GDPR for Small Businesses: Compliance Guide for SMEs (2026)

By Recording Law Editorial TeamReviewed September 11, 202620 min read
GDPR for Small Businesses: Compliance Guide for SMEs (2026)

Frequently Asked Questions

Does the GDPR apply to small businesses?

Yes. The GDPR applies to any organisation that processes personal data of individuals in the EU, regardless of size. A sole trader, a startup, and a 200-employee company are all subject to it if they handle EU personal data. There is no blanket small-business exemption. Compliance obligations are calibrated to the nature and risk of your processing activities, not your headcount.

Do small businesses need a Data Protection Officer?

Most do not. A DPO is mandatory under Article 37 only for public authorities, organisations whose core activities require regular and systematic monitoring of individuals on a large scale, and organisations whose core activities involve large-scale processing of special-category data (health, biometric, genetic, etc.). A typical small retail, service, or technology business does not meet these criteria. Voluntary appointment is possible, but the full GDPR rules on DPO independence and protection then apply.

Are small businesses exempt from GDPR record-keeping?

The Article 30(5) derogation for organisations with fewer than 250 employees is narrower than many assume. The exemption only applies if all three conditions are met simultaneously: the processing is occasional, it poses no risk to individuals, and it involves no special-category data. Most small businesses process customer or employee data regularly, which means they fail the occasional test and must still maintain records. The recommendation is to keep records regardless as a matter of good practice.

What is the GDPR Digital Omnibus and does it help small businesses?

The Digital Omnibus is a package of GDPR amendments the European Commission published on 19 November 2025 (COM(2025) 837 final, procedure 2025/0360(COD)). It changes the definitions, purpose limitation, breach reporting and impact assessments, and moves the cookie rules into the GDPR, but it does not change the records derogation, and it is still at committee stage in Parliament. The record-keeping simplification sits in a different file: the Commission proposal of 21 May 2025 (COM(2025) 501 final, procedure 2025/0130(COD)), part of Omnibus IV. Parliament and the Council reached a provisional agreement on it on 9 June 2026: the threshold becomes fewer than 1000 persons, records are required only for the specific processing activity likely to result in a high risk, they stay mandatory where that activity is a core activity requiring a data protection officer under Article 37(1)(b) or (c), and public authorities are excluded. A first-reading plenary vote is indicatively set for 23 November 2026, so the current 250-employee threshold and three-condition test remain the law.

Can a small business be fined under the GDPR?

Yes. GDPR fines apply to organisations of all sizes based on the severity of the violation. Supervisory authorities must ensure fines are effective, proportionate, and dissuasive, meaning a small business would typically receive a lower absolute fine than a multinational, but penalties can still be significant. Fines reach up to EUR 20 million or 4% of global annual turnover for serious violations. Romania's supervisory authority, for example, fined the clinic Velvet Medical SRL 4,976.4 lei (about EUR 1,000) after a February 2025 investigation into its failure to answer a patient's two requests for a copy of his medical file.

What are the most important GDPR steps for a small business?

Start with six priorities: (1) create a data inventory listing all personal data you process and why; (2) write and publish a clear privacy notice; (3) ensure you have a documented legal basis for each processing activity; (4) implement basic security measures including multi-factor authentication and device encryption; (5) have a simple process for handling data subject rights requests within one month; and (6) confirm that data processing agreements are in place with all vendors that handle personal data on your behalf.

Does GDPR apply to a business outside the EU that sells to EU customers?

Yes. Under Article 3(2), the GDPR applies to organisations outside the EU that offer goods or services to individuals in the EU or monitor their behaviour. A US-based online store with EU customers, a Canadian SaaS provider with EU users, and a UK business serving EU clients post-Brexit must all comply. Article 27 adds a separate duty for organisations caught this way: designate an EU representative in writing, unless the narrow Article 27(2) exemption for occasional low-risk processing applies. Brexit means UK businesses serving EU customers are subject to the EU GDPR for their EU operations, plus the separate UK GDPR for their UK operations.

Do I need a cookie consent banner on my website?

If your website uses non-essential cookies (including analytics cookies, advertising pixels, social media buttons, or any tracking technology), you need a compliant consent mechanism. Valid consent requires an active opt-in before non-essential cookies are set, an equally easy option to reject them, and no pre-ticked boxes. Simply noting that your site uses cookies in a footer is not sufficient. See the EU Cookie Law guide for the full requirements.

Updates

Corrected the account of the pending Article 30(5) record-keeping reform: it is Omnibus IV (COM(2025) 501 of 21 May 2025), not the Digital Omnibus; the provisionally agreed threshold of 9 June 2026 is fewer than 1000 persons, limited to the specific high-risk processing activity, with a first-reading vote indicatively set for 23 November 2026. Corrected the clinic example, added the Article 27 EU representative obligation, replaced an unsourced Romanian fine with the ANSPDCP decision against Velvet Medical SRL, repointed three dead or misdirected citations and updated the EDPB SME guide language count.

Expanded from 2,870 to ~4,800 words. Added a section on the proposed record-keeping reform (then attributed to the Digital Omnibus) and the Council position; expanded Article 30(5) analysis with statutory text; added three sector examples (e-commerce, clinic, marketing agency); added enforcement examples; expanded DPO section with sector nuances; added a proposed-vs-current law comparison table (since removed) and updated citations. Several statements in that revision were found to be inaccurate and were corrected on 10 September 2026; see the entry of that date in this log.

Initial 2026 review and publication.

Sources and References

  1. GDPR Full Text — Regulation (EU) 2016/679(eur-lex.europa.eu).gov
  2. European Commission - Application of the GDPR, including the specific rules for SMEs(commission.europa.eu).gov
  3. EDPB Data Protection Guide for Small Business(edpb.europa.eu).gov
  4. EDPB — Practical Resources for SMEs (Templates and Tools)(edpb.europa.eu).gov
  5. EDPB SME Guide — Data Protection Officer(edpb.europa.eu).gov
  6. Article 29 Working Party - Position Paper on the derogations from the obligation to maintain records of processing activities pursuant to Article 30(5) GDPR (19 April 2018, endorsed by the EDPB)(edpb.europa.eu).gov
  7. EDPB and EDPS - Joint Opinion on the GDPR record-keeping simplification, 9 July 2025(edpb.europa.eu).gov
  8. European Commission - GDPR obligations, including when a Data Protection Officer is required(commission.europa.eu).gov
  9. European Commission - COM(2025) 501 final, 21 May 2025, proposal amending GDPR Article 30(5) (Omnibus IV, procedure 2025/0130(COD))(eur-lex.europa.eu).gov
  10. Your Europe — Data Protection Under GDPR(europa.eu).gov
  11. ICO — Advice for Small Organisations(ico.org.uk).gov
  12. ICO — Who Needs to Document Processing Activities?(ico.org.uk).gov
  13. ICO - Data protection self assessment for small business owners and sole traders (UK GDPR; under review following the Data (Use and Access) Act)(ico.org.uk).gov
  14. ICO — Marketing and Data Protection in Detail(ico.org.uk).gov
  15. EDPB — FAQ for SMEs(edpb.europa.eu).gov
  16. European Parliament Legislative Train — Digital Package(europarl.europa.eu).gov
  17. GDPR-Info.eu — Article 30 Records of Processing Activities(gdpr-info.eu)
  18. European Parliament - Provisional agreement resulting from interinstitutional negotiations, PE790.249, 26 June 2026, on COM(2025)0501 (2025/0130(COD)): agreed replacement of GDPR Article 30(5)(europarl.europa.eu).gov
  19. European Parliament Legislative Observatory - Procedure file 2025/0130(COD): provisional agreement, Coreper letter GEDA/A/(2026)004146, committee approval 2 July 2026, indicative plenary 23 November 2026(oeil.europarl.europa.eu).gov
  20. European Parliament Legislative Train - Omnibus IV, simplifying measures for SMEs and small mid-cap enterprises (regulation), edition of 1 August 2026: provisional agreement of 9 June 2026(europarl.europa.eu).gov
  21. European Commission - COM(2025) 837 final, 19 November 2025, Digital Omnibus (procedure 2025/0360(COD)), full text: amends GDPR Articles 4, 5(1)(b), 9, 12(5), 13(4), 22, 33, 35, 57(1), 64(1), 70(1) and inserts 88a and 88b(eur-lex.europa.eu).gov
  22. ANSPDCP (Romania) - Sanction for the breach of the GDPR, Velvet Medical SRL, press release of 27 February 2025, fine of 4,976.4 lei (about EUR 1,000) under Article 12(1)-(4) with Article 15(3)(dataprotection.ro).gov
Share: