Practical Guide · 2026
// Data protection for small & mid-sized businesses

GDPR & the new rules of data

A plain-English handbook for SMEs — and how the AI Act, Data Act and a wave of new regulation now sit on top of it.

Who this is for. Founders, operators and teams who process personal data but don't have a legal department. No jargon, no scare tactics — just what the rules mean, how they connect, and the concrete steps that keep you on the right side of them.

ℹ️ This guide is general information, current to mid-2026 — not legal advice. Confirm specifics for your jurisdiction and sector.

// 01 — The 60-second version

If you read nothing else

2018
In force since 25 May
€20M
Or 4% of global turnover — max fine
72h
To report a serious breach
€1.2bn
Largest single fine to date

The one idea that carries everything: GDPR isn't about paperwork — it's about being able to answer three questions at any moment.

What personal data do we hold? Why are we allowed to hold it? Could we hand it back or delete it if asked?

Get those three answers straight and the rest of this guide — including the new AI and data laws — becomes far easier to follow.

// 02 — GDPR in plain English

The concepts, without the jargon

The General Data Protection Regulation governs how organisations handle personal data — anything that can identify a living person, directly or indirectly. A name, an email, an IP address, a cookie ID, a photo. If you can tie it to a person, it counts.

Controller vs. Processor

You're a controller when you decide why and how data is used (your customer list). You're a processor when you handle data on someone else's behalf (a payroll tool running for a client). Most SMEs are both, in different moments.

It reaches beyond the EU

If you offer goods or services to — or monitor — people in the EU/EEA, GDPR applies even if you're based in New York or Nairobi. This "extraterritorial" reach is why a small US SaaS firm still needs to care.

The 7 Principles

Every decision you make about data should trace back to one of these.

  • 1
    Lawfulness, fairness & transparency
    People know what you're doing and you have a legal reason.
  • 2
    Purpose limitation
    Collect it for a stated reason; don't quietly reuse it.
  • 3
    Data minimisation
    Only what you actually need. Fewer fields, less risk.
  • 4
    Accuracy
    Keep it correct and up to date; fix or delete what's wrong.
  • 5
    Storage limitation
    Don't keep it forever. Set retention periods and honour them.
  • 6
    Integrity & confidentiality
    Keep it secure — encryption, access control, backups.
  • 7
    Accountability
    You must be able to show you do all of the above — records, policies, evidence.

6 Lawful Bases

You need one before you process.

  • Consent — freely given, specific, revocable.
  • Contract — needed to deliver what they asked for.
  • Legal obligation — a law requires it (e.g. tax).
  • Vital interests — life-or-death situations.
  • Public task — official/public-interest functions.
  • Legitimate interests — a real business need, balanced against privacy.

8 Data-Subject Rights

What individuals can ask of you.

Be informed
Access a copy
Rectification
Erasure
Restrict processing
Portability
Object
Human review
// 03 — The landscape now

GDPR is no longer alone

Since 2024 the EU has shipped a stack of digital laws that all touch personal data. Master the GDPR mindset and each new law is an extension, not a restart.

EU AI Act
AI that uses personal data must also satisfy GDPR. High-risk systems need a risk assessment that dovetails with your GDPR one.
Data Act
Forces data-sharing from connected devices. Where that data is personal, GDPR still governs it — GDPR wins any conflict.
NIS2
Cybersecurity duties overlap with GDPR's "keep data secure" principle and its breach-reporting clock.
ePrivacy
Cookies and marketing consent. Borrows GDPR's definition of valid consent — the rules you already know.
DSA / DMA
Platform rules: limits on targeted ads, dark patterns and profiling of minors — all GDPR-adjacent.
// 04 — The action plan

A step-by-step checklist

You don't need everything at once. Work through these three phases in order.

01
Get your house in order
Weeks 1–4
  • Map your data — list what personal data you hold, where it lives, and who you share it with.
  • Assign a lawful basis to each use of data. If it's consent, make sure you can prove it.
  • Publish a clear privacy notice. Plain language, easy to find, honest about what you do.
  • Fix your cookie banner. Refuse must be as easy as accept.
02
Build the safeguards
Months 1–3
  • Sign data processing agreements with every vendor that touches your data.
  • Set retention periods and actually delete data when they lapse.
  • Lock down security. Encryption, access controls, MFA, backups.
  • Write a breach plan. Who does what, and how you notify the regulator within 72 hours.
  • Have a process for data-subject requests.
03
Stay ahead of the new laws
Ongoing
  • Inventory your AI. List every AI tool you build or use.
  • Train your team on AI. The AI Act's "AI literacy" duty is already live.
  • Run a combined DPIA/FRIA for any high-risk AI that uses personal data.
  • Review connected-product and cloud contracts against the Data Act.
  • Appoint an owner. One named person responsible for privacy.
Infrastructure built to last

Compliance is a system, not a scramble

Build the foundations once and the new laws slot in cleanly. If you'd like a hand mapping your data, assessing your AI, or standing up the safeguards, that's the kind of infrastructure work we do.

Book a call with Avanti →

This guide is general information, accurate to the best of our knowledge as of mid-2026, and does not constitute legal advice.

// Keep reading

Interactive Tool · Compliance
EU AI Act + GDPR Product Assessor

Screen a product against the EU AI Act and GDPR in minutes and generate an auditable gap report with legal references — a self-assessment tool, not legal advice.

Field Notes · System Architecture
The most successful AI systems use the least AI

Choosing where AI belongs is an engineering trade-off across accuracy, cost, complexity and risk. A CXO framework for humans, rules, machine learning and generative AI.

Briefing · AI Infrastructure
Training large language models: an EU briefing

What pre-training, post-training and evaluation involve — and what they mean for compute, data governance and talent decisions in Ireland and the EU.

All resources →