25 checks covering cookie consent, DSAR handling, lawful basis disclosure, GPAI obligations, breach notification, and more. Built for mid-market SaaS, fintech, and healthtech teams.
The average mid-market SaaS, fintech, or healthtech company spends €150,000–€250,000 per year on external legal counsel to stay compliant with GDPR. They get a once-a-year audit. A 50-page report. A list of things to fix — delivered months after the site changed.
Then a regulator runs a scan. Finds three cookie consent violations. Issues a fine of €5 million.
The company spent €250K on legal. The legal didn't catch it. The fine came anyway.
Each check below is ordered by frequency of enforcement in 2025 — not theoretical importance. Regulators have moved to automated scanning at scale. These are the items their systems flag first.
GDPR enforcement has matured past theoretical compliance audits. These 12 checks are the ones most frequently cited in 2025 enforcement actions.
The EU AI Act entered into force on August 1, 2024. As of August 2, 2025, its most consequential chapter for mid-market companies — General-Purpose AI (GPAI) obligations — became enforceable. Full enforcement powers activate August 2, 2026.
| Violation | Maximum Penalty |
|---|---|
| Prohibited AI practices (Art. 5) | €35M or 7% of global turnover |
| Violating GPAI obligations (Art. 50) | €15M or 3% of global turnover |
| Supplying incorrect information to authorities | €7.5M or 1.5% of global turnover |
Score: 0 / 25 passed. If you scored below 20, you have compliance gaps that regulators' automated scans will find. All 25 are fixable — and WatchSuit finds them automatically.
WatchSuit's automated compliance scanner has run thousands of scans on mid-market SaaS, fintech, and healthtech sites. Here's what our data shows — anonymized and aggregated from scan results.
About this article: This article is maintained by WatchSuit and updated as enforcement patterns evolve. Last updated: May 2026. For questions about specific compliance gaps identified in your scan, contact privacy@polsia.app.
This article does not constitute legal advice. GDPR and EU AI Act compliance requirements are fact-specific and vary by company size, sector, and jurisdiction. Consult a qualified legal professional for advice applicable to your situation.