In this article we are going to explore GDPR for SMEs, and how the GDPR applies to them.
In the era of heightened data privacy concerns, small and medium-sized enterprises (SMEs) face unique challenges in navigating the intricate landscape of the General Data Protection Regulation (GDPR). This comprehensive guide aims to demystify the application of GDPR principles to SMEs, offering practical insights and actionable steps for achieving compliance.
Contents
Overview of GDPR
The GDPR is brought into UK law by the Data Protection Act 2018.
The GDPR does three important things:
-
describing the lawful basis for processing personal data
-
setting out the rights people have to control how their data are used
-
listing the obligations people who process personal data have to meet
It partly does this by setting out a series of core GDPR privacy principles which are essential for all organisations, large and small, to follow.
You can understand the concept of processing personal data with this explainer.
How the GDPR Applies to SMEs
There is a myth that the GDPR doesn’t apply to small businesses. This is not true. The GDPR does apply to anyone who processes personal data for non-personal reasons. However, the extent to which is applies varies slightly for SMEs.
Definition of SMEs
SMEs are classified based on their employee count, annual turnover, and balance sheet total. For GDPR purposes, micro, small, and medium-sized enterprises have distinct criteria, ensuring that the compliance burden aligns with their scale.
For the purposes of the GDPR and the Data Protection Act an SME is an organisation that has fewer than 250 employees (see Article 30 of the UK GDPR for more information)
Scope of Application
SMEs must comply with the GDPR as set out in the Data Protection Act with only a small number of exemptions. Those exemptions are:
Record of Processing Activities
A record of processing activities (ROPA) is a statutory requirement. It requires organisations to keep a record of:
-
the name and contact details of the controller and, where applicable, the joint controller, the controller’s representative and the data protection officer;
-
the purposes of the data processing;
-
a description of the categories of data subjects and of the categories of personal data;
-
the categories of recipients to whom the personal data have been or will be disclosed including recipients in third countries or international organisations;
-
where possible, the envisaged time limits for erasure of the different categories of data;
-
where possible, a general description of the technical and organisational security measures used to protect the data
If the organisation has fewer than 250 employees then the organisation does not need to maintain a ROPA unless:
-
unless it is regular processing, like payroll or marketing
-
the processing poses a high risks to people’s rights and freedoms
-
the processing involves sensitive or special category data
Remember: you can find a glossary of the terms used in this article toward the end.
Appropriate Data security
Although there is no exemption relating to data security for SMEs in the GDPR, there is something they should take into account. The GDPR says for data security purposes that:
“taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk [of a data breach].”
It is important that the right level of data protection is put in place, because data breaches should be avoided and people need to be able to trust you with their information. However, small businesses, who do not have the same resources as their larger competitors, can take into account the costs of implementing data security arrangements.
The GDPR Principles for SMEs
As noted above the GDPR does apply to SMEs and therefore it is important that they take every reasonable step to abide by the GDPR privacy principles.
Lawfulness, Fairness, and Transparency
SMEs must process personal data lawfully, fairly and transparently. This means that you must:
-
know the lawful basis for your data processing, like consent or fulfilling a contract
-
process personal data in the way that people would expect
-
explain your data processing with a clear and concise privacy statement
Privacy Statement
A privacy statement can be a great way of engaging with people about how you are going to use their data and build trust. However, it needs to be done in the right way. You can read our article on the main mistakes organisations make with their privacy statements here.
Purpose Limitation
You must only use personal data for the purposes for which it was collected, and in line with your privacy statement. If you need to process the personal data you hold for other reasons, you need to identify a further lawful basis, explain this to people, and update your privacy statement.
Data Minimisation
Collecting only the data necessary for the intended purpose reduces risks and aligns with the GDPR’s emphasis on data minimisation. SMEs should evaluate what information is truly essential for their operations.
Data Accuracy
Maintaining accurate and up-to-date personal data is imperative. SMEs should establish systems to ensure the data they collect is accurate, and put in place mechanisms to correct inaccuracies promptly.
Storage Limitation
SMEs should develop policies and procedures for the retention and deletion of personal data, ensuring that data is not kept longer than necessary.
Security
As noted above SMEs have duties to take reasonable steps to maintain appropriate data security. Security arrangements need to be in place for both physical and electronic records. For example, papers records need to be securely locked away and electronic systems need to be protected against unauthorised access.
Maintaining security requires a combination of technical and organisational measures. Organisational measures include appropriate training for staff and systems in place to address a data breach if it occurs.
You can find a more detailed discussion of the privacy principles here.
Lawful Bases for Data Processing
There are six main ways for lawfully processing personal data. One of the GDPR’s requirements is that you clearly understand which lawful basis you are relying on for processing personal data. You can read more about the lawful bases for data processing here but in summary each lawful basis is:
-
consent: where someone agrees to let you use their data through clear affirmative action like opting-in to marketing
-
legal requirement: you might have to process personal data because of a legal requirement. An example is checking employees’ right to work in the UK when hiring
-
contractual obligation: you might need to process data to comply with a contract, such as delivering goods or services to a customer
-
legitimate interests: if you identify a legitimate interests for processing personal data, and it has a minimal impact on someone’s privacy, you may process their data
-
vital interests: to save a person’s life or protect them from serious harm
-
public authority basis: a public authority can process personal data for a function set out in law. For example the NHS processes medical information to provide healthcare
Sign Up Here:
A small business needs to understand and comply with people’s data rights like any other organisation. Most organisations will get data subject access requests from time to time. Also, people have the right to be informed which is covered by having a clear and comprehensive privacy statement. Other rights include: People have a right to have their data corrected if it is inaccurate or incomplete. People also have a right to have their data deleted in some circumstances. Individuals have the right to have their personal data shared with other organisations in a structured, commonly used, and machine-readable format. SMEs should comply with this transfer when requested. People also have rights to restrict the processing of their personal data. This means they don’t want yo uto use it, but they also don;t want you to delete it. They can also object to the processing of their data in some circumstances such as marketing. While it’s not always mandatory, SMEs should evaluate whether appointing a Data Protection Officer (DPO) would be beneficial. This individual oversees GDPR compliance within the organization. The DPO is responsible for advising on data protection impact assessments (DPIAs), acting as a contact point for data subjects, and liaising with supervisory authorities. SMEs should clearly define the role and responsibilities of their DPO. Small businesses can be subject to enforcement action from the Information Commissioner, and they can also be subject to civil action from people who are victims of a data breach. Some of the consequences of breaching GDPR include: GDPR violations can result in significant fines for SMEs. Understanding the potential financial consequences underscores the importance of compliance. Non-compliance can lead to reputational damage. For SMEs, trust and reputation are invaluable assets, making GDPR for SMEs essential for maintaining a positive image. There are some instances when breaching the GDPR is a criminal offence which could lead to both organisations and individuals being prosecuted. You can find out more about GDPR offences and penalties here. Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course. Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.
In conclusion, GDPR compliance is not an option but a necessity for SMEs aiming to thrive in today’s data-driven business environment. By embracing the principles of lawfulness, fairness, and transparency, and by proactively implementing measures to protect personal data, SMEs can navigate the GDPR landscape successfully. In doing so, they not only meet legal obligations but also gain the trust of customers and partners, fostering a reputation for responsible and ethical data handling practices.Data Subject Rights
Right to Rectification and Erasure
Data Portability
Rights to Object to or Restrict Processing
Data Protection Officer (DPO) for SMEs
Consequences of Non-Compliance for SMEs
Fines
Reputational Damage
Criminal Prosecution
Glossary of Terms
Conclusion: GDPR for SMEs
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: