On January 27, 2017, ENISA issued guidelines for small and medium-sized enterprises ("SMEs") on the security of personal data processing. ENISA undertook a study to support SMEs on how to adopt security measures for the protection of personal data following a risk-based approach. In particular, the objectives of the study were to facilitate SMEs' understanding of personal data processing operations and assessing associated security risks.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.