GDPR for Practices, Associations and Law Firms: The Five Duties That Really Apply to Everyone
The GDPR does not kick in above a certain size — it applies the moment personal data is processed. The good news: the core boils down to five duties.
An appointment request, a membership application, taking on a mandate — personal data arises everywhere, and duties arise with it. Anyone with the following five points under control has essentially covered the everyday reality of the GDPR.
1. Accept responsibility
Your organisation is the controller: it decides which data is processed for what purpose — and is liable for it. That cannot be handed off to service providers. Anyone working for you who touches data needs a contract for processing on your behalf; details in The Data Processing Agreement Explained.
2. Have a reason for every processing activity
Every processing activity needs a legal basis from Art. 6 GDPR — usually a contract (the membership, the treatment contract, the mandate), a legal obligation (retention periods), or consent (the newsletter). Stricter rules apply to special categories under Art. 9 GDPR: health data in a practice — but also the religious affiliation that an Alevi cultural centre implicitly processes with every membership list. Here an explicit basis is required, frequently consent.
3. Inform people before data flows
Data subjects must learn what happens to their data. In practice that means: an understandable privacy policy on the website and short notices wherever data is collected — in the contact form, on the membership application, on the intake questionnaire.
4. Be able to serve data subject rights
Access, rectification, erasure, data portability — your organisation must respond to such requests within one month. The preliminary question is banal: do you know everywhere a person's data is held? Software with export and erasure built in turns this duty from a search operation into the press of a button. A note on my own products: this is built in – users export their own data and can delete their account themselves.
5. Protect data technically and organisationally
Art. 32 GDPR requires "appropriate technical and organisational measures": encryption, role-based access, backups, data minimisation — documented in the record of processing activities. The hosting location belongs to this too; more in the article Your Server, Your Data.
In short
The GDPR in everyday life does not mean perfection — it means order: knowing what data you hold, being able to name a reason, informing people, being able to respond, keeping the technology clean. Tidy up these five points once and the fear of the topic usually disappears for good.
Frequently asked questions
Do we need a data protection officer?
Generally only from around 20 people constantly working with personal data — or with extensive processing of special categories. The duties apply even without one.
Does the GDPR also apply to small, volunteer-run associations?
Yes, in full — there is no de-minimis threshold by size. Supervisory authorities do take scale and circumstances into account, though; visible effort counts.
What does a violation realistically cost?
The headline millions hit corporations; for small organisations, three-to-five-figure fines are what tends to be documented. Often more expensive is the loss of trust.
Last updated: August 2026 · This article provides general information and is not legal advice.
Ask a question — I always reply personally.
Sounds like your topic?
Let’s find out – with no obligation – where your biggest lever is.






