GDPR Templates for SMEs: Get Your Privacy Admin in Order
As a business owner, you process personal data every day: from customer contact details in your CRM to employee time logs. The Dutch Data Protection Authority (AP) requires you to document this properly, which takes time you'd rather spend on actual work. The AP has published free templates that help SMEs and freelancers comply with privacy rules quickly. Below you'll find what you need, how to use the templates, and what's coming next.
Not legal advice — always consult a legal adviser for your specific situation.
What the GDPR Requires From You
The GDPR places two concrete documentation obligations on virtually every business that processes personal data:
1. A processing register (GDPR Art. 30) The AP states that businesses processing customer data are "generally required" to maintain a processing register. In it, you record which data you process, for what purpose, and how long you retain it.
2. A privacy statement (GDPR Art. 13/14) The AP requires you to inform customers how their personal data is used. A privacy statement on your website or in your quotes is the standard way to do this.
Example: if you're an IT consultant logging project hours and client contact details, you're processing personal data, and both obligations apply to you.
The AP has made both documents available as separate templates, specifically aimed at SMEs. Find them at autoriteitpersoonsgegevens.nl.
How to Use the AP's GDPR Templates
The templates are designed to be completed without legal expertise. Follow the steps in order:
| Step | Action | Tool |
|---|---|---|
| 1 | Map out which personal data you process | Internal review + your own records |
| 2 | Complete the processing register per data category | AP processing register template |
| 3 | Draft your privacy statement based on your register | AP privacy statement template |
| 4 | Publish the statement on your website or in quotes | Your website or quoting tool |
| 5 | Repeat steps 2-4 for every new processing activity | Quarterly review |
Always start with step 1: know what you process before filling in any documents. A processing register that doesn't reflect your actual workflows (such as your time tracking or CRM system) offers little protection during an audit.
Do you work with employees or flexible staff? Check whether your time tracking software is GDPR-compliant. Read more about GDPR and automated time tracking decisions and what real cases can teach you.
Get your GDPR admin in order today with the free templates from PrikKlokPlus.
Time Tracking and Personal Data: Where They Overlap
Many business owners don't realise their time tracking falls under the GDPR. When you record who worked how many hours on which project, you're capturing personal data that can be traced back to individual employees or freelancers.
In practice, this means:
- You need a valid legal ground, usually performance of an employment contract or a legitimate interest.
- Don't keep data longer than necessary. Fiscal rules generally require seven years, but check whether you're holding project archives beyond that without purpose.
- If your system logs GPS data or login locations, stricter rules apply.
For a detailed overview, see our knowledge base article on GDPR & time tracking: legal basis, location data and retention.
Freelancers invoicing on logged hours also store client data in their billing system, and this belongs in your processing register too. Read how to set up time tracking correctly as a freelancer.
Upcoming: DPIA Exemption for SMEs
A Data Protection Impact Assessment (DPIA) is a privacy risk analysis required in certain situations (GDPR Art. 35). For many SMEs, this is a significant burden in time and expertise.
The AP is developing a list of processing activities for which SMEs will not need to carry out a DPIA. A public consultation on this list ran until 10 August 2026. Once finalised, standard SME activities (such as a customer database or personnel administration) may be exempt.
Keep an eye on the AP website for the final publication. Getting your processing register in order now means you'll immediately know which activities you have and whether they qualify for exemption.
Want better control over customer data in your CRM? Read how to secure CRM data and reduce supply chain risks.
Conclusion
The AP's GDPR templates are a practical starting point for every SME and freelancer. With a processing register and privacy statement, you meet the two key documentation requirements under the GDPR. Combine that with a clear policy on time tracking and customer data, and you're well prepared, even if the regulator comes knocking.
Still unsure? Always consult a legal adviser for your specific situation.
Frequently Asked Questions
Does every freelancer need a processing register? The AP states that businesses processing customer data are "generally required" to maintain one. As a freelancer, you almost always handle client or contact data, so the obligation almost certainly applies to you.
Where can I find the official GDPR templates for SMEs? The templates are freely available at autoriteitpersoonsgegevens.nl. You'll find both a processing register template and a privacy statement template.
Does my time tracking software fall under the GDPR? Yes. As soon as your software records personal data (such as names, hours worked, or project links) the GDPR applies. You need a valid legal basis and must monitor retention periods.
What is a DPIA and do I need one as an SME? A DPIA is a privacy risk analysis for high-risk processing activities. The AP is working on an exemption list for standard SME processing. Until it's published, check the AP website to see whether your specific activity requires one.
Ready to make your admin GDPR-compliant? PrikKlokPlus gives you structured time tracking, CRM, and invoicing, so you always know where personal data sits.