---
title: "GDPR & the new rules of data | Avanti Technologies"
description: "A plain-English GDPR handbook for SMEs — and how the EU AI Act, Data Act and a wave of new regulation now sit on top of it."
url: https://www.avanti.ie/resources/gdpr
section: "Practical Guide · 2026"
published: 2026-07-18
modified: 2026-08-06
publisher: "Avanti Technologies"
---
Practical Guide · 2026

// Data protection for small & mid-sized businesses

# GDPR & the new rules of data

A plain-English handbook for SMEs — and how the AI Act, Data Act and a wave of new regulation now sit on top of it.

**Who this is for.** Founders, operators and teams who process personal data but don't have a legal department. No jargon, no scare tactics — just what the rules mean, how they connect, and the concrete steps that keep you on the right side of them.

ℹ️ This guide is general information, current to mid-2026 — not legal advice. Confirm specifics for your jurisdiction and sector.

// 01 — The 60-second version

## If you read nothing else

2018

In force since 25 May

€20M

Or 4% of global turnover — max fine

72h

To report a serious breach

€1.2bn

Largest single fine to date

**The one idea that carries everything:** GDPR isn't about paperwork — it's about being able to answer three questions at any moment.

What personal data do we hold? Why are we allowed to hold it? Could we hand it back or delete it if asked?

Get those three answers straight and the rest of this guide — including the new AI and data laws — becomes far easier to follow.

// 02 — GDPR in plain English

## The concepts, without the jargon

The General Data Protection Regulation governs how organisations handle **personal data** — anything that can identify a living person, directly or indirectly. A name, an email, an IP address, a cookie ID, a photo. If you can tie it to a person, it counts.

### Controller vs. Processor

You're a **controller** when you decide why and how data is used (your customer list). You're a **processor** when you handle data on someone else's behalf (a payroll tool running for a client). Most SMEs are both, in different moments.

### It reaches beyond the EU

If you offer goods or services to — or monitor — people in the EU/EEA, GDPR applies **even if you're based in New York or Nairobi**. This "extraterritorial" reach is why a small US SaaS firm still needs to care.

### The 7 Principles

Every decision you make about data should trace back to one of these.

- 1

**Lawfulness, fairness & transparency**

People know what you're doing and you have a legal reason.

- 2

**Purpose limitation**

Collect it for a stated reason; don't quietly reuse it.

- 3

**Data minimisation**

Only what you actually need. Fewer fields, less risk.

- 4

**Accuracy**

Keep it correct and up to date; fix or delete what's wrong.

- 5

**Storage limitation**

Don't keep it forever. Set retention periods and honour them.

- 6

**Integrity & confidentiality**

Keep it secure — encryption, access control, backups.

- 7

**Accountability**

You must be able to show you do all of the above — records, policies, evidence.

### 6 Lawful Bases

You need one before you process.

- ✓ Consent — freely given, specific, revocable.
- ✓ Contract — needed to deliver what they asked for.
- ✓ Legal obligation — a law requires it (e.g. tax).
- ✓ Vital interests — life-or-death situations.
- ✓ Public task — official/public-interest functions.
- ✓ Legitimate interests — a real business need, balanced against privacy.

### 8 Data-Subject Rights

What individuals can ask of you.

**Be informed**

**Access a copy**

**Rectification**

**Erasure**

**Restrict processing**

**Portability**

**Object**

**Human review**

// 03 — The landscape now

## GDPR is no longer alone

Since 2024 the EU has shipped a stack of digital laws that all touch personal data. **Master the GDPR mindset and each new law is an extension, not a restart.**

EU AI Act

AI that uses personal data must also satisfy GDPR. High-risk systems need a risk assessment that dovetails with your GDPR one.

Data Act

Forces data-sharing from connected devices. Where that data is personal, GDPR still governs it — GDPR wins any conflict.

NIS2

Cybersecurity duties overlap with GDPR's "keep data secure" principle and its breach-reporting clock.

ePrivacy

Cookies and marketing consent. Borrows GDPR's definition of valid consent — the rules you already know.

DSA / DMA

Platform rules: limits on targeted ads, dark patterns and profiling of minors — all GDPR-adjacent.

// 04 — The action plan

## A step-by-step checklist

You don't need everything at once. Work through these three phases in order.

01

Get your house in order

Weeks 1–4

- Map your data — list what personal data you hold, where it lives, and who you share it with.
- Assign a lawful basis to each use of data. If it's consent, make sure you can prove it.
- Publish a clear privacy notice. Plain language, easy to find, honest about what you do.
- Fix your cookie banner. Refuse must be as easy as accept.

02

Build the safeguards

Months 1–3

- Sign data processing agreements with every vendor that touches your data.
- Set retention periods and actually delete data when they lapse.
- Lock down security. Encryption, access controls, MFA, backups.
- Write a breach plan. Who does what, and how you notify the regulator within 72 hours.
- Have a process for data-subject requests.

03

Stay ahead of the new laws

Ongoing

- Inventory your AI. List every AI tool you build or use.
- Train your team on AI. The AI Act's "AI literacy" duty is already live.
- Run a combined DPIA/FRIA for any high-risk AI that uses personal data.
- Review connected-product and cloud contracts against the Data Act.
- Appoint an owner. One named person responsible for privacy.

Infrastructure built to last

## Compliance is a system, not a scramble

Build the foundations once and the new laws slot in cleanly. If you'd like a hand mapping your data, assessing your AI, or standing up the safeguards, that's the kind of infrastructure work we do.

[Book a call with Avanti →](https://calendly.com/kumar-avanti)

This guide is general information, accurate to the best of our knowledge as of mid-2026, and does not constitute legal advice.

## // Keep reading

[Interactive Tool · ComplianceEU AI Act + GDPR Product AssessorScreen a product against the EU AI Act and GDPR in minutes and generate an auditable gap report with legal references — a self-assessment tool, not legal advice.](https://www.avanti.ie/resources/eu-ai-gdpr-assessor)[Field Notes · System ArchitectureThe most successful AI systems use the least AIChoosing where AI belongs is an engineering trade-off across accuracy, cost, complexity and risk. A CXO framework for humans, rules, machine learning and generative AI.](https://www.avanti.ie/resources/successful-ai-least-ai)[Briefing · AI InfrastructureTraining large language models: an EU briefingWhat pre-training, post-training and evaluation involve — and what they mean for compute, data governance and talent decisions in Ireland and the EU.](https://www.avanti.ie/resources/training-large-language-models)

[All resources →](https://www.avanti.ie/resources)

## Frequently asked questions

### What does GDPR require a small business to do?

At minimum: know what personal data you hold and why, have a lawful basis for each use, tell people plainly what you do with their data, keep it only as long as you need it, secure it proportionately, be able to answer access and erasure requests, and be able to report a qualifying breach to the supervisory authority within 72 hours.

### Does the EU AI Act replace GDPR?

No. The AI Act sits on top of GDPR rather than replacing it. GDPR governs personal data wherever it is processed, including inside AI systems; the AI Act adds obligations based on the risk category of the AI system itself. A single AI deployment can be subject to both at once.

### What are the six lawful bases for processing personal data under GDPR?

Consent, freely given and revocable; contract, where processing is needed to deliver what the person asked for; legal obligation, where a law requires it; vital interests, for life-or-death situations; public task, for official or public-interest functions; and legitimate interests, a real business need balanced against the individual's privacy. You need one of the six in place before you process, not afterwards.

### How long do you have to report a data breach under GDPR?

72 hours from becoming aware of it, for breaches that meet the reporting threshold. The report goes to your supervisory authority, and where the breach is likely to result in a high risk to individuals they must be told as well. The practical implication is that detection and escalation have to be fast enough to leave time to assess before the clock runs out.

### Does GDPR apply to companies outside the EU?

Yes. If you offer goods or services to people in the EU or EEA, or monitor their behaviour, GDPR applies even if you are based elsewhere. This extraterritorial reach is why a small US SaaS company selling into Europe still has to comply.
