Skip to content

GDPR for solo founders: what actually applies to a one-person product

21 September 2026 · 7 min read

GDPR reads like it was written for banks. Most of it scales down to a handful of habits. Here are the parts that apply to a small product.

This is a practical guide, not legal advice. If real money, health data, children or a regulator’s letter is involved, talk to a lawyer.

Does it apply to me?

It depends on your users, not your address. If you offer your product to people in the EU or UK, or track their behaviour, it applies, wherever you’re based. There’s no small-business exemption from the core rules, though a few duties, such as detailed record-keeping, are lighter for organisations under 250 people.

The five things that matter

What you can usually skip

A data protection officer is only mandatory for large-scale or high-risk processing. Formal impact assessments are for risky uses such as health data or systematic monitoring. If you’re outside the EU with only occasional EU users, the requirement to appoint an EU representative often doesn’t bite, but that one is worth a lawyer’s five minutes if you’re growing there.

The part that shows from outside

Regulators, and the customers who email them, start with what’s visible: is there a policy, does tracking wait for consent, which companies does the page contact. That’s the layer vibeliq scans. The rest, such as how you store data and answer requests, is yours to get right.

Keep reading