Seventy-eight percent. That is the share of European organisations declaring themselves GDPR compliant in sector surveys, and still showing documented gaps under a deep maturity audit. GDPR compliance has become an identity marker, a box in supplier risk questionnaires, a sales argument. It rarely reflects real command of the regulation.
Why? Three structural pillars concentrate most of the non-compliance while receiving a fraction of the attention given to consent management and cookie policy. This article covers why data minimisation, retention control and processor governance are the most frequent blind spots, and what the GRC directors who handle them actually do.
A two-speed GDPR
Since GDPR came into force in 2018, fines from European supervisory authorities have risen steadily, with a marked acceleration between 2023 and 2026. Two categories of breach account for more than 60 percent of significant fines (above 500,000 euros): security failures with data breach (Article 32), and gaps in the lawful basis for processing together with failure to honour data subject rights.
What is striking is what those statistics do not show: most sanctioned organisations had a privacy policy, a cookie banner and a processing register. They had ticked the visible boxes. The breaches sanctioned concerned less visible dimensions, precisely the three pillars below.
The regulatory urgency is real. The European Commission announced reinforced investigative capacity for national authorities under its 2025-2027 digital strategy. Cross-border audits between supervisors are multiplying. The risk of sanction for structural rather than spectacular failings is rising.
Pillar 1: minimisation, misread and misapplied
Article 5(1)(c) is among the most quoted and least applied: personal data must be "adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed". In practice, minimisation is read as a collection obligation, do not collect more than necessary. That reading is incomplete.
Minimisation also applies to retention (do not keep data beyond its usefulness), to access (do not expose data to more people than necessary), and to reuse (do not use data collected for purpose A in context B without an appropriate lawful basis). An organisation that collects only what is strictly needed at signup, but keeps it indefinitely in the CRM, exposes it to every sales team, and reuses it for unsolicited prospecting, breaches Article 5(1)(c) on three of the four dimensions.
Common error: treating minimisation as a questionnaire filled in when the processing is set up, with no periodic reassessment. Data necessary in 2022 for a given purpose may not be in 2026, but it stays in the systems for want of a review process. A serious maturity audit always asks: when did you last re-examine the relevance of the data you hold in your CRM?
What mature organisations do: an annual minimisation review in the GRC programme, per processing activity, with a named owner and documented evidence. That is governance, not a data cleanup project.
Pillar 2: retention periods, the neglected column of the register
Article 5(1)(e) imposes storage limitation: data may be kept in identifiable form only as long as necessary. In theory every organisation with a processing register has defined retention periods. In practice those periods are rarely enforced.
Field audits show three recurring patterns. First, periods are defined in the register but no system applies them automatically: deletion is manual, so it does not happen. Second, statutory limitation periods are confused with GDPR retention periods. A contract must be producible for five years in a commercial dispute; that does not mean the contracting party's personal data must sit in the active CRM for five years. It can be archived with restricted access. Third, periods are applied in the main database but not in backups, analytics tools, or exports shared with partners.
A concrete example: a company that keeps unsuccessful candidate data "until someone remembers to delete it", an extremely common practice, breaches Article 5(1)(e). Supervisors recommend a maximum of two years after last contact for recruitment data. If your applicant tracking system neither deletes automatically nor alerts the HR owner after two years, you hold a documentable non-compliance.
The operational fix: define realistic, enforceable retention periods by data category, implement automatic alerts at expiry (not necessarily automatic deletion, but a documented decision to delete or archive), and extend the rule to backups and exports. Three steps, none technically complex.
Pillar 3: processor governance, the contractual blind spot
Article 28 requires that any processing entrusted to a processor be governed by a contract setting out the processor's data protection obligations. Data processing agreements have been standard since 2018. In practice, processor governance goes well beyond the initial contract.
Three gaps dominate in audits. First, DPAs exist for the main processors (cloud, CRM, email) but not for secondary ones: the web agency running the contact form, the marketing email tool, the customer support platform. GDPR draws no distinction by size or criticality: any processing entrusted to a third party needs a DPA. Second, DPAs are not revisited at contract renewal or scope change. A DPA signed in 2021 does not necessarily cover new processing added in 2024, and nobody checked. Third, your processors' own processors, sub-processors under Article 28(2), are not tracked.
The revealing metric: in GDPR audits run on European small and mid-sized companies in 2025 and 2026, the number of processors identified through deep mapping is on average 2.7 times the number declared in the initial register. Organisations systematically forget providers that process personal data, not through bad faith, but because they have no process to detect new processing entrusted to third parties.
What mature GRC teams put in place: systematic qualification of new providers (any new IT or marketing purchase triggers a DPA check), an annual review of the active processor list with DPA validation, and a sub-processor register kept current by the main processors under a contractual clause.
Assessing your maturity on the three pillars
- Minimisation: when did you last review data relevance in your main CRM? Who owned it, and where is the evidence?
- Retention: are your retention periods applied automatically, or do they depend on a manual action? Are backups and exports in scope?
- Processors: how many active providers process personal data on your behalf? Does that number match your register?
If any of the three cannot get a documented answer within 48 hours, you have a governance gap. Not necessarily a breach, but an exposure auditors will find. Presidio automates the processing register, retention alerts and DPA management in a single flow. See Presidio →
Conclusion
GDPR compliance is not a cookie banner and a processing register. The three pillars examined here, minimisation in all its dimensions, effective retention enforcement, and active processor governance, concentrate most real non-compliance and most significant fines. They do not headline the practical guides because they are less visible and demand governance rather than technology.
Three takeaways: put an annual minimisation review per processing activity in the calendar; implement automatic retention expiry alerts per data category; institute systematic detection of new processors. And in your context: if a supervisor asked tomorrow for the list of your active processors with current DPAs, how long would it take you to produce it?
