GDPR for SMEs: How it Applies

In this article we are going to explore GDPR for SMEs, and how the GDPR applies to them.

In the era of heightened data privacy concerns, small and medium-sized enterprises (SMEs) face unique challenges in navigating the intricate landscape of the General Data Protection Regulation (GDPR). This comprehensive guide aims to demystify the application of GDPR principles to SMEs, offering practical insights and actionable steps for achieving compliance.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

Contents

Overview of GDPR

The GDPR is brought into UK law by the Data Protection Act 2018.

The GDPR does three important things:

  • describing the lawful basis for processing personal data

  • setting out the rights people have to control how their data are used

  • listing the obligations people who process personal data have to meet

It partly does this by setting out a series of core GDPR privacy principles which are essential for all organisations, large and small, to follow.

You can understand the concept of processing personal data with this explainer.

How the GDPR Applies to SMEs

There is a myth that the GDPR doesn’t apply to small businesses. This is not true. The GDPR does apply to anyone who processes personal data for non-personal reasons. However, the extent to which is applies varies slightly for SMEs.

Definition of SMEs

SMEs are classified based on their employee count, annual turnover, and balance sheet total. For GDPR purposes, micro, small, and medium-sized enterprises have distinct criteria, ensuring that the compliance burden aligns with their scale.

For the purposes of the GDPR and the Data Protection Act an SME is an organisation that has fewer than 250 employees (see Article 30 of the UK GDPR for more information)

Scope of Application

SMEs must comply with the GDPR as set out in the Data Protection Act with only a small number of exemptions. Those exemptions are:

Record of Processing Activities

A record of processing activities (ROPA) is a statutory requirement. It requires organisations to keep a record of:

  • the name and contact details of the controller and, where applicable, the joint controller, the controller’s representative and the data protection officer;

  • the purposes of the data processing;

  • a description of the categories of data subjects and of the categories of personal data;

  • the categories of recipients to whom the personal data have been or will be disclosed including recipients in third countries or international organisations;

  • where possible, the envisaged time limits for erasure of the different categories of data;

  • where possible, a general description of the technical and organisational security measures used to protect the data

If the organisation has fewer than 250 employees then the organisation does not need to maintain a ROPA unless:

  • unless it is regular processing, like payroll or marketing

  • the processing poses a high risks to people’s rights and freedoms

  • the processing involves sensitive or special category data

Remember: you can find a glossary of the terms used in this article toward the end.

Appropriate Data security

Although there is no exemption relating to data security for SMEs in the GDPR, there is something they should take into account. The GDPR says for data security purposes that:

“taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk [of a data breach].”

It is important that the right level of data protection is put in place, because data breaches should be avoided and people need to be able to trust you with their information. However, small businesses, who do not have the same resources as their larger competitors, can take into account the costs of implementing data security arrangements.

The GDPR Principles for SMEs

As noted above the GDPR does apply to SMEs and therefore it is important that they take every reasonable step to abide by the GDPR privacy principles.

Lawfulness, Fairness, and Transparency

SMEs must process personal data lawfully, fairly and transparently. This means that you must:

  • know the lawful basis for your data processing, like consent or fulfilling a contract

  • process personal data in the way that people would expect

  • explain your data processing with a clear and concise privacy statement

Privacy Statement

A privacy statement can be a great way of engaging with people about how you are going to use their data and build trust. However, it needs to be done in the right way. You can read our article on the main mistakes organisations make with their privacy statements here.

Purpose Limitation

You must only use personal data for the purposes for which it was collected, and in line with your privacy statement. If you need to process the personal data you hold for other reasons, you need to identify a further lawful basis, explain this to people, and update your privacy statement.

Data Minimisation

Collecting only the data necessary for the intended purpose reduces risks and aligns with the GDPR’s emphasis on data minimisation. SMEs should evaluate what information is truly essential for their operations.

Data Accuracy

Maintaining accurate and up-to-date personal data is imperative. SMEs should establish systems to ensure the data they collect is accurate, and put in place mechanisms to correct inaccuracies promptly.

Storage Limitation

SMEs should develop policies and procedures for the retention and deletion of personal data, ensuring that data is not kept longer than necessary.

Security

As noted above SMEs have duties to take reasonable steps to maintain appropriate data security. Security arrangements need to be in place for both physical and electronic records. For example, papers records need to be securely locked away and electronic systems need to be protected against unauthorised access.

Maintaining security requires a combination of technical and organisational measures. Organisational measures include appropriate training for staff and systems in place to address a data breach if it occurs.

You can find a more detailed discussion of the privacy principles here.

Lawful Bases for Data Processing

There are six main ways for lawfully processing personal data. One of the GDPR’s requirements is that you clearly understand which lawful basis you are relying on for processing personal data. You can read more about the lawful bases for data processing here but in summary each lawful basis is:

  • consent: where someone agrees to let you use their data through clear affirmative action like opting-in to marketing

  • legal requirement: you might have to process personal data because of a legal requirement. An example is checking employees’ right to work in the UK when hiring

  • contractual obligation: you might need to process data to comply with a contract, such as delivering goods or services to a customer

  • legitimate interests: if you identify a legitimate interests for processing personal data, and it has a minimal impact on someone’s privacy, you may process their data

  • vital interests: to save a person’s life or protect them from serious harm

  • public authority basis: a public authority can process personal data for a function set out in law. For example the NHS processes medical information to provide healthcare

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

Data Subject Rights

A small business needs to understand and comply with people’s data rights like any other organisation. Most organisations will get data subject access requests from time to time. Also, people have the right to be informed which is covered by having a clear and comprehensive privacy statement. Other rights include:

Right to Rectification and Erasure

People have a right to have their data corrected if it is inaccurate or incomplete. People also have a right to have their data deleted in some circumstances.

Data Portability

Individuals have the right to have their personal data shared with other organisations in a structured, commonly used, and machine-readable format. SMEs should comply with this transfer when requested.

Rights to Object to or Restrict Processing

People also have rights to restrict the processing of their personal data. This means they don’t want yo uto use it, but they also don;t want you to delete it.

They can also object to the processing of their data in some circumstances such as marketing.

Data Protection Officer (DPO) for SMEs

While it’s not always mandatory, SMEs should evaluate whether appointing a Data Protection Officer (DPO) would be beneficial. This individual oversees GDPR compliance within the organization.

The DPO is responsible for advising on data protection impact assessments (DPIAs), acting as a contact point for data subjects, and liaising with supervisory authorities. SMEs should clearly define the role and responsibilities of their DPO.

Consequences of Non-Compliance for SMEs

Small businesses can be subject to enforcement action from the Information Commissioner, and they can also be subject to civil action from people who are victims of a data breach. Some of the consequences of breaching GDPR include:

Fines

GDPR violations can result in significant fines for SMEs. Understanding the potential financial consequences underscores the importance of compliance.

Reputational Damage

Non-compliance can lead to reputational damage. For SMEs, trust and reputation are invaluable assets, making GDPR for SMEs essential for maintaining a positive image.

Criminal Prosecution

There are some instances when breaching the GDPR is a criminal offence which could lead to both organisations and individuals being prosecuted.

You can find out more about GDPR offences and penalties here.

Glossary of Terms

  • categories: the type of person whose data is being processed e.g. employee, customer; and the type of data e.g. contact information, financial information etc.
  • controller: the person who decides the reasons for collecting and processing personal data
  • data subjects: the people whose personal data are being processed
  • rights and freedoms: the GDPR rights and general rights to privacy and to control their data
  • sensitive personal data: data with additional protections such as medical information

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial

Conclusion: GDPR for SMEs

In conclusion, GDPR compliance is not an option but a necessity for SMEs aiming to thrive in today’s data-driven business environment. By embracing the principles of lawfulness, fairness, and transparency, and by proactively implementing measures to protect personal data, SMEs can navigate the GDPR landscape successfully. In doing so, they not only meet legal obligations but also gain the trust of customers and partners, fostering a reputation for responsible and ethical data handling practices.