In one sentence. A 2026 GDPR compliance programme is built on 11 concrete deliverables: a Record of Processing Activities (Article 30), a lawful basis register (Article 6), DPIAs for high-risk processing (Article 35), an Article 28 processor register with signed DPAs, a Schrems II transfer map, breach response within 72 hours (Article 33), a data subject rights workflow (Articles 15-22), a retention schedule, security measures (Article 32), staff training, and an annual audit cycle. Recent enforcement (Meta €1.2B in 2023, TikTok €530M in 2025) makes the cost of skipping any of these higher than ever.
This guide consolidates the 2025-2026 enforcement reality — EDPB guidelines, CJEU rulings, and 5 billion+ in cumulative GDPR fines — into a deliverables-based roadmap. It mirrors the structure of the official EDPB accountability framework and the European Commission’s GDPR guidance.
Key takeaways
- 11 mandatory deliverables — no “GDPR-lite” exists.
- ROPA (Article 30) is the foundation — every other deliverable depends on it.
- DPIA is required for processing listed in EDPB Guidelines WP248rev.01.
- Breach notification deadline is 72 hours to the supervisory authority.
- Top-tier fines reach €20M or 4% of global turnover (Article 83(5)).
- 2025 fine total exceeded €2.1 billion across the EEA.
1. Map your data: Record of Processing Activities
2. Assign a lawful basis to each activity
3. Run DPIAs for high-risk processing
4. Govern your processors (Article 28)
5. Map and lawfully justify international transfers
6. Build a 72-hour breach response capability
7. Operationalise data subject rights
8. Define retention and storage limits
Article 5(1)(e) — storage limitation — requires deletion or anonymisation when the purpose is fulfilled. Document retention rules per data category in a written schedule; automate purges. For encryption standards, retention periods by data type and secure-deletion workflows, see our detailed GDPR data storage and retention guide.
9. Implement Article 32 security measures
State-of-the-art technical and organisational measures: encryption at rest and in transit, pseudonymisation, access controls, MFA, backups with integrity tests, vulnerability management, incident response procedures. EDPB Guidelines 9/2022 detail breach notification thresholds.
10. Train staff and assign a DPO if required
11. Audit and update annually
12. What DPAs are actually enforcing in 2025-2026
Reading the docket, not the statute, tells you where the risk concentrates. Four themes dominate recent EDPB and national-DPA decisions. International transfers remain the single largest exposure — the €1.2B Meta fine (Irish DPC, May 2023) for EU-US Facebook transfers set the ceiling, and TikTok’s €530M decision (Irish DPC, May 2025) confirmed transfers to China as a live enforcement front. Consent and dark patterns in cookie banners and ad-tech continue to draw fines from the CNIL and the Garante. Legal basis for behavioural advertising — the Meta €390M decision (Irish DPC, January 2023) rejected “contract” as a basis for ads — has reshaped how platforms justify tracking. And children’s data, where TikTok (€345M, Irish DPC, September 2023) established that default-public teen accounts breach the Regulation. If your programme covers these four areas properly, you are aligned with where enforcement energy is going.
13. Sequencing the 11 deliverables
Do not attempt all eleven at once. The dependency order matters: the ROPA comes first because every other deliverable reads from it. With the processing inventory in place, assign lawful bases (Article 6), then layer retention rules and the data controller versus processor mapping on top of the same records. DPIAs and Article 28 processor governance follow, because you cannot assess risk or vendor exposure for activities you have not yet catalogued. Transfers, breach response, and data-subject-rights workflows are the operational layer built last, on a stable inventory. Security measures (Article 32) and staff training run in parallel throughout. A realistic sequence for a mid-market team is: ROPA and lawful bases in month one, processor and transfer mapping in month two, DPIA and rights workflows in month three, then a first internal GDPR audit to close gaps. Trying to boil the ocean produces eleven half-finished artefacts and no defensible accountability record under Article 5(2).
14. Tooling
FAQ
What is the GDPR compliance guide for 2026?
A documented programme covering Article 30 ROPA, Article 6 lawful bases, Article 35 DPIAs, Article 28 processor governance, Schrems II transfers, Article 33 breach response within 72 hours, data subject rights workflow, retention schedule, Article 32 security, training, and annual audit.
How long does GDPR compliance take?
For a mid-size SaaS: 6-12 months with internal effort, 60-90 days with tooling. Programme maintenance is continuous.
What are the biggest GDPR fines in 2025?
TikTok €530M (Irish DPC, May 2025) for Chinese transfers, Uber €290M (Dutch DPA), and multiple Meta and Amazon decisions. Cumulative EEA fines exceeded €2.1B in 2025.
Is GDPR compliance mandatory for non-EU companies?
Yes if they offer goods/services to EU residents or monitor their behaviour (Article 3 territorial scope).
What’s the minimum GDPR compliance deliverable list?
ROPA, lawful basis register, signed DPAs with processors, privacy notice, DSAR procedure, breach response procedure, security measures. Anything less invites Article 83 sanctions.