Back to blog

Small Business Privacy Policy: 8 GDPR Details, From Forms to CCTV

Owner reviewing a website contact form

Most small businesses that collect personal data, through a contact form, a booking system, payroll or a customer email list, must publish a privacy notice. This applies regardless of company size: what matters is whether you process personal data belonging to people in the EU/EEA. The first practical step is simple: list every place personal data enters your business before you write a word of policy.


TL;DR:

  • The exemption for businesses with fewer than 250 employees eases internal processing records only; it does not remove notice duties to customers, staff, or visitors.
  • For each purpose, state its lawful basis, recipients, retention rule, and rights; identify indirect data sources and disclose safeguards for transfers outside the EU/EEA.
  • Consent requires an active opt in, a record of agreement, and an equally easy withdrawal method; prechecked boxes do not qualify.
  • Businesses normally have one month to answer access, correction, or deletion requests, with a two month extension only for complex cases and timely notice.
  • Report breaches that risk people’s rights and freedoms to the authority without undue delay and, where feasible, within 72 hours of becoming aware.

Newbusinesswebsites
Make Privacy Information Easy to Find
A professional small business website can give your privacy notice a clear place alongside the forms and contact details customers use.

Table of Contents

Who needs a privacy policy, including businesses without a website

GDPR applies based on what data you process and whose data it is, not on turnover or headcount. The regulation covers any organisation established in the EU/EEA, and any organisation outside it that offers goods or services to people in the EU/EEA, which means the territorial scope is set by the data subjects, not the business’s size.

A business with no website can still trigger transparency duties. If you take bookings by phone and keep a spreadsheet of customer names and numbers, run payroll, or install a CCTV camera over your shop counter, you are processing personal data and owe the people concerned a notice explaining what you do with it.

Common activities that trigger the requirement include:

  • Website contact or enquiry forms that collect names, emails or phone numbers.
  • Online or phone bookings that store customer details.
  • Email marketing lists, even small ones built from past customers.
  • Payroll and HR records for staff or contractors.
  • CCTV covering a shop, office or yard.
  • Website analytics and cookies that track visitor behaviour.

Some record-keeping obligations are lighter for organisations with fewer than 250 employees, but this exemption only reduces the paperwork for internal processing records. It does not remove the duty to tell customers, staff or visitors what you do with their data, so a small headcount is never a reason to skip the notice itself.

What to include in a privacy policy: a checklist tied to Articles 13 and 14

GDPR sets out exactly what a privacy notice must cover, and Article 13 requires the information to be concise, transparent, intelligible and easily accessible when you collect data directly from someone, such as through a web form. Article 14 covers the same duties when you obtain data from another source, for example a referral list or a public register.

A notice that satisfies both articles needs to cover:

  1. Who you are: your business name, contact details and, if you have one, a data protection officer’s contact details.
  2. Why you process data: a plain description of each purpose, paired with the lawful basis you rely on for it.
  3. Who sees the data: categories of recipients, such as your accountant, payment processor or delivery courier, and any safeguards for transfers outside the EU/EEA.
  4. How long you keep it: a retention period or the criteria you use to decide, plus how data gets deleted afterwards.
  5. What rights people have: access, correction, deletion, restriction, objection and portability, with the process and timescale for exercising them.
  6. Where the data came from: required only when you did not collect it directly, such as data bought from a list broker or shared by a referral partner.
  7. Automated decisions: a note if you use automated decision-making or profiling that produces legal or similarly significant effects, which is rare for most small businesses but worth checking.
  8. Cookies and tracking: a short summary of what you use and a link to cookie settings, rather than folding the whole cookie policy into the main notice.

Pro Tip: Write one purpose at a time (enquiries, bookings, marketing, payroll) and answer all seven checklist points for each before moving to the next. It keeps the document accurate and stops you writing a vague, catch-all paragraph that covers nothing properly.

The notice does not need to read like a legal contract. A short, clearly structured page that walks through these points in ordinary language satisfies the requirement better than a dense document copied from a larger company’s website, because the test is whether an ordinary customer can actually understand it.

Every purpose for processing personal data needs a lawful basis, and GDPR sets out six: consent, contract, legal obligation, vital interests, public task and legitimate interests. Most small businesses rely on three of these in practice.

  • Contract: processing needed to deliver what a customer asked for, such as using an address to post an order.
  • Consent: a freely given, specific agreement, typically used for email marketing or optional cookies.
  • Legitimate interests: processing that is reasonably necessary for your business and does not override the individual’s rights, such as basic website analytics or fraud prevention.

Consent has to be an active opt-in, never a pre-ticked box, and you need to keep a record of when and how someone agreed. Withdrawing consent must be as easy as giving it, so an unsubscribe link or an account setting needs to actually work.

Legitimate interests requires a short balancing exercise rather than a tick-box. The European Data Protection Board recommends keeping a brief Legitimate Interests Assessment that records the purpose, why it is necessary and the outcome of weighing your interest against the individual’s rights. For a small business this can be a few sentences per purpose rather than a formal document.

Data subject rights come with a clock attached: requests to access, correct or delete data must normally be answered within one month, with a possible two-month extension for complex requests provided you tell the person within the first month and explain why. Having a short, written internal process for who handles these requests avoids scrambling when the first one arrives.

Step-by-step: draft a privacy policy for your small business

Writing the notice is easier once you treat it as a documentation exercise rather than a legal drafting one. A workable sequence looks like this:

  1. Map your data: list every system that touches personal data, the fields collected (name, email, payment details, health notes), the purpose and who else sees it, such as a processor or supplier.
  2. Assign a lawful basis to each purpose: contract for order fulfilment, consent for marketing, legitimate interests for basic analytics, and so on, recording your reasoning in a line or two.
  3. Set a retention rule for each data set: a fixed period (for example, seven years for invoices) or a trigger (deletion two years after a customer’s last interaction).
  4. Write the notice by purpose: a short section for enquiries, another for bookings, another for marketing, each covering who you are, why, the lawful basis, retention and rights, in plain language.
  5. Add the contact and request process: one email address or form for data requests, with a note on the one-month response window.
  6. Cover cookies and forms: a short paragraph on tracking technologies, linking to cookie settings, and a note on what happens to data entered into contact or sign-up forms.
  7. Publish it prominently: a footer link on every page, not buried three clicks deep, and keep a simple version log with the date of each change.

A simple data map is the highest-leverage starting point. Practitioner guidance recommends a single spreadsheet listing systems, data fields, purposes and processors, because it exposes exactly where data sits and which vendors need a data processing agreement before you write a single line of the notice.

Once the map exists, the notice almost writes itself: each row becomes a paragraph, and each processor becomes a line in the recipients section.

Retention, security and breach response

A privacy notice promises things your business then has to do, and the two biggest promises are keeping data only as long as needed and protecting it properly while you hold it.

  • Store only what each purpose actually requires, and set a retention window or a deletion trigger for every data set rather than keeping everything indefinitely.
  • Limit who can access customer and staff records, use strong unique passwords, and keep software patched.
  • Back up data securely and check that backups themselves are protected, not just the live system.
  • Put a data processing agreement in place with any vendor that handles personal data on your behalf, such as a payroll provider or email platform.

Breaches happen even in well-run small businesses, so the real question is whether you can respond fast. GDPR requires controllers to notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach that risks people’s rights and freedoms. A named owner and a simple incident log, recording what happened, when you found out and what you did, are often the difference between hitting that window and missing it.

Pro Tip: Write down, in advance, who in your business is responsible for spotting and reporting a breach. Deciding this after an incident starts always costs you time you do not have.

Templates, tools and next steps

You have three realistic routes to a usable notice: a free template, a form-driven generator, or a solicitor-drafted document. Free templates are fast but generic, and need editing to match your actual data map rather than a hypothetical business. Generators speed this up by asking structured questions, though the output still needs checking against your real processors and retention rules. A solicitor draft costs more but suits businesses handling sensitive data, such as health or financial records, where the stakes of getting it wrong are higher.

Whichever route you choose, check the result covers:

  • Lawful basis mapped to each purpose, not a single blanket basis for everything.
  • Retention periods or deletion triggers specific to your data, not placeholder text.
  • A line on processor agreements for your key vendors.
  • A clear data subject request process with a named contact.

Publish the finished notice as a footer link visible on every page, and keep a short changelog noting the date and nature of each update.

Third-party tools and plugins that handle data on your website

Most small business websites rely on outside tools that process personal data on your behalf, and your privacy notice needs to say so. Website analytics tools, hosting providers, booking widgets and live chat or WhatsApp integrations all count as processors, because they handle data you collect even though you chose and installed them.

Before adding any such tool, check what data it collects, where it stores it and whether a data processing agreement is available. Hosting providers typically offer one as standard; smaller plugin developers sometimes do not, which is worth knowing before you commit to a tool that holds customer data without a clear contract behind it.

Your notice should name the categories of these tools, such as “website hosting”, “analytics” and “booking software”, rather than listing every brand, and should be updated whenever you add or remove a significant one. A contact form that feeds into an email inbox, a WhatsApp enquiry button, and a booking system that stores customer phone numbers are all processing activities that belong in the recipients and purposes sections of your notice, not left out because they feel like plumbing rather than data handling.

Keeping a line in your data map for each tool, noting what it does and whether an agreement is in place, makes it far easier to update the notice accurately whenever your website changes.

Cross-border transfers and cloud services

Many small business tools, from email platforms to accounting software to website hosting, store data on servers outside the EU/EEA, most often in the United States. GDPR allows this only where an appropriate safeguard is in place, such as an adequacy decision covering the destination country, or standard contractual clauses built into the provider’s terms.

In practice, this means checking where your key tools actually host data before assuming it stays local. Most major cloud and software providers address this in their own data processing terms, typically published alongside their privacy policy, and will state which transfer mechanism they rely on.

Your own privacy notice does not need to reproduce the legal detail of each provider’s transfer mechanism. A short, honest line, noting that some processors may store data outside the EU/EEA and that appropriate safeguards are in place, is enough for most small businesses, provided you have actually checked rather than assumed this is true. Where a provider cannot explain its transfer safeguard clearly, that is worth treating as a reason to look at alternatives, particularly for sensitive data such as health or financial records.

Employee and contractor data privacy

Staff and contractor data is personal data too, and the same transparency duties apply to it, separately from your customer-facing notice. Payroll details, bank information, performance reviews, sick leave records and CCTV footage covering a workplace all need to be covered by a notice given to employees, often called a staff privacy notice rather than a public-facing one.

This internal notice should explain what you collect, why (payroll, tax compliance, performance management), how long you keep records after someone leaves, and who sees the data, such as an external payroll provider or accountant. Contractors are often overlooked, but if you hold their bank details, PPS-equivalent tax information or performance notes, the same duties apply.

Employee records linked to notice and access controls

Keep staff and contractor records as tightly scoped as customer data: a retention period tied to tax and employment law requirements, access limited to whoever actually runs payroll or HR, and a clear point of contact if a current or former employee wants to see what you hold on them.

How we help small businesses put a privacy notice on their site

We build privacy basics into every website design rather than treating the notice as an afterthought once the site is live. During a build, privacy notices and straightforward cookie controls are included, and actual data flows, forms, booking setups, and email lists are reviewed to ensure the notice describes what the business really does rather than using a generic template.

That mapping work helps create a notice that matches reality and reduces the back-and-forth when a customer asks what data is held on them. Language is kept plain throughout so the notice reads clearly to customers rather than like one written for a courtroom.

Get a privacy notice live alongside your website

Newbusinesswebsites

A privacy notice only works once it is actually published, linked and kept current, which is exactly the kind of detail that gets missed when you are building a site yourself under time pressure. Our website design service includes a plain-language privacy notice and cookie controls as a standard part of a new build, so the legal groundwork and the website launch happen together rather than as a separate task you come back to later.

If you already have a site and need the privacy basics brought up to standard, our redesign service covers that as part of a rebuild. Check our pricing for current packages, or get in touch to talk through what your site needs.

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

FAQ

What is a privacy policy for a website?

A privacy policy for a website is a notice explaining what personal data the site collects, such as through contact forms or analytics, why it is collected, how long it is kept and what rights visitors have over their own data. It must be concise, transparent and easily accessible under GDPR Article 13.

What are the privacy laws that apply to small businesses?

Small businesses handling personal data of people in the EU/EEA fall under GDPR, which applies based on the processing activity and location of the data subjects rather than company size. National data protection authorities, such as Ireland’s Data Protection Commission, provide additional guidance tailored to smaller organisations.

What are the 10 privacy principles businesses should know?

Different frameworks group privacy principles differently, and there is no single universally agreed list of exactly ten. GDPR itself is built around principles including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability.

What are the core principles of data privacy under GDPR?

GDPR sets out seven core principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Every processing activity a small business carries out should be checked against each of these.

How quickly must a business respond to a data subject request?

A business must normally respond to a data subject access, correction or deletion request within one month of receiving it. This can be extended by a further two months for complex requests, provided the individual is told within the first month and given a reason for the delay.

Sources

WhatsApp