JANELA AMBICIOSA

Data protection 2 min read

GDPR for SMEs: five decisions that solve ninety per cent of the problem

GDPR compliance in a small company does not require a department. It requires five decisions taken once and written somewhere they can be found.

An entire industry is built on the idea that the GDPR is impenetrable. For a company of ten people with no large-scale processing of sensitive data, it is not. It is a small set of decisions almost nobody takes explicitly — and it is the absence of a decision, not a wrong decision, that produces most fines in small organisations.

One: know what data you hold

No software required. A sheet with four columns does it: what data, about whom, for what purpose, and where it is stored. Build the list by walking through what the company actually does — the website form, the mailbox, invoicing, payroll, the unsolicited applications sitting in a folder.

This exercise is, in practice, the record of processing activities required by Article 30. It is also the one document a supervisory authority asks for first in nearly every inspection.

Every purpose needs a legal basis, and few apply to an SME:

  • Performance of a contract — client data needed to deliver the service. No consent required.
  • Legal obligation — invoicing, accounting, withholdings. Also no consent.
  • Legitimate interest — premises security or fraud prevention, for example, provided it is balanced and documented.
  • Consent — newsletters, non-essential cookies, use of someone’s image.

The classic mistake is asking for consent for everything. Consent is revocable: if your basis for keeping an invoice is the client’s consent, they can withdraw it and the company falls out of tax compliance. Pick the right basis and the problem disappears.

Three: set retention periods

"We keep it as long as necessary" is not a period. Set numbers, anchored in law where law exists: ten years for tax documentation, the applicable employment periods for HR data, a short and justified period for unsuccessful applications, the warranty period plus the limitation period for client data.

Then honour them. A written period that is not honoured is worse than none, because it proves the company knew.

Four: know who else touches the data

Every service that processes data on the company’s behalf is a processor and requires a contract under Article 28: email hosting, invoicing software, the backup service, external accounting. Most serious suppliers have the agreement ready — accept it and keep a copy.

Also check where the data physically sits. Outside the European Economic Area is possible, but requires adequate safeguards and has to be explained to anyone who asks.

Five: prepare the answer before the request

A data subject has the right to know what data exists about them, to correct it and, in many cases, to have it erased. The law allows one month to respond. A company that has done step one answers in an afternoon; one that has not spends that month searching.

Have a dedicated address for these requests, a responsible person and a one-page procedure.

What is not required

Not every company needs a data protection officer — the obligation depends on the nature and scale of processing. Not every company needs an impact assessment. And few need the permanent consultancy they are sold.

What every company does need is to be able to show, when asked, that it thought about it and wrote down what it decided.

This article is for information only and does not replace legal, tax or accounting advice on a specific case.

Facing this problem right now?

The initial consultation is free and exists to work out whether we can help.

Book a call