PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteMost small and medium-sized enterprises cannot become GDPR-compliant by publishing a privacy policy alone. A defensible program maps personal data, assigns a lawful purpose and basis to each use, controls suppliers and international transfers, protects information, handles individual requests, and preserves evidence that the controls work.
GDPR can apply to an organisation established in the EU or EEA, and to an organisation outside it that offers goods or services to people there or monitors their behaviour. Employee count does not create a blanket exemption. The European Commission explains the territorial scope here: European Commission GDPR scope guidance.
This checklist is a practical framework, not legal advice. National rules, sector requirements, the UK GDPR and high-risk processing can require specialist advice.
Quick SME GDPR checklist
- Confirm whether EU/EEA GDPR applies and identify whether you are a controller, processor or joint controller.
- Name an executive sponsor and an operational privacy owner.
- Inventory customer, employee, applicant, prospect, patient and supplier data, including inferred and AI-generated data.
- Maintain a record of processing activities (ROPA).
- Document a specific purpose and lawful basis for every processing activity.
- Identify special-category and criminal-offence data.
- Complete a legitimate-interest assessment where that basis is used.
- Decide whether a statutory Data Protection Officer (DPO) or EU representative is required.
- Update privacy notices, forms, cookie controls and marketing disclosures.
- Create a rights-request intake, search and response procedure.
- Review every processor, subprocessor, hosting location and data-processing agreement.
- Assess transfers outside the EEA, including overseas remote access.
- Run Data Protection Impact Assessments (DPIAs) before high-risk processing starts.
- Apply proportionate technical and organisational security controls.
- Set retention, deletion, backup and litigation-hold rules.
- Test breach response and record every incident assessment.
- Keep an evidence file and review it after material changes.
Use the detailed sequence below as an implementation plan. Assign an owner and due date to every item rather than treating the list as a one-time declaration.
#1 Best Overall
Step 1: Confirm whether GDPR applies
Ask these questions first:
- Is the business established in the EU or EEA and processing data as part of its activities?
- Does a business outside the EU or EEA offer goods or services to people there?
- Does it monitor behaviour through profiling, analytics, advertising, location tracking or similar tools?
- Does it handle customer, employee, applicant, patient, student or prospect information?
- Does it use cloud providers, support teams or vendors outside the EEA?
A business may be a controller when it decides why and how data is used, a processor when it acts on a controller’s instructions, or a joint controller when parties jointly decide purposes and means. An employee or contractor normally acts within the organisation’s responsibility and is not automatically an independent processor simply because they handle data.
The EU GDPR and UK GDPR are closely related but separate regimes. If you operate in both markets, check each regime’s territorial rules, notices and transfer arrangements.
Step 2: Assign ownership and check DPO requirements
Document an executive sponsor, day-to-day privacy owner, IT or security owner, HR owner, marketing owner, procurement or vendor owner, incident contact and any external adviser. A privacy lead is not automatically a statutory DPO.
When a DPO may be required
A DPO may be mandatory where regular and systematic monitoring is a core activity, or where large-scale processing of sensitive or criminal-record data is a core activity. Public authorities also have specific DPO obligations. Ask whether the processing is genuinely core, regular, systematic, large-scale or high-risk; if the answer is uncertain, consult the relevant supervisory authority or qualified counsel. The European Commission’s obligations guidance is at commission.europa.eu/law/law-topic/data-protection/information-business-and-organisations/obligations_en.
Free tools Windows power users keep installed
One-click scans. No signup required.
EU representative for non-EU organisations
An organisation outside the EU that targets people in the EU may also need an EU representative, subject to the Regulation’s exceptions. Check this separately from the DPO decision and record the conclusion.
Step 3: Map data and create a ROPA
Start with a spreadsheet if that is sufficient for your scale. The important qualities are accuracy, ownership, version control, review dates and accessibility during an audit or incident.
Rank #2
Minimum data-inventory fields
| Field | Example |
|---|---|
| Processing activity | Customer onboarding |
| Business owner | Head of Sales |
| Purpose | Provide a subscription service |
| Data subjects | Customers and authorised users |
| Data categories | Name, email and billing information |
| Special-category data | None, or specify health, biometric or other data |
| Source | Directly from the customer, partner or public source |
| Role | Controller, processor or joint controller |
| Recipients | CRM, payment provider and support platform |
| Storage locations | CRM, cloud storage and backups |
| International transfer | Destination and safeguard, or none |
| Retention | Period or deletion trigger |
| Security | MFA, least privilege, encryption and logging |
| Rights route | Privacy inbox or portal |
| Lawful basis | Contract, legal obligation, consent or legitimate interests |
| Evidence owner and review date | Named person and specific date |
Search every data source
Check website forms, e-commerce, CRM, email marketing, support, accounting, payment, HR, recruitment, payroll, mobile apps, analytics, advertising tags, CCTV, access systems, paper files, shared drives, employee devices, backups, chatbots, AI tools, contractors and agencies.
Include observed, inferred and derived information: IP and device identifiers, location, behavioural profiles, risk scores, support-ticket classifications, partner imports, automated recommendations and AI-generated classifications.
The EDPB specifically identifies recruitment, payroll, training, access management and prospective-customer lists as processing activities to consider. See EDPB guidance for small businesses.
Do not overread the under-250 rule
Organisations with fewer than 250 employees may have a limited exception for purely occasional processing. It does not generally remove records where processing is regular, risks individuals’ rights, involves special-category data, or involves criminal-conviction or offence data. Most SMEs should maintain a ROPA regardless because it supports notices, supplier reviews, retention, rights requests and incident response.
Step 4: Choose a purpose and lawful basis
For each inventory row, record the precise purpose, necessary data, lawful basis, supporting evidence, retention rule and any secondary use. Reusing data for a new purpose requires a fresh compatibility and transparency analysis.
Possible bases include consent, contractual necessity, legal obligation, vital interests, public task and legitimate interests. The European Commission explains the framework at legal grounds for processing data.
Recommended Free Tools
Rank #3
Examples to analyse
- Payroll: usually legal obligations and contract, with statutory retention rules.
- Delivering a paid service: contract for data necessary to provide it.
- Fraud prevention or network security: potentially legitimate interests, with necessity and balancing documented.
- Marketing: the appropriate basis depends on the channel, relationship, expectations and ePrivacy rules; do not assume one basis covers every message.
- Recruitment: distinguish hiring administration from background checks or sensitive information.
Legitimate-interest assessment
Record the interest, why processing is necessary, individuals’ reasonable expectations, likely impact, safeguards, objection and opt-out routes, balancing conclusion, approver and date. Consent is not a universal fallback: it may be unsuitable where processing is contractually necessary, power is imbalanced or withdrawal would be impractical.
Step 5: Check sensitive data and DPIAs
Flag health, biometric identification, genetic, racial or ethnic-origin, political, religious or philosophical, trade-union, sex-life or sexual-orientation data, plus criminal-conviction or offence data. A notice alone does not make this processing lawful; additional conditions and safeguards may apply.
DPIA decision questions
- Does the activity systematically and extensively evaluate people or profile them with legal or similarly significant effects?
- Is sensitive data processed at large scale?
- Is there large-scale systematic monitoring of publicly accessible areas?
- Does it involve biometric identification, location tracking, vulnerable-person marketing or extensive automated evaluation?
Complete a DPIA before high-risk processing begins and update it when the system, purpose, vendor or risk changes. Document the processing, necessity and proportionality, risks, likelihood and severity, mitigations, residual risk, consultation, approval and review date. If high residual risk remains, prior consultation with the supervisory authority may be required.
Step 6: Fix privacy notices, cookies and marketing
At collection, explain the organisation’s identity and contacts, DPO details if applicable, purposes, data categories, lawful basis, retention or criteria, recipients, international transfers, rights, complaint route, consent withdrawal and relevant automated decision-making. Use the European Commission’s transparency guidance: what information must be given to individuals.
Maintain separate, accurate notices
- Website and customer notice
- Employee and applicant notices
- CCTV and access-control notice
- Cookie and app disclosures
- Event, partner and direct-marketing notices
- Just-in-time notices for unexpected or sensitive uses
Review notices when adding an analytics vendor, moving hosting, launching AI, buying a list, changing retention, introducing advertising or automated decisions. A calendar review is useful, but change-triggered review is essential.
Cookies and electronic marketing
GDPR sits alongside ePrivacy and national rules. Classify necessary, analytics, functionality and advertising technologies; block non-essential trackers until the required consent decision; make refusal as easy as acceptance; avoid pre-ticked boxes; record and withdraw consent; review embedded content and ad-tech recipients; and provide a working unsubscribe and suppression process. The European Commission notes the separate ePrivacy context at its GDPR application guidance. No single banner configuration is valid in every European country.
Step 7: Build a rights-request process
Cover access, rectification, erasure, restriction, portability, objection and rights related to profiling or automated decisions.
Rank #4
- Publish a privacy inbox or web form and train frontline staff to recognise ordinary-language requests.
- Record the receipt date and verify identity proportionately.
- Search relevant systems, suppliers and appropriate backups.
- Check exemptions, third-party confidentiality and legal retention duties.
- Coordinate with processors.
- Respond within the applicable period and record systems searched, decisions and information supplied.
- Escalate complex, manifestly unfounded, excessive or high-risk cases.
Plan for different email addresses, former employees, another person’s data, processor-held records, immutable backups and deletion requests made during an active contract. Erasure is not always immediate or absolute where law requires limited retention or a documented hold.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsStep 8: Review suppliers and processor contracts
For each vendor, record its identity, service, data, purpose, role, subprocessors, hosting locations, transfer mechanism, security, breach-notification timing, rights-request assistance, deletion or return, audit rights, retention and backup practices.
Review CRM, payroll, email marketing, cloud, payment, support, recruitment, accounting, IT, agency, document-signing and AI providers. A data-processing agreement is not a compliance certificate: actual data flows, subprocessors, locations and safeguards must match it. A vendor can be a processor for one service and an independent controller for another, such as its own billing or fraud-prevention use.
Step 9: Review international transfers
Identify every transfer outside the EEA, including overseas support access to EEA-hosted systems. The EDPB describes three cumulative criteria for a Chapter V transfer in its international-transfer guidance for SMEs.
Possible safeguards
- Adequacy decision
- Modern Standard Contractual Clauses (SCCs)
- Binding Corporate Rules
- Limited statutory derogations
The European Commission adopted modernised SCCs on 4 June 2021. Choose the correct module, complete the annexes and document a transfer assessment and supplementary technical and organisational safeguards. See the Commission’s SCC overview and SCC questions and answers.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
United States providers
The EU-US Data Privacy Framework is an adequacy mechanism only for covered transfers to participating US companies. Verify the specific company’s active coverage and relevant scope; it is not blanket approval for every US vendor. The EDPB’s business FAQ version 2.0 is dated 23 January 2026: EDPB EU-US DPF FAQ.
Best Value
Step 10: Apply proportionate security
Controls should reflect sensitivity, volume, access and potential harm. Establish at least:
- MFA, unique accounts and least-privilege access
- Joiner, mover and leaver controls
- Encryption in transit and at rest where appropriate
- Secure backups with restore tests
- Endpoint protection, patching and vulnerability management
- Logging, monitoring and secure configuration
- Vendor security reviews and phishing/privacy training
- Secure disposal, portable-device controls and continuity planning
- Incident escalation and tested recovery procedures
The Commission describes security as risk-based technical and organisational measures, not a fixed technology list: obligations guidance.
Step 11: Prepare for breaches
Include confidentiality, integrity and availability incidents: misaddressed email, stolen device, ransomware, exposed storage, compromised account, accidental deletion, unauthorised access, vendor incidents, lost paper, altered records and outages.
- Report internally and contain the incident.
- Preserve evidence and logs.
- Identify systems, data and affected people.
- Assess risk to individuals and notify the controller or processor counterpart as required.
- Notify the supervisory authority when the applicable risk threshold is met, generally without undue delay and at the latest within 72 hours after becoming aware of a qualifying breach.
- Notify individuals where the risk is high and no exception applies.
- Record decisions, timeline, remediation and lessons learned.
The 72-hour rule does not mean every incident must be reported to a regulator. Every suspected incident should nevertheless be logged and assessed promptly; processors must notify their controller of every personal-data breach.
Step 12: Set retention and deletion rules
For each activity define the period, deletion trigger, legal requirement, backup treatment, litigation-hold process, owner, deletion evidence and review method. Cover customers, leads, contracts, invoices, employee and applicant files, support tickets, CCTV, access and security logs, consent records, rights-request files, incident records and backups. Replace “as long as necessary” with an internal schedule and decision criteria.
How to demonstrate accountability
Maintain an evidence file containing:
- Data inventory and ROPA
- Lawful-basis register and legitimate-interest assessments
- Privacy notices and consent records
- DPIAs and approvals
- Processor agreements and subprocessor register
- Transfer assessments and safeguards
- Retention schedule
- Security policies, access reviews and training records
- Rights-request and breach logs
- Audit results, remediation tracker and management approval
Accountability means being able to show how decisions were made and whether controls operate, not merely possessing policies. The EDPB’s SME guidance covers this evidence approach: EDPB small-business compliance guide.
Prioritised implementation order
- Triage: confirm scope, identify high-risk processing, assign an owner, stop obviously unnecessary collection and open a breach channel.
- Map: inventory systems, vendors, recipients and transfers; create the initial ROPA.
- Justify: assign purposes and bases, flag sensitive data, complete legitimate-interest assessments and decide on DPIAs.
- Inform: update notices, forms, cookie controls, marketing disclosures and consent records.
- Control: update supplier contracts, retention, rights procedures, transfer safeguards and security.
- Respond: test breach and rights-request workflows and vendor escalation contacts.
- Maintain: review after product, vendor, system, country or processing changes; refresh training and close remediation tasks.
Spreadsheet, software or outside help?
When a spreadsheet is enough
A controlled spreadsheet is often adequate for a simple SME with few activities, vendors and transfers, stable data flows and one accountable maintainer.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →When software helps
Dedicated tools become more attractive with many systems or subsidiaries, frequent vendor changes, frequent rights requests, multiple frameworks, customer evidence demands or automated discovery and consent workflows. OneTrust (onetrust.com), DataGuard (dataguard.com), Vanta (vanta.com), Drata (drata.com), Cookiebot by Usercentrics (cookiebot.com), iubenda (iubenda.com) and Osano (osano.com) serve different combinations of privacy, consent, security and evidence workflows. Check current pricing and scope directly; no product determines your lawful basis or guarantees compliance.
When specialist advice is justified
Use an adviser for sensitive or biometric data, large-scale monitoring, significant automated decisions, difficult international transfers, regulatory complaints, serious breaches, acquisitions or complex multi-country arrangements. An internal operational owner supported by external expertise is often more sustainable than outsourcing every decision.
Quick Recap
Copyable compliance tracker
| Requirement | Owner | Status | Evidence | Risk | Due date | Review date |
|---|---|---|---|---|---|---|
| Territorial-scope assessment | ||||||
| Data inventory and ROPA | ||||||
| Lawful-basis register | ||||||
| Privacy notices and consent records | ||||||
| DPIA and transfer assessments | ||||||
| Supplier contracts and security controls | ||||||
| Rights and breach procedures | ||||||
| Retention schedule and evidence file |
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




