---
description: With GDPR now over a year old, many SMEs are still failing to conduct even basic elements of GDPR compliance, such as data protection impact assessments. 
image: https://gdm-localsites-assets-gfprod.imgix.net/images/capterra/og_logo-e5a8c001ed0bd1bb922639230fcea71a.png?auto=format%2Cenhance%2Ccompress
title: GDPR turns one – is your SME compliant? - Capterra
---

# GDPR turns one – is your SME compliant?

Canonical: https://www.capterra.co.uk/blog/840/gdpr-turns-one-is-your-sme-compliant

Published on 26/08/2019 | Written by Sonia Navarrete.

![GDPR turns one – is your SME compliant?](https://images.ctfassets.net/63bmaubptoky/KL8zfDxIFqtQrfbbSZMDmJp65AcHOnud0bWK0VWXjLw/6f84c6fba9c1fd7f8c32070e82372c69/shutterstock_1055066480.png)

> On 25 th May 2018, the General Data Protection Regulation (GDPR) became law, making imperative for all firms that process the personal data of EU citizens to do more to protect that data, while also providing individuals with new rights. 

-----

## Article Content

On 25 th May 2018, the General Data Protection Regulation (GDPR) became law, making imperative for all firms that process the personal data of EU citizens to do more to protect that data, while also providing individuals with new rights. However, with the regulation now over a year old, there’s evidence that many SMEs are still failing to conduct even basic elements of GDPR compliance, such as data protection impact assessments. Here, we will look at the current situation between SMEs and GDPR  and ask what more can be done to ensure compliance. Why GDPR mattersBefore we look at what has happened over the past year, it’s worth noting of  of what’s at stake for SMEs. Under GDPR, if a business suffers a data breach and is found not to have implemented appropriate data protection measures, it faces fines of as much as 4% of its global turnover. As well as the significant brand damage that can occur with large scale data breaches and the resulting loss of customer confidence, ensuring GDPR compliance couldn’t be more important for firms of all sizes, as they would also suffer from the financial consequences.  The fines have started Over the past year regulators in Europe have shown that they are ready to start checking who is following the law correctly and start fining those who are not.. In the UK, for example, the Information Commissioner’s Office (ICO) has announced its intention to fine British Airways and Marriott International £183 million and £99 million respectively for recent data breaches. According to the International Association of Privacy Professionals, the first year of GDPR saw a total of €56 million in fines. . While the headlines have focused on large enterprises, SMEs should be under no illusion that the regulators won’t come for them. Are SMEs prepared?According to a study, 30% of European firms  lack confidence that their business is compliant. The research also found that 21% of mid-market businesses admit having no cybersecurity strategy in place. Statistics like these suggest that when it comes to GDPR many businesses are sticking their heads in the sand and hoping they will go unnoticed by regulators and cybercriminals alike. For such firms, the risk of receiving fines for non-compliance are very high. GDPR compliance need not be complicatedThe good news is that once a company realises that it has no choice but to act on GDPR rules, there are a number of solutions available. Such tools enable firms to, for example, rapidly carry out data protection impact assessments on projects so they can ensure the work carried out is GDPR compliant from day one. The challenge you may find is knowing which software package to choose. Different GDPR compliance software services come with different features such as access control, compliance management, consent management and sensitive data identification, and knowing which will meet your specific compliance shortfalls can be a challenge. Make GDPR ‘year two’ a successGDPR is now in full effect and momentum is gathering around regulatory action, so  if you have left your GDPR preparations this long, now really is the time to act. The regulation applies equally to SMEs as it does to large enterprises. Fortunately, the market has what you need to achieve compliance rapidly – visit our  GDPR compliance software list to search over 125 available solutions today and take a step closer to compliance.

## About the author

### Sonia Navarrete

Sonia is a Senior Content Analyst at Capterra, helping SMEs choose the best software. She published in Raconteur, Computer Weekly and IT Pro. Journalist and PR. 

## Related Categories

- [Accounting Software](https://www.capterra.co.uk/directory/1/accounting/software)
- [CRM Software](https://www.capterra.co.uk/directory/2/customer-relationship-management/software)
- [ERP Systems](https://www.capterra.co.uk/directory/9/enterprise-resource-planning/software)
- [Human Resources Software](https://www.capterra.co.uk/directory/5/human-resource/software)
- [Project Management Software](https://www.capterra.co.uk/directory/30002/project-management/software)

## Related Articles

- [76% of UK businesses will spend more on software in 2025: Here's why](https://www.capterra.co.uk/blog/7557/uk-software-buying-trends-2025-research)
- [Smart cities in the UK: Balancing convenience and security for urban transformation](https://www.capterra.co.uk/blog/4185/Smart-city-habits-in-UK)
- [The benefits of apprenticeships for employers](https://www.capterra.co.uk/blog/1216/the-benefits-of-apprenticeships-for-employers)
- [Five ‘horrors’ that keep HR managers up at night](https://www.capterra.co.uk/blog/983/five-hr-issues-that-keep-hr-managers-up-at-night)
- [Free Software Resources to Help Your Business During The Coronavirus Outbreak](https://www.capterra.co.uk/blog/1375/free-software-resources-help-business)

## Links

- [View on Capterra](https://www.capterra.co.uk/blog/840/gdpr-turns-one-is-your-sme-compliant)
- [Blog](https://www.capterra.co.uk/blog)
- [Home](https://www.capterra.co.uk/)

-----

## Structured Data

<script type="application/ld+json">
  {"@context":"https://schema.org","@graph":[{"name":"Capterra UK","address":{"@type":"PostalAddress","addressLocality":"Egham","addressRegion":"ENG","postalCode":"TW20 9AH","streetAddress":"Tamesis, The Glanty, Staines-upon-Thames Egham TW20 9AH United Kingdom"},"description":"Capterra UK helps millions of people find the best business software. With software reviews, ratings, infographics, and the most comprehensive list of business software.","email":"info@capterra.co.uk","url":"https://www.capterra.co.uk/","logo":"https://dm-localsites-assets-prod.imgix.net/images/capterra/logo-a9b3b18653bd44e574e5108c22ab4d3c.svg","@id":"https://www.capterra.co.uk/#organization","@type":"Organization","parentOrganization":"Gartner, Inc.","sameAs":["https://twitter.com/Capterra","https://www.facebook.com/Capterra/","https://www.linkedin.com/company/capterra/","https://www.youtube.com/channel/UCEt7vQSPiPlPAblHdhJAqnA"]},{"name":"Capterra UK","url":"https://www.capterra.co.uk/","@id":"https://www.capterra.co.uk/#website","@type":"WebSite","publisher":{"@id":"https://www.capterra.co.uk/#organization"},"potentialAction":{"query":"required","target":"https://www.capterra.co.uk/search/?q={search_term_string}","@type":"SearchAction","query-input":"required name=search_term_string"}},{"name":"GDPR turns one – is your SME compliant? - Capterra","description":"With GDPR now over a year old, many SMEs are still failing to conduct even basic elements of GDPR compliance, such as data protection impact assessments. ","url":"https://www.capterra.co.uk/blog/840/gdpr-turns-one-is-your-sme-compliant","about":{"@id":"https://www.capterra.co.uk/#organization"},"@id":"https://www.capterra.co.uk/blog/840/gdpr-turns-one-is-your-sme-compliant#webpage","@type":"WebPage","isPartOf":{"@id":"https://www.capterra.co.uk/#website"}},{"description":"On 25 th May 2018, the General Data Protection Regulation (GDPR) became law, making imperative for all firms that process the personal data of EU citizens to do more to protect that data, while also providing individuals with new rights. ","author":[{"name":"Sonia Navarrete","@type":"Person"}],"image":{"url":"https://images.ctfassets.net/63bmaubptoky/KL8zfDxIFqtQrfbbSZMDmJp65AcHOnud0bWK0VWXjLw/6f84c6fba9c1fd7f8c32070e82372c69/shutterstock_1055066480.png","@id":"https://www.capterra.co.uk/blog/840/gdpr-turns-one-is-your-sme-compliant#primaryimage","@type":"ImageObject"},"@type":"BlogPosting","publisher":{"@id":"https://www.capterra.co.uk/#organization"},"inLanguage":"en-GB","datePublished":"2019-08-26T14:11:34.000000Z","articleBody":"&lt;img title=&quot;shutterstock_1055066480&quot; alt=&quot;data protection impact assessment&quot; class=&quot;aligncenter&quot; fetchpriority=&quot;high&quot; src=&quot;https://images.ctfassets.net/63bmaubptoky/KL8zfDxIFqtQrfbbSZMDmJp65AcHOnud0bWK0VWXjLw/6f84c6fba9c1fd7f8c32070e82372c69/shutterstock_1055066480.png&quot; srcset=&quot;https://images.ctfassets.net/63bmaubptoky/KL8zfDxIFqtQrfbbSZMDmJp65AcHOnud0bWK0VWXjLw/6f84c6fba9c1fd7f8c32070e82372c69/shutterstock_1055066480.png?w=400 400w, https://images.ctfassets.net/63bmaubptoky/KL8zfDxIFqtQrfbbSZMDmJp65AcHOnud0bWK0VWXjLw/6f84c6fba9c1fd7f8c32070e82372c69/shutterstock_1055066480.png?w=700 700w, https://images.ctfassets.net/63bmaubptoky/KL8zfDxIFqtQrfbbSZMDmJp65AcHOnud0bWK0VWXjLw/6f84c6fba9c1fd7f8c32070e82372c69/shutterstock_1055066480.png?w=1000 1000w, https://images.ctfassets.net/63bmaubptoky/KL8zfDxIFqtQrfbbSZMDmJp65AcHOnud0bWK0VWXjLw/6f84c6fba9c1fd7f8c32070e82372c69/shutterstock_1055066480.png?w=1500 1500w, https://images.ctfassets.net/63bmaubptoky/KL8zfDxIFqtQrfbbSZMDmJp65AcHOnud0bWK0VWXjLw/6f84c6fba9c1fd7f8c32070e82372c69/shutterstock_1055066480.png?w=2200 2200w&quot; sizes=&quot;(min-resolution: 2x) 2200px, (min-width: 992px) 1000px, 95vw&quot;/&gt;&lt;p&gt;On 25 th May 2018, the General Data Protection Regulation (GDPR) became law, making imperative for all firms that process the personal data of EU citizens to do more to protect that data, while also providing individuals with new rights. &lt;/p&gt;&lt;p&gt;However, with the regulation now over a year old, there’s evidence that many SMEs are still failing to conduct even basic elements of GDPR compliance, such as data protection impact assessments. &lt;/p&gt;&lt;p&gt;Here, we will look at the current situation between SMEs and GDPR  and ask what more can be done to ensure compliance. &lt;/p&gt;&lt;h2&gt;&lt;b&gt;Why GDPR matters&lt;/b&gt;&lt;/h2&gt;&lt;p&gt;Before we look at what has happened over the past year, it’s worth noting of  of what’s at stake for SMEs. Under GDPR, if a business suffers a data breach and is found not to have implemented appropriate data protection measures, it faces fines of as much as 4% of its global turnover. As well as the significant brand damage that can occur with large scale data breaches and the resulting loss of customer confidence, ensuring GDPR compliance couldn’t be more important for firms of all sizes, as they would also suffer from the financial consequences.  &lt;/p&gt;&lt;h2&gt;&lt;b&gt;The fines have started&lt;/b&gt;&lt;/h2&gt;&lt;p&gt; Over the past year regulators in Europe have shown that they are ready to start checking who is following the law correctly and start fining those who are not.. In the UK, for example, the &lt;a href=&quot;https://ico.org.uk/&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Information Commissioner’s Office&lt;/a&gt; (ICO) has &lt;a href=&quot;https://www.computerweekly.com/news/252467726/GDPR-taken-more-seriously-after-first-fines&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;announced its intention&lt;/a&gt; to fine British Airways and Marriott International £183 million and £99 million respectively for recent data breaches. According to the International Association of Privacy Professionals, the first year of GDPR &lt;a href=&quot;https://iapp.org/resources/article/gdpr-one-year-anniversary-infographic/&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;saw a total of&lt;/a&gt; €56 million in fines. . While the headlines have focused on large enterprises, SMEs should be under no illusion that the regulators won’t come for them. &lt;/p&gt;&lt;h2&gt;&lt;b&gt;Are SMEs prepared?&lt;/b&gt;&lt;/h2&gt;&lt;p&gt;According &lt;a href=&quot;https://www.computerweekly.com/news/252467207/Almost-a-third-of-European-firms-still-not-compliant-with-GDPR&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;to a study&lt;/a&gt;, 30% of European firms  lack confidence that their business is compliant. The research also found that 21% of mid-market businesses admit having no cybersecurity strategy in place. &lt;/p&gt;&lt;p&gt;Statistics like these suggest that when it comes to GDPR many businesses are sticking their heads in the sand and hoping they will go unnoticed by regulators and cybercriminals alike. For such firms, the risk of receiving fines for non-compliance are very high. &lt;/p&gt;&lt;h2&gt;&lt;b&gt;GDPR compliance need not be complicated&lt;/b&gt;&lt;/h2&gt;&lt;p&gt;The good news is that once a company realises that it has no choice but to act on GDPR rules, there are a number of solutions available. Such tools enable firms to, for example, rapidly carry out data protection impact assessments on projects so they can ensure the work carried out is GDPR compliant from day one. &lt;/p&gt;&lt;p&gt;The challenge you may find is knowing which software package to choose. Different GDPR compliance software services come with different features such as access control, compliance management, consent management and sensitive data identification, and knowing which will meet your specific compliance shortfalls can be a challenge. &lt;/p&gt;&lt;h2&gt;&lt;b&gt;Make GDPR ‘year two’ a success&lt;/b&gt;&lt;/h2&gt;&lt;p&gt;GDPR is now in full effect and momentum is gathering around regulatory action, so  if you have left your GDPR preparations this long, now really is the time to act. The regulation applies equally to SMEs as it does to large enterprises. &lt;/p&gt;&lt;p&gt;Fortunately, the market has what you need to achieve compliance rapidly – visit our  &lt;a href=&quot;/directory/31309/gdpr-compliance/software&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;GDPR compliance software list&lt;/a&gt; to search over 125 available solutions today and take a step closer to compliance. &lt;/p&gt;","dateModified":"2022-11-15T20:30:57.000000Z","headline":"GDPR turns one – is your SME compliant?","mainEntityOfPage":"https://www.capterra.co.uk/blog/840/gdpr-turns-one-is-your-sme-compliant#webpage"}]}
</script>
