GDPR compliance strategies: the three that work for a small company, and the two that do not

Strategy is a grand word for what is really a sequencing question: with limited time, what do you do first. For a company of five to two hundred people with no privacy team, three sequences work and two waste the year. This page is which, and why.

Works: collect less

Every obligation in the regulation is proportional to what you hold. A field you do not collect needs no lawful basis, no retention period, no disclosure and no search when a request arrives. Deleting a form field is the cheapest compliance work available and the only kind that reduces the total permanently.

Works: write the record of processing first

Article 30 asks for a record of processing activities, and it is usually treated as paperwork to be done last. Done first it is a map: it tells you what you hold, why, who receives it and how long you keep it, which are the inputs to the privacy policy, the vendor list and the request search. Everything else is faster once it exists.

Works: make one request route real

Pick the route, publish it, and walk a fake request through end to end. The walk-through finds the systems nobody remembered, and it converts an untested claim into a rehearsed process. Do it before the first real request rather than during.

Does not work: buying the platform first

A privacy platform automates a process you have. It cannot tell you where your data is, and configuring one before the record of processing exists means paying to encode guesses. Buy after the map, not instead of it.

Does not work: the gap assessment with no owner

A hundred-row spreadsheet of findings with no name against any row produces nothing except the feeling that something has been done. Three findings with an owner and a date beat a hundred without, and the honest version of a gap assessment ends by deleting most of its own rows as not this year.

Questions people ask about gdpr compliance strategies

Where does a small company actually start?

The record of processing. It is the artefact every other obligation reads from, and it is a morning's work with a spreadsheet if you keep it to systems rather than fields.

Do we need a data protection officer?

Only in specific cases: public authorities, large-scale regular monitoring, or large-scale processing of special categories. Most small companies do not, and appointing one you do not need creates an obligation you then have to staff.

Does GDPR reach a US company at all?

It can, where you offer goods or services to people in the EU or monitor their behaviour there. Having EU customers is the usual route in, and having EU website visitors alone usually is not.

Sources

Related answers

Keep the request record: $10 a monthStart the request record