The paperwork exists, the process does not
A typical company that has completed an implementation has a data protection policy, information notices and a record of processing activities. The problem surfaces when an inspector asks who last updated those documents and whether they match what is actually happening in the systems. Accountability under Article 5(2) GDPR means an obligation to demonstrate compliance, not to hold a document.
The usual scenario: the record describes three systems, while the marketing team has meanwhile adopted a fourth tool, rolled out without involving the person responsible for data protection. An inspection exposes the gap within minutes.
Consent where consent is not needed
Consent is only one of six lawful bases and usually the weakest — it can be withdrawn at any moment, at which point the processing loses its basis. For performing a contract, the correct basis is performance of that contract; for pursuing claims and for security, it is the controller's legitimate interest, preceded by a balancing test.
Basing order fulfilment on customer consent means that withdrawing it would, in theory, block performance of the contract. That is a structural error, not a cosmetic one — it is fixed by re-examining the lawful bases, not by rewording the notice.
Sharing data without an agreement
An accountancy firm, a hosting provider, a CRM system, a document destruction company, a marketing agency — each processes data on the controller's behalf and requires a processing agreement compliant with Article 28 GDPR. It must set out the subject matter and duration of processing, its nature and purpose, the type of data, the categories of data subjects, and the controller's obligations and rights.
Server location is a separate question. The assumption that a supplier "surely has everything GDPR-compliant" tends to be tested only when an incident occurs. A transfer to a third country needs its own basis.
Access that is too broad inside the organisation
Data minimisation applies not only to the scope of data collected but also to the circle of people who can reach it. Shared mailboxes, spreadsheets of HR data on a network drive open to a whole department, accounts of former employees left active — these are confidentiality breaches that come to light only after an incident.
- Review permissions at least twice a year, with a list of accounts and assigned roles.
- Withdraw access on the day the working relationship ends.
- Issue processing authorisations by name, with a defined scope.
- Encrypt removable media and send bulk email using blind copy only.
The 72 hours everyone remembers too late
A personal data breach must be notified to the supervisory authority within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to the rights and freedoms of individuals. The clock starts when the organisation becomes aware — including where the incident was reported by a junior employee and the information then stalled in the IT department.
The notification procedure therefore needs a single owner, an escalation path everyone knows, and a breach register kept regardless of whether the incident was ultimately reported. The absence of a register by itself makes accountability harder to demonstrate.
Financial and reputational exposure
Administrative fines can reach EUR 20 million or 4% of total worldwide annual turnover, whichever is higher. For small and medium-sized firms, however, the indirect consequences often bite harder: a contract lost after a counterparty's audit fails, civil claims from the individuals whose data was exposed, and the cost of rebuilding customer trust.
The most expensive breaches are usually those that simple organisational steps would have prevented: a permissions review, an updated record, and one processing agreement.
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR)
- Article 5(2) GDPR — the accountability principle
- Article 30 GDPR — records of processing activities
- Article 33 GDPR — notifying breaches within 72 hours