GDPR Compliance: What Small Businesses Need to Know

  • The General Data Protection Regulation (GDPR) applies to any business handling EU residents’ data, including US small businesses that email or sell to customers in Europe.
  • Consent must be documented and specific when you rely on it as your legal basis for sending marketing emails to contacts in the EU.
  • Fines for violations can reach up to 4% of annual global turnover or EUR 20 million, whichever is higher, so even small businesses face real enforcement risk.
  • Constant Contact offers built-in tools to document consent, manage permissions, and support unsubscribe requests, helping you stay compliant.

GDPR compliance means following the rules set out by the European Union’s data privacy law to protect personal data and respect individuals’ rights over how their information is used. If you’re a small business owner with customers or subscribers in the EU, GDPR affects you, and the stakes are real.

This article covers what GDPR is, its core principles, whether it applies to your business, the rights it gives individuals, what consent means for email marketing, and how Constant Contact helps you comply. We’ll also walk through a practical compliance checklist. (Note: You should consult your own legal counsel to determine if you’re subject to GDPR requirements.)

What is GDPR?

GDPR stands for the General Data Protection Regulation. It’s the EU’s data privacy law, and it has been in force since May 25, 2018. European lawmakers passed it to create a consistent set of data privacy rules across all EU member states.

Its purpose is to:

  • Support privacy as a fundamental human right;
  • Require companies that handle personal data to be accountable for managing that data appropriately; and
  • Give individuals rights over how their personal data is processed or otherwise used.

What are the 7 principles of GDPR?

Article 5 of the GDPR sets out seven principles that guide how you should handle personal data. Think of these as the foundation for everything else in the regulation.

  • Lawfulness, fairness, and transparency: Process data legally, fairly, and in a clear way people can understand.
  • Purpose limitation: Collect data for specific, stated reasons and don’t use it for something else later.
  • Data minimization: Only collect what you actually need. A salon booking appointments only needs a name, email, and phone number, not a full home address.
  • Accuracy: Keep data correct and up to date.
  • Storage limitation: Don’t keep personal data longer than necessary for the purpose you collected it.
  • Integrity and confidentiality: Protect data with appropriate security measures against unauthorized access, loss, or damage.
  • Accountability: You’re responsible for demonstrating compliance with all of the above.

What is personal data?

GDPR defines personal data as “any information relating to an identified or identifiable natural person.”

In addition to the obvious (such as name, address, email address, financial information, contact details, and identification numbers), personal data can include information related to your digital life, such as an IP address, geolocation, browsing history, cookies, or other digital identifiers.

It also could mean information about a person, including their physical, mental, social, economic, or cultural identities.

In short, if information can be traced back to or related in some way to an identifiable person, it’s highly likely to be personal data. For example, if your gym stores a member’s email, attendance history, and payment details, that’s all personal data under GDPR.

What rights does the GDPR provide to individuals?

GDPR gives individuals several rights over their personal data:

  • Right to be informed: Individuals must be told what data you’re collecting, why, how long you’ll keep it, and who you’ll share it with.
  • Right of access: Individuals can ask for a copy of the personal data retained about them and an explanation of how it’s being used.
  • Right to rectification: Individuals have the right to correct, revise, or remove any of the personal data retained about them at any time.
  • Right to be forgotten: Individuals can ask to delete their personal data.
  • Right to restrict processing: If an individual believes, for example, that their personal data is inaccurate or collected unlawfully, they may request limited use of their personal data.
  • Right of portability: Individuals have the right to receive their personal data in a structured, commonly used, and machine-readable format.
  • Right to object: Where an individual decides that they no longer wish to allow their personal data to be included in analytics or to receive direct marketing emails or other personalized marketing content, they may opt out of use of their data for these purposes.
  • Rights related to automated decision-making: Individuals have the right not to be subject to decisions based solely on automated processing (including profiling) that significantly affect them, with some exceptions.

These rights are not absolute, and limitations or exceptions may apply in some cases.

Does GDPR apply to your business?

GDPR doesn’t just apply to companies based in the EU. Under Article 3 (territorial scope), the regulation applies to any organization, anywhere in the world, that offers goods or services to people in the EU or monitors their behavior.

What does this mean for a US small business? If your boutique ships products to Germany, or your fitness studio has EU subscribers on its email list, GDPR likely applies to you. Even if you don’t have a physical presence in Europe, collecting email addresses from EU residents for marketing purposes brings you under GDPR’s reach.

The bottom line: Location doesn’t exempt you. If you’re marketing to or collecting data from people in the EU, consult with your legal counsel about your obligations.

What is Constant Contact doing to comply with the GDPR?

If you exercise any of your GDPR rights as an individual Constant Contact customer or representative of a Constant Contact customer, Constant Contact will respond in accordance with our Privacy Statement.

The Constant Contact privacy notice explains what information we collect about you as a Constant Contact customer and how we handle your personal data in this context where the GDPR applies. This statement includes descriptions of how your personal data may be used by Constant Contact. We suggest that you review how this applies to you.

Where required, we also support you, as a Constant Contact customer, in fulfilling GDPR-related data subject requests you receive from your contacts.

For data transferred from the EU to the United States, current legal mechanisms include the EU-US Data Privacy Framework (adopted by the European Commission in July 2023) and Standard Contractual Clauses. These frameworks help ensure that personal data receives appropriate protection when transferred across borders. You can review the specifics of how Constant Contact handles international data transfers in our Privacy Statement.

Some responsibilities of the GDPR you should understand

Generally speaking, there are two types of parties that have a responsibility regarding the handling of data: the “controller” and the “processor.” It’s important to determine whether you’re acting as a controller or a processor and understand your responsibilities accordingly.

A “controller” determines the purposes and means of the use of personal data.

A “processor,” on the other hand, only acts on the instructions of the “controller” and processes personal data on their behalf.

So, what does this mean?

Constant Contact is the controller in relation to your personal data provided to us as a customer. You are the controller in relation to the contact data you upload and use in your Constant Contact account.

Constant Contact is your processor when we provide our services to you. For example, when facilitating the sending of emails to contacts and providing tools to manage your contact lists, we’re acting as a processor on your behalf.

It’s your responsibility to ensure that you have the necessary notices and consents in place in order to transfer personal data to us for use.

In addition, we review and update, as necessary, our agreements with you and with our subcontractors (including the necessary GDPR terms), as well as notices, policies, and internal processes, features, and templates to support our compliance and help you achieve compliance.

What do I need to do differently to comply with GDPR?

If the GDPR applies to you, there are various obligations you’ll need to comply with in order to send emails to your contacts. The good news is that not all of these are new, so you should be complying with some of them already.

The most important differences in this context are as follows:

  • More information about your use of personal data must be communicated to your contacts. You should make sure that your privacy notices and policies are updated to reflect the requirements of the GDPR, including setting out the purposes of your processing personal data, how long you’re retaining such data, and what legal basis for use of personal data you’re relying on. Also, you should ensure that the email sign-up forms you use include clear and specific language about all the possible ways you’ll be using your contacts’ personal data. For example, you can set their expectations by adding additional language such as “We’ll be sending you our monthly email newsletter, including the latest news about our events and new products, plus advance notice of occasional sales.”
  • You should determine the legal basis for your use of personal data. If you’re relying on consent to use your contact’s data, you should ensure that the consent you have meets the requirements of the GDPR (more details on this below). Please note that sending marketing emails to contacts may require, in certain circumstances, prior opt-in consent from your contact. As a reminder, you’ve already agreed through acceptance of our terms of service to lawfully obtain and process all personal data appropriately and have attested that you have permission to email contacts uploaded to your account.
  • You’ll also need to comply with the rights provided to individuals by the GDPR. See the section above, “What rights does the GDPR provide to individuals?”

To the extent that you have these obligations, we have tools in place to help support your compliance efforts. These include methods for you to document consent to email your existing contacts, as well as ways for you to confirm and document consent for new ones, too.

You should consult with your legal counsel on the above and your other obligations under GDPR.

The GDPR requires documented consent from your contacts.

You may be familiar with implied consent from CAN-SPAM legislation in the US and CASL in Canada where consent may be inferred based on a contact’s actions. For example, a contact may have implied consent by having an existing business relationship with you, including making a purchase from you or a donation to you.

When in doubt, and you’re relying on consent to send emails to your contacts, express consent is typically your best option. You obtain and document express consent when you explicitly ask your potential contacts for permission to send them emails, and they agree, and that agreement is recorded. Constant Contact has ways for you to indicate whether you’ve obtained express or implied consent from a contact, outlined in more detail below.

Now for the good stuff: There may be circumstances where you can rely on something similar to implied consent for sending emails to contacts even when subject to the GDPR. This is called a “soft opt-in” where:

  • You’ve obtained their contact details in the context of a sale of a product or service,
  • You’re sending emails relating to similar products or services, and
  • The contact has the ability to opt out of receiving such emails when they first provided their data when making a purchase and in every subsequent email from you.

You should consult with your legal counsel to determine whether you can rely on the soft opt-in under the GDPR. If you have contacts with soft opt-in consent, you can store them as implied consent in Constant Contact, but you’ll need to maintain your own documentation about how you obtained that soft opt-in consent.

Contacts should also be given an easy way to withdraw their consent in order to comply with the GDPR. Constant Contact provides a SafeUnsubscribe link at the bottom of every email sent by your Constant Contact account.

How is Constant Contact helping me comply with GDPR?

Constant Contact has tools to help you obtain and manage consent within your account.

As always, contacts can opt out of receiving emails at any time by clicking the SafeUnsubscribe link included at the bottom of every email you send with your Constant Contact account.

When a contact gives consent through one of the methods listed below, they’ll be tracked and documented as having provided express consent within Constant Contact:

  1. GDPR email confirmation: Documenting consent for your existing contacts

We’ve created a fully editable email template that you can customize and send to your email contacts. It’s a fast, easy way for you to gain documented consent for your existing contacts that have opted in to receiving emails from you.

Since we’re a permission-based email marketing company, under our terms of service, you agree that you’ve obtained consent to email your contacts where required to do so by law, but the GDPR requires you to have documented evidence of such consent.

You don’t need to send this email if you already hold GDPR-compliant documented consent for these contacts. You can easily see whether you have implied or express consent within Constant Contact by turning on the Advanced Email Permissions. See below for more information on documented consent. See how the “GDPR Consent Confirmation” email works. Please note: You’ll need to log into your account to access this template. Get template.

  1. Sign-up forms: Obtaining consent from your new contacts

Constant Contact sign-up forms where contacts can subscribe to receive your emails will automatically document your contacts’ consent to receive emails if they sign up through those channels.

If you want an extra level of comfort to make sure you have documented consent, you can also turn on confirmed opt-in (also known as double opt-in) in your account. This requires new contacts to confirm their subscription by clicking a link before you can send them additional emails after they’ve opted in to receiving emails from you. Please make sure that you review our documentation about confirmed opt-in to understand how this works.

When you export your contacts to a file, you’ll be able to view permission status, email status, and date of opt-in, allowing you to track consent within Constant Contact.

  1. Check your email permissions

When you view a contact profile within your Constant Contact account, you’ll be able to see if you have permission to send or if the contact has unsubscribed. Further, you can turn on the Advanced Email Permissions to see if consent is implied or express when viewing a contact profile. Please note that for EU contacts, GDPR requires documented consent in order to send email to them.

  1. Export your contacts

When you export your contacts, you’ll have the option to export data showing you which email addresses have provided consent. Additional data fields you can export include:

  • Permission status (implied vs. express)
  • Email status (active, unsubscribed, confirmed, etc.)
  • Date of confirmed opt-in (if the link/confirmed opt-in email is used)
  1. Specify implied or express permission on file import

When you upload a file of contacts, you’ll have the option of selecting if the list of contacts has provided express or implied permission and the contacts will be uploaded with that permission status. Please note that under GDPR, you should only upload lists of contacts who have provided consent. You should maintain your own offline documentation of these contacts’ consent.

If your list only includes contacts located outside of the EU (including contacts located in the US and Canada), which are not subject to the GDPR, you may upload lists of contacts who have provided you with either express or implied consent, and you should select the applicable permission status as it pertains to the list you upload.

  1. Add or edit a single contact to specify permission

You can add a single contact and specify if you have express or implied permission when adding the contact. You can also edit the permission status of a single contact from within your account. For example, in the event you’ve received offline express consent from a contact, you can update that contact’s permission status from “implied” to “express.”

How to access and correct data

You can view and update a contact’s information on the contact profile page within your Constant Contact account.

Your contacts can also access and update their information and their marketing preferences by clicking the update profile link in the footer of each email that is sent to them by you using the Constant Contact service. By default, the update profile form only shows a contact’s email address. If you’re storing more information about contacts, you can enable those fields to be visible to contacts as well.

How to export data

You can export your contacts’ data at any time.

What if you collect contacts offline?

If you use methods outside of Constant Contact to get new contacts, it’s up to you to ensure compliance with the GDPR to get and document consent to send them emails.

When you manually add contacts to your Constant Contact account, if you have the “advanced email permissions” setting turned on, you’ll be able to mark whether those new contacts have given you the express permission. If you don’t have advanced email permissions enabled, all contacts you add will be marked as implied permission.

Your GDPR compliance checklist

Getting compliant doesn’t have to be overwhelming. Here’s a practical checklist to work through:

  1. Map what personal data you collect and why. List the types of data you gather (such as names, emails, purchase history) and your purpose for each.
  2. Identify your lawful basis. For email marketing, this is usually consent. Determine which legal basis applies to each type of processing.
  3. Get and document consent. Use clear sign-up forms, confirmation emails, and Constant Contact’s consent-tracking tools.
  4. Update your privacy notice. Write in plain language what data you collect, why you collect it, how long you keep it, and who you share it with.
  5. Honor data subject requests. Be ready to provide access, make corrections, or delete personal data when individuals ask.
  6. Offer an easy unsubscribe option. Every email should include a clear way to opt out. Constant Contact’s SafeUnsubscribe handles this automatically.
  7. Keep data secure. Use appropriate security measures. If a serious breach occurs, you must notify the relevant supervisory authority within 72 hours of becoming aware of it.
  8. Consider whether you need a DPO or DPIA. Most small businesses doing standard email marketing won’t need a Data Protection Officer (DPO) or a Data Protection Impact Assessment (DPIA). However, if you process personal data on a large scale or handle sensitive categories of data, these may apply. When in doubt, consult legal counsel.

This checklist gives you a starting point, but every business is different. Work with your legal counsel to make sure you’re meeting all applicable requirements.

What are the penalties for not complying with GDPR?

GDPR violations can result in significant fines. Article 83 sets out a two-tier penalty structure:

  • Lower tier: Up to EUR 10 million, or up to 2% of the company’s total worldwide annual turnover from the preceding financial year, whichever is higher. This applies to violations of obligations such as record-keeping and security measures.
  • Upper tier: Up to EUR 20 million, or up to 4% of the company’s total worldwide annual turnover from the preceding financial year, whichever is higher. This applies to violations of core principles (such as consent requirements) and data subject rights.

For a small business, the percentage-based calculation means fines scale to your revenue. It stings to think about enforcement, but regulators have shown they take GDPR seriously. Even if you’re a small operation, non-compliance puts you at risk.

Got more questions about GDPR?

If you’re a Constant Contact customer and have specific questions about GDPR, please contact Support.

Otherwise, if you’re ready to start taking compliance seriously — start your free trial to see how Constant Contact’s consent-tracking, permission management, and reporting tools can help you stay compliant while building stronger relationships with your contacts

NOTE: The information included on this page is meant to guide you through the process of understanding GDPR and is not a substitute for legal advice. For the official regulation text, visit the GDPR official text.

Share with your network
Avatar photo

Andy is a security and privacy expert with experience in the SaaS and SMB industry.

Related Articles