Key takeaways
- GDPR applies regardless of company size if you process the data of individuals in the EU.
- A five-person startup has the same core obligations as a large company.
- Some advanced measures can wait, but the basics cannot.
- Engage focuses small businesses on what actually matters.
Does GDPR apply to small businesses?
Yes, if you process personal data of individuals in the EU. GDPR applies regardless of your company size or where you’re based. A 5-person startup with EU customers has the same core obligations as a Fortune 500 company.
The good news: GDPR is risk-based. What you need to do scales with what data you process, how sensitive it is, and how many people it affects. A small B2B SaaS company processing business contact data has very different obligations than a HealthTech company processing patient records.
What small businesses actually need
The basics (every small business):
- Privacy policy that describes your actual data practices (not a template copied from a competitor).
- Cookie consent mechanism for EU visitors (opt-in, not implied consent).
- Understanding of what personal data you collect, where it goes, and your legal basis for processing it.
- Vendor DPAs with your key processors (hosting, analytics, payments, email) where applicable.
Before your first enterprise customer or funding round:
- Records of Processing Activity (RoPA).
- Data subject request process (access, deletion, correction).
- Breach response plan.
- DPA template ready to send to customers.
- DPO appointment if legally required or commercially expected.
As you grow:
- DPIAs for new products, features, or high-risk processing.
- Vendor risk management program.
- Employee privacy training.
- AI governance if applicable.
- Multi-jurisdictional compliance as you enter new markets.
What small businesses can usually skip (for now)
You probably don’t need a DPO if you’re a small B2B company processing basic business contact data. You probably don’t need DPIAs if you’re not doing high-risk processing. You probably don’t need multi-jurisdictional compliance documentation if you only operate in one market.
The key word is “for now.” These requirements often kick in when you sign your first enterprise customer, raise funding, or start processing more sensitive data.
Common mistakes small businesses make
Copying a competitor’s privacy policy. It doesn’t describe your data practices, which is exactly what GDPR requires.
Assuming GDPR doesn’t apply because you’re based outside the EU. If you serve individuals in the EU, it applies.
Ignoring GDPR because “we’re too small to be fined.” Enforcement doesn’t only target large companies. And more importantly, enterprise customers won’t work with you without basic compliance.
Buying Vanta or Drata and thinking privacy is handled. Those are security certification tools, not DPO services. They help with SOC 2 and ISO 27001, not GDPR compliance.
Appointing the CTO as DPO. This often creates a conflict of interest risk under GDPR because the CTO makes decisions about data processing that the DPO is supposed to independently oversee.
Overbuilding compliance for your stage. You don’t need what a 500-person company needs. Start with what matters for your current size and data activities, and scale from there.
How we help small businesses
Most small businesses start with our Privacy Advisory tier (From €600 per month) or a project-based GDPR audit. We build what you actually need without overbuilding, and we scale with you as your compliance requirements grow.
For small businesses that need a named DPO, our DPO Foundation tier starts From €1,000 per month and includes full DPO appointment, privacy framework build-out, vendor management, enterprise deal support, and ongoing compliance.
We’ve worked with companies from 5 employees to 10,000+. Small businesses often get the most value from outsourced support because they get senior expertise at a fraction of the cost of a full-time hire.