GDPR Policy Generator for small businesses
Written for a website, a contact form, a mailing list and a card machine - and nothing more elaborate.
Small-business GDPR is mostly about the Article 30 exemption that people assume applies to them and usually does not. The under-250 carve-out falls away where processing is regular, which describes every business with a customer list.
Small businesses are subject to the same transparency obligations as large ones, and they usually meet them with a copied policy that describes a company they are not. The result is a document that names cookies the site does not set, promises procedures nobody runs, and misses the one thing the business actually does with personal data.
The realistic processing set for a small business is short: enquiries through a form or an inbox, a customer list for invoicing, a mailing list if there is one, card payments through a terminal or gateway, and a website with analytics. Describing those five things accurately produces a better document than any template.
The obligations people underestimate are the ones outside the privacy policy: the ICO registration fee in the UK, retention of accounting records, and the fact that CCTV on business premises is processing with its own signage and access requirements.
What a GDPR policy for a small business has to cover
Why the Article 30(5) exemption does or does not apply to you, recorded either way
A short processing record covering enquiries, customers, marketing and CCTV
Processor terms with your accounting, email and website providers
The ICO fee position for UK businesses, which is separate from everything else here
A breach procedure proportionate to the business but capable of meeting 72 hours
How a small business actually moves personal data
Enquiries by form, email and phone
Name and contact details held in an inbox indefinitely unless someone decides otherwise.
Customer records and invoicing
Held in accounting software, retained for statutory periods.
Mailing lists
Often built informally from customers and enquiries, with no consent record behind them.
Card payments
Through a terminal or online gateway, with the provider handling card data.
Website analytics
Usually Google Analytics, installed once and never revisited.
CCTV on premises
Processing of images of identifiable people, with signage and retention duties attached.
Third parties the draft will ask you about
Xero, QuickBooks or Sage · SumUp, Zettle or Stripe · Google Workspace or Microsoft 365 · Mailchimp · a website host · a CCTV provider
The rules that apply
Transparency regardless of size
No small-business exemption in UK or EU data protection law. The obligations follow the processing.
ICO registration in the UK
Most businesses processing personal data by automated means must pay the annual data protection fee.
Marketing consent rules
PECR and equivalents apply to a mailing list of fifty as much as to one of fifty thousand.
CCTV and premises monitoring
Processing with its own signage, retention and subject access implications.
Accounting record retention
Statutory periods that justify keeping some customer data after the relationship ends.
What the generated GDPR policy contains
Article 13 and 14 transparency notice
The full disclosure set, split by whether the data came from the person or from somewhere else.
Lawful basis register
Every processing activity mapped to one of the six bases, with the legitimate interests assessment written down where you rely on that basis.
Records of processing (Article 30)
The internal register a supervisory authority can ask for at any time, covering purposes, categories, recipients, transfers and retention.
Data subject rights procedure
How a request arrives, how identity is verified, who handles it, and the one-month clock with its two-month extension.
International transfer mechanism
Adequacy, SCCs with a transfer impact assessment, or the UK IDTA/addendum - named per destination, not asserted in general.
Breach detection and 72-hour notification
The internal escalation path, the assessment test, and the template for notifying the regulator and, where required, the individuals.
Processor and sub-processor controls
Article 28 terms, the sub-processor list, and the change-notification commitment your customers will ask for.
A realistic small-business checklist
List what you actually collect
Enquiries, customers, mailing list, payments, website, CCTV. Five or six lines.
Write the policy from that list
Rather than editing someone else’s.
Pay the ICO fee if you are UK-based
And set an annual reminder.
Fix the mailing list
Suppress anything you cannot evidence and re-collect consent.
Add a cookie notice if you run analytics
And make it actually block until consent.
Set retention for enquiries and CCTV
And apply it.
Where this usually goes wrong
A copied policy describing tools you do not use
The most common small-business failure, and easy for anyone to spot.
A mailing list built without consent records
Adding customers to a newsletter because they bought something is only permitted under narrow soft opt-in conditions.
Not paying the ICO fee
A separate legal duty from anything in the policy, checked against a public register.
Enquiry emails kept forever
There is no purpose after the enquiry is closed and any follow-up window has passed.
CCTV with no notice or retention rule
Signage is required, and footage kept indefinitely is difficult to justify.
Analytics running with no cookie notice
A small site with GA4 and no banner is the single most common finding in the UK.
Frequently asked questions
Does a small business need a privacy policy?
Yes if it processes personal data, which a contact form or a customer list already does. There is no exemption based on size or turnover in the UK or EU.
Do I need to register with the ICO?
Most UK businesses processing personal data by automated means do. The fee is tiered by size and turnover and is enforced separately from other obligations.
Can I email past customers about offers?
Only under the soft opt-in - your own similar products, to someone who bought from you, with an opt-out offered at the time and in every message - or with consent.
Do I need a cookie banner for a small website?
If it runs analytics or any third-party embed, in the UK and EU yes, and it needs to hold those tags until consent is given.
Does GDPR apply to a business outside the EU?
Yes, where you offer goods or services to people in the EU or monitor their behaviour. Article 3(2) is about where the person is, not where you are - and Article 27 may also require you to appoint an EU representative.
What is the difference between EU GDPR and UK GDPR?
The text is nearly identical, but they are separate laws with separate regulators, separate fine ceilings in different currencies, and separate transfer regimes. A business serving both needs both named, not "GDPR" as shorthand.
Do I need a Data Protection Officer?
Only where your core activities involve large-scale regular monitoring or large-scale special-category data, or you are a public authority. Many businesses do not need one - but if you do not have one, say who is accountable instead.
Is a GDPR policy the same as a privacy policy?
No. The privacy policy is the outward-facing notice. The GDPR policy set is the internal machinery - lawful basis register, ROPA, rights procedure, breach plan - that lets you answer a regulator when they ask how the notice is honoured.
GDPR Policy Generator for small businesses
Answer a short questionnaire and get a draft written for a small business. Free to start, no card required.
Generate your GDPR policyOther documents a small business needs
Each one is written for the same context, not a generic template.
The same document, by business type
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.