GDPR for Irish Small Businesses: The 2026 Compliance Checklist
Quick answer. Every Irish business that handles personal data must comply with GDPR. The eight things every small business needs in 2026 are: a data inventory, a lawful basis for each processing activity, a current privacy policy, a cookie consent banner, a data breach response plan, vendor agreements (DPAs), staff training, and procedures for handling subject access requests. Fines can reach €20m or 4% of global turnover.
GDPR is now seven years old. The initial scramble has settled. The Data Protection Commission has spent the last few years building enforcement habits, and they're no longer focused exclusively on big tech. Small Irish businesses get audited, complained about, and occasionally fined. The good news is that most of what's required is actually achievable for a small team in a few weeks of focused work. The bad news is that "we'll get to it" no longer works as a strategy.
This checklist is the plain-English version of what a small Irish business genuinely needs in 2026. Not what a consultant might try to sell you, not what the maximalist interpretation says. What's actually required, with practical steps for each.
GDPR applies to every Irish business, including yours
This is the first thing worth being clear on, because plenty of owners still think it's a "big company problem." It isn't. GDPR applies to sole traders. It applies to businesses with a single employee. It applies if your only "data" is a marketing email list. It applies to a one-person consultancy with three clients.
The threshold isn't size. It's whether you process personal data, and "personal data" means anything that can identify a living person. Customer names. Email addresses. Phone numbers. Eircode. CCTV footage that shows a face. Job applicant CVs. Supplier contacts. If you've got any of that, GDPR applies.
The other thing worth knowing: the Data Protection Commission has been steadily expanding its enforcement work into SMEs. Their published decisions over the last two years include fines against businesses you've never heard of, often arising from a customer complaint rather than an audit. The "we're too small to be on their radar" defence stopped working a while ago.
The eight things you actually need
1. A data inventory (what personal data do you hold?)
Everything starts here. Before you can comply with anything, you have to know what you've got. A spreadsheet is fine. List every place personal data lives in your business.
Customer records (names, emails, addresses, order history). Employee data (HR records, payroll, contracts). Supplier and contractor contacts. CCTV footage. Job applicant CVs. Marketing email lists. Cookies on your website. Forms data going into your CRM. Backups. Old laptops with files on them.
For each: what's collected, where it lives (which system, which provider), who has access, how long it's kept. This single document is the foundation for everything else. It costs nothing to make. It usually takes a focused afternoon.
2. A lawful basis for each type of processing
For every category of personal data you hold, GDPR says you need a lawful basis for processing it. There are six:
- Consent. The person explicitly said yes (used for marketing email, optional cookies).
- Contract. You need the data to deliver a service they've bought.
- Legal obligation. You're required by law, e.g. retaining tax records.
- Vital interests. Protecting someone's life (rarely applies to SMEs).
- Public task. Only public bodies.
- Legitimate interests. You have a genuine business reason and it's balanced against the person's rights.
One basis per activity. Document it. The most common SME basis is contract (for client work) and legitimate interests (for things like security logs or fraud prevention). Consent is needed for marketing email and for non-essential cookies.
3. A current privacy policy
This must say, in plain language: what data you collect, why you collect it, the lawful basis, how long you keep it, who you share it with (including any third-country transfers), and the rights of the person whose data it is. It must be accessible from every page of your website, usually via a footer link.
"Current" means it reflects what you actually do. If your privacy policy says you don't share data with third parties but you use Mailchimp, the policy isn't accurate, and that's worse than not having one. Update it any time your data practices change.
4. A proper cookie consent banner
If your website uses non-essential cookies (analytics, marketing pixels, anything beyond strictly-necessary site function), you need a cookie banner that gets actual consent before those cookies fire. The DPC has been clear and the EDPB has reinforced this: pre-ticked boxes don't count. "By using this site you accept cookies" doesn't count. You need real, freely-given consent.
That means: cookies don't fire until the user actively opts in, refusing must be as easy as accepting, the user can change their mind later, and you only collect consent for the categories you actually use. Tools like Cookiebot, Iubenda, or Osano handle this for under €15/month.
5. A data breach response plan
If you have a breach (meaning personal data was lost, exposed, or accessed without authorisation) you have 72 hours from becoming aware of it to notify the DPC, if the breach is likely to result in risk to the affected people. You may also need to notify the people themselves.
You don't need a 50-page response plan. You need a one-page document that says: how a breach gets detected, who decides whether it qualifies, who notifies the DPC, who notifies affected individuals, and who logs it. Print it. Keep a copy somewhere not on a computer that could be the thing that's breached.
6. Data Processing Agreements (DPAs) with vendors
Anyone who processes personal data on your behalf needs a Data Processing Agreement with you. Your email provider. Your CRM. Your hosting provider. Your accounting software. Your form builder.
The good news is that virtually every reputable SaaS vendor publishes a standard DPA that you can accept online or download. The work is mostly checking which of your tools handle personal data, finding their DPA, and making sure you've signed or accepted it. The bad news is that some smaller tools don't have proper DPAs at all. If you find one of those, it's a flag.
7. Staff training
Human error is the leading cause of small business data breaches. Phishing emails, lost laptops, password reuse, accidentally cc-ing the wrong person, sending a spreadsheet of customer data to someone who shouldn't have it. Training is the cheapest and highest-impact thing you can do.
It doesn't have to be expensive. Even a one-hour session covering the basics (phishing recognition, password hygiene, how to spot and report a possible breach, what to do if you get a subject access request) meaningfully reduces incident rates. Repeat annually.
8. Procedures for handling subject access requests (SARs)
Anyone can ask what personal data you hold on them. When they do, you have one month to respond, free of charge in most cases, with the data in an accessible format.
You need a procedure for: receiving the request (who handles it, where requests get logged), verifying the requester is who they say they are, gathering the data from across your systems, redacting any third-party personal data that shouldn't be included, and responding in writing. Most requests are routine. The work is in being ready, not in any single response.
What you don't necessarily need
A few common myths that lead small businesses to over-comply or pay for things they don't need.
A formal Data Protection Officer (DPO). Most small Irish businesses don't legally require a DPO. DPOs are only mandatory for public authorities, businesses that do "large-scale systematic monitoring" (CCTV across multiple locations might qualify; a customer list does not), or businesses processing "special category" data (health, biometric, racial, political, etc.) on a large scale. If you're a typical 5–20-person SME, you can name a person as the data protection contact without making them a formal DPO.
Servers physically located in Ireland. A common misconception. EU-region servers (Dublin, Frankfurt, Paris) all qualify as "in the EU" for GDPR purposes. You don't need to insist on Ireland specifically.
Cookie consent for strictly-necessary cookies. Cookies required for the site to function (session cookies, login state, shopping cart) don't need consent. Only non-essential cookies do.
The DPC's recent enforcement focus
It's worth knowing where the Commission is currently active, because that's where the practical risk concentrates. Recent enforcement themes in Ireland have included: cookie banners that don't actually get valid consent, marketing emails sent without proper opt-in (the law here is the e-Privacy Regulations as well as GDPR), CCTV footage retained too long or used beyond its original purpose, and unauthorised use of personal data for AI training without consent or notice.
Most published SME fines have been in the €1,000–€50,000 range. They're not normally business-ending in themselves, but the reputational damage and the requirement to fix the underlying issue (often more expensive than the fine) tends to be the bigger cost.
Practical first step today
If GDPR has been on the to-do list for too long and you don't know where to start, do one thing: build the data inventory from item 1. Spend two hours on it. Once you've got a clear list of what personal data your business handles, where it lives, and who can see it, everything else becomes manageable. Most other compliance work flows from that single document.
When to get professional help
The compliance work itself is often more administrative than technical, and many small businesses handle it internally. There are a few situations where outside help genuinely pays back: when you're doing a Data Protection Impact Assessment for high-risk processing (e.g. introducing AI that handles personal data), when you handle special category data, after a breach, and when a subject access request gets complex (often when it's tied up with a complaint or potential legal action).
On the technical side, the actual software that processes the data, we build websites, AI tools, and custom systems with GDPR baked in from day one. Where personal data flows, where it's stored, how it's logged, what's retained and for how long. We cover this on our Cloud & SaaS Solutions page. If you're introducing AI specifically, our guide on AI chatbots for Irish businesses covers some of the same ground from a different angle.
None of this is a substitute for legal advice in genuinely complex situations. But for the day-to-day of a small Irish business, the checklist above is the bulk of what's required, and most of it is achievable with focused effort rather than expensive consultancy.
Frequently asked questions
Does GDPR apply to a sole trader in Ireland?
Yes. GDPR applies regardless of business size. If you handle personal data, GDPR applies.
Do I need a Data Protection Officer (DPO)?
Most small Irish businesses don't. A DPO is only legally required for public authorities, businesses doing large-scale systematic monitoring, or processing special category data on a large scale.
What's the actual fine for a small business that breaches GDPR?
Lower-tier fines are up to €10m or 2% of global turnover. Higher-tier fines reach €20m or 4%. Most SME fines have been in the €1,000–€50,000 range, with reputational damage often costing more than the fine.
Do I need to keep records of consent?
Yes. If you rely on consent as your lawful basis (e.g. for marketing email), you must be able to prove when and how consent was given, and let the person withdraw it easily.
How long do I have to respond to a subject access request?
One month from receipt, with one further month if the request is complex. You must respond in writing and free of charge in most cases.
Is using ChatGPT or Claude for business GDPR-compliant?
It can be, but you need to check the AI provider's data processing terms, ensure no personal data is sent without lawful basis, and ideally use enterprise/business tiers with proper DPAs.
GDPR on the to-do list for too long?
We can help with the technical and software side: building websites, AI tools, and custom systems with GDPR baked in from day one. The first conversation is free.
Start a project →
Share
LinkedIn