GDPR compliance starts with one fact: the General Data Protection Regulation, Regulation (EU) 2016/679, has applied since 25 May 2018 to every business established in the EU that processes personal data — of customers, newsletter subscribers, people who fill in a contact form, staff. The articles in this category show what that means in practice for a small business: on the website, in the store, in marketing and in business systems.
GDPR for small business — the essentials
- Size is no exemption. As the European Commission puts it, what matters is what a business does with data, not how big it is. The GDPR also reaches businesses outside the EU that offer goods or services to people in the EU or monitor their behaviour.
- Records of processing. A business with fewer than 250 employees does not have to keep them unless its processing is regular, likely to put people's rights at risk, or covers sensitive data.
- Data protection officer. Required where core activities involve large-scale processing of sensitive data or large-scale, regular and systematic monitoring of people.
- Breaches. Notify the supervisory authority — in Poland, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO) — without undue delay, and at the latest within 72 hours of becoming aware of the breach, unless it is unlikely to put people's rights at risk.
- Fines. Up to €20 million or 4% of total annual worldwide turnover.
- Cookies. A separate law, the ePrivacy Directive, requires consent for cookies beyond what a service the user requested needs to work, and that consent has to meet the GDPR standard. In Poland the directive is implemented by Article 399 of the Electronic Communications Law (Prawo komunikacji elektronicznej), in force since 10 November 2024.
Where to start
Consent, cookies and marketing
Customer data in your systems