5 Typical GDPR Mistakes Mid-sized Companies Make Again and Again
From 6 years of GDPR audits — the most common weaknesses that almost every mid-sized company has. With concrete tips for fixing them.
Over the past few years, we have carried out many GDPR audits — from 5-person tax offices to mid-sized companies with 200 employees. What is astonishing: certain mistakes come up AGAIN and AGAIN.
1. "We have the data protection concept from our lawyer — that will do"
The concept itself is usually OK. The problem: nobody lives it. Employees do not know the rules, data processing agreements are 3 years old, and data protection impact assessments were never updated.
Solution: A quarterly data protection check — no 4-day marathon sessions; 30 minutes of going through things systematically is enough.
2. Shadow IT with customer data
Marketing uses Mailchimp, sales uses HubSpot, someone still has an old Trello account with customer notes. Nobody knows who has which data where.
Solution: A tool inventory once a year. Excel spreadsheet: tool / purpose / data processed / DPA in place? You will be surprised how much is there.
3. DPAs are signed — but nobody reviews them
DPAs are signed when a tool is introduced and never looked at again. But when the provider expands its sub-processing (e.g., a new data transfer to the US), you only find out through an email notice. One that nobody reads.
Solution: A DPA tracker with renewal dates. For major tools (M365, Salesforce, etc.), explicitly ask about changes.
4. Backups contain deleted data
You received a deletion request and deleted the data in the production database — done? No. Backups still contain the data for months. If you restore, it ends up back in the system.
Solution: A deletion concept that includes backups. Common practice: after 6 months, all backups containing the deleted information have expired. Inform the customer about this.
5. "Right of access" — no processes
A customer asks: "What data do you have about me?" You have 30 days. But: no process, no template, and someone first has to figure out who in your company even has what.
Solution: A standard process for data subject rights. A template for the access response letter + an internal checklist of which systems need to be queried.
How we help
Our GDPR audit finds exactly these kinds of gaps — structured, documented, with prioritized measures. Fixed price from €1,500 for small setups.
If you just want a quick check on whether you are on the safe side: free 30-minute initial consultation.