GDPR Templates for Small Businesses: The Honest Minimum
GDPR templates small business teams can use: six living core records, conditional overlays, free EU clauses, and a practical test for generic packs.

No small organisation needs a 40-document GDPR pack. The useful starting fact for anyone searching for GDPR templates small business teams can operate is that Commission Implementing Decision (EU) 2021/915 already supplies free official controller-processor clauses. A purchase is not the first step.
Those clauses solve one bounded contract problem. They can document an Article 28 controller-processor relationship when the roles and annexes are correct; they cannot decide the roles, describe every processing activity, create a transfer mechanism or replace the records that show what happens in practice 2.
Quick Answer No small organisation needs a 40-document pack. Commission Implementing Decision (EU) 2021/915 gives GDPR templates small business teams can use as free official controller-processor clauses. It covers an Article 28 relationship, but not role analysis, notices, processing records, breach evidence, retention, rights, transfers or DPIAs.
Last updated: 26 August 2026. The authority and template position was checked on 20 August 2026.
The honest minimum is a small evidence system
A small organisation usually needs six core records, not six polished files put away after approval. The records work together: the processing map supplies the facts, notices explain selected facts to people, contracts control relevant suppliers, schedules drive deletion, and the two operational logs preserve decisions about rights and incidents.
Conditional documents sit outside that core. A DPIA belongs only to processing likely to create high risk. Transfer measures belong only where Chapter V is engaged.
Consent evidence or a legitimate-interest assessment follows the chosen legal basis; an Article 26 arrangement follows genuine joint control. DPO records follow the legal test, not a desire to add a title 1.
| Document | Core or conditional? | Minimum operational content | What triggers it |
|---|---|---|---|
| Processing map / record of processing | Core | Purposes, people, data, sources, recipients, locations, retention, security, owner | Any real processing; formal Article 30 scope depends on its conditions |
| Collection-route privacy notice | Core | Controller identity, purpose, basis, recipients, rights, retention and route-specific facts | Personal data collected from the person or elsewhere |
| Controller-processor terms | Core when that role exists | Instructions, confidentiality, security, assistance, deletion, audit and completed annexes | A supplier processes personal data for the controller |
| Retention and deletion schedule | Core | Trigger, period or decision rule, system, owner, evidence | Data is created or received |
| Rights and complaint log | Core | Intake, identity checks, search route, decision, response and evidence | A request, objection or complaint arrives |
| Incident and breach log | Core | Facts, effects, risk decision, action, notification and evidence | A security event involving personal data |
| DPIA, transfer, basis, joint-control or DPO record | Conditional | Facts and reasoning required by the relevant trigger | The processing meets that specific test |
This is a document system because each record has an owner and changes when reality changes. A generic pack is merely a collection of possible shells.
Map the processing before choosing a template
The first task is to write down what actually happens. A useful pass takes one business process at a time, such as paying staff, answering website enquiries or giving an IT provider support access. Its row records the purpose, categories of people and data, source, recipients, systems, storage location, transfer position, deletion rule, security controls and accountable owner.
Map each activity and use the map as the controlled index for the core records. Add a conditional overlay only when its trigger applies, then replace every shell with real facts, assigned ownership and version control 1. Test critical routes with practical scenarios and reopen the linked records whenever processing or official routes change.
The map prevents a common drafting error: a notice says one thing, a supplier contract assumes another and the deletion schedule names a system nobody uses. It also exposes gaps before they become legal prose. If nobody can say where customer attachments are stored, buying a retention policy will not supply the missing fact.
Article 30 specifies the content of records of processing for controllers and processors and contains a limited condition for organisations employing fewer than 250 people. The exception is not a blanket small-business exemption: it does not apply where processing is not occasional, presents the relevant risk, or includes special-category or criminal-conviction data 1. Even when a formal record is not required for a narrow activity, the compact map remains the practical index for the rest of the system.
Use the processing map as the controlled index
One living index is easier to maintain than facts repeated inconsistently across a folder. Every processing activity needs a stable name, an owner and links or references to its notice, supplier terms, retention rule and any conditional assessment. The map need not be elaborate; a controlled spreadsheet can work if access, version history and review responsibility are reliable.
Controller activity and processor activity belong in separate rows rather than one vague entry. Where the same organisation acts in different roles for different services, those services are recorded separately. The legal label follows who determines purposes and essential means for that activity; it does not follow a supplier's preferred contract heading.
Version changes need reasons. A new payroll provider, an added analytics tool or a move to a non-EEA support team is not merely a new date in the footer. It changes the recipients, systems, transfer analysis, contract annexes or notice and should open the linked review tasks.
Make privacy notices follow collection routes
A privacy notice must meet the person where data enters the organisation. Website enquiries, job applications, staff administration and contact details received through a customer can involve different purposes, sources and timing. Articles 13 and 14 distinguish information collected from the person from information obtained elsewhere 1.
Reusable wording is still valuable. Controlled modules can hold the controller's identity, rights and contact route before each route-specific notice is assembled and verified. The final notice must say what is true for that route, not everything the organisation might conceivably do.
For every notice, record where it appears, which version was live and how delivery can be evidenced. A footer link may serve a website visitor, while a recruitment portal may need notice text or a link at application. The test is practical: can the owner reproduce what a particular person was told when their information arrived?
Apply the role test before using Article 28 clauses
Commission Implementing Decision (EU) 2021/915 is the free official route for standard clauses between controllers and processors in the EU/EEA 2. The Commission also publishes the clauses with supporting information 3. They are the sensible no-purchase starting point when a real Article 28 relationship exists and a provider's complete terms are unavailable or unsuitable.
The clauses are not a label that turns any supplier into a processor. Test the activity: who decides why the personal data is used, who determines the essential means, and is the supplier acting only on documented instructions? A supplier may be an independent controller for one service and a processor for another. Profession and business form are unsafe shortcuts because national law can affect categories around the EU; the functional test travels better.
| Question | 2021/915 can cover | It cannot cover |
|---|---|---|
| Is there an Article 28 controller-processor relationship? | Contract terms after the role is correctly established | The role analysis itself |
| What processing is instructed? | A completed annex describing subject, duration, nature, purpose, data and people | Vague or unknown processing facts |
| What security applies? | Recorded technical and organisational measures in the annex | Evidence that controls exist and work |
| Are sub-processors used? | Authorisation and flow-down arrangements | An incomplete or outdated supplier list |
| Is data transferred outside the EEA? | Nothing beyond its Article 28 purpose | A Chapter V transfer mechanism or assessment |
| Are other records needed? | No replacement function | Notices, ROPA, retention, rights, breach records or DPIAs |
Complete the annexes rather than writing “appropriate measures” or “as applicable”. Name systems, access controls, encryption context, recovery arrangements, deletion or return steps and sub-processor information. Someone must then test that the supplier route matches the contract.
Give retention rules an event, owner and proof
A useful retention schedule tells a person when the clock starts and what happens at the end. “Keep invoices for the legal period” merely sends the decision elsewhere. The operational record identifies the data set, system copies, trigger event, applicable decision source, owner, disposal action, exceptions such as a live dispute, and the evidence produced after deletion.
One universal period should not be imported into an EU article. Retention can depend on purpose, necessity and member-state obligations. The organisation's own schedule should record the source of each period or decision rule and route national questions to the appropriate official or specialist source.
The test should use a real sample. Select a closed customer matter, trace the live system, mailboxes, exports and backups, then record what can be deleted, what is technically delayed and who approved any hold. A schedule becomes evidence when its rule changes a system or queue.
Run one rights and complaint evidence route
People rarely use the organisation's preferred form or legal vocabulary. A request can arrive by email, telephone, social message or conversation with an employee. The template therefore begins with an intake route that helps staff recognise a request and send it to one accountable queue.
The log should capture receipt time, request scope, identity and authority checks where necessary, systems and people searched, decisions, extensions or refusals with reasons, response date and the evidence disclosed or withheld. Access to the log must itself be controlled because it can contain identity material and sensitive correspondence.
A twice-yearly scenario test makes the route observable. A plain-language request sent to an ordinary contact address shows whether it reaches the owner, whether searches cover the processing map and whether the final evidence can be reconstructed. A pristine request form cannot compensate for a route employees do not know.
Record every personal-data breach
The incident route must begin before anyone knows whether an event is reportable. Staff need one current way to report a lost device, misdirected email, exposed folder or unavailable system. The incident owner then establishes facts, containment, affected data and people, likely consequences, existing safeguards and timing.
Article 33(5) requires documentation of every personal-data breach, comprising the facts, effects and remedial action, so the supervisory authority can verify compliance 1. The record duty applies even when the risk assessment concludes that notification is unnecessary. A “not notified” outcome needs its reasoning and evidence, not an empty form.
| Breach record field | Question it must answer | Evidence to retain |
|---|---|---|
| Discovery and timeline | What happened, when, and who knew? | Reports, logs and verified chronology |
| Scope | Which people, data and systems were affected? | Search results and system facts |
| Consequences and safeguards | What harm could follow and what reduced it? | Risk reasoning and control evidence |
| Containment and remedy | What stopped exposure and prevented recurrence? | Tickets, configuration or recovery records |
| Notification decision | Was authority notification or communication required? | Decision owner, time, reasons and submissions |
| Article 33(5) record | Can the full decision be reconstructed later? | Versioned incident file, including non-notified breaches |
Authority routes and forms can change. The current official contact route belongs with the incident procedure, not copied permanently into every old template. The EDPB's small-business guidance explains practical breach assessment, while the organisation remains responsible for applying the legal thresholds to its facts 5.
Add conditional overlays only when triggered
Conditional does not mean optional after the trigger arises. Likely high-risk processing calls for a DPIA before processing; a transfer outside the EEA can require a Chapter V mechanism and related assessment; genuine joint control calls for an Article 26 arrangement. Consent and legitimate interests need evidence suited to the chosen basis, while a DPO record follows the GDPR tests 1.
The EDPB's 2026 DPIA template is not a universally final form. Its public consultation closed on 9 June 2026, and the EDPB page says finalisation and adoption steps follow 7. A small organisation may study the closed consultation draft, but should not represent it as a final adopted template or use its boxes instead of analysing the actual high-risk operation.
| Overlay | Add it when | Do not add it merely because |
|---|---|---|
| DPIA | Processing is likely to result in high risk | A pack includes a blank impact form |
| Consent record | Consent is the selected basis and must be demonstrated | A checkbox is easy to add |
| Legitimate-interest assessment | Legitimate interests are relied on and balancing must be evidenced | It is described as the default basis |
| Chapter V documentation | Personal data is transferred to a third country or international organisation | A supplier has an overseas parent |
| Article 26 arrangement | Parties jointly determine purposes and means | Two organisations collaborate |
| DPO appointment records | Articles 37–39 or applicable law make the role necessary | A DPO title appears reassuring |
Turn every selected shell into operating evidence
A template survives challenge when it tells the truth today and creates evidence tomorrow. Every bracket should become a fact, a deliberate “not applicable” and reason, or an assigned fact-finding action. Empty annexes, unexplained boilerplate and copied purposes are warning signs, even when signatures are present.
| Survival check | Weak template pack | Operational record |
|---|---|---|
| Facts and scope | Generic categories | Named activities, systems, data, people and limits |
| Decisions | Conclusions without reasons | Inputs, test, outcome, owner and evidence |
| Routes | An email or authority copied once | Current intake, escalation and notification route |
| Annexes | Blank or “appropriate measures” | Completed processing, security and sub-processor detail |
| Ownership | “The company” | Named role with access and deputy cover |
| Versioning | Download date only | Version, approver, reason and linked change record |
| Testing | Signature treated as completion | Scenario, result, defect, correction and retest |
Run one event through each critical route. A strong test asks for access, removes a former worker's permissions, changes a processor, reaches a deletion trigger and simulates a lost device. The resulting ticket, decision or log entry should stay with the record. Evidence of a working control is more useful than another policy that restates an obligation.
Use free official resources before paid drafting
The no-purchase route is concrete. Its sequence starts with the GDPR text for the duty, the Commission clauses for the bounded Article 28 contract problem, and EDPB small-business guidance for practical orientation. The EDPB practical-resources collection can point to free tools published for small organisations 6. National supervisory-authority tools may also be useful, but their availability does not turn a national claim into an EU-wide rule.
| Need | Free official route | Boundary to preserve |
|---|---|---|
| Legal duty and trigger | Regulation (EU) 2016/679 1 | Read the applicable article and any national dependency |
| Controller-processor terms | Decision (EU) 2021/915 2 and Commission publication 3 | Article 28 relationship only; complete all annexes |
| Small-organisation orientation | EDPB “Be compliant” guide 4 | Guidance does not fill organisation-specific facts |
| Breach workflow | EDPB data-breach guide 5 | The controller still makes and records its assessment |
| Tool discovery | EDPB practical resources for SMEs 6 | Check status, jurisdiction, version and fit |
| DPIA structure | EDPB 2026 consultation page 7 | Closed consultation draft awaiting finalisation/adoption |
Paid help becomes proportionate where role allocation is disputed, transfers are complex, novel monitoring creates serious risk, the processing uses sensitive data at scale, or a DPIA retains high risk. A processing map makes that instruction narrower and more valuable because the adviser receives facts instead of an empty pack.
Ignore documents that cannot change an action
Some downloads cost nothing and still create harmful confidence. Ignore a one-size-fits-all privacy policy that does not name collection routes, an undated pack with no authority or version, processor clauses used without a role test, a checkbox-only DPIA, a retention policy with no deletion event, and a breach form disconnected from the current notification route.
| Ignore this | Why it fails | No-purchase response |
|---|---|---|
| “Complete GDPR pack” sold by document count | Count says nothing about actual triggers | Build the six-record index and add only triggered overlays |
| Universal privacy notice | It hides differences in source, purpose and timing | Map collection routes and maintain controlled notice variants |
| Processor agreement for every supplier | The legal role may be wrong | Apply the functional role test, then use 2021/915 if it fits |
| Universal retention periods | Purpose and national duties differ | Record a sourced trigger and decision rule for each data set |
| DPIA with only risk scores | It omits the processing, necessity, safeguards and decision | Use the real facts; treat the EDPB draft according to its status |
| Breach form with an old address | It fails during the event | Keep one current authority route beside the incident procedure |
| Platform bought before the gap is known | Software preserves bad inputs efficiently | Operate the system in controlled files first and buy for a proved gap |
The specific “ignore this” branch matters because not buying is a valid outcome. If controlled office tools can assign owners, preserve versions, restrict access and produce evidence, use them. Software review becomes proportionate only after a scenario test exposes a real failure such as missed deadlines, uncontrolled copies or an unsearchable processing inventory.
A worked document map for a small service company
Consider a small design company with employees, a website enquiry form, business customers, cloud email, payroll support and an outsourced hosting provider. Its first map has separate activities for enquiries, contracts, staff administration and website operation. It does not assume that every outside party is a processor.
| Activity | Core records connected | Conditional question | Practical test |
|---|---|---|---|
| Website enquiries | Processing row, enquiry notice, retention rule, rights route | Are analytics or marketing choices creating separate purposes or consent evidence? | Submit an enquiry, trace notice delivery and deletion |
| Customer work | Processing row, customer/contact notice, retention, rights and incident logs | Do parties jointly determine any purpose? | Close a project and test the retention trigger |
| Staff administration | Processing row, staff notice, retention, rights and incident logs | Are special-category data, monitoring or high-risk tools involved? | Run an access request and an offboarding check |
| Payroll support | Role-specific row, applicable Article 28 terms, security annex | What role does each party actually perform under the relevant activity? | Compare system access and deletion with the annex |
| Hosted website | Processing row, supplier terms if processor, incident route | Are there non-EEA transfers or sub-processors? | Reconcile the live supplier chain with the contract |
This company may finish with six controlled core record types and only two conditional assessments. Another organisation may need more overlays but fewer notices. The number is an output of the processing, never the compliance target.
Review when the facts or routes change
Calendar review catches quiet drift, but event triggers catch it sooner. Open the linked records when a supplier, system, data source, purpose, legal basis, collection route, retention rule or security measure changes. Recheck them when legislation, EDPB guidance, official templates or supervisory-authority routes change.
| Record owner | Routine check | Change trigger | Evidence of completion |
|---|---|---|---|
| Processing-map owner | Quarterly reconciliation with systems and suppliers | New purpose, tool, recipient, location or data set | Approved row changes and linked actions |
| Notice owner | Route and version check | New source, purpose, recipient or rights effect | Published version and delivery test |
| Contract owner | Supplier and annex review | Service, role, sub-processor, security or transfer change | Executed terms, annex and control check |
| Retention owner | Sample deletion run | New obligation, system or dispute hold | Deletion report or reasoned exception |
| Rights owner | Scenario test | Intake route, search system or staff change | Timed test record and corrected defects |
| Incident owner | Contact and exercise check | Authority route, threat, system or response-team change | Exercise log, decisions and retest |
The final test is simple: an unfamiliar but authorised colleague should be able to use the current records to handle a real request, supplier change, deletion or breach without reconstructing the organisation from memory. If the forms cannot guide that action and preserve its evidence, the system needs repair, not another download.
Frequently Asked Questions
How many GDPR templates does a small business need?
Are there free official GDPR contract templates?
Can one privacy notice cover every way we collect data?
Does every small business need a record of processing activities?
Must we record a breach that is not reported?
Is the EDPB DPIA template a final form for every company?
When should a small business pay for custom GDPR drafting?
What makes a downloaded GDPR template operational?
Sources
- 1.Regulation (EU) 2016/679 — EUR-Lex · 2016
- 2.Commission Implementing Decision (EU) 2021/915 — EUR-Lex · 2021
- 3.European Commission controller/processor standard clauses — European Commission
- 4.EDPB SME guide, Be compliant — European Data Protection Board
- 5.EDPB SME guide, data breaches — European Data Protection Board
- 6.EDPB practical resources for SMEs — European Data Protection Board
- 7.EDPB public-consultation page for its DPIA template — European Data Protection Board · 2026
Want this run on your business?
AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.
You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.