A practical guide to GDPR compliance for small and growing businesses

EU flags waving in front of the European Commission building in Brussels, Belgium

Photo by Marco

The General Data Protection Regulation, usually known as the GDPR, can feel like a difficult place to start. There are legal terms to understand, documents to prepare, supplier arrangements to review and security measures to consider.

For a small or growing business, the hardest part is often working out which requirements apply and what a reasonable first step looks like. Many businesses collect personal information through their website, email, accounting software, customer systems and cloud platforms, but have never had a clear picture of how all those pieces fit together.

A practical approach begins with understanding the personal data your business handles, why you use it, where it goes and how it is protected. Once that foundation is clear, the individual requirements of the GDPR become easier to organise and address.

This article provides general information and should not be treated as legal advice. Businesses should seek specialist legal advice where the application or interpretation of the GDPR is uncertain.

What the GDPR covers

The GDPR is the European Union’s main data protection law. It governs how organisations collect, use, store, share and protect personal data, while giving individuals rights over information that relates to them.

Personal data is any information relating to an identified or identifiable living person. This can include obvious information such as a name, email address or telephone number, along with less obvious information such as an IP address, device identifier, account history or location data. Information that has been encrypted or given a pseudonym may still be personal data when it can be linked back to an individual.

In a small business, personal data may be found in:

  • Customer and prospect records.
  • Employee and contractor files.
  • Email accounts and shared mailboxes.
  • Accounting, payroll and payment systems.
  • Website forms and analytics platforms.
  • Marketing and newsletter systems.
  • Support tickets and project management tools.
  • Cloud storage and shared documents.
  • Security logs and access records.

The GDPR can apply to small businesses as well as large organisations. Its application depends mainly on the nature of the business’s activities and the risks those activities create for individuals. Some of the more formal obligations may not apply to every smaller business, particularly where personal data processing is limited and low risk.

Does the GDPR apply to businesses outside the EU?

A business does not have to be located in the European Union for the GDPR to apply.

A business based in Australia, New Zealand, the United States or another country may come within the GDPR when it:

  • Has an establishment in the EU or European Economic Area and processes personal data as part of that establishment’s activities.
  • Offers goods or services, including some free services, to people located in the EU.
  • Monitors the behaviour of people in the EU, such as through certain forms of online tracking, profiling or behavioural analysis.

The important wording is people located in the EU, rather than EU citizens. The person’s location in connection with the relevant activity is generally more important than their nationality.

For example, an Australian software business that actively markets subscriptions to organisations in France and Germany, accepts payment in euros and provides European delivery or support options may be offering services to people in the EU.

An Australian consultancy with a locally focused website does not necessarily fall within the GDPR simply because someone in Europe can visit the site. The European Commission gives the example of a non-EU provider whose customers may use its services while travelling in Europe. Where the provider does not specifically target people in the EU, that activity alone does not bring it within the GDPR.

Indicators that a business may be targeting the EU can include:

  • Advertising directed towards particular European countries.
  • Referring to European customers or users in marketing.
  • Offering prices in European currencies.
  • Providing delivery options within the EU.
  • Using European languages when they are not commonly used in the business’s home market.
  • Designing services specifically for people or organisations in the EU.

No single indicator provides a complete answer. The business’s overall activities and intentions need to be considered.

A business outside the European Economic Area that is subject to the GDPR may also need to appoint a representative within the EEA. There are exceptions, so this should be assessed based on the nature, frequency and risk of the processing.

Businesses may also encounter GDPR responsibilities through their commercial relationships. An EU-based customer may require privacy and data-processing terms from an overseas supplier, even where the supplier’s direct territorial position requires further analysis.

Where the answer is unclear, legal advice is worthwhile. Confirming whether the GDPR applies is much easier than building a compliance program around the wrong assumption.

Start by understanding the personal data you hold

A clear picture of your data is the foundation for most GDPR work.

Without that picture, it is difficult to write an accurate privacy notice, establish appropriate retention periods, respond to a person requesting their information or understand the effect of a data breach.

A sensible first action is to create a simple data inventory. For each important business activity, record:

  • What personal data is collected.
  • Whose information it is.
  • Where the information comes from.
  • Why the business uses it.
  • Which systems store it.
  • Who can access it.
  • Which service providers receive it.
  • How long it is kept.
  • Whether it is sent outside the EEA.

This does not have to begin as a complicated governance system. A structured spreadsheet can provide enough visibility to identify gaps and guide the next steps.

Some businesses must maintain a formal record of processing activities. Businesses with fewer than 250 employees have a limited exemption, but the exemption may not apply when processing is regular, creates risks for individuals or involves sensitive information or criminal records. In practice, many businesses find that maintaining a proportionate processing record is useful even when the formal requirement is uncertain.

Be clear about why you use personal data

Every use of personal data must have an appropriate legal basis. This is the reason the GDPR allows the business to collect or use the information.

The available legal bases include:

  • Processing that is necessary to perform a contract.
  • Processing required to meet a legal obligation.
  • Processing based on the organisation’s legitimate interests.
  • Processing for which the individual has given valid consent.
  • Processing necessary to protect someone’s vital interests.
  • Processing necessary for a task carried out in the public interest.

Consent is only one of these bases. A business does not need to ask for consent every time it handles personal data.

For example, an online retailer may need a customer’s delivery address to fulfil an order. That processing may be necessary to perform the contract with the customer. Payroll records may be needed to meet employment and taxation obligations.

Where a business relies on legitimate interests, it should identify the interest being pursued and consider whether the individual’s rights and freedoms outweigh it.

The legal basis should be considered before the processing begins and documented as part of the business’s data inventory or processing record.

This review also helps the business apply two important principles:

  • Collect only the personal data genuinely required for the purpose.
  • Keep it only for as long as there is a valid reason to retain it.

The GDPR requires personal data to be processed lawfully, fairly and transparently, collected for clear purposes, limited to what is necessary, kept accurate and protected appropriately.

Make your privacy information clear and accurate

A privacy notice explains how the business handles personal data. It gives customers, employees and other individuals the information they need to understand what is happening to their information.

Depending on the context, a privacy notice will usually explain:

  • Who is responsible for the processing.
  • What personal data is collected.
  • Why the data is used.
  • Which lawful basis applies.
  • Who receives or has access to the data.
  • How long the data is retained.
  • Whether it is transferred outside the EU.
  • What rights the individual has.
  • How the business can be contacted.
  • How the individual can complain to a data protection authority.

The notice should reflect what the business actually does. A generic policy copied from another website may describe systems or practices that do not exist, while overlooking important activities that do.

It also helps to consider when the information is presented. A lengthy website privacy notice may be appropriate as the main reference document, but shorter explanations can be provided near online forms, account registration pages and other collection points.

The GDPR requires this information to be concise, transparent, accessible and written in clear language.

Prepare to respond when people exercise their rights

The GDPR gives individuals several rights over their personal data. Depending on the circumstances, a person may ask a business to:

  • Confirm whether their information is being processed.
  • Provide access to their personal data.
  • Correct incomplete or inaccurate information.
  • Delete information where the right to erasure applies.
  • Restrict how information is used.
  • Provide eligible information in a portable format.
  • Stop certain processing.
  • Stop using their information for direct marketing.
  • Review certain decisions made solely through automated processing.

These rights do not apply in exactly the same way in every situation. For example, a request for deletion does not always require the business to remove information that it has a legal obligation to retain.

The practical starting point is to establish a simple process that covers:

  • Where requests should be sent.
  • Who is responsible for managing them.
  • How the person’s identity will be confirmed.
  • How relevant systems and records will be searched.
  • How decisions and correspondence will be documented.
  • When legal advice or escalation is required.

The business must generally respond without undue delay and within one month of receiving a request.

A central request log can help prevent an email from being overlooked and give the business a record of how each matter was handled.

Review the businesses that process data for you

Small businesses often rely on other companies to store or process personal data. These may include:

  • Cloud hosting providers.
  • Microsoft 365 or Google Workspace.
  • Payroll and accounting platforms.
  • Customer relationship management systems.
  • Email marketing providers.
  • Website hosting and analytics services.
  • Managed IT and support providers.
  • Payment and e-commerce platforms.

Under the GDPR, the organisation that decides why and how personal data is processed is generally the controller. A supplier that processes the information on the controller’s behalf is generally a processor.

Using a processor does not remove the controller’s responsibilities. The business should choose providers that can offer suitable privacy and security assurances, understand which subcontractors they use and put the required contractual terms in place.

The agreement should address matters such as confidentiality, security, assistance with individual rights, breach notification, deletion or return of information and the use of subprocessors. The European Commission advises controllers to appoint processors that provide sufficient guarantees that their measures will meet GDPR requirements.

A sensible supplier review should focus first on the providers that hold the most sensitive information, support critical business functions or have broad access to company systems.

Understand where personal data is transferred

Cloud services can make the location of personal data less obvious. A provider may be headquartered in one country, operate support services in another and store customer information across several regions.

When personal data is transferred from the EEA to a country outside it, the GDPR’s international transfer rules may apply.

Depending on the destination and circumstances, a transfer may be supported by:

  • An adequacy decision made by the European Commission.
  • Appropriate safeguards such as Standard Contractual Clauses.
  • Binding Corporate Rules within an eligible corporate group.
  • A specific exception available under the GDPR.

The underlying principle is that the protection attached to the data should continue when the information leaves the EU.

A useful starting action is to ask important providers where personal data is stored, which international transfers occur and what transfer mechanism they rely on. Complex transfer arrangements should be reviewed with a privacy professional.

Protect personal data with appropriate security

Privacy compliance and cybersecurity are closely connected. A business cannot handle personal data responsibly if accounts, devices and cloud services are poorly protected.

The GDPR does not prescribe a single security product or checklist for every organisation. It expects technical and organisational safeguards that are appropriate to the nature of the data, the way it is used and the potential effect on individuals if something goes wrong.

For many small and growing businesses, the practical foundations include:

  • Enabling multi-factor authentication on important accounts.
  • Limiting administrative access.
  • Giving employees access only to the information required for their work.
  • Removing access promptly when someone leaves or changes roles.
  • Keeping operating systems, applications and devices updated.
  • Encrypting suitable devices and information.
  • Maintaining reliable backups and testing recovery.
  • Configuring Microsoft 365, Google Workspace and other cloud services securely.
  • Training employees in secure and appropriate data handling.
  • Reviewing account activity and important security alerts.
  • Documenting security responsibilities and essential procedures.

The measures should reflect the risks involved. A consultancy storing basic business contact details will have a different risk profile from a healthcare provider holding medical information or a software platform processing large volumes of customer data.

Prepare for personal data breaches

A personal data breach is not limited to a cyberattack. It can occur whenever personal data is accidentally or unlawfully lost, changed, disclosed, destroyed or accessed.

Examples include:

  • An employee sending a document to the wrong recipient.
  • A laptop containing personal data being lost or stolen.
  • An attacker gaining access to an email account.
  • A customer being given access to another customer’s information.
  • Important records being deleted without a usable backup.
  • A supplier exposing information through an incorrectly configured system.

The business should have a process for containing the incident, preserving evidence, identifying the affected information and assessing the possible effect on individuals.

It should also determine whether the breach must be reported. Where a breach is likely to create a risk to individuals, the relevant data protection authority generally needs to be notified within 72 hours of the business becoming aware of it. Where the likely risk is high, affected individuals may also need to be informed without undue delay.

All personal data breaches should be documented, including those that do not meet the notification threshold.

Preparing a short response procedure and assigning responsibility before an incident occurs can make these decisions much more manageable.

Recognise when additional requirements may apply

Some businesses will need more formal privacy arrangements because of the nature or scale of their activities.

Additional requirements may arise when a business:

  • Processes health, biometric or other sensitive information.
  • Regularly monitors or profiles large numbers of people.
  • Uses personal data in ways likely to create a high risk for individuals.
  • Processes children’s information.
  • Makes significant decisions using automated systems.
  • Handles criminal records.
  • Operates across several EU countries.

Depending on the circumstances, this may involve completing a Data Protection Impact Assessment, appointing a Data Protection Officer or consulting with a data protection authority.

A Data Protection Officer is generally required where an organisation’s core activities involve large-scale processing of sensitive data or large-scale, regular and systematic monitoring of individuals. It is not a universal requirement for every small business.

The aim is to recognise when ordinary business processing has moved into an area that deserves closer assessment and specialist advice.

A practical GDPR starting checklist

GDPR compliance is easier to manage when the work is arranged in a sensible order. The following sequence helps establish the foundation before moving into more specialised questions.

  1. Confirm whether the GDPR applies. Consider where the business operates, who it serves and whether it targets or monitors people in the EU.
  2. Map the personal data you handle. Record what is collected, why it is used, where it is stored, who can access it and which suppliers receive it.
  3. Identify the lawful basis for important processing. Document why each main activity is permitted and check whether additional conditions apply to sensitive information.
  4. Review what you collect and retain. Remove unnecessary information and establish reasonable retention periods.
  5. Update your privacy information. Make sure notices clearly and accurately explain the business’s current practices.
  6. Prepare for individual rights requests. Assign responsibility and establish a process for finding information and responding within the required timeframe.
  7. Review important suppliers. Check data-processing contracts, security arrangements, subprocessors and international transfers.
  8. Strengthen access and security controls. Prioritise account protection, device security, cloud configuration, backups and employee access.
  9. Prepare for personal data breaches. Document how incidents will be contained, assessed, recorded and reported.
  10. Identify higher-risk activities. Determine whether a Data Protection Impact Assessment, Data Protection Officer or specialist advice may be required.
  11. Assign ongoing responsibility. Privacy arrangements should be reviewed when systems, suppliers, products or business activities change.

This provides a workable foundation without trying to solve every possible privacy question at the same time.

A clearer path to GDPR compliance

GDPR compliance can look broad when it is viewed as one large legal project. It becomes more practical when the work begins with a few clear questions: what information does the business hold, why is it needed, where does it go, who can access it and how is it protected?

From there, the business can improve its notices, processes, supplier arrangements and security controls in a sensible order.

The goal is not to produce paperwork that sits untouched. Good privacy practices should give the business a clearer understanding of its information, better control over its systems and a more reliable way to respond when customers, employees or regulators ask questions.

BrightShield can help turn those responsibilities into a prioritised plan and provide the level of support needed to carry the work through to completion.

Subscribe to our newsletter

Every week we publish a short email on a topic we think you'll find interesting. We know you're busy, so we keep it short, snappy, and relevant.

Let's Begin

Ready to understand your security risks?

Get a clear, practical view of your risks and a plan to fix them with a BrightShield Security Audit.