Compliance Updated May 2026 25 items · 8 min read

The 2025 Mid-Market GDPR + AI Act Compliance Checklist

25 checks covering cookie consent, DSAR handling, lawful basis disclosure, GPAI obligations, breach notification, and more. Built for mid-market SaaS, fintech, and healthtech teams.

The Trap

Every mid-market company in Europe has a hidden liability sitting on their website right now.

The average mid-market SaaS, fintech, or healthtech company spends €150,000–€250,000 per year on external legal counsel to stay compliant with GDPR. They get a once-a-year audit. A 50-page report. A list of things to fix — delivered months after the site changed.

Then a regulator runs a scan. Finds three cookie consent violations. Issues a fine of €5 million.

The company spent €250K on legal. The legal didn't catch it. The fine came anyway.

€486.8M
Cookie fines from France's CNIL in 2025
€530M
TikTok fine (April 2025, children's data)
€325M
Google fine (September 2025, cookies)
1,021
Fines from Spain's AEPD in 2025 alone
Why mid-market is uniquely exposed
  • GDPR's maximum fine is €20M or 4% of global annual turnover — whichever is higher. For a €50M revenue company, that's a €2M floor. Not a ceiling.
  • The €250K legal retainer buys human review at a point in time. CNIL runs automated scans 24/7. You're being compared against a machine.
  • The EU AI Act added a second regulatory surface that wasn't there 18 months ago. If you use OpenAI, Anthropic, or any major AI provider, you have disclosure obligations most legal teams haven't addressed.

Each check below is ordered by frequency of enforcement in 2025 — not theoretical importance. Regulators have moved to automated scanning at scale. These are the items their systems flag first.

Run a free WatchSuit scan in 30 seconds
Get a compliance score covering cookie consent, lawful basis disclosure, AI system disclosures, security headers, and more. No login required.
Section 1

GDPR — The 12 Checks Regulators Actually Enforce

GDPR enforcement has matured past theoretical compliance audits. These 12 checks are the ones most frequently cited in 2025 enforcement actions.

Check 1 · Most enforced
Cookie Consent — Banner, Mechanism, and Functional Rejection
What's enforced: CNIL fined Google €325M in September 2025 for placing advertising cookies before user consent and for consent designs that steered users toward "Accept All." SHEIN received €150M for identical violations. France issued €486.8M in total cookie-related sanctions in 2025.

The check: Your site must not place non-essential cookies before the user affirmatively interacts with the consent banner. The "Reject All" button must be as prominent, as fast, and as easy to click as "Accept All." The mechanism must actually work — cookies must stop firing when the user rejects.

Common failure: Many mid-market sites use a CMP that looks compliant but still fires analytics or marketing pixels during the 1–2 second window before the user interacts with the banner.

GDPR Art. 7 + ePrivacy €325M precedent fine High-risk
Check 2
Lawful Basis Disclosure for Each Processing Activity
What's enforced: Spain's AEPD issued 1,021 fines in 2025, with unlawful data transfers and inadequate consent as top categories. Meta was fined €479M by a Madrid court for processing user data for behavioral advertising without a valid legal basis.

The check: Your privacy policy must explicitly state which legal basis (Article 6 GDPR: consent, contract, legitimate interest, legal obligation, vital interests, or public task) applies to each distinct processing activity. "We process your data for various purposes" is not compliant.

Common failure: SaaS companies using "legitimate interest" for marketing emails without having completed a balancing test.

GDPR Art. 6
Check 3
DSAR (Data Subject Access Request) Handling Process
What's enforced: The Netherlands fined a company €6,000 for ignoring nine deletion requests. Greece fined a youth association €10,000 for sharing sensitive data about minors and ignoring access requests.

The check: You must have a documented process to receive, verify identity for, respond to, and fulfill DSARs within 30 days. The process must be documented — not just functioning in someone's inbox.

Common failure: No documented DSAR workflow. Requests sitting in a shared inbox with no tracking.

GDPR Art. 15–21
Check 4
Processor/Vendor List — All Third-Party Data Flows Documented
What's enforced: Regulators check whether you know where data goes after it leaves your systems. Amazon received a €746M fine (2021) partly for insufficient processor oversight.

The check: You must maintain a Record of Processing Activities (RoPA) that lists every third-party processor, the data shared, the purpose, legal basis, and retention period. This must be kept current — not a one-time document from 2021.

Common failure: The RoPA exists but includes five vendors when the site actually uses 40+ third-party scripts, pixels, and integrations.

GDPR Art. 28 + Art. 30
Check 5
Privacy Policy Accuracy vs. Actual Practice
What's enforced: California issued over $9 million in fines in 2025 for companies whose privacy policies didn't match their technical implementation.

The check: Your privacy policy must reflect what your site actually does — not what you intended it to do. If you added a new tracking pixel, changed your CRM, or started using a new analytics tool, your privacy policy must be updated.

Common failure: Privacy policy says "we do not sell your data" but the company uses a data broker integration or passes user emails to an advertising platform.

GDPR Art. 13–14
Check 6
Data Retention Statements — Specific, Not Vague
The check: For each data category (customer records, marketing data, support tickets, logs), you must state a defined retention period or a specific criterion for determining when data is deleted.

Common failure: "We retain data for as long as necessary to provide our services" — this is not a retention policy, it's a non-statement. Regulators now ask for exact timeframes.

GDPR Art. 5(1)(e)
Check 7
Consent Records — Proof That Consent Was Given
What's enforced: The SHEIN fine was partly about cookies firing before consent. Google was fined €125M for failing to inform users about advertising cookies placed during account creation.

The check: You must be able to produce a timestamped log of when consent was given, for what purpose, and what the user was shown at the time of consent.

Common failure: No consent management platform, or a CMP that logs consent but doesn't capture the exact version of the privacy notice shown at the time.

GDPR Art. 7(1)
Check 8
International Data Transfer Mechanisms
What's enforced: Meta was fined €1.2B in 2024 for improper data transfers to the US. Ireland's DPC has been the most active enforcer of transfer mechanism adequacy.

The check: If you transfer personal data outside the EU (to the US, or to any third country), you must use an approved transfer mechanism: EU-US Data Privacy Framework (for US companies certified under it), Standard Contractual Clauses (SCCs), or binding corporate rules.

Common failure: Using US-based tools (Salesforce, HubSpot, Intercom, Google Analytics) without having executed SCCs with those vendors.

GDPR Art. 44–49
Check 9
Breach Notification Readiness — 72-Hour Clock
What's enforced: The ICO logged over 400 breach notifications per day in 2025 — the highest rate since GDPR came into force. Regulators check whether you have a documented process for breach detection, assessment, and notification.

The check: You must have a documented incident response process that includes: detection and initial assessment (within 24 hours), classification of whether the breach requires DPA notification (within 72 hours of becoming aware), and notification to affected individuals where required.

Common failure: No documented process. Breach response handled ad-hoc in Slack. No one knows who the DPO is or how to contact the supervisory authority.

GDPR Art. 33–34
Check 10
Children and Vulnerable Groups — Age Verification and Consent
What's enforced: TikTok was fined €530M by Ireland's DPC in April 2025 for handling children's personal data — specifically, making minors' accounts public by default and insufficient age-gating.

The check: If your product or content is accessible to children, or if you have any users under 16 (or under 13 in some member states), you need: age verification or parental consent mechanisms, default privacy settings that are high for minors, and a data minimization approach for under-18s.

Common failure: Assuming "our product is for professionals, not children" is sufficient. Many SaaS tools are used by educators, healthcare workers dealing with minors, or general audiences.

GDPR Art. 8 €530M precedent fine
Check 11
Security Measures — Appropriate to Risk
The check: You must document what technical and organizational security measures are in place — encryption in transit and at rest, access controls, penetration testing schedule, vendor security assessments — and that they are proportionate to the sensitivity of data handled.

Common failure: "We use HTTPS" as the entire security answer. No documented security policy. No pen testing. No review of third-party vendor security.

GDPR Art. 32
Check 12
DPO Appointment and Contact Details Published
The check: If you're required to have a DPO, the name and contact details must be published. If you're not required to have one, you should still have a named privacy contact.

Common failure: DPO listed as "privacy@company.com" without a named individual. DPO role filled by the same person who also runs marketing — creating a conflict of interest.

GDPR Art. 37–39
Section 2

EU AI Act — What Just Became Enforceable in 2025

The EU AI Act entered into force on August 1, 2024. As of August 2, 2025, its most consequential chapter for mid-market companies — General-Purpose AI (GPAI) obligations — became enforceable. Full enforcement powers activate August 2, 2026.

Deployer vs. Provider — Know Your Role
The EU AI Act draws a key distinction
Provider: The company that builds or trains the AI model (OpenAI, Anthropic, Google, Meta, Mistral).
Deployer: Any company that puts an AI system into service for its own purposes or offers it to third parties.

If you use OpenAI's API, Anthropic's Claude, Google's Gemini, or any other foundation model — you are a deployer, not a provider. You have specific obligations under Article 50 of the Act.

AI Act Art. 50
Check 13 · Active since Aug 2025
GPAI Transparency Obligations (Article 50)
If you integrate a GPAI model — via API, SDK, or embedded tool — you must:

1. Inform users that they are interacting with AI (disclosure on first interaction)
2. Label AI-generated content in outputs that you publish, distribute, or display (text, images, audio, video)
3. Maintain documentation of which GPAI model you're using and its version
4. Respect copyright — ensure your AI usage doesn't process content in ways that violate EU copyright law

What this looks like in practice: AI-generated customer support replies: "This response was generated by AI" label required. AI-generated marketing copy: disclosure required. AI-generated summaries: disclosure required. AI-generated blog content: disclosure required.

AI Act Art. 50High-risk
Check 14
AI-Generated Content Disclosure (Art. 50(1)(b))
If your product generates text, images, audio, or video using AI, and that content is displayed to users or published externally, you must disclose that it was AI-generated. WatchSuit's scanner has found that over 60% of mid-market SaaS sites using AI do not display a visible disclosure that the output was AI-generated — the fastest-growing compliance gap in 2025.

AI Act Art. 50(1)(b)
Check 15
AI System Inventory Documented
You must maintain an internal inventory documenting which GPAI models are used in your product, for what purpose, and under what version. This inventory must be updated when models are swapped or upgraded. Regulators can request this documentation.

AI Act Art. 50(3)
Check 16
AI Literacy Training Provided
Employees who work with AI systems must receive AI literacy training appropriate to their role. This includes understanding what AI Act obligations apply, how to identify AI-generated content, and how to report AI incidents.

AI Act Art. 50(5)
Check 17
AI Usage Policy Exists and Governs Employee Use
You must have a documented policy governing how employees can use AI tools — particularly for content generation, decision-making support, and any customer-facing AI output. The policy must be technically enforced, not just a document.

AI Act Art. 50(4)
Check 18
No Prohibited AI Practices in Use
Prohibited since February 2025: AI systems that use subliminal techniques to distort behavior, exploit vulnerabilities, perform social scoring, or conduct real-time biometric categorization in public spaces. If you're using AI for any of these purposes, you are in immediate violation.

Penalties: up to €35M or 7% of global annual turnover.

AI Act Art. 5 Up to €35M Prohibited
Violation Maximum Penalty
Prohibited AI practices (Art. 5) €35M or 7% of global turnover
Violating GPAI obligations (Art. 50) €15M or 3% of global turnover
Supplying incorrect information to authorities €7.5M or 1.5% of global turnover
Check 19 · August 2, 2026 deadline
Full AI Act Enforcement Preparation
GPAI obligations have been enforceable since August 2025, but enforcement powers become fully active on August 2, 2026. The European AI Office and national competent authorities will be able to impose fines at scale from this date.

The EU AI Act has extraterritorial reach — it applies to any deployer whose AI systems affect people in the EU, regardless of where the company is headquartered. A US-based SaaS with EU users falls squarely under this scope.

AI Act Art. 2
Section 3

25-Point Quick-Audit Checklist

Cookie Consent & ePrivacy
GDPR Core Compliance
EU AI Act Compliance
Security & Children

Score: 0 / 25 passed. If you scored below 20, you have compliance gaps that regulators' automated scans will find. All 25 are fixable — and WatchSuit finds them automatically.

Section 4

Common Violations WatchSuit Finds

WatchSuit's automated compliance scanner has run thousands of scans on mid-market SaaS, fintech, and healthtech sites. Here's what our data shows — anonymized and aggregated from scan results.

78%
Cookie Pre-Consent Tracking
At least one third-party script fires before the user interacts with the consent banner.
Common culprits: Google Analytics 4, Intercom, Meta Pixel, Hotjar, LinkedIn Insight Tag
60%
AI Without Disclosure
AI-using sites with no visible disclosure that the output was AI-generated.
AI chatbots, content generation, assisted search, recommendations — all require disclosure
45%
No Documented DSAR Workflow
Requests handled ad-hoc in a shared inbox, sometimes taking 60–90 days with no communication.
Common in companies without a dedicated privacy function
35%
Privacy Policy Stale
Privacy policy lists 8 vendors when the site actually uses 30+. Last updated 18–36 months ago.
Often gaps: new analytics, new AI integrations, new CRM additions
Run the automated scan first
WatchSuit checks all 25 items against your live site in under 30 seconds. Get a scored report with exact remediation steps — no legal jargon.

Frequently Asked Questions

Yes. The UK Data Use and Access Act 2025 mirrors EU GDPR for all data protection obligations. The ICO enforces the same principles — consent, lawful basis, DPA requirements all apply identically. UK-specific note: maximum fines are now up to £17.5M or 4% of global annual turnover. The cross-border transfer rules differ post-Brexit, but the checklist items above remain accurate for UK operations.
Prohibited practices (Art. 5) apply from February 2025. GPAI transparency obligations (Art. 50) became enforceable August 2, 2025. Full enforcement powers activate August 2, 2026. If your product has AI features used by EU individuals, begin your AI Act gap assessment now — the 2026 deadline arrives faster than most expect, and technical documentation, bias testing, and oversight controls take time to implement properly.
Yes. If you're using OpenAI, Anthropic, Google Gemini, or any other foundation model in your product, you are a "deployer" under the EU AI Act and you have specific obligations under Article 50. These include: informing users when they're interacting with AI, labeling AI-generated outputs, maintaining an inventory of which models you use, and providing AI literacy training to relevant employees. The GPAI provider obligations are handled by the model provider — but the deployer obligations are yours.
Required if you: process data on large scale as a core activity; carry out systematic monitoring of individuals on a large scale; process special category data (health, biometric, genetic) on a large scale as a core activity. Most mid-market SaaS companies do not need a dedicated DPO, but must still assign internal responsibility for GDPR compliance. A DPO is advisable if you're processing health data, handling large HR datasets, or operating in multiple EU member states.
Yes, but only if you: implement a functioning consent management platform; block GA loading until consent is received (using gtag('consent') or similar); have a DPA with Google (available in GA settings); consider the US data transfer implications; configure IP anonymisation. Many companies have received enforcement letters for GA loading without consent. An alternative is a privacy-first analytics tool (Plausible, Fathom, Simple Analytics) which doesn't require consent and eliminates the DPA complexity.
At minimum: annually, and before any major product launch that involves new data collection, new AI features, or new third-party integrations. GDPR requires "appropriate technical and organisational measures" to maintain compliance — this implies a process, not a one-time exercise. Many companies run WatchSuit's scanner quarterly as part of their internal audit cycle. After the AI Act full enforcement in August 2026, add a separate AI Act review to your annual calendar.

About this article: This article is maintained by WatchSuit and updated as enforcement patterns evolve. Last updated: May 2026. For questions about specific compliance gaps identified in your scan, contact privacy@polsia.app.

This article does not constitute legal advice. GDPR and EU AI Act compliance requirements are fact-specific and vary by company size, sector, and jurisdiction. Consult a qualified legal professional for advice applicable to your situation.