AI is moving fast. See how Whisperly helps you get control back and reduce risk.See how →
    Data Protection 21 min read

    GDPR for Startups: What the 250-Employee Myth Is Costing You

    No size exemption exists under GDPR. A practical guide to applicability, the 250-employee myth, the five enforcement triggers that hit startups first, and a 12-step compliance checklist.

    Tijana Zunic
    Tijana Zunic| CEO & Co-founder, Whisperly
    Published: · Last reviewed: · Reviewed by: Jelena Djukanovic, Attorney at Law, Data Protection, IT Law and AI Law, Zunic Law Firm
    Last updated:
    GDPR for startups: no size exemption exists. The 250employee myth, 5 enforcement triggers, and a 12step compliance checklist for founders.

    If your data processing is illegal, it does not only expose your startup to high penalties. It leads to two outcomes that no founder plans for and no investor tolerates.

    For founders, this is the GDPR for startups problem in one paragraph: lawful basis is not a paperwork question, it determines whether the customer data you have built your company on is yours to keep.

    The first: your exit gets blocked or discounted. Acquirers and investors conduct data protection due diligence at Series A and beyond. An unlawful customer database, a missing consent mechanism, or a stack of unsigned Data Processing Agreements are not remediation items on a closing checklist. They are valuation deductions or deal killers. Several EU-based acquisitions of SaaS companies have collapsed at the final stage specifically because the target could not demonstrate lawful basis for its core user data processing.

    The second: you may be ordered to erase your customer database. Under GDPR Article 58(2)(d), supervisory authorities have the power to order a temporary or permanent ban on processing, and under Article 17, they can mandate erasure of unlawfully processed data. Your customer list, usage history, and behavioural data may be the most valuable asset on your balance sheet. If it was built without a valid lawful basis, it can be taken from you by regulatory order. This is not a theoretical risk: the German and French supervisory authorities have both issued data deletion orders against companies whose consent collection was found to be invalid.

    These are the stakes, and they sit at the centre of GDPR for startups in 2026. The rest of this guide tells you what to do about them.

    Most founders building a startup learn about GDPR for startups the same way: a prospect's legal team flags it during due diligence, or an enterprise customer's procurement questionnaire asks for a DPA the startup has never signed. By that point, the deal is paused and the clock is running.

    GDPR applied to your startup the moment your first EU resident created an account. Not when you hired a DPO. Not when you raised a round. Not when you crossed 250 employees. There is no size threshold in the regulation, and the persistent belief that there is has cost founders deals, created regulatory exposure, and in a growing number of cases resulted in supervisory authority investigations. Cumulative GDPR fines across EU member states now exceed EUR 7.1 billion (CMS GDPR Enforcement Tracker, 2025), with enforcement accelerating sharply since 2023.

    For the full GDPR compliance framework including all data subject rights, transfer mechanisms, and accountability obligations, see our GDPR compliance pillar guide. This article focuses on what is specific to GDPR for startups: the applicability questions, the early-stage obligations, and the mistakes that trigger enforcement first.

    1. Does GDPR Apply to Your Startup?

    TL;DRYes, if you process personal data of anyone in the EU. GDPR's territorial scope under Article 3 is deliberately wide: it catches any organisation that offers goods or services to EU residents, or monitors their behaviour, regardless of company size, revenue, or where the organisation is incorporated. A solo founder with three EU beta testers is subject to GDPR in exactly the same way as a 500-person scale-up.

    If any of the following are true, GDPR applies to your startup, and it applied from day one:

    • You have an office, employee, or stable presence in any EU member state. A single remote EU-based contractor can create an establishment under Article 3(1).
    • You offer goods or services to people in the EU. This includes EU-specific pricing, accepting EU payment methods, EU-language interfaces, or simply having EU users sign up for your product.
    • You monitor the behaviour of people in the EU. Analytics tracking, behavioural profiling, cookie-based retargeting, and location data collection all qualify under Article 3(2).

    UK GDPR: The Same Rules Apply If You Serve UK Residents

    • If you offer goods or services to individuals in the United Kingdom, or monitor their behaviour, UK GDPR applies to your startup independently of EU GDPR. UK GDPR is the retained EU law version of GDPR, amended by the Data (Use and Access) Act 2025. Its core obligations, including lawful basis, data subject rights, DPIAs, and processor agreements, are substantively identical to EU GDPR. For a full comparison of the two frameworks, see our guide to UK GDPR compliance in 2026.
    • If your startup is based outside both the EU and the UK but processes personal data of UK residents, you must designate a UK Representative under Article 27 UK GDPR, in addition to any EU Representative required under EU GDPR Article 27. These are separate appointments and cannot be satisfied by the same individual unless they are based in the relevant jurisdiction.
    • The UK adequacy decision, which allows personal data to flow freely between the EU and the UK, is subject to periodic review. Startups transferring data in both directions should monitor its status and have Standard Contractual Clauses available as a fallback transfer mechanism.

    The DPA Trigger: When GDPR or UK GDPR Applies Through Your Customer Contracts

    Even where none of the territorial conditions above are satisfied, GDPR or UK GDPR may still apply to your startup through the Data Processing Agreements you sign with your customers.

    If your customer is a GDPR-regulated controller and they appoint your startup as a processor under Article 28, the DPA between you will require your startup to process personal data in accordance with GDPR. This contractual obligation is legally binding regardless of whether GDPR would otherwise apply to you directly. In practice, this means a startup based in Australia with no EU establishment, no EU marketing, and no EU monitoring may still find itself bound by GDPR Article 28 obligations because its enterprise customer insists on a GDPR-compliant DPA as a condition of the contract.

    The same logic applies to UK GDPR. A UK-based customer appointing your startup as a processor will require a UK GDPR-compliant DPA. Non-compliance with the DPA terms is both a regulatory risk (your customer faces enforcement if their processor is non-compliant) and a contractual risk (material breach of the DPA can trigger termination clauses and indemnity obligations).

    The practical consequence: review every enterprise contract in your pipeline for data processing provisions before signing. If a customer DPA requires you to process data in accordance with GDPR, you are operationally subject to those obligations from the moment the contract is executed, regardless of your own jurisdictional position.

    The regulation makes no exemptions based on employee count, revenue, or funding stage, and that is the foundational fact for any honest discussion of gdpr for startups in 2026. GDPR has no equivalent of the FTC's "small business" exemption or CCPA's revenue threshold. The question is solely whether you process personal data of EU residents. If you do, you comply.

    2. The 250-Employee Myth: What Article 30(5) Actually Says

    TL;DRArticle 30(5) GDPR provides a narrow exemption from the full Records of Processing Activities (RoPA) obligation for organisations whose processing is occasional, unlikely to create risk, and does not involve special category data. Most tech startups fail all three conditions simultaneously. The "fewer than 250 employees" phrasing that circulates in founder communities is a misreading of a secondary clause, not a genuine exemption. You need a RoPA, and it is the single most useful document in any practical gdpr for startups programme.

    The 250-employee figure comes from a misreading of Article 30(5), which states that the RoPA obligation does not apply to organisations employing fewer than 250 persons "unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data."

    Read that carefully. It is a triple-condition exemption structured as a double negative. The exemption applies only where processing is occasional and unlikely to result in risk and does not involve special category data. A startup running a CRM, product analytics, marketing emails, or an HR system fails all three conditions simultaneously. Every contact in your CRM represents non-occasional processing. Every user in your product analytics tool represents monitoring behaviour. The exemption does not apply to you.

    Think of the Article 30(5) exemption like a building insurance exclusion for "ordinary wear and tear": technically it exists, but the moment anything happens to the building, you find out it does not cover your situation. The RoPA exemption exists for a parish council that processes members' names once a year. Not for a SaaS product with daily active users.

    The practical consequence: every startup that has been told it does not need a RoPA because it has fewer than 250 employees has been given incorrect advice. Build your Record of Processing Activities now. It is also the most operationally useful compliance document you will produce.

    Building a RoPA is also, in practical terms, the only way to achieve genuine oversight of your data processing. Without a structured record, you cannot answer the most basic compliance question a regulator, acquirer, or enterprise customer will ask: what personal data do you hold, where does it go, and on what legal basis are you processing it? Founders who discover they cannot answer those questions during due diligence typically discover it at the worst possible moment.

    That oversight cannot be built in a spreadsheet. A RoPA is a live document. It changes every time you integrate a new vendor, launch a new product feature, onboard a new category of user, or enter a new market. An Excel file maintained by one person, updated quarterly if remembered, and disconnected from the actual systems that process data is not a RoPA in any meaningful compliance sense. It is a snapshot that is out of date the moment it is saved. Automated RoPA maintenance connects directly to your processing activities as they evolve, so the record reflects your actual data architecture rather than your best recollection of it six months ago.

    3. GDPR for Startups: What Personal Data You Actually Process

    TL;DRPersonal data under GDPR is any information that identifies or can identify a living individual. For a typical SaaS startup, this covers: email addresses, names, IP addresses, cookie identifiers, usage logs, device IDs, payment data, support tickets, and anything held in your CRM, analytics platform, or helpdesk. Indirect identifiers count. If you collect it from EU residents, you need a lawful basis for it.

    A seed-stage SaaS product typically processes personal data across six or more systems simultaneously: the product database, email service provider, analytics platform, CRM, support tool, and payment processor. Most founders map only one or two. The rest are invisible compliance liabilities.

    I audited a 30-person fintech startup that believed it had four data flows. The full mapping exercise found eleven, including a marketing automation tool that had a customer support platform sharing ticket data with a US sub-processor under terms that predated the EDPB's 2022 guidance on SCCs, and a data enrichment vendor receiving exported CRM data on a weekly basis with no DPA in place. None of these were intentional. They were the natural accumulation of growth decisions made without a privacy lens.

    Special category data under Article 9 carries significantly higher obligations. It covers health data, biometric data, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, and trade union membership. If your product processes any of these categories, even indirectly through inferred characteristics, you need explicit consent or another Article 9 condition, and a data protection impact assessment before processing begins.

    4. The Six Lawful Bases: Which One Does Your Startup Actually Use?

    TL;DREvery processing activity must have one of six lawful bases under Article 6 GDPR. For startups, three are commonly relevant: contract (core product functionality), consent (marketing, analytics cookies), and legitimate interests (subject to a documented balancing test). Choosing the wrong basis, or failing to document the choice, is a direct enforcement trigger. The lawful basis must be decided before processing begins, not retroactively assigned.

    The six lawful bases and how they apply to a typical startup product:

    Lawful BasisArticle 6Startup Use Case
    Contract6(1)(b)Delivering the product, processing payments, sending transactional emails. Cleanest basis for core functionality. Cannot be used for activities the user could reasonably receive without (e.g. marketing).
    Consent6(1)(a)Marketing emails, analytics cookies, optional personalisation. Must be freely given, specific, informed, unambiguous. Revocable at any time. Consent records must be maintained. Pre-ticked boxes are invalid.
    Legitimate interests6(1)(f)Fraud prevention, security logging, B2B marketing to existing contacts. Requires a documented three-part balancing test. Cannot be used as a catch-all for analytics or profiling.
    Legal obligation6(1)(c)Financial record retention, tax obligations. Straightforward where a specific legal obligation applies. Not a basis for general data collection.
    Vital interests6(1)(d)Life-threatening emergencies only. Rarely applies to tech startups.
    Public task6(1)(e)Public authorities and bodies exercising official authority. Not applicable to private startups.

    Choosing the wrong basis has direct enforcement consequences. In 2023, the Irish DPC fined Meta Ireland EUR 390 million for using contract as the lawful basis for personalised advertising when consent was the appropriate basis. The fine was not for the advertising itself but for the wrong legal basis. Regulators audit lawful basis choices, and they audit the documentation behind them. Your basis choice must be recorded before processing begins, not assigned retrospectively when a complaint arrives.

    For the detailed legal analysis of each basis, see our GDPR compliance framework, lawful basis selection is the single highest-impact decision in GDPR for startups, and the one regulators audit first.

    5. GDPR for Startups: Five Obligations You Must Have in Place

    TL;DRFive obligations form the non-negotiable foundation: a compliant privacy notice provided at the time of collection; a cookie consent mechanism that actually blocks non-essential scripts; a Record of Processing Activities; signed Data Processing Agreements with every vendor handling your users' data; and a documented process for responding to data subject requests within 30 days. All five must be in place before your first EU user signs up, not before your first regulatory contact.

    Privacy notice

    Your privacy notice must tell users: who you are, what data you collect, why (the lawful basis for each activity), who you share it with, where data goes internationally, how long you keep it, and how they can exercise their rights. It must be written in plain language, not legal boilerplate, and provided at the point of data collection. A notice that says "we use cookies to improve your experience" without naming which cookies, which third parties, and which countries is not compliant.

    A cookie banner that announces cookies without blocking them is not compliant. This is the most commonly enforced violation for small organisations in 2025 and 2026. Regulators across Germany, France, and the Netherlands are now scanning websites with automated tools before any human auditor gets involved. If Google Analytics, Meta Pixel, or any other non-essential script fires before the user clicks Accept, you are in violation.

    A compliant banner in 2026 blocks all non-essential scripts until the user makes an active choice; presents Accept and Reject with equal visual prominence (no grey-text Reject button, no oversized Accept button); allows revocation as easily as consent was given; and logs consent records. The fix takes one afternoon with any standard consent management platform, and it removes the most commonly enforced violation in gdpr for startups work today.

    Record of Processing Activities (RoPA)

    Your RoPA is a structured inventory of every processing activity: what data, for what purpose, on which lawful basis, shared with whom, transferred where, and retained for how long. It must be available to your supervisory authority on request. It is also your most practically useful compliance document: it tells you what you are actually doing with data, which is the prerequisite for every other obligation.

    Whisperly automates RoPA population and maintenance. See Records of Processing Activities automation for how Whisperly maps processing activities across your organisation in real time.

    Data Processing Agreements

    Every vendor that processes personal data on your behalf is a processor under Article 28. You need a signed Data Processing Agreement with each one before processing begins. This means your cloud provider, email platform, analytics tool, CRM, support helpdesk, and any SaaS tool in your stack that touches user data. Most major vendors have standard DPAs available on request. For smaller vendors, the EDPB's standard contractual clauses provide a baseline.

    Data subject rights process

    GDPR gives individuals eight rights: access, rectification, erasure, restriction, portability, objection, and rights relating to automated decision-making. You have 30 days to respond to any request, at no charge. Build the intake mechanism, workflow, and response templates before the first request arrives. The supervisory authority clock starts from the moment of receipt. Regulators treat a pattern of late responses or non-responses as an investigation trigger, not a minor administrative failure.

    6. GDPR for Startups: The Five Enforcement Triggers That Hit First

    TL;DRThe five most common GDPR violations leading to enforcement against small organisations are: non-blocking cookie banners; using legitimate interests without a balancing test; missing DPAs with vendors; ignoring or responding late to data subject access requests; and privacy notices that do not reflect actual data flows. All five are avoidable. All five are enforced systematically by EU supervisory authorities using automated scanning tools.

    Trigger 1: Cookie banner that announces without blocking. The banner exists. Google Analytics fires before the user clicks Accept. This is the single most commonly enforced violation for small organisations in 2025 and 2026. The CNIL in France and the DPA in the Netherlands have made pre-consent script loading a priority enforcement area. The fix takes an afternoon. Not fixing it is a decision.

    Trigger 2: Legitimate interests without a balancing test. Multiple supervisory authorities have fined companies specifically for invoking legitimate interests for analytics, profiling, or marketing without conducting and documenting the required three-part balancing test. The test is not complicated. Failing to document it is.

    Trigger 3: Missing vendor DPAs. If your analytics vendor, email platform, or cloud provider processes personal data on your behalf without a signed DPA, you are in violation of Article 28 for every processing activity involving that vendor. Run through your vendor stack and request DPAs from each one. Most major vendors provide them instantly.

    Trigger 4: Ignoring data subject access requests. You have 30 days. One unanswered DSAR followed by a complaint to the supervisory authority is sufficient to open a formal investigation. Build the process before the first request, not after.

    Trigger 5: Privacy policy that does not reflect actual data flows. Regulators compare what your privacy notice says with what your cookies, network requests, and vendor contracts show. A policy copied from another startup, or one that predates integrations you have added since launch, will have discrepancies. Discrepancies are findings. Your notice must reflect your actual data architecture as it stands today.

    7. GDPR for Startups: When You Need a Data Protection Officer

    TL;DRMost early-stage startups do not require a mandatory DPO. Article 37 mandates a DPO for public authorities, organisations conducting large-scale systematic monitoring of individuals, and organisations processing special category or criminal conviction data on a large scale. The judgment is on "large scale": regulators consider volume, geographic scope, duration, and the proportion of the population affected. Where not mandatory, many growth-stage startups appoint one voluntarily for enterprise sales credibility.

    The DPO question matters most at two inflection points: when you start targeting enterprise customers in regulated industries, and when your data processing scale increases materially. Enterprise procurement teams in financial services, healthcare, and the public sector routinely ask for DPO contact details as part of vendor due diligence. Not having a named DPO is not a disqualifier, but it slows the process and flags a gap that their legal teams will pursue.

    If your startup is based outside the EU but serves EU residents on a non-occasional basis, you are also required under Article 27 to designate an EU Representative. This is separate from the DPO requirement and is frequently overlooked by non-EU founders. It applies as soon as processing is non-occasional, which in practice means it applies from the moment you have regular EU users. Failure to appoint an EU Representative is a standalone infringement with its own fine exposure under Article 83(4).

    8. GDPR for Startups and AI: What Founders Miss in 2026

    TL;DRIf your product uses machine learning, automated scoring, or any processing that produces decisions with significant effects on users, you have additional GDPR obligations. Article 22 gives individuals the right not to be subject to solely automated decisions with significant effects. Any AI system that falls into a high-risk category under the EU AI Act and processes personal data will require both a DPIA and an EU AI Act fundamental rights impact assessment. Consent obtained for the original service does not extend to model training without a separate lawful basis analysis.

    The most common mistake among AI-powered startups is treating the EU AI Act as the privacy compliance framework and GDPR as something separate. They are not alternatives. They are parallel obligations that interact. An AI system can be compliant with EU AI Act transparency requirements and simultaneously in breach of GDPR because it processes personal data without a valid lawful basis, or uses training data that was collected for a different purpose.

    The practical consequence: if you are training a model on user data from your existing product, you need a fresh lawful basis analysis. The consent or contract basis that covers delivering the product does not automatically extend to using that data to train a model. The EDPB has been explicit on this point in its guidelines on AI and data protection. Getting this wrong at seed stage becomes significantly more expensive to remediate at Series B, when the model is embedded in the product and the training data is years old.

    9. GDPR for Startups as a Commercial Advantage

    TL;DRGDPR compliance is a commercial prerequisite in B2B markets. Enterprise procurement teams in regulated industries require documented evidence of compliance before signing. Investors conduct data protection due diligence at Series A and beyond. Startups that can answer compliance questions with evidence, not promises, close deals faster and spend less on remediation later. The compliance programme you build at seed stage is the same one that passes enterprise legal review at Series B.

    The commercial argument for early compliance is not optimistic. It is actuarial. Enterprise SaaS deals in financial services, healthcare, and the public sector now routinely include security questionnaires with GDPR-specific sections: What is your lawful basis for processing customer data? Do you maintain a RoPA? Where is data stored? Do you conduct DPIAs? Who are your sub-processors? A startup that answers these questions with documented evidence closes those deals. A startup that answers with "we are working on it" loses them or delays them by weeks.

    IBM's 2025 Cost of a Data Breach Report found that the average cost of a data breach for organisations with fewer than 500 employees was USD 3.31 million. For a seed-stage startup, a breach of that magnitude is an existential event. Compliance reduces breach probability and, where a breach occurs despite controls, significantly reduces regulatory fine exposure: Article 83(2) explicitly lists "any action taken by the controller or processor to mitigate the damage suffered by data subjects" as a mitigating factor in fine calculation.

    10. GDPR for Startups: 12-Step Compliance Checklist

    TL;DRUse this checklist to assess your current GDPR posture. Each step maps to a documented obligation under the regulation. If you can evidence all 12, you have the foundations in place. Any gap is a priority action before your next enterprise deal, funding round, or regulatory contact. This checklist is operational, not legal advice: have a qualified data protection attorney review your specific situation.

    1. 1.Territorial scope assessment. Documented analysis of whether GDPR applies to your startup and on what basis: establishment, targeting, or monitoring of EU residents.
    2. 2.Data mapping exercise. Structured inventory of all personal data processed: system, purpose, lawful basis, retention period, and third-party recipients for every category. The output is your RoPA.
    3. 3.Lawful basis documented for each processing activity. Every processing activity has a specified lawful basis, chosen before processing began. Where legitimate interests is used, a balancing test is documented.
    4. 4.Privacy notice live and accurate. Notice reflects actual data flows, is in plain language, is provided at the point of collection, and discloses all processors and international transfers.
    5. 5.Cookie consent operational. A CMP blocks all non-essential scripts until the user makes an active, affirmative choice. Accept and Reject have equal visual prominence. Consent records are logged.
    6. 6.RoPA maintained and current. Article 30 record covers all processing activities, is updated when data flows change, and is available to your supervisory authority on request.
    7. 7.DPAs signed with all processors. Every vendor in your stack that handles personal data has a signed DPA. Sub-processor lists are reviewed at contract renewal.
    8. 8.Data subject rights process operational. Intake mechanism, workflow, and response templates exist. Requests are tracked and answered within 30 days. A log of requests and responses is maintained.
    9. 9.Breach response procedure documented. Written procedure covers detection, containment, severity assessment, 72-hour GDPR data breach notification to the supervisory authority, and data subject communication.
    10. 10.DPO or privacy lead named. A named individual holds responsibility for data protection compliance. If a DPO is mandatory, they are registered with the relevant supervisory authority.
    11. 11.EU Representative appointed if required. Where the startup is based outside the EU but targets EU residents, an Article 27 EU Representative is designated and their details are publicly available.
    12. 12.DPIAs on file for high-risk processing. Any processing likely to result in high risk to data subjects, including AI-driven profiling or large-scale special category data, has a documented DPIA.

    11. How Whisperly Helps Build GDPR for Startups Compliance That Scales

    Manual compliance is manageable at seed stage, but gdpr for startups stops being a spreadsheet problem the moment your data flows multiply. It becomes unmanageable once you have more than a handful of data flows, more than one jurisdiction, and more than one person whose role involves touching user data.

    • RoPA automation: Automated population and maintenance of your Record of Processing Activities across the organisation. Whisperly maps processing activities, assigns lawful bases, tracks retention periods, and keeps the record audit-ready at all times.
    • DPIA module: Guided impact assessments meeting EDPB criteria. Built-in risk scoring, remediation tracking, and sign-off workflows.
    • GDPR vendor management: Track vendor DPAs, review sub-processor lists, monitor contract expiry, and flag gaps before they become findings.
    • Data subject rights tracker: Log incoming requests, assign them, track the 30-day deadline, and maintain a full audit trail.
    • Breach management: Structured workflow covering detection, severity assessment, 72-hour supervisory authority notification, and data subject communication.
    • Multi-jurisdiction mapping: As you expand beyond the EU, Whisperly maps obligations under UK GDPR, CCPA, LGPD, and other frameworks in a single compliance view.

    Final Thoughts

    GDPR compliance is not a project you finish. It is a programme you build, maintain, and mature as the company grows. The startups that treat it as a one-time checkbox exercise spend significantly more on remediation than the founders who build it in correctly from the start.

    Start with the five foundational obligations: privacy notice, cookie consent, RoPA, vendor DPAs, and a data subject rights process. Those five eliminate the majority of your enforcement risk. Then add your DPIA procedure, your breach response plan, and the 12-step checklist above.

    Treat gdpr for startups as the operational discipline it is. GDPR for startups is not inherently complex. It becomes complex when ignored. Every month without a RoPA is a month of processing activities that will need to be reconstructed from memory if a supervisory authority asks. Every vendor DPA you have not signed is a liability in every enterprise deal you are trying to close.

    For the complete GDPR compliance framework including transfer mechanisms, accountability documentation, and all data subject rights obligations, see our GDPR compliance pillar guide. When you are ready to automate your RoPA, DPIAs, vendor management, and data subject rights tracking, book a Whisperly demo to see the platform in action.

    GDPRStartupsData ProtectionRoPACompliance

    Questions & Answers

    Does GDPR apply to my startup if we are not based in the EU?+

    Yes, if you process personal data of individuals in the EU. Article 3 GDPR applies to any organisation that offers goods or services to EU residents, or monitors their behaviour, regardless of where the organisation is incorporated or where its servers sit. A startup based in the US, Israel, or Singapore with EU users is subject to GDPR. You are also required to appoint an EU Representative under Article 27 if processing is non-occasional and you have no EU establishment. Non-compliance with the EU Representative requirement is a standalone infringement.

    Is there a GDPR exemption for startups with fewer than 250 employees?+

    No. The 250-employee figure attached to Article 30(5) is not a general exemption. It relates specifically to the RoPA obligation and applies only where processing is occasional, unlikely to create risk, and does not involve special category data. Most startups running a CRM, analytics platform, or marketing database fail all three conditions simultaneously. GDPR contains no revenue threshold, headcount exemption, or startup carve-out of any kind.

    What is the difference between a controller and a processor, and which is my startup?+

    A controller decides why and how personal data is processed. A processor processes data on behalf of a controller. Your startup is almost certainly a controller in relation to your users: you decide what data to collect, for what purpose, and on what basis. Your vendors, including your cloud provider, email platform, and analytics tool, are typically processors. This distinction determines your obligations: controllers hold primary GDPR responsibility, must have lawful bases and privacy notices, and must sign DPAs with their processors. Some startups are simultaneously controllers toward their users and processors for their enterprise customers, which creates overlapping obligations that require careful structuring.

    What lawful basis should my startup use for product analytics?+

    Consent, in most cases. Analytics cookies that track user behaviour require prior consent under the ePrivacy Directive (Cookie Law), which applies across the EU regardless of GDPR. For server-side analytics that do not use cookies and process anonymised or aggregated data only, legitimate interests may be available if you can demonstrate that the analytics are proportionate and that user interests are not overridden. The key test: if a user knew exactly what data you were processing and for what purpose, would they object? If the answer is probably yes for any significant segment of your users, legitimate interests is not available without further mitigation. Document your analysis either way.

    What are the GDPR fines my startup could face?+

    Article 83 GDPR provides for two fine tiers. The lower tier reaches EUR 10 million or 2% of global annual turnover (whichever is higher) for violations of less fundamental obligations including RoPA requirements, DPO obligations, and processor agreement failures. The upper tier reaches EUR 20 million or 4% of global annual turnover for violations of core principles: lawful basis, data subject rights, and international transfer rules. Supervisory authorities also issue processing bans, compliance orders, and public reprimands. Cumulative GDPR fines now exceed EUR 7.1 billion (CMS GDPR Enforcement Tracker, 2025).

    When does my startup need to conduct a Data Protection Impact Assessment?+

    A DPIA is mandatory under Article 35 GDPR when processing is likely to result in high risk to data subjects. The EDPB identifies nine risk criteria including: systematic profiling with significant effects; large-scale processing of special category data; automated decision-making with legal or similarly significant effects; systematic monitoring of publicly accessible areas; and use of new technologies. In practice, any startup using AI to make decisions about users, processing biometric or health data, or conducting large-scale behavioural profiling needs a DPIA before that processing begins.

    Tijana Zunic

    Written by

    Tijana Zunic

    CEO & Co-founder, Whisperly

    Reviewed by: Jelena Djukanovic, Attorney at Law, Data Protection, IT Law and AI Law, Zunic Law Firm

    Share
    Get Started

    Ready to make compliance
    feel effortless?

    Join 100+ companies automating GRC with Whisperly. Get audit-ready in weeks, not months.

    Stay ahead of compliance changes

    Practical compliance tips, delivered to your inbox every two weeks.