Kantis blog
GDPR for startups

GDPR for startups: what it is and why you need it

A customer has just sent you a data processing agreement, or a security questionnaire full of privacy questions. Here is what GDPR actually asks of a small B2B startup, and the minimum you need in place before the next big deal.

30-minute call. No commitment.

GDPR is the EU law that sets the rules for how companies collect, use and protect personal data. If your startup has users, customers, employees or even sales leads in the EU or the UK, it applies to you, however small you are.

The fines get the headlines. For most B2B startups, though, the real reason to sort GDPR out is simpler: bigger customers won't sign until you can answer their privacy questions.

This guide covers what GDPR is in plain English, whether it applies to you, what it actually asks you to do, and the minimum a small team needs in place.

What is GDPR?

GDPR stands for the General Data Protection Regulation. It has applied since 25 May 2018, and it is one law that applies directly across the EU and the wider European Economic Area (EEA).

It covers personal data: any information about a person who can be identified. That is broader than most founders expect:

  • names, email addresses and phone numbers, including work emails like jane.smith@customer.com
  • IP addresses, cookie IDs and device IDs
  • support tickets, call recordings and chat logs
  • your employees' and contractors' records
  • the data your customers upload into your product

The UK has its own version. After Brexit, the UK kept GDPR as "UK GDPR", alongside the Data Protection Act 2018. The Data (Use and Access) Act 2025 changed parts of it, and most of those changes have applied since February 2026. For a startup, the day-to-day rules are close enough that one programme can cover both.

Does GDPR apply to my startup?

Almost certainly, yes. GDPR has no size threshold and no revenue threshold. It applies if any of these are true:

  • your company is established in the EU (or in the UK, for UK GDPR)
  • you offer a product or service to people in the EU or UK, even if you are based in the US or elsewhere
  • you track or analyse how people in the EU or UK behave, for example with product analytics or ad pixels
  • your business customers in the EU or UK put personal data about their staff or their own customers into your product

The last point is the one B2B founders tend to miss. "We only sell to businesses" doesn't take you out of scope. Business contact details are personal data, and the data inside your product almost always includes people.

Controller or processor? You are probably both

GDPR splits responsibility between two roles:

  • Controller: decides why and how personal data is used. You are the controller for your own website visitors, leads, employees and customer contacts.
  • Processor: handles personal data on someone else's behalf and on their instructions. If you run a B2B SaaS product, you are usually the processor for the data your customers put into it.

Each role comes with its own duties. As a controller, you need a lawful basis, a privacy notice and a way to handle people's requests. As a processor, you need a data processing agreement (DPA) with each customer, you have to follow their instructions, and you have to tell them quickly if something goes wrong.

Most of the paperwork enterprise customers send you is about your processor role.

Why GDPR matters for a startup founder

1. Enterprise customers ask before they sign

This is the trigger we see most often. A larger customer's procurement or legal team sends a DPA, a security questionnaire and a list of privacy questions. Until you can answer them, the deal sits in procurement.

Typical questions:

  • Where is our data hosted, and does it leave the EU or UK?
  • Which subprocessors do you use?
  • How do you protect personal data, and who can access it?
  • How quickly will you tell us about a breach?
  • How do you delete our data when the contract ends?
  • Do you use our data to train AI models?

If the answers, documents and evidence are ready, privacy review becomes a formality. If they aren't, it can add weeks to a deal and make you look riskier than you are.

2. Fines and complaints are real

Under EU GDPR, the most serious breaches can be fined up to €20 million or 4% of worldwide annual turnover, whichever is higher. UK GDPR works the same way, with a cap of £17.5 million or 4%.

Regulators rarely go after a small startup out of nowhere. Problems usually start with a complaint from a user, a data request you ignored, or a breach you didn't handle well. Since 19 June 2026, UK organisations also have to give people a way to make data protection complaints, acknowledge them within 30 days and respond without undue delay.

3. Investors and acquirers check it

Due diligence now routinely covers data protection, especially for startups in AI, health, fintech, HR tech and anything else that handles sensitive data. A clear record of what data you hold and why is much easier to show than to rebuild under a deadline.

4. It is cheaper to build in early

Deleting a customer's data on request, setting retention periods, limiting who can see production data: all of this is easy to design in at five people and painful to retrofit at fifty.

What GDPR actually asks you to do

The seven principles, in plain English

Article 5 of GDPR sets out seven principles. Everything else follows from them.

Principle What it means for a startup
Lawfulness, fairness and transparency Have a valid reason for each use of personal data, and tell people about it clearly
Purpose limitation Use data for the purpose you collected it for, not for something unrelated later
Data minimisation Collect only what you need
Accuracy Keep data correct, and let people fix it
Storage limitation Don't keep personal data forever; set retention periods
Integrity and confidentiality Secure it: access control, encryption, backups, monitoring
Accountability Be able to prove all of the above with records and evidence

Accountability is the one that catches startups out. Doing the right things isn't enough; you need to be able to show that you do them.

You don't need consent for everything

This is a common myth. Consent is one of six lawful bases in Article 6. The others are contract, legal obligation, vital interests, public task and legitimate interests.

Most B2B software runs on contract (you need the data to deliver the service) and legitimate interests (for example, security logging and fraud prevention). Consent mainly comes up for non-essential cookies and some marketing.

People have rights over their data

Individuals can ask to access, correct, delete or export their data, or object to how you use it. You normally have one month to respond. As a processor, you need to help your customers answer requests about the data in your product.

Breaches come with a clock

If a personal data breach is likely to put people at risk, the controller has to tell the regulator within 72 hours of becoming aware of it, and tell the people affected if the risk is high. As a processor, you must tell your customer without undue delay, and many enterprise DPAs set an even shorter deadline. That only works if you've decided in advance who does what.

A practical GDPR checklist for startups

This is the minimum viable version for a small B2B software company.

  1. Map your personal data. What you collect, where it lives, why you have it, who can access it and which vendors touch it. Write it down as a record of processing activities (RoPA).
  2. Choose a lawful basis for each use, and note it in the same record.
  3. Publish a privacy notice that matches what you actually do, not a template copied from another company.
  4. Sort out cookies. Non-essential cookies and trackers generally need consent. That rule comes from the ePrivacy rules (PECR in the UK), but it belongs in the same project.
  5. Sign DPAs with your own vendors, and keep an up-to-date subprocessor list.
  6. Have your own DPA ready for customers, with your security measures attached.
  7. Check international transfers. If personal data leaves the EU or UK, for example to US cloud or AI providers, you need a transfer mechanism such as Standard Contractual Clauses or the EU-US Data Privacy Framework. Data can flow freely between the EU and the UK: the European Commission renewed its UK adequacy decision in December 2025, and the UK recognises the EU in the same way.
  8. Secure the data. Multi-factor authentication, least-privilege access, encryption, logging, backups, tested restores and clean offboarding. This is where GDPR and ISO 27001 overlap most.
  9. Set retention periods, and delete data you no longer need.
  10. Set up a process for data subject requests, so nothing sits unanswered for a month.
  11. Write a breach response plan that names who decides, who notifies and by when.
  12. Run a data protection impact assessment (DPIA) where the risk is high, for example large-scale sensitive data, systematic monitoring, or new AI features that use personal data.
  13. Train the team at onboarding, then regularly.
  14. Check the local admin. UK companies that handle personal data generally need to pay the ICO data protection fee. Companies outside the EU that serve people in the EU may need to appoint an EU representative, and the same applies the other way round for the UK.

Do you need a Data Protection Officer?

Probably not. A Data Protection Officer (DPO) is mandatory only if you are a public authority, if your core business involves regular and systematic monitoring of people on a large scale, or if you process special category data, such as health data, on a large scale. Most early-stage B2B startups don't meet that bar.

Some countries go further. In Germany, for example, you generally need a DPO once 20 or more people regularly work with personal data on computers.

You still need a named owner for privacy, usually a founder or the CTO.

Is GDPR a certification?

No. GDPR is a law, not a certificate you can hang on the wall, and there is no standard GDPR certificate that buyers expect the way they expect ISO 27001. The regulation does allow approved certification schemes, but they are rare, and enterprise buyers seldom ask for one.

What buyers ask for is evidence: your DPA, your subprocessor list, your policies, your security measures, and often an independent certificate like ISO 27001 that shows the security side has been audited.

GDPR vs ISO 27001 vs SOC 2

GDPR ISO 27001 SOC 2
What it is EU and UK law on personal data International standard for information security management US attestation framework from the AICPA
Mandatory? Yes, if it applies to you No, but often required by customers No, but often required by US customers
What you get No certificate; you show compliance with documents and evidence A certificate from an accredited certification body A SOC 2 report from an independent CPA firm
Focus Privacy, people's rights, lawful use of data Security of all information, risk-based Security controls, plus optional criteria

They overlap more than they look. GDPR requires "appropriate technical and organisational measures" to protect personal data (Article 32), and an ISO 27001 information security management system (ISMS) covers much of that.

ISO 27001 doesn't cover the privacy-specific parts, though: lawful basis, transparency, people's rights and retention. That's why European startups often do the two together. One set of evidence, two answers for procurement.

If ISO 27001 is also on your list, start with our ISO 27001 for startups guide and the ISO 27001 cost breakdown.

Common GDPR mistakes startups make

  • "We're B2B, so GDPR doesn't apply." It does. Work emails are personal data, and so is what your customers store in your product.
  • "We're not in the EU." If you serve or track people in the EU or UK, the rules follow the data.
  • A copied privacy policy. It lists tools you don't use and misses the ones you do.
  • No DPAs with your own vendors. Your customers will ask for your subprocessor list, and you can't vouch for vendors you never signed terms with.
  • Production data everywhere. Customer data in test environments, in spreadsheets, or pasted into AI tools without checking the terms.
  • Keeping everything forever. Old leads, former employees' files and churned customers' data are all risk and no value.
  • Treating it as a one-off document project. GDPR is ongoing. New vendors, new features and new AI use cases all change your answers.

How Kantis helps startups with GDPR

Kantis helps UK and EU B2B startups get GDPR-ready without turning it into a founder side project. We cover UK GDPR and EU GDPR together, usually alongside ISO 27001, so the same evidence answers both sets of questions.

In practice, that means:

  • mapping your personal data and building your records of processing
  • preparing privacy policies and procedures that match how your team really works
  • reviewing your vendors and subprocessors
  • getting your answers ready for DPAs, security questionnaires and customer due diligence
  • sharing the proof with buyers through your Trust Center

Qorelo completed its ISO 27001 certification, a SOC 2 Type I Security examination and a GDPR readiness review through one coordinated process. Centinel Analytica did its GDPR readiness work alongside ISO 27001, to support customer and procurement conversations.

If a customer has just sent you a DPA or a privacy questionnaire, talk to a founder. We'll tell you honestly what you need now and what can wait.

This guide is general information for founders, not legal advice. For a specific legal question, talk to a qualified data protection lawyer.

Frequently asked questions

Does GDPR apply to small startups? +

Yes. GDPR has no size or revenue threshold. If you handle personal data about people in the EU or UK, including users, leads, employees or the data your customers store in your product, it applies. A few admin duties are lighter for small companies, but the core rules are the same.

Does GDPR apply if we only sell to businesses? +

Yes. Names and work email addresses are personal data, and B2B products usually hold data about your customers' staff or end users. For that data you are usually your customer's processor, which means you need a data processing agreement (DPA) with each of them.

Does GDPR still apply to UK companies after Brexit? +

Yes. The UK has its own version, UK GDPR, which sits alongside the Data Protection Act 2018 and was updated by the Data (Use and Access) Act 2025. If you also serve people in the EU, EU GDPR applies as well.

Does GDPR apply to US startups? +

Yes, if you offer your product to people in the EU or UK or monitor their behaviour, for example through product analytics. Being based outside Europe does not take you out of scope, and you may need to appoint a representative in the EU or UK.

Is there a GDPR certification? +

Not in the way there is for ISO 27001. GDPR is a law, and companies show compliance with documents and evidence. Approved GDPR certification schemes exist but are rare. Customers usually ask for a DPA, a subprocessor list, your policies and security measures, and often an ISO 27001 certificate.

Do startups need a Data Protection Officer? +

Usually not. A DPO is required for public authorities and for companies whose core activities involve large-scale, systematic monitoring of people or large-scale processing of special category data, such as health data. Some countries add their own rules; in Germany, a DPO is generally required once 20 or more people regularly process personal data. Otherwise, most startups just need a named person who owns privacy.

What are the fines for breaking GDPR? +

Up to €20 million or 4% of worldwide annual turnover under EU GDPR, whichever is higher, and up to £17.5 million or 4% under UK GDPR. Small startups rarely see fines that size, but complaints, ignored data requests and badly handled breaches still cost money, time and deals.

Is ISO 27001 enough for GDPR? +

No, but it covers a large part of it. ISO 27001 handles the security side that GDPR requires under Article 32. You still need the privacy parts, such as lawful basis, privacy notices, people's rights, retention and DPAs. Doing both together saves a lot of duplicate work.

What is a DPA? +

A data processing agreement is the contract between a controller and a processor that GDPR requires under Article 28. It sets out what data you process and on whose instructions, how it is protected, which subprocessors you use and what happens to the data when the contract ends.

Allow analytics and advertising cookies? Privacy Policy