The General Data Protection Regulation (GDPR) is one of the world’s most important data protection laws.
It regulates how organizations collect, use, store, protect, and share personal data.
Many small businesses assume GDPR applies only to large companies operating in Europe. That is not necessarily true.
A small business outside the European Union can also fall within the GDPR’s scope in certain circumstances—for example, if it offers goods or services to people in the EU or monitors their behaviour.
For small businesses, GDPR compliance can initially seem complicated.
You may wonder:
- What personal data do I need to protect?
- Does GDPR apply to my business?
- Do I need a privacy policy?
- Do I need customer consent?
- What are the GDPR data protection principles?
- What happens if there is a data breach?
- Do I need a Data Protection Officer?
- How long can I keep customer data?
- What rights do customers have?
- Do I need a GDPR consultant?
This beginner’s guide explains the fundamentals in straightforward language.

What Is GDPR?
GDPR stands for General Data Protection Regulation.
It is the European Union’s data protection framework that governs the processing of personal data.
The regulation establishes rules around:
- Personal data
- Data collection
- Data processing
- Data storage
- Data sharing
- Data security
- Individual privacy rights
- International data transfers
- Data breaches
- Organizational accountability
The European Commission provides specific guidance for businesses and organizations on GDPR principles, legal grounds, obligations, individual rights, and enforcement.
Does GDPR Apply to Small Businesses?
Yes, potentially.
The size of your business does not automatically determine whether GDPR applies.
The European Commission states that GDPR can apply to SMEs and that applicability depends on the nature of the organization’s activities.
For example, a small business may process personal data when it:
- Sells products online
- Runs an e-commerce store
- Collects customer email addresses
- Provides SaaS software
- Runs online advertising
- Operates a website
- Sends marketing emails
- Provides consulting services
- Manages employee information
- Uses customer analytics
The important question is not simply:
“How many employees do we have?”
Instead, ask:
“What personal data do we process, why do we process it, and who are the people whose data we handle?”
Does GDPR Apply to Businesses Outside the EU?
Potentially, yes.
This is especially important for businesses in countries such as:
- United States
- Canada
- United Kingdom
- Australia
- India
- Singapore
The GDPR can apply to organizations established outside the EU when they offer goods or services to individuals in the EU or monitor their behaviour there, subject to the regulation’s requirements and scope.
Example
Imagine a US-based SaaS company.
It has no office in Europe but sells its software to customers in Germany and France.
Depending on the company’s activities and circumstances, GDPR obligations may apply.
Similarly, an online store outside the EU that actively offers products or services to people in EU countries may need to assess whether GDPR applies to its processing activities.
What Is Personal Data Under GDPR?
Personal data is information relating to an identified or identifiable individual.
Examples can include:
- Name
- Email address
- Phone number
- Postal address
- IP address
- Online identifiers
- Customer ID
- Location information
- Account information
- Employment information
- Payment-related information
- Certain device and tracking information
The exact classification depends on the circumstances.
Small businesses often process more personal data than they realize.
For example, a simple contact form might collect:
Name + Email + Message
That is already personal information relating to an individual.
What Does “Processing Personal Data” Mean?
Processing is a broad concept.
It can include:
- Collecting
- Recording
- Organizing
- Storing
- Accessing
- Using
- Sharing
- Updating
- Deleting
For example:
A customer submits an online form.
Collect → Store → Read → Respond → Retain → Delete
All of these activities can involve processing personal data.
The 7 GDPR Principles
The GDPR is built around core data protection principles.
The European Commission and UK ICO guidance identify seven central principles:
- Lawfulness, fairness and transparency
- Purpose limitation
- Data minimisation
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability
Let’s understand each one.
1. Lawfulness, Fairness and Transparency
A business should process personal data lawfully and fairly and should be clear about how it uses that information.
For example, if you collect someone’s email address, you should have an appropriate legal basis for using it.
You should also explain relevant data practices through appropriate privacy information.
The ICO describes transparency as being open and honest with people about how their personal data is used.
2. Purpose Limitation
You should collect personal data for specific purposes and avoid using it for unrelated purposes.
Example
A customer provides their phone number to arrange delivery.
Using that number for an unrelated marketing campaign may require a separate legal analysis and may not be appropriate.
The purpose for collecting information matters.
3. Data Minimisation
Only collect the personal information you actually need.
Don’t collect information simply because:
“We might need it someday.”
Example
If a newsletter only requires an email address, there may be no reason to require:
- Date of birth
- Home address
- Employer
- Government ID
unless there is a legitimate reason for collecting that information.
Data minimisation can also reduce the amount of information exposed if a security incident occurs.
4. Accuracy
Personal information should be accurate and kept up to date where necessary.
For example, if a customer changes their address, your business should have a process for correcting outdated information.
Incorrect information can create:
- Customer service problems
- Delivery problems
- Billing errors
- Compliance issues
5. Storage Limitation
Businesses should not keep personal data indefinitely without justification.
You should determine appropriate retention periods based on:
- Why the data is needed
- Legal obligations
- Contractual requirements
- Business requirements
- Security considerations
When information is no longer needed, it should be appropriately deleted or anonymized where applicable.
6. Integrity and Confidentiality
Personal data should be protected using appropriate security measures.
Depending on the business, these may include:
- Password protection
- MFA
- Encryption
- Access controls
- Backups
- Security monitoring
- Secure software
- Employee training
The level of security should be appropriate to the risk.
7. Accountability
Accountability means that an organization is responsible for complying with the data protection principles and should be able to demonstrate its compliance.
This can involve:
- Policies
- Records
- Risk assessments
- Security procedures
- Training records
- Data-processing documentation
- Vendor management
- Incident records
GDPR compliance isn’t simply about saying:
“We protect customer data.”
You should be able to demonstrate how you protect it.
What Is a Lawful Basis Under GDPR?
Before processing personal data, a business generally needs an appropriate lawful basis.
The six lawful bases are:
- Consent
- Contract
- Legal obligation
- Vital interests
- Public task
- Legitimate interests
The appropriate basis depends on the processing activity. The ICO emphasizes that none of these bases is automatically “better” than the others; organizations should identify the basis that is appropriate for the specific processing.
1. Consent
Consent means the person has given an appropriate affirmative indication agreeing to the processing.
If relying on consent, it generally needs to be:
- Freely given
- Specific
- Informed
- Unambiguous
- Easy to withdraw
Pre-ticked boxes are not an appropriate way to obtain valid consent under the ICO’s guidance.
Example
A website might ask:
“Would you like to receive our marketing emails?”
The person actively chooses whether to subscribe.
2. Contract
Processing may be necessary to perform a contract or take steps requested before entering into a contract.
Example
An online store needs a customer’s:
- Name
- Delivery address
- Order details
to fulfill an order.
The exact lawful basis should be assessed based on the actual processing activity.
3. Legal Obligation
Sometimes a business must process information because the law requires it.
Examples can include certain:
- Tax records
- Accounting records
- Employment records
- Regulatory information
4. Legitimate Interests
A business may sometimes rely on legitimate interests when it has a legitimate reason for processing and the necessary conditions are satisfied.
This requires more than simply saying:
“It’s useful for our business.”
Organizations should assess whether the processing is appropriate, necessary, and balanced against the individual’s interests and rights.
What Are GDPR Data Subject Rights?
GDPR gives individuals various rights concerning their personal data.
These include rights relating to:
- Being informed
- Access
- Rectification
- Erasure
- Restriction of processing
- Data portability
- Objection
- Certain automated decision-making and profiling situations
The precise application and exceptions depend on the circumstances.
For a small business, having a process for handling these requests is important.
Right to Be Informed
People should receive appropriate information about how their personal data is being used.
This is commonly provided through a privacy notice.
A privacy notice can explain:
- What data you collect
- Why you collect it
- How you use it
- Who receives it
- How long you keep it
- Relevant rights
- How to contact you
Right of Access
An individual can request access to personal information that an organization holds about them, subject to applicable rules and exceptions.
This is often called a:
Subject Access Request (SAR)
Small businesses should have a process for recognizing and responding to these requests.
Right to Rectification
Individuals can request correction of inaccurate personal information in appropriate circumstances.
Example
A customer’s name is incorrectly recorded.
The business should have a process for correcting it.
Right to Erasure
This is commonly known as the:
“Right to be forgotten.”
In certain circumstances, an individual can request deletion of their personal data.
However, this right is not absolute.
There can be circumstances where an organization is legally permitted or required to retain information.
Right to Restrict Processing
In certain circumstances, an individual can request that an organization restrict how it processes their personal information.
This is different from simply deleting the data.
Right to Data Portability
Under applicable circumstances, individuals may have a right to receive certain personal data in a structured, commonly used, machine-readable format and transmit it to another organization.
Right to Object
Individuals may have the right to object to certain processing activities, including certain direct marketing activities.
Businesses should understand how objections are handled and ensure relevant requests reach the appropriate person.
What Is a GDPR Privacy Policy?
A website privacy policy or privacy notice explains how your business handles personal information.
It can cover:
- Information collected
- Purpose of collection
- Legal basis
- Cookies and tracking
- Analytics
- Marketing
- Third-party services
- Data retention
- Data rights
- International transfers
- Contact information
A privacy notice should accurately reflect what your business actually does.
Simply copying a generic privacy policy from another website does not automatically make a business GDPR compliant.

GDPR and Cookies
Cookies can involve personal data and online identifiers depending on how they are used.
Businesses should distinguish between:
- Essential cookies
- Analytics cookies
- Advertising cookies
- Personalization cookies
- Tracking technologies
The GDPR analysis for cookies can also interact with other applicable privacy/electronic communications rules.
For businesses targeting European users, cookie and tracking practices should therefore be reviewed carefully rather than relying on a generic cookie banner.
GDPR and Email Marketing
Email marketing is another area where small businesses need to pay attention.
Before sending marketing emails, businesses should consider:
- The applicable lawful basis
- Direct marketing rules
- Consent requirements where applicable
- Opt-out mechanisms
- Record keeping
- Email-list sources
A person giving you their email address does not automatically mean you can send every type of marketing message to them.
GDPR and Employee Data
GDPR isn’t only about customers.
Businesses can also process personal data belonging to:
- Employees
- Job applicants
- Contractors
- Freelancers
- Former employees
Examples include:
- Names
- Addresses
- Payroll information
- Employment records
- Performance information
- Contact details
Employee data should be handled according to applicable data protection and employment requirements.
GDPR and SaaS Businesses
SaaS companies frequently process personal data on behalf of customers.
This creates an important distinction between:
Data Controller
The organization that determines the purposes and means of processing personal data.
Data Processor
An organization that processes personal data on behalf of a controller.
A SaaS provider may act as a processor for certain customer data, while acting as a controller for other processing activities, depending on the circumstances.
The European Commission and ICO provide guidance on controller and processor roles.
What Is a Data Processing Agreement?
A Data Processing Agreement (DPA) is a contractual arrangement between a controller and processor that addresses relevant data-processing requirements.
For SaaS companies, DPAs are commonly important when processing customer personal data on behalf of business customers.
A DPA may address areas such as:
- Processing instructions
- Security
- Confidentiality
- Subprocessors
- Data breaches
- Assistance with data subject rights
- Data deletion or return
- Audits
The exact contractual requirements should be reviewed against applicable law and the specific relationship.
GDPR and Third-Party Vendors
Small businesses often use many third-party services.
For example:
Website → Hosting → Analytics → Email marketing → CRM → Payment provider → Customer support
Some of these vendors may process personal information.
You should know:
- What data they receive
- Why they receive it
- What role they have
- Where data is processed
- What contractual protections apply
- Whether subprocessors are involved
Vendor management is an important part of privacy compliance.
GDPR and Data Breaches
A personal data breach can involve:
- Unauthorized access
- Accidental disclosure
- Loss
- Destruction
- Alteration
- Theft
Examples include:
- Lost laptop containing customer data
- Hacked email account
- Accidentally emailing a customer list to the wrong recipient
- Ransomware affecting personal data
- Database exposed publicly
Not every breach automatically requires notification to a regulator, but organizations need a process to assess breaches promptly.
Under GDPR, where a personal data breach is reportable to the relevant supervisory authority, the general rule is notification without undue delay and, where feasible, within 72 hours after becoming aware of it.
GDPR Security Measures for Small Businesses
A small business can establish a practical security foundation with measures such as:
Account Security
- Strong passwords
- MFA
- Separate administrator accounts
- Access reviews
Device Security
- Screen locks
- Encryption
- Security updates
- Endpoint protection
Data Security
- Encryption
- Secure backups
- Access controls
- Secure deletion
Website Security
- HTTPS
- Secure hosting
- Updated CMS
- Updated plugins
- Web application security
Employee Security
- Security training
- Phishing awareness
- Clear data-handling procedures
Do Small Businesses Need a Data Protection Officer?
Not every small business needs to appoint a DPO.
The requirement depends on the organization’s processing activities.
For example, the European Commission states that a DPO is required in specified circumstances, including where core activities involve large-scale processing of sensitive data or large-scale, regular and systematic monitoring of individuals.
Therefore:
Small company ≠ automatically exempt
and
Small company ≠ automatically required to have a DPO
The actual processing activities matter.
Do Small Businesses Need a Record of Processing Activities?
This depends on the circumstances.
The GDPR contains an exemption from some record-keeping requirements for organizations with fewer than 250 employees, but the exemption has important conditions and does not apply where processing is regular, risky to individuals’ rights and freedoms, or involves certain sensitive or criminal-record data.
The European Commission has also discussed more recent simplification proposals affecting record-keeping requirements for smaller organizations, so businesses should verify the current rules applicable to their situation.
For practical compliance, maintaining a basic inventory of personal-data processing can still be very useful even when a formal record is not legally required.
GDPR Compliance Checklist for Small Businesses
Use the following as a starting point.
Step 1 — Identify Your Data
☐ Customer names
☐ Email addresses
☐ Phone numbers
☐ Addresses
☐ Employee information
☐ Payment-related information
☐ Website analytics data
☐ Cookies and identifiers
☐ Marketing lists
Step 2 — Understand Why You Collect It
For every major category, ask:
Why do we need this information?
If you don’t have a clear reason, reconsider collecting it.
Step 3 — Identify the Lawful Basis
For each processing activity, determine the appropriate lawful basis.
Possible bases include:
- Consent
- Contract
- Legal obligation
- Legitimate interests
- Vital interests
- Public task
Do not automatically use consent for every activity. The appropriate basis depends on the purpose and circumstances.
Step 4 — Create Appropriate Privacy Information
Explain to people:
- What you collect
- Why you collect it
- How you use it
- Who receives it
- How long you retain it
- What rights they have
- How they can contact you
Step 5 — Secure the Data
Implement appropriate measures such as:
- MFA
- Encryption
- Backups
- Access controls
- Software updates
- Security monitoring
Step 6 — Review Vendors
Make a list of third-party services that process personal information.
Examples:
- Hosting provider
- CRM
- Email platform
- Analytics
- Cloud storage
- Payment provider
- Customer support software
Step 7 — Create a Data-Breach Process
Define:
Detect → Assess → Contain → Document → Notify if required → Remediate
Don’t wait until a breach occurs to decide who should respond.
Step 8 — Prepare for Data Requests
Create a process for handling:
- Access requests
- Correction requests
- Deletion requests
- Restriction requests
- Objections
- Portability requests
Step 9 — Review Data Retention
For each major type of personal data, determine:
How long do we actually need this?
Then establish appropriate deletion or anonymization procedures.
Common GDPR Mistakes Small Businesses Make
“We Are Too Small for GDPR”
Company size does not automatically remove GDPR obligations.
The nature of processing and other applicability requirements matter.
“We Have a Privacy Policy, So We’re Compliant”
A privacy policy is only one part of a broader compliance program.
You also need appropriate practices, controls, processes, and accountability.
“We Need Consent for Everything”
Consent is only one lawful basis.
Depending on the processing activity, another lawful basis may be more appropriate.
“We Can Keep Customer Data Forever”
Storage limitation means businesses should consider how long personal information needs to be retained.
“Our Cloud Provider Handles GDPR”
Using a GDPR-aware cloud provider does not automatically make your business compliant.
Your business still needs to understand its own processing activities, responsibilities, configurations, contracts, and security practices.
“GDPR Only Applies to EU Companies”
This is incorrect.
Certain organizations outside the EU can fall within GDPR’s territorial scope.
How Much Does GDPR Compliance Cost?
There is no fixed GDPR compliance price.
Costs depend on:
- Business size
- Amount of personal data
- Number of employees
- Number of vendors
- Security requirements
- Geographic operations
- Industry
- Data sensitivity
- Existing technology
- Need for legal advice
- Need for consulting
A small business with straightforward processing may need relatively simple procedures.
A SaaS company processing sensitive information across multiple countries may require substantially more work.
Possible expenses include:
- Legal advice
- Privacy consulting
- Compliance software
- Security software
- Employee training
- Data-mapping work
- Contract reviews
- Security assessments
GDPR Compliance for E-Commerce Businesses
Online stores commonly process:
- Customer names
- Delivery addresses
- Email addresses
- Phone numbers
- Order history
- Payment-related information
- Marketing preferences
An e-commerce business should therefore review:
- Privacy notices
- Checkout forms
- Marketing consent
- Cookies
- Analytics
- Payment providers
- Shipping providers
- Customer accounts
- Data retention
GDPR Compliance for SaaS Startups
A SaaS startup should consider GDPR early because its application may process personal data belonging to customers or end users.
A practical starting framework is:
Data inventory → Roles → Lawful basis → Privacy notice → Security → DPA → Vendor review → Rights requests → Breach response
For SaaS companies, understanding whether they act as controller, processor, or both for different processing activities is particularly important.
GDPR vs SOC 2
GDPR and SOC 2 are not the same thing.
| GDPR | SOC 2 |
|---|---|
| Data protection law | Assurance/reporting framework |
| Focuses on personal-data protection | Focuses on controls under selected Trust Services Criteria |
| Applies based on legal scope | Typically used by service organizations |
| Creates legal obligations | Provides independent assurance about controls |
| Includes individual rights | Includes security and other selected criteria |
A SaaS business may need to address both GDPR and SOC 2 depending on its customers, services, and operations.
GDPR vs CCPA
GDPR and California’s privacy laws are also different legal frameworks.
They have similarities around:
- Transparency
- Individual rights
- Personal information
- Business responsibilities
But their scope, terminology, rights, exemptions, and obligations differ.
A business operating internationally should avoid assuming that complying with one privacy regime automatically means it complies with another.
Simple GDPR Compliance Workflow
A small business can start with this process:
1. Find the data
↓
2. Understand why you collect it
↓
3. Identify the appropriate lawful basis
↓
4. Explain your processing through privacy information
↓
5. Minimise the data you collect
↓
6. Secure the information
↓
7. Review third-party vendors
↓
8. Establish retention periods
↓
9. Prepare for individual rights requests
↓
10. Create a data-breach response process
↓
11. Review and improve regularly
Frequently Asked Questions
Is GDPR mandatory for small businesses?
It can be. GDPR applicability depends on the organization’s activities and processing rather than simply its size.
Does GDPR apply to US businesses?
It can apply to US businesses when they fall within the GDPR’s territorial scope, such as certain situations involving offering goods or services to individuals in the EU or monitoring their behaviour.
Does GDPR apply to businesses in Canada?
Potentially. Canadian businesses should assess whether their activities fall within GDPR’s territorial scope, particularly when offering goods or services to people in the EU or monitoring their behaviour there.
Does GDPR apply to Indian businesses?
Potentially. An Indian business that falls within the GDPR’s territorial scope may have GDPR obligations even if it has no physical office in the EU.
Do I need consent to collect customer data?
Not necessarily. GDPR provides multiple lawful bases, and the correct basis depends on the purpose and circumstances of the processing.
What is the GDPR 72-hour rule?
Where a personal data breach is reportable to the supervisory authority, the general GDPR rule is to notify the authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach.
Do small businesses need a DPO?
Not automatically. A DPO is mandatory only in specified circumstances, including certain large-scale monitoring or sensitive-data processing activities.
What is the GDPR right to erasure?
It allows individuals to request deletion of personal data in certain circumstances. However, the right is not absolute and exceptions can apply.
Is a privacy policy enough for GDPR compliance?
No. A privacy notice is only one component. GDPR compliance can involve lawful bases, security, data rights, retention, vendor management, documentation, breach response, and accountability.
Final Thoughts
GDPR compliance can seem complicated when you first encounter it, but the basic idea is straightforward:
Know what personal data you have, understand why you use it, use it lawfully, protect it, don’t keep it unnecessarily, and respect people’s rights.
For a small business, a practical starting point is:
Data inventory + lawful basis + privacy notice + security + vendor review + retention + rights process + breach response.
You don’t necessarily need a large compliance department.
But you do need to understand what your business does with personal data and put appropriate processes and safeguards in place.
Because GDPR obligations depend heavily on the specific facts of an organization’s activities, this guide should be treated as general educational information rather than legal advice. Businesses with complex, international, or high-risk processing should obtain advice appropriate to their circumstances.