GDPR for Small Businesses: Compliance Guide for SMEs (2026)

The GDPR applies to every small business that processes personal data of individuals in the EU, with no blanket exemption based on size. Article 30(5) provides a narrow records derogation for organisations under 250 employees, but only if processing is occasional, low-risk, and excludes special-category data. Most small businesses cannot meet all three conditions.
The GDPR applies to every organisation that processes personal data of people in the European Union: a sole trader in Vienna, a ten-employee e-commerce shop in Warsaw, and a US-based SaaS startup with European customers are all subject to it. Size does not determine applicability.
That said, the GDPR is not a one-size-fits-all regulation. Several provisions are calibrated to the nature and scale of processing rather than to headcount alone, and the EU has recently proposed further reductions in administrative burden for smaller organisations. Understanding which obligations are full, which are reduced, and which are currently being reformed is the practical starting point for any small business.
This guide covers what applies to your SME, the Article 30(5) records derogation and its real limits, the DPO question, the pending reform of that derogation under the Commission's May 2025 simplification proposal, sector-specific examples, practical low-cost steps, and recent enforcement that small businesses should know about. For the foundational overview of the regulation, see What Is GDPR.
This article is for informational purposes only and does not constitute legal advice. Consult a qualified data protection attorney or privacy professional for guidance specific to your situation.
Does the GDPR Apply to Your Small Business?
The short answer is almost certainly yes, if you handle any personal data connected to EU individuals.
The European Commission is direct on this point: GDPR applicability turns on the nature of your activities, not your company's size or location. Under Article 3 of the regulation, the GDPR applies if any of the following is true:
- You are established in the EU and process personal data in the course of your activities, regardless of where the processing takes place.
- You are established outside the EU but offer goods or services to individuals in the EU, including a free app, a website that accepts EU orders, or a newsletter directed at EU readers.
- You are established outside the EU but monitor the behaviour of EU individuals, for example through website analytics, advertising pixels, or location tracking.
What Counts as Personal Data for a Small Business?
Most small businesses handle more personal data than they realise. Common processing activities that bring GDPR obligations include:
- Customer names, email addresses, postal addresses, and purchase history
- Employee and contractor records: payroll data, HR files, performance notes, and CVs from applicants
- Website cookies, analytics, and behavioural advertising pixels
- Email marketing subscriber lists
- CCTV and security camera footage covering individuals in or near your premises
- Online booking and reservation systems
- Payment records (even if payment processing is handled by a third party)
- Social media advertising targeted at EU users
Processing any of these in connection with EU individuals brings your business under the GDPR in full.

The Article 30(5) Records Derogation: What It Actually Covers
Article 30 of the GDPR requires controllers and processors to maintain records of processing activities. Article 30(5) provides a partial derogation for smaller organisations:
"The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10."
In plain terms: an organisation with fewer than 250 employees is exempt from mandatory record-keeping only if all three of the following are true simultaneously:
- The processing is unlikely to result in a risk to individuals' rights and freedoms.
- The processing is occasional: not routine or systematic.
- The processing does not include special-category data (health, biometric, genetic, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sexual orientation) or data about criminal convictions.
The Article 29 Working Party position paper of 19 April 2018, endorsed by the EDPB at its first plenary, confirms this is a narrow exemption. It says the three exceptions are alternative, that the occurrence of any one of them on its own triggers the obligation, and that a small organisation's regular processing of employee data cannot be treated as "occasional".
Applying that test to ordinary trading, processing customer records, managing a payroll, running an email marketing list, or operating a website with analytics are recurring and systematic rather than occasional, so the derogation does not cover them.
The same paper sets a limit in the other direction. Where an exception applies, the organisation "need only maintain records of processing activities for the types of processing mentioned by Article 30(5)". Genuinely occasional processing that is unlikely to create a risk and involves no special-category or criminal-offence data does not have to go in the record.
The Practical Reality
The exemption was intended for genuinely one-off processing, such as a small organisation that occasionally processes a one-time event attendee list and does nothing else with personal data regularly. In practice, almost no operating business qualifies fully.
The recommendation is the same regardless of the technical derogation: keep records of processing activities. They are your evidence of accountability, your reference when supervisory authorities inquire, and your tool for managing data subject requests. A simple spreadsheet covering what data you process, why, where it is stored, who has access, and how long you keep it is sufficient for most small businesses.
When a Small Business Needs a Data Protection Officer
The DPO requirement under Article 37 is not linked to employee count. It is triggered by the nature and scale of your core processing activities. A DPO is mandatory in three situations:
- The organisation is a public authority or public body (not applicable to most small businesses).
- The core activities of the organisation require regular and systematic monitoring of individuals on a large scale, for example, a business whose primary product is behavioural advertising technology or large-scale user surveillance.
- The core activities involve large-scale processing of special-category data (health, biometrics, sexual orientation, etc.) or personal data relating to criminal convictions.
The EDPB's SME guide on DPOs is explicit: a small organisation is unlikely to need a data protection officer. A local retail shop, a small marketing agency, a ten-person software company, or a two-partner law firm does not meet these criteria.
Sector Nuances
Some SMEs operate in sectors where the DPO question is less clear:
- Small clinic or medical practice: Processing patient health data is special-category processing under Article 9. Whether it is "large scale" depends on volume and context. A two-doctor practice treating a local patient population is generally not large scale. A regional chain of clinics with tens of thousands of patient records is a closer question. Many EU member states have issued sector-specific guidance for healthcare providers.
- HR software startup: If your product systematically processes employee data for large client organisations, your own core activities may involve large-scale processing of special-category data. Seek specific advice.
- Marketing agency: Profiling and behavioural targeting at scale for clients may bring you closer to the systematic monitoring threshold than a typical SME.
Voluntary Appointment
You can appoint a DPO voluntarily even when not required. If you do, the full GDPR rules on DPO independence, resources, tasks, and protection from dismissal apply automatically. Many small businesses find it more practical to designate a privacy lead internally (a named person responsible for data protection who handles queries and requests) without using the formal DPO title.

The Pending Reform of Article 30(5): Omnibus IV
The reform of the records derogation is not part of the Digital Omnibus. It sits in a separate file: the Commission proposal of 21 May 2025, COM(2025) 501 final, procedure 2025/0130(COD), part of the simplification package known as Omnibus IV. That proposal extends measures already available to small and medium-sized enterprises to "small mid-cap enterprises" (SMCs) across six regulations, and Article 1(2) of it replaces GDPR Article 30(5).
The Digital Omnibus of 19 November 2025 (COM(2025) 837 final, procedure 2025/0360(COD)) is a different package. It does amend the GDPR, but it does not touch Article 30(5). Its GDPR changes run to the definitions in Article 4, the purpose-limitation rule in Article 5(1)(b), special-category data under Article 9, Articles 12(5), 13(4) and 22, breach reporting under Article 33, impact assessments under Article 35, Articles 57(1), 64(1) and 70(1), and two new Articles 88a and 88b that move the cookie consent rules out of the ePrivacy Directive into the GDPR. If you are tracking the record-keeping change, track 2025/0130(COD).
What the Commission Proposed for GDPR Article 30(5)
The Commission's proposal would make two significant changes to the records derogation:
- Raise the employee threshold from fewer than 250 to fewer than 750 employees, extending relief to a category the Commission calls "small mid-cap enterprises" (SMCs).
- Restructure the conditions: Instead of the three current disqualifying factors (risk, not occasional, special-category data), the derogation would apply unless the processing is "likely to result in a high risk" within the meaning of Article 35 (the DPIA threshold). The proposal removes references to "occasional processing" and to special-category data as standalone disqualifying factors.
The Council's Negotiating Mandate (September 2025)
On 24 September 2025, member states' representatives approved the Council's negotiating mandate on the proposal, raising the Commission's thresholds: small mid-caps became enterprises with fewer than 1000 employees and either an annual turnover of up to EUR 200 million or a balance sheet total of up to EUR 172 million. Parliament took the same line on the headcount, and asked that an organisation caught by the high-risk test should have to record only the specific processing activities likely to result in high risk, rather than a complete record of all its processing.
EDPB and EDPS Response
The EDPB and the EDPS welcomed the simplification in a joint opinion issued on 9 July 2025 on this proposal, supporting the general objective of reducing administrative burden for SMEs and small mid-caps. They called the changes targeted and limited in nature, and said they do not affect the core principles or the other obligations of the GDPR. They also asked the co-legislators to explain why fewer than 750 employees was the right threshold rather than the 500 originally considered, to tie the exemption to the newly introduced SME and SMC definitions, and to make clear that public authorities and bodies are outside the derogation. The text later agreed by the co-legislators adopts that last point in its recital.
Current Status: Agreed by the Co-Legislators, Not Yet Law
As of 10 September 2026, the Article 30(5) reform has cleared trilogue but has not been adopted. Parliament and the Council reached a provisional agreement on Omnibus IV on 9 June 2026, Coreper endorsed the agreed text (PE790.249) on 26 June 2026, the responsible joint committee approved it on 2 July 2026, and the Legislative Observatory records an indicative first-reading plenary sitting of 23 November 2026.
The agreed text goes further than the Commission proposed. It replaces Article 30(5) so that the record-keeping obligations "shall not apply to an enterprise or an organisation employing fewer than 1000 persons unless and to the extent that a specific processing activity they carry out is likely to result in a high risk to the rights and freedoms of data subjects, within the meaning of Article 35". Three qualifiers travel with that. Records stay mandatory where the processing activity is a core activity requiring a data protection officer under Article 37(1), point (b) or (c). Where records are required, the obligation attaches only to that specific processing activity, not to the organisation as a whole. And the agreed recital states that public authorities and bodies should not benefit from the derogation.
The Digital Omnibus (2025/0360(COD)) is on a much earlier track. The committee referral was announced in Parliament on 19 January 2026 and the Legislative Observatory still gives the stage reached as awaiting committee decision, so Parliament has no first-reading position and no trilogues have opened on it.
Until the amending Regulation is adopted and in force, the current Article 30(5) text (the 250-employee threshold with three disqualifying conditions) remains the applicable law. If the agreed text is adopted, the practical effect for organisations under the threshold is that routine low-risk processing (customer email lists, staff records, online bookings) would no longer need to be formally documented, while every other obligation, including legal basis, privacy notices, data subject rights, security, breach notification, vendor contracts and the Article 27 representative, continues to apply in full.
Do not adjust your compliance approach based on the agreed text. Continue operating under the current rules until the amending Regulation is formally adopted and in force.
Core Obligations That Apply to All Small Businesses in Full
While certain administrative obligations are calibrated to scale, the following GDPR requirements apply without reduction to every organisation of any size.
1. Lawful Basis for Every Processing Activity
Every processing activity requires a documented legal basis under Article 6. The three bases most relevant to small businesses are:
- Contractual necessity (Article 6(1)(b)): Processing needed to perform a contract with the individual, for example, processing a delivery address to ship an order, or processing salary data to pay an employee.
- Legitimate interests (Article 6(1)(f)): A genuine, proportionate business interest that does not override the individual's rights, for example, basic direct marketing to existing customers, fraud prevention, or network security. Requires a documented legitimate interests assessment.
- Consent (Article 6(1)(a)): The individual freely opts in for a specific, clearly stated purpose. Consent is revocable and creates ongoing management obligations. It is often over-used by small businesses where another basis would be simpler and more durable.
For a full treatment of when consent is and is not the appropriate basis, see GDPR Consent Requirements.
2. Privacy Notices
Every individual whose data you collect must be informed at the point of collection about: who you are, what data you collect, why, the legal basis, how long you retain it, who you share it with, and their rights. This applies to your website, your in-store forms, your employment paperwork, and any other data collection point.
A privacy notice does not need to be long. It needs to be clear, accessible, and complete. The EDPB's practical resources section provides free templates.
3. Data Subject Rights
The GDPR's eight individual rights apply to all organisations. Small businesses must:
- Have a clear, accessible way for individuals to submit requests (email is sufficient).
- Identify and respond to requests within one calendar month (extendable by two months for complex requests, with notice to the requester).
- Provide the first copy of personal data free of charge in response to an access request.
- Process deletion, correction, objection, and portability requests appropriately and document responses.
Romania's supervisory authority fined a clinic, Velvet Medical SRL, 4,976.4 lei (about EUR 1,000) following a February 2025 investigation, after it failed to answer a patient's request for the documents in his medical file and then failed to answer his second request. The breach was of Article 12(1) to (4) read with Article 15(3). This is the type of enforcement that catches small businesses: a small failure, handled badly, ending in a published decision naming the controller.
4. Technical and Organisational Security Measures
Article 32 requires appropriate security measures proportionate to the risk and the nature of the data. Proportionality means what is appropriate for a two-person accountancy firm differs from what is appropriate for a 200-employee healthcare provider, but both must have something in place.
Practical baseline measures for small businesses:
- Enable multi-factor authentication on all business accounts (email, cloud storage, accounting software).
- Use a password manager and enforce strong unique passwords.
- Encrypt laptops, external drives, and mobile devices that contain personal data.
- Limit access to personal data to staff members who genuinely need it for their role.
- Apply software and operating system updates promptly.
- Maintain regular tested backups stored separately from the primary data.
- Have a written policy on how to handle personal data and ensure staff understand it.
- Lock physical files containing personal information.
5. Data Breach Notification
If a personal data breach occurs and it is likely to result in a risk to individuals, you must notify your supervisory authority within 72 hours of becoming aware. If the breach is likely to result in a high risk to individuals, you must also notify the affected individuals directly. See GDPR Data Breach Notification: 72-Hour Rule for the full procedure.
A common small business mistake is assuming only large-scale hacks qualify as breaches. A stolen laptop with unencrypted customer data, an email sent to the wrong recipient containing sensitive information, or a ransomware attack on a shared drive all constitute data breaches that may require notification.
6. Data Processing Agreements with Vendors
Under Article 28, whenever you share personal data with a third party that processes it on your behalf (cloud hosting providers, email marketing platforms, payroll services, accounting software, payment processors, website analytics tools), you need a data processing agreement in place. Most major providers now include GDPR-compliant DPAs in their standard terms of service or offer them on request. Review them and confirm they are in place.
7. An EU Representative If You Are Based Outside the EU
If the GDPR reaches you only through Article 3(2), because you offer goods or services to people in the EU or monitor their behaviour, Article 27 requires you to designate a representative in the Union in writing. The representative must be established in a member state where the affected individuals are, and can be addressed by supervisory authorities and individuals instead of, or in addition to, you.
The exemption in Article 27(2) fails for the same reason the records derogation usually fails. It covers only processing that is occasional, does not include large-scale processing of special-category or criminal-offence data, and is unlikely to result in a risk to individuals. Public authorities and bodies are also outside the obligation. A US or Canadian business running routine EU e-commerce or a subscription service does not qualify.
This is a standalone, documentable obligation, and it is enforceable under Article 83(4) up to EUR 10 million or 2% of worldwide annual turnover.

GDPR in Practice: Three Sector Examples
A Small E-Commerce Shop (10 Employees)
A 10-person online retailer selling clothing to EU customers processes customer names, addresses, email addresses, and purchase history daily. Their processing is not occasional; it is central to every transaction.
Key obligations: legal basis for order processing (contractual necessity), separate basis for marketing emails (consent or legitimate interests), cookie consent banner for analytics and advertising pixels, privacy notice on the website, data processing agreements with the payment processor and email platform, and a clear process for handling access and deletion requests.
The Article 30(5) derogation does not apply because the processing is not occasional. The retailer should maintain a records spreadsheet. No DPO is required. A designated staff member handles rights requests.
A Local Clinic or GP Practice (5 Staff)
A small medical practice processes patient health data daily. Health data is special-category data under Article 9, requiring a legal basis under both Article 6 and Article 9(2). The appropriate Article 9 basis for a healthcare provider treating patients is typically Article 9(2)(h): medical diagnosis and treatment.
The Article 30(5) derogation does not apply because the processing involves special-category data (health records). The legal minimum, under the Article 29 Working Party position paper, is a record of the processing that triggers the exception, so the practice must document its patient-health processing rather than every occasional low-risk activity. Documenting everything remains the practical recommendation. Whether a DPO is required depends on whether the processing is "large scale" in context; most EU data protection authorities view a small local practice as not meeting the large-scale threshold, though member-state guidance varies.
Key additional obligations: strict access controls on patient records, security measures appropriate to sensitive health data, data sharing agreements with any third-party systems used (lab results, appointment platforms), and careful handling of any patient communications by email.
A Small Digital Marketing Agency (15 Employees)
A marketing agency that runs campaigns and processes EU consumer data on behalf of clients sits in a more complex position. The agency acts as both controller (for its own staff data and business contacts) and processor (when handling client data on the client's behalf).
As a processor, the agency must: sign data processing agreements with every client that specifies the nature, purpose, and duration of processing; implement appropriate security measures as instructed by the controller; notify clients promptly of any breach; and not engage sub-processors without the client's authorisation.
For behavioural advertising campaigns using tracking pixels and cookies, GDPR consent requirements for cookies apply. The agency should also be aware that using Google Ads requires Consent Mode v2 implementation as of March 2024 to communicate user consent choices correctly.
Common SME Compliance Mistakes
Assuming Size Creates an Exemption
"We are a small company" is not a legal defence under the GDPR. Supervisory authorities have fined sole traders and micro-businesses for basic violations. Fines apply proportionately, but they apply.
Over-Using Consent as a Legal Basis
Many small businesses add a consent checkbox to every form because it seems safe. In practice, consent is often the wrong basis: it creates revocation rights that are complex to manage, and it should only be used where the individual has a genuine free choice. Where you can rely on contractual necessity or legitimate interests, those bases are often more practical and durable.
Invalid Cookie Consent
Stating "by using this site you accept cookies" in a footer notice is not valid GDPR consent. Consent for non-essential cookies requires a clear opt-in mechanism that allows users to accept or reject cookies before they are set. Pre-ticked boxes and implied consent are non-compliant.
No Data Retention Policy
The storage limitation principle under Article 5(1)(e) requires that personal data not be kept longer than necessary. Keeping customer records indefinitely, or never deleting former employee files, is a breach of this principle. Define retention periods for each category of data and implement a process to delete data when those periods expire.
Forgetting Employee Data
GDPR applies equally to staff data as to customer data. Employee records, salary information, disciplinary files, and CVs submitted by job applicants all require the same protections. Many small businesses focus compliance efforts on customer data and neglect their HR obligations entirely.
No Breach Response Plan
Without a plan, a breach is likely to exceed the 72-hour notification deadline while staff work out what to do. A basic written procedure covering how to detect a breach, how to assess its severity, who is responsible for notification, and how to contain and document it costs nothing to create and can prevent a fine.
Missing Vendor DPAs
Using cloud storage, email marketing tools, or payroll software without reviewing whether a data processing agreement is in place is a common gap. It is also a straightforward enforcement target for supervisory authorities because it is easy to demonstrate as a missing document.
Low-Cost Compliance Steps for Small Businesses
Compliance does not require large budgets or specialist software. The following six steps address the highest-priority GDPR requirements at minimal cost.
Step 1: Data inventory (free): List every type of personal data you process: what it is, whose it is, why you hold it, where it is stored, who can access it, and how long you keep it. A spreadsheet is sufficient. Update it whenever you introduce a new tool or process.
Step 2: Privacy notice (free): Write a plain-language privacy notice covering all required Article 13 and 14 information. Publish it on your website and make it available at every data collection point. Use the EDPB's free templates as a starting point.
Step 3: Cookie consent (free to low cost): If your website uses non-essential cookies (analytics, advertising, social media buttons), implement a compliant opt-in banner. Several free and low-cost tools provide GDPR-compliant consent management.
Step 4: Vendor DPA review (free): Go through your list of service providers and confirm that a data processing agreement is in place with each one that handles personal data on your behalf. Most major providers offer DPAs in their terms or on request.
Step 5: Basic security (free to low cost): Enable multi-factor authentication on all business accounts. Deploy a password manager. Encrypt your devices. Keep software updated. These measures are mostly free and address the most common breach vectors for small businesses.
Step 6: Rights request and breach response procedures (free): Designate a named contact for data subject requests. Create a simple log to track requests, their type, date received, and date resolved. Write a one-page breach response checklist covering the 72-hour notification requirement.
GDPR Obligation Summary for SMEs
| Obligation | Applies to SMEs? | Notes |
|---|---|---|
| Legal basis for processing | Yes | Document for each activity |
| Privacy notice | Yes | Clear and accessible |
| Data subject rights (8 rights) | Yes | One-month response deadline |
| Records of processing (Article 30) | Usually yes | Derogation is narrow; at minimum record the processing that defeats it |
| Security measures (Article 32) | Yes | Proportionate to risk |
| Breach notification (72 hours) | Yes | If breach poses risk to individuals |
| DPO appointment | Rarely | Most SMEs do not need one |
| DPIA | Sometimes | Only for high-risk processing |
| Data processing agreements | Yes | With every processor handling your data |
| EU representative (Article 27) | If Article 3(2) applies | Non-EU controllers and processors; narrow exemption for occasional low-risk processing |
| International transfer mechanisms | Yes | If sending data outside the EU/EEA |
| Cookie consent | Yes | For non-essential cookies |
Free Official Resources for Small Businesses
EDPB Data Protection Guide for Small Business: The EDPB's SME guide is the most comprehensive free official resource. It covers all major GDPR topics with videos, interactive flowcharts, infographics, and practical examples. The practical resources section includes downloadable templates for records of processing, privacy notices, consent forms, and data processing agreements. Available in 23 EU official languages plus Icelandic and Norwegian. Irish is the one EU language where the guide still serves the English text.
ICO Advice for Small Organisations: The UK's Information Commissioner's Office provides guidance specifically for small and medium organisations and a self-assessment checklist for small business owners and sole traders that produces a short report of practical actions. A separate, longer toolkit is aimed at medium-sized organisations. Note that ICO material states the UK GDPR position rather than the EU GDPR, and the ICO has flagged this guidance as under review following the Data (Use and Access) Act.
Your Europe Business Portal: The Your Europe portal provides GDPR guidance in all EU official languages for businesses operating across the single market.
National Supervisory Authorities: Each EU member state's DPA publishes its own SME resources. The Irish DPC, the French CNIL, the Dutch AP, and the German state DPAs all offer free toolkits and helplines for small businesses in their jurisdictions.
Related GDPR Guides
- What Is GDPR for a comprehensive overview of the regulation
- GDPR Compliance Checklist for a step-by-step compliance guide
- GDPR Consent Requirements for valid consent standards and when consent is and is not the right basis
- GDPR Data Subject Rights for all eight individual rights
- GDPR Fines and Penalties for enforcement data and penalty calculation
- GDPR Breach Notification 72-Hour Rule for breach reporting procedure
- EU Cookie Law (ePrivacy Directive) for cookie consent requirements
- EU Data Privacy Laws for the complete EU data protection hub
Frequently Asked Questions
Does the GDPR apply to small businesses?
Yes. The GDPR applies to any organisation that processes personal data of individuals in the EU, regardless of size. A sole trader, a startup, and a 200-employee company are all subject to it if they handle EU personal data. There is no blanket small-business exemption. Compliance obligations are calibrated to the nature and risk of your processing activities, not your headcount.
Do small businesses need a Data Protection Officer?
Most do not. A DPO is mandatory under Article 37 only for public authorities, organisations whose core activities require regular and systematic monitoring of individuals on a large scale, and organisations whose core activities involve large-scale processing of special-category data (health, biometric, genetic, etc.). A typical small retail, service, or technology business does not meet these criteria. Voluntary appointment is possible, but the full GDPR rules on DPO independence and protection then apply.
Are small businesses exempt from GDPR record-keeping?
The Article 30(5) derogation for organisations with fewer than 250 employees is narrower than many assume. The exemption only applies if all three conditions are met simultaneously: the processing is occasional, it poses no risk to individuals, and it involves no special-category data. Most small businesses process customer or employee data regularly, which means they fail the occasional test and must still maintain records. The recommendation is to keep records regardless as a matter of good practice.
What is the GDPR Digital Omnibus and does it help small businesses?
The Digital Omnibus is a package of GDPR amendments the European Commission published on 19 November 2025 (COM(2025) 837 final, procedure 2025/0360(COD)). It changes the definitions, purpose limitation, breach reporting and impact assessments, and moves the cookie rules into the GDPR, but it does not change the records derogation, and it is still at committee stage in Parliament. The record-keeping simplification sits in a different file: the Commission proposal of 21 May 2025 (COM(2025) 501 final, procedure 2025/0130(COD)), part of Omnibus IV. Parliament and the Council reached a provisional agreement on it on 9 June 2026: the threshold becomes fewer than 1000 persons, records are required only for the specific processing activity likely to result in a high risk, they stay mandatory where that activity is a core activity requiring a data protection officer under Article 37(1)(b) or (c), and public authorities are excluded. A first-reading plenary vote is indicatively set for 23 November 2026, so the current 250-employee threshold and three-condition test remain the law.
Can a small business be fined under the GDPR?
Yes. GDPR fines apply to organisations of all sizes based on the severity of the violation. Supervisory authorities must ensure fines are effective, proportionate, and dissuasive, meaning a small business would typically receive a lower absolute fine than a multinational, but penalties can still be significant. Fines reach up to EUR 20 million or 4% of global annual turnover for serious violations. Romania's supervisory authority, for example, fined the clinic Velvet Medical SRL 4,976.4 lei (about EUR 1,000) after a February 2025 investigation into its failure to answer a patient's two requests for a copy of his medical file.
What are the most important GDPR steps for a small business?
Start with six priorities: (1) create a data inventory listing all personal data you process and why; (2) write and publish a clear privacy notice; (3) ensure you have a documented legal basis for each processing activity; (4) implement basic security measures including multi-factor authentication and device encryption; (5) have a simple process for handling data subject rights requests within one month; and (6) confirm that data processing agreements are in place with all vendors that handle personal data on your behalf.
Does GDPR apply to a business outside the EU that sells to EU customers?
Yes. Under Article 3(2), the GDPR applies to organisations outside the EU that offer goods or services to individuals in the EU or monitor their behaviour. A US-based online store with EU customers, a Canadian SaaS provider with EU users, and a UK business serving EU clients post-Brexit must all comply. Article 27 adds a separate duty for organisations caught this way: designate an EU representative in writing, unless the narrow Article 27(2) exemption for occasional low-risk processing applies. Brexit means UK businesses serving EU customers are subject to the EU GDPR for their EU operations, plus the separate UK GDPR for their UK operations.
Do I need a cookie consent banner on my website?
If your website uses non-essential cookies (including analytics cookies, advertising pixels, social media buttons, or any tracking technology), you need a compliant consent mechanism. Valid consent requires an active opt-in before non-essential cookies are set, an equally easy option to reject them, and no pre-ticked boxes. Simply noting that your site uses cookies in a footer is not sufficient. See the EU Cookie Law guide for the full requirements.
Updates
Corrected the account of the pending Article 30(5) record-keeping reform: it is Omnibus IV (COM(2025) 501 of 21 May 2025), not the Digital Omnibus; the provisionally agreed threshold of 9 June 2026 is fewer than 1000 persons, limited to the specific high-risk processing activity, with a first-reading vote indicatively set for 23 November 2026. Corrected the clinic example, added the Article 27 EU representative obligation, replaced an unsourced Romanian fine with the ANSPDCP decision against Velvet Medical SRL, repointed three dead or misdirected citations and updated the EDPB SME guide language count.
Expanded from 2,870 to ~4,800 words. Added a section on the proposed record-keeping reform (then attributed to the Digital Omnibus) and the Council position; expanded Article 30(5) analysis with statutory text; added three sector examples (e-commerce, clinic, marketing agency); added enforcement examples; expanded DPO section with sector nuances; added a proposed-vs-current law comparison table (since removed) and updated citations. Several statements in that revision were found to be inaccurate and were corrected on 10 September 2026; see the entry of that date in this log.
Initial 2026 review and publication.
Sources and References
- GDPR Full Text — Regulation (EU) 2016/679(eur-lex.europa.eu).gov
- European Commission - Application of the GDPR, including the specific rules for SMEs(commission.europa.eu).gov
- EDPB Data Protection Guide for Small Business(edpb.europa.eu).gov
- EDPB — Practical Resources for SMEs (Templates and Tools)(edpb.europa.eu).gov
- EDPB SME Guide — Data Protection Officer(edpb.europa.eu).gov
- Article 29 Working Party - Position Paper on the derogations from the obligation to maintain records of processing activities pursuant to Article 30(5) GDPR (19 April 2018, endorsed by the EDPB)(edpb.europa.eu).gov
- EDPB and EDPS - Joint Opinion on the GDPR record-keeping simplification, 9 July 2025(edpb.europa.eu).gov
- European Commission - GDPR obligations, including when a Data Protection Officer is required(commission.europa.eu).gov
- European Commission - COM(2025) 501 final, 21 May 2025, proposal amending GDPR Article 30(5) (Omnibus IV, procedure 2025/0130(COD))(eur-lex.europa.eu).gov
- Your Europe — Data Protection Under GDPR(europa.eu).gov
- ICO — Advice for Small Organisations(ico.org.uk).gov
- ICO — Who Needs to Document Processing Activities?(ico.org.uk).gov
- ICO - Data protection self assessment for small business owners and sole traders (UK GDPR; under review following the Data (Use and Access) Act)(ico.org.uk).gov
- ICO — Marketing and Data Protection in Detail(ico.org.uk).gov
- EDPB — FAQ for SMEs(edpb.europa.eu).gov
- European Parliament Legislative Train — Digital Package(europarl.europa.eu).gov
- GDPR-Info.eu — Article 30 Records of Processing Activities(gdpr-info.eu)
- European Parliament - Provisional agreement resulting from interinstitutional negotiations, PE790.249, 26 June 2026, on COM(2025)0501 (2025/0130(COD)): agreed replacement of GDPR Article 30(5)(europarl.europa.eu).gov
- European Parliament Legislative Observatory - Procedure file 2025/0130(COD): provisional agreement, Coreper letter GEDA/A/(2026)004146, committee approval 2 July 2026, indicative plenary 23 November 2026(oeil.europarl.europa.eu).gov
- European Parliament Legislative Train - Omnibus IV, simplifying measures for SMEs and small mid-cap enterprises (regulation), edition of 1 August 2026: provisional agreement of 9 June 2026(europarl.europa.eu).gov
- European Commission - COM(2025) 837 final, 19 November 2025, Digital Omnibus (procedure 2025/0360(COD)), full text: amends GDPR Articles 4, 5(1)(b), 9, 12(5), 13(4), 22, 33, 35, 57(1), 64(1), 70(1) and inserts 88a and 88b(eur-lex.europa.eu).gov
- ANSPDCP (Romania) - Sanction for the breach of the GDPR, Velvet Medical SRL, press release of 27 February 2025, fine of 4,976.4 lei (about EUR 1,000) under Article 12(1)-(4) with Article 15(3)(dataprotection.ro).gov