Blog
Business30 June 2026 13 min🇩🇰 Denmark

GDPR for small businesses: a practical compliance guide

A practical GDPR guide for small Danish businesses: your obligations, the 7 key requirements, the most common mistakes and a concrete checklist, without legal jargon.

Karoline, Dokumentkonsulent

Written for Danish law and Danish contract practice.

GDPR. Four letters that can make even the most experienced entrepreneur sigh. The General Data Protection Regulation has applied since 2018, but many small Danish businesses are still unsure what they concretely have to do to comply.

The good news? GDPR compliance for a small business does not have to be overwhelming. This guide gives you a practical overview of what you actually need to have in order, without unnecessary legal jargon.

Note: the GDPR is a complex area of law, and the rules can vary depending on your type of business, your industry and the types of personal data you process. This guide gives a general overview but does not replace individual legal advice. If in doubt, consult a data protection officer or lawyer.

What is the GDPR, and does it apply to my business?

The GDPR (General Data Protection Regulation) is the EU's data protection regulation, which governs how businesses collect, store and process personal data. In Denmark the GDPR is supplemented by the Data Protection Act.

Does the GDPR apply to small businesses?

Yes. The GDPR applies to all businesses that process personal data, regardless of size. If you have even one customer, one employee or one email list, you are subject to the GDPR.

It is a common misunderstanding that the GDPR only applies to large companies. There are certain reliefs for businesses with fewer than 250 employees (including on the record-keeping duty), but the basic requirements apply to everyone.

The 7 most important GDPR requirements for small businesses

1. A legal basis for processing

You must have a legal basis to process personal data. The most relevant for small businesses are typically:

  • Consent: the person has given express permission (for example for a newsletter)
  • Contract: the processing is necessary to fulfil an agreement (for example delivering a product)
  • Legitimate interest: you have a legitimate interest that does not override the person's rights (for example marketing to existing customers)
  • Legal obligation: the law requires it (for example the Bookkeeping Act's storage requirements)

Choose the right basis from the start. It can as a rule not be switched partway through for the same processing.

2. Privacy policy (duty to inform)

You have a duty to inform data subjects (customers, employees, website visitors) about how you process their data. A privacy policy must typically contain:

  • Who the controller is (your business name and contact details)
  • Which personal data you collect
  • The purpose of the processing
  • The legal basis
  • Who the data is shared with (processors, authorities)
  • The storage period
  • The data subjects' rights

The privacy policy must be easily accessible, typically via your website.

3. Data processing agreements

If you use external suppliers that process personal data on your behalf, you must have a data processing agreement (DPA) with them. It is a legal requirement under Article 28 of the GDPR.

Typical examples:

  • Email marketing services (Mailchimp, ActiveCampaign)
  • Cloud storage (Google Drive, Dropbox, OneDrive)
  • Accounting programs (Billy, Dinero, e-conomic)
  • CRM systems (HubSpot, Pipedrive)
  • Web hosting and website platforms
  • Payroll bureaus
  • IT support suppliers with access to your systems

Important: many large SaaS suppliers already have a standard agreement you can accept. For Danish suppliers and specialised services you may need to create one yourself.

4. Record of processing activities

The GDPR as a rule requires you to keep a record (Article 30) of your processing activities. Businesses with fewer than 250 employees are as a rule exempt, but the exemption does not apply if the processing:

  • Is not occasional (that is, you process customer or employee data on an ongoing basis)
  • Involves sensitive personal data (health, trade union, religion)
  • May entail a risk to the data subjects' rights

In practice, most businesses with ongoing customer or employee data fall under the first condition and must therefore keep a record, regardless of size. It does not have to be complicated; a simple spreadsheet can be enough.

The record should as a minimum contain:

  • The purpose of the processing activity
  • The categories of data subjects and personal data
  • The recipients of the data
  • Transfers to third countries (outside the EU and EEA)
  • Storage deadlines
  • A description of the security measures

5. The data subjects' rights

Your customers and employees have a number of rights under the GDPR that you must be able to handle:

  • Right of access: they can ask to see what data you have about them
  • Right to rectification: they can ask to have errors corrected
  • Right to erasure ("the right to be forgotten"): they can ask for their data to be deleted
  • Right to data portability: they can ask for their data in a machine-readable format
  • Right to object: they can object to certain types of processing
  • Right to restriction: they can ask for the processing to be restricted

You should have a procedure for handling such requests. The GDPR as a rule requires an answer without undue delay and at the latest within one month (the deadline can be extended in complex cases).

6. Data security

You must take appropriate technical and organisational measures to protect personal data. What is appropriate depends on your business's circumstances and the risk of the processing, but for most small businesses it should as a minimum include:

  • Strong passwords and two-factor authentication (2FA)
  • Encryption of sensitive data
  • Regular backup
  • Access restriction, so only relevant employees have access
  • Updated software and antivirus
  • Secure deletion of data when the storage period expires

7. Data breaches

If a data breach occurs (for example hacking, a lost laptop or a wrongly sent email with personal data), you have a duty to:

  1. Assess the seriousness of the breach
  2. Notify the breach to Datatilsynet within 72 hours, if it entails a risk to the data subjects
  3. Inform the affected people, if the risk is high
  4. Document all breaches, including those that are not notified

Even small businesses should have a simple data-breach procedure ready in advance.

GDPR checklist for small businesses

Basics

  • You have identified which personal data you collect and process
  • You have a legal basis for each type of processing
  • You have an updated privacy policy on your website
  • You inform customers and employees about how you process their data

Data processing agreements

  • You have mapped all suppliers that process personal data on your behalf
  • You have entered into data processing agreements with all relevant suppliers
  • You have checked whether suppliers transfer data to countries outside the EU and EEA

Documentation

  • You keep a record of processing activities
  • You have a procedure for handling requests from data subjects
  • You have a procedure for handling data breaches

Security

  • Two-factor authentication is enabled on all critical systems
  • Only relevant employees have access to personal data
  • You take regular backups of data
  • You delete personal data when there is no longer a purpose for storing it

Consent and cookies

  • Your consent for newsletters and marketing is active and documented
  • Your website has a cookie banner that complies with the rules
  • You do not use pre-ticked boxes for consent

The 5 most common GDPR mistakes among small businesses

1. Missing data processing agreements

Many small businesses use a range of services and suppliers without the necessary data processing agreements. It is one of the most frequent breaches Datatilsynet criticises.

2. No privacy policy, or an outdated one

Your privacy policy must reflect your current practice. A copied template from 2018 that has not been updated can do more harm than good.

3. Storing data "just in case"

The GDPR requires you to store personal data only for as long as there is a purpose. Many businesses keep customer data for years "just in case", which breaches the principles of data minimisation and storage limitation. Set clear storage deadlines for each type of data and ensure regular deletion.

4. Unclear marketing consent

A consent must be freely given, specific, informed and unambiguous. Pre-ticked boxes, hidden terms or vaguely worded consent texts are invalid. Make sure your sign-up flows meet the requirements.

5. No data-breach procedure

Many small businesses have not thought about what to do in the event of a data breach. With a 72-hour deadline for notification to Datatilsynet, it is important to have a plan ready.

Data processing agreements: what you need to know

The data processing agreement is probably the most practical GDPR document for most small businesses.

What must a data processing agreement contain?

Article 28 of the GDPR sets a number of minimum requirements for the content:

  • The purpose and duration of the processing
  • The types of personal data and categories of data subjects
  • The controller's instructions to the processor
  • Security measures (technical and organisational)
  • Terms for the use of sub-processors
  • The processor's duty to assist with the data subjects' rights
  • Deletion or return of data on termination
  • Audit rights for the controller

Who should create the agreement?

It is the controller (typically you as the business owner) who is responsible for ensuring a valid data processing agreement. In practice the agreement can come from either the controller or the processor, but the responsibility lies with you.

Can you use a standard template?

Yes, and it is a good idea for most small businesses. The European Commission has published standard contractual clauses, and Datatilsynet has published guidance material. A standard agreement adapted to your specific needs and meeting the requirements of Article 28 is sufficient for most.

What happens if my business breaches the GDPR?

The consequences can potentially be serious, even for small businesses:

  • Fines: up to EUR 10 million or 2% of global turnover for certain breaches, and up to EUR 20 million or 4% for the most serious (the higher amount applies). In Denmark the fine is imposed by the courts after a police report from Datatilsynet
  • An order from Datatilsynet: a requirement to change or stop a processing activity
  • Compensation claims: data subjects can claim compensation for harm
  • Reputational damage: loss of customer trust

In practice, fines for small Danish businesses are typically far below the maximum amounts, but Datatilsynet has in several cases recommended fines in the order of hundreds of thousands of kroner for smaller businesses. Enforcement practice develops continually, so it is a good idea to keep up to date via Datatilsynet's website.

How to get started: 4 concrete steps

Step 1: map your data

Make a list of all the personal data you collect, store and process. Think broadly: customer data, employee data, supplier contacts, website visitors and newsletter recipients.

Step 2: review your suppliers

Identify all suppliers and services that have access to or process personal data on your behalf. Check whether you have valid data processing agreements with all of them.

Step 3: update your privacy policy

Make sure your privacy policy is complete, correct and easily accessible. It must reflect your actual practice.

Step 4: establish basic procedures

Create simple procedures for handling requests from data subjects (access, erasure, etc.), handling data breaches, and regular review and deletion of data.

Frequently asked questions about the GDPR for small businesses

Is my business too small for the GDPR?

No. The GDPR applies to all businesses that process personal data, whether you are a sole proprietorship, an ApS or an entrepreneur with a webshop. There is no minimum threshold.

Do I need a DPO?

Most small businesses do not need a DPO. The duty applies mainly to public authorities and to businesses that carry out regular and systematic monitoring on a large scale or process sensitive personal data on a large scale. If in doubt, it can be wise to seek advice.

What is the difference between a controller and a processor?

The controller determines the purpose and means of the processing (typically your business). The processor processes data on the controller's behalf (for example your accounting program or your hosting provider).

May I send customer data to services outside the EU?

That requires a valid transfer basis, for example the European Commission's standard contractual clauses (SCCs) or an adequacy decision for the country in question. Many US services are covered by the EU-US Data Privacy Framework, but the rules in this area can change, so always check the current status.

What do I do if a customer asks to be deleted?

You as a rule have a duty to delete personal data when a data subject requests it, unless you have a legal basis for continued storage (for example the Bookkeeping Act requires accounting records to be kept for 5 years). Answer within one month and document your decision.

Does GDPR compliance cost a lot for a small business?

Not necessarily. Most basic GDPR requirements can be met with simple, structured measures: a privacy policy, data processing agreements, a record in a spreadsheet and basic security procedures.

Summary

GDPR compliance for small businesses comes down to three things:

  1. Transparency: be honest about what you do with personal data
  2. Documentation: have the necessary agreements and records in place
  3. Security: protect the data you store

Start with the most basic things: a privacy policy, data processing agreements with your suppliers and a simple record. It does not take long, and it markedly reduces your risk.


The content of this article is for guidance only and does not constitute legal advice. GDPR rules and enforcement practice can change over time. Consult a lawyer or data protection officer for advice on your specific situation.

This article is for general guidance only and is not individual legal advice. LegalDock documents are templates — consult a lawyer about your specific situation.