Published: August 29, 2026 · Written by Casey, Head of Content at One Person Company

GDPR for Solopreneurs — The Plain-English Compliance Baseline

GDPR applies to a one-person business in Lisbon or Louisville alike if you handle EU residents’ personal data — and most founders overestimate the bureaucracy while underestimating the six concrete things actually required. The compliance baseline for a solo business is genuinely achievable in a day.

This guide walks it: does it apply to you, the lawful basis question, the six practical steps, the documents you need (they are few), and what regulators actually check when they check small businesses.

The short answer

  • GDPR applies based on data subjects, not business size or location — a solo newsletter with EU subscribers is in scope.
  • The overwhelming majority of enforcement against small operations concerns marketing consent, data requests ignored, and breaches unreported.
  • A compliant solo setup is typically a privacy policy, a consent mechanism, records of processing, and functioning data-subject responses.

Who this playbook is for

Built for solo founders outside or inside the EU who touch any EU resident’s personal data.

Step 1: Confirm whether GDPR applies to you

Applies if: you offer goods/services to people in the EU, or monitor EU residents’ behavior (analytics, ads), regardless of where you sit. A US consultant with EU clients, a newsletter with EU readers, an e-shop shipping to Germany — all in scope. Not in scope: purely local business touching no EU data. When borderline, comply anyway — the steps below double as good practice everywhere.

Step 2: Establish your lawful basis per processing activity

Each thing you do with personal data needs a basis: consent (newsletter, marketing), contract (client contact and delivery), legitimate interest (basic analytics, fraud prevention — documented), legal obligation (invoices). Write one line per activity. The newsletter-consent case is the one that trips most founders: pre-ticked boxes and bundled consent are out.

Step 3: Create the minimum document set

Four items: privacy policy (plain-language: what you collect, why, how long, who processes it — mail tools, payment processors), cookie/consent banner if you track, a records-of-processing sheet (one page listing your activities), and data-processing agreements with your subprocessors (major tools provide these on request — Mailchimp, Stripe, etc. all publish DPAs). A weekend of paperwork, done once, reviewed annually.

Step 4: Build the data-subject response capability

People can ask: access their data, correct it, delete it, export it. Your capability: a stated channel (privacy@yourdomain), a 30-day clock, and actually knowing where their data lives (your records sheet tells you). For a solo business this is usually a search across email, CRM and payment tools — an hour per request, handled promptly and politely. Ignoring requests is what gets small operations reported.

Step 5: Handle the breach rule and the transfer basics

Breaches involving personal data risk get reported to your regulator within 72 hours when serious — your breach plan (see the data protection checklist) already covers detection and containment; add the notification step. Data transfers: using major US tools with EU adequacy or standard contractual clauses is today’s normal path — your tools’ DPAs document this. Do not build your own transfer legal theory; use the infrastructure the big processors already provide.

Your weekly operating rhythm

DayActionTime
Setup dayApplicability check + basis lines + document set1 day
On consentOnly clean opt-ins; no pre-ticks, no bundlingongoing
Per requestRespond within 30 days, helpfully~1 hr
AnnuallyReview policy, records, and tool DPAs1 hr

KPIs that tell you it is working

MetricHealthy targetWhy it matters
Lawful basis documentedPer activity, in writingThe foundation regulators and clients both check
Consent recordsTimestamped and provableNewsletter liability lives here
Data requests answeredWithin 30 days, 100%The metric that prevents complaints escalating
Subprocessor DPAs on fileAll major toolsThe chain-of-compliance paperwork

Common mistakes to avoid

A tool stack that fits a one-person budget

ToolWhere it fits
Your email platform’s consent toolsDouble opt-in and timestamped proof
Termly / iubenda / a lawyer templatePrivacy policy and cookie setup
One-page processing records sheetThe map of what you hold and why
Your tool vendors’ DPA librariesThe subprocessor paperwork, pre-written

Keep going

Use these internal references while implementing this guide:

FAQ

Q: What are the actual fines for a solo business?

The headline fines target large-scale violations; small-business enforcement more commonly means warnings, orders to comply, and fines scaled to capacity. The realistic risks are complaint-driven: an ignored deletion request or spam complaints escalating to your regulator. Compliance is cheap; complaints are not.

Q: Do I need a DPO (Data Protection Officer)?

Almost certainly not — DPOs are mandatory for large-scale processing of sensitive data or public-authority roles. A solo business documents its processing and handles requests itself. The DPA acronym soup (DPO vs DPA) trips more founders than the actual obligations do.

Q: How does GDPR interact with my analytics and ads?

EU visitor tracking needs consent before non-essential cookies — hence the banner. Or use cookieless, privacy-first analytics which often needs no banner at all. The marketing-consent rule (no pre-ticked anything) is where real enforcement concentrates; get that right first.

Q: Is UK GDPR different?

Structurally the same with a UK regulator (ICO) and minor divergences — if you comply with EU GDPR you are effectively compliant for UK. Handle both with one setup: one policy covering both regimes, one consent mechanism, one records sheet.


Get the weekly operating brief

Every Monday: 3 moves, 5 minutes. Actionable strategy for your one-person company — no fluff, no filler.