New: GDPRFile 2.0 — faster wizard, clearer guidance.

90% cheaper than a lawyerGet Started

GDPR compliance, without the headache

Built for the SMEs who can't afford a DPO and shouldn't have to. Have a conversation with our AI wizard, get every document GDPR requires, host them on your site, prove your compliance with a public badge.

b19-2696ab800200db873036e7f472a6b6b0.png

"This application lets us create simply with unparalleled efficiency... it helped us show the actions we have taken to protect our members' data."

john-alexander-bogaerts-2def312bec7e641a891bfbf9be7fcd63.jpg

John-Alexander Bogaerts

Chairman, B19 Country Club

Why use GDPRFile

Small businesses struggle with compliance. We solve the 3 biggest pains.

exploding_head.png

Complexity & Stress

You don't know where to start. Securing paper documents, IT systems, and databases feels impossible without a legal team.

world.png

Website Compliance

Cookies, privacy policies, and consent forms must be legally valid and updated constantly. Our AI handles this for you automatically.

money_with_wings.png

Risk of Fines

Non-compliance is expensive. You risk heavy fines (up to 4% of turnover) and losing customer trust if you don't protect their data.

Built by one of Europe's leading data protection experts

Compliance software is only as trustworthy as the expertise behind it. GDPRFile is built and reviewed by Jacques Folon, one of the most experienced data protection professionals in the EU.

  • Member of the European Data Protection Board's Support Pool of Experts

  • 20+ years shaping privacy and data protection expertise across the EU

  • Founder & Scientific Director of Belgium's only long-term DPO training programme

  • Has guided companies, associations, and public bodies in GDPR compliance since the regulation's inception

  • Author of 10+ books on privacy and GDPR

  • Jacques Folon, Founder of GDPRFile

    "Most SMEs don't need a lawyer or a full-time DPO. They need clear answers and the right documents. That's what we built GDPRFile for."

  • Folon_Jacques_200129_2.jpg

    How GDPRFile works

    From diagnosis to compliance in minutes! No expertise needed.

    Step 1: Have a conversation

    Answer plain-English questions adapted to your business — what you do, what data you handle, who you work with. No legal jargon, no spreadsheets, no homework. The AI wizard handles the GDPR translation in the background.

    ⏱️ 10–30 minutes, depending on how far you want to go.

    wizard.png

    Step 2: Stay compliant, automatically

    Your business will change. The law will change. GDPRFile tracks it all for you,  your dashboard alerts you when something needs attention, and your public Compliance Badge always reflects your current status.

    🔄 Living compliance, no recurring panic.

    today.png

    Get all your documents

    Always up-to-date, self-hosted links, as well as a complete "GDPR File" acting as proof in case of control.

    documents.png

    Track everything from one dashboard

    See your live compliance score, identify what's missing, and prioritize what to fix. Export audit-ready evidence packs anytime.

    dash.png

    Show your compliance to the world

    Display your verified Compliance Badge on your website, with a public verification page. Compliance becomes a credential.

    trust2.png

    Customers Love Us

    Hear from businesses like yours who have transformed their GDPR compliance with our innovative tool.

    Clear and Actionable

    "This tool is very useful for understanding the problems of GDPR. It provides a good framework for the actions to be undertaken as an Insurance Broker."

    valery-safarian-33541568cd2275573b50c2fd66cccf60.jpg

    Valery Safarian

    Triangle Partners

    Guided Path to Compliance

    "A great tool for helping SMEs in this task of GDPR compliance. A well-marked path guides you through the various obligations of GDPR — what you need to know, where to start, and which route to follow."

    dimitri-goossens-a375ae04123416e1b7a50683a4f3812c.jpg

    Dimitri Goossens

    MAXEL

    Smart, Simple & Complete

    "Intelligent application, simple and extremely effective for creating a compliance file that is not simple. We find the processes, the legal documents and the necessary texts."

    michel-pirson-3c05d8973c1eaa5b307e41309d49fe88.jpg

    Michel Pirson

    Feprabel

    Everything GDPR requires, in one place

    GDPR is bigger than a privacy policy. Here's what compliance actually involves, and how GDPRFile helps you cover each piece.

    AI Compliance Wizard

    The wizard asks questions adapted to your business, and turns your answers into compliant documents and procedures — automatically.

    Hosted Privacy Policies

    A live privacy policy hosted on a unique URL — for your website, your mobile app, anywhere you collect data. Always in sync with your wizard answers, updated automatically when the law changes.

    Records of Processing (ROPA)

    The master document mapping every category of personal data you handle — required by Article 30 and the first thing a regulator asks for. Generated and maintained from your wizard answers.

    Vendors & Sub-processors

    Track every external tool that touches your data — Stripe, Google, your CRM, your accountant. We help you list them, check their compliance, generate the DPAs you need, and flag missing ones.

    Data Subject Requests (DSAR)

    When a customer asks to access, correct, or delete their data, you have 30 days to respond. Manage every request in one inbox, with deadlines, statuses, and ready-to-use templates so you're never caught off guard.

    Breach & Incident Logging

    If a data breach happens, you have 72 hours to notify the regulator. Log incidents as they occur, classify severity, track notifications, and keep the audit trail — so panic never replaces process.

    Risk Assessment (DPIA)

    A built-in screening questionnaire to determine if your processing requires a Data Protection Impact Assessment. If it does, the platform guides you through it — particularly important for businesses handling sensitive data.

    Public Compliance Badge

    Display your verified compliance level — Bronze, Silver, or Gold — directly on your website. Customers and prospects can click to see your live verification page, building trust with anyone who cares about how you handle their data.

    How far do you want to go?

    Compliance isn't all-or-nothing. The wizard takes you as far as you decide — and you can always come back later to go further.

  • Essentials

    ⏱️ Under 10 minutes

    👤 For — solo founders, freelancers, and very small businesses with easy data flows.

    📋 What it takes — Answer a short series of questions. No internal data gathering required.

    What you walk away with — Privacy policy, cookie policy, cookie banner, and a basic processing register. The documents that keep you off the easy-fine list.

    If GDPR feels like a chore you'd rather not deal with, this is the floor. You won't be perfectly compliant — but you won't be the low-hanging fruit either.

  • Standard — ⭐ Recommended for most businesses

    ⏱️ Under 30 minutes

    👤 For — Most SMEs: agencies, e-commerce, startups, consultancies, B2B services...

    📋 What it takes — Gather some information internally (your vendor list, what employee data you keep, your customer data flows) and feed it to the wizard.

    What you walk away with — Everything in Essentials, plus a full Records of Processing (ROPA), data subject request (DSAR) workflow, vendor & sub-processor register, breach response procedure, employee privacy notice, and DPA templates.

    This is what "compliant" actually means in practice. It's worth the half hour, and it's where we recommend most businesses land.

  • Peace-of-Mind

    ⏱️ A few hours, depending on your business

    👤 For — Businesses handling sensitive data: health, financial, insurance, HR-tech...

    📋 What it takes — Detailed mapping of every data flow, international transfers, sub-processors, and DPIAs (Data Protection Impact Assessments) where required.

    What you walk away with — Everything in Standard, plus DPIAs, Transfer Impact Assessments, sub-processor due diligence files, and audit-ready advanced documentation.

    If a regulator knocks tomorrow, you have nothing to fear. Worth the effort if your data is sensitive — and arguably non-negotiable in those sectors.

  • olena-sergienko-dIMJWLx1YbE-unsplash.jpg

    Simple pricing. Cheaper than a lawyer's first phone call!

    A privacy lawyer in Belgium typically charges €5,000 to set up the same package — only once. GDPRFile is €490/year, and your documents stay up-to-date automatically as your business and the law evolve.

    GDPRFile subscription

    One price. One product.

    €490

    / Year

    €990

    For 3 years

    • AI wizard — guides you to chosen  compliance level

    • Privacy Policy (self-hosted, always up-to-date)

    • Cookie Policy

    • Records of Processing (ROPA)

    • Vendor & sub-processor register

    • Breach response procedure

    • DPA templates (for clients & suppliers)

    • Compliance dashboard

    • Unlimited updates as the law evolves

    Subscribe to GDPRFile now

    Full Setup Service by an Expert

    No time to deal with GDPR? Our experts will. Three sessions, your full compliance package delivered — and a year of GDPRFile included.

    €1 500

    • 3 working sessions with our compliance experts

    • We complete everything for you in GDPRFile

    • Your full compliance package delivered, ready to use

    • 1 year of GDPRFile included (€490 value)

    Book a Full Setup Service by an Expert

    Frequently Asked Questions

    Have questions? We have answers. Find out more about how GDPR Wizard can help your business stay compliant.

    Do I really need to be GDPR compliant if I'm a freelancer or a 5-person business?

    Yes. GDPR applies to every business in the EU that handles personal data — even a contact form on your website counts. The regulator can fine SMEs up to €20 million or 4% of annual turnover, whichever is higher. The good news: small businesses don't need to do as much as a multinational, but they do need the basics covered.

    How is GDPRFile different from a free privacy policy generator?

    Free generators give you one document — usually a template that's not specific to your business and never updated. GDPRFolder generates a complete compliance package (privacy policy, ROPA, vendor agreements, breach procedures, and more), tailors everything to your actual business through the wizard, hosts your documents on a live URL so updates are automatic, and gives you a dashboard to prove your compliance. It's the difference between a one-time PDF and a living compliance system.

    How is GDPRFile different from hiring a privacy lawyer?

    A lawyer typically charges €5,000 for the initial setup, takes weeks of back-and-forth, and gives you static documents that go out of date the moment your business changes. GDPRFolder is €490/year, gets you compliant in 30 minutes, and keeps everything up-to-date automatically. For SMEs without sensitive data, a lawyer is overkill. (For complex situations — health-tech, fintech, large international transfers — we recommend pairing GDPRFolder with occasional legal review.)

    Are the documents legally valid?

    Yes. Templates are reviewed by certified legal DPOs and built on the GDPR's actual requirements. They're updated within 30 days of any regulatory change. The platform is designed by Jacques Folon — 20+ years in data protection, founder of Belgium's longest-running DPO training programme, and member of the European Data Protection Board's Support Pool of Experts.

    Which countries does GDPRFile cover?

    We cover GDPR across all EU and EEA countries. If your business is based in the EU or serves EU customers, GDPRFolder works for you.

    What if my business changes? Do I need to redo everything?

    No. GDPRFolder is built for living compliance. When your business evolves — you add a new tool, hire your first employee, expand to a new country — you go back into the wizard, update the relevant section, and the platform automatically refreshes your documents and dashboard. Compliance stays current without you starting over.

    What happens after my first year?

    Your subscription renews and you keep everything: hosted documents, automatic updates, dashboard access, support, and the public Compliance Badge. If you cancel, your hosted URLs stop working and your documents are no longer maintained.

    Can I share my compliance file with an auditor or regulator?

    Yes. The platform generates an audit-ready evidence pack (your full compliance file plus all uploaded documents) as a single ZIP. You can also create a read-only Auditor Access link that lets a regulator, lawyer, or DPO review everything without needing an account.

    What's the public Compliance Badge?

    It's a verified badge — Bronze, Silver, or Gold — you can display on your website to show customers you take privacy seriously. Anyone clicking it lands on your live verification page, which always reflects your current compliance status. It's one of the strongest trust signals you can put on your site, and it's included in your subscription.

    What if I run a sensitive business — health, financial, insurance, HR?

    GDPRFolder supports the most demanding compliance needs through the Peace-of-Mind level, which includes Data Protection Impact Assessments (DPIAs), Transfer Impact Assessments, and advanced sub-processor due diligence. For those sectors, we recommend either the Compliance Concierge service or pairing the subscription with periodic legal review.

    What's the difference between the subscription and the Full Setup Service by an Expert?

    With the subscription (€490/year), you do the wizard yourself — about 30 minutes. With the Full Setup Service by an Expert (€1,500 one-time, includes one year of subscription), our experts do it with you across three sessions: we gather your documents, complete the wizard for you, and deliver your full compliance package ready to use. Same end result, two ways to get there.

    What about my data? Is GDPRFile itself secure?

    Yes — we'd be in a difficult position otherwise. All data is encrypted at rest and in transit, hosted in EU data centres, with role-based access controls, audit logs, and regular security reviews. You can request our security and processor information directly from the dashboard.

    Not ready to subscribe? Start with the basics for free.

    Download our GDPR Essentials Checklist — a one-page guide covering the 10 things every SME must have in place to avoid the easiest fines. No fluff, no jargon. Built for busy founders.

    Instant download. No spam. Unsubscribe anytime.

    Error

    By submitting your email you agree with our policy

    Paramètres des cookies
    This website uses cookies

    Paramètres des cookies

    Nous utilisons des cookies pour améliorer l'expérience utilisateur. Choisissez les catégories de cookies que vous nous autorisez à utiliser. Vous pouvez en savoir plus à propos de notre politique en matière de cookies en cliquant sur Politique en matière de cookies ci-dessous.

    Ces cookies activent les cookies strictement nécessaires pour la sécurité, la prise en charge de la langue et la vérification de l'identité. Ces cookies ne peuvent pas être désactivés.

    Ces cookies collectent des données afin de mémoriser les choix d'utilisateurs et permettent d'améliorer l'expérience utilisateur.

    Ces cookies nous aident à comprendre comment les visiteurs interagissent avec notre site Web, nous aident à mesurer et à analyser le trafic pour améliorer notre service.

    Ces cookies nous aident à mieux diffuser du contenu marketing et des publicités personnalisées.