Skip to main content
All articles

Privacy Management

GDPR Compliance Checklist for Small Businesses: Start with Applicability

By RiskSensai6 min read
Editorial archive date
First published
Facts checked

The archive date places this article in the editorial collection. It is not an original publication date. Guidance reflects the fact-check date above.

GDPR Compliance Checklist for Small Businesses: Start with Applicability: original RiskSensai editorial cover

A small business can collect personal information through customer orders, employee records, support messages and analytics. That does not mean every business everywhere is subject to the EU GDPR. Conversely, having a U.S. address does not automatically remove your activities from its scope.

The territorial analysis has separate establishment and targeting tests. EDPB guidance discusses processing connected with an establishment in the EU and, for organizations outside the EU, offering goods or services to people in the Union or monitoring their behavior there.1 A website merely being accessible from Europe does not settle that assessment. Record what your business actually does and have uncertain cases evaluated.

This article concerns the EU GDPR. The UK has its own GDPR regime and other jurisdictions have different privacy requirements. Do not reuse a single applicability conclusion across every law or assume that contractual GDPR language establishes your statutory role.

Original applicability decision record

Before assigning checklist tasks, fill in this short record for each relevant activity.

QuestionFacts to collectDecision record
EstablishmentEU offices, staff arrangements and connection to the activityApplicable, not established, or requires review—with reasons
Offering goods/servicesActual targeting, delivery, currencies, languages and campaignsIdentify the people and activity being targeted
MonitoringTracking/profiling of people in the Union and its purposeExplain the monitoring behavior, not just the tool name
RoleWho decides purposes and means; who acts on instructionsController, processor or relationship needing review
DataCustomer, worker, visitor and other personal dataCategories and affected people
ReviewReviewer, source, date and changed-fact triggersNamed owner and unresolved questions

This is a screening record, not an automated legal test. Mark uncertainty explicitly. A manager should not close an item as “not applicable” merely because the company has fewer than 250 employees.

Map the processing that really happens

Create one record per business purpose, not one per application. Your customer relationship tool may support sales, support and marketing, each with different purposes and retention. Conversely, one purpose may span several systems and suppliers.

Useful fields include the purpose, people affected, data categories, source, recipients, system owners, retention, access, and international-transfer arrangements. Add the basis for processing and any additional conditions needed for sensitive categories, with appropriate review.

EDPB's small-business guide explains processing records and data protection by design and default.2 Its guidance also makes clear that limited recordkeeping relief is not a blanket exemption for small organizations. Do not assume recurring payroll, customer management or sensitive processing can disappear from the inventory.

Interview the people doing the work. A list copied from a procurement register may miss spreadsheet exports, support attachments and an employee's unapproved AI tool. Describe the activity before deciding how to control it.

Turn the inventory into a prioritized checklist

Use the following original checklist to organize implementation work. It does not exhaust every GDPR requirement.

  1. Confirm scope and roles. Retain the applicability record and resolve uncertainties with qualified advice.
  2. Document purpose and legal grounds. Connect each activity to its actual purpose. Avoid treating consent as the only possible basis or selecting a basis after processing has begun.
  3. Check transparency. Compare what people are told with actual collection, recipients and use. Update notices through the approved review process.
  4. Minimize collection. Remove fields and exports without a justified purpose; avoid making optional information mandatory.
  5. Restrict access. Identify who needs the information and review broad sharing, former users and supplier access.
  6. Set workable retention. Define triggers and deletion responsibilities, including archives and exports; validate legal retention needs separately.
  7. Review suppliers. Establish roles, appropriate terms, instructions, security responsibilities and subprocessor arrangements.
  8. Assess transfers. Identify destinations and recipients outside the relevant area, and review the applicable mechanism rather than assuming a vendor's brand is sufficient.
  9. Prepare rights handling. Provide a monitored route, identity-verification process, search plan and escalation for complex requests.
  10. Prepare breach response. Establish assessment, evidence preservation and notification decision ownership; verify deadlines for the facts and law involved.
  11. Assess high-risk processing. Decide whether a data protection impact assessment is required before proceeding.
  12. Review accountability roles. Determine whether a representative or data protection officer is required for your circumstances rather than assigning titles casually.

Give each item an owner, evidence requirement and unresolved question. Completing a policy document is different from confirming the policy operates.

Worked example: a U.S. training company

Fictional scenario: A U.S. company runs online training and begins marketing subscriptions specifically to customers in several EU countries. It also uses a third-party support platform and wants to summarize support tickets with AI.

The company records its targeting activity and seeks an applicability assessment rather than relying on its U.S. incorporation. It separates training-account administration, payment processing, marketing and support into different processing records. The support record includes ticket attachments and staff exports, not only the platform's main database.

For the proposed AI use, the owner first tests whether public synthetic tickets can meet the drafting need. Real tickets may contain names, health information or complaints that require additional care. The team maps the AI supplier, retention, access and transfer questions before approving any real-data use.

Its evidence list includes reviewed notices, supplier terms, access-review records and deletion-test results. “Vendor says GDPR compliant” is preserved as a supplier claim, not substituted for the company's own analysis. The owner also records questions about EU representation and rights-response coordination for legal review.

Know when a DPIA is a separate project

A data protection impact assessment evaluates likely high risks to individuals, not merely the business's financial exposure. EDPB guidance identifies examples including large-scale sensitive-data processing, systematic and extensive automated evaluation producing legal or similarly significant effects, and large-scale systematic monitoring of publicly accessible areas.2 Screen proposed activities before launch and check relevant supervisory-authority guidance.

Do not reduce this to “all AI always needs a DPIA” or “small businesses never need one.” The actual activity and risks matter. Where required, the assessment needs analysis and safeguards, not just a completed questionnaire. Unresolved high residual risk can require prior consultation with the relevant authority.2

Make evidence useful and safe

Keep a restricted index pointing to current records. Use redacted examples when demonstrating rights-response or deletion procedures; avoid adding unnecessary personal information to the compliance folder.

For each control, record what happened, when, to which population and who reviewed it. A screenshot of one deleted test contact demonstrates that action, not successful deletion of every copy across all systems. Document limitations and follow-up work.

Questions small businesses ask

Is a privacy policy enough?

No. A notice communicates information. It does not replace lawful processing, appropriate safeguards, supplier management or rights procedures.

Can we use one checklist for the EU and UK?

You can share organizational fields, but confirm each jurisdiction's requirements and scope separately. Guidance and legislation can change independently.

What should we prioritize this week?

Resolve applicability, map your most important recurring processing, and identify one high-consequence gap with an owner. The readiness assessment provides a general self-reported starting point; it does not establish GDPR compliance or replace advice on your processing.

Sources and references

  1. European Data Protection Board. Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) (2019-11-12). Guidance for establishment and targeting tests; scope needs fact-specific assessment. ↩

  2. European Data Protection Board. Small-business guide: Be compliant. Practical EU guidance on design/default, processing records and DPIA triggers. ↩ ↩2 ↩3

General educational information, not legal advice, a professional audit opinion, certification, or a guarantee. Applicability and conclusions depend on your organization and should be assessed by an appropriately qualified professional.

Prepared with AI assistance and automated editorial checks. This does not indicate independent professional review or verification of your organization.

  • GDPR
  • Data Privacy
  • Small Business
Connecting to your conversation workspace…