Start with applicability, not a cookie banner
A small business can collect personal information through customer orders, employee records, support messages and analytics. That does not mean every business everywhere is subject to the EU GDPR. Conversely, having a U.S. address does not automatically remove your activities from its scope.
The territorial analysis has separate establishment and targeting tests. EDPB guidance discusses processing connected with an establishment in the EU and, for organizations outside the EU, offering goods or services to people in the Union or monitoring their behavior there.1 A website merely being accessible from Europe does not settle that assessment. Record what your business actually does and have uncertain cases evaluated.
This article concerns the EU GDPR. The UK has its own GDPR regime and other jurisdictions have different privacy requirements. Do not reuse a single applicability conclusion across every law or assume that contractual GDPR language establishes your statutory role.
Original applicability decision record
Before assigning checklist tasks, fill in this short record for each relevant activity.
| Question | Facts to collect | Decision record |
|---|---|---|
| Establishment | EU offices, staff arrangements and connection to the activity | Applicable, not established, or requires review—with reasons |
| Offering goods/services | Actual targeting, delivery, currencies, languages and campaigns | Identify the people and activity being targeted |
| Monitoring | Tracking/profiling of people in the Union and its purpose | Explain the monitoring behavior, not just the tool name |
| Role | Who decides purposes and means; who acts on instructions | Controller, processor or relationship needing review |
| Data | Customer, worker, visitor and other personal data | Categories and affected people |
| Review | Reviewer, source, date and changed-fact triggers | Named owner and unresolved questions |
This is a screening record, not an automated legal test. Mark uncertainty explicitly. A manager should not close an item as “not applicable” merely because the company has fewer than 250 employees.
Map the processing that really happens
Create one record per business purpose, not one per application. Your customer relationship tool may support sales, support and marketing, each with different purposes and retention. Conversely, one purpose may span several systems and suppliers.
Useful fields include the purpose, people affected, data categories, source, recipients, system owners, retention, access, and international-transfer arrangements. Add the basis for processing and any additional conditions needed for sensitive categories, with appropriate review.
EDPB's small-business guide explains processing records and data protection by design and default.2 Its guidance also makes clear that limited recordkeeping relief is not a blanket exemption for small organizations. Do not assume recurring payroll, customer management or sensitive processing can disappear from the inventory.
Interview the people doing the work. A list copied from a procurement register may miss spreadsheet exports, support attachments and an employee's unapproved AI tool. Describe the activity before deciding how to control it.
Turn the inventory into a prioritized checklist
Use the following original checklist to organize implementation work. It does not exhaust every GDPR requirement.
- Confirm scope and roles. Retain the applicability record and resolve uncertainties with qualified advice.
- Document purpose and legal grounds. Connect each activity to its actual purpose. Avoid treating consent as the only possible basis or selecting a basis after processing has begun.
- Check transparency. Compare what people are told with actual collection, recipients and use. Update notices through the approved review process.
- Minimize collection. Remove fields and exports without a justified purpose; avoid making optional information mandatory.
- Restrict access. Identify who needs the information and review broad sharing, former users and supplier access.
- Set workable retention. Define triggers and deletion responsibilities, including archives and exports; validate legal retention needs separately.
- Review suppliers. Establish roles, appropriate terms, instructions, security responsibilities and subprocessor arrangements.
- Assess transfers. Identify destinations and recipients outside the relevant area, and review the applicable mechanism rather than assuming a vendor's brand is sufficient.
- Prepare rights handling. Provide a monitored route, identity-verification process, search plan and escalation for complex requests.
- Prepare breach response. Establish assessment, evidence preservation and notification decision ownership; verify deadlines for the facts and law involved.
- Assess high-risk processing. Decide whether a data protection impact assessment is required before proceeding.
- Review accountability roles. Determine whether a representative or data protection officer is required for your circumstances rather than assigning titles casually.
Give each item an owner, evidence requirement and unresolved question. Completing a policy document is different from confirming the policy operates.
Worked example: a U.S. training company
Fictional scenario: A U.S. company runs online training and begins marketing subscriptions specifically to customers in several EU countries. It also uses a third-party support platform and wants to summarize support tickets with AI.
The company records its targeting activity and seeks an applicability assessment rather than relying on its U.S. incorporation. It separates training-account administration, payment processing, marketing and support into different processing records. The support record includes ticket attachments and staff exports, not only the platform's main database.
For the proposed AI use, the owner first tests whether public synthetic tickets can meet the drafting need. Real tickets may contain names, health information or complaints that require additional care. The team maps the AI supplier, retention, access and transfer questions before approving any real-data use.
Its evidence list includes reviewed notices, supplier terms, access-review records and deletion-test results. “Vendor says GDPR compliant” is preserved as a supplier claim, not substituted for the company's own analysis. The owner also records questions about EU representation and rights-response coordination for legal review.
Know when a DPIA is a separate project
A data protection impact assessment evaluates likely high risks to individuals, not merely the business's financial exposure. EDPB guidance identifies examples including large-scale sensitive-data processing, systematic and extensive automated evaluation producing legal or similarly significant effects, and large-scale systematic monitoring of publicly accessible areas.2 Screen proposed activities before launch and check relevant supervisory-authority guidance.
Do not reduce this to “all AI always needs a DPIA” or “small businesses never need one.” The actual activity and risks matter. Where required, the assessment needs analysis and safeguards, not just a completed questionnaire. Unresolved high residual risk can require prior consultation with the relevant authority.2
Make evidence useful and safe
Keep a restricted index pointing to current records. Use redacted examples when demonstrating rights-response or deletion procedures; avoid adding unnecessary personal information to the compliance folder.
For each control, record what happened, when, to which population and who reviewed it. A screenshot of one deleted test contact demonstrates that action, not successful deletion of every copy across all systems. Document limitations and follow-up work.
Questions small businesses ask
Is a privacy policy enough?
No. A notice communicates information. It does not replace lawful processing, appropriate safeguards, supplier management or rights procedures.
Can we use one checklist for the EU and UK?
You can share organizational fields, but confirm each jurisdiction's requirements and scope separately. Guidance and legislation can change independently.
What should we prioritize this week?
Resolve applicability, map your most important recurring processing, and identify one high-consequence gap with an owner. The readiness assessment provides a general self-reported starting point; it does not establish GDPR compliance or replace advice on your processing.
Sources and references
-
European Data Protection Board. Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) (2019-11-12). Guidance for establishment and targeting tests; scope needs fact-specific assessment. ↩
-
European Data Protection Board. Small-business guide: Be compliant. Practical EU guidance on design/default, processing records and DPIA triggers. ↩ ↩2 ↩3

