Skip to main content
Compliance & Privacy8 min read

GDPR, NIS2, and Local Privacy Laws: What Small Businesses in Israel and across Europe Must Do

"A plain-English guide to data compliance for small businesses operating in Israel and across Europe - what each country requires, what the real penalties are, and the minimum viable setup to stay clean."

Author

Lior Refael

Published

Jan 20, 2026

Back to Articles

Why compliance feels harder than it should be

This is a technical implementation guide, not legal counsel. We configure the systems that support compliance - retention, access control, audit logs, data residency. We do not give legal advice, and nothing below should be treated as it. For a formal position on your obligations, use a qualified data protection lawyer or DPO in your jurisdiction.

Most small business owners in Israel and across Europe know they need to be "GDPR compliant" - but the actual requirements are buried in legal language, and most consultants either oversimplify or overwhelm. This article cuts through both.

The short version: if you hold personal data about clients, employees, or contacts anywhere in the EU, GDPR applies. If you're in Israel, the Privacy Protection Law applies. If your business connects to EU customers from Israel, GDPR also applies - Article 3 makes the regulation extraterritorial, so being registered outside the EU is not an exemption[1]. None of these require expensive certification - they require documented processes and sensible IT hygiene.

What each country actually requires

What each country actually requires

Greece

Primary law
GDPR (via Hellenic DPA)
Key requirement for SMBs
Privacy policy, data breach notification within 72hrs, lawful basis for processing
Penalties
Up to €20M or 4% of global turnover

Israel

Primary law
Privacy Protection Law, as amended by Amendment 13 (in force since August 2025)
Key requirement for SMBs
Security-level classification of databases, deletion on request, a DPO where the thresholds are met, documented risk assessments
Penalties
Administrative sanctions from the Privacy Protection Authority that scale with database size and data sensitivity, reaching millions of shekels, plus criminal liability in severe cases

Spain

Primary law
GDPR + LOPD-GDD
Key requirement for SMBs
Cookie consent, stricter privacy notices, DPO required if processing data at scale
Penalties
Up to €20M or 4% of turnover; AEPD actively enforces

Source: EUR-Lex, Publications Office of the EU, Regulation (EU) 2016/679 (GDPR), Article 3 - Territorial scope (2016)

For most 5-50 person businesses, GDPR compliance comes down to six concrete things:

  1. Know what personal data you hold and where it lives
  2. Have a privacy policy on your website
  3. Get proper consent before adding people to mailing lists
  4. Have a process to respond to "delete my data" requests within 30 days
  5. Know what to do if you have a data breach (you have 72 hours to notify your DPA)
  6. Have a data processing agreement with any vendor that handles your client data (Microsoft, Google, Acronis all provide these)

Enforcement is the part small business owners tend to discount, on the assumption that regulators only pursue large technology companies. The annual totals say otherwise: fines have settled into a steady rhythm rather than tailing off.

GDPR fines issued across Europe, by year

Total fines issued (EUR billions)

The 2023 peak was inflated by a single EUR 1.2 billion case. What matters for a small business is the flat line after it: enforcement settled at a steady annual rate rather than fading away.

Show the data
Column chart of total GDPR fines issued across Europe: EUR 1.78 billion in 2023, EUR 1.2 billion in 2024, and EUR 1.2 billion in 2025 - showing enforcement holding steady rather than declining.
Total fines issued (EUR billions)Fines issued
2023EUR 1.78B
2024EUR 1.2B
2025EUR 1.2B

Source: DLA Piper, GDPR Fines and Data Breach Survey: January 2026 (Jan 2026)

NIS2 is the other law worth checking rather than assuming. It generally applies to organisations with 50 or more staff or over €10M turnover operating in one of its listed sectors, and it splits them into essential and important entities with different supervision and different penalty ceilings[2]. The term that trips people up is "significant incident". It is not a matter of interpretation - NIS2 Article 23 defines it, and an incident is significant when it has caused or is capable of causing severe operational disruption or financial loss to the entity, or has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage. The same article sets the reporting clock: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, and a final report within one month[2]. ENISA publishes plain-language implementation material for smaller in-scope organisations[3], and for baseline GDPR work the Commission-funded gdpr.eu checklist is the most usable starting point we have found for a small team[4]. In Israel, the Privacy Protection Authority publishes its own binding directives and guidance following Amendment 13[5].

Below those thresholds you are usually caught a different way - as a supplier to somebody who is in scope, because supply-chain security is an explicit obligation they have to pass down to you.

The technical setup that covers most of the requirements

The good news: if your IT stack is already properly configured, you're likely compliant on the technical side without additional effort. "Properly configured" means:

  • Microsoft 365 or Google Workspace with data residency set to EU (for businesses in the EU) - this covers GDPR's data location requirements[6]
  • Encryption at rest and in transit - both platforms do this by default when configured correctly
  • Access controls - only the right people can see sensitive data. Intune's Conditional Access and 1Password's vault separation make this manageable
  • Backup retention policies - Acronis lets you set retention periods that align with GDPR's data minimisation principle
  • Audit logging - Microsoft 365's audit log records who accessed what data and when

What most small businesses are missing isn't the tooling - it's the documentation. A regulator doesn't care that you use good software; they want to see that you know what data you hold, why you hold it, and what you'd do if something went wrong.

The 2026 checklist for small businesses

For EU-based businesses (GDPR):

  1. Privacy policy published on your website - reviewed in the last 12 months
  2. Cookie consent implemented correctly (a "close" button without accepting is not valid consent)
  3. Data processing agreements in place with all vendors handling your client data
  4. Breach response procedure documented - who you call, what you file, when
  5. Data residency confirmed for your Microsoft 365 or Google Workspace tenant

For Israel (Privacy Protection Law):

  1. Understand which of your databases require DPA registration (most small business databases do not)
  2. Classified your databases by security level (Basic, Medium, or High)
  3. Have a process for data access and deletion requests
  4. If you serve EU clients, apply GDPR requirements to that data too

Questions we get asked

Sources

Every figure in this article traces back to a named source. Where we quote our own numbers, they come from work we have done with small businesses in Israel and across Europe, and we say so.

  1. Regulation (EU) 2016/679 (GDPR), Article 3 - Territorial scopeEUR-Lex, Publications Office of the EU · 2016GDPR applies to controllers outside the EU that offer goods or services to, or monitor, people in the EU. (opens in a new tab)
  2. Directive (EU) 2022/2555 (NIS2)EUR-Lex, Publications Office of the EU · 2022Size thresholds, essential vs important entity classification, supply-chain obligations and penalty ceilings. (opens in a new tab)
  3. NIS2 Directive: implementation guidance and factsheetsENISA (EU Agency for Cybersecurity) · 2025EU agency guidance on NIS2 scope, entity classification and reporting obligations. (opens in a new tab)
  4. GDPR compliance checklist for small businessgdpr.eu (Proton / EU Horizon 2020 project) · 2025 · reporting on primary dataPractical, plain-language GDPR checklist aimed at small organisations. (opens in a new tab)
  5. Privacy Protection Authority - directives and guidanceIsrael Privacy Protection Authority · 2025Israeli regulator directives on database security levels and obligations after Amendment 13. (opens in a new tab)
  6. EU Data Boundary for the Microsoft CloudMicrosoft Learn · 2026Where Microsoft 365 customer data is stored and processed for EU tenants. (opens in a new tab)
  7. GDPR Fines and Data Breach Survey: January 2026DLA Piper · Jan 2026Annual GDPR fine totals by year and the cumulative total since May 2018. (opens in a new tab)
  8. Israel marks a new era in privacy law: Amendment 13 ushers in sweeping reformIAPP · 2025 · reporting on primary dataScope, DPO duties and enforcement powers introduced by Amendment 13 to Israel's Privacy Protection Law. (opens in a new tab)
  9. Audit solutions in Microsoft PurviewMicrosoft Learn · 2026Audit logging of who accessed which data and when, used as evidence in a privacy investigation. (opens in a new tab)

Figures last checked 28 July 2026

Not sure if your business is compliant?

Book a free 30-minute call. We'll walk through your current data setup and tell you honestly what's missing - and what doesn't need to change.