In the GDPR draft it was "250 employees or with 5000 records." but 5000 records was dropped.
Now it says:
http://data.consilium.europa.eu/doc/document/ST-5419-2016-IN...
>The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an
organisation employing fewer than 250 persons unless the processing it carries out is likely
to result in a risk to the rights and freedoms of data subjects, the processing is not
occasional, or the processing includes special categories of data as referred to in
Article 9(1) or personal data relating to criminal convictions and offences referred to in
Article 10.
Basically small firm that is just holding minimum amount of customer/user information and data and where the business model is not centered around profiling and processing user data.