01
Short answer
An SMB manages personal data effectively by combining organisational and technical measures: raising awareness among data handlers, defining a binding internal policy, classifying confidential information, controlling access and maintaining a record of processing activities. These controls reduce risks to the confidentiality, integrity and availability of data, from credential theft to a full compromise of the information system.
02
What personal data is and why controls matter
Personal data means any information relating to an identified or identifiable person: name, phone number, email address, browsing or purchase history, photos and audio recordings. Even a customer code or a booking reference can indirectly identify a person.
The risks to manage range from an occasional attack on data confidentiality to a full compromise of the information system through intrusion or malware. The employer remains responsible for data security even when data is processed on personal devices (BYOD) to which access to the company network has been authorised.
03
How to build the controls step by step
Steps
- Create a spreadsheet for risk management covering servers, computers and premises, updating it regularly.
- Raise awareness among data handlers through information sessions, periodic updates and internal communications.
- Document operating procedures in clear language, adapted to each category of data handlers.
- Define a binding internal policy describing data protection and security rules.
- Build and maintain the record of processing activities with purposes, categories of data, recipients and retention periods.
04
Hypothetical example
Hypothetical example: an SMB with 40 employees allows remote work on personal devices. To align the security level with company tools, the business installs a VPN, requires authentication with a unique identifier, encrypts sensitive data, and removes access rights that are no longer needed during a periodic review of profiles.
05
Practical checklist
- Regularly train data handlers on privacy-related risks and sign confidentiality agreements.
- Apply data protection by design and data minimisation.
- Classify confidential information and mark documents and emails containing special categories of data.
- Manage unique identifiers, strong passwords and authentication for access to IT systems.
- Pseudonymise or encrypt data and physically protect premises with controlled access.
06
How to set up controls in a management software
A business can ask its software partner to configure a digital record of processing activities that tracks purposes, categories of data, recipients and retention periods, with responsibility assigned to the organisation's controller. This is a suggested operational choice, not an automatic software requirement.
Likewise, separate access roles, change logs and periodic review of permissions can be set up as a documented internal procedure, so the record remains available to the competent supervisory authority on request.
07
Frequently asked questions about controls
The most common questions concern who must keep the record, how to handle personal devices and when an impact assessment is needed: concise answers are gathered below in the dedicated FAQ.
08
Next step
Start by building the risk management spreadsheet and the record of processing activities, then plan an awareness session for data handlers within the next quarter.
FAQ
Frequently asked questions
Who is responsible for the record of processing activities?
The record falls under the responsibility of the organisation's controller and must be made available to the competent data protection authority of the EEA country, if requested.
Do employees' personal devices require the same level of security as company computers?
Yes: the GDPR requires the same level of security for personal data regardless of the equipment used, and the employer remains responsible even on devices it does not directly control.
Must smaller organisations record every occasional activity?
No: organisations with fewer than 250 employees do not need to mention purely occasional activities in the record, such as data processed for a one-off event.
✓