The GDPR isn’t a form you fill in once and forget about. It’s a way of handling your customers’ and employees’ data that you have to keep up over time. The good news for a small business is that genuine compliance doesn’t require an entire legal department: it takes order, a handful of well-drafted documents and a technical side that almost nobody looks at until an incident or an inspection comes along.
In this guide we explain how to comply with the GDPR in your company, focusing on what actually depends on you: your website, your records, your contracts with suppliers and the security of your data. This isn’t legal advice —that’s what your lawyer or your data protection officer is for—; it’s the technical and organisational roadmap that stops a silly slip-up from turning into a fine.
What the GDPR really asks of you (in plain English)
Get the idea out of your head that the GDPR is about “not sharing data”. It’s about something simpler and more demanding: knowing what data you hold, what you use it for, where it lives and who touches it. If you can answer those four questions about any piece of personal data your company handles —a customer’s email, an employee’s payslip, a candidate’s CV—, you’re on the right track. If you can’t, that’s exactly where your problem lies.
The regulation rests on a set of principles that translate into concrete, very down-to-earth obligations:
- A legal basis for every processing activity. You don’t collect data “just in case”: every piece of data answers to a reason (a contract, consent, a legal obligation).
- Minimisation. You ask only for what you need. A contact form doesn’t need an ID number.
- Transparency. People know what you do with their data before they hand it over.
- Rights. Anyone can ask you for access, rectification or erasure, and you have to be able to handle it.
- Security. You protect data with real technical measures, not with good intentions.
The key point: compliance is demonstrated, not declared. The “accountability” principle means the burden of proving that you comply falls on you. That’s why documentation and records aren’t bureaucracy; they’re your defence the day someone asks.
Your website: legal texts, forms and cookies
The website is where most small businesses risk a complaint, because it’s the one thing anyone can audit from the outside without setting foot in your office. There’s no room for improvisation here, and three things have to be flawless.
Legal texts that tell the truth
You need a privacy policy, a legal notice and, if you use cookies, a cookie policy. The usual mistake is to copy another site’s: you end up with a document that mentions purposes you don’t pursue and leaves out the ones you do. The policy has to reflect your reality —what data you actually collect, with which tools (your CRM, your email marketing provider, your analytics) and how long you keep it—. A generic text is worse than having nothing, because it proves you knew it had to be there and still didn’t get it right.
Forms with genuine consent
Every form —contact, newsletter, quote— needs to state who processes the data and link to the privacy policy. If the aim is to send marketing communications, you need a consent checkbox that isn’t ticked by default. And that consent has to be provable: record when and how it was given. A form that logs nothing is a promise you can’t back up.
Cookies: block before accepting
The cookie banner isn’t decorative. Non-essential cookies —analytics, advertising, social media pixels— can’t load until the user accepts, and rejecting has to be as easy as accepting. Many “off-the-shelf” banners show the notice but load the scripts anyway: that’s non-compliance with a sign attached. The technical setup of the banner and the tag manager matters just as much as the wording.
Record of processing activities and processor contracts
Here’s the part almost no small business has done, and it’s one of the first things asked for in an inspection. The record of processing activities (ROPA) is the inventory of everything you do with personal data: each activity (customer management, payroll, recruitment, video surveillance) with its purpose, its legal basis, the categories of data, the retention periods and the security measures.
You don’t need an expensive tool: a well-structured spreadsheet, kept up to date, does the job. What doesn’t do the job is not having one, or having one that’s out of date. The ROPA is also the best map for everything else: when you fill it in properly you discover processing activities you’d never documented and suppliers who touch data without a contract.
Every company you hand personal data to so it can work for you is a processor. And with each one you need a signed contract. No exceptions.
The data processing agreement is a document under Article 28 of the GDPR that governs what that supplier can do with the data. And who are your processors? More than you’d think:
- Your accountant or advisory firm, which handles payroll and tax data.
- The provider of your email and your CRM, where your customer contacts live.
- The email marketing platform you send your newsletter from.
- The hosting that houses your website and its forms.
- Your external IT support, which accesses your equipment and systems.
Many reputable providers already offer their processor contract ready to sign (they sometimes call it a DPA). Your job is to gather them all and keep them on file. And watch out for international transfers: if your tool stores data outside the European Economic Area, you have to verify that a valid safeguard is in place. It’s not optional.
Common mistakes that end in a fine
Most fines handed to small businesses don’t come from convoluted cases, but from repeated failings that a bit of order would have prevented. These are the ones that come up most:
- Cookies that load without consent. The classic. A banner for show while the analytics and pixels are already running.
- Not handling a right in time. Someone asks you to erase their data, nobody deals with it, and that silence turns into a complaint.
- Not reporting a security breach. When an incident affects personal data, there’s a 72-hour window to assess it and, where appropriate, notify the authority. Improvising on the day is expensive.
- Sending marketing communications without consent or without a clear unsubscribe link.
- Unprotected data. Shared passwords, unencrypted laptops, backups nobody tests, former employees’ access still active.
Notice the pattern: almost all of them are technical and organisational failings, not matters of legal interpretation. A breach from an unpatched server, a backup that failed in silence or a badly configured banner won’t be fixed by a good lawyer; they’re prevented with a well-built, well-monitored infrastructure. That’s where data protection stops being paperwork and becomes applied cybersecurity.
How MagicBoxDesk helps you
Let’s be clear: MagicBoxDesk is not your legal advisor. We don’t draft your privacy policy or tell you which legal basis applies to each processing activity —that’s your lawyer’s or your data protection officer’s job—. What we do is the technical and security half of the GDPR, which is the half that’s usually left half-finished and the one that, when it fails, ends in an incident.
We make sure the security measures the regulation demands actually exist and work: access control, encryption, tested backups, up-to-date patching, monitoring of your systems and a response plan for the day a breach happens. We set up your website and its cookie banner properly, review where and how the data you handle is stored, and help you keep the technical order that holds everything else together. Because we act as your outsourced IT department, this isn’t a one-off project: it’s ongoing support across the whole of Spain, remote and on-site when needed.
Complying with the GDPR in your company is, above all, about having things in order and protected before anyone asks. We put in the technical side so you can get on with your business. Ask for a no-obligation quote and we’ll go over with you what you really need to sleep easy.



