EN

/

NO

The GDPR basics for growing companies

0 MIN READ

What does GDPR actually require, what do you need to have in place, and where does the real risk lie?

GDPR often gets presented as a sprawling, hard-to-navigate set of rules. For most companies, the reality is a lot less dramatic.


The basics of privacy work come down to a handful of core requirements. If your business knows what personal data it processes, why that data is used, who has access to it, and which suppliers are involved, most of the work is already done.


None of this requires a legal department or a big project. Mostly it requires making a few deliberate choices and writing them down in an organized way.


What does GDPR actually require, which documents should be in place, and where does the real risk sit?


This article is a practical rundown of the basic privacy work Norwegian companies should have under control.


GDPR applies in Norway through the EEA agreement, implemented into Norwegian law through the Personal Data Act. The rules apply to every business that processes personal data, regardless of size.


If your company has customers, users, employees, or job applicants, it's processing personal data. Which means the rules apply to you.


What does GDPR actually require of a small company?


GDPR asks five things of you:


  • Have a reason. Every piece of personal data you process needs a valid legal basis. The most common ones are that it's necessary to fulfill an agreement, that you have a legitimate interest, or that the person has consented. You choose the basis before you collect the data, one per purpose.

  • Be transparent. Tell people what data you hold on them, and why. In practice, that means a privacy policy they can easily find.

  • Keep it secure. Protect the data with sensible measures. Control who has access, don't let it sit around unmanaged, and know where it actually lives.

  • Respect people's rights. Individuals can ask what data you hold on them, ask for corrections, and ask to be deleted. You need to be able to respond, usually within a month.

  • Keep control of your suppliers. If someone else processes data on your behalf, you need an agreement with them (more on that below).


Before we go further, a quick note on what personal data actually is. Personal data is any information that can identify a living person, directly or indirectly. Name, email address, and phone number are the obvious examples. But the term also covers things like IP addresses, user IDs, location data, photos and video, employment and salary details, purchase history, customer support conversations, and technical data that can be tied back to a specific user.


A piece of information doesn't need to include someone's name to count as personal data. It's enough that the information, on its own or combined with other information, could be used to identify the person.


Which documents should the business have in place?


The practical minimum for a growing company is short:


A record of what you process. Your business should have a single overview of what personal data it processes, whose data it is, what it's used for, the legal basis, the systems and suppliers involved, any sharing that happens, how long data is kept, and your routines for security and deletion. This is usually called a record of processing activities.


Companies with fewer than 250 employees have a limited exemption from keeping this record, but the exemption normally doesn't cover processing that happens regularly as part of ordinary operations.


Either way, this kind of overview is what you need to write an accurate privacy policy, put the right data processing agreements in place, and set up proper deletion routines. The Norwegian Data Protection Authority (Datatilsynet) can also require you to produce it.


A privacy policy. Your privacy policy should explain how the business handles personal data. It should cover who the data controller is, what data gets collected, the purpose and legal basis, who the data is shared with, any transfers outside the EEA, how long data is retained, people's rights, and how to contact you.


The policy needs to reflect what you actually do, and should get updated whenever the business adopts new systems or services, or starts using data in new ways.


Data processing agreements with your suppliers. Your business needs a data processing agreement with any supplier that processes personal data on your behalf. The agreement should cover, among other things, what data is processed, the purpose, the security requirements, and what happens to the data once the agreement ends.


Many suppliers offer standard agreements, but you should still check that the agreement actually covers how you use the service, including any transfers outside the EEA.


Basic security and an incident routine. Your business should have routines for information security and for handling privacy breaches, things like misdirected emails, lost devices, unauthorized access, publishing errors, cyberattacks, or lost data.


If a breach happens, the business needs to quickly work out what happened, which data and people are affected, and what risk the incident carries. As a general rule, breaches that carry risk need to be reported to Datatilsynet within 72 hours. If the risk is high, the affected individuals need to be told too.


Does every company need a DPIA or a data protection officer?


No.


A Data Protection Impact Assessment (DPIA) is mainly needed when processing could carry high risk for individuals. That might come up with large-scale monitoring, processing of sensitive data, or new technology with significant consequences.


Most smaller companies don't need a data protection officer either. That requirement mainly applies to public sector bodies and companies that monitor people or process sensitive data at scale.


That said, responsibility for privacy should still sit clearly with someone internally.


What should be in place?


For most companies, a solid foundation looks like:


  • An overview of the personal data being processed

  • A legal basis for each purpose

  • An up-to-date privacy policy

  • Data processing agreements with the relevant suppliers

  • Basic security routines

  • Routines for access requests, corrections, and deletion

  • A plan for handling privacy breaches


That covers most of what day-to-day operations actually need.


Privacy work should get revisited whenever the business adopts new systems, brings on new suppliers, or starts using personal data in new ways.


This article is general information and isn't a specific assessment of your business. What you actually need depends on what data your company processes and how it's used.


FAQ


Does GDPR apply to small companies in Norway?


Yes. GDPR applies through the EEA agreement (implemented as the Personal Data Act) to any company that processes personal data, regardless of size. If you have customers, users, or employees, it applies to you.


What is a legal basis?


It's the valid reason you're allowed to process a piece of personal data. For example, that it's necessary to fulfill an agreement, that you have a legitimate interest, or that the person has consented. You need one for each purpose, identified before you collect the data.


Do I need a privacy policy?


Yes. You need to tell people what personal data you hold, why, and what rights they have. A clear, easy-to-find privacy policy (usually in the website footer) is how most companies meet this requirement.


When do I need a data processing agreement (DPA)?


Whenever a third party processes personal data on your behalf. Cloud hosting, CRM, email tools, payroll, analytics, AI tools, and similar. You're the data controller, they're the data processor, and GDPR requires an agreement between you.


Does my company need a data protection officer?


Usually not. It's mainly required for public bodies and private companies processing sensitive data at scale. Most growing private companies don't need one.

Written by

Meagan-headshot
Meagan Leber

meagan@frank.legal

Related readings

Sorry, there are no similar articles...

Book a meeting and see if Frank is right for you.

Book a meeting and see if Frank is right for you.