What GDPR requires
Before shopping, it helps to separate the legal obligations from the products sold against them. The core duties are:
- Have a lawful basis for every processing activity: consent, contract, legal obligation, vital interests, public task or legitimate interests. Consent is only one of six and is often the weakest choice.
- Maintain records of processing activities (ROPA) under Article 30, covering what you collect, why, on what basis, who receives it and how long you retain it.
- Honour data subject rights within one month: access, rectification, erasure, portability, restriction and objection.
- Report qualifying breaches to your supervisory authority within 72 hours of becoming aware.
- Have data processing agreements with every processor handling personal data on your behalf.
- Conduct a DPIA for high-risk processing.
- Implement appropriate technical and organizational measures, including encryption, access control and other security basics.
The four categories of tooling
| Category | What it does | Who needs it |
|---|---|---|
| Consent management (CMP) | Cookie banner, consent capture, preference storage, tag blocking | Anyone with a website using non-essential cookies |
| Data mapping / ROPA | Inventory of processing activities, data flows, retention | Anyone above the Article 30 threshold; in practice, many organizations |
| DSAR automation | Intake, identity verification, discovery across systems, response | Consumer-facing businesses, or anyone above ~10 requests a month |
| Vendor risk / TIA | Processor inventory, DPAs, transfer impact assessments | Organizations with many sub-processors or international transfers |
Few small organizations need four separate products at the outset. A practical sequence is to implement a CMP, maintain the ROPA in a spreadsheet while that remains manageable, and automate DSARs when request volume makes the manual process unreliable.
Why consent management is technically difficult
Cookie consent is a visible enforcement area, and a homemade banner can easily miss one of the technical requirements:
- No pre-ticked boxes and no implied consent. Continuing to browse is not consent.
- Rejecting must be as easy as accepting. A prominent "Accept all" with "Reject" buried behind two clicks has been repeatedly ruled non-compliant, including in enforcement against very large sites.
- No cookies before consent. Analytics and marketing tags must not fire until permission is given. A banner that displays a notice after those tags load does not solve the underlying problem.
- Consent must be granular by purpose, withdrawable as easily as given, and logged with a timestamp as evidence.
Correct prior blocking requires more than displaying a banner, which is why a CMP can be more reliable than a custom implementation. If you serve EU users and run Google services, you also need Google Consent Mode v2. Without it, Google restricts data collection and remarketing for EU traffic regardless of the banner text.
Cookiebot (Usercentrics)
Best CMP for most websites
Scans a site, classifies cookies, blocks tags before consent and maintains a consent log, covering the parts most difficult to maintain manually.
The monthly scan-and-classify feature can find trackers that the site owner did not know were present. Automatic prior blocking is intended to prevent tags from firing before consent, rather than merely displaying a notice over an already loaded tracker.
The free tier can cover a small site. Costs scale by page count and domain, so a large multi-site estate becomes more expensive.
Strengths
- Automatic cookie scanning and classification
- Prior blocking rather than a notice alone
- IAB TCF and Google Consent Mode v2 support
- Free tier suitable for small sites
Trade-offs
- Pricing scales with pages and domains
- Default styling needs work to match a brand
- Scanner can misclassify unusual first-party cookies
OneTrust
The enterprise standard
A broad enterprise suite covering consent, data mapping, DSAR workflow, vendor risk and assessments, with enterprise pricing and implementation scope.
OneTrust is the category benchmark for organizations with a DPO, several jurisdictions and personal data processed at scale. Its broad coverage is the main reason to shortlist it.
That breadth also creates overhead. A small organization may use only a fraction of the suite while still paying for and implementing the wider platform. The purchase makes sense when the obligations justify that scope, not simply because it is the most complete option.
Strengths
- Broad functional coverage across privacy operations
- Handles GDPR, CCPA/CPRA, LGPD and more in one place
- Mature DSAR workflow and assessment automation
- Extensive integration catalog
Trade-offs
- Expensive
- Significant implementation effort
- Substantially over-scoped for most SMBs
Osano
Best mid-market balance
Consent management plus data mapping and vendor monitoring, with a clearer, faster implementation than the enterprise suites.
Osano sits between a standalone CMP and a full enterprise privacy suite. Its vendor monitoring tracks privacy-policy changes at sub-processors, a task that otherwise requires repetitive manual review.
It covers less than OneTrust, in exchange for a faster implementation and lower price. That scope can be enough for a company without a dedicated privacy team.
Strengths
- Faster to implement than enterprise suites
- Vendor privacy monitoring included
- Covers GDPR and US state laws
- Transparent pricing
Trade-offs
- Less depth than OneTrust for complex needs
- Smaller integration catalog
- DSAR automation is more basic
A spreadsheet, a lawyer and a good CMP
The right answer under about 50 people
For a small organization with straightforward processing, a compliant consent banner, maintained ROPA spreadsheet and documented DSAR process may be sufficient.
A 20-person B2B company processing customer contact details and employee records may not need a privacy platform. It still needs a working cookie banner, a maintained spreadsheet ROPA, signed DPAs with processors, an accurate privacy notice and a written process for answering a subject access request within one month.
A few hours with a data protection lawyer can validate lawful bases and review the privacy notice before the same budget goes toward a platform license. Tooling becomes more useful when the volume of systems, vendors or requests exceeds what one person can track reliably.
Strengths
- Minimal cost
- Requires direct understanding of your own processing
- Acceptable to regulators when properly maintained
Trade-offs
- Depends on one person keeping it current
- No automated discovery of new data flows
- Scales badly past a few dozen systems or regular DSARs
The operational work behind DSARs
A subject access request must be answered within one month, extendable to three for complex cases. The operational challenge is locating every copy of one person’s data across the CRM, support desk, analytics, backups, logs and marketing tools.
Automation is worth buying when volume makes manual handling unreliable, roughly above ten requests a month. Below that, a documented runbook naming each system and who searches it is usually enough, and considerably cheaper.
International transfers
Moving personal data outside the EEA requires a valid transfer mechanism. For the US, the EU–US Data Privacy Framework provides adequacy for certified organizations. Check each vendor’s certification rather than assuming it applies; otherwise, Standard Contractual Clauses plus a transfer impact assessment are required.
This area has been overturned twice by the Court of Justice of the EU (Safe Harbour, then Privacy Shield) and the current framework faces ongoing legal challenge. If your architecture depends on it, know which vendors are certified and have a contingency plan.
What to buy, by size
| Organization | Sensible spend |
|---|---|
| Under 20 people, simple processing | CMP (often free tier) + spreadsheet ROPA + a few hours of legal review |
| 20–100 people | Paid CMP + a mid-market platform for data mapping, or a well-maintained spreadsheet |
| 100–500 people | Integrated platform covering consent, mapping and DSAR; likely a designated privacy owner |
| 500+, or high-risk processing | Enterprise suite, a DPO, and formal DPIA processes |
Frequently asked questions
Do I need GDPR compliance software?
Many organizations with a website need a consent management platform because prior blocking and consent records are difficult to maintain by hand. Other tooling is driven by scale. A small company with simple processing may meet its obligations with a maintained spreadsheet and documented processes.
Does GDPR apply to my US company?
It applies if you offer goods or services to people in the EU or UK, or monitor their behavior, including through analytics and advertising. The absence of an EU office does not by itself remove a company from scope. Tracking EU visitors can bring the site within scope.
What are the GDPR fines?
Up to €20 million or 4% of global annual turnover, whichever is higher, for the most serious infringements; up to €10 million or 2% for lesser ones. Regulators also issue warnings, reprimands and orders to stop processing, which can be more disruptive than a fine.
Is a free cookie banner good enough?
Only if it blocks non-essential cookies until consent, makes rejection as easy as acceptance, offers granular choice by purpose and logs consent as evidence. Many free banners display a notice after tracking scripts have already run, which is the violation regulators act on.
How long do I have to respond to a data subject access request?
One month from receipt, extendable by a further two months for complex or numerous requests, provided you inform the individual of the extension and the reason within the first month.
Do I need a Data Protection Officer?
A DPO is mandatory for public authorities, for organizations whose core activities require large-scale regular monitoring of individuals, or large-scale processing of special-category data. Most SMBs do not need one, but should still name someone internally as accountable for privacy.