Skip to content
GDPR Obligations calendar_today Updated: 7 April 2026 schedule 4 min read

Common Objections to Getting Started with GDPR

No time, too complicated, too small, not relevant - we hear it all the time. Here are the most common objections to GDPR compliance and why they do not hold up.

summarize Key Takeaways
  • check_circle Most objections to GDPR stem from misunderstandings about what the law requires
  • check_circle GDPR compliance does not have to be complicated or expensive, especially for SMEs
  • check_circle Delay increases the risk without removing the obligation
  • check_circle Getting the basics in order takes less time than most business owners think

“I’ll deal with it later”

We hear it every day. Business owners who know they need to do something about GDPR, but keep finding reasons to postpone. That is understandable - there are always more urgent matters. But the objections we hear rarely hold up. Here are the most common ones.

”I don’t have time for it”

This is by far the most common objection. And it is understandable: you have a business to run. But GDPR compliance does not have to be a weeks-long project. With the right tools, you can get the basics in order in a few hours. The free scan takes 2 minutes. You fill in the files at your own pace.

Ask yourself: how much time would it cost if you had to report a data breach unprepared?

”It’s too complicated”

GDPR legislation is indeed complex, but that does not mean compliance has to be. For most SMEs, it comes down to concrete, understandable steps: document what you process, inform your customers, secure your data, and respond correctly to requests.

GDPRWise translates those steps into simple questions you can answer without legal expertise.

”My business is too small”

The GDPR does not differentiate based on company size. A freelancer with a customer list falls under it just as much as a multinational. The difference lies in the scope of your obligations, not in their existence.

”Nobody has ever come to check on me”

That may be true, but the risk is growing. Supervisory authorities are conducting random checks more frequently, and most enforcement starts with complaints from data subjects. A dissatisfied customer or former employee can file a complaint, and then you need to have your affairs in order.

”I don’t process personal data”

Nearly impossible. If you have a customer list, store an email address, maintain personnel files, have a contact form on your website, or send invoices with personal details, you process personal data.

”My IT supplier handles that”

Your IT supplier can help with technical security, but the responsibility for GDPR compliance lies with you as the data controller. You can outsource the execution, but not the responsibility.

”It costs too much money”

That might have been true when expensive consultants were your only option. With tools like GDPRWise, you can get compliant for a fraction of the cost of a fine, a consulting report, or legal proceedings.

”I’ll wait until I really have to”

You already have to. Since May 2018. Every day you wait is another day of risk. Start small, start today.

auto_awesome No more excuses needed

The free GDPRWise scan takes 2 minutes and gives you immediate insight into your privacy situation. No costs, no obligations.

GW
GDPRWise Editorial

This article was written by the GDPRWise team and reviewed by our privacy experts. We regularly review our content for accuracy and legal correctness.