GDPR for Small Businesses: A Sensible Minimum Without Panic

Among small entrepreneurs the GDPR has two camps: those who are convinced it does not apply to them, and those who, out of fear, do not even send a newsletter. The truth is in between: the rules apply to a one-person s.p. too, but the required minimum for a typical small service activity is entirely manageable. Let us go through it step by step – for information only, this is not legal advice.

A laptop with a GDPR checklist – personal data protection in practice

Does the GDPR apply to me?

If you store clients’ e-mail addresses, issue invoices to individuals, keep contact lists or have a contact form on your site – yes, you process personal data and the rules apply to you. Personal data is anything relating to an identifiable individual: name, e-mail, phone, IP address. Company data (info@company.si, a d.o.o.’s tax number) is not personal data, while the data of sole proprietors and contact persons generally is.

First step: make an inventory of what you actually have

On a single sheet of paper write down: which data you collect (clients, potential clients, newsletter recipients), for what purpose, where it is stored and who has access. This inventory is the core of the record of processing activities – a document the GDPR requires in certain cases, and which in any case gives you an overview. For a typical micro business this is one table, not a binder.

An inventory of personal data processing on paper – record of processing activities

Legal bases: why you may hold the data at all

  • Contract: you process clients’ data because it is necessary to carry out the job – for this you do not need separate consent.
  • Legal obligation: accounting records and invoices are kept because the regulations require it.
  • Legitimate interest: e.g. reasonable communication with existing clients – it requires careful consideration and the possibility to object.
  • Consent: for newsletters to non-clients and similar purposes; it must be freely given, specific and revocable.

Newsletters: the most common practical question

To send newsletters to people who are not your clients, you need their consent – a pre-ticked box does not count, and good practice is a confirmation e-mail (double opt-in). In every message enable easy unsubscription and respect it without exception. Purchased lists of e-mail addresses are, under this framework, a bad idea in every respect: legally, reputationally and commercially.

A confirmation e-mail for a newsletter – consent via double opt-in

Processors: your tools process on your behalf

Your e-mail provider, newsletter tool, accounting service, website hosting – all of these process personal data on your behalf and are your processors. With established providers, a data processing agreement (DPA) is usually already part of the general terms; your task is to choose serious providers and to know where the data is.

Website: a notice and cookies

Your site should have an understandable privacy policy (who you are, which data you collect, why, for how long, individuals’ rights and a contact) and properly arranged consent for cookies that are not essential for operation – analytics and advertising cookies may only be loaded after consent. A simple site without tracking is a completely legitimate (and increasingly popular) choice.

A cookie consent banner on a website before loading analytics

If something goes wrong

In the event of a security breach (loss, intrusion, a wrong recipient), first limit the damage and document the event; breaches that pose a risk to individuals must be reported to the Information Commissioner within 72 hours, and in the case of a high risk the affected people must also be notified. The best prevention is boring basic measures: strong passwords and 2FA, updated software, access only for those who need it, and data you no longer need – deleted.

Two-factor authentication (2FA) as a basic security measure for data

Sort it out in one afternoon

An inventory of processing, a privacy policy, properly arranged newsletter consents and a review of access rights – for a typical micro business that is one focused afternoon. Members of makerSP_CE like to carry out such “administrative sprints” in a quiet corner of the space, where focus is easier than at home – and where at the next desk there is often someone who has already ticked off the same list. Coffee is already included in the membership.

Frequently asked questions

As an s.p. without employees, do I need a Data Protection Officer (DPO)?

A typical small entrepreneur does not – the obligation applies above all to large-scale or systematic processing and special categories of data. But in any case you are the contact point for individuals’ questions.

How long may I keep data?

As long as the purpose or a legal obligation lasts: accounting documentation for the prescribed retention periods, consent-based databases until revocation, and applications and inquiries for a reasonably limited time. The key is that you set the deadlines yourself and respect them.

Where do I get official guidance?

From the Information Commissioner of the Republic of Slovenia (ip-rs.si), which publishes guidelines, templates and answers specifically for small businesses. For more complex processing, it is worth consulting a data-protection lawyer.

Conclusion

For a small entrepreneur the GDPR is not a monster but hygiene: knowing which data you have and why, having a basis (a contract or consent), an understandable privacy policy and basic security. Sort out the minimum in one afternoon – and then just maintain it with every new tool or form.

Reserve your spot at makerSP_CE

Coworking makerSP_CE, Pivovarniška ulica 6, Ljubljana (next to Tivoli Park). Fixed price, no notice period, 24/7 access and free parking.

Web: makerspace.si | E-mail: rezervacije@makerspace.si | Phone: +386 30 393 405

Book your workspace