11/06/2026
There are a few phrases we hear regularly when talking to organisations about data protection and compliance.
One of the most common is "We're too small for GDPR."
The reality is that data protection isn't based on the size of your organisation. If you're handling personal data, you have responsibilities around how it's collected, used, stored, and protected.
Some of the other things we hear include:
🔸 "We don't hold much personal data."
🔸 "We've never had a data breach."
🔸 "Our IT provider takes care of all that."
🔸 "We're not a target."
Most of the time, these aren't signs that people don't care about compliance. They're simply assumptions that have never been challenged.
The trouble is, assumptions can leave gaps that nobody realises are there until something goes wrong.
What's the most common misconception you come across in your industry?