library · field guide

Stay GDPR-safe without becoming a lawyer.

The moment you hold a customer's email address, data-protection law applies to you — garden centre, wholesale grower or one-person nursery alike. The good news: compliance is a handful of sensible habits, and most of them are decisions about your software rather than your statute book.

where it starts

The law starts the moment you hold an email.

GDPR is not reserved for banks and tech giants. A name on an invoice, a phone number for a delivery, a mailing list for the spring catalogue — each is personal data, and holding it makes you responsible for it.

the plain-English version

You do not need a lawyer.

Data-protection law reads like a wall of clauses, and that is exactly why so many small growers quietly hope it does not apply to them. It does. But strip away the jargon and the day-to-day obligation comes down to three plain questions you should always be able to answer:

  • Where is the personal data you hold? You cannot protect, export or delete what you cannot find.
  • Who can see it? Not everyone in the business needs every customer's details — and the law expects you to keep access to what a job actually requires.
  • Can you act on it? When a customer asks what you hold, or asks you to delete it, you need to be able to do so — and to show you did.

None of those is a legal question. Each is a question about how your records are kept. Which means the honest route to compliance runs through your software. A system built to keep clean, structured records makes the law a matter of routine; a drawer of spreadsheets and a shared inbox makes it a matter of luck.

Know where the personal data is.

question one · location

Know where the personal data is.

The first failure of most small businesses is rarely a breach; it is not knowing what they hold or where. Personal data leaks into a dozen places: a spreadsheet of customers, a WhatsApp thread with a courier, a notebook by the till, an old mailing list nobody has opened in a year.

The property to look for in any system is simple: every person you deal with (customers, suppliers, couriers and your own staff) held as a single structured record rather than scattered across spreadsheets, chats and notebooks. When a person's data lives in one record instead of five files, "where is it?" stops being a research project. That consolidation is the foundation of every other obligation: you cannot honour a request about data you have lost track of.

Not everyone needs to see everything.

question two · access

Not everyone needs to see everything.

Data minimisation is one of GDPR's plainest ideas: people should be able to reach the data their job needs, and no more. A seasonal worker ringing up sales does not need your full customer contact book; the propagation team does not need everyone's bank details.

Good systems enforce that with roles and permissions. Each role is a named bundle of rights (finance, logistics, production and the like) and each person is granted only the roles their work requires. When access is defined that way, limiting who sees personal data is a deliberate setting, not an accident of who happens to know a shared password.

question three · control

Your data is not pooled with anyone else's.

You cannot promise to delete a customer's data if it is smeared across a shared table you do not control. Ownership is what makes the rest enforceable.

Much cloud software pools every customer it has into one shared database, your records sitting in the same tables as a hundred other businesses'. It usually works — until the day you need to prove that your data is separated, exportable and genuinely deletable.

The criterion worth insisting on is the opposite arrangement: single-tenant isolation, your own database rather than one mixed with other businesses'. That isolation is what turns your GDPR promises into ones you can actually keep. When your records sit in a database of their own, a customer's data really is yours to control: to export in a format that opens anywhere, to hand over, or to erase, with no shared table, no other tenant and no vendor standing between you and your own records.

Records that keep their own history.

accountability

Records that keep their own history.

GDPR asks you to be accountable, to demonstrate rather than merely assert that you handle data properly. That is far easier when your records keep their own history instead of quietly overwriting it.

Trustworthy record systems never silently rewrite the past. Stock is the sum of every logged movement rather than a number you edit, and when something has to be undone a good system writes a reversal rather than deleting the original. Records that keep their own history that way leave the trail whole, so "who changed this, and when?" has an answer.

Keep what you must, purge what you may.

retention

Keep what you must, purge what you may.

The other half of data protection is not keeping data forever. You should hold personal data only as long as you have a reason to: a live relationship, an open order, a legal record-keeping period. After that, let it go.

When you control the database your data sits in rather than renting a slice of someone else's, retention is genuinely your decision. You choose what is kept and for how long, and with backups behind you so a purge is never an accident you cannot recover from, deletion can mean deletion.

atlas core

How Atlas Core handles GDPR for your nursery

The habits above are software-agnostic — here is how Atlas Core builds them in:

  • Single structured record per person — customers, suppliers, agents, couriers and staff each held once, so "where is this customer's data?" is a lookup rather than a hunt across spreadsheets and inboxes.
  • Role-based access, least privilege by default — named roles (finance, logistics, production and the like) grant each person only the rights their job needs.
  • Single-tenant by design — your own isolated database, never pooled with other businesses, so export, hand-over and genuine deletion are promises you can keep.
  • Honest, append-only history — stock is the sum of logged movements and corrections are written as reversals, so demonstrating how a record was handled is a search rather than a scramble.
  • Retention stays your decision — backed by recoverable backups, hold personal data only as long as you need it, then purge it deliberately.

Read further

Bolt-on translation always breaks Field guide · 2026

Bolt-on translation always breaks

Plants cross borders long before software does. Systems born speaking one language crack at the seams - the label printed in the wrong tongue. Why bolt-on translation always shows, and building multilingual from day one is the fix.

7 min read · Jul 2026 Read →

See how Atlas Core keeps your data yours.

Data protection becomes routine when the record-keeping underneath it is sound. Talk to us about how Atlas Core fits your nursery.