Since GDPR (EU Regulation 2016/679) took effect in May 2018, two generations of updates have arrived, and for 2026 new EDPB guidelines on AI systems, cloud storage outside the EU, and telemetry retention come into effect. Fines for SMBs for GDPR violations grew in SK in 2023-2025 by 320%. Here is a practical 20-point checklist that, in 2026, every company can manage without an external DPO.

Why GDPR compliance pays off even for a 15-person company

Arguments like “GDPR does not apply to us, we are a small company” no longer hold in 2026. The Office for Personal Data Protection of the SR (UOOU) confirmed in its 2024 annual report that 62% of fines went to companies with up to 50 employees. The average fine was 8,200 EUR. The highest in SK: 94,000 EUR (e-shop, mishandled data subject requests).

In addition to fines, there is one more risk: B2B contracts. Large companies today require a DPA (Data Processing Agreement) and security audits from all suppliers. If you do not have compliance, you lose tenders.

Tip: GDPR is not a one-time project. It is a continuous process. Run through the checklist once a year, ideally in Q1 after the tax close, when you are reviewing processes anyway.

20-point GDPR checklist for an SK SMB (2026)

Basics and documentation (1-5)

1. Do you maintain an up-to-date record of processing activities (Art. 30 GDPR)? An Excel table with the list: type of data, purpose, legal basis, retention period, recipients. An obligation for every company over 250 people, and in practice also for smaller ones that process sensitive data.

2. Do you have correctly informed consent in every contract or another legal basis under Art. 6 GDPR? Marketing newsletters, opt-in consent. Invoices, legitimate interest + statutory obligation.

3. Do you have up-to-date Personal Data Processing Information (privacy notice) on the website and at receptions? At least 13 points under Art. 13 GDPR. Concrete, not “we process your data according to law.”

4. Do you have signed DPAs with all processors (cloud providers, accountant, HR agency, IT supplier)? GDPR Art. 28, a written agreement is mandatory. For 2026, check that the DPA also covers AI sub-processors (ChatGPT, Claude, etc.).

5. Do you have a designated responsible person (DPO or internal contact)? A DPO is mandatory for large-scale processing of sensitive data (healthcare, biometrics, judiciary). For SMBs, an internal contact is usually enough, but it must be defined and publicly available.

Technical measures (6-12)

6. Is your data hosted in the EU? Servers outside the EU = a Schrems II problem. After the burning of the US-EU Data Privacy Framework in 2023, the safe bet for SMBs is hosting exclusively in the EU (ideally DE, FR, PL). Verify where your ERP, CRM, and email run. More about our approach on the security page.

7. Do you have 2FA enabled for all administrative accounts? The “admin123” password is not enough in 2026. A de-facto obligation if you have access to personal data of more than 1,000 individuals.

8. Do you have regular backups and a verified recovery plan? Recovery test at least 2x a year. Ransomware attacks on SK SMBs grew by 180% in 2024.

9. Do you encrypt personal data at rest and in transit? HTTPS everywhere. AES-256 or equivalent for databases. For sensitive categories (health, financial), a bonus at audit.

10. Do you have an audit log that records access to personal data? “Who, when, which record viewed/changed.” Without it you will not pass a serious B2B audit or breach response. Modulario provides this audit log natively, more info on the security page.

11. Do you have retention policies and automatic deletion after the period expires? Act 18/2018 Coll. + Tax Act 595/2003 Coll.: invoices 10 years, personnel data 50 years (pension), marketing consents until withdrawal or 24 months.

12. Do you have pseudonymization or anonymization where possible? E.g., website analytics without IP addresses, internal dashboard with hashed employee IDs.

Processes (13-17)

13. Do you have a defined process for responding to data subject requests (access, correction, deletion)? Deadline: 1 month, extension to 3 in complex cases. Who in the company receives the email, who verifies identity, who carries out deletion?

14. Do you have a security incident response plan (data breach)? 72 hours to report to UOOU. In practice you have <24h before the incident spreads. Template + responsible person + communication plan.

15. Do you have a trained team? At least annual training for everyone who handles personal data. A 2-hour e-learning is enough for the basics.

16. Do you vet new suppliers (vendor due diligence)? Question for SaaS: Where do they host? Do they have ISO 27001 / SOC 2? What sub-processor structure do they have? Do they have a DPA prepared?

17. Do you have a DPIA (Data Protection Impact Assessment) for risky processing? Mandatory for systematic monitoring, large-scale processing of sensitive categories, automated decision-making. In 2026 also for some AI use cases (see AI Act).

2026 specifics (18-20)

18. Do you map AI systems and models that process personal data? New EDPB 2025 guidelines: if an AI model processes personal data (chatbot, HR assist, AI scoring), you must have a DPIA + transparency.

19. Do you have clear rules for the use of generative AI (ChatGPT, Claude, Copilot)? Employees routinely paste customer data into public AI tools. Policy + whitelist + enterprise accounts solve the problem.

20. Do you have a process for a GDPR audit (internal or external)? Run through the checklist annually, an external audit every 2 years. The protocol is useful in tenders.

Most common fines in SK in 2023-2025

ViolationAverage fineFrequency
Missing/incorrect marketing consent3,200 EURHighest
No response to data subject request5,800 EURHigh
Missing DPA with processor4,500 EURHigh
Data breach without notification12,000 EURMedium
Inadequate technical measures8,400 EURMedium

Tip: The cheapest and most effective investment in GDPR in 2026 is to have an ERP/CRM system with native audit log, EU hosting, and a signed DPA. This automatically covers 10 of the 20 points in this checklist.

Conclusion

GDPR compliance is not a bogeyman, it is a discipline. The average SK SMB will work through the 20-point checklist in 2-4 days of work. Fines start in the thousands of EUR and the regulator in 2026 is more active than ever. Add the pressure from B2B clients for DPAs and security certifications and you have the complete business case.

Need an ERP/CRM system that handles GDPR natively, EU hosting, audit log, automatic retention policies? See the details of our security measures or contact us via a free consultation. We will prepare a GDPR-ready environment for you within 2 weeks.