GDPR reads like it was written for banks. Most of it scales down to a handful of habits. Here are the parts that apply to a small product.
This is a practical guide, not legal advice. If real money, health data, children or a regulator’s letter is involved, talk to a lawyer.
Does it apply to me?
It depends on your users, not your address. If you offer your product to people in the EU or UK, or track their behaviour, it applies, wherever you’re based. There’s no small-business exemption from the core rules, though a few duties, such as detailed record-keeping, are lighter for organisations under 250 people.
The five things that matter
- Know what you collect and why. Emails to log people in, payment details to charge them, logs to keep the service running. Each needs a reason: usually “needed to provide the service”, sometimes consent. If you can’t say why you hold something, stop collecting it.
- Say so in a privacy policy that matches what your app really does. What goes in one.
- Know your processors. Your host, database, email sender, analytics and payment provider all handle your users’ data for you. Accept each one’s data processing agreement (it’s usually a click in their dashboard) and list them in your policy. Finding the ones you forgot.
- Answer requests. People can ask for a copy of their data, a correction, or deletion, and you have a month to respond. For a small product that’s an email address someone reads and a database query.
- Keep it safe, and own up if you don’t. Reasonable security for your size, and a breach that puts people at risk has to be reported to the regulator within 72 hours of finding out.
What you can usually skip
A data protection officer is only mandatory for large-scale or high-risk processing. Formal impact assessments are for risky uses such as health data or systematic monitoring. If you’re outside the EU with only occasional EU users, the requirement to appoint an EU representative often doesn’t bite, but that one is worth a lawyer’s five minutes if you’re growing there.
The part that shows from outside
Regulators, and the customers who email them, start with what’s visible: is there a policy, does tracking wait for consent, which companies does the page contact. That’s the layer vibeliq scans. The rest, such as how you store data and answer requests, is yours to get right.