GDPR Compliance Checklist for French SMEs

Use this GDPR compliance checklist for French SMEs to review data processing, legal bases, CNIL requirements, cookies, security, breaches, DPIAs and more.

GDPR compliance checklist for French SMEs featuring a checklist, lock, and data privacy documents.

If you run a small or medium-sized business in France, GDPR (in French, RGPD) compliance is not optional and it does not depend on your company's size. Many SME owners assume that being small automatically puts them outside the scope of European data protection rules, but that assumption can be costly. Compliance also involves far more than publishing a privacy policy on your website. It requires knowing what personal data (données personnelles) you hold, why you hold it, how long you keep it, and how you protect it as the responsable de traitement, the data controller responsible for the processing.

This guide gives you a practical, checkbox-style checklist to assess where your business stands today, a quick-reference summary table, detailed explanations of each requirement, France-specific CNIL expectations, common mistakes SMEs make, and a clear path toward stronger compliance.

Quick definition: A GDPR compliance checklist for French SMEs is a structured list of actions used to verify whether a small or medium-sized business properly manages personal data, respects GDPR requirements, protects individuals' rights, and meets applicable CNIL obligations.

Who Is This Checklist For?

This checklist is built for:

  • French TPEs (very small businesses) and PMEs (SMEs)

  • Startups operating in or selling into France

  • E-commerce businesses with French customers

  • Professional services firms (accounting, legal, consulting)

  • Employers processing employee data

  • Businesses relying on cloud or SaaS providers

  • Marketing teams handling customer and prospect data

If any of these describe your business, GDPR applies to you, regardless of headcount.

GDPR Checklist at a Glance

A fast summary before the detailed breakdown below.

GDPR area

What SMEs should check

Priority

Data inventory

Know what personal data is collected and where

High

Legal basis

Document the lawful basis for each processing activity

High

Processing register

Maintain a record of processing activities where required

High

Privacy notices

Keep notices transparent, complete and current

High

Data subject rights

Have a working process for access, erasure and other requests

High

Retention

Define and enforce retention periods

Medium/High

Security

Protect data with appropriate technical and organizational measures

High

Breach response

Have a documented incident and notification procedure

Critical

Processors (sous-traitants)

Review Article 28 contracts with vendors

High

International transfers

Confirm safeguards for data leaving the EU/EEA

Medium/High

Cookies and trackers

Verify consent is valid under CNIL rules

High

DPIA (AIPD)

Assess whether an impact assessment is required

Medium/High

Employee data

Review HR, payroll and monitoring practices

High

Training

Make sure staff understand their role in compliance

Medium

Responsibilities/DPO

Assign ownership, appoint a DPO if required

Medium/High

The Full GDPR Compliance Checklist for French SMEs

Work through each item below. Tick what is already in place and flag what needs attention.

☐ 1. Identify all personal data your SME processes

  • ☐ Customer data

  • ☐ Employee data

  • ☐ Prospect data

  • ☐ Supplier information

  • ☐ Website visitor data

  • ☐ Email and marketing data

  • ☐ Sensitive or special-category data (health, biometric, etc.)

☐ 2. Map your data processing activities

  • ☐ What data is collected

  • ☐ Why it is collected

  • ☐ Where it comes from

  • ☐ Who receives it

  • ☐ Where it is stored

  • ☐ How long it is retained

☐ 3. Determine a lawful basis for each processing activity

  • ☐ Consent

  • ☐ Contract

  • ☐ Legal obligation

  • ☐ Legitimate interest

  • ☐ Vital interests

  • ☐ Public task, where applicable

☐ 4. Maintain a record of processing activities (registre des activités de traitement)

  • ☐ Confirm whether Article 30 documentation applies to your activities

  • ☐ Keep the register current even if a partial exemption applies

  • ☐ Treat the register as good governance practice, not just a legal minimum

☐ 5. Review your privacy notices

  • ☐ Data collected

  • ☐ Purpose

  • ☐ Legal basis

  • ☐ Retention period

  • ☐ Recipients

  • ☐ Individuals' rights (droits des personnes)

  • ☐ Transfers outside the EU, where relevant

  • ☐ Contact details and DPO information, where applicable

☐ 6. Check data subject rights procedures

  • ☐ Right of access

  • ☐ Right to rectification

  • ☐ Right to erasure

  • ☐ Right to restriction

  • ☐ Right to data portability

  • ☐ Right to object

  • ☐ Rights relating to automated decision-making, where applicable

☐ 7. Establish a DSAR response process

  • ☐ Who receives requests

  • ☐ How identity is verified

  • ☐ Who handles the request

  • ☐ How the deadline is tracked

  • ☐ How the response is documented

☐ 8. Review data retention periods

  • ☐ Avoid keeping personal data indefinitely

  • ☐ Define retention periods per data category

  • ☐ Create deletion or archiving procedures

  • ☐ Align retention with legal and business requirements

☐ 9. Secure personal data

  • ☐ Access controls

  • ☐ Password policies and multi-factor authentication

  • ☐ Encryption, where appropriate

  • ☐ Backups

  • ☐ Device and cloud security

  • ☐ Security monitoring

☐ 10. Prepare a personal data breach (violation de données personnelles) response procedure

  • ☐ Incident identification process

  • ☐ Internal escalation procedure

  • ☐ Breach risk assessment process

  • ☐ CNIL notification procedure, where required

  • ☐ Data subject communication process, where required

  • ☐ Incident documentation

☐ 11. Review contracts with data processors (sous-traitants)

  • ☐ Cloud providers

  • ☐ Payroll providers

  • ☐ CRM providers

  • ☐ Email marketing platforms

  • ☐ IT providers and hosting companies

  • ☐ SaaS vendors

  • ☐ Confirm required Article 28 contractual provisions

☐ 12. Check international data transfers (transferts hors UE)

  • ☐ Transfers outside France

  • ☐ Transfers outside the EU/EEA

  • ☐ International cloud providers

  • ☐ Suppliers located outside the EU

  • ☐ Applicable safeguards (adequacy decisions, standard contractual clauses)

☐ 13. Review website cookies and tracking technologies

  • ☐ Analytics cookies

  • ☐ Advertising cookies

  • ☐ Marketing trackers

  • ☐ Consent mechanisms and banners

  • ☐ Consent withdrawal

  • ☐ Third-party trackers

☐ 14. Determine whether a DPIA (AIPD) is required

  • ☐ Large-scale monitoring

  • ☐ Sensitive data processing

  • ☐ Systematic profiling

  • ☐ Other high-risk processing

☐ 15. Review employee data processing

  • ☐ Recruitment

  • ☐ Employee records

  • ☐ Payroll

  • ☐ HR software

  • ☐ Attendance systems

  • ☐ Video surveillance

  • ☐ Employee monitoring

  • ☐ Internal communications

☐ 16. Train employees on GDPR

  • ☐ Personal data handling

  • ☐ Phishing and social engineering awareness

  • ☐ Secure passwords

  • ☐ Data sharing practices

  • ☐ Privacy incident and breach reporting

☐ 17. Review marketing and email practices

  • ☐ Marketing consent

  • ☐ Prospecting rules

  • ☐ Unsubscribe mechanisms

  • ☐ Email databases

  • ☐ SMS marketing

  • ☐ Lead-generation forms

☐ 18. Review your GDPR documentation

  • ☐ Privacy policies

  • ☐ Processing register

  • ☐ Processor agreements

  • ☐ DPIAs

  • ☐ Data breach records

  • ☐ Retention policies

  • ☐ Consent records

☐ 19. Assign GDPR responsibilities

  • ☐ Privacy compliance owner

  • ☐ Data security owner

  • ☐ DSAR handler

  • ☐ Breach management lead

  • ☐ Vendor review owner

  • ☐ Assess whether appointing a DPO is mandatory or advisable

☐ 20. Review and update GDPR compliance regularly

  • ☐ Treat compliance as an ongoing process, not a one-time project

What Does GDPR Compliance Mean for a French SME?

In practical terms, GDPR compliance (conformité RGPD) means being able to demonstrate accountability. That includes processing data lawfully, being transparent with individuals about what you do with their data, collecting only what you need, keeping it accurate, not holding onto it longer than necessary, and securing it properly. The regulation expects businesses to be able to prove compliance, not just claim it.

Does Every French SME Have to Comply With GDPR?

Yes. GDPR applies based on the fact that personal data is being processed and on territorial scope, not on the number of employees a company has. A five-person consultancy that keeps a client email list is just as subject to GDPR as a two-hundred-person manufacturer.

Are Small Businesses Exempt From GDPR?

Not generally, and this is worth being precise about. There is a narrow exception under Article 30 that reduces the formal record-keeping obligation for organizations with fewer than 250 employees, but only under specific conditions, such as when processing is occasional, does not involve special categories of data, and is unlikely to result in a risk to individuals. This is not a blanket exemption from GDPR itself. The best practical approach is to maintain a record of processing activities where the exemption clearly does not apply, and to consider maintaining one anyway as good governance practice even where it might technically apply, since a processing register is often one of the first things reviewed if the CNIL opens an inquiry. The CNIL and Bpifrance make this point directly in their joint guidance for small businesses, noting there are no general exceptions to GDPR obligations for French SMEs simply because of their size.

What Does CNIL Expect From French SMEs?

The CNIL, France's national data protection authority, plays a central role in how GDPR is applied and enforced in the country. The CNIL and Bpifrance jointly published a practical GDPR awareness guide in April 2018 aimed specifically at helping small and medium businesses understand their obligations, and the CNIL has continued to expand its resources for TPE and PME since then, including a dedicated checklist for small businesses.

For French SMEs, CNIL expectations generally track the GDPR itself, with additional local emphasis on cookie and tracker rules, security guidance, breach notification, and how these apply practically to smaller organizations. The European Data Protection Board has also published a guide for very small and small businesses available in eighteen languages, including French and English, that explains GDPR principles through concrete examples. You can review it on the CNIL's page introducing the EDPB guide.

GDPR vs CNIL: What Is the Difference?

GDPR is the European Union regulation that sets the legal framework for data protection across all member states. The CNIL is France's supervisory authority (autorité de contrôle) responsible for overseeing GDPR compliance within the country, publishing guidance, and enforcing the rules through investigations and sanctions when necessary. For the full legal text of the regulation, consult the official version on EUR-Lex.

GDPR Compliance Checklist for French SME Websites

A website is often the first place personal data collection happens, so it deserves its own mini checklist.

Website GDPR checklist:

  • ☐ Privacy policy is available and current

  • ☐ Cookie consent mechanism is properly configured

  • ☐ Users can withdraw consent as easily as they gave it

  • ☐ Contact and newsletter forms explain how data will be used

  • ☐ Analytics and third-party services are reviewed for data sharing

  • ☐ Tracking pixels and embedded content are accounted for

  • ☐ Data collection is minimized to what is actually needed

  • ☐ The website connection is secure

  • ☐ Retention periods are defined for form submissions

GDPR checklist for e-commerce SMEs:

  • ☐ Customer accounts and order information

  • ☐ Payment-related data handling

  • ☐ Delivery information

  • ☐ Marketing consent for promotional emails

  • ☐ Abandoned-cart marketing practices

  • ☐ Customer service records

  • ☐ Reviews and loyalty program data

On cookies specifically, French rules are more detailed than many businesses expect, and this is one of the areas where CNIL guidance goes beyond a generic reading of GDPR. The CNIL requires that visitors be informed and give consent before cookies or other trackers are placed or read on their device, unless the tracker falls under a recognized exemption. Consent must involve a clear positive action, since simply continuing to browse the site can no longer be interpreted as consent. The CNIL has also stated that interfaces used to collect cookie choices should avoid misleading design practices, such as faded buttons or hard-to-understand scroll bars. Full guidance is available on the CNIL's cookies and trackers compliance page.

GDPR Compliance Checklist for Employees and HR

Employee data deserves the same rigor as customer data, and it is often overlooked. Review your practices around recruitment and CVs, employee records, payroll, HR software, attendance systems, video surveillance, employee monitoring, internal communications, privacy notices for staff, retention of records, and how former employee data is handled after departure.

SME example: A ten-person marketing agency uses an external payroll platform, a time-tracking app, and keeps CVs from past recruitment rounds. Each of these needs a defined retention period, a documented legal basis, and a check on whether the vendor qualifies as a sous-traitant under Article 28.

This area is particularly relevant for businesses searching for guidance on RGPD RH or RGPD salariés.

GDPR Data Breach Checklist for French SMEs

When something goes wrong, speed and documentation matter.

72-hour rule: Where notification to the CNIL is required, the controller must notify without undue delay and, wherever feasible, no later than 72 hours after becoming aware of the breach.

Emergency checklist when a breach occurs:

  1. ☐ Identify the incident.

  2. ☐ Contain the breach.

  3. ☐ Assess the risk to the individuals affected.

  4. ☐ Document the incident internally, regardless of severity.

  5. ☐ Determine whether CNIL notification is required.

  6. ☐ Notify the CNIL within 72 hours where required.

  7. ☐ Inform affected individuals where the risk is high.

  8. ☐ Implement corrective measures to prevent recurrence.

Under Article 33 of the GDPR, the notification to the CNIL must be transmitted as soon as possible after a breach presenting a risk to individuals' rights and freedoms is discovered. If you cannot gather every required detail immediately, you can notify in two stages: an initial notification within 72 hours where possible, followed by additional details once the investigation is complete. Not every incident requires notification. If the breach does not create a risk for the rights and freedoms of the people affected, the controller only needs to document it internally in a register, without notifying the CNIL or the individuals concerned. Full procedure available on the CNIL's breach notification page.

GDPR Compliance Checklist for Third-Party Software and Vendors

Most SMEs rely heavily on external software and service providers, and each one is a potential compliance gap if left unchecked. Using the right GDPR compliance software for French SMEs can also help businesses organize compliance tasks, monitor documentation, and manage privacy requirements more consistently. 

SME example: A French accounting firm might process employee payroll data through an external HR platform, store client documents in a cloud service, and use a CRM for prospect management. Each provider should be assessed for its role, contractual obligations, security measures, and any international data transfers involved.

Vendor review checklist:

  • ☐ Data processing agreement in place

  • ☐ Processor and subprocessor roles reviewed

  • ☐ Hosting location confirmed

  • ☐ International transfers assessed

  • ☐ Security measures verified

  • ☐ Data deletion and retention settings checked

  • ☐ Access controls reviewed

  • ☐ Article 28 contractual obligations confirmed, not assumed

Common GDPR Compliance Mistakes Made by French SMEs

  1. Treating GDPR as a one-time project instead of an ongoing responsibility.

  2. Having a privacy policy but no internal procedures to back it up.

  3. Collecting more data than is actually necessary.

  4. Keeping personal data indefinitely rather than defining retention periods.

  5. Ignoring employee data as if only customer data matters.

  6. Assuming that being a small company is automatically an exemption.

  7. Using cookies without proper, verifiable consent.

  8. Failing to review SaaS providers and their subprocessors.

  9. Not preparing for data breaches before one actually happens.

  10. Failing to train employees on basic data protection practices.

How to Perform a GDPR Compliance Audit in a French SME

A structured audit does not need to be complicated. A simple five-step framework works well for most SMEs.

Step 1: Identify processing activities. List every place personal data enters, moves through, and exits your business.

Step 2: Assess legal and regulatory compliance. Check each activity against GDPR requirements and CNIL guidance.

Step 3: Identify privacy and security gaps. Be honest about where documentation, consent, or security controls are missing.

Step 4: Prioritize remediation. Fix the highest-risk gaps first, particularly anything involving sensitive data or weak security.

Step 5: Monitor and review. Build compliance checks into your regular business rhythm rather than treating them as a one-off exercise.

A simple status system helps track progress:

Status

Meaning

Green

Requirement implemented and documented

Amber

Partially implemented or requires improvement

Red

Missing or high-priority compliance gap

If your audit surfaces more Amber and Red items than you expected, that is normal, and it is exactly the point where structured training or outside support tends to make the biggest difference. The Diploma in GDPR Compliance and Data Protection is built to help SME teams turn an audit like this into a working compliance program.

How Often Should a French SME Review GDPR Compliance?

There is no single universal interval that applies to every GDPR activity. Instead, review your compliance after major business changes, when introducing new technologies, when launching new processing activities, after security incidents, when changing suppliers, when entering new markets, when regulatory guidance changes, and periodically as part of normal governance.

What Happens If a French SME Is Not GDPR Compliant?

Non-compliance can lead to regulatory investigation, orders to correct specific practices, restrictions on processing, administrative fines, reputational damage, loss of customer trust, and operational disruption. That said, it is worth keeping perspective. GDPR compliance is primarily about risk management, accountability, and protecting the personal data your business is trusted with, not about triggering fear over every small gap.

★ Free PDF Certificate Included

Master GDPR Compliance & Data Protection.

Build a strong understanding of GDPR, French data protection requirements, CNIL expectations, privacy governance, DPO responsibilities, DPIAs, data breaches, vendor management, and international data transfers. Earn a certificate of completion at no additional cost. Develop the knowledge to support effective privacy compliance, strengthen data protection practices, and manage GDPR responsibilities with confidence.

Enrol Now →

Final GDPR Compliance Checklist for French SMEs

A compact, printable summary of everything above.

☐ Personal data identified 

☐ Processing activities mapped 

☐ Legal bases documented 

☐ Processing register reviewed 

☐ Privacy notices updated 

☐ Data subject rights procedure established 

☐ Retention periods defined 

☐ Security controls reviewed 

☐ Breach procedure established (72-hour rule understood) 

☐ Processor contracts reviewed 

☐ International transfers assessed 

☐ Cookies and trackers reviewed 

☐ DPIA requirements assessed 

☐ Employee data reviewed 

☐ Employees trained 

☐ Marketing practices reviewed 

☐ GDPR documentation maintained 

☐ Responsibilities assigned 

☐ Compliance reviewed regularly

Want a printable version? Download the GDPR Compliance Checklist for French SMEs and keep it on hand for internal audits and CNIL readiness reviews.

Strengthen GDPR Knowledge With Professional Training

Working through a checklist is a strong start, but building lasting compliance usually comes down to how well your team understands GDPR principles day to day. Structured training helps staff understand data protection requirements, learn core privacy principles, grasp organizational responsibilities, and build stronger governance habits over time.

The Diploma in GDPR Compliance and Data Protection is designed to help SME teams build practical, working knowledge of GDPR rather than just theoretical awareness.

Frequently Asked Questions

Knowing what personal data you process, having a lawful basis for each activity, giving clear privacy notices, respecting data subject rights, keeping data only as long as needed, securing it appropriately, and being ready to respond to a breach.

Yes. Compliance depends on whether personal data is processed and on territorial scope, not on company size.

Yes, though certain documentation requirements, such as parts of the Article 30 register, are reduced for smaller organizations under specific conditions.

It typically covers data mapping, legal basis, privacy notices, data subject rights, retention, security, breach response, processor contracts, international transfers, cookies, DPIAs, employee data, training, and documentation.

In many cases yes. The CNIL generally recommends that all businesses maintain some form of processing record, even where the strict Article 30 threshold does not fully apply.

No. A Data Protection Officer is mandatory in specific situations, such as large-scale monitoring or processing of sensitive data, but many SMEs assign privacy responsibilities informally without a formal DPO.

Privacy policies, a processing register, processor agreements, DPIAs where relevant, breach records, retention policies, and consent records.

Only as long as necessary for the purpose it was collected for, with retention periods defined per data category rather than kept indefinitely.

Identify and contain the incident, assess the risk, document it internally, and notify the CNIL within 72 hours if the breach presents a risk to individuals.

Yes, alongside the ePrivacy rules transposed into French law, and the CNIL publishes detailed recommendations on how valid consent must be collected.

By keeping documentation current, maintaining a processing register, training staff, and running periodic internal audits rather than waiting for a control to reveal gaps.