By business type

GDPR Policy Generator for small businesses

Written for a website, a contact form, a mailing list and a card machine - and nothing more elaborate.

Generate your GDPR policy Read the GDPR policy guide

Small-business GDPR is mostly about the Article 30 exemption that people assume applies to them and usually does not. The under-250 carve-out falls away where processing is regular, which describes every business with a customer list.

Small businesses are subject to the same transparency obligations as large ones, and they usually meet them with a copied policy that describes a company they are not. The result is a document that names cookies the site does not set, promises procedures nobody runs, and misses the one thing the business actually does with personal data.

The realistic processing set for a small business is short: enquiries through a form or an inbox, a customer list for invoicing, a mailing list if there is one, card payments through a terminal or gateway, and a website with analytics. Describing those five things accurately produces a better document than any template.

The obligations people underestimate are the ones outside the privacy policy: the ICO registration fee in the UK, retention of accounting records, and the fact that CCTV on business premises is processing with its own signage and access requirements.

What a GDPR policy for a small business has to cover

How a small business actually moves personal data

Enquiries by form, email and phone

Name and contact details held in an inbox indefinitely unless someone decides otherwise.

Customer records and invoicing

Held in accounting software, retained for statutory periods.

Mailing lists

Often built informally from customers and enquiries, with no consent record behind them.

Card payments

Through a terminal or online gateway, with the provider handling card data.

Website analytics

Usually Google Analytics, installed once and never revisited.

CCTV on premises

Processing of images of identifiable people, with signage and retention duties attached.

Third parties the draft will ask you about

Xero, QuickBooks or Sage · SumUp, Zettle or Stripe · Google Workspace or Microsoft 365 · Mailchimp · a website host · a CCTV provider

The rules that apply

Transparency regardless of size

No small-business exemption in UK or EU data protection law. The obligations follow the processing.

ICO registration in the UK

Most businesses processing personal data by automated means must pay the annual data protection fee.

Marketing consent rules

PECR and equivalents apply to a mailing list of fifty as much as to one of fifty thousand.

CCTV and premises monitoring

Processing with its own signage, retention and subject access implications.

Accounting record retention

Statutory periods that justify keeping some customer data after the relationship ends.

What the generated GDPR policy contains

A realistic small-business checklist

  1. List what you actually collect

    Enquiries, customers, mailing list, payments, website, CCTV. Five or six lines.

  2. Write the policy from that list

    Rather than editing someone else’s.

  3. Pay the ICO fee if you are UK-based

    And set an annual reminder.

  4. Fix the mailing list

    Suppress anything you cannot evidence and re-collect consent.

  5. Add a cookie notice if you run analytics

    And make it actually block until consent.

  6. Set retention for enquiries and CCTV

    And apply it.

Where this usually goes wrong

A copied policy describing tools you do not use

The most common small-business failure, and easy for anyone to spot.

A mailing list built without consent records

Adding customers to a newsletter because they bought something is only permitted under narrow soft opt-in conditions.

Not paying the ICO fee

A separate legal duty from anything in the policy, checked against a public register.

Enquiry emails kept forever

There is no purpose after the enquiry is closed and any follow-up window has passed.

CCTV with no notice or retention rule

Signage is required, and footage kept indefinitely is difficult to justify.

Analytics running with no cookie notice

A small site with GA4 and no banner is the single most common finding in the UK.

Frequently asked questions

Does a small business need a privacy policy?

Yes if it processes personal data, which a contact form or a customer list already does. There is no exemption based on size or turnover in the UK or EU.

Do I need to register with the ICO?

Most UK businesses processing personal data by automated means do. The fee is tiered by size and turnover and is enforced separately from other obligations.

Can I email past customers about offers?

Only under the soft opt-in - your own similar products, to someone who bought from you, with an opt-out offered at the time and in every message - or with consent.

Do I need a cookie banner for a small website?

If it runs analytics or any third-party embed, in the UK and EU yes, and it needs to hold those tags until consent is given.

Does GDPR apply to a business outside the EU?

Yes, where you offer goods or services to people in the EU or monitor their behaviour. Article 3(2) is about where the person is, not where you are - and Article 27 may also require you to appoint an EU representative.

What is the difference between EU GDPR and UK GDPR?

The text is nearly identical, but they are separate laws with separate regulators, separate fine ceilings in different currencies, and separate transfer regimes. A business serving both needs both named, not "GDPR" as shorthand.

Do I need a Data Protection Officer?

Only where your core activities involve large-scale regular monitoring or large-scale special-category data, or you are a public authority. Many businesses do not need one - but if you do not have one, say who is accountable instead.

Is a GDPR policy the same as a privacy policy?

No. The privacy policy is the outward-facing notice. The GDPR policy set is the internal machinery - lawful basis register, ROPA, rights procedure, breach plan - that lets you answer a regulator when they ask how the notice is honoured.

GDPR Policy Generator for small businesses

Answer a short questionnaire and get a draft written for a small business. Free to start, no card required.

Generate your GDPR policy

Other documents a small business needs

Each one is written for the same context, not a generic template.

The same document, by business type

Go deeper

PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.