The filing deskSmall businesses · personal data
GDPR for a small business in France: the practical duties, from the register to the 72 hours
A small French business processing customer or employee data must organise records, information, processor contracts and security (GDPR, articles 30, 13, 28 and 32). A breach likely to pose a risk must be notified to the CNIL without undue delay, where feasible within 72 hours after awareness; every breach must be documented (article 33). A DPO is compulsory only in the cases of article 37. The CNIL imposed 83 penalties in 2025.
Go to the tool: the filing desk
Julie by AlphaDeep is an AI legal assistant for French law: it researches official references to help answer your questions (Légifrance, case law, service-public), analyses your documents and drafts your letters, for individuals and professionals alike.
General legal information with official references and dated checks. It is not personalised advice: for a decision that commits you, have your situation checked by a qualified professional.
Let’s look at your situation
Give your activity, the number of employees and the data you process.
Example questions
Your question carries over after signup. Maximum 400 characters. Avoid health data and names.
Which GDPR duties apply to a small business, from the most urgent to the rarest?
Eight duties, ranked by urgency: the first three concern time limits or the failings the CNIL most often penalises under its simplified procedure; the last one only concerns certain activities.
Secure access and backups
Technical and organisational measures suited to the risk (article 32). According to the CNIL, 14 organisations were penalised in 2025 under the simplified procedure for poor security, for example weak passwords or shared accounts.
Answer people’s requests within a month
Access, rectification, erasure, objection: the answer comes within a month, extendable by two months for a complex request (article 12). In 2025, 14 CNIL decisions under the simplified procedure concerned requests left unanswered.
Assess and notify a risky breach
If a leak poses a risk to people, notification goes without undue delay and where feasible within 72 hours after awareness; every breach is documented, even when it is not notified (article 33).
Keep the record of processing activities
One entry per processing: purposes, people, data, recipients, retention periods, security (article 30). Under 250 employees, the exemption only covers occasional, risk-free processing: payroll and the customer file are not part of it.
Inform people when collecting their data
The company’s identity, purposes and legal basis, recipients, retention period, rights and the option of complaining to the CNIL (article 13).
Bind each processor by a contract
Host, payroll software, emailing tool: the contract sets the subject, duration, instructions and security of the processing entrusted (article 28).
Wait for consent before non-essential cookies
Advertising, social networks: nothing is set before the visitor chooses. Strictly necessary trackers are exempt, such as audience measurement that meets the CNIL’s conditions (article 82 of the French Data Protection Act).
Appoint an officer only in the cases provided
Compulsory for a public body, or when the core activity consists of monitoring people on a large scale or processing sensitive or criminal data on a large scale (article 37).
Where does your business stand, and where should you start?
Tick what is already in place and what applies to you: the plan ranks the actions by priority and prepares a register sheet for the use of your choice. The example is a 6-employee firm with a showcase website.
Fictional example · compliance plan
7 actions to take, 3 of them urgent.
P1: deal with first · P2: next · P3: to schedule
- P1
Remove shared accounts, require strong passwords and test your backups. Article 32 of the GDPR
- P1
Name who receives and handles requests, and keep to the one-month time limit, extendable by two months for a complex request. Article 12 of the GDPR
- P1
Write the procedure: who spots it and assesses risk, who notifies the CNIL without undue delay and where feasible within 72 hours after awareness when a risk is likely, and where every breach is recorded. Article 33 of the GDPR
- P2
Open one sheet per processing, starting with payroll and the customer file: the sheet below is a starting point. Article 30 of the GDPR
- P2
Check the contract of the host, the payroll software or the emailing tool: subject, duration, documented instructions, confidentiality, security, sub-processors. Article 28 of the GDPR
- P2
Check the destination country: a Commission adequacy decision or appropriate safeguards, such as standard clauses; record the transfer in the register and in the information. Articles 44 to 46 of the GDPR
- P3
Set a period per category, limited to what the purpose requires, then delete or archive; record it in the register. Article 5 of the GDPR
Under 250 employees: the article 30 exemption only covers occasional, risk-free processing. Payroll, customers and prospects stay in the register.
REGISTER SHEET · ARTICLE 30 OF THE GDPR Activity: Managing customers and prospects Controller: [name, address and contact of the business] Data protection officer: none, appointment not compulsory according to your answers Purposes: Order management, invoicing and customer relations; commercial prospecting People concerned: Customers, prospects Categories of data: Identity, contact details, order and exchange history, invoicing data Recipients: Authorised staff (sales, accounts); processors: [invoicing software, CRM, host] Transfers outside the European Union: [country and safeguard: adequacy decision or standard clauses] Retention periods: [one period per category of data] Security measures: [individual accounts, strong passwords, backups] Last updated: [date]

What do the CNIL’s figures for 2025 show?
The key figures of the CNIL’s 2025 annual report. They describe CNIL activity, not only small businesses.
- Complaints received
- 20,1502025, against 17,772 in 2024 · CNIL, 2025 annual report
- Data breaches notified
- 6,1672025, up 9.5% · CNIL, 2025 annual report
- Breaches due to hacking
- 50%of the 2025 notifications · CNIL, 2025 annual report
- Penalties imposed
- 832025, 67 of them under the simplified procedure · CNIL, 2025 annual report
- Formal notices
- 1432025, for 323 inspections · CNIL, 2025 annual report
- Total fines
- €486,839,5002025, most of it for two cookie penalties · CNIL, 2025 annual report
Is a business with fewer than 250 employees exempt from the register?
Rarely. Article 30 of the GDPR exempts organisations with fewer than 250 employees, except for processing that is not occasional, processing that poses a risk to people’s rights and processing of sensitive or criminal data.
The CNIL draws the consequence: payroll and the management of customers, prospects and suppliers are not occasional and go into the register, as do video surveillance and geolocation. The exemption covers one-off cases, for example a campaign for the opening of a new site. When in doubt, record the processing.
Sources: GDPR · CNIL, register
What should you do in the 72 hours after a data leak?
Notify the breach to the CNIL without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to create a risk for people. After that time, the notification gives the reasons for the delay (GDPR, article 33).
It describes the nature of the breach, the categories and approximate number of people concerned, the likely consequences and the measures taken. If the risk is high, also inform the people without undue delay (article 34). Every breach, notified or not, is documented internally.
Source: GDPR
What must the privacy notice of a form state?
At the time of collection, article 13 of the GDPR requires the identity and contact details of the company, those of the officer if there is one, the purposes and legal basis, the recipients, any transfer outside the European Union, the retention period, people’s rights and the option of complaining to the CNIL.
In practice, a short notice under the form links to the full privacy policy. The whole must stay concise, understandable and written in clear and plain language (article 12).
Source: GDPR
Will the GDPR be lightened for small businesses?
Two European Commission proposals would do so. The one of 21 May 2025 would extend the register exemption to organisations with fewer than 750 employees, except for high-risk processing. The one of 19 November 2025 would limit notification to high-risk breaches, within a time limit raised to 96 hours.
On 24 September 2026, neither had been adopted: the rules on this page are still the ones that apply. A change will only count after its adoption and publication in the Official Journal of the European Union.
Sources: COM(2025) 501 · COM(2025) 837
What does article 33 of the GDPR say about the 72-hour time limit?
The text sets the time limit and its starting point: when the business becomes aware of the breach.
En cas de violation de données à caractère personnel, le responsable du traitement en notifie la violation en question à l’autorité de contrôle compétente conformément à l’article 55, dans les meilleurs délais et, si possible, 72 heures au plus tard après en avoir pris connaissance, à moins que la violation en question ne soit pas susceptible d’engendrer un risque pour les droits et libertés des personnes physiques. Lorsque la notification à l’autorité de contrôle n’a pas lieu dans les 72 heures, elle est accompagnée des motifs du retard.
In English, briefly (our summary, not an official translation): In the case of a personal data breach, the controller notifies it to the competent supervisory authority under article 55 without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where notification is not made within 72 hours, it comes with the reasons for the delay. The processor, for its part, informs the business without undue delay after becoming aware of the breach (paragraph 2): provide for this in your contracts. In France, the competent authority is the CNIL.
What do small business owners ask about the GDPR?
Must my business appoint a data protection officer?
Only in three cases: a public body, a core activity requiring regular and systematic monitoring of people on a large scale, or large-scale processing of sensitive or criminal data (GDPR, article 37). Outside these cases, an appointment remains possible on a voluntary basis.
Which fine does a small business risk?
The GDPR provides for up to €10 or €20 million, or 2 or 4% of worldwide turnover depending on the failing, whichever is higher (article 83). Under the simplified procedure, the fine is capped at €20,000 and the daily penalty at €100; since 28 May 2026, these caps rise to €100,000 and €500 above €50 million of turnover (article 22-1 of the French Data Protection Act).
Do audience measurement cookies require consent?
Not always. The CNIL exempts them from consent if they only measure audience, exclusively for the publisher, and produce anonymous statistics, without cross-checking or tracking on other sites. It recommends a lifetime of 13 months and data retention of 25 months at most.
Is a self-employed person with no employees covered by the GDPR?
Yes, as soon as they process customer or prospect data for their business: the GDPR sets no size threshold, apart from the limited register exemption. Only processing in the course of a purely personal or household activity is excluded (GDPR, article 2).
Must you declare your files to the CNIL?
No, for routine processing: since 25 May 2018, businesses no longer declare their files in advance. They document their compliance themselves, in particular through the register, which they make available to the CNIL on request (GDPR, article 30(4)).
Which texts and reports set these duties?
- Regulation (EU) 2016/679 (GDPR), consolidated text: articles 2, 5, 12, 13, 28, 30, 32, 33, 34, 37, 44 to 46 and 83EUR-Lex
- Law no. 78-17 of 6 January 1978, article 82 (cookies and other trackers)Légifrance, in French
- Law no. 78-17 of 6 January 1978, article 22-1 (simplified procedure), as amended by law no. 2026-403 of 26 May 2026Légifrance, in French
- The record of processing activitiesCNIL, in French
- Cookies: solutions for audience measurement toolsCNIL, in French
- 2025 annual reportCNIL, in French
- Proposal for a regulation COM(2025) 501 of 21 May 2025 (register for organisations under 750 employees)EUR-Lex · not adopted on 24 September 2026
- Proposal for a regulation COM(2025) 837 of 19 November 2025 (breach notification within 96 hours)EUR-Lex · not adopted on 24 September 2026
Texts cited last checked: 24 September 2026