Note upfront: this article gives a practical overview but does not replace legal advice. For specific questions about your situation, it's worth consulting a professional.
What counts as personal data in the first place
A customer's name, address, phone number, email address — all of that falls under the GDPR as soon as it's stored, whether in a spreadsheet, a CRM system, or on paper in a filing cabinet. That applies to essentially any business with customer contact, not just online shops or large companies.
The core principles, briefly summarized
- Data minimization — only collect what you actually need, don't stockpile data "just in case."
- Purpose limitation — data collected for order processing shouldn't casually be reused for marketing.
- Storage limitation — don't keep data indefinitely; delete it once it's no longer needed (subject to statutory retention periods, e.g. for invoices).
- Appropriate security — protect customer data from unauthorized access, e.g. through access restrictions and current software.
Practical pitfalls in daily business
A few situations that get overlooked more often than you'd think: passing customer data to subcontractors via unencrypted email. A shared spreadsheet with customer data that anyone on the team can view unprotected. Old customer records that are still sitting around digitally, years after the contract ended, with nobody quite sure why.
Your own website's contact form
Your website is also relevant here: if you offer a contact form, you need a privacy policy explaining what happens with the submitted data — what's collected, for what purpose, and for how long it's kept.
What to do in an actual incident
If customer data is exposed through a security incident (e.g. a stolen laptop, a hacked email account), there may be an obligation to notify the relevant data protection authority within 72 hours. That's another reason prevention (backups, encryption, access restrictions) is cheaper than damage control after the fact.
Data protection problems are rarely one big mistake — usually they're many small lapses that add up.
Sort out the technical side of data protection
Access rights, encryption, and secure storage — the technical implementation can move forward independently of legal advice.
Get in touch