The GDPR applies to everyone who processes personal data: a company, a sole trader, an association, a community body, a public institution and a state authority. The size of the company, its turnover and the number of employees do not decide whether it applies. In short: all companies that process personal data, whatever their size, must comply with the GDPR.
What takes an activity outside the Regulation is not smallness but the nature of the activity. The main exception for individuals is a purely personal or household activity. Law-enforcement authorities investigating and prosecuting crime fall under separate rules. For a foreign company, the GDPR applies if it has an establishment in the EU, or offers goods or services to people in the EU, or monitors their behaviour. Below we explain how to check this and where mistakes can be made.
Two questions that decide the answer
Do you process personal data? Personal data is any information relating to an identified or identifiable natural person (Article 4(1) GDPR). Processing is almost any operation on it: collecting, recording, storing, using, transmitting, erasing (Article 4(2) GDPR). Simply keeping customers’ email addresses is already processing.
Data about legal persons, such as a company’s name, legal form and general contact details, is not covered by the Regulation (Recital 14 GDPR). But a contact person’s name, surname and work email address are data about a human being. So even a company that deals only with other companies almost always processes personal data.
Do you process it in a way the Regulation covers? Article 2(1) GDPR covers processing by automated means and paper records that form part of a filing system. A computer, a phone, a cloud service or a sorted folder — all of these are included.
Size does not matter: the small business myth
A controller is a natural or legal person, public authority, agency or other body that determines the purposes and means of processing (Article 4(7) GDPR). This definition contains no size threshold.
The Regulation gives small businesses only one exemption from a duty, and it is narrow. Recital 13 GDPR explains that the derogation for organisations with fewer than 250 employees concerns record-keeping only. That is Article 30(5) GDPR, and even it does not apply if the processing is not occasional, may pose a risk to people’s rights, or includes special categories of data or data on criminal convictions and offences. Employee and customer data are processed all the time, so for most small companies this exception does not fit.
All the other duties apply regardless of size: informing people (Article 13 GDPR), ensuring security (Article 32 GDPR), signing contracts with processors (Article 28(3) GDPR). Size matters elsewhere — in how far the measures must go. Article 24(1) GDPR and Article 32(1) GDPR link the measures to the nature, scope and risk of the processing. What the security duty requires is covered in GDPR security measures: what Article 32 actually requires.
Sole traders, associations and public bodies
Sole traders. A natural person can also be a controller (Article 4(7) GDPR). A person working under an individual activity certificate or a business licence processes customer data as a controller. The household exemption does not apply, because it covers activity with no connection to a professional or commercial activity (Recital 18 GDPR).
Associations, community bodies, clubs. A list of members, membership fee records, event registrations and photos are personal data. An association or community body, as a legal person, and an unregistered club, as an “other body”, are controllers under Article 4(7) GDPR, and the same duties apply to them.
State and municipal authorities, budgetary institutions. The GDPR applies to them, and some duties are stricter. The exception is processing by competent authorities for the prevention, investigation and prosecution of criminal offences, to which the GDPR does not apply (Article 2(2)(d) GDPR). Separate rules cover it. A public authority or body, except courts acting in their judicial capacity, must designate a data protection officer (Article 37(1)(a) GDPR). When an officer is mandatory for others is covered in our article do we need a data protection officer. In Lithuania, administrative fines can also be imposed on public authorities (Article 33 of the Law on Legal Protection of Personal Data, ADTAĮ).
Journalism and expression. Article 4 ADTAĮ disapplies some GDPR articles where data are processed for journalistic, academic, artistic or literary purposes, including the duties to inform, the individual’s rights and records. But the exemption is not total: the principles, the legal bases and the security requirements remain. The exemption follows the purpose, not the organisation. A media company processing its subscribers’ or employees’ data applies the GDPR as usual.
The household exemption and where it ends
Article 2(2)(c) GDPR disapplies the Regulation where a natural person processes data in the course of a purely personal or household activity. Recital 18 GDPR gives as examples correspondence, keeping addresses and social networking in the course of such activity. It also adds that the Regulation applies to those who provide the means for such activity (social networks, for example).
The exemption ends where work begins. A personal phone holding customer contacts and correspondence with them is a work tool. Another example is a camera on a house. Interpreting the same exemption in the earlier directive, the Court of Justice held in its judgment of 11 December 2014 in case C‑212/13 that video surveillance which covers, even partially, a public space cannot be regarded as a purely personal or household activity.
When the organisation is not in Lithuania
An establishment in the EU. Article 3(1) GDPR applies the Regulation to processing carried out in the context of the activities of an establishment of a controller or processor in the EU, regardless of where the data are physically processed. An establishment means effective and real activity through stable arrangements, and the legal form is not decisive (Recital 22 GDPR). The EDPB Guidelines 3/2018 note that in some circumstances a single employee or agent acting in the EU may be enough for a foreign entity. According to the same guidelines, where an EU establishment processes the data, the location or nationality of the people whose data are processed does not matter. A Lithuanian company applies the GDPR to the data of its non-EU customers too.
Goods or services to people in the EU, monitoring behaviour. Article 3(2) GDPR also applies the Regulation to a company not established in the EU if its processing relates to offering goods or services to people in the EU, or to monitoring their behaviour in the EU. The mere fact that a website can be reached from the EU is not enough. What matters is whether it is apparent that the company envisages serving people in the EU. Signs of this include, for example, the language or currency of an EU country with the possibility of ordering in it, or mention of customers in the EU (Recital 23 GDPR). The EDPB Guidelines 3/2018 say monitoring may include, for example, behavioural advertising, online tracking through cookies or video surveillance.
An EU representative. Such a company must designate in writing a representative in the Union (Article 27(1) GDPR). The exception covers only occasional processing that does not involve special categories of data or data on criminal convictions on a large scale and is unlikely to result in a risk to people’s rights, and public authorities (Article 27(2) GDPR). According to the EDPB Guidelines 3/2018, failing to designate a representative is an infringement of the Regulation.
What happens when you think the GDPR does not apply to you
The risk here is not one particular duty but all of them at once. An organisation that saw itself as “too small” may have nothing: no information text, no contracts with providers, no retention periods, no incident procedure. This comes to light not on the day of an inspection, but when someone asks for their data, files a complaint, or a personal data breach occurs that usually has to be notified to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it (Article 33(1) GDPR). Then everything has to be built in a hurry, with the deadlines already running. How and when to answer a subject access request is covered in Subject access requests: the deadline and the answer.
When imposing a fine, the supervisory authority takes into account the nature, gravity and duration of the infringement, whether it was intentional or negligent (Article 83(2) GDPR), and which technical and organisational measures the organisation had put in place. An organisation that has nothing in place looks worst against this list. Which documents are most often missing is covered in our article on the GDPR document package.
When to call a lawyer
- you are a non-EU company and do not know whether your activity in the EU counts as “offering goods or services” or “monitoring”;
- you have a group company, branch or employee in Lithuania and need to determine which establishment processes the data;
- you are an association, community body or institution and have never assessed what data you process;
- you work as a sole trader with sensitive data, for example health data or children’s data;
- you rely on the journalism exemption or another exemption and want to be sure which duties remain.
Frequently asked questions
Does the GDPR apply to a company with one employee?
Yes. Article 4(7) GDPR defines the controller without any size threshold. Organisations with fewer than 250 employees have only a narrow records exemption under Article 30(5) GDPR, and it does not apply to the ongoing processing of employee or customer data. All the other duties apply.
Does the GDPR apply if we deal only with companies?
Almost always, yes. A company’s name and legal form are not personal data, but a contact person’s name, surname, phone number and work email address are. You also hold your own employees’ data. Recital 14 GDPR explains that only data about legal persons fall outside the Regulation, not data about their staff.
Is a camera on a private house covered by the GDPR?
If the camera films only your own yard, this may be a household activity under Article 2(2)(c) GDPR. If it covers, even partially, the street or another public space, the Court of Justice in case C‑212/13 did not regard such surveillance as a purely personal activity. The GDPR duties then apply, including the duty to inform.
Does the GDPR apply to a non-EU company with customers in Lithuania?
Yes, if it offers goods or services to people in the EU or monitors their behaviour in the EU (Article 3(2) GDPR). In that case it usually has to designate in writing a representative in the Union (Article 27(1) GDPR). The mere fact that a website can be reached from Lithuania does not by itself bring it under the Regulation.
How to start
Tell us what your organisation does, where it is established and whose data it processes: employees, customers, members or visitors. We will tell you whether and how far the GDPR applies to you and which duties to start with.
You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).
Email: info@linden.lt
More about this service: GDPR audit and compliance documents.