You hold more than you think
Almost every small business underestimates what data it holds, and the exercise of finding out is worth an afternoon because it changes several decisions at once.
Where it accumulates. The obvious systems: accounting, customer records, the website. Then email, which is usually the largest single store, containing years of correspondence with attachments nobody has looked at. Then personal devices, where files were saved to finish something at home. Then old systems still running because nobody switched them off. Cloud storage from a project three years ago. Spreadsheets exported once and never deleted. And backups of all of the above.
What is typically in there. Customer names and contact details. Payment information, sometimes including full card details that should never have been stored. Employee records including bank details, identity documents and health information. Applicant CVs from a hiring round in 2019. Supplier contracts. And correspondence containing far more about people's circumstances than anyone realises.
Why this matters practically rather than as an abstraction.
It determines your obligations. Data protection law applies according to what you process, and you cannot assess obligations you have not enumerated.
It determines your exposure. In an incident, the first question is what was taken, and a business that cannot answer spends days finding out while the notification clock runs.
And it identifies what to delete, which is the cheapest security control available. Data you no longer hold cannot be breached, cannot be published, and does not appear in a notification. Most small businesses could delete a substantial proportion of what they hold with no operational consequence whatsoever.

