GDPR applies to anyone handling EU residents' personal data, wherever the company sits. The core duties are simple to state and broad in effect: collect only what you need, say plainly what you do with it, keep it secure, and let people see, correct and erase their data.
For small businesses the practical load is a handful of honest documents — a privacy policy that describes reality, a cookie banner that actually gates trackers, a processor register, a way to answer deletion requests — plus security proportionate to what you hold. The 4% headline is for giants; small-firm fines still sting.
Related terms
Data minimization
Collecting and keeping only the data the job needs — the GDPR principle that is also the cheapest security control: what you do not hold cannot leak.
Encryption at rest
Encrypting data where it is stored — disks, databases, backups — so a stolen drive or leaked dump is ciphertext, not data.
Incident response
The plan and the practice for what happens between noticing something is wrong and being back to normal.
