HomeBlogPersonal Data in Your Business: A Practical Guide
Back to blog
Legal Protection

Personal Data in Your Business: A Practical Guide

Customer files, emails, cameras, staff records: personal data flows through every part of your business. Here is how to collect it, secure it, respect people's rights and react to a leak, with simple habits.

5 March 20264 min read
Share :
Personal Data in Your Business: A Practical Guide
Photo: FlyD on Unsplash

What counts as personal data?

Personal data means any information about an identified or identifiable individual. A name, a work email address, a phone number or a number plate all qualify. So does an IP address, in many cases. Your business therefore handles personal data about clients, prospects, staff and even suppliers.

Some information calls for extra care: health, beliefs, ethnic origin, biometrics or criminal records. By contrast, truly anonymous information falls outside the Regulation. Pseudonymised information, however, still counts as personal data.

This guide focuses on everyday habits. For the documentation side (record, DPO, impact assessment), read our GDPR compliance action plan.

Collect less, collect better

Every form should answer a simple question: what is this information for? If you cannot answer, do not ask for it. Less personal data means less risk if a leak occurs.

  • Remove unnecessary optional fields.
  • State the purpose next to the form.
  • Set a retention period for each file.
  • Delete or anonymise what you no longer need.

Also inform people at the point of collection, with a short and readable privacy notice.

Securing personal data every day

Most leaks come from simple mistakes. A few measures cover the essentials.

1Turn on two-factor authentication for email and online tools.
2Limit access, so that each employee sees only what they need.
3Encrypt laptops and phones.
4Back up regularly, with an offline copy.
5Install software and system updates without delay.
6Train the team to spot phishing.

Choose reliable providers too. Your hosting firm or invoicing software processes personal data for you, so a processing agreement must frame its role.

Respecting individuals' rights

Anyone can ask for access to their personal data, its correction or its erasure. People can also object to direct marketing at any time. You generally have one month to reply.

So prepare a simple procedure: a dedicated email address, a proportionate identity check and a template reply. Log each request and the date of your answer.

Marketing, newsletters and cookies

For email marketing to private individuals, prior consent remains the rule. A narrow exception exists for existing customers and similar products. Every message must include an easy unsubscribe link.

On your website, non-essential cookies require prior consent. Refusing must stay as easy as accepting. A banner that forces a "yes" exposes your business to a complaint.

Cameras and staff records

A security camera films identifiable people, so its footage counts as personal data. The Camera Act of 21 March 2007 requires, among other things, a declaration to the police services and a pictogram at the entrance. Never film workstations without a precise reason.

Staff files deserve the same care. Restrict access to HR documents and frame any monitoring of work emails. In Belgium, collective agreement no. 81 sets the conditions for that monitoring.

Responding to a personal data breach

A leak can happen despite every precaution. Act fast and in the right order.

1Contain the incident: change passwords and isolate the device.
2Assess the risk for the people affected.
3Notify the DPA within 72 hours if a risk exists.
4Warn the people concerned if the risk looks high.
5Document the incident and the measures you took.

Cyber insurance can fund expert help and crisis management. Our guide to professional insurance presents this cover.

Example: a physiotherapy practice

Tom runs a physiotherapy practice in Wavre with two colleagues. His files hold health information, which counts as sensitive. First, he replaces the shared spreadsheet with secure medical software. Next, he turns on two-factor authentication and encrypts the laptops. Then he displays a clear privacy notice at reception. One day, a colleague loses a phone, yet encryption keeps the patients' personal data unreadable.

Common mistakes

  • Emailing a client file as an unprotected attachment.
  • Keeping old CVs with no time limit.
  • Putting all recipients in visible copy.
  • Using one password for every tool.
  • Forgetting the personal data stored on phones.

In summary

Protecting personal data mostly takes discipline: collect less, secure better, respect rights and react quickly to a leak. For an overview of all your safeguards, read our guide to legal protection for your company. The DPA website also offers practical guidance. With Juristelo, include these tools and training costs in your financial plan.

Share :

Work with your own figures

Juristelo builds your financial plan and business plan from your answers. You get a file ready for your bank.

See the Juristelo plans