Personal data: practical first steps for small organisations
Data protection starts by knowing what information is collected, why it is needed and who can use it. A short accurate inventory is more useful than a long policy disconnected from daily work.
What to remember.
- Map real data flows and their owners.
- Collect only what supports a defined purpose.
- Set retention, access and deletion rules that teams can follow.
Map the information you actually use
Review forms, email, spreadsheets, analytics, CRM tools, cloud storage and suppliers. Record the people concerned, data categories, source, destination, access and responsible owner. Include informal processes, not only official systems.
Define purpose and lawful basis
Explain the operational reason for each processing activity and identify the appropriate legal basis. Do not reuse information for an unrelated purpose simply because it is available. Seek qualified advice when the context is sensitive.
Reduce collection and exposure
Remove optional fields that are not used, avoid free-text requests for sensitive details and choose privacy-conscious defaults. Less data means less effort to secure, explain, correct and delete.
Control access and suppliers
Grant access by role, review it periodically and remove it when no longer needed. Check processor contracts, data locations, security measures, sub-processors and procedures for returning or deleting data.
Set realistic retention rules
Define how long each category is needed and what event starts the period. Automate deletion where reliable, but keep a documented way to handle exceptions, legal holds and backups.
Prepare requests and incidents
People need a clear contact route for access, correction or deletion requests. Staff should know how to recognise a personal-data breach, contain it and escalate it quickly enough for the organisation to assess notification duties.
Check the reference material.
Related guides
Put the method into practice
An illustrative application case
Several files contain the same contacts with different statuses. Identify each source and owner before centralising. Define the reference record and necessary uses. Technical merging does not automatically resolve contradictions or retention periods.
Choose a CRM around real workflows
Use this worksheet in a review with the person responsible for delivery. Keep the evidence alongside the decision, rather than marking a task complete on trust alone.
| Action | Evidence |
|---|---|
| Connect each collected field to an explicit purpose. | A record describing necessity, the legal basis to assess and recipients. |
| Define retention and deletion within the actual tools. | A documented rule and deletion test, including service providers. |
| Check the information supplied before a form is submitted. | An understandable notice, a rights contact and a tested journey. |
Download the worksheet to fill in (CSV)
A question to resolve before acting
Does every form need a consent checkbox?
The legal basis depends on purpose and context. Separate contact requests from marketing subscriptions. Identify the appropriate basis, provide the required information and consult the relevant regulator’s guidance for the processing.