GDPR for Solopreneurs — The Plain-English Compliance Baseline
GDPR applies to a one-person business in Lisbon or Louisville alike if you handle EU residents’ personal data — and most founders overestimate the bureaucracy while underestimating the six concrete things actually required. The compliance baseline for a solo business is genuinely achievable in a day.
This guide walks it: does it apply to you, the lawful basis question, the six practical steps, the documents you need (they are few), and what regulators actually check when they check small businesses.
The short answer
- GDPR applies based on data subjects, not business size or location — a solo newsletter with EU subscribers is in scope.
- The overwhelming majority of enforcement against small operations concerns marketing consent, data requests ignored, and breaches unreported.
- A compliant solo setup is typically a privacy policy, a consent mechanism, records of processing, and functioning data-subject responses.
Who this playbook is for
Built for solo founders outside or inside the EU who touch any EU resident’s personal data.
Step 1: Confirm whether GDPR applies to you
Applies if: you offer goods/services to people in the EU, or monitor EU residents’ behavior (analytics, ads), regardless of where you sit. A US consultant with EU clients, a newsletter with EU readers, an e-shop shipping to Germany — all in scope. Not in scope: purely local business touching no EU data. When borderline, comply anyway — the steps below double as good practice everywhere.
Step 2: Establish your lawful basis per processing activity
Each thing you do with personal data needs a basis: consent (newsletter, marketing), contract (client contact and delivery), legitimate interest (basic analytics, fraud prevention — documented), legal obligation (invoices). Write one line per activity. The newsletter-consent case is the one that trips most founders: pre-ticked boxes and bundled consent are out.
Step 3: Create the minimum document set
Four items: privacy policy (plain-language: what you collect, why, how long, who processes it — mail tools, payment processors), cookie/consent banner if you track, a records-of-processing sheet (one page listing your activities), and data-processing agreements with your subprocessors (major tools provide these on request — Mailchimp, Stripe, etc. all publish DPAs). A weekend of paperwork, done once, reviewed annually.
Step 4: Build the data-subject response capability
People can ask: access their data, correct it, delete it, export it. Your capability: a stated channel (privacy@yourdomain), a 30-day clock, and actually knowing where their data lives (your records sheet tells you). For a solo business this is usually a search across email, CRM and payment tools — an hour per request, handled promptly and politely. Ignoring requests is what gets small operations reported.
Step 5: Handle the breach rule and the transfer basics
Breaches involving personal data risk get reported to your regulator within 72 hours when serious — your breach plan (see the data protection checklist) already covers detection and containment; add the notification step. Data transfers: using major US tools with EU adequacy or standard contractual clauses is today’s normal path — your tools’ DPAs document this. Do not build your own transfer legal theory; use the infrastructure the big processors already provide.
Your weekly operating rhythm
| Day | Action | Time |
|---|---|---|
| Setup day | Applicability check + basis lines + document set | 1 day |
| On consent | Only clean opt-ins; no pre-ticks, no bundling | ongoing |
| Per request | Respond within 30 days, helpfully | ~1 hr |
| Annually | Review policy, records, and tool DPAs | 1 hr |
KPIs that tell you it is working
| Metric | Healthy target | Why it matters |
|---|---|---|
| Lawful basis documented | Per activity, in writing | The foundation regulators and clients both check |
| Consent records | Timestamped and provable | Newsletter liability lives here |
| Data requests answered | Within 30 days, 100% | The metric that prevents complaints escalating |
| Subprocessor DPAs on file | All major tools | The chain-of-compliance paperwork |
Common mistakes to avoid
- Assuming size exempts you. GDPR has no small-business exemption; it has proportionate enforcement. The solo compliance burden is real but small — the steps above are the whole burden.
- Buying consent (adding people from scraped lists or "partners"). Purchased lists under GDPR are violations with a paper trail attached — the list you bought is evidence of the breach.
- Building the documents and ignoring the practice. A privacy policy while ignoring deletion requests is worse than nothing — the policy documents the duty you then breached.
A tool stack that fits a one-person budget
| Tool | Where it fits |
|---|---|
| Your email platform’s consent tools | Double opt-in and timestamped proof |
| Termly / iubenda / a lawyer template | Privacy policy and cookie setup |
| One-page processing records sheet | The map of what you hold and why |
| Your tool vendors’ DPA libraries | The subprocessor paperwork, pre-written |
Keep going
Use these internal references while implementing this guide:
- One Person Company Hub
- How to Start a One Person Company
- Solopreneur Operating System
- Liability Insurance for Solopreneurs
- The IP Assignment Clause
- The Independent Contractor Agreement
FAQ
Q: What are the actual fines for a solo business?
The headline fines target large-scale violations; small-business enforcement more commonly means warnings, orders to comply, and fines scaled to capacity. The realistic risks are complaint-driven: an ignored deletion request or spam complaints escalating to your regulator. Compliance is cheap; complaints are not.
Q: Do I need a DPO (Data Protection Officer)?
Almost certainly not — DPOs are mandatory for large-scale processing of sensitive data or public-authority roles. A solo business documents its processing and handles requests itself. The DPA acronym soup (DPO vs DPA) trips more founders than the actual obligations do.
Q: How does GDPR interact with my analytics and ads?
EU visitor tracking needs consent before non-essential cookies — hence the banner. Or use cookieless, privacy-first analytics which often needs no banner at all. The marketing-consent rule (no pre-ticked anything) is where real enforcement concentrates; get that right first.
Q: Is UK GDPR different?
Structurally the same with a UK regulator (ICO) and minor divergences — if you comply with EU GDPR you are effectively compliant for UK. Handle both with one setup: one policy covering both regimes, one consent mechanism, one records sheet.
Get the weekly operating brief
Every Monday: 3 moves, 5 minutes. Actionable strategy for your one-person company — no fluff, no filler.