GDPR compliance rests on 10 obligations, in this order: (1) establish a lawful basis for every processing activity (Art. 6), (2) record those activities in a ROPA (Art. 30), (3) tell people what you do with their data (Arts. 13-14), (4) answer data subject rights requests within one month (Arts. 15-22), (5) run a DPIA before high-risk processing (Art. 35), (6) put an Art. 28 contract in place with every processor, (7) cover international transfers with an adequacy decision or SCCs (Chapter V), (8) apply appropriate technical and organisational security (Art. 32), (9) notify breaches within 72 hours (Art. 33), and (10) delete data once the retention period expires (Art. 5(1)(e)). Failure on any one of them can trigger fines of up to €20 million or 4% of global annual turnover.
There is no partial version of this list. A supervisory authority that opens an investigation into one complaint — usually an unanswered access request or a cookie banner — will audit the other nine. This guide walks through each obligation with the article reference, the concrete deliverable it demands, and the enforcement record that shows what regulators actually sanction. Because storage limitation and security are where most organisations fail in practice, and where 2025-2026 enforcement has concentrated, obligations 8 and 10 are covered in greater depth than the rest.
The General Data Protection Regulation (GDPR) applies to any organisation established in the EU, and to any organisation outside the EU that offers goods or services to people in the EU or monitors their behaviour (Art. 3). Whether you are a startup or a multinational, the ten obligations are identical; only the proportionality of the measures changes.
Key Takeaways
- Ten obligations, no “GDPR-lite” — Arts. 6, 30, 13-14, 15-22, 35, 28, 44-49, 32, 33 and 5(1)(e).
- The ROPA (Art. 30) is the load-bearing deliverable: every other obligation reads from it.
- Rights requests must be answered in one month; breaches notified in 72 hours.
- Undocumented “just-in-case” retention is now an independent basis for sanction.
- Top-tier fines reach €20M or 4% of global annual turnover (Art. 83(5)).
- The CNIL alone issued 83 sanctions totalling €486.8 million in 2025, against roughly €55 million in 2024.
The 10 GDPR compliance obligations at a glance
| # | Obligation | Article | Deliverable |
|---|---|---|---|
| 1 | Lawful basis for each activity | Art. 6 (Art. 9 for special categories) | Lawful basis register |
| 2 | Record of processing activities | Art. 30 | ROPA |
| 3 | Transparency and information | Arts. 12-14 | Privacy notice, layered notices |
| 4 | Data subject rights | Arts. 15-22 | Rights workflow, 1-month SLA |
| 5 | Data protection impact assessment | Art. 35 | DPIA for high-risk processing |
| 6 | Processor governance | Art. 28 | Signed DPAs, processor register |
| 7 | International transfers | Arts. 44-49 | Transfer map, SCCs, TIA |
| 8 | Security of processing | Art. 32 | Encryption, access control, testing |
| 9 | Breach notification | Arts. 33-34 | 72-hour playbook, breach register |
| 10 | Storage limitation and deletion | Art. 5(1)(e) | Retention schedule, deletion evidence |
Two cross-cutting requirements sit alongside the ten: appointing a Data Protection Officer where Art. 37 triggers apply, and accountability (Art. 5(2)) — the obligation not merely to comply but to be able to demonstrate compliance on demand.
1. Establish a lawful basis for every processing activity
Article 6 lists six lawful bases: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Every processing activity needs exactly one, chosen before processing begins and documented. You cannot switch basis retroactively when the first one fails — a point the CNIL and the EDPB have both made repeatedly in cookie and direct-marketing cases. See our guide to Article 6 lawful bases for the decision tree, and the legitimate interest assessment for the three-part test that legitimate interests requires.
Special categories of data — health, biometrics, religion, trade union membership, sexual orientation, political opinions — need a second gateway under Article 9(2) on top of the Article 6 basis. In practice this usually means explicit consent or a substantial public interest laid down in national law.
2. Build the Record of Processing Activities (Art. 30)
The ROPA is the spine of a compliance programme. It lists, per processing activity: the purpose, the lawful basis, the categories of data subjects and data, the recipients, the transfers outside the EU, the retention period, and a general description of the security measures. Every other obligation on this list reads from it — your privacy notice, your retention schedule, your transfer map and your breach assessments are all derived views of the ROPA.
Organisations with fewer than 250 employees are nominally exempt (Art. 30(5)), but the exemption falls away if the processing is not occasional, is likely to result in a risk to rights and freedoms, or involves special categories — which covers almost every SaaS, e-commerce or HR operation. See our record of processing activities guide and the Article 30 data fields template.
3. Tell people what you do with their data (Arts. 12-14)
Articles 13 and 14 set out what must be disclosed when data is collected from the individual and when it is obtained elsewhere. The list is prescriptive: identity of the controller, contact details of the DPO, purposes and lawful basis, recipients, transfers and the safeguards used, retention period or the criteria used to set it, the full set of rights, the right to lodge a complaint, and whether provision of the data is a statutory or contractual requirement. Article 12 adds the form requirement — concise, transparent, intelligible, in clear and plain language. Our GDPR information notices guide sets out the drafting patterns that survive a DPA review.
4. Answer data subject rights requests within one month (Arts. 15-22)
Individuals have the right of access, rectification, erasure, restriction, portability, objection, and the right not to be subject to solely automated decisions with legal or similarly significant effects. The response deadline is one month from receipt (Art. 12(3)), extendable by two further months for complex or numerous requests, provided the individual is told within the first month and given reasons.
The right of access is the single most complained-about right in Europe and the most frequent trigger for enforcement. A compliant response is not a database dump: it is a copy of the data plus the Article 15(1) contextual information. See our right of access guide, the data subject access request procedure and the right to erasure.
5. Run a DPIA before high-risk processing (Art. 35)
A Data Protection Impact Assessment is mandatory where processing is likely to result in a high risk to rights and freedoms — in particular for systematic and extensive profiling with legal effects, large-scale processing of special categories, and large-scale systematic monitoring of publicly accessible areas. The EDPB’s WP248rev.01 criteria and each national authority’s mandatory DPIA list determine the trigger. The DPIA must describe the processing, assess necessity and proportionality, evaluate the risks, and set out the mitigating measures. See our DPIA guide.
6. Govern your processors (Art. 28)
Every processor must be bound by a written contract containing the eight mandatory clauses of Article 28(3): processing only on documented instructions, confidentiality undertakings, Article 32 security, sub-processor authorisation, assistance with rights requests, assistance with Arts. 32-36, deletion or return at the end of the service, and the obligation to make available all information needed to demonstrate compliance and submit to audits. Controllers remain liable for their processors’ failures, which makes due diligence before signing more valuable than any clause after. See the controller vs processor distinction and what a data processor is.
7. Cover your international transfers (Chapter V)
Personal data may leave the EEA only under an adequacy decision (Art. 45), appropriate safeguards such as Standard Contractual Clauses or Binding Corporate Rules (Art. 46), or a narrow derogation (Art. 49). Since Schrems II, SCCs alone are not enough: the exporter must run a Transfer Impact Assessment on the destination country’s surveillance law and add supplementary measures where the assessment shows the clauses cannot be honoured in practice. See our cross-border transfers guide, Article 44 on transfers to third countries and the transfer impact assessment guide.
8. Secure the processing (Art. 32)
Article 32 requires technical and organisational measures appropriate to the risk, and names four: pseudonymisation and encryption, ongoing confidentiality/integrity/availability/resilience, the ability to restore availability after an incident, and a process for regularly testing and evaluating effectiveness. This obligation is developed in detail below under Best Practices for GDPR-Compliant Data Storage and Technical Implementation.
9. Notify breaches within 72 hours (Arts. 33-34)
A personal data breach must be notified to the supervisory authority within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to rights and freedoms. Where the risk to individuals is high, they must also be informed without undue delay (Art. 34). Article 33(5) requires an internal register of every breach — including those not notified — with the facts, effects and remedial action. The register, not the notification, is what a DPA asks for first. See our breach notification playbook, Article 33 notification to the authority and Article 34 communication to individuals.
10. Delete data when the retention period expires (Art. 5(1)(e))
Storage limitation is where the largest volume of 2025 enforcement landed, and the remainder of this guide covers it in operational depth: how to set retention periods, how to prove deletion, and what regulators found when they audited 764 controllers across Europe.
Storage, retention and security in depth
Understanding GDPR Data Storage Requirements
The GDPR outlines specific principles that govern the storage of personal data, ensuring organizations handle information responsibly and protect individual privacy rights. Key principles related to data storage include data minimization, storage limitation, integrity and confidentiality, and accountability. These principles form the foundation of GDPR compliance and must be diligently applied to all data storage practices.
Data minimization requires organizations to collect only the data essential for their defined purposes. By avoiding excessive data collection, businesses can reduce storage burdens and lower risks associated with retaining unnecessary information. This practice not only ensures compliance but also improves operational efficiency by focusing resources on critical data management tasks. The official texts on data minimisation and storage limitation show how these two principles interlock.
The storage limitation principle dictates that personal data must not be retained longer than necessary for the purposes for which it was collected. Organizations must establish clear retention periods based on the data’s purpose and ensure timely deletion or anonymization once the data is no longer needed. Adhering to this principle helps prevent data accumulation, reduces storage costs, and aligns with GDPR mandates (the official EUR-Lex text of Article 5 storage limitation sets the exact wording).
Integrity and confidentiality demand that organizations implement appropriate security measures to protect personal data from unauthorized access, disclosure, alteration, or destruction. This involves deploying advanced encryption techniques, establishing robust access controls, and conducting regular security assessments to ensure data remains secure and unaltered. Ensuring data integrity and confidentiality not only complies with GDPR but also safeguards against potential data breaches and cyber threats.
Legal Obligations and Responsibilities
Compliance with GDPR data storage requirements is mandatory for organizations operating within the EU or handling data of EU citizens. Failure to adhere can lead to severe legal repercussions, including hefty fines and reputational damage. Understanding and implementing necessary measures to achieve compliance is essential for safeguarding your organization against potential legal challenges.
Data controllers determine the purposes and means of processing personal data, while data processors manage data on behalf of controllers. Both roles carry distinct responsibilities concerning data storage and protection to ensure GDPR compliance. Clearly defining these roles fosters accountability and facilitates effective data management across the organization.
Non-compliance with GDPR can incur substantial fines, reaching up to €20 million or 4% of an organization’s global annual turnover, whichever is higher. Notable cases include the British Airways GDPR Fine, the Marriott GDPR Penalty, and the H&M GDPR Violation. These instances highlight the financial and reputational consequences of failing to comply with GDPR data storage requirements.
Best Practices for GDPR-Compliant Data Storage
Achieving GDPR data storage compliance requires implementing best practices that ensure data is managed securely and efficiently. The following strategies are essential for maintaining compliance and protecting personal data.
Implementing robust encryption is a foundational security measure. Encrypting personal data both at rest and in transit ensures that, even if data is intercepted or accessed without authorization, it remains unreadable and secure. Advanced encryption standards, such as AES-256, are recommended for formidable data protection, aligning with GDPR’s stringent security requirements. Regularly updating encryption protocols and conducting encryption audits are critical for maintaining data security.
Restricting access to personal data solely to authorized personnel is imperative. Utilizing role-based access controls (RBAC), multi-factor authentication (MFA), and conducting regular access reviews can prevent unauthorized data access and bolster security. These measures ensure that only individuals who need access to data can obtain it, mitigating the risk of internal breaches and maintaining data integrity.
Conducting regular data audits helps organizations inventory stored data, assess its relevance, and verify compliance with retention schedules. Audits are pivotal in identifying and rectifying potential vulnerabilities in data storage practices. Establishing a routine audit schedule and utilizing automated audit tools can enhance the efficiency and accuracy of data audits.
The importance of rigorous data storage governance was underscored by the EDPB’s 2025 Coordinated Enforcement Framework report on the right to erasure, adopted on 10 February 2026. The action involved 32 supervisory authorities auditing 764 controllers across Europe, and it revealed persistent gaps: half of the responding DPAs reported that many controllers have no specific procedures for erasure in back-up systems, with some controllers not deleting data from backups at all. The report also flagged that many anonymization techniques deployed as a substitute for permanent deletion were weak and amounted to mere pseudonymization. These findings highlight the critical need for organizations to implement automated data lifecycle management, including robust retention schedules and verified deletion workflows, as part of their GDPR data storage compliance strategy.
Enforcement of the storage-limitation principle intensified sharply in 2025: the CNIL issued 83 sanctions for a total of €486.8 million, against roughly €55 million in 2024. Several decisions rested squarely on Art. 5(1)(e) GDPR. The CNIL fined Free Mobile €42 million in part for keeping former subscribers’ data with no sorting or deletion process once retention was no longer justified. CALOGA was fined €80,000 because a prospect’s data could be retained indefinitely, its clock resetting each time an email was opened. PAP was fined €100,000 for imposing a blanket ten-year retention on certain paying customers’ accounts with no legal justification. The lesson is consistent: undocumented or “just-in-case” retention is now an independent basis for sanction, and the volume of over-retained data is treated as an aggravating factor.
Implementing a GDPR Data Retention Policy
A meticulously defined data retention policy is vital for GDPR compliance. It outlines how long different types of personal data are stored and the methods employed for their secure disposal. Implementing an effective data retention policy involves several critical steps that ensure consistent and compliant data management practices across the organization.
Conducting a comprehensive data inventory is the initial step. Organizations should audit all personal data collected and stored, categorizing it based on type, source, purpose, and sensitivity. Understanding the data held is fundamental for determining appropriate retention periods and ensuring responsible data management.
Defining explicit retention periods for each data category based on legal requirements, business needs, and GDPR principles is essential. For instance, financial records might need to be retained for seven years to comply with tax laws, while marketing data may only be kept for a few years. Establishing specific timeframes aids in maintaining compliance and efficient data management.
Technical Implementation of GDPR-Compliant Data Storage
Ensuring GDPR compliance in data storage requires the integration of robust technical solutions and security measures. The following technical implementations are crucial for maintaining compliance and safeguarding personal data.
Selecting appropriate data storage solutions is paramount. Opt for storage providers that offer built-in security features and compliance certifications. Cloud storage providers such as AWS, Microsoft Azure, and Google Cloud offer GDPR-compliant services with extensive security controls. Evaluating providers based on their compliance capabilities ensures that data storage practices meet legal standards and organizational requirements. From 12 September 2025, the EU Data Act introduced additional requirements for cloud storage providers, mandating interoperable data formats and the elimination of switching fees by September 2027 – organisations should factor these obligations into their data storage vendor selection (European Commission, Data Act Explained).
Deploying advanced encryption techniques fortifies data security. Utilizing strong encryption protocols like AES-256 for data at rest and TLS for data in transit ensures that personal data remains protected against unauthorized access. Encryption acts as a critical barrier against data breaches, aligning with GDPR’s stringent security standards.
Implementing these technical measures secures data and ensures that organizations can efficiently manage and access data in compliance with GDPR standards. Regularly updating security protocols, conducting vulnerability assessments, and utilizing automated security tools are vital for maintaining effective data protection strategies.
Industry-Specific GDPR Data Storage Guidelines
Different industries have unique data storage needs and regulatory requirements. Tailoring GDPR data storage practices to align with specific industry standards is essential for compliance and effective data management. Below are guidelines tailored to various sectors to help organizations implement industry-specific GDPR data storage strategies.
In the healthcare sector, organizations handle highly sensitive personal data, including health records. GDPR mandates stringent data protection measures to ensure patient privacy. Key guidelines include encrypting patient data both at rest and in transit, implementing robust access controls to restrict data access to authorized personnel only, and conducting regular data protection impact assessments (DPIAs) to identify and mitigate risks.
Financial institutions manage vast amounts of personal and transactional data. GDPR compliance in the finance sector involves ensuring data integrity and accuracy through regular audits, implementing robust encryption and security measures to protect financial data, and establishing clear data retention policies that adhere to regulatory mandates, such as retaining financial records for a specified number of years.
E-commerce businesses collect substantial customer data to facilitate transactions and improve user experience. GDPR compliance in e-commerce entails secure data storage systems that protect customer information, transparent data processing policies, and mechanisms for customers to exercise their data rights, such as accessing, correcting, or deleting their data.
Case Studies and Real-World Examples
Analyzing real-world examples offers valuable insights into effective GDPR data storage compliance. The following case studies highlight successful implementations and the lessons learned from these endeavors.
A leading healthcare provider adopted AES-256 encryption for all patient records, both at rest and in transit. By integrating encryption into their data storage systems, they ensured that sensitive health information remained secure and compliant with GDPR requirements. Additionally, they enforced stringent access controls, limiting data access exclusively to authorized medical staff.
A major financial institution overhauled its data retention policies to align with GDPR. They conducted a thorough data inventory, categorizing personal data based on type and purpose. By establishing clear retention periods and automating data deletion processes, they minimized the risk of retaining unnecessary data.
An e-commerce company streamlined its data collection practices by adopting a data minimization approach. They limited data collection to essential information required for transactions and customer service. Implementing clear and concise consent mechanisms ensured customers were informed and provided explicit consent for data processing.
FAQ
What are the main GDPR compliance requirements?
Ten: a lawful basis for every processing activity (Art. 6), a Record of Processing Activities (Art. 30), transparent information notices (Arts. 12-14), a workflow answering data subject rights within one month (Arts. 15-22), a DPIA before high-risk processing (Art. 35), Article 28 contracts with every processor, a lawful mechanism for every transfer outside the EEA (Chapter V), security measures appropriate to the risk (Art. 32), breach notification within 72 hours (Art. 33), and deletion once the retention period expires (Art. 5(1)(e)). A DPO is required on top where the Article 37 triggers apply.
Where should a GDPR compliance programme start?
With the ROPA. Every other obligation is a derived view of it: the privacy notice restates its purposes and recipients, the retention schedule restates its retention column, the transfer map restates its transfers, and breach assessments read its data categories. Building the ROPA first means the remaining nine obligations become editing exercises rather than fresh discovery projects. Our 11-deliverable compliance framework sets out the build order in project form.
How long does GDPR compliance take?
For an organisation of 20-200 employees with a single product and no special category data, a first pass across the ten obligations typically runs three to four months: four to six weeks to interview process owners and build the ROPA, two to three weeks for notices and the rights workflow, two weeks for processor contracts, and the remainder for security measures, retention schedules and the breach playbook. The recurring cost afterwards is the part organisations underestimate — the ROPA has to be maintained as products change, or it decays into a document that describes a company you no longer are.
What is GDPR data storage?
GDPR data storage refers to the methods and practices organizations must follow to store personal data in compliance with the General Data Protection Regulation (GDPR). This includes ensuring data security, implementing appropriate retention policies, and maintaining data integrity.
How long can I store personal data under GDPR?
Under GDPR, personal data should not be kept longer than necessary for the purposes for which it was collected. The retention period varies depending on the type of data and its intended use. Organizations must define and document retention periods based on legal, regulatory, and business requirements.
What are the penalties for non-compliance with GDPR data storage?
Non-compliance with GDPR data storage can result in significant fines, up to €20 million or 4% of an organization’s global annual turnover, whichever is higher. Additionally, organizations may face legal actions, reputational damage, and loss of customer trust.
What measures can I implement to secure stored data?
To secure stored data, organizations should implement strong encryption, access controls, regular data audits, data anonymization techniques, and robust backup and recovery systems. Additionally, conducting regular security assessments and employee training can enhance data protection.
Do I need a Data Protection Officer (DPO) for data storage compliance?
Whether you need a DPO depends on the nature and scale of your data processing activities. Learn more about DPO designation requirements. Organizations that conduct large-scale processing of sensitive data or systematically monitor individuals are required to appoint a DPO. The DPO oversees GDPR compliance, including data storage practices.
Conclusion
GDPR compliance is not a document, it is ten deliverables that have to stay current: a lawful basis register, a ROPA, information notices, a rights workflow, DPIAs, processor contracts, a transfer map, security measures, a breach playbook and a retention schedule with evidence of deletion. Organisations that treat the first nine as one-off projects and the tenth as optional are the ones that appear in enforcement decisions — the 2025 CNIL record of 83 sanctions and €486.8 million rested disproportionately on retention and security failures that would have been caught by an annual review.
Start with the ROPA, work through the list in order, and set a review cadence that matches how fast your product changes. For the same programme expressed as a project plan with 11 named deliverables, see our step-by-step GDPR compliance framework; for the shorter operational version, the GDPR compliance checklist.
Legiscope automates this for you
Stop doing compliance manually. Legiscope's AI handles ROPA creation, DPA audits, and gap analysis — in minutes, not weeks.
Start free trial





