Cys Infotech

Smarter sites, safer businesses — no strings attached.

Home / Blog

Data Privacy Basics for Small Businesses: A GDPR-Anchored Baseline

Short answer: Most small businesses hold more personal data than they realize, from booking forms to mailing lists and analytics. GDPR's core ideas (collect only what's needed, know why, don't keep it forever, protect it, and answer people's requests) are a useful baseline even where GDPR doesn't strictly apply.

Ask most small-business owners "do you handle personal data?" and the honest first reaction is "not really — we're not Facebook." Then look at what's actually sitting on the business's systems: a booking form with names, phone numbers, and email addresses; a mailing list built up over a few years; website analytics tracking every visitor; a customer database with order history and notes. That's personal data, in volume, collected by a business that's never once thought about privacy as its own topic.

This post uses the EU's General Data Protection Regulation (GDPR) as the anchor because it's one of the most detailed and widely enforced privacy laws in the world, and its core ideas — know what you collect, have a real reason to collect it, don't keep it forever, protect it, let people ask questions about it — are a useful baseline for any small business, whether or not GDPR technically applies to that business. Other countries and provinces have their own privacy laws with their own specific rules (Canada's PIPEDA and Quebec's Law 25 among them, covered in the Canadian privacy law walkthrough) — those deserve their own separate walkthroughs rather than a paragraph here. This one stays with GDPR.

What personal data does a typical local business actually hold?

More than it looks like at a glance:

None of this is exotic. It's what running an ordinary website and taking ordinary bookings produces automatically, which is exactly why it's easy to have a real privacy exposure without ever making a deliberate decision to collect anything sensitive.

When does GDPR actually reach a business outside the EU?

GDPR doesn't require an EU presence to apply. Article 3(2) extends it to any business processing personal data of people who are in the EU, if that processing relates to either of two things:

  1. Offering goods or services to people in the EU — even if nothing is ever paid for. A shop that ships to EU countries, prices in euros, or markets specifically to EU customers is likely "offering" to them in the sense the regulation means; regulators look at these signals together, and no single one is automatically decisive. A business that simply has an English-language website an EU visitor happens to stumble across is not automatically in scope — the test is whether the business is actually targeting EU people, not whether an EU person can technically reach the site.
  2. Monitoring the behavior of people in the EU — tracking EU visitors' activity on a website, building profiles from it, or using it to predict preferences or make decisions about them. European regulators have said not every online collection of data counts as monitoring; what matters is the purpose and whether behaviour is analysed or profiled. Retargeting and ad-profiling tools are the clearest case, and detailed analytics can be too, depending on how it's used.

For a business with genuinely no EU customers, no EU marketing, and no tracking of EU visitors, GDPR realistically doesn't reach it. For a business running Google Analytics or Meta ad pixels on a public website with no geographic restriction, "we don't have EU customers" is a claim, not a control — and the second trigger above (monitoring EU visitors' behavior) may apply regardless of where the business is based or where it thinks its customers are.

The core ideas, in plain English

GDPR's Article 5 sets out seven data protection principles: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality (security); and accountability, meaning the business has to be able to show it follows the other six. Together with the lawful-basis rules and individual rights, they hold up as a general baseline even outside a strict legal-compliance context:

Separately from the principles, individual rights (Articles 15–22, with Article 12 setting the response rules) give people the right to find out what data a business holds about them, get it corrected, ask for it to be deleted, object to certain processing (marketing, most directly), and receive a copy in a portable format. Article 12 requires a response "without undue delay" and, in any case, within one month of the request — extendable by up to two more months for genuinely complex requests, with the person told why.

The written-records question — and why "we're too small" usually doesn't hold

Article 30 requires a record of processing activities (a document listing what personal data is collected, why, how long it's kept, and who it's shared with). There's a real exemption for organizations with fewer than 250 employees — but it only applies if the processing is occasional, doesn't include special categories of data (health, biometric, and similar) or criminal-conviction data, and is unlikely to create a risk to people's rights. European regulators' guidance treats routine, ongoing processing as not occasional (their own example is employee records), and the same logic reaches most everyday customer and marketing processing — so in practice, most small businesses that assume the exemption covers them turn out not to actually qualify once their everyday processing is looked at closely. A simple written record of what's collected and why is a low-cost habit worth keeping regardless of whether the exemption technically applies.

Scenario: the loyalty list that outgrew its purpose

(This is a composite, illustrative scenario built from a pattern that shows up across small retail and hospitality businesses — not a specific real business's story.)

A boutique built an email list over several years by collecting addresses at checkout for "receipt by email," at in-store events for a prize drawing, and through a website popup offering 10% off a first order. Every address landed in the same marketing platform, merged with no notes on which signup method applied to which contact or what, if anything, each person had actually agreed to receive. The business genuinely believed it was doing something reasonable — everyone loves a discount, and a bigger list meant more sales.

An EU-based customer who'd bought once, years earlier, during a period the shop briefly ran international shipping, emailed asking to be removed from the list and to know what data the business held on her. The person who received the email had no idea where to even look — there was no record of consent, no way to isolate her data from the rest of the list, and no established process for the request at all. It took over five weeks and several rounds of manual searching across three different tools to compile an answer and confirm deletion — past the one-month response window the request was entitled to, though nothing beyond an apology and a completed response was asked for or escalated.

What closing this gap actually looked like: the business built a single record of what it collects, from where, and under what basis (checkout receipts under contract necessity; marketing signups under consent, tagged by source and date); added an unsubscribe and a "what data do you have on me" contact path that actually routed to a person with authority to act; and set a retention rule — inactive marketing contacts get purged after a set period instead of accumulating forever. None of it required new software, just a decision to treat the list as something with rules attached, not just a growing asset.

A practical starting point: your own mini data inventory

The single most useful thing a small business can do — GDPR-applicable or not — is write down, in one document, for each category of personal data it holds:

That's a record of processing in miniature — evidence, not just a claim, that the business knows what it's holding and why. It also makes every other question — "can we delete this?", "did we actually get consent for that?", "do we need this cookie banner or not?" — much faster to answer, because the answer is already written down instead of reconstructed from memory under pressure.

If you want a quick, no-signup sense of where your own business might have a gap in general data privacy — alongside the other areas that come up for local businesses — the free Compliance & Accessibility Self-Check covers general data privacy in plain English, and nothing entered leaves your browser.

A note on what this is and isn't: this post is educational — general patterns and plain-English explanations, written as I work through this material myself. It isn't legal advice, and it isn't a GDPR or privacy compliance assessment of your specific business — GDPR applicability and obligations depend on facts (where your customers are, what you actually collect, what your website's tracking setup does) that a blog post can't evaluate for you. If any part of this sounds familiar, that's worth a conversation with a qualified privacy professional, not just a blog post.