GDPR applies to a small business the moment it processes the personal data of people in the EU, regardless of headcount or turnover. Size affects how much paperwork you keep and whether you need a data protection officer, not whether the law applies. Most small firms need a lawful basis, a privacy notice and basic records.
What GDPR actually applies to a small business
The General Data Protection Regulation, Regulation (EU) 2016/679, has applied since 25 May 2018. It governs how any organisation collects, uses and stores the personal data of people in the EU. There is no small-business exemption from the regulation itself: a sole trader with a mailing list is covered the same way a multinational is. UK organisations follow the UK GDPR alongside the Data Protection Act 2018, which mirror the EU rules closely.
What does scale with size is the burden. The regulation is risk-based, so a five-person company processing a customer list carries lighter obligations than a firm running large-scale profiling. The common myth that GDPR is only for large corporations is wrong, but so is the panic that a small business must build an enterprise programme. The honest position sits in between: the principles always apply, the paperwork is proportionate.
The seven principles in Article 5 are the spine of the whole regulation: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Everything below is how those principles show up in practice for a small team.
What are the six lawful bases in practice?
Every time you process personal data you need a lawful basis under Article 6. There are six, and consent is only one of them. Picking the right basis up front matters because it determines which rights apply and how you justify the processing if a regulator asks.
- Consent: the person has clearly opted in. Useful for marketing, but it can be withdrawn, so it is rarely the right basis for core operations.
- Contract: you need the data to deliver something the person asked for, such as fulfilling an order or running an account.
- Legal obligation: a law requires you to process the data, such as keeping payroll or tax records.
- Vital interests: the processing is needed to protect someone’s life. Rare outside healthcare and emergencies.
- Public task: you are carrying out a function in the public interest or under official authority. Mostly relevant to public bodies.
- Legitimate interests: you have a genuine business reason that does not override the person’s rights. Flexible, but it requires you to document a balancing test.
In practice a small B2B company runs most of its processing on contract and legitimate interests, with consent reserved for things like marketing emails and non-essential cookies. The mistake to avoid is treating consent as the default for everything; it is the hardest basis to rely on because it must be freely given and can be withdrawn at any time.
Which documents do you genuinely need?
Most small businesses need far less documentation than the compliance industry implies, but a few records are not optional. The list below is the realistic minimum for a typical small company that does not process high-risk or special-category data at scale.
- A privacy notice: the public-facing explanation of what data you collect, why, the lawful basis, how long you keep it and who you share it with. Required under Articles 13 and 14 and the first thing anyone checks.
- A record of processing activities (RoPA): an internal inventory of what you process and why. Article 30 exempts organisations under 250 staff from the full record, but only where processing is occasional, low-risk and excludes special-category data. Most businesses fail that test in practice, so keeping a light RoPA is the safer default.
- A lawful-basis record: a note of which basis you rely on for each processing activity, including a legitimate-interests assessment where you use that basis.
- Data processing agreements: written terms with any third party that processes data on your behalf, such as your email platform or hosting provider, as required by Article 28.
- A breach procedure: a simple plan for who does what, because you may have to notify the supervisory authority within 72 hours of becoming aware of a qualifying breach under Article 33.
- A data protection impact assessment (DPIA): required only when processing is likely to result in a high risk to individuals, for example large-scale monitoring or profiling. Many small businesses never need one.
If you build a product that handles personal data, it is far cheaper to design these obligations in from the start than to retrofit them. We cover that approach in our guide to data protection by design.
When does a small business need a DPO?
A data protection officer is mandatory only in the specific cases set out in Article 37. You must appoint one if you are a public authority, if your core activities involve large-scale, regular and systematic monitoring of individuals, or if your core activities involve large-scale processing of special-category data such as health, biometric or criminal-offence data.
The great majority of small businesses meet none of those triggers and are not legally required to appoint a DPO. The key word is “core”: processing has to be central to what you do, not incidental, and “large-scale” is judged on the number of people, the volume of data and how long you process it. A small SaaS firm with a normal customer base usually falls outside the requirement.
That said, you still need someone accountable for data protection even when a formal DPO is not mandatory, and some enterprise customers will ask who holds that role before they sign. Where the obligation does bite, or where a buyer expects the function, an outsourced or virtual DPO is usually more proportionate for a small team than hiring in-house.
What are the common GDPR myths for small businesses?
- “GDPR only applies to big companies.” It applies to any organisation processing personal data of people in the EU, regardless of size.
- “We’re outside the EU, so we’re exempt.” The regulation can still apply if you offer goods or services to people in the EU or monitor their behaviour.
- “We need consent for everything.” Consent is one of six lawful bases and often the weakest fit; contract and legitimate interests cover most routine processing.
- “Every small business must appoint a DPO.” A DPO is mandatory only in the Article 37 cases; most small firms are not caught.
- “Compliance is a one-off project.” Accountability is ongoing; notices, records and bases need reviewing as the business changes.
The pattern across all of these is the same: GDPR is more demanding in scope than small businesses expect, but less demanding in paperwork than the scare stories suggest. Getting the lawful basis and the privacy notice right covers most of the real risk.
How Atoro helps
Atoro is Europe’s first ISO 42001 certified consultancy, with more than 200 certifications delivered across security and compliance. For small businesses we keep GDPR proportionate: the right lawful bases, a privacy notice that holds up, the records you actually need and nothing you don’t. We offer fixed-scope GDPR implementation and, where it helps, an outsourced DPO so a small team gets the accountability without the headcount.
GDPR for small businesses FAQs
Does GDPR apply to small businesses?
Yes. GDPR applies to any organisation that processes the personal data of people in the EU, regardless of company size. There is no exemption based on headcount or turnover; size only affects how proportionate your documentation and obligations are.
Does GDPR apply to my business if I’m based outside the EU?
It can. GDPR applies to organisations outside the EU if they offer goods or services to people in the EU or monitor their behaviour. UK organisations follow the UK GDPR and the Data Protection Act 2018, which closely mirror the EU regulation.
What are the six lawful bases under GDPR?
Article 6 sets out six lawful bases for processing personal data: consent, contract, legal obligation, vital interests, public task and legitimate interests. You must identify the right basis for each processing activity, and consent is only one option rather than the default.
Does a small business need a Data Protection Officer?
Usually not. Under Article 37 a DPO is mandatory only for public authorities, for organisations whose core activities involve large-scale systematic monitoring, or for those whose core activities involve large-scale processing of special-category data. Most small businesses meet none of these and are not required to appoint one.
Do small businesses need a record of processing activities?
Article 30 exempts organisations under 250 staff from the full record, but only where processing is occasional, low-risk and excludes special-category data. Many businesses do not strictly meet that test, so keeping a light record of processing activities is the safer and simpler default.
What documents does a small business need for GDPR?
At minimum: a privacy notice, a record of what you process and why, a note of your lawful basis for each activity, data processing agreements with your suppliers, and a simple breach procedure. A data protection impact assessment is only needed for high-risk processing.
What are the data subject rights under GDPR?
Individuals have rights including access to their data, rectification of inaccurate data, erasure, data portability and the right to object to certain processing. A small business must be able to recognise these requests and respond within the timeframes the regulation sets.
What is the maximum fine under GDPR?
The maximum fine is the higher of 20 million euros or 4% of global annual turnover for the most serious infringements, with a lower tier of 10 million euros or 2% of turnover for other breaches. Fines are proportionate and are not reserved for large companies alone.
How long does a small business have to report a data breach?
Where a breach is likely to result in a risk to people’s rights and freedoms, you must notify the relevant supervisory authority within 72 hours of becoming aware of it under Article 33, and inform affected individuals where the risk is high.