Certix

GDPR for small businesses: what is mandatory and what is proportionate to size

Certix
Certix®
· 1 Jun 2026 · 8 min read

Informative article. It does not replace individualised professional advice.

A Spanish pyme (Spanish SME) processes personal data from day one: employees, customers, suppliers, job applicants, web visitors, business contacts and, in many cases, video surveillance footage. Complying with the GDPR is not optional for businesses above a certain size: it is an obligation that applies equally to those with five employees and those with five hundred. What changes is the proportionate documentation footprint: what looks like folders of protocols in a multinational fits, in a well-structured SME, into a dozen short, useful documents.

This guide explains how to bring the GDPR (Regulation (EU) 2016/679), the LOPDGDD (Spain's Organic Law 3/2018) and the LSSICE (Spain's Law 34/2002 on Information Society Services) down to the real size of a Spanish SME, without over-engineering compliance or falling short. It is aimed at companies with staff, an office and stable operations: retail, distribution, manufacturing, professional services, agencies, workshops, hospitality with several employees.

The principle of proportionality: what changes and what does not

The GDPR does not impose a single compliance model. Article 24 requires the controller to apply appropriate technical and organisational measures taking into account the nature, scope, context and purposes of processing, as well as the risks to the rights and freedoms of natural persons. That flexibility allows an SME to build a compliance approach tailored to its reality without having to copy a corporate model.

What does not change with size:

  • The principles of art. 5 GDPR (lawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, storage limitation, integrity and confidentiality, accountability).
  • The duty to inform the data subject (art. 13 GDPR): every time the company collects data from a customer, employee or applicant, it must inform them.
  • The rights of the data subject (access, rectification, erasure, objection, restriction, portability) and the one-month deadline to respond (art. 12(3) GDPR).
  • The obligation to notify breaches to the AEPD within 72 hours where they may affect rights and freedoms (art. 33 GDPR).

What does change with size:

  • The documentation footprint: the RoPA of an SME with fifteen employees can fit on one and a half pages; the RoPA of a company with five hundred employees is a substantial document.
  • The level of specialisation required in security: an SME applies reasonable measures based on standard commercial software and good practice; a large enterprise may need SOC, CISO and formal policies.
  • The DPO obligation: applies only in specific cases under art. 37 GDPR and art. 34 LOPDGDD; most SMEs are not subject to it.
  • The potential RoPA exemption of art. 30(5) GDPR for entities with fewer than 250 employees, although in practice almost all of them carry out non-occasional processing that disqualifies them from it.

The five typical processing activities of an SME

Almost any Spanish SME boils down to five processing blocks. Identifying them first helps scale the rest of the documentation:

Processing Typical data Common legal basis
Employees Identifiers, payroll, IBAN, tax data, sick leave, holidays, training. Employment contract (art. 6(1)(b) GDPR) + legal obligation (art. 6(1)(c))
Customers Business name/individual name, tax ID, contact, address, IBAN, orders, history. Performance of contract (art. 6(1)(b) GDPR)
Suppliers Supplier details and details of their business contacts. Performance of contract (art. 6(1)(b) GDPR)
Job applicants CV, contact details, education, work experience, occasionally cover letter. Pre-contractual measures (art. 6(1)(b)) or consent (art. 6(1)(a))
Marketing and communications Newsletter subscribers, business contacts, identified web visitors. Consent (art. 6(1)(a)) or legitimate interest (art. 6(1)(f)) + art. 21 LSSICE

To this you add, if the SME uses video surveillance, a sixth processing activity based on legitimate interest (art. 6(1)(f) GDPR) and subject to the specific regime of art. 22 LOPDGDD; if the business involves the export or processing of data in countries outside the EEA, you must consider the safeguards in Chapter V of the GDPR.

Proportionate minimum documentation

An SME reasonably complies with five well-prepared documentary blocks. The length of each depends on the company's actual complexity, but none of them needs to be a treatise:

  • Record of Processing Activities (RoPA): one entry per identified processing activity (five or six for a standard SME), with the information required by art. 30(1) GDPR: controller, purpose, categories of data subjects, categories of data, recipients, retention periods, security measures and international transfers where applicable. An Excel document or a table inside a Word file; nothing more is needed.
  • Privacy notices: one for employees (delivered when signing the employment contract), one for customers (delivered with the first quote or contract), one for job applicants (delivered when a CV is received or when a vacancy is published), and the web privacy policy if there is a website. Four short texts.
  • Art. 28 GDPR contracts with technology providers that process data: HR and payroll software, external accountancy/payroll firm, IT or maintenance provider, hosting, email marketing tool, CRM, ERP, cloud storage platform. Most of them offer the contract as a standard adhesion annex.
  • Operational security policy: two or three pages with the actual measures applied: individual, strong passwords; two-factor authentication for critical access; encrypted backups; device encryption; automatic screen locking; antivirus; onboarding and offboarding of staff with system access; segregation of guest and corporate Wi-Fi networks.
  • Breach protocol: one page describing what to do if an incident is detected (lost laptop, successful phishing, ransomware attack, internal leak), who is responsible for assessing it, in which cases it must be notified to the AEPD within 72 hours, and how. Includes the notification template.

If the SME uses video surveillance, you must add the information sign required under art. 22(4) LOPDGDD and the internal rules of the system (recorded areas, retention periods, who has access to the viewer, transfer to law enforcement).

Employees: the most sensitive processing in the SME

Processing the workforce's data concentrates the most serious legal risks in an SME. Three critical points:

  • Information to the employee at the time of hiring: a specific privacy notice covering employment purposes (payroll, social security contributions, occupational risk prevention, health surveillance where applicable), transfers to third parties (TGSS — Spanish Social Security Treasury, AEAT — Spanish Tax Agency, external payroll provider, mutua insurer), retention periods linked to labour obligations and limitation periods.
  • Time recording (mandatory since Spanish Royal Decree-Law 8/2019 on time recording): the company must record the working day of each employee. The SME has several legitimate and proportionate options to implement it: individual PIN, RFID proximity card, corporate mobile app, signed paper record, or HR software with personalised login.
  • Access to email and systems after an employee leaves: corporate email contains customer and business data the company is entitled to recover. The protocol must be defined and communicated to the employee when signing the contract: redirection of email to another person for a reasonable period, no systematic opening of personal correspondence that may have been received, secure deletion at the end of the period.

"The SME does not need a one-hundred-page compliance manual. It needs ten real pages, aligned with what it actually does every day. The difference between compliance that holds and compliance that does not is not the volume of the document — it is whether it reflects the reality of the company."

Mario P. Talamillo · Managing Partner, Certix®

Technology providers: the chain few SMEs document

An average SME works with around ten technology providers that process personal data on its behalf: external payroll firm, HR and payroll software, IT provider maintaining servers and equipment, cloud ERP, email marketing tool, storage platform, CRM. Each of them is a processor and must sign the contract required by art. 28 GDPR with the content set out in art. 28(3).

The critical points the SME must review when contracting:

  • The provider offers the contract as an annex to its terms. If it does not, it must be expressly requested.
  • The contract lists the sub-processors and obliges the provider to notify any changes.
  • It identifies international transfers and their legal basis (Data Privacy Framework for the US, standard contractual clauses).
  • It obliges the provider to assist the controller with data subject rights and breaches.
  • It guarantees the return of the data at the end of the relationship (art. 28(3)(g) GDPR), not just its destruction.

Marketing and newsletter: what SMEs usually get wrong

The average SME holds a list of business contacts accumulated over time: business cards from trade fairs, LinkedIn contacts, emails received in response to quotes, newsletter subscribers. The temptation to use that list for campaigns is high, and mistakes concentrate here:

  • Lists from different sources must not be mixed: people who gave their email to receive a quote did not consent to receiving a newsletter. Express consent is needed to add them to the marketing list.
  • Consent boxes on web forms must be unticked by default and separate from acceptance of the policy. It is not acceptable to bundle everything into a single checkbox.
  • Art. 21 LSSICE allows commercial communications by email to existing customers about products or services similar to those already contracted, always with an unsubscribe mechanism in each message. Outside that scenario, consent is required.
  • The unsubscribe mechanism must be easy, free and effective: one click, no reasons asked, no log-in required.

Minimum SME checklist

  • RoPA up to date with the five or six real processing activities.
  • Four operational privacy notices: employees, customers, applicants, website.
  • Art. 28 GDPR contracts signed with external payroll firm, HR software, IT provider, hosting and other relevant providers.
  • Operational security policy of two or three pages, tailored to actual size.
  • Breach protocol with AEPD notification template.
  • Video surveillance information sign and internal rules where cameras are used.
  • Annual review of documentation and providers.
  • Designated contact point for data subject rights and enquiries (this may be the manager, the HR department or an external DPO if voluntarily appointed).

Frequently asked questions

Is an SME with fewer than 10 employees exempt from the GDPR?

No. The GDPR applies regardless of size. Article 30(5) GDPR provides a very narrow exemption from the RoPA for controllers with fewer than 250 employees, and only where processing is occasional, does not include special categories and presents no risk. In practice, almost any SME carries out non-occasional processing (employees, recurring customers) and always benefits from keeping a RoPA, even a short one.

How many documents does an SME need at a minimum to comply with the GDPR?

Five blocks: the RoPA, the privacy notices (customers, employees, applicants, website), the Art. 28 GDPR contracts with relevant technology providers, an operational security policy tailored to the business and a breach management protocol. Plus the website's privacy and cookie policies. What matters is that those documents are alive and reflect what the company actually does.

Does an SME need to appoint a Data Protection Officer (DPO)?

As a general rule, no. A standard SME does not fall within the exhaustive cases of art. 37 GDPR or art. 34 LOPDGDD. The exceptions are activities involving regular and systematic monitoring on a large scale, or large-scale processing of special categories. Although this is the general sector rule, the final requirement will depend on the size, volume and exact type of processing. Each case requires individual analysis. Appointing a voluntary DPO brings internal order.

Can an SME use free internet templates or does it need professional advice?

Templates can serve as a structural reference but rarely work as the final document. Policy, RoPA and Art. 28 GDPR contracts must reflect the specific controller, real purposes, actual providers and current transfers. Templates fail where the AEPD imposes penalties: real retention periods, actual recipients and legal bases consistent with each purpose.

This content is purely informational and educational; it does not constitute specialised legal advice. Applying the regulations to each specific case requires individual analysis. Spanish regional sectoral regulations may extend or modify deadlines and requirements.

Want to organise your SME's GDPR compliance in a proportionate and useful way?

At Certix we assign you an SME compliance specialist. No commercial intermediaries, no generic templates.

Speak to a specialist

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →