01

Three roles, one shared responsibility

An SMB manages personal data effectively when it distributes clear tasks among those who lead the organisation, those who process data in day-to-day operations (the "data handlers"), and those who use personal devices for work. The GDPR requires the same level of security regardless of the equipment used, and the employer remains responsible for data security even when data resides on devices it does not own but has authorised to access company resources.

02

What personal data is and who processes it

Personal data means any information relating to an identified or identifiable person: name, phone number, email address, purchase history, photos, or voice recordings are examples that allow direct or indirect identification. Recognising which business activities process this data - hiring, payroll, badge management, customer lists - is the first step in assigning precise responsibilities.

03

The role-based procedure

Steps

  1. The organisation's leader maps the activities that process personal data and maintains the record.
  2. For each activity, the record notes purpose, categories of data, recipients, transfers outside the EEA, retention period, and security measures.
  3. Data handlers report to management the personal devices used to access the company network.
  4. Management updates a risk-management sheet with identified material and human risks.
  5. The leader organises periodic awareness sessions for data handlers on privacy risks.

04

Hypothetical example: a personal device in a sales team

Hypothetical example: in a forty-person company, a sales employee uses their own tablet to consult the customer list. The organisation's leader verifies that the device is protected by authentication and encryption, and that the employee has signed a confidentiality agreement, since the required security level is identical to that of a company computer.

05

Minimum controls to activate

  • Regularly inform and train data handlers on privacy risks.
  • Define a binding internal data protection policy.
  • Apply data minimisation: process only what is necessary.
  • Manage permissions with unique identifiers and periodic access reviews.
  • Protect personal devices used for work (BYOD) with encryption and VPN.

06

How a software partner can support these roles

A company can ask its software partner to configure distinct roles for those who administer the record of processing activities, those who process data in daily operations, and those who carry out periodic reviews, so that every activity remains traceable and assigned to an identified person. Choosing tools that allow recording purposes, categories of data, and retention periods for each activity supports orderly record-keeping.

07

Points to clarify with the team

The record of processing activities is the responsibility of the organisation's leader and must be available to the supervisory authority on request.

Organisations with fewer than 250 employees do not need to mention purely occasional activities in the record, such as a shop-opening event.

08

Next step

Start mapping processing activities by assigning a responsible person to each, and plan the first awareness session for data handlers.

FAQ

Frequently asked questions

Who is responsible for the record of processing activities in an SMB?

The record falls under the responsibility of the organisation's leader and must be available to the data protection authority of the EEA country if requested.

What must each entry in the record of processing activities contain?

Purpose of processing, categories of data, recipients, any transfers outside the EEA, retention period, and a general description of the security measures adopted.

How is the security of personal devices used for work (BYOD) managed?

The GDPR requires the same security level as company devices: authentication, encryption, and, for remote work, a dedicated VPN protect the data processed.

Sources and verification