Does the GDPR also apply to self-employed people?
Yes. The GDPR may apply as soon as self-employed people process personal data, for example customer data, invoices, emails, contact forms, payment data, employee data or digital documents.

Data protection, customer data and office processes
Data protection in everyday office work: process data lawfully, protect access, review service providers and organise deletion and data-subject rights.
Photo by Schluesseldienst, Pixabay
The GDPR governs how personal data may be processed. For self-employed people and small businesses, it covers more areas than many expect: customer data, invoices, quotes, emails, employee data, applications, receipts, website forms, newsletters, payment data and documents in the digital office. Well-organised data protection reduces legal risks and supports more professional work.
GDPR compliance is not simply a matter of putting a privacy notice on a website. Data protection must work in everyday operations: Which data is collected? What is it used for? On what legal basis? Who has access? How long is it stored? Which service providers process data on your behalf? How are data-subject rights, deletion, access requests and security incidents handled? Motorica can help organise office processes more systematically. Where necessary, legal assessment, review and the specific design of data-protection measures should be agreed with a qualified data-protection or legal adviser.
The General Data Protection Regulation is an EU regulation protecting personal data. It applies when businesses, self-employed people or organisations process personal data. Personal data is any information relating to an identified or identifiable natural person. It includes not only names and addresses but also email addresses, telephone numbers, customer numbers, IP addresses, payment data, location data and information in invoices or documents.
Personal data is any information that can identify a person directly or indirectly. Small businesses generate such data constantly in everyday office work: in quotes, invoices, customer records, scheduling, emails, payment reconciliation, document filing and website contact forms. Business contact details can also be personal data when they can be assigned to a specific person.
The GDPR is based on principles that shape every processing operation. Data must not be collected arbitrarily or stored indefinitely. It must be processed lawfully, fairly, transparently, for specified purposes, accurately, with appropriate protection and only for as long as necessary or legally required. For self-employed people, this means collecting no more data than necessary, not repurposing it improperly and carefully restricting access.
Personal data may be processed only when an appropriate legal basis exists. For small businesses, performance of a contract, pre-contractual measures, legal obligations, legitimate interests and consent are particularly relevant. The correct legal basis should not be guessed after the event. It must fit the actual purpose and be documented.
A privacy notice should tell data subjects which personal data is processed, for what purposes, on which legal basis, by whom, for how long and with which rights. On a website, this can concern contact forms, server logs, cookies, analytics tools, embedded content, newsletters, appointment booking or payment services. The notice must match the actual website and services used.
Processing on behalf occurs when a service provider processes personal data for your business according to your instructions. Common examples include hosting, cloud software, newsletter services, support systems, external IT providers and certain accounting or office software. You will generally need a data processing agreement. Among other things, it governs the subject matter, duration, nature and purpose of processing, data categories, data subjects, instructions, subprocessors and technical and organisational measures.
Technical and organisational measures are intended to protect personal data appropriately. They involve more than encryption: access rights, passwords, backups, logging, roles, devices, training, deletion processes and emergency procedures also matter. Measures must match the risk. A cleaning business needs different safeguards from a healthcare provider, but both must protect personal data.
The record of processing activities documents which personal data the business processes. It is not a marketing document, but an internal data-protection overview. It should show traceably which processes use data, for what purpose and legal basis, who is affected, which data categories are processed, which recipients are involved, how long data is stored and which safeguards exist.
People whose data is processed have various rights, including access, rectification, deletion, restriction of processing, data portability and objection. For businesses, this means requests must not remain unorganised. You need a process for properly checking identity, deadlines, affected data, exceptions and the response.
Data protection does not mean deleting every item of data immediately. Some data must be deleted when its purpose ends and no legal basis remains. Other data must be retained longer because of tax, commercial-law or contractual obligations. Every business therefore needs a deletion policy that distinguishes active use, blocking, archiving and final deletion.
A personal data breach can occur when personal data is lost, disclosed accidentally, accessed without authorisation, altered or deleted. Examples include misdirected emails, lost devices, open cloud folders, hacked accounts or unauthorised access. Where a breach is reportable, the supervisory authority must generally be informed without undue delay and, where feasible, within 72 hours. A clear emergency procedure is therefore important.
Not every small business automatically needs a data protection officer. In Germany, one relevant threshold for non-public bodies is generally at least 20 people who continuously work with automated processing of personal data. Appointment may also be required for other reasons, such as certain high-risk processing or where core activities involve particular processing. Seek professional assessment when in doubt.
For small businesses, data protection must work in practice. Legally polished documents achieve little if customer data sits in private chats, unsorted folders or old spreadsheets. A stable office process is better: collect data only when needed, restrict access, file receipts systematically, document service providers, observe deadlines and avoid distributing sensitive information unnecessarily.
Many data-protection problems arise not from bad intent but from a lack of structure. Small businesses often use several tools, messengers, email inboxes, local files and cloud storage at once. This makes it unclear where customer data is located, who has access and when it must be deleted. A sound process helps more here than a template downloaded once.
Motorica does not replace data-protection advice and does not guarantee GDPR compliance in an individual case. The software can, however, help process personal data more systematically in everyday office work. Customer data, invoices, receipts, documents, tasks and payment information come together in one place. This makes processes more traceable, access easier to organise and records easier to find for tax advice, a data-protection review or internal control.
FAQ
Yes. The GDPR may apply as soon as self-employed people process personal data, for example customer data, invoices, emails, contact forms, payment data, employee data or digital documents.
Personal data is information relating to an identified or identifiable natural person. It includes names, addresses, email, telephone numbers, customer numbers, IP addresses, payment data and many details in invoices or documents.
No. A privacy notice is important, but data protection must also work in actual processes. This includes legal bases, data processing agreements, access protection, a deletion policy, data-subject rights, documentation and suitable technical and organisational measures.
It is generally required when a service provider processes personal data for your business according to your instructions. Typical examples include hosting, cloud software, newsletter services, external IT, support and certain office or accounting software.
They are measures protecting personal data, such as access controls, passwords, two-factor authentication, encryption, backups, role permissions, logging, training and secure deletion.
Many businesses must document their processing activities. The record shows which personal data is processed, for what purpose and legal basis, with which recipients and safeguards.
In Germany, a data protection officer must be appointed, among other cases, when generally at least 20 people continuously work with automated processing of personal data. Other reasons may also apply, including certain high-risk processing.
Document the incident immediately, assess the risk, stop the cause and check whether the supervisory authority or affected people must be notified. For reportable breaches, the general deadline is, where feasible, 72 hours.
No. Personal data should be retained only for as long as the purpose requires or legal obligations require retention. Every business therefore needs a deletion and retention policy.
Yes. Motorica can help organise customer data, invoices, receipts, documents, tasks and deadlines more systematically. It does not replace data-protection advice or guarantee GDPR compliance in an individual case.
No. MIRA can explain documents more clearly and highlight organisational information. Legal assessment, data-protection concepts, review of processing agreements or binding advice on an individual case belong with qualified data-protection or legal advisers.