01

The answer in brief

An SME organizes personal data protection by combining documented technical and organizational measures, from risk assessment to training staff who handle data. The GDPR requires the same level of security regardless of the equipment used, including remote work or personal devices (BYOD).

02

Why responsibility stays with the employer

When an employee uses personal computers, tablets or smartphones to connect to the company network, the employer remains responsible for the security of the personal data processed, even on devices it does not physically or legally control but for which it has authorized access. A dedicated remote-work security policy helps maintain this level of protection.

03

The daily workflow

Steps

  1. Assess risks and document them in a spreadsheet updated regularly, including material and human risks.
  2. Define a binding internal policy describing data protection and security rules.
  3. Secure premises, hardware, software and communication channels with updated firewalls and antivirus.
  4. Manage authorizations with unique identifiers, strong passwords and periodic access reviews.
  5. Encrypt or pseudonymize sensitive data and protect remote work with a dedicated VPN.

04

A concrete example: a bookshop's order form

A bookshop that wants to sell books online designs a standardized order form. The owner makes all fields mandatory, including date of birth, phone number and home address, but not all are necessary: an eBook, for example, can be downloaded directly without a delivery address. Applying data protection by design means limiting collection to what is needed for each specific purpose.

05

Daily checklist for data security

  • Regularly train data handlers on privacy-related risks.
  • Sign confidentiality agreements with employees and other processors.
  • Provide automatic session lock, firewall, updated antivirus and backups.
  • Limit the use of USB devices and external media to what is essential.
  • Secure premises with alarms, protected keys and specific access authorizations.

06

How to set up controls with a software partner

An SME can ask its software partner to configure distinct roles for those who access personal data, traceability of changes and periodic reviews of authorizations, so that the software reflects the same rules set out in the internal policy. This operational choice supports the principle of data protection by design, applied to the company's everyday tools.

07

Frequently asked questions

The most common questions about data protection in daily work are collected below.

08

Next step

Start by creating a spreadsheet for risk management, updated regularly, and use it as the basis to define your internal policy and priority technical measures.

FAQ

Frequently asked questions

Does the security level change if an employee uses a personal device?

No, the GDPR requires the same level of security for personal data regardless of the equipment used, and the employer remains responsible even for authorized BYOD devices.

What should an internal data protection policy contain?

It should be a binding document, integrated into internal regulations, with a clear description of the data protection and security rules applied in the company.

How is data protection by design applied in practice?

It means limiting data collection to what is necessary for each specific purpose, as in the example of the bookshop that does not require an address for a downloadable eBook.

Sources and verification