Many small business owners assume that data protection rules only concern large companies, but the GDPR applies to organisations of every size. Even if you only process customer names, emails or payment details, you are handling personal data and must follow the law.
Regulators across the UK and EU continue to take enforcement action against businesses that fall short of their obligations. A single data breach or failure to respond to a customer’s request can lead to complaints, investigations and potential fines. Good compliance is not just about avoiding penalties; it also helps build trust with customers who want to know their information is handled responsibly.
Do the UK GDPR, EU GDPR or both apply to you?
If your business is based in the UK, you must comply with the UK GDPR alongside the Data Protection Act 2018. This applies to most organisations that collect or use personal data about individuals in the UK.
If you offer goods or services to people in the European Union, or if you monitor the behaviour of individuals there, the EU GDPR may also apply to you. This can be the case even if you have no offices or staff in the EU. Many UK SMEs find that they fall under both regimes, so it is important to review where your customers are located and how you target them.
Data mapping: understanding what you process and why
A key first step in compliance is to know exactly what personal data you hold. This means creating a clear record of the types of data you collect, where it comes from, the reasons you use it, and who you share it with. You should also record how long you keep the information and what security measures protect it.
Small businesses sometimes assume they are exempt from keeping formal records. In practice, the exemptions are very narrow, and regulators expect even smaller organisations to understand their processing activities. Treat your data map as the foundation of your compliance programme, as it will guide your privacy notices, contracts, and security decisions.
Lawful bases: choosing the right one for each activity
Every time you process personal data, you need a lawful basis under the GDPR. There are six to choose from, and you must identify one for each purpose:
- Consent – when individuals have given you clear permission to use their data.
- Contract – where processing is necessary to deliver a contract with the individual.
- Legal obligation – when the law requires you to process certain data, for example, tax records.
- Vital interests – to protect someone’s life in an emergency.
- Public task – applies mainly to public authorities.
- Legitimate interests – where your business has a genuine need, balanced against the rights of the individual.
Document your choice for each activity and avoid swapping between bases later. If you rely on legitimate interests, carry out and keep a balancing assessment that shows why it is appropriate.
Transparency: clear and accessible privacy notices
Individuals have the right to understand how their personal data is used. A privacy notice is the main way to provide this information, and it should be written in plain, straightforward language. Avoid legal jargon and make sure the notice is easy to find on your website or in any customer-facing materials.
Your notice should cover the following points:
- What personal data you collect
- Why you collect it and how it will be used
- The lawful basis for each purpose
- How long you keep the information
- Who you share data with, including suppliers
- Whether data is transferred outside the UK or EU and on what basis
- The rights individuals have under the GDPR
- Contact details for your business and, if applicable, your Data Protection Officer or Article 27 representative
Updating your notice should be part of your regular compliance routine. If your data processing changes, your privacy notice must change too.
People’s rights: respond within one month
Under the GDPR, individuals can request access to their data and ask for it to be corrected, deleted, restricted, moved to another provider, or for certain uses to stop. You must have a clear process for handling these requests and respond within one month. Only extend the deadline to three months if the request is complex and let the person know why.
Security: protecting the data you hold
Small businesses do not need enterprise-level systems, but regulators expect sensible, proportionate safeguards. Focus on measures that reduce the most common risks:
- Limit access to personal data to those who need it
- Use strong passwords and multi-factor authentication
- Keep software and devices up to date with security patches
- Encrypt sensitive data in storage and when sending externally
- Back up data securely and test recovery regularly
- Train staff on spotting phishing and handling data safely
- Check the security practices of your suppliers before sharing data
Good security is not just about technology. Clear policies and regular training are just as important as the tools you use.
Breach response: act fast and document everything
If personal data is lost, stolen or accessed without permission, assess the risk straight away. Serious breaches must be reported to the regulator within 72 hours, and affected individuals must also be told if the risk to them is high. Even if you decide not to report, keep a clear record of what happened, your assessment, and any actions taken.
The Article 27 requirement
If your business is based outside the EU but you offer goods or services to people there, or monitor the behaviour of individuals in the EU, you may need to appoint an EU representative under Article 27 of the GDPR. The same applies in reverse for the UK: if your business is outside the UK but you target individuals in the UK, you may need a UK representative under the UK GDPR.
The representative must be based in the EU or UK (depending on the law that applies) in a country where some of your customers are located. They act as your point of contact for regulators and individuals, and they must be named with contact details in your privacy notice.
There are limited exemptions. You may not need a representative if your processing is only occasional, does not involve large-scale use of special category or criminal offence data, and is unlikely to pose risks to people’s rights. However, regulators interpret this exemption narrowly, so most businesses targeting these regions should assume that a representative is required.
Failure to appoint one when required can lead to enforcement action. For example, the Dutch Data Protection Authority fined Locatefamily.com €525,000 for failing to designate an EU representative.
Do you need a Data Protection Officer (DPO)?
Most small businesses do not need to appoint a formal DPO. The role is only mandatory if you are a public authority, carry out large-scale monitoring of individuals, or process special category data on a large scale. If these conditions do not apply, it is still good practice to nominate someone responsible for data protection within your business to ensure accountability.
International data transfers
If you transfer personal data outside the UK or EU, you must ensure it remains protected to GDPR standards. This can be achieved through recognised mechanisms such as Standard Contractual Clauses (SCCs), the UK’s International Data Transfer Agreement (IDTA), or approved adequacy decisions like the EU–US Data Privacy Framework and the UK–US “Data Bridge”. Always assess the risks of the transfer and document the safeguards you rely on.
Accountability: evidence you can show
GDPR requires you not only to comply with the law but also to prove it. Regulators expect to see records that demonstrate how you meet your obligations. Small businesses should keep:
- A record of processing activities (data map)
- Privacy notices and any updates
- Lawful basis assessments (and legitimate interest balancing tests if used)
- Data Protection Impact Assessments (where required)
- Contracts with processors and supplier due diligence checks
- Staff training records and policies
- Logs of data breaches and incidents, with outcomes
- Evidence of representative appointment (if Article 27 applies)
Maintaining this documentation shows that you take data protection seriously and can respond quickly if the regulator ever asks for proof.
Next steps for small business owners
Staying on top of GDPR obligations may feel daunting for small businesses, but it is manageable with a clear, step-by-step approach. By mapping your data, choosing the right lawful bases, maintaining transparent privacy notices, and embedding good security practices, you can reduce risk while strengthening customer trust. Remember that compliance is not just about avoiding fines; it is about demonstrating professionalism and reassuring your clients that their personal information is treated with care.
If your business targets individuals in the EU, appointing an Article 27 representative is a critical legal requirement that should not be overlooked. At EU Business Partners, we specialise in helping non-EU organisations meet this obligation, providing a reliable point of contact for regulators and data subjects. Contact us today to ensure your business has the right representation in place and stays fully compliant with GDPR requirements.





0 Comments