Note upfront: this article gives a practical overview but does not replace legal advice. For specific questions about your situation, it's worth consulting a professional.

What counts as personal data in the first place

A customer's name, address, phone number, email address — all of that falls under the GDPR as soon as it's stored, whether in a spreadsheet, a CRM system, or on paper in a filing cabinet. That applies to essentially any business with customer contact, not just online shops or large companies.

The core principles, briefly summarized

Practical pitfalls in daily business

A few situations that get overlooked more often than you'd think: passing customer data to subcontractors via unencrypted email. A shared spreadsheet with customer data that anyone on the team can view unprotected. Old customer records that are still sitting around digitally, years after the contract ended, with nobody quite sure why.

Your own website's contact form

Your website is also relevant here: if you offer a contact form, you need a privacy policy explaining what happens with the submitted data — what's collected, for what purpose, and for how long it's kept.

What to do in an actual incident

If customer data is exposed through a security incident (e.g. a stolen laptop, a hacked email account), there may be an obligation to notify the relevant data protection authority within 72 hours. That's another reason prevention (backups, encryption, access restrictions) is cheaper than damage control after the fact.

Data protection problems are rarely one big mistake — usually they're many small lapses that add up.

Sort out the technical side of data protection

Access rights, encryption, and secure storage — the technical implementation can move forward independently of legal advice.

Get in touch