All questions

GDPR basics for a small business: what am I actually required to do?

Freelance & BusinessLegislation verified on

Short answer

If you run a small business in the Netherlands and process personal data of customers, staff, suppliers or anyone else, the EU General Data Protection Regulation (Algemene verordening gegevensbescherming, AVG) and the Dutch implementing act (Uitvoeringswet AVG, UAVG) apply to you in full. There is no SME exemption from the substantive rules. What you must do, in practice, comes down to six things: have a legal basis for every processing activity, tell people what you do with their data, honour their rights, keep records (with a partial exception for very small occasional processing), secure the data, and report serious breaches to the Autoriteit Persoonsgegevens (AP) within 72 hours.

Reasoning

1. Does the AVG actually apply to a small business?

The AVG applies to any "controller" (verwerkingsverantwoordelijke) and "processor" (verwerker) that processes personal data in the context of an establishment in the Netherlands, or that targets people in the Netherlands (see Art. 3 AVG and Art. 4 UAVG on territorial scope). There is no minimum turnover, employee count or data volume below which the AVG stops applying. The only place where size matters is in the proportionality of supervision: Art. 2a UAVG requires the AP to take "the specific needs of small, medium-sized and micro-enterprises" into account when applying the regulation (source: https://wetten.overheid.nl/jci1.3:c:BWBR0040940&artikel=2a&g=2026-08-27). That is a soft duty, not an exemption.

2. What you must always do

ObligationWherePractical meaning for a small business
Lawful basis for every processingArt. 5(1)(a) and Art. 6 AVGPick one of six grounds: consent, contract, legal obligation, vital interests, public task or legitimate interests. Document the choice.
Inform data subjectsArt. 13 AVG (collected from the person) and Art. 14 AVG (collected elsewhere)Publish a privacy statement (privacyverklaring) on your website with your identity, contact details, purposes, legal basis, recipients, retention period and data-subject rights.
Honour data-subject rightsArt. 15–22 AVGRespond to requests for access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21) within one month (Art. 12(3) AVG).
Data protection by design and by defaultArt. 25 AVGUse the least intrusive settings and only process what you need.
SecurityArt. 32 AVGPseudonymisation, encryption, access control, backups, secure development; pick measures proportionate to the risk.
Breach notificationArt. 33 AVG (to AP within 72 hours) and Art. 34 AVG (to the people affected if the risk is high)Have a process in place before something happens.

3. Where small businesses get a partial break

  • Records of processing activities (Art. 30 AVG). The obligation to keep a verwerkingsregister does not apply to an enterprise with fewer than 250 employees unless the processing is likely to result in a risk to data subjects, is not occasional, or involves special-category data or criminal-conviction data (Art. 30(5) AVG). For most small businesses that run a customer database, payroll, or any online tracking, at least one of those carve-outs is triggered, so in practice you will need a register.
  • Data Protection Officer (Art. 37 AVG). You only have to appoint a Functionaris voor de gegevensbescherming (FG) if your core activities consist of large-scale monitoring of individuals or large-scale processing of special-category data, or if Dutch or EU law requires it. A typical shop, consultancy or tradesman is not required to appoint one, but may do so voluntarily.
  • Data Protection Impact Assessment (Art. 35 AVG). A gegevensbeschermingseffectbeoordeling (DPIA) is only mandatory where processing is "likely to result in a high risk" (e.g. systematic profiling, large-scale monitoring of public spaces, processing of sensitive data). Most small businesses fall outside this.

4. Dutch specifics from the UAVG

  • Age for consent. Where the AVG lets Member States choose between 13 and 16 for the consent of a child in information-society services (Art. 8 AVG), the Netherlands sets the age at 16 in Art. 5(1) UAVG. Below that age, the legal representative must consent (source: https://wetten.overheid.nl/jci1.3:c:BWBR0040940&artikel=5&g=2026-08-27). The Art. 5(5) UAVG carve-out for direct, free child-line services still applies.
  • Special-category data. Processing of data revealing race, political opinions, religion, trade-union membership, genetic data, biometric identification data, health data, or data on sexual behaviour or orientation is in principle prohibited (Art. 9(1) AVG, mirrored in Art. 22(1) UAVG) with limited exceptions listed in Art. 22(2) UAVG and elsewhere.
  • Criminal-conviction data. Outside the public sector, you may only process these in narrow situations (e.g. to protect your own interests against offences committed against you or your staff), see Art. 33 UAVG.
  • BSN. The Burgerservicenummer (BSN) may only be used where a Dutch law obliges or expressly permits it (Art. 46 UAVG); this matters for payroll and invoicing with the tax office.
  • Supervisory authority and enforcement. The AP is the lead regulator (Art. 14 UAVG). It can issue a last onder bestuursdwang (Art. 16 UAVG) and administrative fines up to the ceilings in Art. 83 AVG (EUR 20 million or 4 % of worldwide annual turnover for the gravest breaches, EUR 10 million or 2 % for the others).

5. A pragmatic minimum for a typical small business

  1. Map the personal data you actually process (customers, prospects, staff, suppliers) and the purpose for each flow.
  2. Write a short, plain-language privacy statement on your website that satisfies Arts. 13 and 14 AVG.
  3. Make sure you have a lawful basis under Art. 6 AVG for each activity, and use consent only where it really is freely given, specific, informed and unambiguous (Art. 4(11) and Art. 7 AVG).
  4. Draw up a verwerkingsregister (Art. 30 AVG) — for most small businesses this is mandatory in practice.
  5. Put basic security in place: strong unique passwords, two-factor authentication, encryption at rest and in transit, role-based access, backups, an up-to-date patch policy (Art. 32 AVG).
  6. Prepare a breach playbook so that a personal-data breach can be reported to the AP within 72 hours of becoming aware (Art. 33 AVG) and to affected individuals where the risk is high (Art. 34 AVG).
  7. Train staff who handle personal data, and keep records of that training.

6. The main exceptions to be aware of

  • Purely personal or household activity (Art. 2(2)(c) AVG) — a freelancer's private address book does not count, but any business use does.
  • Anonymous data is outside the AVG entirely; if you strip identifiers so re-identification is not reasonably possible, the rules stop applying (recital 26 AVG).
  • Occasional, low-risk processing by a sub-250-employee business that touches no special categories — this is the only meaningful carve-out and only affects the records-of-processing duty (Art. 30(5) AVG).

7. Where this article leaves off

This overview covers the typical small-business case. If you carry out large-scale profiling, systematic monitoring, processing of health, biometric or children's data, or operate across borders, additional obligations kick in (DPIA under Art. 35 AVG, FG under Art. 37 AVG, representative under Art. 27 AVG, etc.), and Dutch sector-specific rules may add further conditions.


This article is general information, not legal advice. For a binding opinion on your situation, consult a qualified Dutch privacy lawyer or contact the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

Sources cited