (invoicing, hiring, marketing, etc.) - **Legal basis:** consent, contract, legal obligation, legitimate interest, etc. - **Recipients:** which third parties receive the data, and whether they sit inside or outside the EU - **Retention:** how long you keep each category - **Security:** the technical and organisational measures in place You should keep separate records for activities where you are the **Data Controller** (you decide why and how the data is processed) and where you are a **Data Processor** (you handle data on behalf of someone else). ## What happens if you don't have one The supervisory authority can request your register during an inspection or after a complaint. If you can't produce one, that itself is a GDPR breach. Penalties for missing or incomplete records have already been issued across the EU, including to SMEs. Beyond fines, the register is your own internal compass: without it, you can't reliably answer data subject requests, manage breaches, or demonstrate accountability. ## How to start You have three options: 1. **Build it yourself in a spreadsheet.** Free, but high-maintenance and easy to leave incomplete. 2. **Hire a consultant.** Thorough, but expensive and dependent on their continued availability. 3. **Use a tool like GDPRWise.** The platform asks the right questions per business sector, generates the register from your answers, and keeps it current as your operations change. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### GDPR: What Is It and Why Does It Matter for Your Business? URL: https://gdprwise.eu/en/kennisbank/verplichtingen/gdpr-what-is-it/ Summary: The GDPR is the European privacy law governing how businesses handle personal data. This article explains in plain language what the law covers, who it applies to, and why compliance matters. Key takeaways: - GDPR stands for General Data Protection Regulation - the EU-wide privacy law in force since May 2018 - It applies to every organisation that processes personal data of people in the EU, regardless of company size - Personal data is broader than you think: name, email, IP address, purchase history - it all counts - Non-compliance can lead to fines, reputational damage, and loss of customer trust FAQ: Q: What counts as personal data? A: Personal data is any information that can directly or indirectly identify an individual. This includes obvious items like name and address, but also email addresses, IP addresses, purchase history, photos, and even location data. Q: Does the GDPR apply outside Europe? A: Yes. The GDPR applies to any organisation that processes personal data of people in the EU, regardless of where the company itself is based. A US company offering services to European customers falls under it too. Q: Is the GDPR the same everywhere in the EU? A: Yes. The GDPR is a regulation, not a directive, so it applies uniformly across all EU member states. Each country has its own supervisory authority for enforcement. ## The European privacy law in brief The GDPR (General Data Protection Regulation) is a European regulation that has been in force since 25 May 2018. Its core message is straightforward: if you collect or process personal data, you must do so responsibly - transparently, securely, and with a valid reason. ## What counts as personal data? Personal data is any information that can directly or indirectly identify a person. That is broader than most business owners realise: - **Directly identifiable** - name, address, phone number, email address, national ID number - **Indirectly identifiable** - IP address, purchase history, location data, cookie data - **Sensitive data** - health records, criminal records, biometric data, religious beliefs If you have a customer list, send a newsletter, manage personnel files, or run a website with a contact form, you are processing personal data. ## What does the GDPR require? The law rests on several core principles: ### Transparency Tell people which data you collect, why, and what you do with it. You do this through a privacy policy. ### Purpose limitation Collect data only for a specific, legitimate purpose. Do not use it for anything other than what you collected it for. ### Data minimisation Do not collect more data than you need. If you only need an email address for your newsletter, do not ask for a date of birth as well. ### Accuracy Keep personal data up to date and correct inaccurate records. ### Storage limitation Do not keep data longer than necessary. When a customer relationship ends and you have no legal retention obligation, delete the data. ### Security Take appropriate measures to protect personal data against unauthorised access, loss, or theft. ## Why does it matter? ### Fines Supervisory authorities can impose fines for non-compliance. For serious infringements, up to 20 million euros or 4% of annual turnover. In practice, SMEs receive lower fines, but they do occur. ### Customer trust Consumers are increasingly aware of their privacy rights. A business that handles personal data carefully earns trust. A data breach or privacy violation can destroy that trust instantly. ### Competitive advantage GDPR compliance is increasingly a requirement in B2B relationships. Larger companies ask their suppliers to demonstrate that they are compliant. ### It is the law Ultimately, the GDPR is not optional. It is an obligation for every organisation that processes personal data. ## Where to start? The first step is knowing which personal data you process and why. GDPRWise helps you with that: the free scan maps out what is happening on your website, and the dossiers help you document all your processing activities. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### GPS Tracking of Employees: What Is and Isn't Allowed under the GDPR? URL: https://gdprwise.eu/en/kennisbank/verplichtingen/gps-tracking-employees-gdpr/ Summary: GPS data from company vehicles and employees is personal data under the GDPR. This article explains when tracking is permitted, with two Belgian court cases as a warning. Key takeaways: - GPS location data is personal data as soon as it can be linked to an individual - 24/7 tracking of employees is almost never permitted, even when the company vehicle is used privately - A Belgian employer lost a court case for continuously tracking employees outside working hours - You need a DPIA (Data Protection Impact Assessment) if you systematically process location data FAQ: Q: May I install GPS trackers in company vehicles? A: Yes, but only if you have a clear purpose (e.g. route planning, theft prevention), limit tracking to working hours, inform employees in advance, and document it in your processing register. 24/7 tracking is almost never permitted. Q: Can employees refuse to be tracked? A: If the tracking is based on legitimate interest, employees can object. You must then demonstrate that your interest outweighs theirs. With consent as the legal basis, there is a problem: consent in an employment relationship is rarely 'freely given' due to the power imbalance. Q: Do I need to conduct a DPIA for GPS tracking? A: Yes, if you systematically and/or on a large scale process location data. This applies to most transport companies and businesses with a fleet of company vehicles. Q: How long may I retain GPS data? A: No longer than necessary for the purpose. For route planning, that is typically a few weeks. For invoicing purposes it may be longer, but then only retain the necessary data (e.g. kilometres driven, not the full route). ## GPS data is personal data As soon as location data can be linked to an identifiable person, it is personal data under the GDPR. With company vehicles, this is almost always the case: the vehicle is assigned to a specific employee, so the vehicle's location equals that person's location. This applies to: - GPS trackers in company cars - Location data from company phones - Route logging via onboard computers - Apps that track the location of field staff Because location data provides detailed insight into someone's behaviour and movements, the GDPR treats it as particularly sensitive. ## Two Belgian cautionary tales ### Labour Court Leuven: 24/7 tracking is unlawful An employer installed GPS trackers in company vehicles and tracked employees continuously, including outside working hours. The vehicle was used both professionally and privately. The court ruled: - 24/7 tracking is a **disproportionate interference with private life** - The employer had **no clear, legitimate purpose** for continuous surveillance - Employees were **insufficiently informed** about the data processing **Result:** the processing was unlawful. The employer lost the case. ### Belgian DPA fine: transport company (2022) A transport company collected GPS data from drivers via onboard computers. The Data Protection Authority (GBA) found: - **No clear legal basis** (legitimate interest not properly substantiated, no valid consent) - **No internal privacy policy** on the use of GPS data - **Insufficient information** to drivers about what happened with their data **Result:** administrative fine for lack of transparency. ## When IS GPS tracking permitted? GPS tracking is not prohibited, but you must meet strict conditions: **1. You have a clear, specific purpose** Examples of valid purposes: - Route optimisation and planning - Vehicle theft prevention - Invoicing based on kilometres driven - Employee safety in high-risk areas "Checking whether employees are actually working" is rarely a valid purpose. **2. You choose the right legal basis** - **Legitimate interest** is the most common basis for GPS tracking, but you must conduct and document a balancing test - **Consent** is problematic in an employment relationship due to the power imbalance; an employee can hardly give "free" consent **3. You limit tracking to what is necessary** - Only during working hours, not 24/7 - Only the data you actually need (e.g. start and end point, not position every second) - No tracking of private journeys **4. You inform your employees** - Include GPS tracking in your employee privacy policy - Explain: what data, for what purpose, how long retained, who has access - Inform employees before activating tracking, not afterwards **5. You conduct a DPIA** For systematic, large-scale tracking, a Data Protection Impact Assessment (DPIA) is mandatory. Document the risks and the measures you take. ## Do's and don'ts ### What you SHOULD do - Document GPS usage in your **processing register** and **employee privacy policy** - Limit tracking to **working hours** unless you have a specific justification - Limit **access** to GPS data to managers who genuinely need it - Conduct a **DPIA** for large-scale tracking - Apply **pseudonymisation** where possible (e.g. vehicle ID instead of employee name) - Set **retention periods** and automatically delete old GPS data ### What you should NOT do - **24/7 tracking** without a compelling necessity - Base tracking on **general consent** ("you signed the employment contract, so you consent") - Use GPS data for **purposes other than** those for which you collected it (e.g. collected for route planning, used for performance evaluation) - **Retain GPS data longer than necessary** - Ignore the **data breach notification obligation** if GPS data is leaked ## What should you do now? 1. **Identify** whether you process GPS data (company vehicles, phones, apps) 2. **Document** the purpose, legal basis and retention period in your processing register 3. **Check** whether employees are informed via the employee privacy policy 4. **Limit** tracking to working hours and necessary data 5. **Conduct a DPIA** if you systematically process location data 6. **Set retention periods** and automatically delete old GPS data import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### How to Create an AI Acceptable Use Policy for Your Business URL: https://gdprwise.eu/en/kennisbank/verplichtingen/ai-acceptable-use-policy/ Summary: Your employees are already using AI tools. An internal AI acceptable use policy sets clear rules for responsible use, protects personal data, and keeps your business GDPR-compliant. Here is a practical guide to building one. Key takeaways: - Your employees are already using AI tools - with or without your permission. A policy gives them clarity and protects your business. - The GDPR requires you to document AI tool usage, have processing agreements in place, and inform data subjects. - Sensitive personal data (Article 9) and confidential business data should never go into AI tools without strict safeguards. - Start simple. A two-page policy that your team actually reads is better than a 30-page document that nobody follows. FAQ: Q: Do I legally need an AI use policy? A: There is no specific legal requirement for a standalone AI policy. However, the GDPR requires you to document processing activities, implement appropriate security measures, and ensure employees handle personal data responsibly. An AI use policy is the most practical way to meet these obligations when your team uses AI tools. Q: What AI tools should I include in the policy? A: Any tool that uses artificial intelligence or machine learning and that your employees might use for work - ChatGPT, Microsoft Copilot, Google Gemini, Midjourney, AI features in your CRM, AI-powered transcription tools, and similar services. Include both dedicated AI tools and AI features embedded in existing software. Q: How often should I update the AI policy? A: At minimum once a year. But also update it when you adopt new AI tools, when regulations change (such as the EU AI Act), or when an incident reveals a gap. The AI landscape moves fast, so a fixed yearly review may not be enough. Q: What if an employee accidentally enters personal data into ChatGPT? A: Treat it as a potential data breach. Document what happened, assess the risk to the data subjects, and follow your incident response procedure. Depending on the severity, you may need to notify your supervisory authority within 72 hours and inform the affected individuals. ## Your team is already using AI - the question is whether you know about it Here is the reality: your employees are using AI tools. They paste customer emails into ChatGPT to draft replies. They use Copilot to summarize meeting notes. They feed data into AI-powered tools to speed up their work. Most of them mean well - they want to be productive. The problem is not that they use AI. The problem is that without clear guidelines, they have no idea what is safe to enter and what is not. One wrong paste - a customer complaint with personal details, a CV, an internal document with financial data - and you have a GDPR issue on your hands. An AI acceptable use policy solves this. It tells your team what is allowed, what is not, and what to do when something goes wrong. It does not have to be a legal masterpiece. It has to be clear, practical, and enforceable. ## What the GDPR requires when your business uses AI tools Before diving into the policy structure, understand what the GDPR actually demands: - **Documentation.** Every AI tool that processes personal data must be recorded in your processing register. What data goes in? For what purpose? What is the legal basis? - **Processing agreements.** If an AI provider processes personal data on your behalf, you need a Data Processing Agreement (DPA). Most enterprise versions of ChatGPT, Copilot, and Claude offer these - free versions typically do not. - **Transparency.** If you use AI to process personal data of customers, employees, or other individuals, you must inform them. Your privacy policy should mention this. - **Data minimization.** Only enter the personal data that is strictly necessary. Better yet, anonymize data before entering it into any AI tool. - **Transfer safeguards.** Most AI providers process data on US servers. That is a transfer to a third country under the GDPR, which requires appropriate safeguards. Our companion article on [AI tools and privacy](/en/kennisbank/verplichtingen/ai-tools-privacy-gdpr) covers the legal background in more depth. This article focuses on the practical policy you need internally. ## The 10 sections your AI policy should cover ### 1. Scope - who does this apply to? Make it explicit: the policy applies to everyone who does work for your organisation. Employees, freelancers, interns, temporary workers, contractors. If they use AI tools for any work-related task, the policy applies to them. Be specific about what counts as an "AI tool" - not just ChatGPT, but also AI features in existing software like smart compose in email, AI summaries in your CRM, or AI-powered transcription services. ### 2. Approved vs. unapproved tools Maintain a clear list of approved AI tools. For each tool, document: - The tool name and provider - Which subscription tier is approved (enterprise vs. free matters for GDPR compliance) - Whether a DPA is in place - What the tool may be used for - Any restrictions on data input Any AI tool not on the approved list is off limits for work purposes. This is not about being restrictive - it is about knowing which tools handle your data and under what terms. Review this list quarterly. New AI tools appear constantly, and employees will ask to use them. ### 3. Prohibited data - what should NEVER go into AI tools This is the most critical section. Be very specific about what employees must never enter into any AI tool: - **Sensitive personal data (Article 9 GDPR):** racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, health data, sexual orientation - **Confidential business data:** financial statements, strategic plans, merger or acquisition details, investor communications - **NDA-protected materials:** anything covered by non-disclosure agreements with clients or partners - **Intellectual property:** proprietary code, trade secrets, unpublished patents, product designs - **HR records:** performance reviews, disciplinary files, salary details, workplace accident reports, dispute documentation Make it easy to remember: if the data is personal, confidential, or sensitive, it does not go into an AI tool. ### 4. Permitted use cases - what IS allowed Balance the restrictions with clear examples of what employees can do. This prevents the policy from feeling like a blanket ban: - Drafting generic text (marketing copy, blog outlines, email templates) that contains no personal data - Brainstorming ideas, structuring arguments, or getting writing feedback - Translating non-confidential, non-personal content - Summarizing publicly available information - Generating code snippets for non-sensitive internal tools - Creating presentation outlines based on public information The key principle: if the input contains no personal data and no confidential business information, most approved AI tools are fine to use. ### 5. Human review requirement All AI-generated content must be reviewed by a human before it is used, sent, or published. No exceptions. AI tools make mistakes. They produce incorrect information confidently. They can generate biased content. They sometimes reproduce copyrighted material. Your employees need to verify AI output for accuracy, bias, and appropriateness before it leaves their desk. This is especially critical for external communications, customer-facing content, and any decisions that affect individuals. ### 6. Automated decision-making rules When AI is used to make or support decisions about people - screening job applicants, evaluating employee performance, credit scoring, customer profiling - Article 22 of the GDPR applies. Your policy should state clearly: any use of AI for automated decision-making about individuals requires prior approval from management and, where necessary, your privacy coordinator or legal advisor. A Data Protection Impact Assessment (DPIA) may be required. Human intervention must always be guaranteed. ### 7. Governance and responsibility Specify who owns the policy: - **Management** is ultimately responsible for compliance - **A designated privacy coordinator** (or DPO if you have one) oversees implementation and handles questions - **Team leads** ensure their teams follow the policy in practice - **Every employee** is personally responsible for following the rules Also clarify the consequences: violations of the AI policy are treated like any other breach of company policy and may lead to disciplinary measures. ### 8. Training and awareness A policy nobody reads is useless. Include in your policy: - All new employees receive AI policy training during onboarding - Annual refresher training for all staff - Updates communicated whenever the policy or approved tools list changes - A clear contact point for questions ("not sure if you can use a tool? Ask your privacy coordinator before you start") Training does not have to be elaborate. A 30-minute session with practical examples and a Q&A is more effective than a two-hour lecture. ### 9. Incident handling What happens when someone accidentally enters personal data into an AI tool? Your policy needs a clear incident procedure: 1. Stop using the tool for that data immediately 2. Report the incident to the privacy coordinator (within 24 hours) 3. Document what data was entered, which tool was used, and when it happened 4. Assess the risk - can the data be deleted? Was training data enabled? What is the potential impact on the data subjects? 5. Follow your data breach procedure if needed (notification to the supervisory authority within 72 hours, notification to data subjects if high risk) Make reporting easy and blame-free. If employees are afraid of punishment, they will hide mistakes instead of reporting them - making the situation worse. ### 10. Review cycle The AI landscape changes fast. Your policy should be reviewed: - At minimum annually - Whenever a new AI tool is adopted - After any incident that reveals a gap - When relevant regulations change (such as the EU AI Act implementation) Assign a specific person or team responsible for the review and document the review date in the policy itself. ## Practical tips: getting started **Start simple.** A clear two-page document is better than a comprehensive 20-page policy nobody reads. You can expand later. **Involve your team.** Ask employees which AI tools they already use. You might be surprised. Building the policy together creates buy-in. **Use real examples.** "Do not enter sensitive data" is vague. "Do not paste a customer complaint email into ChatGPT" is concrete. **Make it accessible.** Publish the policy where employees can find it - your intranet, shared drive, or employee handbook. Not buried in a SharePoint folder nobody opens. **Iterate.** Your first version will not be perfect. Review it after three months, gather feedback, and adjust. ## How GDPRWise helps GDPRWise makes it easier to integrate AI tool usage into your broader GDPR compliance: - **Processing register:** Capture each AI tool as a processor, documenting what data it processes, the legal basis, and whether a DPA is in place - **Staff privacy policy:** Reference your AI acceptable use policy within the employee privacy documentation that GDPRWise helps you generate - **Website scan:** Detect AI-powered third-party services running on your website that you may not have documented yet Having an AI policy is one piece of the puzzle. Making sure it connects to your processing register, your privacy statements, and your overall GDPR file is what makes it work in practice. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### I Only Work B2B - Do I Still Need to Worry About GDPR? URL: https://gdprwise.eu/en/kennisbank/verplichtingen/b2b-gdpr-applies/ Summary: A common misconception: the GDPR doesn't apply to B2B companies. But even in B2B you process personal data of contact persons, employees, and suppliers. Read why the GDPR applies to you too. Key takeaways: - The GDPR protects natural persons, not companies, but behind every company are people - Contact persons at your clients and suppliers are data subjects under the GDPR - Employee data, payroll, and HR files fall fully under the GDPR - CRM systems with business contacts also contain personal data that you must protect FAQ: Q: Are business email addresses personal data? A: Yes. An email address like john.smith@company.com contains a name and is therefore personal data. Even generic addresses like info@company.com can be personal data if you know which individual is behind it. Q: Do I need a processing register if I only work B2B? A: Yes. You process personal data of contact persons, employees, and possibly suppliers. All those processing activities belong in your processing register, including the purpose, legal basis, and retention period. Q: Can I just put business contacts in my CRM? A: Yes, but you need a legal basis. Usually that is legitimate interest (you have a legitimate business interest in maintaining your relationships). You must document this and inform the contact persons via your privacy policy. Q: Does the GDPR also apply to sole traders and freelancers I work with? A: Yes. For sole traders and freelancers, the business data is often identical to the owner's personal data. Name, address, bank account - these are all personal data. ## Short answer: yes The short answer to the question in the title is unambiguous: yes. The GDPR applies to every company that processes personal data, regardless of whether your clients are consumers or businesses. And as a B2B company, you process more personal data than you think. ## The misconception The reasoning often goes like this: "The GDPR protects consumers. My clients are businesses, not consumers. So the GDPR doesn't apply to me." That reasoning is wrong on two counts. First: the GDPR doesn't protect consumers. The GDPR protects natural persons. That is an important distinction. A consumer is someone who buys something as a private individual. A natural person is any living human being. That includes the contact person at your client, the employee who receives your invoice, and the director who signs your proposal. Second: even if you never deal with consumers, as a B2B company you are guaranteed to process personal data. Let's look at where that data sits. ## Where is your personal data? ### Client contacts You have a CRM or at least an address book. It contains names, email addresses, phone numbers, and job titles of contact persons at your clients. john.smith@clientcompany.com is personal data. The purchasing manager's phone number is personal data. The note "John is always off on Mondays" is personal data. ### Employees If you have staff, you process a mountain of personal data: name, address, national ID number, salary, sick leave records, performance reviews, copy of identity document. These even include special or sensitive categories. The GDPR fully applies here. ### Suppliers and partners Your accountant, your IT supplier, your freelancers - you have contact details for all of them. And for sole traders and freelancers, the business data is often identical to the owner's personal data. ### Job applicants Do you occasionally receive an open application or CV? That is personal data. And it has a retention period: you cannot keep a CV indefinitely. ### Website visitors Even if your website targets only business visitors, you process IP addresses, cookie data, and possibly form data. IP addresses are personal data. ## What must you arrange as a B2B company? Exactly the same things as any other company. The GDPR makes no distinction between B2B and B2C. Specifically: **Processing register** - document all your processing activities. Maintaining client contacts, payroll, invoicing, marketing, website analytics - it all belongs in there. **Privacy policy** - inform data subjects about what you do with their data. That applies to your website visitors, but also to your business contacts. Many B2B companies have a privacy policy on their website but forget that their business contacts must also be informed. **Processing agreements** - do you have a processing agreement with your CRM provider? Your accountant? Your cloud provider? In B2B this is often taken more lightly than in B2C, but the obligation is identical. **Legal bases** - for every processing activity you need a legal basis. For client relationship management that is usually legitimate interest. For payroll a legal obligation. For a newsletter, consent. **Retention periods** - you cannot keep data indefinitely. That quote request from five years ago that never led to an assignment? There probably is no legal basis for that anymore. ## B2B-specific considerations A few matters deserve extra attention in a B2B context: - **LinkedIn and networking** - business cards collected at a trade fair or contacts added from LinkedIn to your CRM: that is processing of personal data - **References and testimonials** - if you publish client references on your website with name and job title, you are processing personal data - **Shared mailboxes** - a shared inbox like sales@yourcompany.com contains emails with personal data of business contacts - **Old data** - B2B companies often keep relationship data for years "just in case". Without a valid legal basis, that is not allowed ## The good news The basics of GDPR compliance for B2B companies are no different from B2C. In fact, it is often simpler. You probably process less data, fewer special categories, and have fewer data subjects. But "less" is not "none". And the supervisory authority makes no distinction. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Ignoring the Regulator Can Cost You Thousands URL: https://gdprwise.eu/en/kennisbank/verplichtingen/ignoring-regulator-costs/ Summary: Ignoring a request from the data protection authority is one of the most expensive mistakes a business owner can make. This article explains what happens when the regulator contacts you. Key takeaways: - Ignoring a request or complaint from the supervisory authority can multiply your fine - Most enforcement procedures start with a complaint from a data subject, not a random inspection - Cooperation and a constructive attitude work in your favour during assessment - If your basics are in order, you don't need to fear a request from the regulator FAQ: Q: What if the supervisory authority contacts me? A: Always respond, and as quickly as possible. Usually it concerns a question following a complaint. Demonstrate which measures you've taken and cooperate with the procedure. A cooperative attitude is taken into account in the assessment. Q: Can I receive a fine without warning? A: That is unusual. Most supervisory authorities start with a request for information or a warning. But if you don't respond or if the infringement is serious, a fine can be imposed directly. Q: How high are fines in practice for SMEs? A: Fines for SMEs range from a few thousand to tens of thousands of euros. The Belgian DPA has imposed fines from 2,000 to 50,000 euros on smaller organisations. The Dutch DPA applies comparable amounts. ## It usually starts with a complaint Most enforcement procedures don't start with a random inspection, but with a complaint. A customer who can't get their data deleted. A former employee who wants access to their personnel file. A website visitor who files a complaint about tracking without consent. The supervisory authority takes up the complaint and contacts you. ## What happens if you don't respond The worst thing you can do is not respond. The authority first sends a request for information. If you ignore it: 1. **Reminder** - you receive a second request, with a clear deadline 2. **Formal notice** - if silence continues, a formal notice follows 3. **Penalty or fine** - the authority can impose a periodic penalty (a daily increasing amount) or a direct fine The fine for non-cooperation is on top of any fine for the original infringement. You are only making the problem bigger. ## What the authority expects from you With a request for information, the authority typically asks for: - An explanation of the situation - Evidence of the measures you've taken - Your record of processing activities - Your privacy policy - Relevant data processing agreements If your GDPR file is in order, you can deliver this quickly. If you have nothing, it becomes a stressful and expensive exercise. ## Cooperation works in your favour Supervisory authorities take your attitude into account. A business that: - **Responds promptly** to the request - **Is transparent** about the situation - **Takes measures** to resolve the problem - **Can produce documentation** typically receives a milder assessment than one that ignores, denies, or obstructs. ## Prevention is cheaper than cure The cost of GDPR compliance is a fraction of the cost of a fine, legal assistance, and reputational damage. A GDPRWise subscription costs less than an hour of legal advice, and your file is in order. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Privacy Policy Example: What Must It Include? URL: https://gdprwise.eu/en/kennisbank/verplichtingen/privacy-policy-guide/ Summary: Looking for a privacy policy example? This article gives a concrete example of each mandatory element, with a structure you can follow, exactly as the GDPR requires. Key takeaways: - A privacy policy is mandatory for every organisation that processes personal data - Never copy a privacy policy from the internet - it must reflect your actual processing activities - The policy must be written in clear, understandable language, not legal jargon - GDPRWise generates your privacy policy automatically based on your actual processing activities FAQ: Q: Does every website need a privacy policy? A: Yes, if your website processes personal data (which is almost always the case - think of contact forms, analytics, cookies). The privacy policy must be easy to find, typically via a link in the footer. Q: Can I copy a privacy policy from another website? A: That is risky. If the policy does not match what your business actually does, it can work against you during an inspection. The supervisory authority will see a document that does not reflect reality. Q: How often should I update my privacy policy? A: After every significant change in your processing activities: a new tool, a new processor, a new purpose. Check at least annually whether your policy is still up to date. Q: Do I need a separate privacy policy for employees? A: Yes, an internal privacy policy for employees is separate from your website privacy policy. You must inform employees about how you process their personal data (payroll, HR files, CCTV, GPS tracking). ## Why is a privacy policy mandatory? The GDPR requires you to inform data subjects about how you process their personal data. The privacy policy is how you do that. It is not about creating a legal document nobody reads. It is about communicating clearly and honestly about: - What data you collect - Why you collect it - What you do with it - How long you keep it - What rights people have ## What must it contain? The GDPR (Articles 13 and 14) specifies exactly what information you must provide. Below you work through each mandatory element with a concrete example. A word of caution: copying a privacy policy example word for word is risky, because it must match your actual processing activities. Use the examples below as a structure, not as a ready-made document. ### 1. Who are you? The name and contact details of your organisation (the data controller). If you have a Data Protection Officer (DPO), include their contact details as well. ### 2. What data do you collect? Be specific. Not "personal information", but: - Name, email address, phone number (via contact form) - IP address, browser type, pages visited (via analytics) - Payment details (via the ordering process) - Employee data (via HR processes) ### 3. What do you use the data for? Per category of data, state the purpose. Examples: - "To respond to your enquiry via the contact form" - "To process and ship your order" - "To improve our website based on usage statistics" - "To send our newsletter (only with your consent)" ### 4. What is your legal basis? The GDPR provides six legal bases. The most commonly used for SMEs: - **Consent** (e.g. newsletter, marketing cookies) - **Performance of a contract** (e.g. processing an order) - **Legal obligation** (e.g. accounting retention requirements) - **Legitimate interest** (e.g. security, analytics) ### 5. Who do you share data with? All parties that have access to the data: - Your accountant - Your email marketing tool (Mailchimp, ActiveCampaign) - Your hosting provider - Google Analytics (if used) - Payment provider (Mollie, Stripe) State whether data is processed outside the EU. ### 6. How long do you keep the data? Per data type, the retention period: - Customer data: duration of the relationship + 2 years - Invoicing data: 7 years (legal retention obligation) - Contact form: 2 years after last contact - Analytics data: maximum 26 months ### 7. What rights do data subjects have? Refer to the rights under the GDPR: - Right of access - Right to rectification - Right to erasure - Right to restriction - Right to data portability - Right to object State how they can exercise these rights (email address, contact form) and that they can lodge a complaint with the supervisory authority. ### 8. Cookies If your website places cookies, describe which cookies, for what purpose, and how visitors can withdraw their consent. This can be included in the privacy policy itself or in a separate cookie policy. ## Common mistakes - **Copied from the internet** without adapting it to your situation - a generic policy that does not match your business is worse than no policy at all - **Legal jargon** that nobody understands - write in the language of your target audience - **Outdated** because you started using a new tool but did not update the policy - **Hard to find** on your website - place a link in the footer of every page - **No separate policy for employees** - your staff have the same right to information as your customers ## Checklist - Your policy states your company name and contact details - You describe specifically what data you collect and why - You state the legal basis per processing activity - You list all parties you share data with - You describe the retention periods - You inform data subjects about their rights - You state how data subjects can get in touch - You mention the right to lodge a complaint with the supervisory authority - The policy is written in clear, understandable language - The policy is easy to find on your website (link in footer) import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Privacy-Focused Google Analytics Alternatives: A Practical Guide for SMEs URL: https://gdprwise.eu/en/kennisbank/verplichtingen/privacy-analytics-alternatives/ Summary: Google Analytics has been ruled non-compliant with GDPR by multiple EU data protection authorities. This guide compares six privacy-friendly analytics alternatives that can run without cookies, eliminating consent popups and simplifying compliance. Key takeaways: - Multiple EU data protection authorities have ruled Google Analytics non-compliant with GDPR due to US data transfers - Cookie-free analytics tools eliminate the need for consent popups, improving both compliance and user experience - EU-hosted alternatives like Plausible, Matomo and Pirsch keep all visitor data within the European Economic Area FAQ: Q: Is Google Analytics illegal under GDPR? A: Not explicitly banned, but multiple DPAs (Austria, France, Italy, Denmark) have ruled its use non-compliant with GDPR due to data transfers to the US. Using it requires complex safeguards that most SMEs cannot realistically implement. Q: Can I use analytics without a cookie consent popup? A: Yes. Several analytics tools offer a cookie-free mode that collects visitor statistics without placing any cookies on the user's device. When no cookies are set, you do not need consent for analytics under the ePrivacy Directive. Q: Which privacy-friendly analytics tool is best for a small business? A: For most small businesses, Plausible or Pirsch offer the simplest setup - lightweight scripts, cookie-free by default, EU hosting included, and pricing starts around 9 euros per month. Q: Does GDPRWise detect which analytics tool my website uses? A: Yes. The GDPRWise scan automatically detects Google Analytics, Matomo, Plausible and other analytics scripts on your website, and flags potential GDPR issues such as US data transfers or missing consent mechanisms. ## Why Google Analytics is a GDPR problem Google Analytics is by far the most popular analytics tool on the web. But since 2020, it has become one of the most legally contested tools for European businesses. The core issue is simple: when you add Google Analytics to your website, your visitors' data is sent to Google's servers in the United States. Under GDPR, transferring personal data to the US requires specific legal safeguards. After the Schrems II ruling invalidated the Privacy Shield in 2020, those safeguards became extremely difficult to implement. Starting in 2022, data protection authorities across Europe began issuing formal decisions against Google Analytics: - **Austria (DSB)** - January 2022: ruled that a website's use of Google Analytics violated GDPR due to US data transfers - **France (CNIL)** - February 2022: issued formal notices to multiple websites using Google Analytics, finding it non-compliant - **Italy (Garante)** - June 2022: gave websites 90 days to stop using Google Analytics or find compliant alternatives - **Denmark (Datatilsynet)** - September 2022: concluded that Google Analytics cannot be used lawfully without additional measures most organizations cannot implement These are not fringe opinions. They represent a coordinated effort across EU regulators. The message is clear: standard use of Google Analytics puts your business at legal risk. Beyond the data transfer issue, Google Analytics also places cookies on your visitors' devices. Under the ePrivacy Directive, analytical cookies require prior consent. That means you need a cookie consent popup, and you cannot load Google Analytics until the visitor actively clicks "Accept." Visitors who decline give you zero analytics data. ## The cookie-free advantage This is where privacy-focused alternatives shine. Most modern privacy analytics tools can operate entirely without cookies. No cookies means: - **No consent popup needed** for analytics (the ePrivacy consent requirement applies to cookies specifically) - **Data from 100% of visitors**, not just the ones who click "Accept" - **Simpler compliance** - one fewer thing to manage in your cookie policy - **Better user experience** - visitors are not immediately confronted with a popup To be clear: you still need a cookie consent banner if other parts of your website set cookies (marketing pixels, chat widgets, etc.). But removing analytics from the consent equation simplifies things significantly. ## Six alternatives compared Here is a practical comparison of six privacy-focused analytics tools that work well for SMEs. ### Plausible Analytics Plausible is an open-source, lightweight analytics tool built in the EU (Estonia). It is cookie-free by default and has a script size under 1 KB, making it one of the fastest options. - **Cookie-free:** yes, by default - **EU hosting:** yes, servers in the EU (Hetzner, Germany) - **Self-hosting option:** yes, fully open source - **Key features:** real-time dashboard, UTM tracking, goal conversions, simple API - **Pricing:** from 9 EUR/month (cloud), free if self-hosted - **Best for:** businesses that want simplicity and speed ### Matomo Matomo (formerly Piwik) is the most feature-rich open-source alternative. It offers a cookie-free tracking mode and can be self-hosted for full data control. - **Cookie-free:** yes, configurable cookieless mode - **EU hosting:** yes (cloud version hosted in EU), or self-host anywhere - **Self-hosting option:** yes, fully open source - **Key features:** full visitor analytics, heatmaps, session recordings, A/B testing, tag manager - **Pricing:** free (self-hosted), cloud from 23 EUR/month - **Best for:** businesses that need detailed analytics comparable to Google Analytics ### Pirsch Analytics Pirsch is a German-made analytics tool that is privacy-first by design. It uses a unique server-side tracking approach that never loads any JavaScript on the visitor's device. - **Cookie-free:** yes, by default - **EU hosting:** yes, servers in Germany - **Self-hosting option:** no (cloud only), but open-source API client - **Key features:** server-side tracking, conversion goals, UTM parameters, real-time dashboard - **Pricing:** from 5 EUR/month - **Best for:** developers and businesses that prefer server-side tracking ### Piwik PRO Piwik PRO is the enterprise-grade sibling of Matomo, aimed at larger organizations. It offers a free plan for up to 500,000 actions per month, making it accessible for smaller sites too. - **Cookie-free:** yes, configurable - **EU hosting:** yes, data centers in EU (Germany, Netherlands) - **Self-hosting option:** private cloud only - **Key features:** analytics suite, tag manager, consent manager, customer data platform - **Pricing:** free up to 500K actions/month, paid plans on request - **Best for:** larger businesses or those needing an integrated consent manager ### Simple Analytics Simple Analytics is a Dutch company focused on truly minimal analytics. It collects no personal data at all, going beyond cookie-free to fundamentally privacy-safe design. - **Cookie-free:** yes, by default - **EU hosting:** yes, servers in the Netherlands - **Self-hosting option:** no - **Key features:** page views, referrers, device info, goals, events, tweet analytics - **Pricing:** from 9 EUR/month - **Best for:** businesses that want the absolute minimum data footprint ### Fathom Analytics Fathom is a Canadian-made tool with EU data isolation. It routes all EU visitor data through EU-based infrastructure, keeping data out of Canada/US entirely. - **Cookie-free:** yes, by default - **EU hosting:** yes, EU isolation mode available - **Self-hosting option:** no (the open-source "Lite" version is discontinued) - **Key features:** real-time dashboard, event tracking, uptime monitoring, email reports - **Pricing:** from 15 USD/month (approx. 14 EUR) - **Best for:** businesses already familiar with Fathom from the English-speaking market ## How GDPRWise detects your analytics setup When you run a GDPRWise scan on your website, we automatically detect which analytics tools are active. The scan identifies: - Google Analytics (both Universal Analytics and GA4) and flags the US data transfer risk - Cookie-based analytics tools and whether consent is obtained before they load - Privacy-friendly alternatives like Plausible, Matomo and Pirsch - Third-party scripts that may be collecting data without your knowledge If your site uses Google Analytics without proper safeguards, the scan report will flag this as a compliance risk and suggest alternatives. ## Which tool fits your business? Here is a quick decision guide: - **You want the simplest possible setup:** Plausible or Simple Analytics. Install one script tag and you are done. - **You need detailed analytics (comparable to GA):** Matomo. It is the closest feature-match to Google Analytics. - **You are a developer or prefer server-side tracking:** Pirsch. No client-side JavaScript at all. - **You are a larger organization needing enterprise features:** Piwik PRO. Integrated consent management and customer data platform. - **You have a small budget:** Piwik PRO (free tier up to 500K actions) or self-hosted Matomo (free). Whichever tool you choose, verify these three things before going live: 1. **Cookie-free mode is actually enabled.** Some tools require explicit configuration to disable cookies. 2. **Data stays in the EU.** Check that the hosting location is within the EEA. 3. **Your privacy policy mentions the tool.** Even cookie-free analytics must be disclosed in your privacy statement. Switching from Google Analytics to a privacy-friendly alternative is one of the highest-impact compliance improvements an SME can make. It removes a major legal risk, eliminates consent friction for your visitors, and in most cases takes less than 30 minutes to set up. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### The 6 GDPR Legal Bases: When Can You Process Personal Data? URL: https://gdprwise.eu/en/kennisbank/verplichtingen/gdpr-legal-bases/ Summary: The GDPR provides 6 legal bases for processing personal data. This article explains them practically for SMEs, with concrete examples and the most common mistake: asking consent for everything. Key takeaways: - Every processing of personal data requires a legal basis - without one, the processing is unlawful - For SMEs, four legal bases are most relevant: consent, contract, legal obligation, and legitimate interest - The most common mistake: asking consent for everything, when another basis would be more appropriate - Choose your legal basis in advance and document it in your processing register FAQ: Q: What are the 6 GDPR legal bases? A: The six legal bases are: consent, performance of a contract, legal obligation, vital interest, public interest or public authority, and legitimate interest. For most SMEs, the first four are most relevant. Q: Can I just ask consent for everything? A: You can, but it is often unwise. Consent can be withdrawn at any time, and then you must immediately stop processing. If another basis applies (such as contract or legal obligation), choose that one instead. Q: What is legitimate interest? A: Legitimate interest is a legal basis where your own interest outweighs the privacy interests of the data subject. Examples: website analytics, IT security, fraud prevention. You must conduct and document a balancing test. Q: Do I need to record my legal basis somewhere? A: Yes. Your processing register must state the legal basis per processing activity. Your privacy policy must also mention the basis per processing purpose. ## No legal basis, no processing The GDPR is crystal clear on this point: you may only process personal data if you have a valid legal basis. Article 6 of the GDPR gives you six options. None of the six apply? Then you simply cannot process the data. Sounds strict, but in practice it is manageable. Most SMEs deal with no more than three or four legal bases. Below we walk through all of them, with concrete examples so you can immediately determine which ones apply to your processing activities. ## The 6 legal bases at a glance ### 1. Consent **When:** someone gives you their voluntary, specific, and unambiguous consent. **Example:** a website visitor subscribes to your newsletter. You place marketing cookies only after someone clicks "accept." **Note:** consent must be truly free. A pre-ticked box does not count. The data subject can withdraw consent at any time, after which you must immediately stop that processing. This makes consent a fragile basis. ### 2. Performance of a contract **When:** the processing is necessary to perform a contract or to take steps at the data subject's request before entering into a contract. **Example:** a customer places an order in your webshop. You need their name, address, and payment details to process and deliver the order. That is permitted because it is necessary for performing the purchase agreement. **Note:** this only covers processing that is truly necessary for the contract. Shipping the order? Yes. Adding the customer's email to your marketing list? No, that falls outside the contract. ### 3. Legal obligation **When:** the law requires you to process or retain certain data. **Example:** your accounting records. Tax authorities require you to keep invoices for 7 years, including the customer details on them. Your payroll administration contains national identification numbers because the law requires it. **Note:** you can only rely on a concrete, specific legal obligation. "It seemed like a good idea" is not a legal obligation. ### 4. Vital interest **When:** the processing is necessary to protect someone's life. **Example:** a visitor at your premises suffers a heart attack and you share their medical information with the ambulance service. In practice, this basis is rarely relevant for most SMEs. You only encounter it in healthcare or emergency situations. ### 5. Public interest or public authority **When:** the processing is necessary for a task carried out in the public interest or in the exercise of official authority. **Example:** a municipality processing personal data for population registry purposes. As an SME, you will almost never need this basis. This is the domain of government bodies and public institutions. ### 6. Legitimate interest **When:** you have a legitimate interest that outweighs the privacy interests of the data subject. **Example:** you analyse visitor statistics on your website to understand which pages are popular. Or you install cameras at your premises for burglary prevention. Or you send an existing customer an email about a similar product (soft opt-in). **Note:** you must conduct a balancing test. Your interest must outweigh the impact on the data subject's privacy. Document this assessment, as the supervisory authority may ask for it. ## The four bases SMEs use most In practice, these are the legal bases SMEs use most frequently: | Processing | Legal basis | |-----------|-------------| | Sending a newsletter | Consent | | Placing marketing cookies | Consent | | Processing an order | Contract | | Preparing a quote | Contract | | Retaining invoices (7 years) | Legal obligation | | Payroll administration | Legal obligation | | Website analytics | Legitimate interest | | IT security/logging | Legitimate interest | ## The most common mistake: asking consent for everything Many SME owners think: "if I ask consent for everything, I'm covered." This is a misunderstanding that can get you into trouble. **Why?** Because consent can be withdrawn at any time. If a customer withdraws consent for a processing activity where you actually had a better basis (such as contract or legal obligation), you still have to stop - even though you could have lawfully continued. Example: you ask consent to put customer details on an invoice. The customer withdraws consent. Now you have a problem, because tax law requires you to keep those details. Had you chosen "legal obligation" as your basis from the start, there would be no issue. **The rule of thumb:** only use consent when no other basis is available. And when you do ask for consent, make sure withdrawing it is just as easy as giving it. ## How to document your legal bases 1. **Processing register** - record which legal basis you use per processing activity 2. **Privacy policy** - state the basis per processing purpose 3. **Balancing test** - for each processing based on legitimate interest, write a brief assessment Tip: choose your legal basis before you start processing, not afterwards. Retroactively finding a basis that fits what you are already doing is not how the GDPR works, and it is exactly what supervisory authorities check during inspections. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### What Is a Processing Agreement? URL: https://gdprwise.eu/en/kennisbank/verplichtingen/processing-agreement/ Summary: A processing agreement is mandatory when you have personal data processed by an external party. Learn what it must contain and download our free template. Key takeaways: - A processing agreement is mandatory as soon as you have personal data processed by a third party - The contract must cover at least 8 topics, including security measures and sub-processors - Without a processing agreement you risk a fine of up to 10 million euros or 2% of annual turnover FAQ: Q: When do I need a processing agreement? A: As soon as you have personal data processed by an external party, for example your accountant, email marketing tool or cloud storage service. Q: What is the difference between a controller and a processor? A: The controller determines the purpose and means of processing. The processor processes data solely on behalf of the controller. ## What is a processing agreement? A processing agreement (also known as a Data Processing Agreement or DPA) is a contract required under the GDPR when an organisation has personal data processed by another party. This contract governs the responsibilities and obligations of both parties. ## When do you need a processing agreement? You need a processing agreement when you share personal data with an external party that processes this data **on your behalf**. Examples include: - Your accountant who has access to employee data - An email marketing tool such as Mailchimp or ActiveCampaign - Your cloud storage service (Google Workspace, Microsoft 365) - An external payroll processor ## What must it contain? The GDPR (Article 28) requires a processing agreement to cover at least the following topics: 1. The subject and duration of the processing 2. The nature and purpose of the processing 3. The type of personal data and categories of data subjects 4. Security measures 5. Engagement of sub-processors 6. Assistance with data subject requests 7. Data breach notification obligations 8. Deletion or return of data upon termination ## What if you don't have a processing agreement? Without a processing agreement, you are in breach of the GDPR. The supervisory authority can impose fines of up to **10 million euros or 2% of your annual turnover**, whichever is higher. --- ### What Must Be in Your Cookie Policy? URL: https://gdprwise.eu/en/kennisbank/verplichtingen/cookie-policy-requirements/ Summary: A cookie policy is more than a paragraph of text. For every cookie you must list the name, provider, purpose, retention period and legal basis. This article explains exactly what belongs in it, why a template usually falls short, and how to keep it current. Key takeaways: - A cookie policy lists, per cookie: name, provider, purpose, retention period and legal basis - The information duty follows from the GDPR and the ePrivacy rules combined: consent is only valid if the visitor was properly informed beforehand - Most websites do not know which cookies they set; tag managers, chat widgets and embeds add cookies unnoticed - A cookie policy is never finished: every new tool on your website can introduce new cookies - A cookie banner and a cookie policy are two different things; you need both FAQ: Q: Is a cookie policy legally required? A: In practice, yes. The GDPR obliges you to inform visitors transparently about the processing of their personal data, and the ePrivacy rules require informed consent before you set non-essential cookies. Without clear cookie information, the consent your cookie banner collects is not valid. The Court of Justice of the EU confirmed in the Planet49 ruling that visitors must know, among other things, the retention period of cookies and any third-party recipients. Q: Can I include my cookie policy in my privacy policy? A: You can, as long as the information is complete and easy to find. In practice a separate cookie policy works better: it stays readable, your cookie banner can link to it directly, and you can update it independently from your privacy policy whenever your cookies change. Q: How often should I update my cookie policy? A: Every time the cookies on your website change. That happens more often than you think: a new plugin, a different chat widget, a YouTube video or a modified marketing tag can introduce new cookies. Run a cookie scan periodically at minimum, or use a tool that keeps scanning your website automatically and updates your policy along with it. Q: What happens if my cookie policy is wrong? A: A cookie policy that lists cookies you do not use, or worse, stays silent about cookies you do set, undermines the validity of the consent you collect. Regulators such as the French CNIL have repeatedly issued fines for cookie violations. Besides, any visitor with a browser extension can see within seconds that your policy does not match reality. Almost every website has one, but few business owners know what exactly belongs in it: the cookie policy. Often it is a generic three-paragraph text, copied from another website at some point. That does not cut it. A cookie policy must describe which cookies your website actually sets, and list a number of mandatory details for each cookie. ## Why you need a cookie policy The obligation comes from two directions at once. **The ePrivacy rules** (implemented in national legislation across the EU) require consent before you set non-essential cookies. That consent must be *informed*: a visitor can only validly agree to something that has been clearly explained. **The GDPR** adds a transparency duty on top for every processing of personal data. Many cookies collect identifiable data such as a unique visitor ID or IP address, so they fall under that duty. The Court of Justice of the EU made this concrete in the Planet49 ruling (2019): visitors must know, among other things, **how long cookies remain active** and **whether third parties have access to them**. Exactly the information that belongs in a cookie policy. ## What must be listed per cookie A proper cookie policy contains a table with, for every cookie your website sets: **Name.** The technical name of the cookie, such as `_ga` or `PHPSESSID`. This lets a visitor (or regulator) verify that your policy matches what the browser shows. **Provider.** Who sets the cookie? You (first-party) or an external service such as Google, Meta or HubSpot (third-party)? For third-party cookies, readers also expect a reference to that party's privacy policy. **Purpose.** What is the cookie for? "Marketing" alone is too vague; better is, for example, "measures advertising effectiveness by recognising visitors across websites". **Category.** Necessary, functional, analytics or marketing. This classification must match the choices in your cookie banner: a visitor who declines analytics cookies must not receive any. **Retention period.** How long does the cookie stay on the device? A session, 24 hours, 13 months, 2 years? This is the information the Court of Justice explicitly made mandatory. **Legal basis.** For necessary cookies this is usually legitimate interest; for all other categories it is consent. The policy should also cover: how visitors can withdraw or change their consent, whether data is transferred outside the EEA, and when the policy was last updated. ## The real problem: do you know which cookies you set? This is where most websites go wrong. Not because owners want to hide anything, but because modern websites set cookies the owner is unaware of. A few examples from practice: - **A tag manager** (such as Google Tag Manager) loads scripts that set cookies of their own. One marketing colleague adding a tag, and your cookie landscape has changed. - **A chat widget** such as Intercom or Tawk.to sets cookies to link conversations to visitors. - **A YouTube embed** can set Google tracking cookies, even if the visitor never plays the video. - **Social share buttons** and pixels from Meta or LinkedIn set cookies that follow visitors across websites. Writing a cookie policy based on what you *think* you use is therefore almost guaranteed to produce a policy that is wrong. And a wrong policy is not a detail: it means the consent you collect is not validly informed. The only reliable approach is measuring instead of guessing: scan your website the way a real visitor experiences it, and build your cookie table from what actually happens. You can use our [free cookie policy generator](/en/cookie-policy-generator/) for that, or do it manually with our [cookie audit template](/en/kennisbank/sjablonen/template-cookie-audit/). ## Cookie policy and cookie banner: two different things The terms are often mixed up, but each solves a different part of the puzzle: - **The cookie banner** asks for consent *before* non-essential cookies are set, and remembers the visitor's choice. - **The cookie policy** documents *which* cookies exist, with all mandatory details, so that the consent is informed. A banner without a proper policy collects consent that is legally shaky. A policy without a banner means you are setting cookies without consent. You need both, and they must reference each other: your banner should link straight to your cookie policy. ## A cookie policy is never finished Perhaps the most important insight: a cookie policy is not a document you write once. Every change to your website can alter the cookie landscape. The new booking module, the replaced analytics tool, the campaign pixel that was added "temporarily": all potential new cookies that belong in your policy. So schedule a periodic check, or better: automate it. GDPRWise rescans your website periodically and updates your cookie policy automatically when new cookies appear. That way what you publish keeps matching what your website does, months after launch too. import ArticleCTA from '@/components/ArticleCTA.astro'; --- ### Who Is My GDPR Authority at National Level? URL: https://gdprwise.eu/en/kennisbank/verplichtingen/national-dpa-authority/ Summary: Every EU country has its own supervisory authority for the GDPR. This article gives an overview of the main national authorities and explains when you deal with which one. Key takeaways: - Every EU country has its own independent supervisory authority that enforces the GDPR - Your main establishment determines which authority is your 'lead authority' - Data subjects can file a complaint with the authority in their own country - In the Benelux, the Autoriteit Persoonsgegevens (NL) and the GBA (BE) are the key authorities FAQ: Q: Which authority should I report a data breach to? A: To the supervisory authority in the country where your main establishment is located. For the Netherlands that is the Autoriteit Persoonsgegevens, for Belgium the GBA. You must report a notifiable data breach within 72 hours. Q: Can a customer in another EU country file a complaint about me? A: Yes. Data subjects may file a complaint with the authority in their own country, regardless of where your business is based. That authority then cooperates with the authority in your country. Q: Do I deal with multiple authorities if I operate in several countries? A: If you have establishments in multiple EU countries, you have a 'lead authority' based on your main establishment. That authority coordinates with the others. If you only operate from one country but have customers in other countries, your own national authority is the primary point of contact. ## Every member state has its own supervisory authority The GDPR is a European regulation, but enforcement happens at national level. Every EU country has an independent supervisory authority (Data Protection Authority, or DPA) responsible for overseeing compliance. ## The Benelux ### Netherlands - Autoriteit Persoonsgegevens (AP) - Website: autoriteitpersoonsgegevens.nl - Data breach reports: via the reporting portal on the website - Complaints: via the complaint form - The AP is active in enforcement and regularly imposes fines, including on SMEs ### Belgium - Gegevensbeschermingsautoriteit (GBA) - Website: gegevensbeschermingsautoriteit.be - Data breach reports: via the reporting form on the website - Complaints: via the disputes chamber - The GBA is known for a constructive but strict approach ### Luxembourg - Commission Nationale pour la Protection des Donnees (CNPD) - Website: cnpd.public.lu - Data breach reports: via the online reporting form ## Other key EU authorities ### Germany Germany has a unique structure with both a federal supervisor (BfDI) and supervisory authorities per state. The competent authority depends on where your business is located. ### France - CNIL The Commission Nationale de l'Informatique et des Libertes is one of the most active supervisory authorities in Europe and has imposed the highest fines. ### Ireland - Data Protection Commission (DPC) Relevant because many large tech companies (Google, Meta, Apple) have their European headquarters in Ireland. ## Which authority is relevant for you? The rule of thumb: the authority in the country where your main establishment is located is your primary point of contact. That is also the authority you report data breaches to. If you only operate in the Netherlands: the Autoriteit Persoonsgegevens. If you only operate in Belgium: the GBA. If you operate in multiple countries: the authority where your main establishment is located is your lead authority. ## Cooperation between authorities National supervisory authorities cooperate through the European Data Protection Board (EDPB). For cross-border cases, the lead authority coordinates with the other involved authorities. In practice, as a business owner you mainly deal with your own national authority. import ArticleCTA from '@/components/ArticleCTA.astro'; ---