Datenmaske
← Blog
DSGVO PRACTICE · Datenmaske Editorial Team

5 DSGVO mistakes that cost small businesses dearly

Small and medium-sized enterprises (SMEs) face particular challenges in implementing the DSGVO. Often there is no dedicated data protection officer, and the processing of personal data happens on the side. But supervisory authorities make no exceptions for SMEs — the fine catalogues apply to everyone. This article shows the five most common DSGVO mistakes in small businesses and how to avoid them.

Mistake 1: Insecure redaction — black bar instead of true removal

The most widespread mistake: employees place black rectangles over sensitive data in PDF documents and consider that redaction. In reality, the text remains in the PDF and can be made visible again with simple means — such as copying via Ctrl+C or opening it in a text editor.

The risk: If third-party personal data is "redacted" in this way and remains legible, this constitutes a breach of Art. 5 Abs. 1 lit. f DSGVO (integrity and confidentiality). The data was not adequately protected.

Fine potential: Up to EUR 10 million or 2 % of worldwide annual turnover (Art. 83 Abs. 4 DSGVO). In practice, supervisory authorities impose fines in the four- to five-figure range on SMEs, depending on the severity and duration of the breach.

The solution: Use tools that irreversibly remove text from the PDF. Datenmaske, for example, physically removes text from the PDF content stream and simultaneously sanitises metadata, comments and bookmarks. This makes the redaction not only visually but also technically irreversible.

Mistake 2: No data minimisation when sharing documents

Many SMEs share documents unfiltered — whether with tax advisors, lawyers, customers or authorities. Bank statements with all postings, contracts with the complete contact details of all parties involved, personnel files with sensitive health data. However, the DSGVO requires data minimisation (Art. 5 Abs. 1 lit. c): only data that is necessary for the respective purpose may be processed.

The risk: Anyone who shares a bank statement with all postings with the landlord, although only the balance is relevant, violates the data minimisation principle. Anyone who passes on customer files with data of other customers to third parties breaches purpose limitation.

Fine potential: Up to EUR 10 million or 2 % of worldwide annual turnover. Supervisory authorities specifically check whether data minimisation was observed in the event of complaints.

The solution: Before sharing any document, check: which data is necessary for this specific purpose? Redact all personal data beyond that. Datenmaske automatically detects which data is contained in a document and suggests targeted redactions.

Mistake 3: Missing logging of redaction

If you redact documents but do not document what was redacted, when, by whom and why, traceability is lost. In an audit by the supervisory authority or in the event of a complaint, you cannot prove that you complied with the DSGVO requirements.

The risk: Missing documentation breaches the accountability principle (Art. 5 Abs. 2 DSGVO). The authority cannot verify whether the redaction was carried out correctly and completely. In the worst case, the breach is classified as intentional.

Fine potential: Fines for missing documentation are typically in the five-figure range. In combination with other breaches, they can increase significantly.

The solution: Maintain a redaction log (audit log) for each process. Document: which document, which data was redacted, when, by whom and for what reason. Datenmaske automatically creates a cryptographically secured audit log for every redaction operation.

Mistake 4: Manual processes without quality control

In many SMEs, employees redact documents manually — they search for personal data themselves, draw black rectangles and export the document. This process is highly error-prone: data is overlooked, especially in long documents or with confusing formatting. A second review usually does not take place.

The risk: A sample of publicly indexed PDFs (Essex Software, n=72) found that in roughly every sixth document (approx. 17 %) text remained selectable under the manual redaction. In an audit by the supervisory authority, such errors are highly likely to be discovered.

Fine potential: Depending on the type and quantity of overlooked data. In the case of systematic deficiencies, fines in the six-figure range are possible.

The solution: Automate the detection of personal data. Datenmaske uses a combination of rule-based patterns (regex for IBANs, email addresses, telephone numbers) and Named Entity Recognition (NER for names, places, organisations). Automatic detection finds data that is easily overlooked manually — and includes a human review of the results.

Mistake 5: Sharing documents without review

Perhaps the most banal but also most dangerous mistake: documents are shared without any review for personal data. This happens particularly often with email forwarding, cloud sharing or the handover of paper documents.

The risk: Any sharing of documents containing third-party personal data without a legal basis is a data protection breach. This also applies to internal sharing within the company when there is no need-to-know.

Fine potential: Up to EUR 20 million or 4 % of worldwide annual turnover for particularly serious breaches (Art. 83 Abs. 5 DSGVO). Even for SMEs, five- or six-figure fines can quickly be imposed.

The solution: Establish a release process: before documents go out, they are checked for personal data and redacted if necessary. With a tool like Datenmaske, this process can be carried out in minutes rather than hours.

Comparison of the 5 mistakes

| Mistake | Risk | Fine up to | Solution |
|--------|--------|---------------|--------|
| Insecure redaction | Text remains legible | EUR 10 million / 2 % turnover | Irreversible text removal |
| No data minimisation | Too much data shared | EUR 10 million / 2 % turnover | Targeted redaction of unneeded data |
| Missing logging | No traceability | 5-figure range | Automatic audit log |
| Manual processes | Data is overlooked | 6-figure range | Automatic detection + human review |
| Unreviewed sharing | Uncontrolled data dissemination | EUR 20 million / 4 % turnover | Release process with automatic review |

Conclusion

The five mistakes described have one thing in common: they are avoidable. With the right tools and processes, small businesses can ensure DSGVO compliance in document processing efficiently and cost-effectively. Datenmaske was developed to prevent precisely these mistakes: automatic detection, irreversible redaction, complete logging — NER self-hosted on EU servers, no sending to US AI services.

FAQ

What DSGVO fines threaten small businesses?

The DSGVO distinguishes between less serious and serious breaches. Less serious breaches (e.g. missing documentation) can be punished with up to EUR 10 million or 2 % of worldwide annual turnover. Serious breaches (e.g. unauthorised data sharing) with up to EUR 20 million or 4 % of turnover. For SMEs, fines imposed in practice are usually in the four- to six-figure range.

Is it sufficient to place a black bar over text in a PDF?

No. A black bar only visually masks the text. The original text remains in the PDF and can be made visible again by copying, opening in a text editor or removing the graphics layer. Such 'redacted' PDFs are not secure. The DSGVO requires an effective protective measure that irreversibly removes the text.

Do small businesses have to appoint a data protection officer?

A data protection officer is mandatory if at least 20 persons are constantly engaged in automated data processing (§ 38 BDSG). Below that threshold, appointment is at the company's discretion. However, SMEs are affected by the DSGVO obligation to process data in a privacy-compliant manner regardless of their size.

What is data minimisation under the DSGVO?

Data minimisation (Art. 5 Abs. 1 lit. c DSGVO) means that personal data must be adequate and relevant for the purpose and limited to what is necessary for processing. In practice: share only the data that is really needed for the respective purpose, and redact everything else.

How can small businesses implement DSGVO compliance cost-effectively?

Automation is the key. Instead of manually reviewing and redacting documents, use tools like Datenmaske that automatically detect personal data and redact it irreversibly. This saves staff time, reduces errors and automatically creates audit logs for traceability.

Weiterlesen