GDPR and cloud tools: what SMBs need to know
Practical GDPR compliance guide for SMBs using cloud tools: Google Workspace, AWS and Shopify. Obligations, best practices and pitfalls to avoid.
Updated on 3 October 2023
GDPR applies in the cloud too
The General Data Protection Regulation applies to any company that processes the personal data of European residents, whatever the tool used. Using Google Workspace, AWS or Shopify does not exempt you from your obligations. These providers act as processors of your data, but you remain responsible for the processing. This guide clarifies your obligations and the best practices to put in place.
Your role and your cloud provider’s role
The GDPR distinguishes between the data controller (you) and the processor (your cloud provider). You decide which data to collect, why and how to process it. Your cloud provider processes the data according to your instructions and commits contractually to protection measures.
Each cloud provider offers a data processing addendum (DPA) that formalizes these commitments. Google Workspace, AWS and Shopify all have a GDPR-compliant DPA. Verify that you have accepted the DPA of each provider you use.
Concrete obligations for SMBs
Processing register
Document each processing activity involving personal data: which data, for what purpose, on what legal basis, for what retention period and with which processors. This register is mandatory for all companies, whatever their size.
Informing individuals
Inform the individuals whose data you process: customers, prospects, employees. Your privacy policy must be clear, accessible and complete. It must mention the cloud processors you use and any data transfers outside the EU.
Individual rights
Set up procedures to respond to requests to exercise rights: access, rectification, deletion, portability. You have one month to respond. Google Workspace and Shopify provide tools to export and delete a user’s data.
Data security
Set up security measures suited to the risks: encryption, access control, backups, monitoring. Cloud providers secure the infrastructure, but the configuration and usage are your responsibility.
Best practices by tool
Google Workspace
Enable 2FA for all users, configure data regions to store data in Europe, limit external file sharing and set up a data retention policy with Google Vault.
AWS
Encrypt data at rest and in transit, use IAM with the principle of least privilege, enable CloudTrail for auditing and configure AWS Config to monitor your infrastructure’s compliance.
Shopify
Configure your privacy policy and your cookie consent banner, limit data collection to what is strictly necessary, and set up procedures to delete customer data on request.
LCMH supports SMBs in GDPR compliance for their cloud tools.
To go further on Google Workspace security, read our article on data protection in Google Workspace.
Sources
- CNIL, GDPR: Where to Start. cnil.fr/fr/rgpd-par-ou-commencer
- CNIL, Using Data Processors. cnil.fr/fr/sous-traitance
- Google, GDPR and Google Workspace. cloud.google.com/privacy/gdpr
Frequently asked questions
- Are US cloud tools GDPR-compliant?
- The main cloud providers (AWS, Google, Microsoft) have adapted their services to the GDPR with data processing addendums (DPA), standard contractual clauses and storage options in Europe. Compliance also depends on your configuration and your internal practices.
- Do you need a DPO to use cloud tools?
- Appointing a DPO (Data Protection Officer) is mandatory for public bodies and for companies whose core activity involves large-scale, regular and systematic monitoring of individuals. For most SMBs, an internal GDPR contact is enough.
- What should you do in case of a data breach in the cloud?
- You must notify the CNIL, the French data protection authority, within 72 hours of discovering the breach if it presents a risk to individuals' rights. If the risk is high, you must also inform the individuals concerned. Document the incident, the measures taken and the consequences.
Related Articles
Securing your S3 buckets: essential best practices
Security best practices guide for Amazon S3: encryption, access control, versioning and monitoring to protect your data.
AWS for startups: where to start
Practical guide for startups getting started on AWS: account setup, budget, essential services and pitfalls to avoid.
2026 RAM Shortage: Why Your Servers Will Cost More (and Why Migrate to Cloud)
RAM prices have doubled in 2026 due to AI. Analysis of the historic shortage and why cloud becomes the only viable option for SMBs.
Cybersecurity for SMBs: 10 essential measures
The 10 cybersecurity measures every SMB should implement to protect against the most common threats.
Do Data Centers Really Consume Too Much Water? The Burger Comparison
The debate on data center water consumption lacks perspective. Quantified comparison between Colossus 2 and the food industry.
AWS Lambda: 10 concrete use cases to automate your business
Discover 10 practical AWS Lambda use cases to automate your business processes without managing servers.