GDPR for businesses
Personal data is anything that can be linked to a person: name, email address, phone number, an order. You already handle it, so here is how to do it right without it getting complicated.
This is our interpretation of GDPR and the rules on email advertising, not legal advice. We are not lawyers. Read up at the Swedish Authority for Privacy Protection, IMY, and get help from a lawyer if you process sensitive data or data from many customers.
What GDPR is, and when it applies to you
GDPR, the General Data Protection Regulation, is the EU law that protects individuals' personal data. If you collect names, email addresses, phone numbers or addresses from customers, and almost every company does, it applies to you. It also applies to data about employees and about contacts at your business customers. The company is the data controller, and in a limited company it is ultimately the board that is responsible for ensuring the rules are followed.
Every processing activity needs a legal basis. The most common for a small company are contract (you need the address to deliver the order), legal obligation (bookkeeping requires that receipts and invoices are kept), legitimate interest and consent. Write down which basis you use for what.
May we save the customer list in a spreadsheet?
Yes. A spreadsheet on your own computer, for example in LibreOffice Calc, is a perfectly fine place for a customer list. Only collect what you need: name, email and what the person ordered is often enough, address when you are going to deliver or invoice, and personal identity number only if you really must. Share the list only within the company, never as an open link. Protect the computer with a password, encrypt the disk and make backups, so that the list neither disappears nor ends up with the wrong person. If you want to work in the list several people at the same time, works CryptPad, which stores everything encrypted.
Newsletters and advertising by email
Here the Marketing Act applies alongside the GDPR. Advertising by email or text message to a private individual requires that the person has said yes in advance, for example by ticking a box at the checkout or signing up on your list. A sole proprietorship (enskild firma) counts as a private individual here.
There is an exception for existing customers. If you received the customer's email address when they bought something from you, you may send advertising for your own, similar products, if the customer was given a clear opportunity to opt out when the address was collected and gets it again in every mailing. To companies and other legal entities, you may send advertising without consent, but the recipient must always be able to opt out of further mailings.
Every mailing must show who is sending it and have an unsubscribe link that actually works. Emails about the customer's own order, delivery or receipt are not marketing and do not require a separate yes.
Services that manage the data for you
The email tool, the web shop, the accounting software and the cloud storage process your customers' data on your behalf. You need a data processing agreement with each of them; with most serious providers it is included in the terms or can be approved in the control panel. Also check where the data is stored. If it is outside the EU, your privacy policy must state this.
How long may you store the data?
For as long as you need them for what you said they would be used for, and no longer. Make a simple retention plan: which lists exist, how long each list is kept and who clears them. A fixed day in the calendar, preferably the same day as the annual accounts, makes it happen.
Receipts and invoices are an exception. Accounting records must be kept for seven years, and for that long you can refuse a customer who wants exactly that information deleted. But the exception applies only to the accounting records: the same customer must still be removed from the newsletter list and the customer register if they ask for it.
For UF companies
When the UF year ends, you need to settle your personal data. Delete customer lists, email lists and accounts that are no longer needed. Go through everything with the guide Closing in June and the June closing checklist, so that nothing is forgotten.
What a privacy policy should contain
It does not need to be long, but it should answer this, in plain language:
- Who is the data controller, with the company's name and contact details.
- What data you collect, why, and which legal basis you rely on.
- Who gets access to them, for example your web shop, your email tool or the shipping company, and whether they are transferred outside the EU.
- How long you store it, for example two years after the last purchase, and seven years for what belongs to the bookkeeping.
- The customer's rights: to find out what data you have, to have it corrected or deleted, to object and to withdraw consent.
- That the customer can complain to IMY if they think you are doing something wrong.
Add the text as a separate page in the online store or link to it at the bottom of the website. Legal checklist goes through the rest of the legal side.
Inventory, customer questions and incidents
A small business needs in practice a record of its processing activities. The exemption for companies with fewer than 250 employees does not apply to processing that takes place all the time, such as a customer register or payroll. A spreadsheet with one row per list is enough: what, why, legal basis, how long and which services are involved.
If a customer asks for a copy of their data, or to have it deleted, you must respond within one month. And if something goes wrong, for example a computer with the customer list is stolen or an email goes to the wrong recipient, it must be reported to IMY within 72 hours if it could pose a risk to those affected. Write down what happened even if you do not report it.
What happens if you make a mistake?
The penalty fees can in theory become very large. For a small company it is in practice about being able to show that you take the rules seriously: that you know which obligations you have and why, that you have a policy that matches and that you correct mistakes when you find them.
If you want to go deeper, The Swedish Authority for Privacy Protection, IMY the Swedish authority that explains GDPR in plain Swedish, with answers aimed at small businesses.
Do you want help getting it right?
We help you write a short privacy policy and clean up your lists. UF companies get free advice by us; everyone else is welcome to contact us.
Contact us Tools with privacy