GDPR: a simple guide for small business compliance
Learn what GDPR means for your Australian business, who it applies to, and how to get compliant.

Written by Lena Hanna—Trusted CPA Guidance on Accounting and Tax. Read Lena's full bio
Published Tuesday 26 May 2026
Table of contents
Key takeaways
- GDPR applies to any business worldwide that handles the personal data of people in the EU or UK, including Australian businesses that offer goods or services to, or monitor the behaviour of, individuals in those regions.
- The seven core GDPR principles require you to collect only necessary data, use it solely for stated purposes, keep it accurate and secure, and be transparent about your data handling practices.
- Non-compliance can result in fines of up to 20 million euros or 4% of your global annual turnover, whichever is higher, so it's worth getting your data processes right from the start.
- Australian businesses should also be aware of the Privacy Act 1988 and its 2024 reforms, which introduced a statutory tort for serious privacy invasions alongside existing obligations under the Australian Privacy Principles.
What is GDPR?
The General Data Protection Regulation (GDPR) is Europe's comprehensive data privacy law. It sets the rules for how businesses collect, store, and use personal information about people in the European Union.
GDPR took effect on 25 May 2018 and applies to every company worldwide that processes personal data about people in the EU. The regulation gives individuals control over their personal data, including the right to know what information you hold, request its deletion, and receive a portable digital copy.
Who does GDPR apply to?
GDPR isn't just for European companies. It applies to any business, anywhere in the world, that handles the personal data of people located in the European Union (EU) or the United Kingdom (UK).
You may need to comply if you:
- have customers located in the EU or UK
- market goods or services to people in those regions
- track or monitor website visitors from the EU or UK
- offer goods or services to people in the EU or UK, even for free
If any of these apply to your business, you'll need to follow GDPR requirements regardless of where your business is based. This means many Australian businesses with European customers or website visitors are subject to the regulation.
What does GDPR mean for your business?
GDPR establishes clear rules for how you handle customer data and gives individuals specific rights over their information. Here are the key areas GDPR covers.
- Personal data scope. GDPR protects the personal data of your customers, employees, suppliers, and anyone else in the EU whose data you collect. Personal data includes names, contact details, medical information, credit card or bank account details, and other identifying information.
- Data collection transparency. You must make it clear what the personal data will be used for and only use it for that purpose. Contracts, terms, and conditions should be simple, clear, and easy to understand.
- Individual rights. GDPR gives individuals the right to know what information you hold about them, to request deletion of their data, and to receive a portable digital copy. You must respond to these requests within one month at no charge.
- Breach reporting. You must report certain types of data breaches to the relevant supervisory authority within 72 hours of becoming aware of them.
The UK government adopted GDPR into UK law as the UK GDPR before Brexit. However, the UK's Data (Use and Access) Act 2025 has since introduced reforms to UK data protection rules, so UK and EU requirements are no longer identical. If you handle data from both UK and EU individuals, check the specific obligations under each regime.
The 7 principles of GDPR
GDPR is built on seven key principles for handling personal data. These principles form the foundation of compliant data practices.
- Lawfulness, fairness, and transparency. Be clear and honest about why you're collecting data and what you'll do with it.
- Purpose limitation. Only use the data for the specific reason you collected it for.
- Data minimisation. Only collect the data you actually need, and nothing more.
- Accuracy. Make sure the personal data you hold is accurate and up to date.
- Storage limitation. Don't keep data for longer than you need to.
- Integrity and confidentiality. Keep the data safe and secure from unauthorised access or loss.
- Accountability. You're responsible for showing how you comply with these principles.
GDPR vs Australia's Privacy Act
If you're an Australian business, you may need to comply with both GDPR and Australia's own privacy legislation. Understanding the differences helps you meet your obligations under each framework.
Australia's Privacy Act 1988 establishes the Australian Privacy Principles (APPs), which set out how businesses should handle personal information. The Privacy Act applies to private sector organisations with an annual turnover of at least AUD $3 million and all federal government agencies.
Key differences between GDPR and the Privacy Act include:
- Consent requirements. GDPR requires express, informed consent for data processing, while the Privacy Act allows implied consent in many situations and only requires express consent for sensitive information.
- Scope of "personal data". GDPR's definition of personal data is broader and includes data that allows a person to be identified, while Australia's definition covers information about an identified or reasonably identifiable individual.
- Individual rights. GDPR provides broader rights including the right to erasure ("right to be forgotten") and data portability, which aren't explicitly covered under the Privacy Act.
- Penalties. GDPR fines can reach up to 20 million euros or 4% of global annual turnover, while Australian penalties can be up to AUD $50 million or 30% of Australian annual revenue under 2022 amendments.
The Privacy and Other Legislation Amendment Act 2024, which received royal assent on 10 December 2024, introduced significant reforms to Australia's privacy framework. These include a statutory tort for serious invasions of privacy (commenced 10 June 2025), a framework for a Children's Online Privacy Code, and enhanced enforcement powers for the Office of the Australian Information Commissioner (OAIC). If you handle EU personal data, you should ensure compliance with both frameworks.
GDPR penalties and fines
GDPR uses a two-tier system of penalties for non-compliance. Understanding the potential consequences helps you prioritise your compliance efforts.
For less severe infringements, fines can reach up to 10 million euros or 2% of your business's global annual turnover from the previous year, whichever is higher. For serious infringements, fines can be up to 20 million euros or 4% of global annual turnover.
Regulators consider your business size, the nature of the infringement, and your efforts to comply when deciding on penalties. Since GDPR took effect in 2018, regulators across Europe have issued thousands of fines totalling billions of euros, with enforcement activity continuing to increase year on year.
The main goal of these penalties is to encourage you to protect personal data properly. Even for small businesses, the financial and reputational risks of non-compliance make it worth investing in good data practices from the start.
How to make your small business GDPR compliant
GDPR compliance centres on treating personal data ethically and transparently. Follow these steps to get your small business on the right track.
1. Audit your data collection
Start by mapping what personal data you collect, where it's stored and how it's used. Check which of your products, services or website features collect personal data from EU or UK individuals. Make sure you have a lawful basis for processing each type of data you collect.
2. Update your privacy notices and contracts
Review your privacy notices to ensure they clearly explain what data you collect, why you collect it and how individuals can exercise their rights. Update customer contracts to include necessary GDPR clauses and data processing terms. Keep the language simple and accessible.
3. Set up processes for individual rights requests
Create clear procedures for responding to data access, deletion, and portability requests within the one-month timeframe GDPR requires. Ensure your systems can locate and export an individual's personal data when requested.
4. Assign data protection responsibility
Designate someone in your organisation to oversee GDPR compliance and privacy matters. Most small businesses don't need a formal data protection officer, but having someone accountable for data protection helps you stay on track. Train your team so everyone understands their data protection responsibilities.
5. Secure your systems
GDPR requires appropriate technical and organisational measures to protect personal data. This includes secure storage, access controls, and encryption where necessary. Using cloud-based accounting software with built-in security features can help you meet these requirements for your financial data.
6. Manage international data transfers
If you transfer personal data outside the EU, you need adequate safeguards in place. For transfers to the United States, check whether providers participate in the EU-US Data Privacy Framework (DPF), which has provided a formal adequacy mechanism for EU-US data transfers since July 2023.
Participating US organisations can receive EU personal data without additional safeguards. For non-participating providers, you'll need standard contractual clauses or other appropriate protections.
Manage your data with confidence using Xero
Getting your data practices right doesn't have to be complicated. Cloud-based accounting software like Xero helps you keep financial records organised, secure, and accessible, with built-in features like access controls, encryption, and automated backups that support your compliance efforts. To see how Xero can help your business, get one month free.
FAQs on GDPR
Here are answers to frequently asked questions about GDPR.
Does GDPR apply to Australian businesses?
Under GDPR Article 3(2), the regulation applies to any non-EU business that offers goods or services to, or monitors the behaviour of, individuals in the EU. In practice, this means an Australian business should check whether its website, marketing, or customer base touches the EU or UK market, and if so, treat GDPR compliance as a legal obligation rather than optional best practice.
Is there a GDPR exemption for very small businesses?
No, GDPR doesn't include a small business exemption based on size or revenue. If you process personal data of EU or UK individuals, you must comply regardless of how small your business is. However, some obligations scale with the volume and sensitivity of data you handle.
What happens if an Australian business breaches GDPR?
GDPR has extraterritorial reach, so the EU can pursue non-EU businesses for non-compliance. Enforcement typically works through your appointed EU representative or through contractual obligations with EU-based partners and customers who are required to ensure their supply chain complies.
Do I need a data protection officer for my small business?
Under GDPR Article 37, a DPO is required if your core activities involve large-scale systematic monitoring of individuals, if you process special category data (such as health or biometric information) on a large scale, or if you're a public authority. If none of these apply, you aren't legally obliged to appoint one.
How does GDPR affect Australian websites with EU visitors?
If your website uses tracking cookies, analytics or marketing tools that collect data from EU visitors, GDPR likely applies to you. You'll need to obtain consent before placing non-essential cookies and provide clear information about how you use visitor data.
Disclaimer
Xero does not provide accounting, tax, business or legal advice. This guide has been provided for information purposes only. You should consult your own professional advisors for advice directly relating to your business or before taking action in relation to any of the content provided.
Get one month free
Purchase any Xero plan, and we will give you the first month free.