The General Data Protection Regulation (GDPR) is often perceived by directors of TPE (very small enterprises) and PME (small and medium-sized enterprises) as an insurmountable regulatory maze reserved for tech multinationals. However, this European regulation, which came into force in 2018, applies to any legal entity handling personal data, starting from their very first client or employee. For small businesses in France, compliance is not just a legal obligation backed by heavy sanctions; it is also a major token of trust for your clients and partners. This practical guide, designed by AvocatAI, presents the "essential minimum" to bring your business into compliance without disrupting your daily operations.
---
The legal framework: what does the law actually say?
Personal data protection in France is based on a dual legal foundation: the European Regulation 2016/679 (GDPR) and the national law known as the Loi Informatique et Libertés (French Data Protection Act) of January 6, 1978, as amended.
Contrary to popular belief, there is no global exemption for small structures. Article 2 of the GDPR specifies that the regulation applies to the processing of personal data, whether automated or not, as long as this data is contained or intended to be contained in a filing system.
What is personal data and processing?
- Personal data: According to Article 4.1 of the GDPR, this means any information relating to an identified or identifiable natural person (a name, a professional email, a phone number, an IP address, or even a license plate number).
- Processing: Article 4.2 defines processing as any operation performed on data (collection, recording, storage, adaptation, consultation, dissemination, or erasure). Thus, simply storing your prospects' email addresses in an Excel spreadsheet constitutes data processing.
The fundamental principles to respect
Article 5 of the GDPR sets out the cardinal principles that every small business must respect:
- Lawfulness, fairness, and transparency: You must have a legal basis to process data (consent, performance of a contract, legal obligation, or legitimate interest) and inform individuals clearly.
- Purpose limitation: You cannot collect data "just in case". Every collection must have a specific and legitimate purpose.
- Data minimisation: You must only collect what is strictly necessary. To send a newsletter, asking for your prospect's date of birth or family status is excessive.
- Storage limitation: Data cannot be kept indefinitely. It must be deleted or anonymised once the objective has been achieved.
---
Practical steps: your 5-step roadmap
For a TPE or PME, compliance must be pragmatic. Here are the 5 essential steps to lay the foundations of your GDPR compliance.
Step 1: Map your processing activities (The Register)
Article 30 of the GDPR requires the maintenance of a record of processing activities. Although businesses with fewer than 250 employees benefit from a derogation for occasional processing, the CNIL (French National Commission for Information Technology and Civil Liberties) points out that managing clients, prospects, and employee payroll is not occasional. Keeping a simplified register is therefore, in practice, mandatory.
For each file (clients, payroll, newsletter), you must note:
- Who is responsible for the processing (you).
- Why you collect this data (the purpose).
- Which categories of data are collected.
- Who has access to it (your employees, your accountant, your web host).
- How long you keep it.
Step 2: Sort through your data (Minimisation)
Review your contact forms, client databases, and job applications. Delete all unnecessary or obsolete data.
- Example of legal retention period: Your clients' data should generally not be kept for more than 3 years after the last commercial contact, except for accounting or tax obligations (which require invoices to be kept for 10 years according to Article L. 123-22 of the Code de commerce / French Commercial Code).
Step 3: Inform individuals (Transparency)
You must draft a privacy policy accessible on your website and insert clear information notices on your collection forms (contact form, registration form, etc.). These notices must specify the identity of the data controller, the purpose, the retention period, and how individuals can exercise their rights.
Step 4: Guarantee data security
Article 32 of the GDPR requires ensuring data security. For a small business, this involves common-sense measures:
- Use complex and unique passwords for each session.
- Enable multi-factor authentication (MFA) on your management tools and email inboxes.
- Lock your computers as soon as you leave your desk.
- Regularly back up your data on an external drive or a secure cloud.
- Raise awareness among your employees regarding hacking risks (phishing).
Step 5: Formalise relations with your processors
If you use online invoicing software, a newsletter delivery tool (such as Mailchimp or Brevo), or if you hire an external expert-comptable (chartered accountant), these actors are your "processors" within the meaning of Article 28 of the GDPR. You must ensure they present sufficient guarantees of compliance and sign a contract (or accept general terms) containing specific clauses on data protection.
---
Deadlines, amounts, and key figures to remember
To measure the importance of the GDPR, here are the essential figures that every entrepreneur must keep in mind:
- 20 million euros or 4% of global annual turnover (whichever is higher): this is the maximum administrative fine that the CNIL can impose in the event of a serious violation of the GDPR (Article 83 of the GDPR).
- 72 hours: this is the maximum timeframe you have to notify the CNIL of a personal data breach (hacking, loss of a USB key containing client files, etc.) if this breach presents a risk to the rights of individuals (Article 33 of the GDPR).
- 1 month: this is the maximum legal timeframe to respond to a request to exercise a right by a client or an employee (right of access, rectification, or erasure). This period can be extended by 2 months in the case of complex requests, provided the individual is informed.
- 0 euros: the cost of the self-assessment tool and register templates provided free of charge by the CNIL to help TPEs and PMEs.
---
Two concrete examples of application
To better understand how these rules are implemented, let us analyse two common situations for small French businesses.
Example 1: Sophie's home decor e-commerce website
Sophie runs a micro-entreprise (sole proprietorship/micro-business) selling home decor items online on her own. Her site processes about 150 transactions per month. She collects the name, delivery address, email address, and phone number of her clients.
- What she must do: Sophie must integrate a privacy policy on her website. During the order process, she must obtain separate consent (via an unchecked box by default) if she wishes to use the client's email to send them commercial offers (marketing). For delivery, she transfers the details to the carrier: she must ensure in the carrier's contract that the latter will not use this data for other purposes.
- Retention: She keeps invoicing data for 10 years (legal obligation) but must delete or anonymise any client account that has been inactive for more than 3 years.
Example 2: Pierre's real estate agency (3 employees)
Pierre runs a local real estate agency. He collects highly confidential data on prospective tenants: payslips, tax notices, employment contracts.
- What he must do: Pierre must keep a processing register because handling this financial data presents a risk to the privacy of individuals. He must secure access to these files (physical cabinets locked with keys, digital folders protected by passwords).
- The sorting rule: As soon as a property is allocated, Pierre must immediately destroy or return the files of the unsuccessful candidates. Keeping these files "just in case another apartment becomes available" without the express written consent of the candidates is illegal.
---
Mistakes to avoid at all costs
To protect yourself against inspections and client complaints, avoid these common pitfalls:
- Pre-ticked boxes for newsletters: This is one of the most common infractions. Consent must be a clear positive act. Pre-ticking the box "I wish to receive your offers" is strictly prohibited.
- Unlimited storage of CVs: Keeping the CV of an unsuccessful candidate for years without their consent is illegal. The CNIL recommends a maximum retention period of 2 years after the last contact, unless the candidate requests immediate destruction.
- Lack of a processing contract with your IT provider: If your external IT provider has access to your servers containing client data, you are jointly responsible if they commit a negligence. Demand a written commitment from them regarding GDPR compliance.
- Neglecting access or erasure requests: Ignoring an email from a client asking to delete their data from your database is the fastest way to trigger a report to the CNIL. Always respond, even if it is to explain why you must keep certain data (such as an invoice).
---
FAQ (Frequently Asked Questions)
Does a business with fewer than 10 employees need to appoint a DPO?
No, appointing a Délégué à la Protection des Données (DPO / Data Protection Officer) is not mandatory for the majority of small businesses. It only becomes mandatory if your core activity consists of regular and systematic monitoring of individuals on a large scale, or if you process "sensitive" data (health data, political opinions, criminal offenses) on a large scale. However, appointing an internal GDPR contact person remains a good practice.
Can I prospect professionals (B2B) by email without their prior consent?
Yes, but under certain conditions. In France, the rule of prior consent (opt-in) applies strictly to individuals (B2C). In B2B (professionals), you can send marketing emails without prior consent if the recipient is informed, if they can object easily and free of charge at any time (unsubscribe link), and if the subject of the message is directly related to their professional activity.
What does my small business actually risk in case of non-compliance?
While record fines of several million euros target web giants, the CNIL also inspects and sanctions PMEs and TPEs. Financial sanctions are proportionate to the size of the company and the severity of the breach, but they can amount to several thousand euros, which can weaken a small structure. Furthermore, a public sanction by the CNIL seriously damages your company's reputation.
My website uses cookies, does the GDPR apply to me?
Yes. Trackers and cookies (excluding cookies strictly necessary for the operation of the website) require the prior and explicit consent of the user. You must install a cookie banner compliant with CNIL guidelines, allowing the user to refuse cookies as easily as they accept them.
---
Summary
- The GDPR applies to all businesses, regardless of their size or turnover, as long as they handle personal data.
- Keeping a simplified processing register is essential to identify and list your data files (clients, employees, prospects).
- You must apply the minimisation principle: only collect strictly necessary data and set clear retention periods.
- Informing individuals is mandatory: integrate clear legal notices and a privacy policy on your collection channels.
- Secure your IT access and contractually bind your processors who handle your data.
Legal information for guidance only, not personalised legal advice. For your specific situation, ask your question free of charge on AvocatAI — answers based on French law, in your language.
⚖️ Content reviewed by the AvocatAI legal editorial team
This article is provided for information only and is not legal advice. Consult a lawyer for advice tailored to your situation.