GDPR Compliance for Small Business: A Practical 2026 Guide
GDPR compliance for small business explained: which rules apply to you, the SME exemptions, what documents you need, and how to avoid fines under Article 83.
GDPR compliance for small business sounds like an enterprise problem until a customer emails asking for a copy of everything you hold on them. The General Data Protection Regulation (GDPR) applies to a two-person consultancy exactly as it applies to a bank, with only a handful of size-based reliefs written into the text. This guide covers what genuinely applies to a small company, what you can skip, and the specific articles behind each requirement, though you should consult a qualified attorney for advice tailored to your situation.
What GDPR Compliance for Small Business Actually Means
GDPR compliance is the ongoing practice of processing personal data only where you have a lawful basis, telling people what you do with their data, keeping it secure, and honoring their rights within statutory deadlines. It is not a certificate you obtain once. No official "GDPR certified" badge exists for general compliance under Article 42 outside approved certification schemes.
The regulation applies to any organization that processes the personal data of people in the European Union, regardless of where the organization is based. Article 3(2) extends it to businesses outside the EU that offer goods or services to people in the EU or monitor their behavior. A Texas Shopify store that prices in euros and ships to Ireland is in scope.
Personal data under Article 4(1) is broader than most owners expect. It includes:
- Names, email addresses, and postal addresses
- IP addresses and cookie identifiers, confirmed as personal data in Case C-582/14 (Breyer)
- Customer order histories and support tickets
- CCTV footage of identifiable people
- Employee records, including job applicant CVs you never shortlisted
If you run a mailing list, a contact form, or a website with analytics, you process personal data. The question is not whether GDPR touches your business but how much of it you need to implement.
The Size Exemptions That Genuinely Exist
Three reliefs matter for small companies, and they are narrower than the internet suggests.
Article 30(5): records of processing activities. Organizations with fewer than 250 employees are exempt from maintaining full records of processing activities, unless the processing is likely to result in a risk to rights and freedoms, is not occasional, or involves special category data under Article 9 or criminal conviction data under Article 10. In practice, most businesses process customer data regularly rather than occasionally, so the exemption rarely applies cleanly. The European Data Protection Board and national regulators still expect a simplified record.
Article 37: Data Protection Officer. You must appoint a DPO only if you are a public authority, your core activities require regular and systematic monitoring of data subjects on a large scale, or your core activities involve large-scale processing of special category or criminal offence data. A dental practice with 400 patients does not hit "large scale." An adtech startup profiling millions of visitors does, even with five employees.
Article 27: EU representative. Non-EU businesses in scope of Article 3(2) must appoint a representative in the EU, but Article 27(2) exempts occasional processing that does not include large-scale special category data and is unlikely to result in risk. A US SaaS company with a steady stream of EU subscribers does not qualify for that exemption.
Nothing else scales with headcount. Consent standards, breach deadlines, transparency obligations, and data subject rights apply identically to a freelancer and a multinational.
The Six Lawful Bases and Which Ones Fit a Small Business
Every processing activity needs a lawful basis under Article 6(1). You choose one per purpose, document it, and stick with it. Switching bases later, for example moving from consent to legitimate interests after consent is withdrawn, is not permitted.
| Lawful basis | Article | Typical small business use |
|---|---|---|
| Consent | 6(1)(a) | Marketing emails, non-essential cookies, newsletter signups |
| Contract | 6(1)(b) | Fulfilling an order, delivering a subscription, invoicing |
| Legal obligation | 6(1)(c) | Retaining invoices for tax law, payroll reporting |
| Vital interests | 6(1)(d) | Rare outside healthcare and emergency contexts |
| Public task | 6(1)(e) | Rare outside public authorities |
| Legitimate interests | 6(1)(f) | Fraud prevention, network security, some B2B direct mail |
Two mistakes come up repeatedly in small business GDPR compliance work. The first is using consent for something you need to do anyway, such as processing a delivery address for an order that the customer placed. That is contract, not consent, and asking for consent implies a right to refuse that does not exist.
The second is treating legitimate interests as a catch-all. Article 6(1)(f) requires a documented balancing test weighing your interest against the individual's rights and reasonable expectations. Write it down in three paragraphs: your purpose, why the processing is necessary, and why it does not override the person's interests.
Your Privacy Notice: The Document Regulators Check First
Articles 13 and 14 list exactly what you must tell people, and supervisory authorities routinely open investigations by reading a company's published notice. A compliant notice must cover:
- Your identity and contact details, plus your DPO or EU representative if you have one
- The purposes of processing and the lawful basis for each purpose
- Your legitimate interests, where you rely on Article 6(1)(f)
- Recipients or categories of recipients, including processors like your email provider
- Any transfers outside the EU and the safeguard used, such as Standard Contractual Clauses or the EU-US Data Privacy Framework
- Retention periods, or the criteria used to determine them
- The full list of data subject rights, including the right to lodge a complaint with a supervisory authority
- Whether providing data is a statutory or contractual requirement, and the consequences of not providing it
Vague retention language is the most common failure. "We keep data as long as necessary" tells the reader nothing. Write "customer order records: seven years, to meet tax law retention obligations" and "newsletter subscribers: until unsubscribe, then 30 days."
You can produce a notice covering these points with a privacy policy generator that maps each section to the relevant articles, then adapt the retention and vendor sections to your actual operations. A generated notice that lists tools you do not use is worse than no notice, because it misstates your processing. Our privacy policy guide walks through each clause in more detail.
Cookies, Analytics, and the Consent Rules Small Sites Get Wrong
Cookie consent sits under Article 5(3) of the ePrivacy Directive, not GDPR itself, though GDPR supplies the standard for what counts as valid consent. You must obtain consent before storing or reading any non-essential information on a visitor's device. Essential cookies, such as a session token or a shopping cart identifier, do not need consent.
Analytics cookies are non-essential in most member states. The CNIL in France has fined companies over cookie banners repeatedly, including a 60 million EUR fine against Google and a 40 million EUR fine against Criteo in 2023 relating to consent evidence. Small businesses face far smaller numbers, but the same rules.
A compliant banner for a small site must:
- Load no non-essential scripts before the visitor makes a choice
- Make rejecting as easy as accepting, with a reject button on the first layer
- Avoid pre-ticked boxes, which Case C-673/17 (Planet49) confirmed cannot constitute consent
- Let visitors withdraw consent as easily as they gave it, per Article 7(3)
- Record what each visitor consented to and when
Google Consent Mode v2 signals consent state to Google tags, but it does not collect consent. You still need a Consent Management Platform in front of it. See our guide to GDPR and cookies for how the two layers interact.
Your cookie disclosures also need to match reality. Most small sites load more third-party trackers than the owner realizes, because embedded YouTube videos, chat widgets, and payment scripts each set their own. TermsBox scans a site, lists the cookies and third-party services it finds, and keeps the resulting cookie policy in sync when new ones appear.
Data Subject Rights: The 30-Day Clock
Chapter 3 of the GDPR gives individuals eight rights. Article 12(3) requires you to respond without undue delay and within one month of receiving the request, extendable by two further months for complex requests if you tell the person within the first month.
- Access (Article 15): a copy of their data plus the supporting information from your privacy notice
- Rectification (Article 16): correction of inaccurate data
- Erasure (Article 17): deletion where the data is no longer necessary, consent is withdrawn, or processing was unlawful
- Restriction (Article 18): pause processing while a dispute is resolved
- Portability (Article 20): data in a structured, machine-readable format, limited to consent and contract bases
- Object (Article 21): including an absolute right to stop direct marketing
- Rights around automated decision-making (Article 22)
- Withdraw consent (Article 7(3))
Responses are free under Article 12(5), though you may charge a reasonable fee or refuse for manifestly unfounded or excessive requests. You cannot demand identity documents by default. Article 12(6) allows additional identity information only where you have reasonable doubts.
The practical step for small business GDPR compliance is a written list of every system holding customer data: your CRM, email platform, accounting software, helpdesk, backups, and any spreadsheet on a laptop. Without that list, a single access request turns into a week of searching. Our subject access request guide covers the handling process step by step.
Vendors, Processors, and Article 28 Contracts
Every tool that touches customer data on your behalf is a processor, and Article 28(3) requires a written contract with each one. Mailchimp, Stripe, HubSpot, Google Workspace, and your web host all qualify. The contract must specify subject matter, duration, nature and purpose of processing, types of personal data, categories of data subjects, and the eight mandatory processor obligations.
Privacy Policy Generator
Create a comprehensive privacy policy for your website or app. Create yours in minutes with TermsBox.
Generate NowMost major providers publish a Data Processing Addendum you accept in your account settings or by signature. Your job is to find and accept it, not to draft one. Keep a folder with a copy of each signed DPA, because that folder is the first thing a regulator asks for after a complaint.
International transfers add a second layer. Chapter 5 requires a transfer mechanism for personal data leaving the EEA. In practice, small businesses rely on:
- Adequacy decisions under Article 45, covering the UK, Switzerland, Japan, South Korea, Canada (commercial organizations), and US companies self-certified under the EU-US Data Privacy Framework
- Standard Contractual Clauses under Article 46(2)(c), using the 2021 modules, plus a transfer impact assessment
- Derogations under Article 49, which are narrow and not a basis for routine transfers
Check whether your US vendors are on the Data Privacy Framework list before assuming SCCs are needed. Many large providers are certified, which simplifies the paperwork considerably.
Breach Notification and the 72-Hour Deadline
Article 33(1) requires notification to your supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to individuals. Article 34 adds a duty to tell affected individuals directly where the risk is high. Article 33(5) requires you to document every breach internally, including ones you decide not to report.
A breach is not only a hacker. A misdirected email containing customer details, a lost unencrypted laptop, and a ransomware attack that makes data unavailable all qualify. The clock starts when you become aware, not when you finish investigating.
Prepare three things in advance, because 72 hours across a weekend disappears quickly:
- The name and online reporting form of your lead supervisory authority, for example the ICO in the UK or your national DPA in the EU
- A one-page internal template capturing what happened, categories and approximate numbers affected, likely consequences, and mitigation steps
- A named person responsible for making the call, with a deputy
A Realistic Small Business GDPR Compliance Sequence
You do not need to do everything at once. Work in this order, because each step makes the next one easier.
- Map your data. List every system holding personal data, what it holds, who can access it, and how long it stays. Two hours with a spreadsheet covers most small businesses.
- Assign a lawful basis to each processing purpose you found, and write the legitimate interests balancing tests you need.
- Set retention periods per data category and configure deletion where the tool supports it.
- Publish an accurate privacy notice covering the Articles 13 and 14 points, matched to what your map says.
- Collect your DPAs from every processor and confirm the transfer mechanism for non-EEA vendors.
- Fix cookie consent, ensuring no non-essential script fires before a choice and rejection is one click.
- Write the rights and breach procedures, each one page, and name the responsible person.
- Review quarterly, or whenever you add a new tool, since a new chat widget or pixel changes your disclosures.
Small businesses on a budget can cover the tooling side cheaply. TermsBox offers a free tier with a consent banner covering 5,000 views per month and manual scans, with paid plans at $12 per month for Starter and $25 per month for Pro per website when you need monthly or weekly scanning and documents that update automatically as your site changes. Whatever tooling you pick, the data map and the lawful basis decisions remain yours to make.
What Enforcement Against Small Businesses Actually Looks Like
Article 83(2) requires supervisory authorities to consider the nature, gravity, and duration of the infringement, whether it was intentional or negligent, mitigation steps, and cooperation with the authority before setting a fine. The headline maximums, 20 million EUR or 4% of global annual turnover for the more serious category and 10 million EUR or 2% for administrative failures, apply to the worst cases.
Real enforcement against small organizations is more mundane. The ICO and other authorities most often act on complaints about ignored access requests, marketing to people who unsubscribed, and unsecured data. Outcomes for small businesses are frequently reprimands, enforcement notices, or fines in the hundreds to low thousands of euros. Direct marketing breaches under national ePrivacy rules carry their own penalties, up to 500,000 GBP under the UK PECR.
The bigger practical risks for a small company are commercial. Enterprise buyers send security questionnaires asking for your DPA, your subprocessor list, and your breach procedure. App stores and ad platforms suspend accounts over missing or inaccurate privacy disclosures. Compliance work you complete once answers all of those.
Frequently Asked Questions
Does GDPR apply to small businesses with fewer than 250 employees?
Yes. The General Data Protection Regulation has no minimum size threshold, so a one-person business processing EU residents' data is covered. The only size-based relief is in Article 30(5), which exempts organizations under 250 employees from full records of processing activities unless processing is regular, risky, or involves special category data.
Do I need a Data Protection Officer for my small business?
Most small businesses do not. Article 37(1) requires a DPO only for public authorities, organizations whose core activities involve large-scale regular monitoring of individuals, or large-scale processing of special category or criminal offence data. A marketing agency or online shop with normal customer data typically falls outside those triggers.
What is the minimum GDPR paperwork a small business actually needs?
At minimum you need a privacy notice meeting Articles 13 and 14, a documented lawful basis for each processing purpose under Article 6, a data processing agreement with every processor under Article 28, and a breach response process that can meet the 72-hour deadline in Article 33. Companies with 250 or more employees, or riskier processing, also need Article 30 records.
How much can a small business be fined under GDPR?
Article 83 sets two tiers: up to 10 million EUR or 2% of global annual turnover for administrative failures, and up to 20 million EUR or 4% for breaches of core principles and data subject rights. Regulators must set fines proportionate to the case, and small business fines from bodies like the ICO and CNIL usually land in the hundreds to low thousands of euros.
Do I need cookie consent if I only use Google Analytics?
Yes. Article 5(3) of the ePrivacy Directive requires consent before storing or reading any non-essential information on a visitor's device, and analytics cookies are treated as non-essential in most EU member states. You must obtain opt-in consent before the analytics script loads, and Google Consent Mode v2 alone does not replace a compliant consent banner.
Does GDPR apply to my US small business if I have no EU office?
It can. Article 3(2) extends GDPR to organizations outside the EU that offer goods or services to people in the EU or monitor their behavior. Passively receiving a few EU visitors is not enough, but pricing in euros, shipping to EU countries, or retargeting EU visitors brings you in scope.