Scan your site free
EU Compliance

Does GDPR apply to your small business? A practical checklist

July 27, 2026  ·  6 min read  ·  By masoSec

If you've read our guide on whether NIS2 applies to your small business, you'll know that law only reaches you if you're in a specific sector, above a size threshold, or a supplier to a company that is. GDPR is different — and the difference catches a lot of small business owners off guard.

There is no employee-count threshold, no turnover threshold, and no list of covered sectors. If you collect a single email address, name, or IP address from someone in the EU, GDPR already applies to you, whether you're a one-person shop or a 500-person company.

What GDPR is, in one paragraph

The General Data Protection Regulation ((EU) 2016/679) is the EU's data protection law, in force since 25 May 2018. It governs how organisations collect, store, use, and share "personal data" — any information relating to an identified or identifiable person, which covers names, email addresses, IP addresses, cookies, and far more than most people assume. It applies to any organisation established in the EU, and — separately — to any organisation outside the EU that offers goods or services to, or monitors the behaviour of, people located in the EU. That second rule is why a small online shop or SaaS business outside the EU can still be in scope if it sells to EU customers.

"But I'm too small for this to apply to me" — the actual rule

This is the most common misconception, and it's understandable given how NIS2 and similar laws work. GDPR does include one narrow small-business carve-out: Article 30(5) exempts organisations with fewer than 250 employees from having to maintain a formal written record of processing activities — but only if your data processing is occasional, unlikely to result in a risk to people's rights, and doesn't involve special categories of data (health, biometric, religious belief, etc.) or criminal records.

In practice, most small businesses process customer or employee data regularly, not occasionally — which means even this narrow exemption often doesn't apply. And crucially, it only ever exempts you from one specific paperwork requirement. Every other GDPR obligation — lawful basis, security, breach notification, honouring data subject requests — applies regardless of your size.

There is no "GDPR-lite" tier for small businesses. A solo consultant with a mailing list has the same core obligations as a 200-person company — just a smaller volume of data to manage them for.

The core obligations checklist

1

A lawful basis for every use of personal data

Consent, contract necessity, legal obligation, or legitimate interest are the ones small businesses use most. You need to know which one applies to each way you use data — "we've always done it this way" isn't one of them.

2

A privacy notice

A page (usually /privacy) that plainly explains what data you collect, why, how long you keep it, and who you share it with. This needs to be genuinely accessible, not a copy-pasted template that doesn't match what your business actually does.

3

A process for data subject requests

People have the right to ask what data you hold on them, correct it, delete it, or receive a copy. You need a way to actually fulfil these requests — even if that's currently just "someone checks an inbox and exports a spreadsheet."

4

Data processing agreements with your vendors

Your email provider, hosting company, CRM, analytics tool, and payment processor are all "processors" acting on your behalf. GDPR (Article 28) requires a contract governing how they handle that data — most established vendors already offer a standard DPA you can accept.

5

Appropriate technical and organisational security measures

Article 32 requires security "appropriate to the risk" — encryption in transit and at rest, access controls, and the ability to detect and recover from incidents. This is the one requirement that overlaps directly with website and email security: an unencrypted contact form or a spoofable email domain is a GDPR gap, not just a security one.

6

A breach notification plan

If personal data is breached in a way likely to risk people's rights, you must notify your national supervisory authority within 72 hours of becoming aware, and notify affected individuals directly if the risk is high. You need to know this deadline exists before an incident happens, not during one.

7

Cookie and tracking consent

Technically governed by the ePrivacy rules alongside GDPR, but enforced together in practice: if your site sets non-essential cookies (analytics, ad pixels) before a visitor consents, that's a compliance gap regulators actively pursue.

Two things people get wrong

"We're not in the EU, so it doesn't apply"

If you sell to, or track the behaviour of, people located in the EU — regardless of where your business is registered — GDPR's extraterritorial scope (Article 3) can still reach you.

"We just need a cookie banner"

A cookie banner addresses one requirement. Lawful basis, security measures, vendor contracts, and breach response are separate obligations a banner doesn't touch.

What happens if you don't comply

GDPR fines are tiered by severity: the higher tier reaches up to €20 million or 4% of total worldwide annual turnover, whichever is higher, for the most serious infringements. In practice, regulators typically start with warnings and corrective orders for small businesses acting in good faith rather than jumping straight to maximum fines — but a customer complaint or a data breach can still trigger a real investigation regardless of company size.

What to actually do about it

1
Map what personal data you actually collect

Contact forms, newsletter sign-ups, customer accounts, employee records, website analytics — list where personal data enters your business and where it's stored.

2
Write (or fix) your privacy notice

Match it to what you actually do with the data you mapped in step 1. A generic template that doesn't reflect reality is worse than no notice at all.

3
Get DPAs signed with your key vendors

Check your email provider, hosting company, and any tool that touches customer data for a standard data processing agreement — most SaaS vendors have one ready to accept.

4
Lock down the technical basics

HTTPS everywhere, SPF/DKIM/DMARC on your email domain so it can't be spoofed to impersonate you in a breach, and access controls on anything storing customer data. These satisfy a meaningful share of Article 32 on their own.

Check the security basics behind your GDPR compliance

See your actual website security score in about 10 seconds — no signup needed. This covers HTTPS, security headers, and exposed files: the technical measures Article 32 expects you to have in place.