In January 2024, we got a panicked call from a client -- a 12-person accounting firm in Zagreb. They'd received a complaint filed with the Croatian DPA because a former client requested deletion of their data and the firm had no process to handle it. No data inventory, no documented procedures, no idea where that person's data even lived across their systems. The complaint didn't result in a fine, but the 47 hours they spent scrambling to respond could have been avoided entirely with a weekend's worth of preparation.
We've helped over 60 small businesses get their GDPR house in order since the regulation took effect. Here's the practical guide we wish someone had given us -- and them -- on day one.
First, Let's Kill Some Myths
Myth: "GDPR only applies to EU companies"
Wrong. If you process data of anyone in the EU -- even if you're based in Bosnia, the US, or anywhere else -- GDPR applies to you. Have a website that EU citizens visit? Use Google Analytics? Collect emails from EU subscribers? You're in scope.
Myth: "Small businesses are exempt"
There's no small business exemption. The only partial exemption is for companies with fewer than 250 employees, who don't need to maintain a formal Record of Processing Activities -- unless processing is regular, involves sensitive data, or could affect rights and freedoms. In practice, every business that collects customer data should maintain one anyway. It takes two hours to create and saves you dozens later.
Myth: "We just need a cookie banner and we're compliant"
A cookie banner is roughly 10% of compliance. It's visible, which is why people focus on it, but the real work is in your data processing documentation, consent mechanisms, vendor agreements, and incident response procedures.
Myth: "Nobody actually gets fined for small amounts"
In 2023, a Spanish restaurant was fined EUR 2,000 for having a CCTV system without proper signage and documentation. A Portuguese hospital was fined EUR 400,000. A Greek school was fined EUR 3,000 for publishing student photos online without consent. Fines scale to the violation, and regulators are increasingly going after smaller organisations to set examples.
What You Actually Need to Do: The Checklist
After working through GDPR compliance with dozens of clients, we've distilled it to 12 concrete actions. Not legal theory -- actions you can implement.
1. Create a Data Inventory
List every type of personal data you collect, where it's stored, why you collect it, and how long you keep it. This is the foundation everything else builds on.
Typical small business data map:
- Contact forms -- name, email, phone, message -- stored in email inbox and/or CRM
- Customer records -- name, address, payment info -- stored in accounting software and invoicing
- Employee data -- personal details, contracts, payroll -- stored in HR system and local files
- Website analytics -- IP addresses, browsing behaviour -- stored by Google Analytics / Matomo
- Email marketing -- name, email, consent date -- stored in Mailchimp / Brevo / ActiveCampaign
- CCTV (if applicable) -- video footage -- stored on local DVR/NVR
For each entry: document the legal basis (consent, contract, legitimate interest), retention period, and who has access.
2. Set Up Proper Cookie Consent
This is where most websites fail an audit. A compliant cookie consent mechanism must:
- Block all non-essential cookies before the user gives consent. This means Google Analytics, Facebook Pixel, and marketing scripts must NOT fire until the user clicks "Accept."
- Offer granular choices -- necessary, analytics, marketing -- not just "accept all."
- Make rejecting cookies as easy as accepting them. A prominent "Accept" button and a hidden "Manage preferences" link is not compliant. The French DPA (CNIL) has been fining for this specifically.
- Record consent with timestamp, version of consent text, and choices made.
- Allow withdrawal of consent at any time, and make it easy to find.
Tools we recommend:
- Cookiebot (from EUR 12/month) -- solid, widely recognised, auto-scans your site for cookies
- Complianz (WordPress plugin, from EUR 45/year) -- excellent for WordPress sites, good geo-targeting
- Klaro (open source, free) -- lightweight, self-hosted, full control but requires technical setup
- Tarteaucitron (open source, free) -- popular in European markets, good documentation
We install Cookiebot or Complianz for about 70% of our clients. The setup takes 2-3 hours including testing.
3. Write a Privacy Policy That Humans Can Read
Your privacy policy must include:
- Who you are (company name, address, contact details)
- What data you collect and why
- Legal basis for each type of processing
- Who you share data with (including processors like Google, Mailchimp, your hosting provider)
- Data retention periods
- User rights and how to exercise them
- Cookie information (or link to separate cookie policy)
- Right to complain to a supervisory authority
Skip the legalese. Write it at a 9th-grade reading level. We've seen 14-page privacy policies that say nothing useful and 2-page policies that cover everything clearly. Aim for the latter.
4. Implement Data Processing Agreements (DPAs)
Every third-party service that processes personal data on your behalf needs a DPA. The good news: most major services already have them available.
- Google -- DPA available in Google Workspace and Analytics admin settings
- Mailchimp -- standard DPA in account settings, includes EU SCCs
- Stripe -- DPA auto-accepted in terms of service
- Your hosting provider -- should provide a DPA. If they don't, ask. If they refuse, switch providers. (We include DPAs with all our hosting plans.)
Download or accept each DPA and keep copies. An auditor will ask for them.
5. Set Up a Process for Data Subject Requests
Under GDPR, individuals can request:
- Access -- "What data do you have on me?"
- Rectification -- "Correct this data."
- Erasure ("Right to be forgotten") -- "Delete my data."
- Portability -- "Give me my data in a machine-readable format."
- Restriction -- "Stop processing my data but don't delete it."
- Objection -- "Stop using my data for this purpose."
You have 30 days to respond. You need a documented process: who receives the request, how you verify identity, who fulfils it, and how you confirm completion.
For most small businesses, this is a simple checklist document and a dedicated email address (e.g., privacy@yourdomain.com). The accounting firm from our opening story didn't have this, and it turned a 20-minute task into a 47-hour crisis.
6. Secure Your Data (For Real)
GDPR requires "appropriate technical and organisational measures." For a small business, that means:
- HTTPS everywhere -- no excuses, free SSL certificates have existed for years
- Strong passwords + 2FA on all accounts that touch personal data
- Encrypted backups stored separately from production systems
- Access control -- not everyone needs access to everything. Your intern doesn't need the customer database.
- Updated software -- unpatched WordPress sites are the #1 vulnerability we see. We patch an average of 23 outdated plugins per week across our managed hosting clients.
- Encrypted email for sensitive data transfers, or use a secure file sharing service
7. Prepare a Breach Response Plan
If personal data is breached, you have 72 hours to notify your supervisory authority (if the breach poses a risk to individuals). You need:
- A documented procedure for identifying and assessing breaches
- Contact details for your supervisory authority
- A notification template ready to fill in
- A process for notifying affected individuals (required if the breach is high-risk)
We've seen three breaches across our client base in five years. In all three cases, having the response plan ready meant notification happened within 24 hours. Without a plan, most small businesses don't even realise they need to notify anyone.
8. Legitimate Interest Assessments
If you're relying on "legitimate interest" as your legal basis (common for B2B marketing, analytics, or fraud prevention), document your reasoning. A Legitimate Interest Assessment (LIA) is a short document that weighs your interest against the data subject's rights. It doesn't need to be complex -- a half-page per processing activity is sufficient.
9. Update Your Forms
Every form that collects personal data needs:
- Clear statement of what the data will be used for
- Separate, unchecked checkboxes for each purpose (no pre-ticked boxes, ever)
- Link to your privacy policy
- No bundled consent ("By submitting this form you agree to receive marketing" is not valid consent for marketing)
10. Employee Training
Your entire team needs to understand the basics: what personal data is, how to handle data subject requests, what constitutes a breach, and who to contact internally. This doesn't require a formal training programme -- a 30-minute team meeting with a clear one-page reference document works for most small businesses.
Real Fines That Should Get Your Attention
- EUR 90,000 -- Italian medical centre, patient data accessible to unauthorized staff (2023)
- EUR 5,000 -- Romanian company, continued sending marketing emails after unsubscribe request (2023)
- EUR 20,000 -- Belgian company, no DPO appointed when required, inadequate data processing records (2022)
- EUR 1,200,000 -- Spanish bank, but relevant because the violation was simply insufficient consent mechanisms on their website (2021)
- EUR 8,500 -- German sole trader, used customer data from one business for marketing another business (2023)
The pattern is clear: regulators are targeting businesses of all sizes, and the most common violations are consent failures, inadequate documentation, and ignoring data subject rights.
The Compliance Weekend
Here's what we tell clients: block out a weekend. Not a fun weekend, but a productive one.
Saturday morning (3 hours): Data inventory. Go through every system, every spreadsheet, every inbox. Document what personal data is where.
Saturday afternoon (3 hours): Privacy policy draft. Cookie consent tool setup and configuration. Test that non-essential cookies are actually blocked before consent.
Sunday morning (3 hours): DPA collection. Go through your vendor list, download or accept every DPA. Set up your privacy email address. Write your data subject request procedure.
Sunday afternoon (2 hours): Form audit. Update consent language on every form. Breach response plan. Team reference document.
That's roughly 11 hours. It's not glamorous, and it won't feel urgent -- until someone files a complaint or a regulator comes knocking. The 47 hours our accounting client spent in crisis mode could have been 11 hours of calm, planned preparation.
Ongoing Maintenance
GDPR isn't a one-time project. Schedule quarterly reviews:
- Review and prune data you no longer need
- Check that cookie consent is still functioning after site updates
- Update your data inventory when you add new tools or services
- Fulfil any pending data subject requests
- Update staff training if processes change
Compliance is a habit, not an event. Build it into your operations and it becomes invisible. Ignore it and it becomes a crisis.
We help our hosting and development clients with GDPR compliance as part of every project. If you're unsure where you stand, start with the data inventory. Everything else flows from knowing what data you have and where it lives.