Small does not mean exempt
The assumption that consumer protection and data rules are for large companies is common among small business owners and it is wrong in most of the ways that matter.
Advertising law applies from your first customer. Consumer protection law applies regardless of turnover. Data protection law applies to a sole trader with a customer list. Contract terms are enforceable against a one-person business exactly as against a corporation.
What does scale with size is enforcement attention and, in a few specific places, the obligation itself. Some regimes have genuine small-entity accommodations, and the EU AI Act's Digital Omnibus amendments added simplified technical documentation for small mid-caps and extended simplified quality management arrangements to SMEs. Those are real, and they are narrow.
The general position is that the rules apply and the resources to comply do not exist, which is a genuine difficulty rather than a reason to ignore them.
The practical response is proportionality rather than exemption. A one-person business is not expected to have a compliance function. It is expected to be honest about what it sells, careful with customer data, and clear when a customer is dealing with a machine.
Those three obligations cover the great majority of the exposure, they are achievable without advice, and the rest of this lesson takes them in turn.
And one framing worth holding. Each of these is also just how you would want to be treated as a customer, which is a more reliable guide than trying to remember a rule.

