EU Privacy Law EU/EEA

GDPR for SMEs: Practical Compliance Without a Dedicated Privacy Team

What GDPR actually requires from small and mid-sized businesses, which obligations scale down, which do not, and a lean sequence for getting compliant.

Regulation

Regulation (EU) 2016/679 (GDPR)

Max Penalty

EUR 20 million or 4% of global annual turnover, whichever is higher

Enforcing Authority

National supervisory authorities, coordinated by the EDPB

Official Source

eur-lex.europa.eu

Executive Summary

  • GDPR has no small-business exemption; the same principles, lawful bases, and data subject rights apply to a five-person shop and a multinational.
  • What scales down is the paperwork: most SMEs need no DPO, benefit partially from the Article 30(5) records exemption, and rarely trigger mandatory DPIAs.
  • SME fines are real but proportionate: European authorities issue hundreds of fines yearly in the thousands to tens of thousands of euros, most starting from a single complaint.
  • The highest-risk SME surface is the website: pre-consent trackers, missing privacy notices, and marketing without consent generate the complaints.
  • A lean program is achievable in weeks: inventory, notice, consent, vendor contracts, and a breach plan.

GDPR applies to organizations, not to organizations above a certain size. A five-person web shop that processes EU customer data carries the same core obligations as a bank: lawful basis, transparency, data subject rights, security, and breach notification. What differs is proportionality: the regulation and its enforcers scale expectations to the risk and scale of the processing, and several of the heaviest requirements have thresholds an SME never reaches.

RegulationRegulation (EU) 2016/679 (GDPR)
Max penaltyEUR 20M or 4% of global annual turnover
Enforcing authorityNational supervisory authorities, coordinated by the EDPB
Official textEUR-Lex CELEX 32016R0679

What scales down, and what does not

Three obligations have built-in thresholds. The DPO is mandatory only for large-scale monitoring or special category processing (Article 37), which excludes almost all SMEs outside ad tech and health. DPIAs attach to high-risk processing (Article 35), not routine operations. And Article 30(5) trims record-keeping for sub-250-employee organizations, though only for genuinely occasional processing.

Nothing else scales down. Every access request gets answered within a month. Every breach gets assessed against the 72-hour rule. Every marketing email needs a basis. Every vendor that touches personal data needs an Article 28 contract. The good news: at SME scale these are procedures, not departments.

Where SMEs actually get fined

Reading enforcement decisions across Europe shows a consistent SME pattern. Complaints, not audits, start the cases, and they cluster around: video surveillance capturing more than the business premises, marketing to people who unsubscribed or never consented, ignored or late data subject requests, and websites whose trackers fire before consent. The amounts are proportionate, typically four to five figures, but the process cost of an investigation dwarfs the fine. Prevention is dramatically cheaper.

A lean compliance sequence

  1. Scan your website. It is your most exposed surface and the source of most complaints. A free scan shows your trackers, cookie behavior, and policy gaps in minutes.
  2. Inventory your data in an afternoon. List systems, data types, purposes, and vendors in a spreadsheet. This becomes your Article 30 record.
  3. Publish a real privacy notice. Cover the Articles 13/14 items in plain language. Delete the template boilerplate that describes processing you do not do.
  4. Fix consent. Marketing lists need provable opt-ins; the website needs a banner where refusing is as easy as accepting.
  5. Collect your DPAs. Most SaaS vendors have a signable DPA online; an hour of work covers your stack.
  6. Write the breach page. One page: who decides, who notifies the authority, and the 72-hour clock. Our breach notification playbook has the details.

Revisit annually and when you add tools. For the complete requirement set, the ultimate GDPR guide covers the full roadmap.

Frequently Asked Questions

Does GDPR apply to a business with fewer than 250 employees?

Yes, fully. The 250-employee line only affects the Article 30 record-keeping exemption, and even that survives only for occasional, low-risk processing. All other obligations apply regardless of size.

Does a small business need a Data Protection Officer?

Usually not. Article 37 requires a DPO only for public bodies, large-scale systematic monitoring, or large-scale special category processing. A typical SME does none of these, though some national laws, notably Germany's, set stricter thresholds.

What does GDPR compliance cost a small business?

The main costs are time: a data inventory, a privacy notice, a consent banner, and processor agreements with your vendors. Most SaaS vendors provide DPAs for free. External help is worth buying for one-off items like the initial notice rather than as a retainer.

Can a small business be fined under GDPR?

Yes. Article 83 fines apply to turnover of any size, and authorities fine SMEs regularly, typically in the four-to-five-figure range for issues like CCTV overreach, marketing without consent, or ignoring access requests. Fines scale with turnover, so they are proportionate but not hypothetical.

Where should a small business start with GDPR?

Fix what is publicly visible first: your website's cookie behavior and privacy notice, because complaints start there. Then inventory your data, sign DPAs with vendors, and write a one-page breach response plan.

Regulatory Crosswalk

UK GDPRePrivacy Directive

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.