ZeerFlow

HomeWhy usAboutServicesProcessBlogFAQContact
Let's talk

ZeerFlow

Workflow & agent agency

ZeerFlow , turning manual workflows into automated systems.

·ZeerFlow.com

Navigate

  • Home
  • Why us
  • About
  • Services
  • Process
  • Blog
  • FAQ
  • Contact

Start

Let's talkWhatsApp
© 2026 ZeerFlow. All rights reserved.
General

GDPR Basics for Small Business in 2026: What You Actually Have to Do

GDPR for small business in plain English. What you actually have to do, what you do not, and how to avoid the most common mistakes.

ZT
ZeerFlow Team·Jun 10, 2026·10 min read
GDPR Basics for Small Business in 2026: What You Actually Have to Do

You run a small business. You have customers or leads in the EU or UK. You have heard about GDPR. You do not know what you actually have to do, and you are worried about being fined.

Here is the honest answer in 2026. GDPR is real, but for most small businesses the actual requirements are manageable. The most common mistake is treating GDPR as a problem to outsource and ignore, which leads to specific, avoidable, and sometimes expensive failures.

Summary

  • GDPR applies if you process personal data of EU or UK residents, regardless of where your business is based.
  • The maximum fine is 4% of global revenue or €20 million, whichever is higher. Real fines for small businesses are usually much smaller but still meaningful.
  • The core requirements: have a lawful basis, be transparent, honor data subject rights, keep data secure, document what you do, and report breaches.
  • For most small businesses, the right path is: do a data audit, write a privacy notice, set up data subject request handling, secure your data, and document the basics.
  • The biggest mistake is treating GDPR as a one-time project. It is an ongoing practice. The second biggest is doing nothing because it feels overwhelming.

When does GDPR apply to your small business?

GDPR applies when you process personal data of EU or UK residents. "Process" is broad — it includes collecting, storing, using, sharing, deleting, anything with personal data.

The trigger is not your business size or your revenue. The trigger is:

A US business with one EU customer is subject to GDPR. A UK business with no EU customers is not subject to EU GDPR but is subject to UK GDPR. A business with EU customers that processes their data through a US service provider is still subject to GDPR.

The right question is not "am I big enough for GDPR" but "do I have any EU/UK personal data." If yes, GDPR applies.

  • You have customers, leads, or users in the EU or UK
  • You collect any personal data (name, email, IP address, browsing data, anything)
  • You are a controller or processor of that data

What is the actual fine risk?

The maximum fine under GDPR is €20 million or 4% of global annual revenue, whichever is higher. For a small business with $1M revenue, the absolute maximum is €20M (since 4% = $40K, lower than €20M).

In practice, the fines for small businesses are usually much smaller. The ICO (UK regulator) and various EU DPAs have shown restraint for small businesses that are trying to comply. The pattern of recent enforcement:

The cost of a real fine is not the only cost. The reputational cost, the cost of remediation, and the cost of management distraction are real. But the right framing: GDPR is not going to put a small business out of business for a one-time mistake. It will for systemic non-compliance.

  • Large companies: fines in the hundreds of millions (Meta, Clearview AI, etc.)
  • Mid-size companies: fines in the millions (BA, Marriott, Equifax)
  • Small businesses: fines in the thousands to low millions, often for specific failures, not "we did not have a privacy program"

What are the core requirements?

The 6 core requirements, in plain English:

Requirement 1: Lawful basis for processing

You need a legal reason to process personal data. The lawful bases are:

Most small businesses use consent (for marketing) and contract (for service delivery) and legitimate interests (for things like fraud prevention).

The right answer depends on the use case. The wrong answer is "we have a privacy policy, so we are good." A privacy policy describes the lawful basis; it does not create one.

Requirement 2: Transparency

You must tell people what you are doing with their data. This is the privacy notice. The privacy notice must be:

The minimum: a privacy policy on your website that explains what data you collect, why, how long you keep it, who you share it with, and what rights the person has.

Requirement 3: Data subject rights

People have rights over their data. You must honor them. The rights:

For most small businesses, the practical rights are: access requests, erasure requests ("right to be forgotten"), and marketing opt-out. You need a process to handle these in 30 days.

Requirement 4: Security

You must implement appropriate security measures. "Appropriate" depends on the sensitivity of the data. For most small businesses, this means:

The data breach notifications requirement is also part of this: if you have a breach that risks the rights of individuals, you must notify the regulator within 72 hours and the affected individuals where the risk is high.

Requirement 5: Documentation

You must document what you do. The minimum:

This is a lot of documentation for a small business. The right approach: a single document (called a Record of Processing Activities or RoPA) that covers all your processing in one place. Most small businesses can do this in a few pages.

Requirement 6: Data protection by design and by default

You must consider data protection when designing products and processes, and you must default to the most privacy-protective option.

For a small business, this means: collect only the data you need, retain it only as long as you need it, and default to not sharing it with third parties unless necessary.

  • Consent (the person agreed)
  • Contract (the processing is needed to perform a contract with them)
  • Legal obligation (you are required by law)
  • Vital interests (life or death)
  • Public task (you are a public body)
  • Legitimate interests (you have a legitimate business reason, balanced against the person's rights)
  • Concise, transparent, intelligible, and easily accessible
  • Written in clear and plain language
  • Provided at the time you collect the data
  • Available on your website
  • Right to access (give them a copy of their data)
  • Right to rectification (correct wrong data)
  • Right to erasure (delete their data, where applicable)
  • Right to restrict processing (stop using their data in certain ways)
  • Right to data portability (give them their data in a machine-readable format)
  • Right to object (stop using their data for certain purposes, especially marketing)
  • Rights related to automated decision making (including profiling)
  • Encryption in transit (HTTPS)
  • Encryption at rest (the database and the backup)
  • Access control (only people who need access have access)
  • 2FA on important accounts
  • Regular security updates
  • Tested backup
  • Record of processing activities (what data, why, how long, who you share it with)
  • Privacy notice
  • Data processing agreements with vendors
  • Breach response process
  • Lawful basis for each processing activity

What should a small business actually do?

The 90-day GDPR plan for a small business:

Days 1-30: foundations

Days 31-60: processes

Days 61-90: ongoing

After 90 days, you have a working GDPR program. It is not perfect, but it is real, and the regulators care more about effort than perfection.

  • Do a data audit. What personal data do you collect, where is it stored, who has access, how long do you keep it, who do you share it with?
  • Write a privacy notice. Publish it on your website. Make it clear, not legalese.
  • Document your lawful basis for each processing activity. This is a simple table.
  • Review your data processor agreements (with SaaS vendors, cloud providers, etc.). Make sure they have DPAs that meet GDPR requirements.
  • Set up a process for data subject requests. Email address, response template, 30-day timeline. Most requests can be handled in a day; the process is just making it official.
  • Set up a breach response process. Who to call, what to do, when to notify. The 72-hour clock starts when you become aware.
  • Review your marketing practices. Do you have consent for email marketing? Is the opt-out clear? Are you honoring opt-outs promptly?
  • Set retention periods. How long do you keep customer data, lead data, employee data, financial data? Document and enforce.
  • Train your team. Most GDPR failures are people failures (an employee emails data to the wrong person, a contractor shares a customer list, etc.). A 2-hour training is sufficient for most small teams.
  • Set up annual review. The data audit, the privacy notice, the vendor list, the process — all need to be reviewed at least annually.
  • Subscribe to ICO (UK) or your local DPA (EU) communications. They publish guidance, enforcement actions, and templates.

What are the most common small business GDPR mistakes?

The honest list:

Mistake 1: No privacy notice

You do not have a privacy policy on your website. Or the privacy policy is a generic template that does not match what you actually do. The ICO has fined small businesses for this specific failure.

Mistake 2: Marketing without consent

You email people who did not specifically opt in. Or you added them to a list and assumed consent. The right rule: explicit opt-in for marketing emails (in the EU and UK), clear unsubscribe in every email, honor opt-outs within a reasonable time.

Mistake 3: Vendor data processing without DPAs

You use a US-based SaaS provider to process EU/UK personal data, and you do not have a DPA. The provider is processing data on your behalf without a GDPR-compliant agreement. This is a common failure for small businesses.

Mistake 4: No breach response

You do not know what to do if you have a breach. You have no process, no contact at the regulator, no template. When a breach happens (and it will eventually), the 72-hour clock starts and you are not ready.

Mistake 5: Data retention forever

You keep customer data, lead data, employee data indefinitely. GDPR requires that you retain data only as long as necessary. Most small businesses keep too much, for too long.

Mistake 6: No record of processing

You do not know what data you have, where it is, or who has access. The audit alone is the most valuable exercise. Most small businesses are surprised by what they find.

Mistake 7: Treating consent as a checkbox

You have a consent box on the form. The person checks it. You assume you have consent. But the consent was bundled with terms of service, or it was pre-checked, or it was not specific. GDPR consent must be specific, informed, freely given, and unambiguous.

How do you handle data subject requests?

The process:

Most access requests can be handled in 1-2 days of actual work. The 30-day timeline is rarely the bottleneck; finding the data is.

For erasure requests: confirm the request, delete the data (and notify processors), respond within 30 days. Some data cannot be erased (legal obligations, ongoing contracts); explain this in the response.

For data portability requests: provide the data in a structured, commonly used format (CSV, JSON). This is most relevant for data the person provided to you.

  • Receive the request (usually by email, sometimes by letter)
  • Verify the identity (reasonable steps, not exhaustive)
  • Find the data (search your systems)
  • Provide the data (in a commonly used format, usually PDF or CSV)
  • Respond within 30 days (one-month extension is possible for complex requests)
  • Document the request and the response

What about AI and GDPR in 2026?

The 2024 EU AI Act and the EDPB guidance on AI and GDPR create additional requirements for AI systems that process personal data:

For most small businesses using AI, the practical requirements are:

The honest assessment: AI + GDPR is still being defined. The regulators are still issuing guidance. The right approach is to be conservative, document carefully, and stay current.

  • Lawful basis for using personal data to train AI
  • Transparency about AI decision-making
  • Data subject rights in the context of AI
  • Special protections for high-risk AI systems
  • Documentation and human oversight
  • Document what personal data you feed into AI tools
  • Use AI providers with GDPR-compliant DPAs (OpenAI, Anthropic, Google all have these)
  • Be transparent with users when AI is making decisions that affect them
  • Allow opt-out where possible (e.g., let users choose not to have their support ticket processed by AI)

What is the bottom line on GDPR for small business in 2026?

GDPR is real, but for most small businesses the actual requirements are manageable. The 90-day plan is the right starting point: data audit, privacy notice, lawful basis, vendor DPAs, breach process, training.

The biggest mistake is doing nothing because it feels overwhelming. The 5-10 hours of work for the foundations is much less than the cost of a regulator investigation or a data breach without a process.

The second biggest mistake is treating GDPR as a one-time project. It is an ongoing practice. The data audit, the privacy notice, the vendor list, the processes — all need to be reviewed annually.

The right framing: GDPR is the cost of doing business with EU/UK customers. The cost is manageable. The discipline is good for the business regardless. Do the foundations, stay current, and treat it as an ongoing practice.

Related reading

  • SaaS Contracts in 2026: 7 Clauses Every Business Owner Should Read
  • Your First Cybersecurity Audit in 2026: What to Ask and Who to Hire
  • Data Backup and Recovery in 2026: The 3-2-1 Rule and What It Costs
  • Password Managers in 2026: Why You Need One, Which to Use, How to Migrate
  • How to Evaluate a Tech Vendor in 2026: Red Flags and Green Flags

Frequently asked questions

Summary?
- GDPR applies if you process personal data of EU or UK residents, regardless of where your business is based. - The maximum fine is 4% of global revenue or €20 million, whichever is higher. Real fines for small businesses are usually much smaller but still meaningful. - The c…
When does GDPR apply to your small business??
GDPR applies when you process personal data of EU or UK residents. "Process" is broad — it includes collecting, storing, using, sharing, deleting, anything with personal data. The trigger is not your business size or your revenue. The trigger is: - You have customers, leads, o…
What is the actual fine risk??
The maximum fine under GDPR is €20 million or 4% of global annual revenue, whichever is higher. For a small business with $1M revenue, the absolute maximum is €20M (since 4% = $40K, lower than €20M). In practice, the fines for small businesses are usually much smaller. The ICO…
What are the core requirements??
The 6 core requirements, in plain English: Requirement 1: Lawful basis for processing You need a legal reason to process personal data. The lawful bases are: - Consent (the person agreed) - Contract (the processing is needed to perform a contract with them) - Legal obligation…

10 min read

Share

On this page

  • Summary
  • When does GDPR apply to your small business?
  • What is the actual fine risk?
  • What are the core requirements?
  • Requirement 1: Lawful basis for processing
  • Requirement 2: Transparency
  • Requirement 3: Data subject rights
  • Requirement 4: Security
  • Requirement 5: Documentation
  • Requirement 6: Data protection by design and by default
  • What should a small business actually do?
  • Days 1-30: foundations
  • Days 31-60: processes
  • Days 61-90: ongoing
  • What are the most common small business GDPR mistakes?
  • Mistake 1: No privacy notice
  • Mistake 2: Marketing without consent
  • Mistake 3: Vendor data processing without DPAs
  • Mistake 4: No breach response
  • Mistake 5: Data retention forever
  • Mistake 6: No record of processing
  • Mistake 7: Treating consent as a checkbox
  • How do you handle data subject requests?
  • What about AI and GDPR in 2026?
  • What is the bottom line on GDPR for small business in 2026?
  • Related reading

Continue Reading

Public WiFi in 2026: What's Actually Dangerous and What Isn't
General

Public WiFi in 2026: What's Actually Dangerous and What Isn't

The honest risk map for public WiFi in 2026. What's overhyped, what's real, and the 4 habits that keep you safe in any coffee shop.

Jul 10, 2026·8 min read
SaaS Contracts in 2026: 7 Clauses Every Business Owner Should Read
General

SaaS Contracts in 2026: 7 Clauses Every Business Owner Should Read

The 7 SaaS contract clauses that matter most. What to look for, what to push back on, and what to walk away from.

Jul 28, 2026·10 min read
Phishing in 2026: How to Spot the New Attacks (and What to Do If You Click)
General

Phishing in 2026: How to Spot the New Attacks (and What to Do If You Click)

Phishing in 2026 is AI-generated, voice-cloned, and works on text messages. The new patterns, the tell-tale signs, and the right response if you click.

Jul 18, 2026·9 min read

Enjoyed this article?

Get our latest engineering insights delivered straight to your inbox.

Previous Article

AI-Generated Code in Enterprise: The 2026 Productivity Numbers Are In

Next Article

Sovereign AI in 2026: Why EU and UK Enterprises Are Rebuilding Their AI Stack On-Prem