Smarter sites, safer businesses — no strings attached.
Short answer: Most small businesses hold more personal data than they realize, from booking forms to mailing lists and analytics. GDPR's core ideas (collect only what's needed, know why, don't keep it forever, protect it, and answer people's requests) are a useful baseline even where GDPR doesn't strictly apply.
Ask most small-business owners "do you handle personal data?" and the honest first reaction is "not really — we're not Facebook." Then look at what's actually sitting on the business's systems: a booking form with names, phone numbers, and email addresses; a mailing list built up over a few years; website analytics tracking every visitor; a customer database with order history and notes. That's personal data, in volume, collected by a business that's never once thought about privacy as its own topic.
This post uses the EU's General Data Protection Regulation (GDPR) as the anchor because it's one of the most detailed and widely enforced privacy laws in the world, and its core ideas — know what you collect, have a real reason to collect it, don't keep it forever, protect it, let people ask questions about it — are a useful baseline for any small business, whether or not GDPR technically applies to that business. Other countries and provinces have their own privacy laws with their own specific rules (Canada's PIPEDA and Quebec's Law 25 among them, covered in the Canadian privacy law walkthrough) — those deserve their own separate walkthroughs rather than a paragraph here. This one stays with GDPR.
More than it looks like at a glance:
None of this is exotic. It's what running an ordinary website and taking ordinary bookings produces automatically, which is exactly why it's easy to have a real privacy exposure without ever making a deliberate decision to collect anything sensitive.
GDPR doesn't require an EU presence to apply. Article 3(2) extends it to any business processing personal data of people who are in the EU, if that processing relates to either of two things:
For a business with genuinely no EU customers, no EU marketing, and no tracking of EU visitors, GDPR realistically doesn't reach it. For a business running Google Analytics or Meta ad pixels on a public website with no geographic restriction, "we don't have EU customers" is a claim, not a control — and the second trigger above (monitoring EU visitors' behavior) may apply regardless of where the business is based or where it thinks its customers are.
GDPR's Article 5 sets out seven data protection principles: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality (security); and accountability, meaning the business has to be able to show it follows the other six. Together with the lawful-basis rules and individual rights, they hold up as a general baseline even outside a strict legal-compliance context:
Separately from the principles, individual rights (Articles 15–22, with Article 12 setting the response rules) give people the right to find out what data a business holds about them, get it corrected, ask for it to be deleted, object to certain processing (marketing, most directly), and receive a copy in a portable format. Article 12 requires a response "without undue delay" and, in any case, within one month of the request — extendable by up to two more months for genuinely complex requests, with the person told why.
Article 30 requires a record of processing activities (a document listing what personal data is collected, why, how long it's kept, and who it's shared with). There's a real exemption for organizations with fewer than 250 employees — but it only applies if the processing is occasional, doesn't include special categories of data (health, biometric, and similar) or criminal-conviction data, and is unlikely to create a risk to people's rights. European regulators' guidance treats routine, ongoing processing as not occasional (their own example is employee records), and the same logic reaches most everyday customer and marketing processing — so in practice, most small businesses that assume the exemption covers them turn out not to actually qualify once their everyday processing is looked at closely. A simple written record of what's collected and why is a low-cost habit worth keeping regardless of whether the exemption technically applies.
(This is a composite, illustrative scenario built from a pattern that shows up across small retail and hospitality businesses — not a specific real business's story.)
A boutique built an email list over several years by collecting addresses at checkout for "receipt by email," at in-store events for a prize drawing, and through a website popup offering 10% off a first order. Every address landed in the same marketing platform, merged with no notes on which signup method applied to which contact or what, if anything, each person had actually agreed to receive. The business genuinely believed it was doing something reasonable — everyone loves a discount, and a bigger list meant more sales.
An EU-based customer who'd bought once, years earlier, during a period the shop briefly ran international shipping, emailed asking to be removed from the list and to know what data the business held on her. The person who received the email had no idea where to even look — there was no record of consent, no way to isolate her data from the rest of the list, and no established process for the request at all. It took over five weeks and several rounds of manual searching across three different tools to compile an answer and confirm deletion — past the one-month response window the request was entitled to, though nothing beyond an apology and a completed response was asked for or escalated.
What closing this gap actually looked like: the business built a single record of what it collects, from where, and under what basis (checkout receipts under contract necessity; marketing signups under consent, tagged by source and date); added an unsubscribe and a "what data do you have on me" contact path that actually routed to a person with authority to act; and set a retention rule — inactive marketing contacts get purged after a set period instead of accumulating forever. None of it required new software, just a decision to treat the list as something with rules attached, not just a growing asset.
The single most useful thing a small business can do — GDPR-applicable or not — is write down, in one document, for each category of personal data it holds:
That's a record of processing in miniature — evidence, not just a claim, that the business knows what it's holding and why. It also makes every other question — "can we delete this?", "did we actually get consent for that?", "do we need this cookie banner or not?" — much faster to answer, because the answer is already written down instead of reconstructed from memory under pressure.
If you want a quick, no-signup sense of where your own business might have a gap in general data privacy — alongside the other areas that come up for local businesses — the free Compliance & Accessibility Self-Check covers general data privacy in plain English, and nothing entered leaves your browser.
A note on what this is and isn't: this post is educational — general patterns and plain-English explanations, written as I work through this material myself. It isn't legal advice, and it isn't a GDPR or privacy compliance assessment of your specific business — GDPR applicability and obligations depend on facts (where your customers are, what you actually collect, what your website's tracking setup does) that a blog post can't evaluate for you. If any part of this sounds familiar, that's worth a conversation with a qualified privacy professional, not just a blog post.
A demand letter over an inaccessible website isn't rare, and it isn't just a big-company problem. What WCAG actually requires, and the handful of common, fixable failures on small-business sites.
WCAG / accessibility fundamentalsAll sectorsGovernance, Risk, and Compliance sounds like a Fortune 500 problem. Two real-world scenarios showing why it isn’t.
GRC fundamentalsAll sectorsAlmost every local business that takes a card is already in scope for PCI DSS. What that actually means, and a scenario of how a small shop got it wrong.
PCI DSS fundamentals