The RoadmapSetupLegal Requirements and Licenses

A Small Business Guide to GDPR Compliance

Everything UK small business owners need to know to comply with GDPR—from the basics to practical steps, risks, and real-world examples.

6 minute read
Setup — Legal Requirements and Licenses
✓ Verified against GOV.UK
Claire Henderson
Written by Claire Henderson
Finance & Tax Editor · GuideToBusiness
Back to Setup

Getting GDPR compliance right isn’t just a legal box-tick—it’s essential for building customer trust, avoiding steep fines, and running a credible business. Yet, many UK small business owners are left confused by jargon and myths about what GDPR really means in practice. This guide cuts through the noise and gives you clear, actionable advice on what GDPR compliance requires, mistakes to avoid, and how to make data protection work for your business. Read on to ensure you’re protected, your customers are confident, and you never get caught out by the Information Commissioner’s Office (ICO).

What is GDPR and Why Does It Matter for UK Small Businesses?

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect across the EU in May 2018. After Brexit, the UK adopted its own version, known as the UK GDPR, alongside the Data Protection Act 2018. For UK small businesses, GDPR isn’t optional—it’s a legal requirement that governs how you collect, store, use, and share personal data. Personal data means any information that can identify a living person, from names and emails to IP addresses and even CCTV footage.

Complying with GDPR is about more than avoiding fines (which can be up to £17.5 million or 4% of your annual global turnover, whichever is higher). It’s about building trust with customers, partners, and suppliers, showing you take their privacy seriously. Even if you’re a sole trader with a small client list, GDPR likely applies to you if you handle any personal data for business purposes.

The Information Commissioner’s Office (ICO) is the UK’s data protection regulator. They provide guidance, investigate complaints, and issue penalties for breaches. The ICO expects every business—regardless of size—to be able to demonstrate their compliance. This means you must not only follow the rules but also keep records to prove you’re doing so.

Stat: GDPR fines in the UK

The ICO issued over £42 million in GDPR-related fines in 2022 alone, with small businesses among those penalised for avoidable breaches.

  • GDPR applies to all UK businesses processing personal data—not just large corporations.
  • You must comply even if you only store basic contact details of customers or suppliers.
  • The ICO can investigate your business if a customer complains about how you handle their data.
  • Good data protection practices can set your business apart from competitors.

What Counts as Personal Data and Processing Under GDPR?

A common mistake is underestimating what GDPR covers. Personal data is any information relating to an identified or identifiable person. This means more than just names and addresses. If you keep client email addresses, staff payroll records, customer telephone numbers, or even use cookies on your website, you’re handling personal data. Special category data—such as health information, racial or ethnic origin, or religious beliefs—requires even stricter controls.

Processing is any operation performed on personal data. This includes collecting, recording, organising, storing, altering, retrieving, consulting, using, sharing, or deleting data. If you email a customer, upload their details to a cloud service, or analyse their behaviour on your website, you’re processing data under the law.

It’s easy to assume that if you outsource to a third party (like a payroll provider or email marketing platform), you’re not responsible. Wrong. GDPR makes you responsible for ensuring all third-party suppliers (data processors) are compliant. The ICO’s view is clear: you can’t outsource liability.

Info: Examples of Personal Data

Personal data includes: names, addresses, phone numbers, email addresses, IP addresses, CCTV images, bank details, employee records, and more.

  • Website analytics data linked to individuals counts as personal data.
  • Photographs of staff or clients are covered by GDPR.
  • Payroll and HR records are subject to strict data processing rules.
  • Contact lists—even if only used for business-to-business (B2B) marketing—fall under GDPR.

Key Principles of GDPR Every Small Business Must Follow

GDPR is built on seven core principles. These aren’t optional—every business must be able to show how they meet each one. Understanding these principles is fundamental to building a compliant business and avoiding the classic ‘I didn’t know’ defence, which won’t protect you from the ICO.

The first principle is lawfulness, fairness, and transparency. You must have a valid legal reason (known as a lawful basis) for collecting and using personal data, and you must be open with people about what you’re doing. The other principles cover purpose limitation (only using data for the reason collected), data minimisation (collecting only what’s necessary), accuracy (keeping data up to date), storage limitation (not keeping data longer than needed), integrity and confidentiality (keeping data secure), and accountability (being able to prove you comply).

For small businesses, the accountability principle is often the hardest. You need to document your GDPR decisions and actions, such as your privacy policy, records of processing activities, and staff training. This creates an evidence trail if you’re ever challenged by the ICO or a customer.

GDPR PrincipleWhat It Means for Small Businesses
Lawfulness, Fairness, TransparencyHave a clear legal basis; be open about data use; provide privacy notices.
Purpose LimitationOnly collect data for specific, explicit purposes.
Data MinimisationOnly ask for and store the data you actually need.
AccuracyKeep data up to date; correct errors promptly.
Storage LimitationDelete or anonymise data when you no longer need it.
Integrity and ConfidentialityKeep data secure; protect against unauthorised access or loss.
AccountabilityDocument what you do and be able to demonstrate compliance.
  • Map out all the personal data you collect and why.
  • Review your privacy policy annually and update it as needed.
  • Limit access to personal data to only those who genuinely need it.
  • Always document your data protection decisions.

Lawful Bases for Processing: What You Need to Know

Under GDPR, you can’t just collect or use personal data because it’s handy. You must identify and document a lawful basis for each type of processing. The six lawful bases are: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Most small businesses will rely on contract (e.g., to provide a service), legal obligation (e.g., payroll records), or legitimate interests (e.g., certain marketing activities).

Consent must be freely given, specific, informed, and unambiguous—no pre-ticked boxes, vague wording, or silence as consent. For marketing, consent is often required, especially for email marketing to individuals (under the Privacy and Electronic Communications Regulations—PECR). If you rely on legitimate interests, you must balance your business needs against people’s privacy rights and be ready to justify your reasoning.

A common pitfall is assuming that a general business relationship covers all data use. For example, just because someone buys from you doesn’t mean you can automatically send them marketing emails. You need to check the lawful basis for every type of processing and document your decision-making process.

Warning: Don’t Assume Consent Covers Everything

Misusing consent or failing to get clear, proper consent is one of the most common GDPR breaches investigated by the ICO. Always keep records of how and when consent was given.

  • Document the lawful basis for each data processing activity.
  • Review your marketing practices—consent or legitimate interests may apply.
  • Don’t use consent if another lawful basis is more appropriate.
  • Withdraw consent if asked and act promptly.

Privacy Notices and Transparency: What You Must Tell People

GDPR requires you to tell people—clearly and in plain language—what you do with their data. This is usually done through a privacy notice (also called a privacy policy). Your privacy notice must be easily accessible (such as on your website), regularly updated, and cover specific details required by law. The ICO provides a checklist of what to include.

Your privacy notice must specify: who you are; what data you collect; why you collect it; your lawful basis; how long you keep it; who you share it with; how people can exercise their rights; and how to contact you or complain. If you use cookies, analytics, or third-party services, you must explain this clearly—no hiding behind legalese.

A major mistake is copying and pasting a template without personalising it to your business. The ICO regularly investigates businesses with inadequate privacy notices. Don’t treat this as a tick-box exercise—your privacy notice is a public-facing sign of your professionalism and trustworthiness.

Tip: Update Your Privacy Notice Regularly

Review your privacy notice at least once a year or whenever you change how you handle data. Mark the date of the last update so customers know it’s current.

  • Make your privacy notice clear, concise, and jargon-free.
  • Include contact details for your business and the ICO.
  • Explain how customers can access, correct, or delete their data.
  • Be upfront about any data sharing or third-party processors.

Data Security: Protecting Personal Data in Practice

GDPR requires you to keep personal data secure—regardless of your business size or resources. The ICO expects small businesses to take proportionate technical and organisational measures. This means strong passwords, encrypted devices, up-to-date software, regular backups, and staff training. The ‘it won’t happen to us’ mentality is risky: most data breaches at small businesses are caused by simple errors or poor security habits.

Physical security matters too. Paper files containing personal data must be locked away, not left on desks or in vehicles. If you use cloud services, check where data is stored (it should be in the UK or a country with adequate protection), and make sure the provider has robust security and GDPR compliance statements.

Access to personal data should be limited to staff who genuinely need it for their work. Small businesses often overlook this, especially when roles are blurred. Regularly review who has access, and remove it promptly when staff leave or change duties. The ICO’s security checklists are a good starting point, but you should tailor your approach to your own risks.

Security MeasureWhy It Matters
Use strong, unique passwordsReduces risk of unauthorised access from leaked credentials.
Encrypt laptops and mobile devicesProtects data if devices are lost or stolen.
Regularly update softwareCloses security vulnerabilities exploited by hackers.
Limit access to dataPrevents accidental or malicious breaches by staff.
Lock paperwork securelyPhysical security is just as important as digital.
Use secure, GDPR-compliant cloud providersEnsures your data is protected and legally stored.
  • Train all staff on data protection basics—most breaches are down to human error.
  • Enable two-factor authentication on all business accounts.
  • Dispose of old computers and files securely—use certified shredders or destruction services.
  • Check your suppliers’ data security policies before sharing personal data.

Data Subject Rights: Responding to Customer Requests

Individuals (data subjects) have a range of rights under GDPR. These include the right to access their data, correct mistakes, erase data, restrict or object to processing, and move their data elsewhere (data portability). You must be able to recognise and respond to these requests promptly—usually within one month. Ignoring, delaying, or mishandling requests is a common cause of ICO investigations and fines.

A subject access request (SAR) is the most common. Customers, staff, or even former employees can ask for a copy of all personal data you hold on them. You can only refuse in specific situations (e.g., if the request is manifestly unfounded or excessive), and you cannot usually charge a fee. You must provide the information in a clear, accessible format.

Other rights are equally important. If someone asks you to correct inaccurate data, you must do so. If they request deletion (‘the right to be forgotten’), you need to evaluate whether you have grounds to keep the data (e.g., for legal reasons). All requests must be logged and handled according to your documented process. Failing to do so is a red flag for the ICO.

Handling Data Subject Access Requests under GDPR

1
Recognise the request
Train your team to spot data subject requests—these might arrive by email, letter, phone, or even social media.
2
Verify identity
Before releasing any personal data, confirm the requester’s identity to prevent unauthorised disclosure.
3
Locate the data
Search all systems, files, and platforms where the person’s data might be held, including emails, databases, and paper records.
4
Respond within one month
Provide the requested data or take the requested action (such as correcting or deleting data) within 30 calendar days.
5
Document and learn
Keep a log of all requests and how you handled them. Use any issues as learning points to improve your processes.
Info: Data Subject Rights

The main rights include: access, rectification, erasure, restriction, objection, data portability, and the right not to be subject to automated decision-making.

  • Set up a clear, published process for handling data rights requests.
  • Don’t ignore or delay—failure to respond is itself a GDPR breach.
  • Keep a log of all data subject requests and your responses.
  • Seek legal advice if you’re unsure about a complex or sensitive request.

Data Breaches: How to Prepare and What to Do if It Happens

A data breach is any incident where personal data is lost, stolen, accessed, or disclosed without authorisation. This could be a lost laptop, a hacked email account, or accidentally sending customer details to the wrong recipient. Under GDPR, you must have a process for detecting, reporting, and investigating breaches.

If a breach is likely to result in a risk to people’s rights and freedoms (e.g., identity theft, financial loss, reputational damage), you must report it to the ICO within 72 hours and, in some cases, inform affected individuals. Failing to report a notifiable breach is itself a serious offence. The ICO provides a self-assessment tool to help you decide if a breach is reportable.

Preparation is critical. Don’t wait for a breach to happen. You should have an incident response plan, train your staff, and regularly review your security measures. Many small businesses wrongly assume they’re too small to be targeted, but the ICO’s records show otherwise.

Warning: Failing to Report a Breach Can Result in Heavy Fines

The ICO can fine you for failing to report a breach, even if the breach itself was not malicious. Always err on the side of caution and seek advice if unsure.

  • Create a written data breach response plan and share it with your staff.
  • Regularly test your breach response with tabletop exercises.
  • Keep records of all breaches—even those not reported to the ICO.
  • After a breach, review and strengthen your data security measures.

Working with Third Parties and International Data Transfers

If you use suppliers, freelancers, or cloud services to process personal data on your behalf, you are legally required to have written contracts in place (data processing agreements) that set out GDPR responsibilities. You must select processors who can guarantee they meet GDPR standards and regularly check their compliance.

International data transfers—sending personal data outside the UK, even to cloud platforms or apps hosted abroad—are tightly regulated. You must ensure data is only transferred to countries with adequate protection (such as those covered by the UK’s adequacy regulations), or put appropriate safeguards in place (such as Standard Contractual Clauses). After Brexit, UK and EU rules aren’t always identical, so check the latest ICO guidance.

Small businesses often overlook these requirements when using popular tools like US-based email marketing platforms or project management apps. Ignorance is no excuse: you must ask suppliers where data is stored and whether data transfer safeguards are in place. The ICO provides a list of countries with adequate data protection and guidance on international transfers.

Country/RegionIs Transfer Permitted Without Extra Safeguards?
EU/EEAYes (under UK adequacy regulations)
USANo (unless specific safeguards are in place)
AustraliaNo (unless safeguards)
Canada (commercial organisations)Yes
IndiaNo (unless safeguards)
  • Ask all suppliers where your data is stored and processed.
  • Use UK- or EU-based cloud providers where possible.
  • Sign a data processing agreement with every data processor.
  • Check the ICO’s list of adequate countries before sending data abroad.

Registration, Documentation, and Ongoing Compliance

Most UK businesses processing personal data must register with the ICO and pay a data protection fee. The fee varies by business size and turnover, starting from £40 per year (as of 2026). Failing to register and pay the fee is a criminal offence, and the ICO routinely checks for non-payers.

You must also maintain documentation of your data processing activities. For most small businesses, this means keeping a record of what personal data you hold, why you hold it, who you share it with, your lawful bases, and your security measures. The ICO provides templates and checklists for this purpose. You don’t need an in-house Data Protection Officer (DPO) unless you process large volumes of sensitive data, but you must still assign someone to oversee compliance.

Ongoing compliance isn’t a one-off task. You should review your data protection practices at least annually, train new staff, and keep up with changes to the law. The ICO regularly updates its guidance, and sector-specific advice is available for charities, retailers, and professional services. Ignoring ongoing compliance is one of the key reasons small businesses get caught out.

Stat: ICO Fee Non-Payment

In 2023, the ICO issued over 4,000 penalty notices to UK small businesses for failing to pay the data protection fee.

  • Register with the ICO and pay the data protection fee promptly.
  • Keep written records of all personal data processing activities.
  • Assign someone in your business to be responsible for GDPR compliance.
  • Regularly review and update your data protection policies.

Common GDPR Pitfalls and How to Avoid Them

Many small businesses fall foul of GDPR not through deliberate neglect but by misunderstanding or cutting corners. Some of the most common mistakes include relying on outdated consent, failing to update privacy notices, ignoring subject access requests, and not securing data properly. Small businesses often wrongly believe that GDPR isn’t relevant to them, especially if they have few staff or only work B2B. The ICO treats all businesses equally, regardless of size.

Another common pitfall is failing to consider new data uses as the business grows—such as launching a new marketing campaign or adopting a new software tool. Every time you change how you use personal data, you need to review your GDPR compliance. This includes updating your privacy notice and assessing the risks of new technologies.

Finally, don’t assume that using a ‘GDPR-compliant’ supplier means your work is done. You are still responsible for your customers’ data in the eyes of the law. Always check suppliers’ credentials, sign contracts, and monitor compliance over time.

  • Review GDPR compliance whenever you change business processes.
  • Never ignore a data subject request or complaint.
  • Don’t assume GDPR doesn’t apply to small or B2B-only businesses.
  • Be wary of ‘GDPR-compliant’ claims by suppliers—do your due diligence.

Practical Steps to Get GDPR Right in Your Small Business

GDPR compliance can seem daunting, but breaking it down into practical steps makes it manageable. Start by mapping out all the personal data you hold, where it’s stored, and how it’s used. This data mapping exercise is the foundation of compliance—you can’t protect what you don’t know you have.

Next, review your privacy notices and lawful bases. Make sure every processing activity is justified, documented, and clearly communicated to customers and staff. Train your team—no matter how small—on data protection basics. Most data breaches at small businesses happen because of simple human mistakes, not sophisticated hacks.

Finally, put in place processes for handling data subject requests and data breaches. Keep everything documented, and set a regular schedule to review and improve your practices. GDPR isn’t a one-off project—it’s an ongoing part of running a responsible business in the UK.

Complying with GDPR for UK Small Businesses

1
Audit your data
List every type of personal data your business holds, where it’s stored, who has access, and why you collect it.
2
Review lawful bases and privacy notices
Check you have a valid reason for each data use. Update your privacy notice and make it available to customers and staff.
3
Train your team
Provide basic GDPR training for all staff, including how to spot data subject requests and report breaches.
4
Set up processes for rights and breaches
Create clear, documented procedures for handling subject access requests and data breaches.
5
Register with the ICO and keep records
Pay the annual data protection fee and maintain up-to-date records of your processing activities, policies, and supplier contracts.
Key Takeaways
  • GDPR applies to nearly all UK small businesses. If you collect or use any personal data, you must comply—no matter your size or sector.
  • Document everything. From your privacy notice to your data mapping and breach response, keep written records to demonstrate compliance.
  • Don’t ignore data subject rights. Respond promptly and professionally to requests—failing to do so is a fast way to attract ICO attention.
  • Data security is your responsibility. Take practical steps to protect personal data, both digitally and physically, and train your staff.
  • Review compliance regularly. GDPR isn’t a one-off project; update your policies and practices as your business changes.
  • Choose suppliers carefully. You can’t outsource liability—sign contracts and check that all third-party processors are GDPR compliant.
  • Register with the ICO and pay the fee. Failure to do so is a criminal offence and the ICO actively pursues non-payers.
  • Preparation is key for breaches. Have a plan, know what to do, and don’t be afraid to seek advice from the ICO or a legal professional if an incident occurs.
⭐ Exclusive Partner Offers
Tide
Tide Business Account

Ready for the next step? Open a business bank account to keep your finances organised.

Code: REFER200
Claim £200 Free
Capital on Tap
Capital on Tap Card

Get 7,500 free points (worth £75) on your first transaction. No annual fee. Instant decision.

Code: SETTINGUP
Claim 7,500 Points

Affiliate disclosure: we may earn a commission via our links. This does not affect our editorial independence.