Image by kaboompics on Pixabay

GDPR Relief for Small Businesses and Nonprofit Organizations: What Might Change?

The government wants to ease the data protection burden on nonprofit organizations and small businesses—here's what's planned and what will continue to apply.

Data protection imposes a significant burden, particularly on small businesses, nonprofit organizations, and the self-employed. Planned reforms are intended to simplify low-risk data processing and reduce documentation requirements. However, a complete exemption from the GDPR has not been approved, nor is it readily possible for the German legislature to grant one on its own.

Who is subject to the GDPR today?

The General Data Protection Regulation (GDPR) generally applies as soon as a company or nonprofit organization processes personal data. This includes names, addresses, phone numbers, email addresses, and account information. That is why even small craft businesses, sole proprietors, and nonprofit organizations must comply with the GDPR. To date, there is no general exemption based solely on a small number of employees or low revenue.

The data collected includes, for example, customer lists, membership directories, personnel files, newsletter distribution lists, and data from contact forms. Non-commercial activities of associations are also not automatically exempt.

What relief measures are planned?

The governing coalition plans to further ease the burden on associations and small and medium-sized enterprises when it comes to low-risk data processing. A simple customer list maintained by a small business is cited as a typical example. In addition, the plan is to make better use of national discretion, simplify data protection oversight, and consolidate data protection regulations more clearly in a national “Data Code.”

Separately, the European Commission has already proposed relaxing the requirement to maintain a record of processing activities. This relaxation is to be extended to companies and organizations with fewer than 750 employees, provided that their data processing is not likely to result in a high risk to the rights of data subjects. To date, Article 30 of the GDPR has provided a more limited exemption for organizations with fewer than 250 employees.

The reform would primarily reduce the administrative burden associated with documentation. However, it does not mean that smaller organizations would be allowed to use personal data indefinitely or without a legal basis in the future.

What obligations remain?

Even if certain exemptions are granted, the fundamental data protection principles are expected to remain in effect. Personal data may only be processed for a specified and legitimate purpose. No more data may be collected than is actually necessary. In addition, data must be adequately protected and deleted as soon as it is no longer needed.

Companies and organizations must therefore continue to verify whether consent, a contract, a legal obligation, or a legitimate interest permits the processing. The data subjects’ rights to access, rectification, and erasure also remain unaffected by a mere reduction in documentation requirements.

In the event of a data breach, it may still be necessary to report the incident to the supervisory authority. Similarly, specific requirements continue to apply when sensitive health data, extensive employee data, or other high-risk information is processed.

Why Germany Cannot Repeal the GDPR on Its Own

The GDPR is a directly applicable regulation of the European Union. Germany therefore cannot independently suspend its scope of application for all associations or small businesses. Fundamental exceptions would have to be decided at the European level.

However, German lawmakers can make use of existing enabling provisions. This applies, for example, to national regulations governing the appointment of corporate data protection officers. A German data code could also consolidate various provisions and make them easier to understand, but it must not conflict with the GDPR.

Exemption does not mean a lack of data protection

Reducing bureaucracy can make day-to-day operations easier for small businesses and organizations. However, until specific changes are adopted and take effect, the existing data protection obligations remain in force. Existing directories, privacy notices, or data deletion policies should therefore not be discarded prematurely.

Are small businesses already exempt from the GDPR?

No. The GDPR generally applies regardless of revenue or the number of employees.

Does a club have to comply with the GDPR?

Yes. This also applies to nonprofit organizations as soon as they process data such as member, donor, or employee information.

Should the record of processing activities be abolished?

Under the European Commission’s proposal, more organizations could be exempted. However, the obligation would remain in place for processing operations deemed to pose a high risk.

Will it be permissible to store customer data in the future without a legal basis?

No. Even with less documentation required, a legal basis for processing is still necessary.

What should businesses do now?

They should continue to comply with applicable obligations and not scale back their data protection documentation solely on the basis of political announcements.

Kostenloser Newsletter

Aktuelle Urteile, Praxistipps und neue Folgen aus Marken-, Urheber-, Medien- und Wettbewerbsrecht. Kompakt per E-Mail.

Double-Opt-in. Abmeldung jederzeit über den Link in jeder E-Mail.

Contact person

Picture of Florian Wagenknecht

Florian Wagenknecht

Specialist lawyer for copyright and media law

Free newsletter

Kostenloser Newsletter

Aktuelle Urteile, Praxistipps und neue Folgen aus Marken-, Urheber-, Medien- und Wettbewerbsrecht. Kompakt per E-Mail.

Double-Opt-in. Abmeldung jederzeit über den Link in jeder E-Mail.

Search

Request