How to Create a HACCP Plan
Learn how to create a HACCP plan step by step, from hazard analysis and CCPs to critical limits, monitoring, corrective actions, verification, and records.
Use this GDPR compliance checklist for French SMEs to review data processing, legal bases, CNIL requirements, cookies, security, breaches, DPIAs and more.
If you run a small or medium-sized business in France, GDPR (in French, RGPD) compliance is not optional and it does not depend on your company's size. Many SME owners assume that being small automatically puts them outside the scope of European data protection rules, but that assumption can be costly. Compliance also involves far more than publishing a privacy policy on your website. It requires knowing what personal data (données personnelles) you hold, why you hold it, how long you keep it, and how you protect it as the responsable de traitement, the data controller responsible for the processing.
This guide gives you a practical, checkbox-style checklist to assess where your business stands today, a quick-reference summary table, detailed explanations of each requirement, France-specific CNIL expectations, common mistakes SMEs make, and a clear path toward stronger compliance.
Quick definition: A GDPR compliance checklist for French SMEs is a structured list of actions used to verify whether a small or medium-sized business properly manages personal data, respects GDPR requirements, protects individuals' rights, and meets applicable CNIL obligations.
This checklist is built for:
French TPEs (very small businesses) and PMEs (SMEs)
Startups operating in or selling into France
E-commerce businesses with French customers
Professional services firms (accounting, legal, consulting)
Employers processing employee data
Businesses relying on cloud or SaaS providers
Marketing teams handling customer and prospect data
If any of these describe your business, GDPR applies to you, regardless of headcount.
A fast summary before the detailed breakdown below.
|
GDPR area |
What SMEs should check |
Priority |
|
Data inventory |
Know what personal data is collected and where |
High |
|
Legal basis |
Document the lawful basis for each processing activity |
High |
|
Processing register |
Maintain a record of processing activities where required |
High |
|
Privacy notices |
Keep notices transparent, complete and current |
High |
|
Data subject rights |
Have a working process for access, erasure and other requests |
High |
|
Retention |
Define and enforce retention periods |
Medium/High |
|
Security |
Protect data with appropriate technical and organizational measures |
High |
|
Breach response |
Have a documented incident and notification procedure |
Critical |
|
Processors (sous-traitants) |
Review Article 28 contracts with vendors |
High |
|
International transfers |
Confirm safeguards for data leaving the EU/EEA |
Medium/High |
|
Cookies and trackers |
Verify consent is valid under CNIL rules |
High |
|
DPIA (AIPD) |
Assess whether an impact assessment is required |
Medium/High |
|
Employee data |
Review HR, payroll and monitoring practices |
High |
|
Training |
Make sure staff understand their role in compliance |
Medium |
|
Responsibilities/DPO |
Assign ownership, appoint a DPO if required |
Medium/High |
Work through each item below. Tick what is already in place and flag what needs attention.
☐ 1. Identify all personal data your SME processes
☐ Customer data
☐ Employee data
☐ Prospect data
☐ Supplier information
☐ Website visitor data
☐ Email and marketing data
☐ Sensitive or special-category data (health, biometric, etc.)
☐ 2. Map your data processing activities
☐ What data is collected
☐ Why it is collected
☐ Where it comes from
☐ Who receives it
☐ Where it is stored
☐ How long it is retained
☐ 3. Determine a lawful basis for each processing activity
☐ Consent
☐ Contract
☐ Legal obligation
☐ Legitimate interest
☐ Vital interests
☐ Public task, where applicable
☐ 4. Maintain a record of processing activities (registre des activités de traitement)
☐ Confirm whether Article 30 documentation applies to your activities
☐ Keep the register current even if a partial exemption applies
☐ Treat the register as good governance practice, not just a legal minimum
☐ 5. Review your privacy notices
☐ Data collected
☐ Purpose
☐ Legal basis
☐ Retention period
☐ Recipients
☐ Individuals' rights (droits des personnes)
☐ Transfers outside the EU, where relevant
☐ Contact details and DPO information, where applicable
☐ 6. Check data subject rights procedures
☐ Right of access
☐ Right to rectification
☐ Right to erasure
☐ Right to restriction
☐ Right to data portability
☐ Right to object
☐ Rights relating to automated decision-making, where applicable
☐ 7. Establish a DSAR response process
☐ Who receives requests
☐ How identity is verified
☐ Who handles the request
☐ How the deadline is tracked
☐ How the response is documented
☐ 8. Review data retention periods
☐ Avoid keeping personal data indefinitely
☐ Define retention periods per data category
☐ Create deletion or archiving procedures
☐ Align retention with legal and business requirements
☐ 9. Secure personal data
☐ Access controls
☐ Password policies and multi-factor authentication
☐ Encryption, where appropriate
☐ Backups
☐ Device and cloud security
☐ Security monitoring
☐ 10. Prepare a personal data breach (violation de données personnelles) response procedure
☐ Incident identification process
☐ Internal escalation procedure
☐ Breach risk assessment process
☐ CNIL notification procedure, where required
☐ Data subject communication process, where required
☐ Incident documentation
☐ 11. Review contracts with data processors (sous-traitants)
☐ Cloud providers
☐ Payroll providers
☐ CRM providers
☐ Email marketing platforms
☐ IT providers and hosting companies
☐ SaaS vendors
☐ Confirm required Article 28 contractual provisions
☐ 12. Check international data transfers (transferts hors UE)
☐ Transfers outside France
☐ Transfers outside the EU/EEA
☐ International cloud providers
☐ Suppliers located outside the EU
☐ Applicable safeguards (adequacy decisions, standard contractual clauses)
☐ 13. Review website cookies and tracking technologies
☐ Analytics cookies
☐ Advertising cookies
☐ Marketing trackers
☐ Consent mechanisms and banners
☐ Consent withdrawal
☐ Third-party trackers
☐ 14. Determine whether a DPIA (AIPD) is required
☐ Large-scale monitoring
☐ Sensitive data processing
☐ Systematic profiling
☐ Other high-risk processing
☐ 15. Review employee data processing
☐ Recruitment
☐ Employee records
☐ Payroll
☐ HR software
☐ Attendance systems
☐ Video surveillance
☐ Employee monitoring
☐ Internal communications
☐ 16. Train employees on GDPR
☐ Personal data handling
☐ Phishing and social engineering awareness
☐ Secure passwords
☐ Data sharing practices
☐ Privacy incident and breach reporting
☐ 17. Review marketing and email practices
☐ Marketing consent
☐ Prospecting rules
☐ Unsubscribe mechanisms
☐ Email databases
☐ SMS marketing
☐ Lead-generation forms
☐ 18. Review your GDPR documentation
☐ Privacy policies
☐ Processing register
☐ Processor agreements
☐ DPIAs
☐ Data breach records
☐ Retention policies
☐ Consent records
☐ 19. Assign GDPR responsibilities
☐ Privacy compliance owner
☐ Data security owner
☐ DSAR handler
☐ Breach management lead
☐ Vendor review owner
☐ Assess whether appointing a DPO is mandatory or advisable
☐ 20. Review and update GDPR compliance regularly
☐ Treat compliance as an ongoing process, not a one-time project
In practical terms, GDPR compliance (conformité RGPD) means being able to demonstrate accountability. That includes processing data lawfully, being transparent with individuals about what you do with their data, collecting only what you need, keeping it accurate, not holding onto it longer than necessary, and securing it properly. The regulation expects businesses to be able to prove compliance, not just claim it.
Yes. GDPR applies based on the fact that personal data is being processed and on territorial scope, not on the number of employees a company has. A five-person consultancy that keeps a client email list is just as subject to GDPR as a two-hundred-person manufacturer.
Not generally, and this is worth being precise about. There is a narrow exception under Article 30 that reduces the formal record-keeping obligation for organizations with fewer than 250 employees, but only under specific conditions, such as when processing is occasional, does not involve special categories of data, and is unlikely to result in a risk to individuals. This is not a blanket exemption from GDPR itself. The best practical approach is to maintain a record of processing activities where the exemption clearly does not apply, and to consider maintaining one anyway as good governance practice even where it might technically apply, since a processing register is often one of the first things reviewed if the CNIL opens an inquiry. The CNIL and Bpifrance make this point directly in their joint guidance for small businesses, noting there are no general exceptions to GDPR obligations for French SMEs simply because of their size.
The CNIL, France's national data protection authority, plays a central role in how GDPR is applied and enforced in the country. The CNIL and Bpifrance jointly published a practical GDPR awareness guide in April 2018 aimed specifically at helping small and medium businesses understand their obligations, and the CNIL has continued to expand its resources for TPE and PME since then, including a dedicated checklist for small businesses.
For French SMEs, CNIL expectations generally track the GDPR itself, with additional local emphasis on cookie and tracker rules, security guidance, breach notification, and how these apply practically to smaller organizations. The European Data Protection Board has also published a guide for very small and small businesses available in eighteen languages, including French and English, that explains GDPR principles through concrete examples. You can review it on the CNIL's page introducing the EDPB guide.
GDPR is the European Union regulation that sets the legal framework for data protection across all member states. The CNIL is France's supervisory authority (autorité de contrôle) responsible for overseeing GDPR compliance within the country, publishing guidance, and enforcing the rules through investigations and sanctions when necessary. For the full legal text of the regulation, consult the official version on EUR-Lex.
A website is often the first place personal data collection happens, so it deserves its own mini checklist.
Website GDPR checklist:
☐ Privacy policy is available and current
☐ Cookie consent mechanism is properly configured
☐ Users can withdraw consent as easily as they gave it
☐ Contact and newsletter forms explain how data will be used
☐ Analytics and third-party services are reviewed for data sharing
☐ Tracking pixels and embedded content are accounted for
☐ Data collection is minimized to what is actually needed
☐ The website connection is secure
☐ Retention periods are defined for form submissions
GDPR checklist for e-commerce SMEs:
☐ Customer accounts and order information
☐ Payment-related data handling
☐ Delivery information
☐ Marketing consent for promotional emails
☐ Abandoned-cart marketing practices
☐ Customer service records
☐ Reviews and loyalty program data
On cookies specifically, French rules are more detailed than many businesses expect, and this is one of the areas where CNIL guidance goes beyond a generic reading of GDPR. The CNIL requires that visitors be informed and give consent before cookies or other trackers are placed or read on their device, unless the tracker falls under a recognized exemption. Consent must involve a clear positive action, since simply continuing to browse the site can no longer be interpreted as consent. The CNIL has also stated that interfaces used to collect cookie choices should avoid misleading design practices, such as faded buttons or hard-to-understand scroll bars. Full guidance is available on the CNIL's cookies and trackers compliance page.
Employee data deserves the same rigor as customer data, and it is often overlooked. Review your practices around recruitment and CVs, employee records, payroll, HR software, attendance systems, video surveillance, employee monitoring, internal communications, privacy notices for staff, retention of records, and how former employee data is handled after departure.
SME example: A ten-person marketing agency uses an external payroll platform, a time-tracking app, and keeps CVs from past recruitment rounds. Each of these needs a defined retention period, a documented legal basis, and a check on whether the vendor qualifies as a sous-traitant under Article 28.
This area is particularly relevant for businesses searching for guidance on RGPD RH or RGPD salariés.
When something goes wrong, speed and documentation matter.
72-hour rule: Where notification to the CNIL is required, the controller must notify without undue delay and, wherever feasible, no later than 72 hours after becoming aware of the breach.
Emergency checklist when a breach occurs:
☐ Identify the incident.
☐ Contain the breach.
☐ Assess the risk to the individuals affected.
☐ Document the incident internally, regardless of severity.
☐ Determine whether CNIL notification is required.
☐ Notify the CNIL within 72 hours where required.
☐ Inform affected individuals where the risk is high.
☐ Implement corrective measures to prevent recurrence.
Under Article 33 of the GDPR, the notification to the CNIL must be transmitted as soon as possible after a breach presenting a risk to individuals' rights and freedoms is discovered. If you cannot gather every required detail immediately, you can notify in two stages: an initial notification within 72 hours where possible, followed by additional details once the investigation is complete. Not every incident requires notification. If the breach does not create a risk for the rights and freedoms of the people affected, the controller only needs to document it internally in a register, without notifying the CNIL or the individuals concerned. Full procedure available on the CNIL's breach notification page.
Most SMEs rely heavily on external software and service providers, and each one is a potential compliance gap if left unchecked. Using the right GDPR compliance software for French SMEs can also help businesses organize compliance tasks, monitor documentation, and manage privacy requirements more consistently.
SME example: A French accounting firm might process employee payroll data through an external HR platform, store client documents in a cloud service, and use a CRM for prospect management. Each provider should be assessed for its role, contractual obligations, security measures, and any international data transfers involved.
Vendor review checklist:
☐ Data processing agreement in place
☐ Processor and subprocessor roles reviewed
☐ Hosting location confirmed
☐ International transfers assessed
☐ Security measures verified
☐ Data deletion and retention settings checked
☐ Access controls reviewed
☐ Article 28 contractual obligations confirmed, not assumed
Treating GDPR as a one-time project instead of an ongoing responsibility.
Having a privacy policy but no internal procedures to back it up.
Collecting more data than is actually necessary.
Keeping personal data indefinitely rather than defining retention periods.
Ignoring employee data as if only customer data matters.
Assuming that being a small company is automatically an exemption.
Using cookies without proper, verifiable consent.
Failing to review SaaS providers and their subprocessors.
Not preparing for data breaches before one actually happens.
Failing to train employees on basic data protection practices.
A structured audit does not need to be complicated. A simple five-step framework works well for most SMEs.
Step 1: Identify processing activities. List every place personal data enters, moves through, and exits your business.
Step 2: Assess legal and regulatory compliance. Check each activity against GDPR requirements and CNIL guidance.
Step 3: Identify privacy and security gaps. Be honest about where documentation, consent, or security controls are missing.
Step 4: Prioritize remediation. Fix the highest-risk gaps first, particularly anything involving sensitive data or weak security.
Step 5: Monitor and review. Build compliance checks into your regular business rhythm rather than treating them as a one-off exercise.
A simple status system helps track progress:
|
Status |
Meaning |
|
Green |
Requirement implemented and documented |
|
Amber |
Partially implemented or requires improvement |
|
Red |
Missing or high-priority compliance gap |
If your audit surfaces more Amber and Red items than you expected, that is normal, and it is exactly the point where structured training or outside support tends to make the biggest difference. The Diploma in GDPR Compliance and Data Protection is built to help SME teams turn an audit like this into a working compliance program.
There is no single universal interval that applies to every GDPR activity. Instead, review your compliance after major business changes, when introducing new technologies, when launching new processing activities, after security incidents, when changing suppliers, when entering new markets, when regulatory guidance changes, and periodically as part of normal governance.
Non-compliance can lead to regulatory investigation, orders to correct specific practices, restrictions on processing, administrative fines, reputational damage, loss of customer trust, and operational disruption. That said, it is worth keeping perspective. GDPR compliance is primarily about risk management, accountability, and protecting the personal data your business is trusted with, not about triggering fear over every small gap.
Master GDPR Compliance & Data Protection.
Build a strong understanding of GDPR, French data protection requirements, CNIL expectations, privacy governance, DPO responsibilities, DPIAs, data breaches, vendor management, and international data transfers. Earn a certificate of completion at no additional cost. Develop the knowledge to support effective privacy compliance, strengthen data protection practices, and manage GDPR responsibilities with confidence.
Enrol Now →A compact, printable summary of everything above.
☐ Personal data identified
☐ Processing activities mapped
☐ Legal bases documented
☐ Processing register reviewed
☐ Privacy notices updated
☐ Data subject rights procedure established
☐ Retention periods defined
☐ Security controls reviewed
☐ Breach procedure established (72-hour rule understood)
☐ Processor contracts reviewed
☐ International transfers assessed
☐ Cookies and trackers reviewed
☐ DPIA requirements assessed
☐ Employee data reviewed
☐ Employees trained
☐ Marketing practices reviewed
☐ GDPR documentation maintained
☐ Responsibilities assigned
☐ Compliance reviewed regularly
Want a printable version? Download the GDPR Compliance Checklist for French SMEs and keep it on hand for internal audits and CNIL readiness reviews.
Working through a checklist is a strong start, but building lasting compliance usually comes down to how well your team understands GDPR principles day to day. Structured training helps staff understand data protection requirements, learn core privacy principles, grasp organizational responsibilities, and build stronger governance habits over time.
The Diploma in GDPR Compliance and Data Protection is designed to help SME teams build practical, working knowledge of GDPR rather than just theoretical awareness.