GDPR SolicitorMary Molloy Solicitors · Dublin

GDPR for Small Business: Compliance Without the Panic

What a small Irish business actually has to do — proportionate, practical, and considerably less than the consultants implied in 2018.

The GDPR applies to the corner pharmacy and the multinational alike, but it applies proportionately: what compliance looks like scales with the risk and volume of the processing. A small business that knows what data it holds, why, and for how long — and can answer a customer's request without panic — is most of the way there.

This guide covers the practical core for Irish SMEs: the documents worth having, the rules that actually bite (marketing, CCTV, staff data, breaches), and the requests you must be able to handle. It is general information; a compliance review for your specific operation is the tailored version.

Know your data: the mapping exercise

Everything starts with a simple inventory: what personal data do you hold (customers, staff, suppliers, CCTV, marketing lists), where does it live (systems, cloud services, filing cabinets, phones), why do you hold it, and how long do you keep it. For most SMEs this is an afternoon's honest work, and it becomes your record of processing activities — the accountability document the DPC asks for first.

The exercise reliably surfaces the same findings: data kept forever for no reason, personal data in personal email accounts and WhatsApp, and marketing lists of unclear origin. Fixing those three findings is often the bulk of real-world compliance.

Lawful bases, in plain terms

Every use of personal data needs one of six lawful bases. For SMEs, four do nearly all the work: contract (processing needed to serve your customer), legal obligation (payroll, tax and employment records), legitimate interests (ordinary business operations, security, some marketing — with a balancing test), and consent (where you genuinely offer a free choice, principally electronic marketing).

The classic error is defaulting everything to consent — consent can be withdrawn, must be demonstrable, and is usually the wrong basis for things you need to do anyway. Match the basis to the reality of each purpose once, write it down, and the question stops recurring.

The documents worth having

Four documents cover most SMEs: a privacy notice on your website and at collection points, in plain language, saying what you collect, why, on what basis, retention, and rights; a record of processing activities (the mapping above, kept current); a short data protection policy for staff — including what to do when a request or breach arrives; and processor agreements with the services that handle data for you (payroll bureau, cloud software, IT support, marketing platform). Reputable providers offer their processor terms as standard; the task is checking they exist and filing them.

Marketing, CCTV and staff: where SMEs get caught

Electronic marketing runs under the ePrivacy rules alongside the GDPR: unsolicited marketing email and SMS to individuals needs consent, with a limited existing-customer exception for your own similar products where an opt-out was offered at collection and in every message. Bought-in lists are where trouble lives.

CCTV needs signage, purpose, and retention discipline (see our CCTV guide). Staff data needs the same discipline as customer data plus employment law retention periods — and staff access requests, which arrive precisely when relations sour, are answered from the file you kept, however you kept it.

Requests and breaches: the two fire drills

Two events test SME compliance in real time. An access request: one-month deadline, everything about the person across your systems, exemptions applied properly — our access request guide shows what the requester has been told to expect. A breach: contain, assess risk, notify the DPC within 72 hours unless risk is unlikely, tell affected people if risk is high, and document everything — our breach response guide and checklist tool walk the sequence.

The preparation for both is the same mapping exercise from the start of this page: you cannot retrieve, or assess the exposure of, data you never knew you held.

What about a DPO?

Most SMEs do not need a statutory Data Protection Officer — the mandatory triggers are public authorities, large-scale regular and systematic monitoring, and large-scale processing of special category data. What every business needs is an identified person who owns the topic. If you appoint a voluntary DPO, the statutory independence rules attach, so many SMEs sensibly designate a data protection lead instead.

Frequently asked questions

Does GDPR really apply to my small business?

Yes — but proportionately. A small operation's compliance is a mapping exercise, a handful of documents, marketing discipline and the ability to handle requests and breaches. It is a bounded task, not an ongoing consultancy engagement.

Do I need consent for everything?

No — consent is one of six bases and usually the wrong one for core operations. Contract, legal obligation and legitimate interests carry most business processing; consent belongs mainly to electronic marketing.

Do I need a Data Protection Officer?

Almost certainly not as a statutory matter — the mandatory triggers involve public authorities and large-scale monitoring or special category processing. Designate a responsible person without the statutory DPO title unless a trigger genuinely applies.

Can I email my customer list with offers?

Your own customers, for similar products, where an opt-out was offered when you collected the address and appears in every message — generally yes under the existing-customer exception. Beyond that, electronic marketing to individuals needs consent, and bought-in lists are high risk.

What happens if I get an access request?

The one-month clock starts: identify everything you hold about the person across systems, apply exemptions properly (other people's data, privileged material), and respond with the copy and the supporting information. A current data map turns this from crisis into procedure.

Related pages

Talk to a GDPR solicitor

Mary Molloy Solicitors acts for individuals and organisations across Ireland on data protection matters — access requests, breaches, compensation claims, complaints and compliance. All enquiries are handled through our Dublin office.

Contact us — 01 5827148

This page contains general information about Irish law and practice. It is not legal advice, it may not reflect your circumstances, and reading it does not create a solicitor–client relationship with Mary Molloy Solicitors. We do not advise on taxation; please speak to your accountant or Revenue. In contentious business, a solicitor may not calculate fees or other charges as a percentage or proportion of any award or settlement.