← All packs

Kit RGPD TPE/PME

6 documents and 2 tooled spreadsheets for GDPR compliance in a small organisation: obligations memo, 6-sheet Excel processing register, privacy policy, article 28 processor contract, data-subject rights and breaches, 50-point check-list. Status verified on 31/07/2026.

There is no headcount or turnover threshold that exempts you from the GDPR: a one-person business with a customer file, a contact form and a payroll provider processes personal data. And an inspection always starts with the record of processing activities — it is the first document requested. This kit covers GDPR compliance for a small organisation, from the register to the breach procedure, in six documents including two genuinely tooled spreadsheets. Inside: a memo of the real obligations (am I concerned, the controller/processor distinction, the six principles, the six legal bases with the “consent everywhere” mistake, your eight obligations ranked in the order an inspector looks at them, penalties, the DPO question, a five-week plan); a record of processing activities in Excel, 6 sheets, a 16-column controller register with 12 common processing activities already entered, an automatic red alert on an unjustified legitimate interest or a missing retention period, a processor register, vendor tracking and an 11-indicator steering sheet, with a manual and a two-hour method; a full privacy policy plus the short notices to paste on your contact form, newsletter, quotes and job adverts, and an employee information note; an article 28 processor section that starts with the method that saves useless work (most vendors already publish a GDPR annex: your job is to find it and check it covers the 10 mandatory points), with a qualification table, a 5-article contract outline and a tracking table; the 8 data-subject rights with their pitfalls, an 8-step procedure, a request register, then the 72-hour reflex (hour-by-hour timeline, an 18-field incident sheet, the register required even for unnotified incidents, a template message to the people concerned); and a 4-sheet Excel compliance check-list, 50 points across 7 areas, dashboard and a 50-line action plan, with the eight most frequent gaps in small businesses. Triple format DOCX + PDF + Markdown, guided [Indiquer …] zones and a PERSONALIZATION block. 23 files, immediate delivery. Documents are in French. They are professional information, not individual legal advice.

What you get

  • Memo of the real obligations: scope, controller/processor distinction, six principles, six legal bases, eight obligations ranked in the order an inspector looks at them, five-week plan
  • 6-sheet Excel processing register: 16 columns, 12 common processing activities already entered, automatic red alert on an unjustified legitimate interest or a missing retention period, processor register, 11-indicator steering sheet
  • Full privacy policy + short ready-to-paste notices: contact form, newsletter, quotes, job adverts, employee information note
  • Article 28 processing: the method that saves useless work (find the vendor’s GDPR annex and check its 10 mandatory points), qualification table, 5-article contract outline with a security annex, tracking table
  • Data-subject rights and breaches: the 8 rights with their pitfalls, an 8-step procedure, a request register, the 72-hour reflex, an 18-field incident sheet, a template message
  • 4-sheet Excel compliance check-list: 50 points across 7 areas, colour-coded status, dashboard, 50-line action plan, the eight most frequent gaps in small businesses
  • No retention period is set for you and no “per breach” penalty scale is repeated: only the caps of article 83 GDPR and the French CNIL simplified procedure are cited
  • Triple format DOCX + PDF + Markdown, guided [Indiquer …] zones and a PERSONALIZATION block in every .md file

Frequently asked questions

I work alone — am I really concerned?
There is no headcount or turnover threshold that exempts you from the GDPR. A one-person business with a customer file, a contact form and a payroll provider processes personal data. The pack’s memo opens on exactly that question and has you qualify your situation.
Why start with the record of processing activities?
Because an inspection always starts there: it is the first document requested, and its absence puts you on the back foot before the substance is even discussed. The spreadsheet ships with 12 common processing activities already entered and a manual that walks you through a two-hour method.
Why is no retention period set for me?
Because the GDPR sets none in general terms, and a made-up period published in a privacy policy is a commitment you cannot keep. The pack has you set your own justified periods, and the register raises an alert as long as one is missing. Likewise, no “per breach” penalty scale is repeated: only the caps of article 83 GDPR and the French CNIL simplified procedure are cited.
What does the pack not cover?
Deliberately: the CNIL lists of processing subject to or exempt from an impact assessment, the technical procedure for notifying a breach, the cookies and trackers regime beyond the principle, and transfer rules outside the European Union, whose framework keeps evolving. The pack points to cnil.fr and recommends professional support on sensitive topics (health data, video surveillance, employee geolocation, transfers outside the EU, impact assessment, a complaint received).
Can I withdraw after purchase?
No: digital content delivered immediately after payment. By ticking the consent box before buying, you request immediate performance and expressly waive your right of withdrawal (art. L221-28 of the French Consumer Code). Any issue: contact@chipiestudio.com.

See all questions (every pack) →

Go further with the bundle

All 3 packs + lifetime updates for €97 instead of €127. The complete toolkit, €30 cheaper.