GDPR for small businesses: a practical starting point

The GDPR applies to your business if you’re established in the EU, or if you offer goods or services to people in the EU or monitor their behavior online, wherever you’re based. The UK has its own near-identical version, the UK GDPR. For a small business, compliance mostly comes down to a short list: know what personal data you hold and why, have a lawful basis for using it, explain it in a privacy notice, keep it secure, sign data processing agreements with your suppliers, and be ready to handle requests and breaches. You don’t need a consultant’s 200-page binder to get there.

There’s no small-business exemption from the core rules. Size mostly changes how much paperwork is proportionate, not whether the principles apply.

First, check whether it applies to you

A bakery in Lyon with a customer mailing list is covered. So is an online store in Ohio that ships to Germany, prices in euros and runs ads aimed at French shoppers. A US consultancy whose website happens to be visible in Europe, but which doesn’t market to or track people there, probably isn’t, although other privacy laws may still apply to it.

Flowchart with three questions: are you established in the EU or UK, do you offer goods or services to people there, and do you monitor their behavior such as tracking or profiling; a yes to any question means the GDPR applies, and three noes mean you are probably outside it
One yes is enough. The UK GDPR uses the same structure for people in the UK.

“Personal data” is broad. Names, emails, phone numbers, IP addresses, cookie IDs, delivery addresses, customer notes, staff records and CCTV footage all count. If it can identify a person, directly or indirectly, it’s in scope. Information about a company itself (a generic info@ address, say) generally isn’t personal data, but a named person’s work email is.

Know what you hold and why

Start with a simple spreadsheet. For each kind of data (customers, newsletter subscribers, staff, suppliers, website visitors), write down what you collect, why, where it’s stored, who you share it with and how long you keep it. That’s the backbone of everything else.

Formal records of processing are required, but businesses with fewer than 250 employees are partly exempt. The exemption falls away if the processing isn’t occasional, and for most businesses it isn’t (payroll alone runs every month). In practice, keep the spreadsheet. It’s the first thing a regulator or a big client will ask for.

Pick a lawful basis for each use

The GDPR lists six lawful bases for processing personal data. Small businesses mostly use four:

A common mistake is relying on consent for everything. If you need the data to fulfill an order, consent is the wrong basis, because the customer can’t meaningfully say no.

Cookies and marketing emails are also governed by separate e-privacy rules, which vary by country and generally require consent for non-essential cookies and for most direct marketing to individuals. In the UK these rules are known as PECR.

The documents you actually need

In the UK, most businesses that process personal data also have to pay an annual data protection fee to the Information Commissioner’s Office. It’s modest for small businesses, and easy to forget.

You probably don’t need a Data Protection Officer. The GDPR requires one for public authorities and for organizations whose core activities involve large-scale monitoring of people or large-scale processing of sensitive data. A ten-person agency doesn’t usually qualify, although someone should still own privacy internally.

Requests and breaches

People have rights to access their data, correct it, have it deleted in some circumstances, object to certain uses and get a copy in a portable format. You generally have one month to respond, which can be extended for complex requests. Access requests from unhappy customers and departing employees are common, so know where your data lives before one arrives.

If you have a personal data breach (a lost laptop, a hacked mailbox, a spreadsheet emailed to the wrong list), you must report it to the relevant data protection authority within 72 hours of becoming aware of it, unless it’s unlikely to put people at risk. If the risk to people is high, you must tell them too, without undue delay. Record every breach, including the ones you decide not to report.

Timeline of a data breach: at hour zero you become aware, then you assess the risk, and by hour 72 you report to the regulator if there is a risk to people; if the risk is high you also tell the affected people without undue delay, and every breach goes in your log
The 72-hour clock starts when you become aware of the breach, not when you finish investigating it.

Sending data outside the EU or UK

Sending EU personal data outside the EU, including to a US software provider, needs a transfer mechanism. The EU has adequacy decisions for some countries, including the UK and, for certified companies, the US under the EU-US Data Privacy Framework. Otherwise, standard contractual clauses are the usual route. Most major software vendors build these into their data processing terms, so check that yours do.

What the risk really looks like

The maximum fines are large: up to €20 million or 4% of worldwide annual turnover, whichever is higher, for the most serious breaches. Small businesses rarely see anything close to that. The realistic risks are a complaint from a customer or ex-employee that prompts questions from the regulator, a bigger client refusing to sign because you can’t answer their privacy questionnaire, and the time and cost of cleaning up a breach you weren’t ready for.

Next steps

  1. Build the data spreadsheet this week. An afternoon is usually enough.
  2. Check that every supplier on it has a data processing agreement in place.
  3. Update your privacy notice and cookie banner to match what you actually do.
  4. Turn on two-factor authentication everywhere and encrypt laptops.
  5. Write a one-page breach plan with names and phone numbers.

If a larger client sends you their data processing terms or a confidentiality clause to sign, you can review them with LegalWolf before agreeing to obligations you can’t meet.

This article is general information, not legal or tax advice. Laws differ between countries and states and change over time, so check the rules that apply to you or speak to a qualified professional.