GDPR compliance for enterprise documents — a 2026 checklist
A practical 2026 GDPR checklist for enterprise documents — data inventory, retention, audit trail, EU residency, deletion workflow and how a DMS closes the gaps.
Kenan Trgic8 min read
GDPR compliance for enterprise documents means that every document containing personal data is captured under a lawful basis, retained only as long as needed, protected by appropriate technical and organisational measures, and demonstrably deletable on request. eelik d.o.o. delivers GDPR-aligned DMS deployments in EU data centres for clients in the DACH region, covering both the technical configuration and the process design that supervisory authorities actually audit. In 2026, the bar has shifted from "are you breach-ready" to "can you prove your retention, access and deletion practices in production".
Why has GDPR enforcement changed in 2026?
Supervisory authorities — the relevant Land DPAs in Germany (LfDI BW, BayLDA, HmbBfDI and others, depending on the data controller's seat), DSB in Austria, AZOP in Croatia — now conduct routine audits of retention and access practices, not only post-incident investigations. Fines for systemic non-compliance have grown: the CMS GDPR Enforcement Tracker records 2,685 fines totalling €6.11B as of March 2026, with a steady rise in seven-figure penalties. While the biggest cases concern lawful basis and general processing-principle violations, failures around data-subject deletion rights (e.g. Clearview AI, €30.5M) and inadequate retention/access controls remain a recurring theme that auditors actively look for.
What does GDPR actually require for documents?
Three articles do most of the work for document management:
- Article 5 — principles. Documents must be processed lawfully, with purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability.
- Article 17 — right to erasure. On a valid request, personal data must be deleted unless a legal retention obligation overrides it.
- Article 32 — security of processing. Appropriate technical and organisational measures: encryption, confidentiality, integrity, availability, resilience, and regular testing.
A DMS does not make you compliant on its own — process and governance do — but it provides the technical primitives (retention rules, audit trails, access control, encryption, deletion workflows) that make compliance demonstrable rather than aspirational.
The 2026 checklist
The following twelve items cover what we look for in a GDPR readiness assessment for an enterprise document estate.
- Data inventory. Every document class is recorded in your records of processing activities (Art. 30): what personal data it contains, lawful basis, retention period, recipients, location. If you cannot list your document classes on one page, start here.
- Retention policy in the DMS. Each document class has a retention rule configured in the DMS (e.g. HR personnel file: 10 years after employment ends; supplier invoice: 8 years per HGB §257 (DE, reduced from 10 years on 1 Jan 2025 by Bürokratieentlastungsgesetz IV), 7 years per BAO §132 (AT, general business records); CCTV footage: 72 hours). Rules execute automatically — manual retention is not retention.
- Audit trail. Every access, change, download and deletion is logged with user, timestamp and action. Logs are tamper-evident and retained for at least one year, ideally for the life of the document.
- Access controls. Role-based access, least privilege, separation of duties between IT administrators and document owners. Administrators have access to the system; they should not have unmediated access to the contents of personnel files or medical records.
- Encryption at rest and in transit. AES-256 at rest, TLS 1.2+ in transit (TLS 1.3 recommended for new deployments). Key management documented, with rotation procedures and separation between data and keys.
- Data Processing Agreement (DPA) with cloud providers. A signed Art. 28 DPA covering each processor and sub-processor. The current versions of the Microsoft, AWS, Hetzner and Google DPAs all meet the formal requirements; verify your signed version is current.
- Data residency. Production data and backups in EU regions. Hetzner (Nuremberg, Falkenstein, Helsinki), Azure (Germany West Central, Sweden Central), AWS (Frankfurt, Ireland, Stockholm) are all defensible choices. Watch for hidden transfers in support and telemetry channels.
- Incident response process. Documented 72-hour notification process to the supervisory authority and, where required, to affected data subjects. Test it once a year with a tabletop exercise.
- Deletion-on-request workflow. A defined process to receive, validate and execute Art. 17 requests within one month (Art. 12(3) GDPR, extendable by two further months for complex requests). The DMS must support actual deletion, not just hiding, and must record what was deleted, by whom and when. Legal-hold exceptions must be explicit.
- Employee training. Annual, role-specific training for everyone with access to personal data. Document attendance and refresh after material changes.
- Sub-processor list. Current public list of sub-processors, with notification of changes. Required for B2B contracts and good practice generally.
- Regular audits. Internal audit at least annually, external audit (ISO 27001, SOC 2, or a focused GDPR audit) every two to three years. Findings tracked to closure.
How does a DMS address each gap?
| Checklist item | Typical file-server gap | DMS capability |
|---|---|---|
| Data inventory | Documents scattered across shares | Document classes with mandatory metadata |
| Retention policy | Manual, often ignored | Rule-based, automatic |
| Audit trail | OS-level only | Application-level, tamper-evident |
| Access controls | Folder ACLs, drift over time | Role-based, reviewed |
| Encryption at rest | Optional, often off | Standard, configurable per class |
| Deletion-on-request | Manual, error-prone | Workflow with audit record |
| Data residency | Where the file server lives | Explicit per repository |
| Audit evidence | Reconstructed from backups | One-click compliance report |
A DMS does not remove the need for governance, but it turns governance into something configurable and auditable rather than a binder of policies nobody can prove are followed.
What are the most common compliance gaps we see?
- Personnel files on a shared drive with informal access control and no retention rule. The most common single issue.
- Email attachments as the de facto archive. Outlook PST files containing years of contracts that nobody can search or delete.
- Backups beyond retention period. Documents deleted from production but still on tape for years. Backups are processing under GDPR and must follow the same retention logic.
- CCTV and visitor logs without a deletion schedule. Often configured once and forgotten; supervisory authorities ask about them on the first visit.
- Sub-processor changes not tracked. If your DPA chain does not reflect current sub-processors, the contract is incomplete.
- No documented process for Art. 17 requests. Handled ad hoc, often outside the one-month statutory window.
What about AI and cross-border transfers?
AI document processing introduces considerations under Art. 22 (automated decision-making) and the EU AI Act. For invoice automation the risk is low; for HR document classification or CV screening you must document the logic, allow human review, and assess whether the system is high-risk under the AI Act. For cross-border transfers, the safest DACH baseline is EU regions of EU-resident providers (Hetzner, IONOS) or EU regions of US hyperscalers under the current EU-US Data Privacy Framework. Design the architecture so that moving regions is feasible.
How does eelik d.o.o. deliver a GDPR-aligned DMS?
A typical engagement covers four streams running in parallel:
- Technical: DMS deployment in EU region, encryption, access model, integration with identity provider, retention configuration.
- Process: retention catalogue, deletion workflow, incident playbook, sub-processor register.
- Documentation: records of processing activities, DPIA where applicable, AI Act assessment for automated processing.
- Training: role-specific training for administrators, document owners and end users.
The full delivery is described on the document management service page, and the supporting cloud architecture choices on the cloud infrastructure service page. For a regulatory assessment specific to your industry, the IT consulting service is the right entry point.
Frequently Asked Questions
Is Microsoft 365 GDPR-compliant by default?
Microsoft 365 in EU tenants meets the formal requirements when configured correctly, but the default configuration is not sufficient. Retention labels, Purview policies, conditional access and audit retention all require explicit configuration. A standard tenant is a starting point, not a compliant document archive.
How long can we keep personal data?
Only as long as needed for the purpose, or as required by law. Tax-relevant documents: 8 years in Germany (HGB §257, reduced from 10 on 1 Jan 2025), 7 years in Austria (BAO §132 general; 22 years for real-estate records), 10 years in Switzerland (OR Art. 958f). Personnel files commonly retained 10 years after termination, CVs of unsuccessful candidates 6 months, CCTV usually 72 hours (per Land DPA guidance). Configure each class explicitly; "we keep everything for ten years" is not a defensible policy.
What if a customer requests deletion but we have a legal retention obligation?
You inform the customer, document the conflict, suspend further processing beyond what the legal obligation requires, and execute the deletion the moment the obligation expires. The DMS must support this "delete-on-expiry" pattern — manual diary entries do not survive an audit.
Can we run a GDPR-compliant DMS in AWS or Azure?
Yes, in EU regions with the current DPA and Standard Contractual Clauses, and with documented technical measures (encryption with customer-managed keys is the strongest position). The choice between Hetzner, Azure and AWS becomes a cost and integration question, not a compliance one — provided the configuration is correct. Contact eelik d.o.o. for a GDPR readiness assessment.
Related service
Services
About the author

Founder & CEO
IT consultant with over 12 years of experience in enterprise content management, system integrations, and digital transformation. Specialized in DMS and ECM implementations across Central Europe.
LinkedIn