I've seen this happen too many times: a business with a working website, happy customers, everything looking fine. Then suddenly a notice arrives from Spain's data authority about a contact form that didn't have consent properly configured. It's not a movie. It happens. And the fines are real.

GDPR has been in force since 2018, but don't think it's done and dusted. In 2026 things have shifted significantly. Spain's data authority has ramped up inspections, the EU AI Regulation came into force and intersects with data protection, and a GDPR reform (Omnibus Package IV) is coming that could change some SMB obligations.

I'm not trying to scare you for no reason. But I'll explain what you need to control, with real data and concrete steps, so you're not caught off guard.

What Spain's data authority is actually fining in 2026

Spain's data protection authority processed over 22,000 cases in 2023, a 44% increase in fines versus the prior year. The trend has kept climbing. They're not targeting SMBs specifically, but when a large company and a small one commit the same breach, the smaller one often has fewer resources to defend itself.

The areas generating the most fines right now:

Newsletters without explicit consent. The classic mistake. Someone gives you their email to download something or you chat at an event, and you add them to your list. But without specific, informed consent (unchecked box, link to privacy policy, double opt-in), you're breaking the law. 45% of SMBs running email marketing have this problem, according to data protection consultants.

Deceptive cookie banners. Spain's data authority is clear: the reject button must have equal visibility and ease as accept. Only an "Accept all" button, dark colors on reject, cookie walls that block entry without acceptance—all documented violations. Typical fines for this range €3,000–€30,000.

Vendor contracts missing data processing agreements. If you use cloud CRM, email marketing, analytics, external accounting—they all process personal data on your behalf. You need a data processing agreement with each. 60% of SMBs don't have these signed.

60% SMBs without signed data processing agreements
45% Newsletters without valid opt-in consent
70% Without audit log of personal data access

The data inventory: where everything starts (and breaks)

The first thing any data protection auditor asks for is your records of processing activities. This means: what data you collect, what you use it for, what legal basis you rely on, how long you keep it, and who you share it with.

Sounds complicated, but it's just answering simple questions. Do I collect customer emails? Yes. For what? To send invoices and promotions. What's my legal basis? Invoicing by contract, promotions by consent. How long do I keep them? Invoices 6 years per commercial law, marketing data until users opt out.

Here's important news: the European Parliament is processing Omnibus Package IV, a reform that expands the exemption from maintaining activity records to companies up to 750 employees (currently 250). Meaning many more SMBs could be exempt from formal record-keeping.

But there's a nuance everyone misses: even if you're not required, having a basic data inventory protects you. If the authority investigates and you can prove you control your data handling, your position is much stronger. The record isn't just paperwork—it's your shield.

"Not having records of processing activities is like not keeping accounting: when things go well, no problem. When they don't, you can't prove anything to anyone." , Accountability principle, GDPR Art. 5.2

Artificial intelligence has entered your office (and nobody warned you)

This worries me most. SMB employees using ChatGPT, Copilot, or Gemini to summarize text, draft emails, analyze data. Fine, until one of those "texts" contains a customer's name, email, or data.

What happens when you paste a customer's name and phone number into free AI? You're sending personal data to a third party. That third party has no data processing agreement with you. And you don't know what they do with it. According to Spain's data authority and 2025 European data protection guidelines, this can constitute unauthorized international data transfer.

Practical solutions: establish an AI use policy (which tools are allowed and which aren't), use enterprise versions with data processing agreements when possible, and train your team. Real training—sit down with employees and explain what data can and can't go into these tools.

And watch the EU AI Regulation that came into force in 2025, which directly intersects with data protection. If your company uses AI systems that profile customers, make credit decisions, or process job applicant data, you have additional specific obligations. Impact assessments, transparency to users, human oversight. AI Regulation fines can reach €35 million. Not a joke.

The deadlines you need to remember (write them down)

A common mistake is not knowing how long to keep each type of data. Keeping data longer than necessary is a violation, but deleting it too early is too. Here's a practical summary:

Data type Minimum retention period Legal basis
Invoices and accounting documents 6 years (10 in specific sectors) Commercial Law
Payroll documents 6 years Social Security Law
Tax records (income tax, VAT) 4–6 years Tax Law
Marketing consent Until revoked, max 24 months with no activity GDPR Art. 6.1.a
Video surveillance Maximum 30 days Spanish GDPR implementation law Art. 22

Deletion must be active, don't wait for users to ask. Set up automated tasks to delete expired data. If you do it "when I get time," it never happens.

Data breaches: the day everything can go wrong

Picture this: an employee loses a laptop with customer data, someone accesses your CRM without permission, or you get hit with ransomware. Each is a personal data breach. And you have 72 hours to notify the authority.

72 hours. That's not much time, especially without a plan. So write it down before it happens: who detects the breach, who notifies internally, who contacts the authority, how you assess risk to affected people, and how you notify them if needed.

For SMBs, breaches aren't usually sophisticated cyberattacks. They're human error: email to the wrong person, spreadsheet with customer data shared by accident, contact form broken for weeks with nobody noticing. Small things that seem trivial until the authority takes them seriously.

Do I need a Data Protection Officer?

Depends. It's required if you're a public authority, process sensitive data at scale, if your main activity is systematic observation of people, or if you're a school, telecom, or energy company.

For a typical SMB (shop, clinic, consulting, agency), generally not required. But having an internal person responsible—even if not a formal DPO—helps a lot. Someone who knows what data you have, what documentation exists, and who to call if there's a problem. You don't need an expert. You need someone with common sense and a few hours monthly to review things.

What you can do this week (free)

Okay, enough obligations and warnings. Let's get practical. Things you can do yourself in the coming days:

Review your web forms. Every form collecting personal data needs: first-layer info (who you are, why you use data, link to privacy policy), unchecked acceptance box, and double opt-in for newsletter subscriptions. If your forms are misconfigured, fix them in an afternoon.

Review your cookie banner. Is the reject button equally visible as accept? Or hidden on a second screen, grayed out, tiny font? If so, change it. Free and low-cost plugins handle this properly in WordPress and most CMS platforms.

List your data vendors. Your hosting, CRM, email tool, accounting firm, labor consultant. You need a data processing agreement with each. If you don't have it, request it. It's a standard document most vendors already have ready.

Set up double opt-in for your newsletter. If you don't have it, you're sending emails to people who never explicitly confirmed they wanted them. One of the easiest and most common violations to detect.

Frequently asked questions

Can they fine me if my company is very small?

Yes. GDPR doesn't exempt by size. What's true is fines must be proportional. For an SMB with €5 million in revenue, realistic fines for minor violations range €50,000–€200,000, and €200,000–€500,000 for serious ones. Not symbolic amounts. Plus reputational damage.

How much does it cost to make a website GDPR-compliant?

Depends what's needed. If it's just configuring the cookie banner and reviewing forms, €200–€500. If you need privacy policies drafted from scratch, impact assessments, and vendor contracts signed, €1,500–€5,000. Compared to a fine, it's a bargain.

What if a customer asks me to delete their data?

You have one month. Verify their identity (so someone doesn't impersonate them), delete their data from all systems, and confirm in writing. With a decent database, this shouldn't take more than 30 minutes.

Can I use Google Analytics without GDPR issues?

Yes, with conditions. You need user consent before analytics cookies load, and Consent Mode must be correctly configured. With Google Signals disappearing June 15, 2026, this is more critical. If ad_storage is "granted" by default without real consent, you're collecting data illegally.

Will Omnibus Package IV free me from complying?

Not exactly. The reform simplifies some admin requirements (like record-keeping for small companies), but GDPR principles remain the same. You still need to process data lawfully, inform users, protect their rights, and secure information. Less paperwork doesn't mean less responsibility.

What do I do if I've already had a data breach?

Notify the authority within 72 hours through their electronic office. Assess risk to affected people: if high, notify them individually too. Document everything: what happened, how many people, what you did to contain it, how you'll prevent it next time. And don't hide it: a breach handled well damages less than one discovered by others.