Self-employed professionals and SMEs
Data protection
for small businesses
A small business processes personal data from day one: employees, clients, suppliers. The GDPR makes no distinction by size or turnover. What matters is what you process, not how much you invoice.
€0
minimum turnover threshold
72 h
to report a data breach
Art. 30
GDPR — RoPA mandatory
24 h
personalised proposal
Sector challenges
General obligations for small businesses
Employee data
Payroll, contracts, attendance monitoring, sick leave and workplace CCTV are processing activities that require adequate employee information and specific security measures.
Record of Processing Activities
The RoPA is the central document of GDPR compliance. It records what data the business processes, for what purpose, for how long and with what security measures. The AEPD may request it during an inspection.
Suppliers and data processors
Any supplier with access to the business's data — payroll advisers, accountants, management software, cleaning companies — may act as a data processor and requires a specific contract.
Website and commercial communications
A business website with a contact form, quotation request or newsletter requires a privacy policy, legal notice and consent management. Email marketing requires an evidenced legal basis.
Information security
Strong passwords, access controls, backups and encryption of sensitive documents are basic measures. Small businesses are a frequent target of phishing and ransomware attacks.
Data breach management
Following a data breach, the business has 72 hours to report it to the AEPD if it poses a risk to those affected. Without a protocol in place, meeting this deadline is practically impossible.
The service
What the service includes for small businesses
Full RoPA
Record of Processing Activities covering all the business's processing: clients, employees, suppliers and website.
Information clauses
Texts for employment contracts, quotations, web forms and commercial communications.
Privacy policy and legal notice
Complete documentation for the business website.
Cookie management
Banner and cookie policy configuration tailored to the website's actual tools.
Data Processing Agreements (DPA)
DPAs with all suppliers acting as data processors.
Data breach protocol
Response procedure with AEPD notification within 72 hours and communication to affected individuals.
Data subject rights management
Procedure for handling access, rectification, erasure and portability requests.
Document management platform
Access to a private platform with documents, electronic signature and real-time updates.
Ongoing support
Unlimited queries. Updates in response to regulatory or business activity changes.
Do you need a proposal for your business?
Tell us about your activity. Proposal within 24 hours.
FAQ
Frequently asked questions about data protection for small businesses
Does a small business with few employees have GDPR obligations?
Yes. The GDPR sets no thresholds based on headcount or turnover. Any business that processes personal data of clients, employees or suppliers is subject to its obligations. The precise scope depends on the type of data processed and the nature of the activity.
What basic documentation does a small business need?
The minimum documentation includes the Record of Processing Activities (RoPA), information clauses for clients and employees, Data Processing Agreements with suppliers who access the data, a privacy policy and legal notice for the website, and a data breach response protocol.
Does a small business need a Data Protection Officer?
The obligation to appoint a DPO depends on the type of processing carried out, not the size of the business. In general, small businesses are not required to do so unless they carry out large-scale processing of special-category data or systematic monitoring activities. Each case requires individual analysis.
How does the GDPR affect the employment relationship?
Small businesses must inform their employees of the processing carried out with their data (payroll, attendance monitoring, CCTV, etc.), implement appropriate security measures and comply with the retention periods for employment documentation. Employment contracts must include information clauses.
What happens if a supplier suffers a data breach involving my business's data?
If the supplier acts as a data processor, they must notify you of the breach without undue delay. As the data controller, you must assess whether the breach must be reported to the AEPD within 72 hours and, where applicable, to the individuals concerned. Having a current Data Processing Agreement and a breach protocol in place facilitates the management of such incidents.
How often should data protection documentation be reviewed?
There is no fixed period prescribed by law. Reviews should be carried out when there are changes to the business activity, the systems used, the applicable regulations, or when incidents are identified. Continuous risk-based evaluation is recommended.
Sector resources
Learn more
Small businesses
GDPR for small businesses: what is mandatory and what is proportionate to your size
GDPR compliance tailored to the Spanish SME: proportionate RoPA, information clauses, contracts with providers, operational security policy and breach protocol. Without overdoing or falling short.
8 min·Read article
Small businesses
Employees and GDPR in the SME: payroll, time recording and CCTV
How an SME handles its workforce data under the GDPR: information clause when signing the contract, time recording, workplace CCTV, employee offboarding and deletion of professional email.
8 min·Read article
Small businesses
External IT provider as processor: the Art. 28 GDPR contract many SMEs lack
How to govern the external IT provider, the maintenance company or the cloud supplier under Art. 28 GDPR: mandatory contract, minimum content, remote access, home copies and provider switching.
8 min·Read article
Free tool
Data protection self-check
Check in 5 minutes your overall adaptation level in personal data protection.
No email · Anonymous · No commitment
Small businesses
GDPR compliance
adapted to your business.
An expert analyses your activity and proposes the right solution. No intermediaries.
Proposal within 24 h · info@certix.es
Legal notice: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.