GDPR for SMEs in Reunion Island
— your obligations in practice
Company size alone does not determine the applicable duties. Inventory processing activities, roles, risks and processors, then check current official rules.
Processing records, breach procedures, data-subject rights and processor contracts may need review. An ECLAUD IT proposal can define selected technical or documentation assistance; it does not guarantee legal compliance or assume a DPO role unless expressly contracted.
What GDPR concretely requires of SMEs
The General Data Protection Regulation applies to any organisation that processes personal data — with no minimum size or turnover threshold. Your client database, employee payslips, prospect email addresses, website cookies: all of this constitutes personal data processing within the meaning of GDPR.
For a Reunion Island SME, the obligations come down to four pillars: document (processing register), secure (technical and organisational measures), inform (data subject rights, privacy policy) and react (CNIL notification within 72 hours of a breach). This is not theory — the CNIL simplified procedure, in place since April 2022, specifically targets micro-businesses and self-employed professionals.
"48% of French SMEs have no formalised cybersecurity strategy — and most do not have a GDPR-compliant processing register."— Konica Minolta / IFOP study, 2025
In Reunion Island, the situation is even more pronounced. The local economy is 95% micro-businesses and SMEs. Many operate with an Excel file for their client list, a non-compliant web host and no GDPR documentation. On the day of a CNIL inspection or a ransomware attack that exfiltrates data, the consequences are serious — financially and reputationally.
The 5 concrete GDPR obligations for your SME
Processing register
Document the relevant processing activities, purposes, data categories, retention and security. Verify the applicable duties against current official guidance.
Data security
Implement appropriate technical and organisational measures: encryption, backups, access control, pseudonymisation. The CNIL verifies the proportionality of measures relative to risks.
Breach handling
Prepare qualification, documentation, any required notification and communication according to the rules applicable to the incident.
Data subject rights
Organise intake, assessment and response according to the applicable deadlines and exceptions.
Managing processors
Identify providers, hosts and vendors, then verify their roles, safeguards and clauses with qualified advice.
CNIL penalties and risks for SMEs
Penalties and procedures depend on the facts, the organisation's role and the applicable legal framework. Consult current official texts, guidance and decisions.
Processing, risks, measures and circumstances must be established for the case concerned.
Official texts, guidance and decisions must be checked at the date of the assessment.
The amount and procedure cannot be inferred from a generic range on a commercial page.
The amount of any sanction depends on the facts and the CNIL's decision. Some decisions are published; consult official sources rather than a generic range.
Processing records, security, data-subject rights and cookies must be assessed case by case. No universal remediation time is asserted.
Any administrative, civil or criminal consequences require qualified legal assessment; this page does not publish a generic ceiling or range.
How to scope GDPR assistance
We do not sell paperwork. Our GDPR approach is operational: we audit your IT estate, identify the gaps, fix the technical vulnerabilities and formalise the documentation. The result: compliance that holds over time, not a folder gathering dust.
Initial assessment
The processing, documents, systems and risks to examine are defined before the engagement; the deliverable depends on the accepted scope.
Processing register
Collection, validation and update responsibilities must be assigned. Any documentation assistance is specified in the proposal.
Security policy
Policies, incidents, access and encryption may be reviewed without promising legal or framework compliance.
DPO role
Need, independence, competence and responsibility must be confirmed separately with qualified advice.
What distinguishes us from a traditional GDPR consultancy: we are also your IT provider. When the audit reveals that your backups are not encrypted or that your host is non-compliant, we do not just write it in a report — we fix it. Technical security and legal compliance advance together.
For SMEs in Reunion Island, we offer on-the-ground support: on-site audit, in-person team training, a single point of contact reachable at +33 6 58 56 53 79.
GDPR and cloud processors — what you need to check
Your GDPR responsibility does not stop at the walls of your company. The moment you entrust personal data to a provider (host, SaaS vendor, online accountant, cloud CRM), you remain the data controller under GDPR. This is the principle of joint liability.
In practice, this means three things for your SME:
GDPR contractual clauses
Every contract with a processor must include GDPR clauses (Article 28): object and duration of processing, nature of data, security obligations, fate of data at end of contract. If your IT provider or host does not have these clauses, you are both in breach.
HDS hosting for health data
If you process health data, confirm the applicable hosting obligations with qualified counsel. Any host and scope proposed by ECLAUD IT must be identified in the proposal; no exclusive practice is claimed here.
Transfers outside the European Union
If your CRM, email or cloud backup stores data on servers outside the EU, you must frame the transfer: standard contractual clauses (SCC), adequacy decision, or the Data Privacy Framework for the United States. The CNIL is increasingly controlling these transfers — several French companies have been sanctioned for using Google Analytics without sufficient safeguards.
We audit your entire IT processing chain: hosting, SaaS, cloud backup, collaboration tools. For each provider, we verify the location of data, certifications and contractual clauses. Result: a clear map of your data flows and a remediation plan if needed.
GDPR compliance pricing for SMEs
| Service | Includes | Indicative price |
|---|---|---|
| One-off GDPR audit | Processing activities mapping, gap identification, report with prioritised action plan | Written proposal |
| Full support package | Audit + register + security policy + IT charter + team training | Written proposal |
| Outsourced DPO | CNIL interface, regulatory monitoring, handling data subject requests, ongoing training | Written proposal |
The exact scope and professional role must be confirmed for the organisation. Pricing and any tax treatment are not assumed and should be verified in the proposal and with the appropriate adviser.
FAQ — GDPR for SMEs
Does GDPR apply to my SME with fewer than 10 employees?
Applicability depends on processing activities and the organisation's role, not only headcount. Verify applicable duties and exceptions against official guidance or qualified advice.
What penalties could a Reunion Island SME concretely face?
The amount and procedure depend on the facts, the legal framework and the CNIL decision. Check official texts and decisions; no typical SME range is asserted here.
Do I need to appoint a DPO (Data Protection Officer)?
DPO appointment depends on the processing activities and applicable legal criteria. Confirm the requirement with qualified legal or data-protection advice. Any ECLAUD IT documentation or coordination scope is defined in the proposal; no DPO role is assumed unless expressly contracted and legally appropriate.
Is my cloud host GDPR compliant?
Not necessarily. Document processors, processing locations, transfers and contractual safeguards. Confirm health-data hosting duties where relevant. Any technical or contractual review scope must be defined in writing.
How much does GDPR compliance cost for an SME?
Price depends on processing activities, sites, data categories, existing documentation, technical review, training and any ongoing assistance. Scope, deliverables, professional responsibilities, setup costs and recurring charges are confirmed in writing.
How should an SME check regulatory changes?
Consult current official texts and guidance, then have their applicability to your processing assessed. This page is not a legal-monitoring service.
Your GDPR compliance
deserves a field expert
Discuss a GDPR gap assessment and prioritised action plan. Scope, deliverables, professional responsibilities and price are confirmed before work begins.