GDPR readiness for startups
Start with the personal data you collect and why you use it. Check whether GDPR applies and whether you decide how the data is used, act on a customer's instructions, or do both for different activities. These are controller and processor roles. Your responsibilities depend on the role you have.
New to compliance? Start with the shared foundations, then return here for the GDPR path.
By Sythe Labs Team · Sources reviewed September 14, 2026
Use this guide to plan the work. Confirm which requirements apply and what the review needs to cover with your auditor or adviser. EDPB: guidance for small businesses.
- Start here if
- Your business uses personal data and needs to establish which GDPR responsibilities apply.
- What to have ready
- Bring a list of the data you collect, why you collect it, the providers you share it with, and your existing privacy notices.
Read the steps in order, or jump to the one you need. The highlight shows your selected step, not completed work.
1. List the data you use
List the personal data you collect, why you use it, whose data it is, where it is stored, and who receives it. For each use, check whether GDPR applies and whether you decide how the data is used or handle it on someone else's instructions.
EDPB: controller and processor roles
Record to keep: A list of how you use personal data and your responsibility for each use.
2. Document the decisions
Check the legal reason for each use of personal data, what you tell people, how long you keep it, and the agreements with providers. Review transfers between countries and flag any uses needing a closer assessment.
EDPB: lawful use of personal data
Record to keep: The reasons for using and keeping data, the notices you give people, and agreements with providers.
3. Make procedures work
Practice responding when someone asks for a copy of their data or asks you to delete it. Check that data is removed when it should be and that staff know how to report a security incident. Test the protections appropriate to the data you use and save the results.
EDPB: responding to individuals' rights
Record to keep: Records of requests, decisions about keeping or deleting data, and security checks.
4. Review new uses
Review new uses of personal data and new providers before you introduce them. Update your privacy notices and records when practices change, and check whether those changes introduce new risks.
Record to keep: Decisions about new data uses and providers, with updated notices and supporting records.
A deletion request reaches engineering
A software startup receives a deletion request and discovers that account data also appears in support tickets and an analytics service. Deleting the production row would leave the request unresolved across the other systems.
The team checks who is responsible for answering the request, verifies the person's identity, and checks whether any data must be kept. It works through the systems involved and records what was deleted, what was kept, and why. Practicing with made-up data can reveal missing steps before a real request arrives.
Check your preparation
Can the responsible owner trace a request through the relevant systems and explain what was done, what was retained, and why?
This helps you find unfinished work. It is not an audit result.
Questions for your team
- For each processing activity, are you acting as controller or processor?
- Do your privacy notices and rules for keeping data match what the product actually does?
- Who reviews new uses of data, providers, and transfers between countries before launch?
What is your next GDPR task?
Choose one task from the guide, assign someone to resolve it, and agree on what they will bring back. Download your notes before leaving this page; they are not saved between visits.
________________________________
________________________________
________________________________
________________________________
Supporting articles, sources, and templates
When you have worked through this route, return to your startup compliance plan to assign the remaining work and ongoing reviews.