Guide
GDPR for Small Business: What You Actually Need to Do
GDPR compliance sounds intimidating, but it does not have to be. This guide cuts through the legal jargon, debunks the myths, and gives you a clear, actionable plan to get your small business compliant — without spending a fortune or hiring a lawyer.
Does GDPR apply to my small business?
The short answer is almost certainly yes. If your business collects, stores, or processes any personal data from people located in the European Union — and that includes names, email addresses, IP addresses, cookie identifiers, and payment information — then GDPR applies to you. It does not matter where your business is physically located. A small online store in Texas that ships to customers in Germany is subject to GDPR. A freelance consultant in Australia who collects email addresses from EU visitors through a website contact form is subject to GDPR. A five-person SaaS company in Canada whose analytics tool tracks visitors from France is subject to GDPR.
The regulation applies to any organization that processes personal data of EU residents, regardless of the organization's size, location, or revenue. There is no small business exemption. There is no minimum employee count below which GDPR stops applying. There is no revenue threshold that makes you too small to care about. If you have a website and any of your visitors come from the EU, you need to comply. The size of your company only determines the scope and complexity of your compliance obligations — not whether those obligations exist in the first place.
This catches many small business owners off guard. They assume that regulations written to rein in companies like Google and Meta could not possibly apply to their 3-person marketing agency or their family-run e-commerce shop. But GDPR was intentionally designed to protect personal data universally. The rights it grants to individuals — the right to know what data is collected, the right to have it deleted, the right to withdraw consent — apply regardless of who is doing the collecting. A 500-person enterprise and a solo freelancer owe the same fundamental duties to the people whose data they process.
The 250-employee myth, debunked
One of the most persistent and dangerous misconceptions about GDPR is the belief that businesses with fewer than 250 employees are exempt from the regulation. This is wrong, and relying on it can expose your business to significant fines and legal liability. Here is where the myth comes from and why it is completely misleading.
The Myth
“I have fewer than 250 employees, so GDPR does not apply to my business.”
The Reality
Article 30(5) of GDPR exempts organizations with fewer than 250 employees from maintaining detailed records of processing activities — but only if the processing is occasional, does not include sensitive data, and is unlikely to result in a risk to individuals' rights. Every other GDPR obligation applies in full.
The source of the confusion is Article 30 of the GDPR, which deals specifically with record-keeping requirements. Article 30(5) states that organizations with fewer than 250 employees do not need to maintain a formal register of processing activities, but only under very narrow conditions: the processing must be occasional (not regular), must not include special categories of data like health information or biometric data, and must not be likely to result in a risk to the rights and freedoms of individuals. In practice, almost no business qualifies for this exemption because virtually every business that collects email addresses, runs analytics, or uses cookies is engaged in regular, ongoing processing of personal data.
But even if you did qualify for the Article 30(5) record-keeping exemption, it would change nothing about your core obligations. You would still need to obtain valid consent before setting non-essential cookies. You would still need to publish a GDPR-compliant privacy policy. You would still need to honor data subject access requests, deletion requests, and portability requests within the legally mandated timeframes. You would still need to ensure that third-party processors you share data with have appropriate safeguards in place. You would still need to report data breaches to the relevant supervisory authority within 72 hours. The record-keeping exemption is a minor administrative convenience, not a get-out-of-GDPR-free card.
If your website has EU visitors and you are collecting email addresses through a newsletter signup, using Google Analytics or any other analytics platform, setting cookies for advertising or personalization, embedding social media widgets that track visitors, or processing payments that involve personal data — then you must comply with GDPR. Full stop. The number of people on your payroll is irrelevant.
8 concrete steps to get your small business GDPR compliant
GDPR compliance for a small business does not require a dedicated legal team or a six-figure budget. It requires methodical attention to a finite set of requirements. Here are the eight steps that will take you from non-compliant to compliant, in order of priority.
-
Audit your data collection
Before you can comply with GDPR, you need to understand what personal data your business actually collects. Start by listing every touchpoint where you gather information from people: website forms, email signups, checkout pages, customer support tickets, job applications, CRM entries, and analytics tools. For each touchpoint, document what data is collected, why it is collected, where it is stored, who has access to it, and how long you keep it. Most small businesses discover during this audit that they collect far more personal data than they realized — often through third-party scripts and plugins that were installed and forgotten about. This audit forms the foundation for every compliance step that follows. You cannot protect data you do not know you have.
-
Add a compliant cookie consent banner
If your website sets any cookies beyond those strictly necessary for the site to function — and virtually every website does — you need a consent banner that asks visitors for permission before those cookies are placed. Under GDPR and the ePrivacy Directive, consent must be freely given, specific, informed, and unambiguous. That means no pre-ticked checkboxes, no cookie walls that force consent, no “by continuing to browse you accept all cookies” banners, and no dark patterns that make the reject button harder to find than the accept button. Your banner must allow visitors to accept or reject non-essential cookies with equal ease, and it must actually block non-essential cookies from loading until consent is granted. A banner that appears but does not block tracking scripts is not compliant — it is decorative.
-
Publish a GDPR-compliant privacy policy
GDPR Articles 13 and 14 require you to tell people what you do with their personal data, and the privacy policy is where you do it. Your policy must include the identity and contact details of the data controller (that is your business), the types of personal data you collect, the purposes and legal basis for each type of processing, who you share data with (including third-party services like Google Analytics, Mailchimp, and Stripe), whether data is transferred outside the EU and what safeguards are in place, how long you retain data, and a clear explanation of data subject rights including how to exercise them. Do not copy someone else's privacy policy or use a generic template from the internet. Your policy must reflect your actual data practices accurately. An inaccurate privacy policy is arguably worse than not having one at all, because it demonstrates that you attempted compliance but failed to do it honestly.
-
Set up consent records
GDPR requires you to demonstrate that consent was obtained — not just claim that it was. This means you need to keep records of when consent was given, what the person consented to, how the consent was collected (which version of the form or banner was displayed), and whether consent was later withdrawn. For cookie consent, your consent management platform should handle this automatically by logging timestamps, consent categories selected, and the version of the banner presented. For email marketing consent, record the date, the signup form URL, and the exact wording that was shown when the person subscribed. If a data protection authority ever asks you to prove that a particular individual consented to a particular type of processing, you need to be able to produce that evidence. “They must have consented because they are on our mailing list” is not evidence — it is speculation.
-
Review third-party tools and sign DPAs
Every third-party service that processes personal data on your behalf — your email marketing platform, your analytics provider, your payment processor, your hosting company, your CRM — is a data processor under GDPR, and you need a Data Processing Agreement (DPA) with each one. A DPA is a legally binding document that defines how the processor handles personal data, what security measures they implement, and what happens to data when the relationship ends. Most major services like Google, Mailchimp, Stripe, HubSpot, and AWS already offer standard DPAs that you can sign through their dashboards or legal pages. Review each one, sign it, and keep copies. If a vendor does not offer a DPA or refuses to sign one, that is a serious red flag and you should consider switching to a provider that takes data protection seriously.
-
Enable data subject rights
Under GDPR, individuals have the right to access their personal data, request corrections, request deletion, restrict processing, receive their data in a portable format, and object to certain types of processing. Your business needs a clear, documented process for handling these requests. You do not need an enterprise-grade automated workflow — for a small business, a dedicated email address (like [email protected]) and a simple internal procedure is often sufficient. What matters is that you can receive requests, verify the identity of the requester, fulfill the request within 30 days (the legal deadline), and document everything. The most common request types are access requests (people wanting to know what data you hold about them) and deletion requests (people wanting you to erase their data). Make sure every member of your team knows how to recognize these requests and who to forward them to.
-
Secure your data
GDPR Article 32 requires you to implement “appropriate technical and organisational measures” to protect personal data. For a small business, this does not mean you need enterprise-grade security infrastructure. It means you need to cover the fundamentals: use HTTPS on your entire website (not just the checkout page), require strong passwords for all accounts that have access to personal data, enable two-factor authentication where available, keep your CMS, plugins, and server software updated, restrict data access to employees who genuinely need it, encrypt sensitive data at rest and in transit, and have a basic plan for what to do if a breach occurs. Security is proportional — the measures you take should match the volume and sensitivity of the data you process. A small blog collecting email addresses needs less than a healthcare startup processing medical records, but both need something.
-
Train your team
Even the smallest team needs basic GDPR awareness. Every person in your organization who handles personal data — and that likely includes everyone — should understand what personal data is, why GDPR matters, how to recognize a data subject request, what to do (and not do) with customer data, and who to contact if they suspect a data breach. This does not need to be a formal training program. A 30-minute team meeting covering the basics, combined with a simple one-page reference document, is enough for most small businesses. The goal is to make GDPR awareness part of your culture, not just a checkbox. When the person answering your support emails knows that “please delete all my data” is a legally binding request with a 30-day deadline and not just a frustrated customer venting, you are in a much better position to stay compliant.
The real cost of GDPR compliance for small businesses
One of the biggest reasons small businesses avoid GDPR compliance is the perception that it is prohibitively expensive. And if you look at the enterprise market, that perception seems justified. Enterprise consent management platforms like OneTrust typically cost between $50,000 and $500,000 per year. Hiring a dedicated Data Protection Officer costs $80,000 to $150,000 annually. Engaging a privacy consultancy for a full compliance audit can run $10,000 to $50,000. These are real numbers — and they are completely irrelevant for most small businesses.
The truth is that a small business can achieve meaningful GDPR compliance for a fraction of these costs. Here is a realistic breakdown of what compliance actually costs for a typical SMB.
| Compliance need | Enterprise approach | SMB approach |
|---|---|---|
| Consent management | OneTrust / TrustArc ($50K+/yr) | FixGDPR Starter ($9/mo) |
| Privacy policy | Law firm ($3K–$15K) | FixGDPR generator (included) |
| Cookie scanning | Included in enterprise CMP | FixGDPR scanner (free) |
| Compliance monitoring | Dedicated DPO ($80K+/yr) | FixGDPR scheduled scans ($9/mo) |
| Staff training | Training vendor ($5K–$20K) | Free online resources + team meeting ($0) |
| DPA management | Legal counsel ($2K–$10K) | Sign vendor DPAs directly ($0) |
| Total annual cost | $50,000–$500,000+ | Under $108/year |
At $9 per month, GDPR compliance with FixGDPR costs less than most business subscriptions you already pay for without thinking twice. It costs less than a single team lunch. It costs less than one month of your Spotify plan. And the cost of not complying — fines that can reach tens of thousands of euros for small businesses, plus the reputational damage and customer trust lost when a complaint is filed — makes that $9 per month look like the most obvious investment your business can make.
6 common GDPR mistakes small businesses make
After scanning thousands of websites, we see the same compliance failures over and over. Here are the six most common mistakes small businesses make — and every one of them is avoidable.
-
× Pre-ticked consent boxes
Using pre-selected checkboxes for newsletter signups, marketing preferences, or cookie categories is a direct violation of GDPR's requirement for unambiguous consent. The Court of Justice of the European Union ruled explicitly in the Planet49 case (C-673/17) that pre-ticked boxes do not constitute valid consent. Every checkbox must start unchecked, and the person must actively tick it. This applies to your cookie banner categories, your email signup forms, your checkout page marketing opt-ins, and anywhere else you ask for consent. If any consent mechanism on your site uses pre-ticked boxes, fix it immediately.
-
× No cookie banner (or a decorative one)
Many small business websites either have no cookie consent banner at all, or they have one that is purely cosmetic — it appears on the page but does nothing to actually block cookies before consent. If your banner says “This site uses cookies” with only an “OK” button and no reject option, it is not compliant. If your banner appears but Google Analytics, Facebook Pixel, and advertising cookies have already been set before the visitor clicks anything, it is not compliant. A GDPR-compliant banner must appear before non-essential cookies load, must offer granular choices, must make acceptance and rejection equally easy, and must actually block scripts until the visitor makes a choice.
-
× Copy-pasting someone else's privacy policy
Copying a privacy policy from a competitor's website or using a generic free template without customizing it is one of the most common shortcuts small businesses take, and it is one of the most dangerous. Your privacy policy must accurately describe your specific data practices. If you copied a policy that references data processing activities you do not perform or, worse, fails to mention ones you do, you are in violation of GDPR's transparency requirements. A regulator or data subject who reads your privacy policy and then discovers that your actual practices are different has grounds for a formal complaint. Write a policy that reflects what your business actually does. If you lack the time or confidence to write one from scratch, use a guided privacy policy generator that asks you specific questions about your business practices and produces a tailored document.
-
× Not knowing what cookies your own site sets
A surprising number of small business owners have no idea what cookies their website places on visitors' browsers. They installed a WordPress theme two years ago, added a handful of plugins, embedded a YouTube video, and connected Google Analytics — and they have never once checked what tracking technologies those tools introduced. Your site might be setting 30 or 40 cookies without your knowledge, some of which track visitors across the web for advertising purposes. You cannot get consent for cookies you do not know about, and you cannot properly categorize them in your banner or disclose them in your privacy policy. Run a cookie scan on your site before you do anything else. Until you know what your site is doing, you cannot make it compliant.
-
× Ignoring subject access requests
When someone emails your business and asks what personal data you hold about them, or asks you to delete their data, that is a formal data subject access request (DSAR) under GDPR Articles 15 through 22. You are legally required to respond within 30 days. Ignoring it, forgetting about it, or not recognizing it as a formal request is a violation. Many small businesses receive DSARs without realizing it — the requests do not come with legal letterheads; they often look like ordinary customer emails saying “What data do you have on me?” or “Please remove me from your systems.” Make sure everyone on your team can recognize a DSAR and knows the escalation process.
-
× Assuming “we are too small to be fined”
This is perhaps the most dangerous assumption of all. While the headline-grabbing GDPR fines target companies like Meta and Amazon, data protection authorities across Europe are increasingly focused on smaller organizations. Regulators in Spain, Romania, Poland, Hungary, and other countries have issued fines to individual shop owners, small e-commerce businesses, dental practices, and local associations. The fines may be smaller in absolute terms — typically ranging from a few thousand to a hundred thousand euros — but relative to a small business's revenue, they can be devastating. Beyond the fines themselves, the administrative burden of responding to a regulatory investigation, the legal costs, and the reputational impact can be existential for a small business.
GDPR penalties for small businesses: real examples
The maximum GDPR fine is 4% of annual global turnover or 20 million euros, whichever is higher. Those are the numbers that make headlines. But the reality of GDPR enforcement for small businesses looks quite different. Data protection authorities across Europe issue fines at every scale, and small businesses are not immune. In fact, as enforcement infrastructure matures, regulators are increasingly turning their attention to the long tail of non-compliant smaller organizations.
€75,000
Small e-commerce store (Spain)
Sending marketing emails without valid consent and failing to honor unsubscribe requests. AEPD enforcement action.
€50,000
Local medical practice (Romania)
Inadequate security measures for patient data and failure to conduct a data protection impact assessment.
€20,000
Small recruitment agency (Poland)
Processing candidate data without a proper legal basis and failing to provide required privacy information.
€8,000
Individual online shop owner (Hungary)
No cookie consent mechanism, no privacy policy, and tracking cookies loaded on every page visit without any disclosure.
These fines may seem modest compared to the billions imposed on big tech, but for a small business generating $200,000 or $500,000 in annual revenue, a fine of $20,000 to $75,000 represents a significant financial hit. And fines are just one dimension of the cost. The investigation process itself demands time and resources — responding to regulator inquiries, gathering documentation, potentially engaging legal counsel. There is also the reputational damage: when a fine is publicized, customers and partners take notice. Many regulators now publish enforcement decisions on their websites, meaning your non-compliance becomes a matter of public record.
The trend is unmistakable. European DPAs have collectively increased the number of enforcement actions year over year since GDPR came into effect in 2018. Several authorities have established dedicated teams for website compliance audits, systematically scanning sites for missing consent banners, non-functional cookie blocking, and absent privacy policies. The Austrian, French, and Belgian DPAs have been particularly active in conducting proactive sweeps of websites. If your site has EU traffic and lacks basic compliance measures, it is a matter of when, not if, enforcement catches up.
Get compliant for less than your coffee budget
GDPR compliance should not cost more than your daily coffee. Start a free scan to see where you stand, then get fully compliant with a consent banner, privacy policy, and monitoring — all for $9 per month.
Related Resources
Continue your GDPR journey.
A step-by-step checklist to make sure your website meets every GDPR requirement, from cookies and consent to privacy policies and data rights.
A comprehensive explainer of the General Data Protection Regulation — its history, scope, key principles, and what it means for your business.
Enterprise GDPR tools cost $50K+/year. See how FixGDPR delivers the same website compliance features for a fraction of the price.
Scan your website to see every cookie and tracking script it sets. Get a compliance score and fix instructions in 30 seconds.