Data protection obligations apply to businesses of every size, and the common assumption that a small company is somehow outside the scope of the General Data Protection Regulation is wrong. What is true is that the practical burden scales with what the business actually does, and a small company processing employee and customer records has a considerably lighter task than one whose business model is built on personal data.
Start with an inventory
Almost every sensible compliance step depends on first knowing what personal data the business holds, where it came from, why it is held, who has access, and how long it is kept. Most small businesses find this exercise produces surprises: data retained long after any reason for retaining it expired, access rights that outlived the employment that justified them, and copies in systems nobody thought of as data storage.
Lawful basis and transparency
Every processing activity needs a lawful basis, and consent is only one of six. For much routine activity the applicable basis is performance of a contract, compliance with a legal obligation, or legitimate interests, and reaching for consent where one of those applies creates problems rather than solving them, because consent can be withdrawn. Separately, individuals must be told what is done with their data, in clear language and at the point of collection.
- Keep records of processing. The obligation is reduced but not eliminated for smaller organisations.
- Have written processor terms. Every supplier that handles data on your behalf needs a contract that says so.
- Set retention periods. Indefinite retention is the most common finding in a small-business review.
- Prepare for requests. Access and erasure requests have a statutory response deadline.
Breaches
A personal data breach may require notification to the supervisory authority within seventy-two hours of becoming aware of it, and notification to affected individuals where the risk to them is high. The practical implication is that the decision-making cannot start from scratch when a breach happens. Knowing in advance who assesses it and who notifies is most of what makes the deadline achievable.
The Czech layer
The Regulation applies directly, and Czech implementing legislation supplements it in specific respects, with the national supervisory authority responsible for oversight and enforcement. Sector-specific rules, particularly in employment and in electronic communications, add requirements on top for the businesses they cover.
For a small company the realistic goal is proportionate compliance rather than perfection. Knowing what data is held and why, having the supplier contracts in place, deleting what is no longer needed, and being able to respond to a request within the deadline covers the great majority of what a supervisory authority would actually look at.
This article is general information about Czech law and is not legal advice.
Leave a Reply