GDPR for a small business | White Eagles & Co.

GDPR for a small business: what you actually need on your website

Two beliefs cost small companies the most here: "we are too small for this" and "we have a privacy policy, so we are covered". Neither survives contact with an actual inspection.

Below is what genuinely applies to a small business, what has to be on the site, what belongs outside it, and where people get caught.

Shall we talk about your project?

Send a few lines about what you need. I reply within 24 hours, no obligation.

There is no size threshold

The first misconception: "there are three of us, this does not concern us." It does. GDPR applies to anyone processing personal data, regardless of size.

A relief for organisations under 250 people exists — it exempts them from keeping processing records. But even that falls away when processing is regular. An enquiry form on your site working every day is regular processing. So the relief most likely does not apply to you.

The good news: for a small company those records are a one-page table, not a volume.

What personal data means in your case

Practically anything a person can be identified by:

  • name, email, phone from an enquiry form
  • IP address and cookie identifiers
  • session recordings in tools like Microsoft Clarity
  • chat conversations on the site
  • invoicing details

The last one often surprises people: data you are obliged to keep for accounting is still personal data, simply with a different legal basis and a different retention period.

The minimum set on the site

A privacy policy. A page of its own stating:

  • who processes the data — company name, IČO, address, contact
  • what data and for what purpose
  • on what basis — consent, contract, legal obligation or legitimate interest
  • how long it is kept
  • who it is shared with — analytics, mailing, hosting providers
  • what rights the person has and how to exercise them

Correct forms. In every form where you collect contacts:

  • the consent box is not pre-ticked
  • a link to the privacy policy sits next to it
  • only what you genuinely need is collected

That last point is the most underrated. Every unnecessary field is both a legal risk and a lost enquiry: the longer the form, the fewer people complete it. Here the law and common sense point the same way.

A cookie banner, if analytics or advertising is present. That is a topic of its own — the cookie banner in 2026.

The company's mandatory details. Formally a separate requirement, but inspections tend to look at everything at once — the full list.

Is your cookie banner compliant?

A custom solution with Consent Mode v2, without a monthly plugin subscription.

What is needed outside the site

Processing records. A table: what data, why, on what basis, how long, who it goes to. For a small company that is one page.

Contracts with providers. Hosting, mailing service, CRM, accountant — they all process your data, and each needs a processing agreement. With large services this is handled by accepting terms in the account; nothing separate to sign.

A breach procedure. A simple instruction: who to call, what to check, who notifies the supervisory authority. Inventing it during an incident is a bad idea, and the deadline is only 72 hours.

A procedure for requests. A person has the right to learn what data you hold and to demand its deletion. You have to answer within a deadline, and it helps to know in advance where that data lives.

Where people get caught most often

A pre-ticked consent box. Consent must be an active action. A box ticked by default is not consent.

Analytics running before consent. The most widespread technical error. The banner is displayed while the tracker has already fired.

A form collecting more than it needs. Date of birth, address, employer — "just in case". If the data is not needed to perform the contract, it should not be in the form.

A policy copied from another company, complete with their name and their services. An inspector sees it at once.

Data kept forever. Three-year-old enquiries sitting in email and CRM with no retention limit. Storage has to have an end.

Mailing everyone on the list. Writing to existing clients about something similar is permitted; writing to new contacts requires consent.

Step by step

  1. List everywhere personal data ends up: forms, email, CRM, accounting, analytics.
  2. For each source define the purpose, the legal basis and the retention period.
  3. Write a privacy policy for your actual situation rather than copying one.
  4. Check the forms: no pre-ticked boxes, a link to the policy, no unnecessary fields.
  5. Check the cookie banner — does anything load before consent?
  6. Collect the processing agreements from your providers.
  7. Write down the breach procedure.

Steps one, two and seven are organisational and worth discussing with a lawyer if your processing is unusual. Steps three to five are work on the website.

If you need the technical part

I set up forms that ask only for what is needed, a cookie banner that actually blocks what it should before consent, and analytics that keeps working afterwards. Details on the cookie consent service page.

I have lived in Slovakia for over ten years, work as a Slovak s.r.o. and issue a faktúra with an IČO.

Related: the cookie banner in 2026 and mandatory website details.

Want to know what is holding your site back?

I go through it the way Google sees it and send a concrete list within 3 working days.