GDPR for Small Businesses That Are Not Tech Companies

GDPR guidance is mostly written for organisations with compliance departments. If you run a bakery with four employees, a mailing list and a booking system, most of it does not apply to you, and the parts that do are manageable in an afternoon.

Here is the version scaled to an actual small business.

You are covered, and that is fine

Any business handling personal data of people in the EU is in scope. Personal data means anything identifying a person: names, emails, phone numbers, addresses, photographs, IP addresses, and CVs.

So yes, you are covered. Almost every business is. Being covered does not mean you need a compliance programme.

The register of processing

This is the one genuinely mandatory document, and the one most small businesses do not have.

A register of processing activities, or registre des traitements, lists what personal data you hold, why, where it lives, who can see it, how long you keep it, and who you share it with. Organisations under 250 employees have a reduced obligation, but it still applies to processing that is regular, involves sensitive categories, or poses a risk to individuals, which covers customer and employee data in practice.

For a small business it is a table with maybe eight to fifteen rows. Customers, prospects, employees, job applicants, suppliers, website visitors, newsletter subscribers, CCTV if you have it.

Regulators ask for this first. Having it prepared changes the tone of any interaction considerably.

Know your lawful basis

Every processing activity needs one. In practice small businesses use four:

Contract. Processing needed to deliver what someone bought. Customer names and addresses for fulfilling orders.

Legal obligation. Data you must keep by law. Accounting records, payroll.

Legitimate interests. A broad basis covering things like fraud prevention or contacting existing business customers about related services. Requires a balancing judgement, which for straightforward cases can be brief but should be written down.

Consent. Required for marketing to individuals, and for non-essential cookies. Must be freely given, specific, informed and as easy to withdraw as to give. Pre-ticked boxes are not consent.

The common error is treating consent as the default basis for everything. It is the most fragile one, because it can be withdrawn. Where contract or legal obligation applies, use that.

Privacy notice

Tell people what you do with their data, in plain language, at the point you collect it. Who you are, what you collect, why, on what basis, how long you keep it, who you share it with, and what rights they have.

One page on your website, linked from forms. It does not need to be written by a lawyer, and shorter usually means more compliant, since the requirement is that it be intelligible.

Handling rights requests

People can ask for a copy of their data, ask for correction, ask for deletion, object to processing, or ask for portability. You generally have one month to respond.

Two things make this survivable. Knowing where data actually is, which is what the register gives you. And having a named person who handles requests, so they do not sit in a shared inbox for three weeks.

You almost certainly do not need a Data Protection Officer. That obligation applies to public bodies and to organisations whose core activity involves large-scale monitoring or sensitive data. A normal small business does not qualify, and appointing one voluntarily creates obligations you do not need.

Retention

Do not keep data forever. Decide how long you need each category and delete on schedule.

Some periods are set by law. Accounting records have statutory retention. Employment records have their own. For everything else, decide a period, write it in the register, and actually apply it. Unbounded retention is one of the more common findings in enforcement.

Vendors are your responsibility

If a supplier processes personal data for you, cloud storage, email marketing, accounting software, an AI tool, you need a data processing agreement with them under Article 28.

Reputable vendors publish one. When evaluating any tool, look for the DPA and read the sub-processor annex, which names every third party touching the data and where they sit. It is usually the most informative page a vendor publishes.

For AI tools specifically, this matters more than usual, because inference often runs through providers outside the EU. Mirage Cloud, for instance, publishes a full sub-processor annex naming its model and voice providers with their locations and transfer safeguards. That level of disclosure is what you want to see, and its absence is a reasonable reason to look elsewhere.

Breaches

If personal data is exposed and there is a risk to the people involved, you have 72 hours to notify the supervisory authority. Where the risk is high, you must tell the affected individuals too.

Seventy-two hours is short. Decide in advance who makes the call and what the first steps are. A half-page document is enough.

The realistic checklist

Write the register. Identify your lawful bases. Publish a privacy notice. Name someone to handle requests. Set retention periods and apply them. Get DPAs from your vendors. Have a breach plan.

That is a day of work for a small business, and it puts you ahead of most of your competitors, who have done none of it.

Disclaimer: This and other personal blog posts are not reviewed, monitored or endorsed by TalkMarkets. The content is solely the view of the author and TalkMarkets is not responsible for the content of this post in any way. Our curated content which is handpicked by our editorial team may be viewed here.

Comments