GDPR and IT for a small company: what the tech actually handles

GDPR sounds like a bogeyman for large corporations, but in reality it concerns every company that works with personal data, including a small one. We will not go into legal paragraphs here; that is for a specialist. We will look at the technical and security side that a company can actually influence and that we will help you manage.
What personal data actually is
Personal data is anything by which a specific person can be identified: name, email, phone, address, IP address, a photo, but also camera footage. If, as a company, you hold such data about customers or employees (and almost every company does), GDPR concerns you.
The basic principles behind the rules
GDPR rests on a few principles. You do not need to know them by heart, but they help explain why things are done the way they are:
- Lawfulness and purpose. You collect data only for a specific, predefined purpose, not as a stockpile.
- Minimisation. You ask only for what you really need, not everything that might come in handy.
- Consent, where required. Some processing (for example marketing) needs clear consent, which can also be withdrawn.
- Limited period. You do not keep data longer than necessary or than the law requires.
The IT side of GDPR, in simple terms
In practice, a large part of GDPR is about keeping data under control and secure:
- Securing the data. A leak or encryption of data by ransomware is a security incident from a GDPR point of view. Updates, backups and security principles help.
- Access only for those who need it. Not everyone should see everything, and when an employee leaves their access must be revoked.
- Cameras by the rules. Marking the area, a justified purpose and a limited retention period; more in the article on camera systems.
- Deletion and retention. Being able to delete data on request, while keeping what the law requires.
- Service providers. The cloud, email or accounting system process your data for you, so choose trustworthy ones.
The rights of the people whose data you hold
A person whose data you process has rights towards you. In practice you should be able to respond above all to:
- The right of access to the data you hold about them.
- The right to rectification of incorrect data.
- The right to erasure (the right to be forgotten) once the reason for keeping it has passed.
Such a request usually has to be handled without undue delay, as a rule within one month.
A data breach and the duty to report
If a security incident with a risk to people occurs (for example a leak of the customer database), GDPR imposes a duty to report it to the supervisory authority, as a rule within 72 hours of discovery. In case of high risk you also have to inform the affected people themselves. That is why it is important to recognise an incident quickly and have a procedure ready. Serious breaches risk noticeable fines that can be ruinous for a small company, so prevention pays off.
Contracts with suppliers (processors)
When someone else processes your data (cloud, email service, an accountant, external IT), they are a processor from a GDPR point of view. With such a supplier you should have a data processing agreement in place that sets out what they may do with the data and how they protect it. So choose trustworthy partners.
What a small company should practically do
- have an overview of what personal data it holds and why,
- secure the systems (updates, antivirus, strong passwords and 2FA),
- manage access and revoke it when people leave,
- back up and be able to restore data in case of an incident,
- report a more serious data leak within the set deadline.
This is the technical and security part that we can set up for you. Consult the legal aspects (directives, consents, contracts) with a GDPR specialist; the two go hand in hand.
Want the IT side of data protection properly handled? Get in touch and we will help secure the systems, access and backups so that you are prepared.
GDPR and data security without the headache
We set up access rights, backups and system security so you are technically ready for GDPR. For homes and businesses across Liptov.
Get in touchThis article is part of our Business and IT overview.
Frequently asked questions
Who does GDPR actually concern?
What counts as personal data?
Within how many hours must a data leak be reported?
What rights does a person whose data a company processes have?
What is a processor and do you need a contract with one?
What should a small company practically do to comply with GDPR?
Need help with IT?
We will take care of your computers, networks and security - for businesses and households in the Liptov region.
Contact us