Questions about GDPR compliance frequently arise in compliance channels, vendor discussions, and audit preparations. Even six years after GDPR's implementation, teams still grapple with key issues: when to hire a Data Protection Officer (DPO), calculating fine exposure, understanding "sensitive" data in Article 9, and assessing if a marketing setup might prompt an audit.
Below are common questions with direct answers linked to specific GDPR provisions.
Are We Required to Have a Data Protection Officer?
Your need for a DPO depends on three criteria in Article 37. You need a DPO if:
- You're a public authority (except courts acting in their judicial capacity).
- Your core activities involve large-scale systematic monitoring of individuals.
- Your core activities involve large-scale processing of special categories of data under Article 9 or criminal conviction data under Article 10.
"Core activities" means processing central to your business model. For example, a hospital processing patient health records needs a DPO. A law firm occasionally handling health data in litigation likely doesn't, unless the processing is systematic and large-scale.
"Large-scale" isn't numerically defined, but the Article 29 Working Party guidance considers factors like the number of data subjects, volume of data, processing duration, and geographic scope. Processing data on hundreds of thousands across multiple EU states likely qualifies as large-scale.
If you don't meet these criteria but want a DPO for strategic reasons, you can appoint one. However, they must meet the same legal protections and independence requirements as a mandatory DPO.
How Are GDPR Fines Calculated?
Fines can reach €20,000,000 or 4% of global annual revenues, whichever is higher, for serious violations like breaching Article 5's core processing principles or ignoring Individual Rights under Articles 12-22.
Lesser infringements, like failing to notify a DPO appointment, cap at €10,000,000 or 2% of global revenues.
Supervisory authorities consider several factors under Article 83(2):
- Nature, gravity, and duration of the breach.
- Number of affected data subjects.
- Involvement of special categories under Article 9.
- Whether you self-reported or cooperated.
- Prior infringements and history with the authority.
- Use of an approved certification mechanism or code of conduct.
While the 4% figure is daunting, most fines fall below this threshold. Authorities reserve the maximum for repeat offenders or deliberate misconduct.
What's the Difference Between a Controller and a Processor?
A controller determines the purposes and means of processing. A processor acts on the controller's behalf under a contract.
If you decide why and how to collect and use email addresses, you're the controller. If you're a vendor running email campaigns based on client instructions, you're the processor.
This distinction matters because obligations differ. Controllers must establish a lawful processing basis (Article 6), conduct Data Protection Impact Assessments (Article 35), and handle Data Subject Requests (Articles 12-22). Processors must implement technical measures (Article 32), maintain records (Article 30), and follow documented instructions (Article 28).
Joint controllers, who jointly determine purposes and means, need a transparent arrangement under Article 26 defining responsibilities.
If your vendor contract is vague about decision-making, a supervisory authority might deem you joint controllers, increasing liability exposure.
What If We Get Breached? Do We Always Have to Notify?
You have 72 hours from becoming aware of a personal data breach to notify your supervisory authority, unless the breach is unlikely to risk individuals' rights and freedoms (Article 33).
"Aware" means having reasonable certainty of a breach, not completing a full investigation. The clock starts when your security team or vendor confirms unauthorized access.
If the breach poses a high risk to individuals, notify affected data subjects without undue delay (Article 34). High risk involves special data categories, large-scale financial data exposure, or risks like identity theft or discrimination.
You're exempt from notifying individuals if you used protections like encryption, took measures to eliminate high risk, or if notification requires disproportionate effort (in which case, make a public communication).
Document every breach in your internal register, even if notification isn't required. Authorities audit these registers, and unreported incidents will raise questions during reviews.
Can We Just Get Consent for Everything?
No. Consent under Article 7 is one lawful basis, not a universal solution.
Valid consent must be freely given, specific, informed, and unambiguous, requiring a clear affirmative action. In power imbalances (employer-employee, government-citizen), consent is rarely freely given.
Consent might not be the best option. If processing is needed to fulfill a contract (Article 6(1)(b)), for legal compliance (Article 6(1)(c)), or for legitimate interests (Article 6(1)(f)), those bases are often more stable than consent, which can be withdrawn anytime.
Relying on consent when another basis applies creates risk. If consent is withdrawn and you needed the data to deliver a contracted service, you're in a documentation nightmare explaining continued processing.
Our Vendor Says They're "GDPR Compliant." Is That Enough?
No. Article 28 requires due diligence before engaging a processor and documenting their technical and organizational measures.
"GDPR compliant" is marketing language, not a certification. You need a contract with mandatory Article 28(3) clauses: processing on documented instructions, confidentiality, security measures, sub-processor restrictions, assistance with Data Subject Requests and DPIAs, data deletion or return at contract termination, and audit rights.
If your vendor breaches, you're responsible for notifying the authority within 72 hours. If they transfer data outside the EU without safeguards, you share liability. If they process beyond your instructions, they've become a controller, requiring a new risk assessment.
Request their SOC 2 Type II report, ISO 27001 certificate, or equivalent evidence. Review their sub-processor list. Verify their audit controls, even through third-party assessments. Ensure your contract allows immediate termination if they breach Article 28 obligations.
Where Do We Go From Here?
If you're still working through these questions, you're not alone. Start with your Data Processing Register (Article 30). Map every processing activity, identify the lawful basis, document retention periods, and flag special categories or cross-border transfers.
Then audit your processor contracts. If they predate May 2018 or lack Article 28(3) clauses, update them.
Finally, test your breach response. Run a tabletop exercise with a 72-hour notification window. If you can't identify the authority, draft the notification, and determine individual notification requirements in that timeframe, you've found your next project.
GDPR isn't simpler, but your response to these questions can be.





