
Personal data: practical first steps for small organisations
Data protection starts by knowing what information is collected, why it is needed and who can use it. A short accurate inventory is more useful than a long policy disconnected from daily work.
What to remember.
- Map real data flows and their owners.
- Collect only what supports a defined purpose.
- Set retention, access and deletion rules that teams can follow.
Map the information you actually use
Review forms, email, spreadsheets, analytics, CRM tools, cloud storage and suppliers. Record the people concerned, data categories, source, destination, access and responsible owner. Include informal processes, not only official systems.
Define purpose and lawful basis
Explain the operational reason for each processing activity and identify the appropriate legal basis. Do not reuse information for an unrelated purpose simply because it is available. Seek qualified advice when the context is sensitive.
Reduce collection and exposure
Remove optional fields that are not used, avoid free-text requests for sensitive details and choose privacy-conscious defaults. Less data means less effort to secure, explain, correct and delete.
Control access and suppliers
Grant access by role, review it periodically and remove it when no longer needed. Check processor contracts, data locations, security measures, sub-processors and procedures for returning or deleting data.
Set realistic retention rules
Define how long each category is needed and what event starts the period. Automate deletion where reliable, but keep a documented way to handle exceptions, legal holds and backups.
Prepare requests and incidents
People need a clear contact route for access, correction or deletion requests. Staff should know how to recognise a personal-data breach, contain it and escalate it quickly enough for the organisation to assess notification duties.