In August, enjoy 2 free months on Djaboo with the code: DJABOO26 → I'm taking advantage of it
GDPR: definition, obligations and compliance for very small and small businesses

GDPR: definition, obligations and compliance for very small and small businesses

5 / 5 - (562 votes)

You manage a customer fileyou send newsletterIf you have employees and use a camera on your premises, then you are processing personal data, and the GDPR fully applies to you. However, according to the France Num 2025 Barometer, only 41% of micro-enterprises/SMEs keep a register of processing activitiesThis obligation applies to all businesses, regardless of size. This guide explains, in no legal jargon, what the GDPR requires of you in concrete terms and how to comply with it step by step.

GDPR: Definition and Fundamental Principles

The GDPR, or General Data Protection Regulation, is European Regulation No. 2016/679 of April 27, 2016. It entered into force on May 25, 2018, in all member states of the European Union, replacing Directive 95/46/EC of 1995. Unlike a directive, a regulation applies directly, without national transposition. In France, it is supplemented by the Data Protection Act of January 6, 1978 (amended in 2018) and overseen by the CNIL (National Commission for Information Technology and Civil Liberties).

Its main objective is to strengthen the rights of individuals over their personal data, while harmonizing rules within the EU to create a single legal framework. It also introduces the principle of accountability, meaning the obligation to provide information and demonstrate compliance.

The 7 fundamental principles of the GDPR (Article 5)

Article 5 of the regulation sets out the principles that every organization must respect when processing personal data:

1.Legality, loyalty, transparency The data must be processed lawfully, fairly and transparently. The data subject must be clearly informed.
2.Limitation of purposes The data is collected for specific, explicit and legitimate purposes. It cannot be reused for an incompatible purpose.
3.Data minimization Only data strictly necessary for the stated purpose should be collected. No "just in case" collection.
4.Accuracy The data must be accurate and kept up to date. Any inaccurate data must be corrected or deleted.
5.Limitation of preservation Data must not be kept longer than necessary. Retention periods must be defined and respected.
6.Integrity and confidentiality : data must be protected against unauthorized access, loss or destruction.
7.Accountability The data controller must be able to demonstrate compliance. It is not enough to be compliant; the measures taken must be documented and proven.

These principles apply to you, manager of a very small business/small and medium-sized enterprise, as soon as you collect the name of a customer, the email address of a prospect or the bank details of a supplier.

Who is affected and what data is protected?

All companies, regardless of size

The determining factor is not the size of your organization, but the fact that you process personal data. A micro-enterprise with a single employee that manages a customer database is subject to the GDPR just like a large corporation. Associations, the self-employed (doctors, lawyers, accountants), and subcontractors who process data on behalf of a data controller are also affected.

The GDPR also applies to companies established outside the EU when they target European residents. The €150 million fine imposed on SHEIN by the CNIL in 2025 perfectly illustrates this principle: the Chinese brand was deploying advertising trackers before any user interaction, and its location outside the EU did not protect it.

What is personal data?

Personal data is any information that allows for the direct or indirect identification of a natural person: name, surname, email address, telephone number, IP address, location data, customer number, photo, etc. The definition is broad: a license plate, an online identifier, or even a combination of seemingly innocuous information taken in isolation can constitute personal data.

Concrete examples for a very small business/small and medium-sized enterprise (SME):

Your customer file with names, addresses and purchase history: personal data.
Your employees' payslips: personal data.
Email addresses collected via your contact form: personal data.
Images captured by your CCTV camera: personal data.

Sensitive data: a category apart

Article 9 of the GDPR prohibits in principle the processing of certain categories of data known as "sensitive", which reveal racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data relating to sexual life or sexual orientation.

For a very small business or SME, this sensitive data can appear in unexpected contexts: employee sick leave (health data), information gathered during a job interview, or even images from a facial recognition system at the entrance to your premises. Its processing is subject to strictly regulated conditions and generally requires the explicit consent of the individual concerned.

The 6 legal bases for processing

All processing of personal data must be based on one of the six legal bases provided for in Article 6 of the GDPR. This list is exhaustive: if none of these bases applies, the processing is prohibited. The choice of legal basis must be made before the start of processing and documented in your records.

1. Consent (art. 6.1.a)

The individual gave their consent freely, specifically, knowingly, and unambiguously. Consent must be withdrawn as easily as it was given. This is the basis for newsletters, non-essential cookies, and B2C email marketing.

Concrete example : Your newsletter signup form must include an unchecked checkbox, with a clear statement on the use of data.

2. The performance of a contract (art. 6.1.b)

The processing is necessary for the performance of a contract to which the person is a party. It is the natural basis for managing your customer relationship, invoicing, delivery, or payroll for your employees.

Concrete example : You collect your customer's delivery address to send them their order. No additional consent is needed.

3. The legal obligation (art. 6.1.c)

The processing is mandated by law or regulation. It is the basis used for retaining payslips, invoices (10 years for accounting purposes), and tax and social security declarations.

Concrete example : You must keep your employees' payslips for a minimum of 5 years, in accordance with the Labour Code.

4. Safeguarding vital interests (art. 6.1.d)

Exceptional use case, limited to medical emergency situations where the person is unable to consent.

5. The public interest mission (art. 6.1.e)

Reserved for public authorities and bodies responsible for a public service mission. Does not apply to traditional private companies.

6. Legitimate interest (art. 6.1.f)

The data controller pursues a legitimate interest, provided that the fundamental rights and freedoms of the individual do not override them. This basis is flexible but requires a documented "triple test": Is the interest legitimate? Is the processing necessary? Do the individual's rights override it?

Concrete examples validated by the CNIL: B2B sales prospecting with existing clients, fraud prevention, IT security, proportionate video surveillance of premises.

Please note: The CNIL has sanctioned several companies for having wrongly invoked legitimate interest, in particular to justify permanent surveillance of employees or prospecting campaigns based on files purchased from data brokers.

The rights of individuals

The GDPR grants individuals eight fundamental rights regarding their personal data (Chapter III of the regulation). As a data controller, you must be able to respect these rights and respond within one month of receiving the request.

Right of access (art. 15) Any person may request confirmation that you process their data and obtain a copy of it. A response is mandatory within one month.

Right of rectification (art. 16) The person can request the correction of inaccurate or incomplete data. Update your customer file as soon as a customer notifies you of a change of address.

Right to erasure (“right to be forgotten”, art. 17) The individual can request the deletion of their data under certain conditions (withdrawal of consent, data no longer necessary, unlawful processing). This right is not absolute: it does not apply if you have a legal obligation to retain the data.

Right to data portability (art. 20) The individual can retrieve their data in a structured and machine-readable format to transmit it to another service provider. This right applies only to processing based on consent or contract.

Right to limitation (art. 18) : the person can request the temporary suspension of the processing of their data, for example while its accuracy is being verified.

Right to object (art. 21) The individual has the right to object to processing, particularly for marketing purposes. This right is absolute with regard to marketing: you must cease immediately.

Law related to automated decisions (art. 22) : a person cannot be subject to a decision based solely on automated processing (scoring, profiling) producing significant legal effects, without human intervention.

Right to information (art. 13-14) : every person must be informed of the collection and use of their data, at the time of collection.

How can these requests be managed in practice? Designate a dedicated email address (e.g., rgpd@yourcompany.fr), record each request with its date of receipt, and document your response. In 2026, the CNIL (French Data Protection Authority) sanctioned very small businesses and medical practices not for the initial breach, but because they had never responded to the requests of the individuals concerned. Silence constitutes a separate breach.

Your specific obligations: processing register, information, security, subcontractors

The register of processing activities (art. 30)

This is your central compliance document. All companies, regardless of size, are required to maintain this register. The common misconception that companies with fewer than 250 employees are exempt is false: the exemption only applies to a few very specific cases of occasional and low-risk processing, not to the general obligation.

For a very small business/small and medium-sized enterprise (SME), this register can take the form of a simple table listing, for each processing activity:

The purpose (why you collect this data)
The categories of people concerned (customers, employees, prospects)
The categories of data processed (contact details, banking data, health data)
The recipients (accountant, billing software, hosting provider)
Shelf life
The security measures implemented

The CNIL provides a simplified register template suitable for small organizations.

The obligation to provide information

You must inform the individuals concerned at the time their data is collected. This information may be included in:

A privacy policy on your website
An information notice on your contact forms, quotes or contracts
A sign in your premises (for video surveillance)
A clause in your employees' employment contracts

The information must be clear, accessible, and written in French. The CNIL (French Data Protection Authority) sanctioned a company for providing its privacy policy only in English.

The obligation of safety (art. 32)

You must implement appropriate technical and organizational measures to protect data. For a very small business/small and medium-sized enterprise (SME), this means, in concrete terms:

Strong passwords (minimum 12 characters, uppercase letters, lowercase letters, numbers, special characters) for all data access
Regular backups
Access to data is limited to only those who need it.
Antivirus software and regular updates
Encrypting sensitive data

Regulation of subcontractors (art. 28)

Any service provider that processes data on your behalf (hosting provider, billing software, accountant, marketing agency) is a data processor under the GDPR. You must enter into a written contract with them containing specific clauses on data protection: purposes of processing, security measures, confidentiality obligations, and what happens to the data at the end of the contract.

Concrete example : If you use software CRM In SaaS mode to manage your customers, check that the publisher offers a data processing agreement (DPA) compliant with the GDPR.

Data Protection Officer (DPO), impact assessment (IAPD): in what cases?

The Data Protection Officer (DPO)

The appointment of a DPO is mandatory in three specific cases (Art. 37 GDPR):

1.For public authorities and bodies
2.For organizations whose core activities lead them to carry out regular and systematic monitoring of individuals on a large scale (e.g., telephone operators, insurers)
3.For organizations that process sensitive data on a large scale (health data, biometric data, etc.)

For the vast majority of micro-enterprises/SMEs, the DPO is therefore not mandatory. However, it is strongly recommended to appoint an internal "GDPR officer," meaning a person responsible for monitoring compliance, even without an official title. This person could be yourself, an employee, or an external service provider.

Data Protection Impact Assessment (DPIA)

A Data Protection Impact Assessment (DPIA) is mandatory before any processing likely to result in a high risk to the rights and freedoms of individuals (Article 35 of the GDPR). The CNIL (French Data Protection Authority) has published a list of nine categories of processing for which a DPIA is systematically required.

Specific cases where a very small business/small or medium-sized enterprise (SME) may be affected:

Implementation of a video surveillance system that continuously films employees' workstations
Use of real-time productivity tracking software (screenshots, mouse movement analysis)
Processing health data of your clients or employees
Implementation of a geolocation system for your employees' vehicles

If you do not fall into these categories, a Data Protection Impact Assessment (DPIA) is not mandatory. However, a proportionate risk assessment remains a good practice.

Compliance in 7 steps for a very small business/small and medium-sized enterprise (SME)

Here is a concrete action plan, without jargon, to help you get into compliance.

Step 1: Appoint a GDPR representative

Appoint a person (yourself or an employee) to oversee compliance. This person will be the point of contact for requests to exercise rights and any potential audits by the CNIL (French Data Protection Authority).

Step 2: Map your treatments and create your register

List all the activities for which you collect data: customer file, employee management, newsletter, contact form, video surveillance, accounting. For each, provide the information required by Article 30. Use the simplified template from the CNIL available at [website address]. cnil.fr.

Step 3: Verify and document your legal basis

For each processing activity listed in your register, identify the applicable legal basis. Document this choice. If you cannot identify a valid legal basis, you must cease this processing activity.

Step 4: Implement your information obligations

Draft or update your privacy policy, information notices on your forms, and GDPR clauses in your employment contracts. Install a compliant cookie banner on your website if you use tracking technologies.

Step 5: Secure your data

Conduct a quick audit of your security practices: passwords, file access, backups, updates. Fix any vulnerabilities identified. Train your employees on best practices.

Step 6: Supervise your subcontractors

List all your service providers who process data on your behalf. Verify that you have entered into a data processing agreement with each one that complies with Article 28 of the GDPR.

Step 7: Establish a rights and violations management procedure

Create a dedicated email address for GDPR requests. Keep a log of requests received and responses provided. Prepare a data breach notification procedure: you have 72 hours to notify the CNIL (French Data Protection Authority) and, if the risk is high, inform the individuals concerned.

Data breaches and penalties: what you really risk

Notification of data breaches (Art. 33-34)

In the event of a data breach (hacking, loss of a computer, sending an email to the wrong person, unauthorized access to your customer file), you are required to notify the CNIL (French Data Protection Authority) within 72 hours of discovering the incident. If the breach is likely to pose a high risk to the individuals concerned, you must also inform them directly.

The notification is made on the CNIL portal (notifications.cnil.frEven if you are not certain of the severity of the incident, it is best to report and document your analysis.

The penalties: two levels of fines

The GDPR provides for a two-tiered sanctions regime:

Level 1 (art. 83.4): up to 10 million euros or 2% of global annual turnover for technical shortcomings (missing register, late notification, failure to carry out DPIA).

Level 2 (art. 83.5): up to 20 million euros or 4% of global annual turnover for violations of fundamental rights, consent or international transfers.

The reality of sanctions for very small and small businesses

Large fines make headlines, but the statistical reality also affects small businesses. In 2025, the CNIL (French Data Protection Authority) issued 83 sanctions totaling €486,8 million, and over 60% of these sanctions targeted SMEs. In 2026, almost all of the first 23 sanctions issued under simplified procedures targeted very small businesses, medical practices, and law firms.

The simplified procedure, created in 2022, allows the CNIL (French Data Protection Authority) to quickly sanction common breaches with fines of up to €20,000, without a public hearing. For a firm of five people, €10,000 often represents an entire quarter's profit margin.

The most frequently sanctioned breaches in very small and small businesses:

Video surveillance continuously filming employees' workstations
Non-compliant cookie banner (refusal is more difficult than acceptance)
Requests to exercise rights have gone unanswered.
Silence in response to letters from the CNIL during the investigation

This last point deserves special attention: silence in the face of the CNIL constitutes an independent breach provided for in Article 31 of the GDPR, and it is often this that transforms a banal case into an aggravated sanction.

FAQ: Your questions about the GDPR

My company has fewer than 10 employees, am I really affected by the GDPR?

Yes, without exception. The GDPR applies to any organization that processes personal data, regardless of its size. As soon as you manage a customer database, have employees, or use a contact form on your website, you are subject to the GDPR. The CNIL's simplified procedure is specifically designed for small businesses, and the 2026 rulings primarily concern very small businesses and the self-employed.

Do I have to appoint a DPO?

No, not for the vast majority of very small and small businesses. Appointing a Data Protection Officer (DPO) is only mandatory for public bodies, those that process sensitive data on a large scale, or those whose main activity consists of systematically monitoring individuals on a large scale. However, it is strongly advised to appoint an internal GDPR representative, even informally.

How long should I keep my customers' data?

There is no universal retention period: it depends on the purpose of the processing. For business management, the CNIL (French Data Protection Authority) recommends keeping the data of active customers for the duration of the business relationship, and then for three years for marketing purposes after the end of that relationship. Invoices must be kept for 10 years for accounting and tax reasons. The data of unsuccessful candidates should not be kept for more than two years. Document these retention periods in your records.

What should I do if I receive a deletion request from a client?

You must respond within one month. If the request is legitimate (the customer withdraws their consent, the data is no longer needed), you must delete their data from your active files. Note: if you have a legal obligation to retain data (e.g., invoices must be kept for 10 years), you can refuse to delete that portion of the data, but you must clearly inform the customer. Always document your response.

Managing GDPR compliance means centralizing and securing the data of your customers, prospects, and teams. Djaboo, the all-in-one CRM software designed for French SMEs, helps you organize your customer relationships, invoicing, and projects in one secure place, with controlled access and easy data traceability. To learn more, visit [djaboo.com](https://djaboo.com).

5 / 5 - (562 votes)