ePact – Digital underskrift med MitID
KYC

GDPR for Small Businesses: Practical Implementation

GDPR for Small Businesses: Practical Implementation
Profile image of Aron M. Bratlann
Aron M. Bratlann
Jul 26, 2026

GDPR for Small Businesses: Practical Implementation

"GDPR? That's something big companies need to worry about." That attitude cost a local hairdresser 75,000 DKK in fines after a data breach. GDPR applies to EVERYONE processing personal data - including the sole proprietor with a customer database.

The good news? GDPR doesn't have to be a bureaucratic nightmare. With the right approach, small businesses can implement compliance without drowning in paperwork.

The Four Basic Requirements

GDPR is about protecting personal information. For your business, this means four main obligations: You need to know what personal data you have, have legal basis for having them, protect them properly, and respect people's rights.

Typical Personal Data in a Small Business

You likely have more personal data than you think. Customer information like names, addresses and purchase history. Employee data from CVs to time tracking. Supplier information with contact persons. Marketing data from newsletters and website statistics.

Even a smaller craftsman has personal data about customers, accounting and suppliers.

Legal Basis: The Most Important Exercise

GDPR requires legal basis for each data processing. The most important are consent (person actively says yes), contract fulfillment (most common for customer relationships), legal obligation (when law requires it), and legitimate interest (most flexible but requires balancing).

You must choose a basis and be able to argue for it.

Practical Implementation

Step 1: Create data inventory. Map what personal data you have. A spreadsheet works fine with columns for data type, information, storage location, legal basis, retention time and access.

Step 2: Assess your systems. Check access control, encryption, backups and cloud providers. Do you use shared passwords? Do former employees still have access?

Step 3: Establish procedures. GDPR requires procedures for access requests (30-day response time), deletion requests, security breaches (72-hour reporting deadline), and employee onboarding.

Step 4: Create documentation. Data processing agreements with all suppliers, privacy policy on website, cookie policy, and personal data processing register.

Step 5: Train employees. One hour training at hire and annual follow-up is typically sufficient.

The Biggest Pitfalls

Missing consent for marketing - pre-checked boxes aren't valid consent. Too long retention periods - "in case of" isn't good reason. Missing data processing agreements with external suppliers. Insecure data transfers via email or unencrypted USB sticks.

Concrete Examples

A hairdresser processes customer names, phone numbers and treatment history. Requires booking system with good security and deletion of inactive customers.

A restaurant handles reservations, payments and possibly video surveillance. Requires GDPR-compliant POS system and correct signage for surveillance.

A craftsman has customer information, project photos and insurance information. Requires consent for photos in marketing and encrypted backups.

When Things Go Wrong

Data breaches happen. Within 24 hours: identify the problem and document everything. Within 72 hours: assess if data authorities should be notified. At high risk: notify affected persons directly.

Most important is not hiding problems. Data authorities are more positively disposed toward companies that are open and act quickly.

Costs

GDPR compliance doesn't have to be expensive. Expect 20-40 hours at startup and 5-10 hours annually for maintenance. Consultant help can cost 5,000-15,000 DKK at startup.

Compare with fines: Up to 4% of annual revenue or 20 million euros. Even for small businesses, fines can be existence-threatening.

Your 30-Day Plan

Week 1: Map all personal data.
Week 2: Check suppliers and agreements.
Week 3: Update policies and procedures.
Week 4: Train employees and test procedures.

After 30 days you have basic GDPR compliance in place.

GDPR as Competitive Advantage

Instead of seeing GDPR as burden, use it as competitive advantage. Customers value companies that take privacy seriously. The small business getting GDPR right builds not just compliance - it builds a better business with structured processes and higher trust from all stakeholders.

Start today. GDPR compliance is an investment in your company's future.