GDPR Compliance Checklist for Small Business Owners (2026)

This article provides general educational information about GDPR requirements. It is not legal advice. Small businesses with specific compliance questions should consult a qualified data protection solicitor or an outsourced Data Protection Officer.


GDPR Still Applies to Your Small Business. Here’s What That Means in 2026.

GDPR does not have a small business exemption. If your business collects, stores, or processes personal data about EU residents — regardless of where your business is located — you are subject to its requirements. A three-person business in Texas with European website visitors is subject to GDPR. A ten-person UK business processing customer data is subject to UK GDPR. A twenty-person Australian business with EU clients is subject to GDPR.

The enforcement landscape in 2026 makes this more urgent, not less. Regulators issued approximately €1.2 billion in GDPR fines in 2025 alone — a 22% year-on-year increase. More than €600 million had already been issued in the first half of 2026. Crucially, enforcement is no longer focused exclusively on Big Tech. Supervisory authorities across Europe issued five and six-figure fines to small and medium-sized businesses for consent failures, inadequate vendor contracts, and — notably — late breach notification.

In April 2025, the UK Information Commissioner’s Office fined DPP Law Ltd £60,000 following a ransomware attack. The fine specifically cited access control failures and, for the first time in ICO enforcement, explicitly named late breach notification as an aggravating factor — DPP Law reported the breach 43 days after becoming aware of it. GDPR requires notification within 72 hours.

Two significant developments in 2026 affect small businesses specifically. First, the EU AI Act’s high-risk AI system provisions became enforceable on 2 August 2026, adding a second penalty layer — up to €35 million or 7% of turnover — for businesses using AI systems that process personal data without required safeguards. Second, the UK Data (Use and Access) Act 2025, commencing February 2026, raised the maximum fine under PECR (the Privacy and Electronic Communications Regulations) from £500,000 to £17.5 million or 4% of global turnover for unlawful outbound marketing.

This checklist covers what a small business actually needs to do to achieve and maintain GDPR compliance in 2026. It is organised by priority — the items most likely to generate regulatory exposure are listed first.


Does GDPR Apply to Your Business?

GDPR applies if your business does any of the following:

  • Collects personal data from people located in the EU or UK (website visitors, customers, subscribers, leads)
  • Stores personal data about EU or UK residents (customer records, employee data, contact lists)
  • Monitors the behaviour of EU residents (analytics tracking, behavioural advertising, profiling)
  • Offers goods or services to people in the EU or UK, even for free

Personal data includes: names, email addresses, phone numbers, IP addresses, cookie identifiers, location data, purchase history, device identifiers, and any other information that can identify a specific individual. A company email address (info@business.com) is generally not personal data. A named individual’s work email (firstname.surname@business.com) is.

UK GDPR vs EU GDPR: Since Brexit, the UK operates under its own UK GDPR — largely mirrored from EU GDPR but administered by the Information Commissioner’s Office (ICO) rather than EU Data Protection Authorities. Businesses operating across both UK and EU need to comply with both frameworks, which are similar but have diverging provisions following the Data (Use and Access) Act 2025.

If GDPR applies to your business, the checklist below applies. If you’re genuinely unsure whether it applies, assume it does and work from there.


The GDPR Compliance Checklist for Small Businesses

1. Complete a Data Audit (Data Mapping)

Before any other compliance activity, understand what personal data your business holds. Document:

  • What personal data you hold (names, emails, phone numbers, payment data, health data, IP addresses)
  • Where it’s stored (CRM, email marketing platform, accounting software, spreadsheets, paper files, cloud storage)
  • Why you hold it (customer orders, newsletter subscriptions, employee payroll, website analytics)
  • Where it came from (collected directly, purchased from a list, obtained from a partner)
  • Who has access (internal staff, third-party processors)
  • How long you keep it

This data map — often called a Record of Processing Activities (ROPA) — is the foundation of all other compliance work. You cannot identify lawful bases, cannot write an accurate privacy notice, and cannot respond correctly to a data subject request without knowing what data you hold.

ROPA requirement: Under Article 30, businesses with fewer than 250 employees are technically exempt from maintaining a full written ROPA if their processing is occasional, doesn’t involve special categories of data, and is unlikely to result in a risk to individuals’ rights. In practice, most small businesses processing customer data, employee data, or any marketing activity do not meet the “occasional” threshold. Maintain a ROPA regardless. Regulators expect it, and it protects you if a complaint or audit arises.

What a basic ROPA contains:

  • Category of personal data
  • Purpose of processing
  • Lawful basis
  • Data retention period
  • Third parties the data is shared with
  • Security measures applied

A spreadsheet is adequate. The ICO provides free ROPA templates for small businesses.


2. Establish a Lawful Basis for Each Processing Activity

Every piece of personal data processing requires a lawful basis under Article 6. There are six options, but only four are practically relevant for most small businesses:

Consent: The individual has freely given, specific, informed, and unambiguous consent for this specific purpose. Consent must be opt-in (a pre-ticked box is not valid consent). You must document when and how consent was obtained, and be able to demonstrate it. Consent can be withdrawn at any time, and withdrawal must be as easy as giving consent.

Contract: Processing is necessary to perform a contract with the individual or to take pre-contractual steps at their request. Processing a customer’s name and delivery address to fulfil an order they placed is lawful under contract performance. This is the most straightforward basis for customer transaction data.

Legitimate interests: You have a legitimate business interest in processing the data, that interest is necessary, and it is not overridden by the individual’s rights. This is the most flexible basis but requires a documented Legitimate Interests Assessment (LIA). Common uses: fraud prevention, network security, customer analytics. Marketing to existing customers about similar products may qualify — marketing to purchased lists does not.

Legal obligation: Processing is necessary to comply with a legal requirement. Employee payroll data, tax records, accounting records. Use this basis for data you’re legally required to keep.

Important distinctions:

Do not use consent as the default basis for everything. If processing is genuinely necessary for a contract, use the contract basis — consent is a weaker basis because it can be withdrawn, and withdrawing consent then obligates you to stop processing and delete data. Use the right basis for each activity.

Special categories of data — health information, racial or ethnic origin, religious beliefs, sexual orientation, biometric data — require both a lawful basis under Article 6 and a separate condition under Article 9. Most small businesses should avoid collecting special category data unless it’s essential to their service.


3. Write and Publish an Accurate Privacy Notice

A privacy notice (also called a privacy policy) is the document that tells individuals what personal data you collect, why you collect it, what you do with it, and what their rights are. It must be:

  • Concise and plain English — not pages of dense legalese
  • Available at the point of data collection — on your website, in your sign-up form, in your contract documents
  • Accurate — if it says you don’t share data with third parties and you use Mailchimp or HubSpot, that statement is wrong and creates compliance exposure

Your privacy notice must include:

  • Your business name and contact details (and your DPO’s contact if you have one)
  • What personal data you collect
  • The lawful basis for each processing activity
  • How long you keep data (or the criteria used to determine retention)
  • Who you share data with (named categories of third parties or specific named processors)
  • Whether data is transferred outside the UK/EU and on what basis
  • Each individual’s rights under GDPR (access, rectification, erasure, restriction, portability, objection)
  • The right to withdraw consent where consent is the lawful basis
  • The right to complain to a supervisory authority (ICO in the UK; the relevant national DPA in the EU)

Cookie consent: If your website uses non-essential cookies (analytics, advertising, third-party embeds), you need cookie consent under PECR (UK) or the ePrivacy framework (EU). A cookie banner where users can accept or decline non-essential cookies is required. Pre-ticked boxes are not valid consent. The EDPB’s 2026 coordinated enforcement action specifically targets transparency compliance — cookie notices and privacy disclosures are in scope.


4. Sign Data Processing Agreements with All Third-Party Processors

A data processor is any third party that processes personal data on your behalf — your CRM provider, your email marketing platform, your cloud storage provider, your payroll bureau, your IT support company, your accountant if they access client data.

Under Article 28, you must have a written Data Processing Agreement (DPA) with every processor. This agreement must include:

  • What data is being processed and for what purpose
  • The processor’s security obligations
  • Restrictions on the processor engaging sub-processors without your consent
  • The processor’s obligation to return or delete data at the end of the relationship
  • Cooperation with audits and data subject requests

In practice: Most large SaaS providers (Google, Microsoft, Mailchimp, HubSpot, Xero, Salesforce) provide standard DPAs in their terms of service or available for download from their privacy/legal pages. Review and accept these. For smaller local suppliers — your IT support company, your outsourced accountant — you may need to request a DPA or issue one yourself.

The ICO has specifically noted that missing DPAs with processors are a common finding in SME audits and are cited as aggravating factors in breach-related enforcement. A UK legal SME (DPP Law Ltd) was fined £60,000 after a 2023 ransomware attack — the fine referenced inadequate security controls and the late notification. Processor relationship management was part of the remediation requirements.


5. Implement the 72-Hour Breach Notification Process

Under Article 33, when you become aware of a personal data breach that is likely to result in risk to individuals’ rights and freedoms, you must notify your supervisory authority (the ICO in the UK; the relevant national DPA in the EU) within 72 hours.

This is the requirement that most frequently catches small businesses out — not because they wouldn’t report, but because they don’t have a process, don’t know who’s responsible, and lose time figuring out what happened before notifying.

The 72 hours starts from when you become aware — not when the breach began. A ransomware attack that encrypts your files overnight means the clock started when your first employee noticed the problem Monday morning, not at the time of the attack. DPP Law Ltd’s 43-day notification timeline — which was explicitly cited as an aggravating factor in its £60,000 ICO fine — illustrates the enforcement risk of treating notification as something to investigate before reporting.

Not every breach requires notification. Low-risk incidents — an email sent to the wrong internal recipient with non-sensitive information — may not require supervisory authority notification, though they should still be documented. Assess the risk to individuals; if the breach could cause real harm (discrimination, financial loss, reputational damage, identity theft), notify within 72 hours.

High-risk breaches require individual notification. If a breach is likely to result in high risk to individuals — exfiltration of payment data, health records, or sensitive personal information — you must also notify the affected individuals directly without undue delay.

Build your breach response process now:

  • Designate who decides whether a breach meets the notification threshold
  • Keep the ICO/DPA notification form bookmarked (ICO: ico.org.uk/report-a-breach)
  • Maintain an internal breach register, even for incidents that don’t meet the notification threshold
  • Test the process annually — most organisations discover they don’t know who to call or what to report only when they need to

6. Know How to Respond to Data Subject Requests

Individuals have the following rights under GDPR, and your business must have a process to respond to them within one month:

Right of access (Subject Access Request / SAR): Any individual can request a copy of all personal data you hold about them. You must respond within one calendar month (extendable to three months for complex requests, with notification). You cannot charge a fee in most cases.

Right to rectification: An individual can request correction of inaccurate data.

Right to erasure (Right to be forgotten): An individual can request deletion of their data where it’s no longer necessary for the original purpose, consent has been withdrawn, or there’s no legitimate interest justifying continued processing. This right is not absolute — legal obligations to retain certain records override it.

Right to restriction: An individual can request that processing is restricted while accuracy is disputed or while a legitimate interests objection is being assessed.

Right to data portability: For data processed by consent or contract, an individual can request their data in a structured, machine-readable format.

Right to object: An individual can object to processing based on legitimate interests, including direct marketing.

Practical process:

Designate a specific email address for data subject requests (e.g., privacy@yourbusiness.com) and include it in your privacy notice. When a request arrives, verify the individual’s identity before releasing data. Document requests and responses in an internal register. For SARs specifically, remember to include all data held — including emails, CRM notes, support tickets, and any other records — not just the obvious customer profile.


7. Review Data Retention and Implement Deletion Schedules

You may not keep personal data indefinitely. Data must be kept only for as long as necessary for the original purpose — and that retention period must be documented in your ROPA and your privacy notice.

Practical retention considerations for common data categories:

  • Customer order data: typically 6–7 years for tax and accounting purposes (legal obligation basis)
  • Marketing consent records: keep for the duration of the consent plus evidence of withdrawal
  • Employee data: retain during employment plus a defined post-employment period (typically 6 years in the UK for potential employment tribunal claims)
  • Website analytics data: IP addresses are personal data; configure analytics tools (Google Analytics 4, etc.) to anonymise or delete data within your defined retention period
  • Job applicant data for unsuccessful candidates: typically 6 months unless you’ve obtained consent to retain longer

Implement automated deletion where possible. Many CRM and email platforms allow you to configure automatic data expiry. For data stored in spreadsheets or shared drives, build a quarterly review process. Data that nobody is actively using and that has passed its retention period should be deleted — keeping it indefinitely is both a compliance failure and an unnecessary risk.


8. Check Your International Data Transfers

If your business transfers personal data from the UK or EU to a country outside those territories — including to US-based cloud providers, US-based software tools, or international offices — that transfer requires a legal mechanism.

EU-US Data Privacy Framework (DPF): The successor to Privacy Shield, the DPF allows EU-to-US data transfers to certified US organisations. As of July 2026, the DPF is legally valid but facing significant uncertainty: a challenge is pending at the Court of Justice of the EU, a separate Schrems III challenge is expected to be heard by late 2026 or early 2027, and a June 2026 US Supreme Court ruling has raised questions about the independence of one of its oversight bodies. Small businesses relying on US-based vendors should ensure Standard Contractual Clauses (SCCs) are signed with those vendors as a fallback, rather than depending solely on the vendor’s DPF certification.

Standard Contractual Clauses (SCCs): The most widely used transfer mechanism. Major US cloud providers (Google, Microsoft, Amazon, Salesforce, Mailchimp) provide SCCs as part of their DPAs. Review and accept them. The updated EU SCCs (2021 version) are the current standard.

UK International Data Transfer Agreements (IDTAs): The UK equivalent of EU SCCs, issued by the ICO. UK businesses transferring data to non-adequate countries should use the IDTA (for data subject to UK GDPR) alongside EU SCCs (for data subject to EU GDPR) when using the same vendor.

Adequacy decisions: The EU has granted adequacy decisions to certain countries (including the UK, for now) that allow transfers without additional mechanisms. Check the EU’s current list of adequate countries, as these decisions can be challenged.


9. Implement Appropriate Technical and Organisational Security Measures

Article 32 requires businesses to implement security measures appropriate to the risk of the data they process. GDPR does not prescribe a specific list of controls — it requires a risk-based approach. For most small businesses, the following controls are appropriate and expected:

Access controls: Employees should only access personal data necessary for their role (principle of least privilege). Use role-based access controls in your CRM, cloud storage, and other systems.

Encryption: Personal data should be encrypted at rest and in transit. Most major cloud platforms encrypt by default. Verify encryption settings for any on-premise or legacy systems. Encrypt laptops and mobile devices that store personal data.

Multi-factor authentication: MFA on all accounts that access personal data. This is one of the most effective controls against the credential theft that precedes most breaches, and regulators increasingly treat its absence as inadequate security. The DPP Law Ltd fine specifically cited inadequate access controls — MFA was part of the remediation.

Patch management: Keep all software updated. Unpatched vulnerabilities are a leading initial access vector for the ransomware attacks that cause most small business data breaches.

Backup and recovery: Maintain tested backups. A ransomware attack that encrypts your data and your backups simultaneously is both a business continuity crisis and a GDPR breach — the personal data has been lost and potentially exfiltrated.

Staff training: Employees must understand GDPR basics, data handling procedures, and how to recognise phishing. Training completion should be documented.

Privacy by design: When deploying new systems or tools that process personal data, assess privacy implications before deployment — not after. This is Article 25’s requirement, and it becomes more significant as AI tools that process personal data proliferate.


10. Assess Whether You Need a Data Protection Officer

Most small businesses do not legally require a DPO. GDPR mandates a DPO only if:

  • You are a public authority
  • Your core activities involve large-scale, systematic monitoring of individuals (e.g., operating a platform that profiles millions of users)
  • Your core activities involve large-scale processing of special categories of data (health data, criminal records)

A typical small business processing customer data, employee records, and marketing contacts does not trigger the DPO mandate.

However, appointing someone — even if they’re not formally a DPO — to own data protection compliance is strongly advisable. This person is the internal point of contact for data subject requests, manages the breach notification process, maintains the ROPA, and ensures vendor DPAs are in place. For businesses where no one has the expertise, outsourced DPO services are available from data protection consultancies typically at a few hundred to a few thousand pounds or euros per year.


11. Address the EU AI Act if You Use AI Tools (Effective 2 August 2026)

The EU AI Act’s high-risk AI system provisions became enforceable on 2 August 2026. For small businesses, the most relevant provisions concern AI tools that process personal data in ways that affect individuals’ rights.

If your business uses AI systems classified as “high-risk” under the Act — which includes AI used in certain HR decisions, credit scoring, biometric identification, or systems that make consequential decisions about individuals — additional obligations apply: conformity assessments, technical documentation, human oversight mechanisms, and transparency requirements.

For most small businesses using AI tools for marketing automation, customer service chatbots, content generation, or productivity: these are generally not high-risk categories under the Act. However, the Act’s transparency requirements and prohibition on certain AI practices (manipulation, social scoring, certain biometric uses) apply broadly.

Practically: if you’re using AI tools that process personal data, ensure your privacy notice accurately describes this. Verify that your AI tool vendors’ DPAs cover AI-specific processing. If you’re unsure whether a specific AI system falls within the Act’s scope, the EU’s official AI Act compliance checker (available from the European AI Office) provides guidance.


12. Review and Maintain — GDPR Is Not a One-Time Exercise

GDPR compliance is not a project with an end date. It’s an ongoing operational programme. The following should occur on a defined schedule:

Annually:

  • Review and update the ROPA for any new processing activities
  • Audit vendor DPAs for any new tools adopted during the year
  • Update the privacy notice if any processing activities have changed
  • Deliver staff training (document completion)
  • Review retention schedules and action any overdue data deletion

When you adopt a new tool or service that processes personal data:

  • Assess the privacy implications before adoption
  • Obtain a signed DPA before connecting the tool to live personal data
  • Update the ROPA
  • Update the privacy notice if the processing activity is new

After any security incident:

  • Document the incident in the internal breach register
  • Assess the risk to individuals
  • Notify within 72 hours if the threshold is met
  • Review what controls failed and update security measures

The 2026 Enforcement Priorities Worth Knowing About

The European Data Protection Board (EDPB) announced a coordinated enforcement action for 2026 specifically focused on transparency compliance — privacy notices, consent documentation, data subject communication clarity, and disclosure accuracy. Historical coordinated enforcement actions have resulted in a spike in related fines within 6–12 months of announcement. Small businesses should prioritise reviewing the accuracy and clarity of their privacy notices and cookie consent mechanisms in the near term.

The three fastest-growing fine triggers going into the second half of 2026 are:

AI processing: Businesses using AI tools that process personal data without accurate privacy disclosures, without appropriate DPAs with AI vendors, or without assessing processing against the EU AI Act framework.

Consent UX: Cookie banners and consent flows that make it harder to decline than to accept, or that use dark patterns to push users toward consent. The CNIL (France) fined several organisations for consent UX failures in 2025, and the pattern of enforcement is spreading.

Vendor management: Missing or incomplete DPAs with processors. This is consistently cited in SME enforcement actions and is straightforward to remedy.


Practical Resources

ICO (UK): ico.org.uk — guides for small businesses, ROPA templates, privacy notice generator, DSAR response templates, and the breach reporting portal.

EU GDPR resources: gdpr.eu — plain-language articles on specific GDPR requirements. The official EUR-Lex text of the Regulation is also publicly available.

EU AI Act: artificialintelligenceact.eu — the text of the Act and official EU guidance. The European AI Office’s compliance tools are being developed through 2026.

Supervisory authority guidance: Each EU member state’s DPA publishes guidance. The ICO’s SME-specific guidance is among the most accessible in English. The Irish DPC (Data Protection Commission) publishes extensive guidance relevant to businesses operating in Ireland or under the One Stop Shop mechanism.

Outsourced DPO services: Available from multiple data protection consultancies across the UK and EU. Typically £500–£3,000/year for a small business retainer covering core DPO obligations.


GDPR Compliance Checklist Summary

PriorityRequirementDone?
1Complete data audit and draft ROPA
2Document lawful basis for each processing activity
3Publish accurate privacy notice (including cookies)
4Sign DPAs with all third-party processors
5Implement 72-hour breach notification process
6Document data subject rights response process
7Define and implement retention schedules
8Review international data transfers and mechanisms
9Implement appropriate technical security measures
10Assess DPO requirement; appoint lead if needed
11Address EU AI Act obligations for AI tools used
12Schedule annual compliance review

Frequently Asked Questions

Does GDPR apply to my US-based small business?

Yes, if your business collects or processes personal data from people in the EU or UK. The relevant test is not where your business is located — it’s where the data subjects are. If your website is accessible to EU visitors and you collect their email addresses, you’re subject to GDPR. If you provide services to UK customers and hold their contact data, you’re subject to UK GDPR. The fact that you have no physical presence in Europe does not exempt you from the regulation. In practice, enforcement against small non-EU businesses is harder for European regulators to pursue, but the obligation exists and many US businesses with EU customers take compliance seriously for commercial reasons as well as legal ones.

What’s the difference between a data controller and a data processor?

A data controller is any person or organisation that determines the purpose and means of processing personal data. If you decide what customer data to collect, why to collect it, and how to use it, you’re a controller. A data processor is any person or organisation that processes personal data on behalf of a controller — your CRM provider, email platform, payroll bureau, or cloud storage service processes data on your instructions. Both have GDPR obligations. As a controller, you’re responsible for ensuring your processors have appropriate safeguards in place — which is why DPAs with processors are mandatory. Most small businesses are controllers of their customer and employee data, and processors for any clients whose data they handle as part of their service.

How long do I have to respond to a data subject access request?

One calendar month from receipt of the request. For complex or numerous requests, you may extend to three months — but you must notify the individual of the extension and the reason within the first month. You cannot charge a fee in most cases, and you cannot demand information beyond what’s needed to identify the requester and locate their data. If the request is manifestly unfounded or excessive (a pattern of repeat requests intended to cause disruption), you may charge a reasonable administrative fee or refuse — but this exception is narrow and requires documented justification. Failing to respond within one month is a GDPR violation in itself, regardless of the content of the response.

What’s the fine for failing to notify a data breach within 72 hours?

The failure to notify within 72 hours is a Tier 1 violation under Article 83(4) — subject to fines of up to €10 million or 2% of global annual turnover, whichever is higher. In practice, late notification is typically an aggravating factor in fines that are primarily triggered by the underlying breach and its root causes, rather than the sole basis for a fine. The DPP Law Ltd case — £60,000 for a ransomware breach in a legal SME — explicitly named 43-day notification as an aggravating factor. Regulators are making clear that the 72-hour timeline is enforced, not aspirational.

Does GDPR require me to appoint a Data Protection Officer?

For most small businesses, no. GDPR mandates a DPO only for public authorities, organisations whose core activities involve large-scale systematic monitoring, and organisations whose core activities involve large-scale processing of special categories of data. A typical small business processing customer and employee data does not meet these thresholds. However, assigning someone — even without the DPO title — to own data protection compliance is strongly advisable. That person becomes the internal point of contact for data subject requests, manages breach notification, and maintains compliance documentation. For small businesses without internal expertise, outsourced DPO services are available at accessible price points and provide professional accountability without a full-time hire.


This article provides general educational information and does not constitute legal advice. GDPR requirements depend on specific business circumstances and the applicable national law of EU member states. Small businesses with specific compliance questions should seek advice from a qualified data protection solicitor or a registered Data Protection Officer. For authoritative guidance, see the ICO’s guidance for small organisations and the EDPB’s official guidelines.

Related reading on SmallBiz Defense:

1 thought on “GDPR Compliance Checklist for Small Business Owners (2026)”

Leave a Comment