Yes. GDPR protects personal data regardless of business model — employee records, contact persons at customer companies, CVs, CCTV footage and marketing lists are all personal data. B2B companies need lawful bases, processing records and Article 32 security measures just like consumer businesses.
What B2B companies typically owe
- Records of processing (Article 30) and a defensible privacy policy
- Data-processing agreements with every vendor touching personal data
- Technical measures: access control, MFA, encryption, backups, logging
- 72-hour breach notification capability to the supervisory authority
See our engineering-led GDPR compliance services — including DPO-as-a-service and 24/7 breach detection.