Privacy & GDPR

Email and the GDPR for small organisations

The GDPR also applies to email in a small business, association or sole proprietorship: the moment you send and store names, addresses or customer data, you are processing personal data and the privacy rules apply. The good news is that as a small organisation you don't need a legal department. With a sensible foundation, a reliable provider and some common sense, you'll get a long way. Below you'll read what the GDPR asks of you in practice and what to watch out for. This article is informative and not legal advice; consult a specialist if in doubt.

By the Mailflux team Published on , updated on

What does the GDPR mean for email in a small business?

The GDPR (General Data Protection Regulation, the European privacy law) requires you to handle personal data carefully and securely. Email falls squarely within this, because a mailbox is full of names, addresses, appointments and sometimes sensitive information.

There's a persistent misconception that the GDPR only applies to large companies. That's not true: the rules apply to anyone who processes personal data, from freelancers and self-employed people to non-profits, associations and SMEs. What does differ is the scope of what's practically expected of you. For a small organisation, that's usually manageable.

Why it matters

For a small business, more is at stake than a fine. Your customers, members or patients entrust you with their data. If something leaks, it directly affects your reputation, and as a small player you weigh that especially heavily.

There's also a more concrete concern. Many free email services make money from scanning content, and with providers outside Europe it's often unclear where your data ends up. That makes it hard to demonstrate that you handle the data others entrust to you with care. If you can explain in one sentence where your email is stored and how it's secured, you're immediately in a stronger position.

Finally, there's peace of mind. As a small organisation you don't want to be dealing with privacy rules every week. A solid foundation means you don't have to.

Also important is the difference between "having to" and "being able to demonstrate". The GDPR expects not only that you act carefully, but also that you can show it if someone asks. For a small organisation, that needn't be a thick dossier: knowing where your email is stored, which security is switched on and who has access already gets you a long way. That clarity also helps you if a customer or supervisory authority ever asks questions.

How it works

Making the GDPR practical for your email comes down to a few pointers:

  1. Choose a provider that hosts in Europe and complies with the GDPR. Then your data falls under the European privacy rules instead of unknown foreign legislation. What "GDPR-compliant" precisely means is explained in GDPR-compliant email: what does that mean.
  2. Secure access. A strong password and two-factor authentication (2FA) keep unauthorised people out, and make sure connections are encrypted.
  3. Send deliberately. Not everything belongs in an ordinary email. Stricter requirements apply to sensitive data; weigh up case by case whether email is the right channel.
  4. Keep management in order. Give people access only to what they need, clean up old or departing addresses and keep track of who can access what. For teams with changing staff, this is especially important.
  5. If you need a processor, make agreements. If an external party processes personal data on your behalf, the GDPR may require a data processing agreement. What exactly is needed in your case is tailored to the situation.

What to watch out for

A few common mistakes at small organisations:

  • Thinking the GDPR doesn't apply to you. Even as a sole proprietor or association you process personal data. The rules apply, even if the burden is usually manageable.
  • Using a free address for business email. Free services sometimes scan content for ads or profiles, and an address like name@freeservice also looks less trustworthy than your own domain.
  • Mailing member lists and customer databases around. If you put many addresses in the CC instead of the BCC, you unintentionally share personal data. A classic, easily avoided mistake.
  • Forgetting people who leave. At a non-profit or association, board members change. Make sure access is handed over neatly and old accounts are closed.
  • Ignoring the data location. "It's in the cloud" says nothing about the country the servers are in. Ask where your data is stored.

Again: these are general points of attention, not a definitive legal judgement for your situation. Consult a specialist or the Belgian Data Protection Authority (GBA) if in doubt.

And with Mailflux

Mailflux lays the foundation a small organisation can build on: professional mailboxes on your own domain, hosted in Europe and GDPR-compliant, without your content being scanned for ads. Connections are encrypted, and every plan includes filtering against spam, phishing and malware, automatic backups and optional two-factor authentication.

For teams there's bulk account management, so you can create and manage several addresses at once, plus 20 free aliases for addresses like info@ or board@. If you work as a freelancer, take a look at email for freelancers and the self-employed; for an association there's email for your association or non-profit.

Ready to get started?

Professional email on your own domain, hosted in Europe and GDPR-compliant. Request your mailbox with no obligation.

Get started

FAQ

Frequently asked questions

Does the GDPR also apply to my sole proprietorship or association?

Yes. The GDPR applies to anyone who processes personal data, regardless of size. For a small business or association the practical burden is usually limited, but the basic rules on care and security apply in full. Consult a specialist if in doubt.

May I send customer data by email as a small business?

Often yes, provided you do so carefully and securely. Stricter requirements apply to sensitive or special categories of personal data, and ordinary email is by no means always suitable for those. Weigh up case by case what you send and through which channel.

Do I need a data processing agreement for my email?

That depends on your situation. If an external party processes personal data on your behalf, the GDPR may require a data processing agreement. What exactly is needed varies from case to case; consult a specialist if in doubt.

Should I keep all emails or delete them for the GDPR?

The GDPR asks that you don't keep personal data longer than necessary for the purpose you collected it for. The law gives no fixed retention periods for email; it depends on your situation and any sector-specific rules. Clean up what you no longer need and consult a specialist if in doubt.