What’s actually mandatory for an SME

Two elements apply to nearly every SME: a privacy policy published on your site (as soon as you collect data, even just via a contact form), and a record of processing activities describing what data you process and why. A small business is only exempt if the processing presents a low risk to the people concerned, which rarely holds once HR or customer data is involved.

Processors (hosting, CRM, HR tools) need a contract

As soon as an external provider processes data on your behalf (hosting, email sending, payroll), a data processing agreement must govern that relationship. Many SMEs discover this obligation only during an audit or a complaint.

What to do in case of a data breach

A leak or unauthorised access to personal data can trigger a duty to notify the Federal Data Protection and Information Commissioner (FDPIC) if it poses a high risk to the people concerned. Having a procedure defined in advance (who does what, within what timeframe) avoids improvising under pressure.

An important note

This guide presents general rules, not individualized legal advice. The required level of compliance depends on the volume and sensitivity of the data you actually process.

For compliance work tailored to your business, see our subscription plans.