Apps & SaaS

Personal Data Protection: What Your Business Must Comply With

If you keep a customer list with names and phone numbers, you already handle personal data — and the data-protection laws that reached almost every country apply to your business too, not just to corporations. The good news: complying with the essentials doesn't require a legal department — it requires understanding five principles and assembling a minimum kit.

October 6, 20256 min read
In this article
  1. What counts as personal data (more than you think)
  2. The five principles all the laws share
  3. Where your business touches data (the map)
  4. The most-broken rule: consent is not assumed
  5. The minimum compliance kit
  6. The side nobody mentions: compliance sells
  7. Frequently asked questions

If you keep a customer list with names and phone numbers, you already handle personal data. If you send WhatsApp promotions, have a form on your website or store purchase histories, you handle quite a lot of it. And the data-protection laws that reached almost every country over the last decade — with Europe's GDPR as the model — apply to your business too, not just to corporations: fines scale with severity, not only with size.

The good news against the scare: complying with the essentials doesn't require a legal department — it requires understanding the five principles all these laws share and assembling a minimum kit you can build in weeks. This guide gives you both, plus the map of the points where your business touches data without noticing.

What counts as personal data (more than you think)

Personal data is any information that identifies or can identify a person: name, phone, email, address, ID number, photo, a purchase history tied to someone, even the IP address under many legal frameworks. And there's a second category with a higher bar: sensitive data — health, finances, beliefs, children's data — which demands reinforced protection and, generally, explicit consent. The mental rule: if a specific person would be affected were that data leaked, it's personal; if it would also embarrass them or cause serious trouble, it's sensitive.

The five principles all the laws share

  • Legal basis: you need a valid reason to hold each piece of data — the person's consent, a contract that requires it, or a legal obligation; "I got it and I use it" is not a basis.
  • Purpose: data is used for what you said when asking for it — the phone number given to coordinate a delivery is not automatically a marketing channel.
  • Minimisation: ask only for what you need; every extra form field is extra liability with no benefit.
  • The subject's rights: people can ask to see their data, correct it and — with nuances — have it deleted; your business must be able to respond.
  • Security: protecting what you store isn't optional — it's part of the law, and the practices are in the data security guide.

Where your business touches data (the map)

The typical personal-data touchpoints and what to mind at each.
TouchpointData you captureWhat to mind
Web formsName, email, phone, enquiryA linked privacy notice and minimal fields — detail in the forms guide
Sales and invoicingTax ID, address, historyClear legal basis (the contract/invoice provides it) — but for that purpose only
Marketing and newslettersEmail, phone, behaviourRecorded consent and easy unsubscribe in every send — the highest-infringement zone
Vendors and toolsYour customer data processed by third parties (CRM, email, cloud)A contract or terms covering the processing — you answer for what they do

The minimum compliance kit

  1. Take the inventory: what data you hold, whose, where it lives and what for — an afternoon's work that underpins everything else.
  2. Publish a plain-language privacy notice: what you capture, why, who you share it with and how to exercise rights — linked from every form and visible on the site.
  3. Record marketing consent: who accepted, when and how — and put a one-click unsubscribe in every send.
  4. Define the rights process: who responds if someone asks to see or delete their data, and within how many days — don't let the first real request catch you improvising.
  5. Cover your vendors: verify that the tools where your data lives (CRM, email, cloud) have data-processing terms — and if you commission your own software, put these duties in the project specification.

The side nobody mentions: compliance sells

Data protection is usually told as a burden, but it has a commercial face: the customer who sees a short form with a clear notice, receives only what they agreed to receive and can unsubscribe in one click trusts more — and buys more — than the one who feels watched and bombarded. Minimisation also makes you cheaper to run: less data is less risk, less storage and less breach surface. And in markets where almost nobody complies well, the business that does holds a seriousness argument the competition can't copy overnight.

Frequently asked questions

Do these laws really apply to my five-person business?

Yes — the laws' criterion is the processing of data, not the size of whoever processes it. What does change with size is the intensity of some formal duties (registries, data-protection officers), usually required only of large or sensitive-data operations. This guide's minimum kit covers what a small business needs in practice; check your country's specifics, because deadlines and nuances vary.

Can I send promotions to customers who already bought from me?

It depends on your legal framework, but the common doctrine: many countries allow contacting existing customers with offers for products similar to what they bought (the "prior relationship exception"), always with easy unsubscribe in every message. What almost no framework allows: contacting someone who was never a customer without consent, or using the data for purposes foreign to the relationship. The safe and more effective practice: ask for explicit consent at the moment of sale — most people say yes.

What do I do if someone asks me to delete their data?

First verify identity (don't delete someone's data because a third party asked), then distinguish: marketing data gets deleted outright — it's their right; data tied to legal obligations (invoices, contracts, warranties) is kept for the period tax or commercial law demands, and you explain that. Respond within your law's deadline, keep a record of what was done, and delete in your third-party tools too (CRM, mailing list) — the data surviving in a forgotten copy is still your responsibility.

Do I need a lawyer for this?

For the minimum kit, generally not: the inventory, a privacy notice based on serious templates for your country, recorded consent and a rights process are within any organised business's reach. A lawyer earns their fee in three scenarios: you handle sensitive data at volume (health, finance, minors), you transfer data across borders, or you received a demand from the authority. The most profitable investment before the lawyer: an hour reading the official small-business guide your country's data authority almost certainly publishes for free.

Keep reading

Apps & SaaSPillar guide

How to Build an App or Platform for Your Business: From Idea to MVP

Every day, a good idea dies crushed by a development effort that started too big. This guide walks through the path that actually works: validate cheaply, build the minimum that delivers value, and grow on evidence — not on faith.

April 21, 20265 min read
Apps & SaaS

Data Security in Your Software: The Minimum You Should Demand

Your software holds the most valuable thing the business owns after the till: your customers' data, your prices, your history. And the real threat isn't the movie hacker — it's the password shared on a sticky note, the access of the employee who left a year ago, and the backup nobody ever tested. Security isn't a product you buy: it's practices you demand.

September 21, 20255 min read