Personal Data Protection: What Your Business Must Comply With
If you keep a customer list with names and phone numbers, you already handle personal data — and the data-protection laws that reached almost every country apply to your business too, not just to corporations. The good news: complying with the essentials doesn't require a legal department — it requires understanding five principles and assembling a minimum kit.
October 6, 20256 min readIn this article
If you keep a customer list with names and phone numbers, you already handle personal data. If you send WhatsApp promotions, have a form on your website or store purchase histories, you handle quite a lot of it. And the data-protection laws that reached almost every country over the last decade — with Europe's GDPR as the model — apply to your business too, not just to corporations: fines scale with severity, not only with size.
The good news against the scare: complying with the essentials doesn't require a legal department — it requires understanding the five principles all these laws share and assembling a minimum kit you can build in weeks. This guide gives you both, plus the map of the points where your business touches data without noticing.
What counts as personal data (more than you think)
Personal data is any information that identifies or can identify a person: name, phone, email, address, ID number, photo, a purchase history tied to someone, even the IP address under many legal frameworks. And there's a second category with a higher bar: sensitive data — health, finances, beliefs, children's data — which demands reinforced protection and, generally, explicit consent. The mental rule: if a specific person would be affected were that data leaked, it's personal; if it would also embarrass them or cause serious trouble, it's sensitive.
The five principles all the laws share
- Legal basis: you need a valid reason to hold each piece of data — the person's consent, a contract that requires it, or a legal obligation; "I got it and I use it" is not a basis.
- Purpose: data is used for what you said when asking for it — the phone number given to coordinate a delivery is not automatically a marketing channel.
- Minimisation: ask only for what you need; every extra form field is extra liability with no benefit.
- The subject's rights: people can ask to see their data, correct it and — with nuances — have it deleted; your business must be able to respond.
- Security: protecting what you store isn't optional — it's part of the law, and the practices are in the data security guide.
Where your business touches data (the map)
| Touchpoint | Data you capture | What to mind |
|---|---|---|
| Web forms | Name, email, phone, enquiry | A linked privacy notice and minimal fields — detail in the forms guide |
| Sales and invoicing | Tax ID, address, history | Clear legal basis (the contract/invoice provides it) — but for that purpose only |
| Marketing and newsletters | Email, phone, behaviour | Recorded consent and easy unsubscribe in every send — the highest-infringement zone |
| Vendors and tools | Your customer data processed by third parties (CRM, email, cloud) | A contract or terms covering the processing — you answer for what they do |
The most-broken rule: consent is not assumed
The minimum compliance kit
- Take the inventory: what data you hold, whose, where it lives and what for — an afternoon's work that underpins everything else.
- Publish a plain-language privacy notice: what you capture, why, who you share it with and how to exercise rights — linked from every form and visible on the site.
- Record marketing consent: who accepted, when and how — and put a one-click unsubscribe in every send.
- Define the rights process: who responds if someone asks to see or delete their data, and within how many days — don't let the first real request catch you improvising.
- Cover your vendors: verify that the tools where your data lives (CRM, email, cloud) have data-processing terms — and if you commission your own software, put these duties in the project specification.
The side nobody mentions: compliance sells
Data protection is usually told as a burden, but it has a commercial face: the customer who sees a short form with a clear notice, receives only what they agreed to receive and can unsubscribe in one click trusts more — and buys more — than the one who feels watched and bombarded. Minimisation also makes you cheaper to run: less data is less risk, less storage and less breach surface. And in markets where almost nobody complies well, the business that does holds a seriousness argument the competition can't copy overnight.
Frequently asked questions
Do these laws really apply to my five-person business?
Yes — the laws' criterion is the processing of data, not the size of whoever processes it. What does change with size is the intensity of some formal duties (registries, data-protection officers), usually required only of large or sensitive-data operations. This guide's minimum kit covers what a small business needs in practice; check your country's specifics, because deadlines and nuances vary.
Can I send promotions to customers who already bought from me?
It depends on your legal framework, but the common doctrine: many countries allow contacting existing customers with offers for products similar to what they bought (the "prior relationship exception"), always with easy unsubscribe in every message. What almost no framework allows: contacting someone who was never a customer without consent, or using the data for purposes foreign to the relationship. The safe and more effective practice: ask for explicit consent at the moment of sale — most people say yes.
What do I do if someone asks me to delete their data?
First verify identity (don't delete someone's data because a third party asked), then distinguish: marketing data gets deleted outright — it's their right; data tied to legal obligations (invoices, contracts, warranties) is kept for the period tax or commercial law demands, and you explain that. Respond within your law's deadline, keep a record of what was done, and delete in your third-party tools too (CRM, mailing list) — the data surviving in a forgotten copy is still your responsibility.
Do I need a lawyer for this?
For the minimum kit, generally not: the inventory, a privacy notice based on serious templates for your country, recorded consent and a rights process are within any organised business's reach. A lawyer earns their fee in three scenarios: you handle sensitive data at volume (health, finance, minors), you transfer data across borders, or you received a demand from the authority. The most profitable investment before the lawyer: an hour reading the official small-business guide your country's data authority almost certainly publishes for free.