01
The short answer
An SME organizes data protection by combining organizational measures (internal policies, training, document classification) with technical measures (authentication, encryption, antivirus, backups), applying data protection by design and by default to every new processing activity.
02
Why it matters
Data breaches can cause financial loss, fines and a drop in customer trust, and may require notifying the national authority or the affected individuals. The employer remains responsible for the security of personal data even when employees use personal devices (BYOD) to access the company network, because the security level required by the GDPR is the same regardless of the equipment used.
03
The practical workflow
Steps
- Map material and human risks related to servers, computers and premises in a regularly updated log.
- Train data handlers on privacy risks and the measures adopted, with periodic awareness sessions.
- Define a binding internal policy describing data protection and security rules.
- Apply data protection by design, limiting the data processed to what is necessary for the purpose.
- Secure workstations, communication channels, paper documents and premises with appropriate technical measures.
04
Hypothetical example
Hypothetical example: a bookshop wants to sell books online and creates an order form. If it makes date of birth, phone number and address mandatory for every purchase, it processes more data than necessary: for a directly downloadable eBook, these fields aren't needed. By applying protection by design, the bookshop would limit mandatory fields to what is actually required to deliver the purchased product.
05
Organizational and technical checks to verify
- Automatic session lock, firewall and up-to-date antivirus on workstations.
- A confidentiality agreement or clause signed with employees and other data handlers.
- Data stored on network storage with regular backup, not just on workstations.
- Access permissions reviewed periodically and removed when no longer needed.
- A dedicated security policy for remote work and protection of personal devices (BYOD).
06
What a company can configure with software support
A company can ask its software partner to track who has access to which data, with unique identifiers per user and a log of permissions granted and revoked. It's useful to have distinct roles for those who manage, review and approve data access, and a documented periodic review process to remove permissions that are no longer needed, in line with the risk management practices described in the EDPB guide.
07
Operational recipe in 4 steps
Steps
- Assign each user a unique identifier and require authentication to access systems.
- Document operating procedures in clear language, adapted to each category of data handler.
- Classify sensitive documents and clearly mark those containing special categories of data.
- Periodically review the risk log and revise measures when processing changes.
08
Next step
Start by creating a simple risk log for your company's systems and premises, then plan the first awareness session for data handlers.
FAQ
Frequently asked questions
Who is responsible if an employee uses a personal device to work?
The employer remains responsible for the security of personal data even when it is on devices not directly controlled by the employer, provided access to company resources was authorized.
What does data protection by design mean?
It means embedding data protection measures and safeguards into every stage of processing, and by default handling only the data necessary for the specific purpose.
What basic technical measures are needed for workstations?
Automatic session lock, a firewall with limited ports, up-to-date antivirus, and data storage on network space with regular backup.
✓