GDPR for small businesses

GDPR guidance for small businesses: the requirements in your business

Few companies operate without processing personal data. The General Data Protection Regulation sets out the conditions under which companies may process personal data, for example to perform a contract. It is therefore essential that companies apply and comply with GDPR requirements whenever personal data is processed.

When companies process personal data, they also have a legal duty to understand and reduce the risks associated with that processing and to take measures to safeguard the data. Depending on the business, a range of measures—some more complex than others—may be needed. As complexity varies with your specific circumstances, a thorough understanding of the framework is vital, both to meet GDPR requirements and to avoid making compliance more complicated than necessary for your operations. This is core gdpr guidance for small businesses and highly relevant to gdpr for businesses across sectors.

Illustration of a courthouse and judge’s gavel representing GDPR fines and legal compliance, symbolizing GDPR for small businesses that must follow EU data protection rules.

GDPR fines for companies: what it means for gdpr for small businesses

GDPR infringements can result in significant fines for companies. Administrative fines may be up to the higher of EUR 20 million or 4% of global annual turnover. The amount in an individual case depends on the specific circumstances. The Swedish Data Protection Authority (IMY) may also issue a warning, reprimand or an order, including restrictions or prohibitions. Depending on what has occurred, a fine is not inevitable.

 

The high maximum amounts underline the importance of taking GDPR seriously and implementing robust data protection practices. Beyond financial impact, infringements can damage reputation and erode the confidence of customers and other stakeholders. To reduce the risk of fines, companies should:

  • Train staff in GDPR and data protection.
  • Review technical security measures to protect personal data.
  • Maintain clear processes for handling personal data breaches.
  • Keep a GDPR checklist within the business.
  • Regularly review and update data protection practices.
  • Appoint a person responsible for GDPR within the business.

May companies record calls under GDPR?

Telephone call recording is sensitive from a privacy perspective. A call contains not only the conversation, but also other personal data protected by GDPR such as voice and emotional tone. Calls may also include data the company did not expect to capture, for example health information or other special categories of personal data protected under Article 9 GDPR. More than one person is involved in a call—such as a customer and an employee—and they may have different interests in whether recording is permissible.

These aspects require careful consideration before recording calls. The answer will depend on whether the company can apply the GDPR principles. Companies should consider:

  • Can the data subjects be informed before recording starts?
  • Have we defined a clear purpose for the recording?
  • Is there a lawful basis to record the call, for example consent, legitimate interests or legal obligation?

Consent can appear straightforward as a lawful basis. However, it may not be the most appropriate, as there are strict requirements for valid consent, including that it must be freely given. If consent is not provided, the call must not be recorded.

Some sectors are required by law to record calls, for example parts of the insurance industry. In such cases, legal obligation should be evaluated to confirm it covers the intended recording. Legitimate interests may also be relevant following a balancing test.

Customer support agent on a video call recording client details on a laptop, illustrating GDPR for small businesses and compliant handling of customer data in call centers.

Key steps for call recording under GDPR

When a company plans to record calls, it must ensure that the processing of personal data complies with GDPR. This means taking several concrete steps to address both legal and practical requirements. Key steps include:

  • Inform data subjects that the call will be recorded and why, before recording begins.
  • Establish the lawful basis for recording, for example consent, legitimate interests or legal obligation.
  • Document the purpose of the recording and limit use of recordings to that purpose.
  • Implement safeguards to prevent unauthorised access to recordings.
  • Set procedures to handle requests for access, rectification or erasure of recorded calls.

By following these steps, companies can reduce the risk of infringements while building trust with customers and employees.

Two business professionals connecting puzzle pieces with a padlock icon, symbolizing GDPR for small businesses and how legal experts help implement data protection and privacy compliance.

We support GDPR for small businesses

Our solutions are tailored to your needs. Whether you are a small business tackling your first GDPR question or looking to take the next step with ongoing support, we are ready to help. Our services include:

  • GAP analysis of your current state.
  • Drafting data protection policies and procedures.
  • Advice on lawful bases for personal data processing.
  • Support with personal data incidents.
  • Ongoing advice on GDPR compliance and regulatory monitoring.

Contact Morling Consulting for an initial meeting at no cost. Let us help you not only meet GDPR requirements but also use data protection as a competitive advantage in your business. We operate across Europe.

Common questions and answers on GDPR for businesses

Yes. GDPR applies to all companies that process personal data — regardless of size, sector or scale. There are no exemptions for small businesses. Even if processing is limited, the company must follow the requirements of the Regulation.

GDPR contains a wide range of requirements, and Morling Consulting helps map how they apply in your operations. To comply, companies should, among other things:

  • Identify which types of personal data are processed and why.
  • Ensure the company has a lawful basis for processing.
  • Provide clear information to data subjects, for example via a privacy notice.
  • Ensure technical and organisational measures are implemented commensurate with the risk.
  • Document your personal data processing.
  • Maintain procedures to handle personal data breaches and data subject rights.

A data processing agreement is required where a company engages a third party to process personal data on its behalf.

Example: A company engages an IT provider to store customer data on its behalf. The agreement must regulate responsibilities, security measures, incident reporting and more, in line with GDPR.

It depends on the purpose of the recording and your lawful basis. Before recording, you must:

  • Inform callers that the call will be recorded and why.
  • Choose the correct lawful basis: for example consent, legitimate interests or legal obligation.
  • Avoid collecting special category data unless necessary and you have a lawful basis.

Remember that if your lawful basis is consent, it must be freely given, informed and easy to withdraw.

Consequences can be serious. The Data Protection Authority can issue:

  • Warnings or reprimands.
  • Orders, for example to temporarily or permanently cease specific processing.
  • Administrative fines — up to EUR 20 million or 4% of global annual turnover.

Beyond this, the company risks reduced trust from customers and partners.

Yes. If your company collects personal data via the website — for example through contact forms, newsletters or cookies — you must have an accessible, clear privacy notice. It should explain:

  • What data is collected.
  • For which purposes the data is used.
  • The lawful basis for processing.
  • Which rights the visitor has.
  • How to contact the controller (the company).

It depends on the purpose of processing. Common lawful bases include:

  • Contract — when processing is necessary to perform a contract, for example delivering the service purchased by the customer.
  • Legal obligation — for example processing required to meet accounting requirements.
  • Consent — when the individual actively agrees to the processing.
  • Legitimate interests — when the company’s interests outweigh the individual’s privacy interests and processing is necessary for the purpose.

Selecting the right lawful basis is critical — Morling Consulting’s GDPR lawyers can help assess your specific processing, including gdpr guidance for small businesses and gdpr for businesses with complex vendor landscapes.

It depends on the type of processing you carry out. Under GDPR, a Data Protection Officer is required if:

  • Processing is carried out by a public authority.
  • The company monitors individuals systematically and on a large scale.
  • The company processes special category data on a large scale.

If you are not legally required to appoint a Data Protection Officer, it may still be beneficial to have external data protection support — for example from Morling Consulting.

Yes. If you do not have the right expertise or resources internally, you can appoint an external Data Protection Officer. Morling Consulting can take that role and help to:

  • Monitor GDPR compliance.
  • Act as a contact point with the Data Protection Authority.
  • Advise on data protection matters, including risk assessments and Data Protection Impact Assessments (DPIAs).
  • Support incident response and dialogue with data subjects.
  • Provide regulatory monitoring and ongoing compliance support.

This offers assurance and continuity in data protection without building in-house capacity.

Advice is tailored to each company’s needs and maturity. Examples include:

  • Drafting or updating a privacy notice for your website or app.
  • Reviewing or drafting data processing agreements before starting a new engagement.
  • Support in a personal data incident, for example assessing whether notification to the Data Protection Authority is required.
  • Legal analysis of the appropriate lawful basis for specific processing.
  • GAP analyses and current-state assessments to identify gaps and development areas.
  • Ongoing advice to the Data Protection Officer or leadership team on interpretation and application of GDPR in the business.

Contact us

If you prefer phone, please feel free to contact Felix Morling at +46 70 444 42 85

"*" indicates required fields