By · Updated

Data protection · 9 min

Personal data: practical first steps for small organisations

Data protection starts by knowing what information is collected, why it is needed and who can use it. A short accurate inventory is more useful than a long policy disconnected from daily work.

Key points

What to remember.

  • Map real data flows and their owners.
  • Collect only what supports a defined purpose.
  • Set retention, access and deletion rules that teams can follow.
01

Map the information you actually use

Review forms, email, spreadsheets, analytics, CRM tools, cloud storage and suppliers. Record the people concerned, data categories, source, destination, access and responsible owner. Include informal processes, not only official systems.

02

Define purpose and lawful basis

Explain the operational reason for each processing activity and identify the appropriate legal basis. Do not reuse information for an unrelated purpose simply because it is available. Seek qualified advice when the context is sensitive.

03

Reduce collection and exposure

Remove optional fields that are not used, avoid free-text requests for sensitive details and choose privacy-conscious defaults. Less data means less effort to secure, explain, correct and delete.

04

Control access and suppliers

Grant access by role, review it periodically and remove it when no longer needed. Check processor contracts, data locations, security measures, sub-processors and procedures for returning or deleting data.

05

Set realistic retention rules

Define how long each category is needed and what event starts the period. Automate deletion where reliable, but keep a documented way to handle exceptions, legal holds and backups.

06

Prepare requests and incidents

People need a clear contact route for access, correction or deletion requests. Staff should know how to recognise a personal-data breach, contain it and escalate it quickly enough for the organisation to assess notification duties.

Sources

Check the reference material.

CNIL · GDPR for small organisations

European Commission · Data protection

Put the method into practice

An illustrative application case

Several files contain the same contacts with different statuses. Identify each source and owner before centralising. Define the reference record and necessary uses. Technical merging does not automatically resolve contradictions or retention periods.

Choose a CRM around real workflows

Use this worksheet in a review with the person responsible for delivery. Keep the evidence alongside the decision, rather than marking a task complete on trust alone.

Actions and evidence to retain
ActionEvidence
Connect each collected field to an explicit purpose.A record describing necessity, the legal basis to assess and recipients.
Define retention and deletion within the actual tools.A documented rule and deletion test, including service providers.
Check the information supplied before a form is submitted.An understandable notice, a rights contact and a tested journey.

Download the worksheet to fill in (CSV)

A question to resolve before acting

Does every form need a consent checkbox?

The legal basis depends on purpose and context. Separate contact requests from marketing subscriptions. Identify the appropriate basis, provide the required information and consult the relevant regulator’s guidance for the processing.

Continue

Turn the method into a clear project.

Use the directory to explore relevant resources, or describe your context so the right questions can be identified before a conversation begins.