One of the most persistent myths in European business is this: "We're too small for GDPR to apply to us." It's repeated in Facebook groups, whispered between business owners, and assumed by thousands of Croatian and European SMBs every day.

It is completely wrong.

GDPR applies to your business regardless of size, turnover, or how many employees you have. If you collect, store, or process the personal data of people in the EU β€” a contact form submission, an email newsletter signup, a customer order β€” you are in scope. Full stop.

This guide explains what GDPR actually is, what it requires from you in plain language, and the 7 practical steps every small business needs to take in 2026.

What is GDPR?

The General Data Protection Regulation (EU) 2016/679 β€” GDPR β€” is a European Union law that came into force on 25 May 2018. It replaced a patchwork of national data protection laws across EU member states with a single, unified framework governing how personal data must be collected, processed, stored, and deleted.

Personal data means any information that relates to an identified or identifiable living person. This includes:

If you run a website with a contact form, you are processing personal data. If you send a newsletter, you are processing personal data. If you use Google Analytics, you are processing personal data. The bar is low β€” deliberately so.

Does GDPR Apply to Small Businesses?

The short answer is yes β€” with one narrow exception.

Article 30(5) GDPR provides a limited exemption from the obligation to maintain detailed written records of processing activities for organisations with fewer than 250 employees, but only if the processing is:

That exemption is narrower than most SMBs assume. If you send regular email newsletters, operate an e-commerce store, or use analytics tools, your processing is systematic β€” not occasional. The exemption does not apply to you.

All other GDPR obligations apply regardless of company size. This includes the requirement to have a lawful basis for processing, a privacy policy, a cookie consent mechanism, and the ability to respond to data subject requests.

Enforcement data confirms this is not theoretical. A 2024 report from Slovakia's data protection authority found that 62% of GDPR fines that year went to companies with fewer than 50 employees, with an average fine of €8,200. The highest fine in that period was €94,000 β€” issued against an e-commerce shop that mishandled data subject requests. These are not enterprise-level sums, but they are life-altering for a small business.

The 7 Core Things GDPR Requires From Your Business

1. A Lawful Basis for Every Processing Activity

Under Article 6 GDPR, you cannot process personal data unless you have a valid lawful basis. There are six options, but for most SMBs, only two are relevant:

Consent (Art. 6(1)(a)) β€” The person clearly and actively agreed to their data being processed for a specific purpose. This is what you need for newsletter subscriptions, marketing emails, and non-essential cookies.

Legitimate Interest (Art. 6(1)(f)) β€” You have a genuine business reason that is not outweighed by the individual's rights. This applies to things like basic website security logging or processing enquiry form data to respond to a message.

The critical word is specific. You cannot use vague language like "to improve our services." Each processing activity needs its own explicit, documented purpose. Regulators have been actively scrutinising this since 2024.

2. A Privacy Policy That Actually Explains Things

Your privacy policy is not a formality β€” it is a legal document required under Articles 13 and 14 GDPR. It must tell visitors:

A generic privacy policy template copied from the internet almost certainly does not meet these requirements. It needs to be specific to your business and your actual data flows.

3. A Compliant Cookie Banner

If your website uses any cookies beyond what is strictly necessary for the site to function β€” and almost every website does β€” you need a consent mechanism.

The consent must be freely given, specific, informed, and unambiguous. This means:

We cover this in detail in our companion article: The 5 Most Common Cookie Banner Mistakes.

4. Data Subject Rights Mechanism

GDPR gives individuals eight rights over their personal data. The most commonly exercised are:

You must be able to respond to these requests within 30 days, free of charge. You need a clear mechanism β€” a labelled email address or a web form β€” for people to submit requests. Burying it in a long privacy policy is not sufficient.

5. Third-Party Agreements (Art. 28 DPAs)

Every third-party tool that processes personal data on your behalf β€” your email platform, your CRM, your hosting provider, your analytics tool β€” is a "data processor" under GDPR. You need a Data Processing Agreement (DPA) with each one.

The good news is that most reputable SaaS companies already have DPAs available in their terms of service or legal documentation. You need to check, confirm, and document these agreements.

6. A Cookie and Data Inventory

You cannot protect data you don't know about. GDPR's accountability principle (Art. 5(2)) requires you to be able to demonstrate compliance β€” which starts with knowing what data you collect, where it goes, and how long you keep it.

For most small businesses, this is a simple document listing:

7. A Breach Response Plan

Under Article 33 GDPR, if you experience a personal data breach β€” a hack, an accidental email to the wrong person, a lost laptop β€” you must notify your supervisory authority within 72 hours. In Croatia, that is AZOP (Agencija za zaΕ‘titu osobnih podataka).

This doesn't mean having a complex incident response team. For a small business, it means knowing: what constitutes a breach, who to contact (AZOP: azop.hr), and what information to include in a notification.

Common Myths Debunked

"We don't have an office in the EU so GDPR doesn't apply."

Wrong. GDPR applies to any organisation that processes the data of EU residents, regardless of where the organisation is based. A US company with EU customers is in scope.

"We only collect business email addresses, not personal ones."

Business email addresses in the format firstname.lastname@company.com are personal data. GDPR applies.

"We use a cookie banner so we're compliant."

Having a banner is not the same as having a compliant banner. Most cookie banners we audit have at least two or three violations. See our cookie article for details.

"GDPR only matters for big companies."

Enforcement data from across the EU consistently shows that SMBs are increasingly in scope. The Slovak and Spanish data protection authorities issued more fines against small businesses than large ones in 2024.

What Happens If You Don't Comply?

The consequences of non-compliance fall into three categories:

Regulatory fines β€” up to €20 million or 4% of global annual turnover, whichever is higher, for serious violations. For minor violations, up to €10 million or 2% of turnover. For an SMB with €1 million in revenue, that upper tier represents €40,000.

Reputational damage β€” data breaches and GDPR enforcement actions are public. Your competitors, customers, and partners can see them.

B2B contract risk β€” larger clients increasingly require their suppliers and service providers to demonstrate GDPR compliance as a condition of doing business. Non-compliance can cost you contracts.

Where to Start

The most effective starting point is a compliance audit β€” understanding what you currently do, what the gaps are, and what needs fixing. This doesn't have to be expensive or complex.

You can run a free audit of your website right now using the tool at the top of this page. It checks 10 critical GDPR requirements in under 30 seconds and gives you a prioritised list of what to fix.

If you want help implementing the fixes, or just want someone to review your privacy policy and cookie setup in plain language without the legal jargon β€” that's exactly what GDPRGard does. Book a free consultation β†’

This article is for informational purposes and does not constitute legal advice. For complex compliance situations, consult a qualified data protection professional or lawyer.

Also read:

⚠️ This article is for informational purposes only and does not constitute legal advice. For complex compliance situations, consult a qualified data protection professional. GDPR and EU AI Act requirements are subject to ongoing regulatory guidance β€” verify current obligations with your legal adviser.