Use Motorica for €59 per month for twelve months instead of €100 per month.Offer valid until 31 August 2026Claim this offer
A self-employed person reviews customer data, data-protection duties and digital documents under the GDPR

Data protection, customer data and office processes

GDPR for self-employed people: customer data, legal bases and duties

Data protection in everyday office work: process data lawfully, protect access, review service providers and organise deletion and data-subject rights.

Photo by Schluesseldienst, Pixabay

The GDPR governs how personal data may be processed. For self-employed people and small businesses, it covers more areas than many expect: customer data, invoices, quotes, emails, employee data, applications, receipts, website forms, newsletters, payment data and documents in the digital office. Well-organised data protection reduces legal risks and supports more professional work.

GDPR compliance is not simply a matter of putting a privacy notice on a website. Data protection must work in everyday operations: Which data is collected? What is it used for? On what legal basis? Who has access? How long is it stored? Which service providers process data on your behalf? How are data-subject rights, deletion, access requests and security incidents handled? Motorica can help organise office processes more systematically. Where necessary, legal assessment, review and the specific design of data-protection measures should be agreed with a qualified data-protection or legal adviser.

What is the GDPR?

The General Data Protection Regulation is an EU regulation protecting personal data. It applies when businesses, self-employed people or organisations process personal data. Personal data is any information relating to an identified or identifiable natural person. It includes not only names and addresses but also email addresses, telephone numbers, customer numbers, IP addresses, payment data, location data and information in invoices or documents.

  • The GDPR protects the personal data of natural persons
  • Customers, prospects, employees, applicants and contacts are affected
  • Small businesses and solo self-employed people can also be affected
  • Processing includes collecting, storing, using, transmitting, deleting and archiving
  • Data protection must be implemented in daily work, software and processes
  • A privacy notice alone is not enough

Which data is personal data?

Personal data is any information that can identify a person directly or indirectly. Small businesses generate such data constantly in everyday office work: in quotes, invoices, customer records, scheduling, emails, payment reconciliation, document filing and website contact forms. Business contact details can also be personal data when they can be assigned to a specific person.

  • Name, address and contact details
  • Email address and telephone number
  • Customer number and contract data
  • Invoice and payment data
  • IP addresses and online identifiers
  • Employee and applicant data
  • Location and assignment data
  • Notes about customers, contacts or transactions
  • Documents containing personal information

The key GDPR principles

The GDPR is based on principles that shape every processing operation. Data must not be collected arbitrarily or stored indefinitely. It must be processed lawfully, fairly, transparently, for specified purposes, accurately, with appropriate protection and only for as long as necessary or legally required. For self-employed people, this means collecting no more data than necessary, not repurposing it improperly and carefully restricting access.

  • Lawfulness: every processing operation needs a legal basis
  • Transparency: data subjects must receive clear information
  • Purpose limitation: use data only for specified purposes
  • Data minimisation: collect only necessary data
  • Accuracy: keep data current and factually correct
  • Storage limitation: do not retain data unnecessarily long
  • Integrity and confidentiality: protect data technically and organisationally
  • Accountability: document data-protection decisions traceably

Privacy notice: what must be explained clearly?

A privacy notice should tell data subjects which personal data is processed, for what purposes, on which legal basis, by whom, for how long and with which rights. On a website, this can concern contact forms, server logs, cookies, analytics tools, embedded content, newsletters, appointment booking or payment services. The notice must match the actual website and services used.

  • Name and contact details of the controller
  • Purposes of processing
  • Legal bases for processing
  • Categories of data processed
  • Recipients or categories of recipients
  • Retention period or the criteria used to determine it
  • Data-subject rights
  • Information about the right to complain to a supervisory authority
  • Information about cookies, tracking and external services
  • Information about transfers to third countries where relevant

Data processing agreements: classify processing on behalf correctly

Processing on behalf occurs when a service provider processes personal data for your business according to your instructions. Common examples include hosting, cloud software, newsletter services, support systems, external IT providers and certain accounting or office software. You will generally need a data processing agreement. Among other things, it governs the subject matter, duration, nature and purpose of processing, data categories, data subjects, instructions, subprocessors and technical and organisational measures.

  • Check which service providers process personal data
  • Conclude data processing agreements with processors
  • Document subprocessors and subservice providers
  • Review technical and organisational measures
  • Clearly regulate instructions and support access
  • Consider deletion or return of data after the contract ends
  • Do not confuse a data processing agreement with standard terms and conditions
  • Assess controllers and joint controllers differently

Technical and organisational measures

Technical and organisational measures are intended to protect personal data appropriately. They involve more than encryption: access rights, passwords, backups, logging, roles, devices, training, deletion processes and emergency procedures also matter. Measures must match the risk. A cleaning business needs different safeguards from a healthcare provider, but both must protect personal data.

  • Use strong passwords and two-factor authentication
  • Assign access rights by role
  • Allow only necessary people to access customer data
  • Set up and test regular backups
  • Keep devices, browsers and software current
  • Encrypt data transmission
  • Document and restrict support access
  • Store or destroy paper documents securely
  • Define deletion and blocking processes
  • Raise employees’ awareness of data protection

Record of processing activities

The record of processing activities documents which personal data the business processes. It is not a marketing document, but an internal data-protection overview. It should show traceably which processes use data, for what purpose and legal basis, who is affected, which data categories are processed, which recipients are involved, how long data is stored and which safeguards exist.

  • Customer management
  • Quotes and invoices
  • Receipt and document filing
  • Payment reconciliation
  • Employee management
  • Applications
  • Contact form and website
  • Newsletter or marketing
  • Support and customer communication
  • Tax advice and accounting

Data-subject rights: access, deletion and objection

People whose data is processed have various rights, including access, rectification, deletion, restriction of processing, data portability and objection. For businesses, this means requests must not remain unorganised. You need a process for properly checking identity, deadlines, affected data, exceptions and the response.

  • Access to personal data being processed
  • Rectification of incorrect data
  • Deletion where no obligation or legal basis for further retention exists
  • Restriction of processing
  • Data portability in suitable cases
  • Objection to certain processing
  • Withdrawal of consent for the future
  • Right to complain to a data-protection supervisory authority
  • Document responses and meet deadlines

Deletion and retention: not everything may be deleted immediately

Data protection does not mean deleting every item of data immediately. Some data must be deleted when its purpose ends and no legal basis remains. Other data must be retained longer because of tax, commercial-law or contractual obligations. Every business therefore needs a deletion policy that distinguishes active use, blocking, archiving and final deletion.

  • Check the purpose of storage
  • Observe statutory retention periods
  • Do not delete invoices and accounting records prematurely
  • Do not retain applicant data indefinitely
  • Handle newsletter data appropriately after withdrawal
  • Review customer accounts after contracts end
  • Protect archived data from unauthorised access
  • Document deletion and blocking
  • Schedule regular deletion runs

Personal data breach: what matters in an incident

A personal data breach can occur when personal data is lost, disclosed accidentally, accessed without authorisation, altered or deleted. Examples include misdirected emails, lost devices, open cloud folders, hacked accounts or unauthorised access. Where a breach is reportable, the supervisory authority must generally be informed without undue delay and, where feasible, within 72 hours. A clear emergency procedure is therefore important.

  • Document the incident immediately
  • Assess the affected data and people
  • Assess the risk to affected people
  • Secure access and stop the cause
  • Involve service providers or processors
  • Check whether notification to the supervisory authority is required
  • Check whether affected people must be informed
  • Document measures and decisions traceably
  • Remedy the vulnerability permanently

Data protection officer: when is one relevant?

Not every small business automatically needs a data protection officer. In Germany, one relevant threshold for non-public bodies is generally at least 20 people who continuously work with automated processing of personal data. Appointment may also be required for other reasons, such as certain high-risk processing or where core activities involve particular processing. Seek professional assessment when in doubt.

  • Check how many people continuously perform automated data processing
  • Assess the nature and risk of processing
  • Review special categories of personal data with particular care
  • A data protection impact assessment may trigger additional duties
  • An external data protection officer may be more practical for small businesses
  • Do not confuse appointment with general data-protection organisation
  • The business remains responsible even without a data protection officer

GDPR in the everyday office work of small businesses

For small businesses, data protection must work in practice. Legally polished documents achieve little if customer data sits in private chats, unsorted folders or old spreadsheets. A stable office process is better: collect data only when needed, restrict access, file receipts systematically, document service providers, observe deadlines and avoid distributing sensitive information unnecessarily.

  • Do not organise customer data in private messenger chats
  • File invoices and receipts centrally
  • Restrict access to customer data
  • Handle employee data separately and confidentially
  • Review old export files regularly
  • Do not forward documents unnecessarily by email
  • Review cloud and software providers for data protection
  • Apply deletion and archiving rules in daily work

Common GDPR mistakes

Many data-protection problems arise not from bad intent but from a lack of structure. Small businesses often use several tools, messengers, email inboxes, local files and cloud storage at once. This makes it unclear where customer data is located, who has access and when it must be deleted. A sound process helps more here than a template downloaded once.

  • No suitable privacy notice on the website
  • Contact forms without clear information
  • Forgetting data processing agreements with service providers
  • Storing customer data on private devices or in chats
  • Too many people have access to sensitive data
  • No deletion periods defined
  • Keeping backups and exports without control
  • Failing to document data-subject requests
  • Failing to report data breaches internally
  • Treating data protection only as a website issue

How Motorica supports GDPR-oriented office work

Motorica does not replace data-protection advice and does not guarantee GDPR compliance in an individual case. The software can, however, help process personal data more systematically in everyday office work. Customer data, invoices, receipts, documents, tasks and payment information come together in one place. This makes processes more traceable, access easier to organise and records easier to find for tax advice, a data-protection review or internal control.

  • Manage customer data more centrally
  • File invoices, receipts and documents systematically
  • Consider access and role models in office processes
  • Organise tasks and deadlines more traceably
  • Use MIRA to classify official letters and documents more clearly
  • Prepare data for tax advisers and administration more systematically
  • Reduce uncontrolled filing in email, paper and messengers
  • Keep data-protection documents such as processing agreements, technical and organisational measures and the deletion policy in view

FAQ

Frequently asked questions about the GDPR

Does the GDPR also apply to self-employed people?

Yes. The GDPR may apply as soon as self-employed people process personal data, for example customer data, invoices, emails, contact forms, payment data, employee data or digital documents.

What is personal data?

Personal data is information relating to an identified or identifiable natural person. It includes names, addresses, email, telephone numbers, customer numbers, IP addresses, payment data and many details in invoices or documents.

Is a privacy notice enough for GDPR compliance?

No. A privacy notice is important, but data protection must also work in actual processes. This includes legal bases, data processing agreements, access protection, a deletion policy, data-subject rights, documentation and suitable technical and organisational measures.

When do I need a data processing agreement?

It is generally required when a service provider processes personal data for your business according to your instructions. Typical examples include hosting, cloud software, newsletter services, external IT, support and certain office or accounting software.

What are technical and organisational measures?

They are measures protecting personal data, such as access controls, passwords, two-factor authentication, encryption, backups, role permissions, logging, training and secure deletion.

Must I keep a record of processing activities?

Many businesses must document their processing activities. The record shows which personal data is processed, for what purpose and legal basis, with which recipients and safeguards.

When do I need a data protection officer?

In Germany, a data protection officer must be appointed, among other cases, when generally at least 20 people continuously work with automated processing of personal data. Other reasons may also apply, including certain high-risk processing.

What must I do in a personal data breach?

Document the incident immediately, assess the risk, stop the cause and check whether the supervisory authority or affected people must be notified. For reportable breaches, the general deadline is, where feasible, 72 hours.

May I store customer data indefinitely?

No. Personal data should be retained only for as long as the purpose requires or legal obligations require retention. Every business therefore needs a deletion and retention policy.

Does Motorica help with GDPR-oriented work?

Yes. Motorica can help organise customer data, invoices, receipts, documents, tasks and deadlines more systematically. It does not replace data-protection advice or guarantee GDPR compliance in an individual case.

Is MIRA a data-protection advisory service?

No. MIRA can explain documents more clearly and highlight organisational information. Legal assessment, data-protection concepts, review of processing agreements or binding advice on an individual case belong with qualified data-protection or legal advisers.