Privacy & Data · Pillar Guide

    GDPR Compliance for Tech Companies

    Privacy enforcement is no longer a Big Tech problem. What growth-stage companies need to know now.

    Back to Insights
    Johnathan Aloni, Adv. | Strategic Legal Advisor | Dublin / EU

    Why This Matters Now

    In January 2026, DLA Piper reported that cumulative GDPR fines from May 2018 to January 2026 reached €7.1 billion. More than 60% of that total was issued after January 2023. The EDPB's 2026 Coordinated Enforcement Framework targets transparency obligations under Articles 12, 13, and 14 GDPR, with 25 data protection authorities participating. Coordinated enforcement actions increase the likelihood that transparency failures will be identified, escalated, and followed by targeted supervisory action.

    The enforcement pattern has shifted. Regulators are no longer focused exclusively on the largest players. A €50,000 penalty from a national DPA following a customer complaint, combined with a remediation order and operational disruption, is a serious business event for a company at seed or Series A.

    GDPR applies to companies established in the EU, and to companies outside the EU that target individuals in the EU, offer goods or services, or monitor their behaviour. If any of those conditions apply to your business, the regulation applies to you.

    Five Things Growth-Stage Companies Get Wrong

    1. Treating the Privacy Policy as the Compliance Programme

    A privacy policy is a public commitment. It is not an internal control. A company can have a well-drafted privacy policy and still carry significant regulatory exposure, because the policy describes how data should be handled, while the actual tech stack does something different. Regulators check the gap between the two. The compliance programme is the data map, the processing records, the legal basis documentation, the vendor agreements, and the internal policies. The privacy policy is the public face of that programme. In early-stage companies, the public face exists. The programme behind it often does not.

    2. Assuming Small Companies Are Not Targets

    Spain leads Europe by volume of published GDPR fines, followed by Italy and Romania. The practical exposure for a growth-stage SaaS company is not a €500 million headline fine. It is a €50,000 penalty from a national DPA following a customer complaint, combined with a remediation order and the operational disruption that follows. For a company at seed or Series A, that combination is a serious business event.

    3. Ignoring the US State Law Patchwork

    Around twenty US states have now enacted comprehensive privacy laws, each with different effective dates, thresholds, rights regimes, and enforcement models. California's CPRA is the most demanding, but Virginia, Colorado, Connecticut, Texas, and others impose their own requirements. For an Israeli or European SaaS company with US users, this patchwork creates real exposure that sits completely outside GDPR. The companies most at risk are those that invested in GDPR compliance and assumed that covered their US obligations. It does not.

    Related reading: The US Privacy Minefield

    4. Separating Privacy from Product Architecture

    The companies with the largest enforcement exposure are almost never the ones that ignored privacy entirely. They are the ones that added a privacy layer on top of a product that was not built with privacy in mind. The product collects data the policy does not disclose. The retention timeline in the policy does not match what the database actually does. Third-party integrations were never mapped into the processing records. Retrofitting privacy into existing architecture is always more expensive than building it in from the start.

    Related reading: Data Protection: The Key to Startup Success in Global Markets

    5. Missing the Vendor Risk

    Most growth-stage companies process a significant portion of their users' personal data through third-party tools: analytics platforms, CRM systems, marketing automation, customer support software, payment processors. Where a vendor processes personal data on your behalf, Article 28 requires a Data Processing Agreement. This issue surfaces in fundraising due diligence more than most founders expect. The company believed its privacy position was clean. The data room review found vendor relationships without DPAs, and the process slowed while the gap was addressed.

    The Risk Framework: What Regulators Are Actually Looking For

    Privacy enforcement in 2026 is not primarily about data breaches. Breaches trigger investigations, but the fines that follow are almost always about what was already wrong before the breach occurred. Public enforcement data shows that the violation categories below account for the overwhelming majority of GDPR fine value.

    Unlawful processing (Article 6)

    Insufficient legal basis for processing, weak or manipulative consent mechanisms, failure to establish lawful grounds. This is the single largest source of enforcement action. Analytics tools, advertising pixels, and CRM systems processing personal data without a documented legal basis are the most common exposure.

    Non-compliance with general data processing principles (Article 5)

    Data minimisation failures, purpose limitation violations, retention of data beyond its original purpose. A company that collects more data than it needs, keeps it longer than necessary, or uses it for purposes not disclosed at collection is in this category. This is where the gap between privacy policy and actual practice becomes a fine.

    Insufficient technical and organisational security measures (Article 32)

    The enforcement issue is not merely that an attacker got in. Sanctions focus on inadequate security measures and failures in notifying affected individuals within the required timeframe.

    International data transfers (Articles 44 to 49)

    EU user data transferred to non-adequate countries without a valid legal mechanism remains a high-impact enforcement area. For companies using US-based processors, the EU-US Data Privacy Framework provides a valid transfer mechanism for certified organisations. For non-certified US recipients, Standard Contractual Clauses or another approved tool are required.

    Related reading: Privacy Enforcement and Operational Compliance

    How J.A. Consulting Works on This

    Framework Builds for Market Entry

    For companies entering the EU market or bringing their privacy posture into line with GDPR, this covers data mapping and classification, legal basis documentation, privacy policy and terms of use aligned with actual data practices, DPA execution with key vendors, and internal policies. The output is a privacy framework that functions operationally, not one that exists only in documents.

    Cross-Border and Multi-Jurisdiction Alignment

    For companies managing dual compliance across different regulatory frameworks, this covers the gap analysis between the relevant regimes, the practical changes required, and how to structure a single programme that covers multiple jurisdictions without running parallel compliance efforts.

    US Privacy Mapping

    For companies with US users or US market ambitions, this covers the state law landscape, the FTC enforcement exposure, California-specific requirements under CCPA and CPRA, and how to structure a privacy policy that accurately reflects actual data practices.

    For most companies at the consideration stage, the right entry point is understanding which of these three areas is the immediate priority.

    Privacy & Data Support

    Privacy Governance & DPO Support

    Go Deeper

    INSIGHTS

    The US Privacy Minefield

    The US has no comprehensive federal privacy law. Companies selling to US users face a patchwork of state statutes, FTC enforcement authority, and class action exposure that most founders do not see until it is too late. A privacy policy that does not match your actual data practices is a litigation risk, not a compliance formality.

    Read the full analysis →
    INSIGHTS

    Data Protection as a Competitive Advantage

    Most founders treat GDPR as a cost to manage. Companies that build data governance into their product architecture early reduce friction in enterprise sales, investor due diligence, and cross-border market entry. The companies that move fastest in regulated markets are the ones that treated privacy as a structural decision rather than a late addition.

    Read the full analysis →

    Resources

    FREE RESOURCES

    Practical Tools for Privacy and Compliance

    Download checklists and reference tools for data protection reviews, contract assessment, and founder legal infrastructure at the J.A. Consulting resources library.

    Browse all resources →

    If you are outside the EU

    Companies with no EU establishment that offer goods or services to people in the EU, or monitor their behaviour, must appoint a representative in the Union under Article 27. It is separate from a DPO, and it is usually a customer's data protection questionnaire that surfaces it.

    GDPR EU Representative, what Article 27 requires

    Most of my clients come to me after a close call.

    A few come before one.

    The second group sleeps better.

    If something is on your desk, I'd be glad to hear it.

    Book a 30-minute call
    J.A. Consulting
    J.A. CONSULTINGLegal. Strategy. Execution.

    Johnathan Aloni, Adv. | Strategic Legal Advisor | Dublin, Ireland

    Website content is informational and does not constitute legal advice or create an attorney-client relationship.

    J.A. Consulting | Legal. Strategy. Execution.

    © 2026 J.A. Consulting. All Rights Reserved.

    Admitted in Israel. Not admitted in Ireland.