Compliance

GDPR for UK small businesses: a practical guide

James Whitfield25 October 20257 min read
Back to all articles

GDPR entered UK law in 2018 and, despite the scaremongering at the time, most small businesses don't need to spend thousands on compliance. What they do need is a basic understanding of the rules and some practical steps to follow them.

UK GDPR versus the original GDPR

After Brexit, the EU's General Data Protection Regulation was incorporated into UK law as the UK GDPR, with some minor variations. For most small businesses, the practical requirements are the same. You still need a lawful basis for processing personal data, you still need to respond to subject access requests, and you still need to have appropriate security measures in place.

The Information Commissioner's Office, or ICO, is the UK's data protection regulator. Their website has genuinely useful, plain-English guidance for small businesses, including self-assessment tools that are worth an hour of your time.

The ICO has consistently stated that it takes a proportionate approach to small businesses. Most small business GDPR issues are resolved through guidance rather than fines. The largest penalties are reserved for organisations that handle large volumes of sensitive data and act negligently.

When you need to register with the ICO

Most organisations that process personal data need to pay the ICO's data protection fee, which is a modest annual registration requirement. The fee starts at £40 per year for small organisations. Some businesses are exempt, including sole traders who only process data for accounting purposes.

Check the ICO's self-assessment tool on their website to confirm whether you need to register. It takes about five minutes.

Your lawful basis for processing data

Every time you process personal data, you need a lawful basis for doing so. For small businesses, the most relevant ones are contract, legitimate interests, and consent.

Contract means you need the data to fulfil a contract with the person. This is appropriate for client data you hold to deliver services and send invoices. Legitimate interests covers processing that is necessary for your business interests, provided those interests aren't overridden by the individual's rights. This applies to many marketing and CRM activities. Consent means the person has explicitly agreed to a specific use of their data. This is the most restrictive basis and must be freely given, specific, and easy to withdraw.

What you must tell people

Whenever you collect personal data, you must provide a privacy notice: who you are, what data you're collecting, why you're collecting it, how long you'll keep it, who you share it with, and what rights the individual has.

For most small businesses, this means a privacy policy on your website and a brief information clause in your contracts or intake forms. The ICO's website has template language that's easy to adapt.

Subject access requests

Any individual can ask you what personal data you hold about them and request a copy. You have one month to respond, and you can't charge for it. You must provide the data in a commonly used format.

For a small business, this rarely happens. When it does, it's usually a current or former employee rather than a client. Having your data in a well-organised system rather than scattered across email inboxes makes responding much easier.

Keeping data secure

You must have appropriate security measures for the personal data you hold. For a small business, this means strong passwords, two-factor authentication on business systems, encrypting sensitive files, and having a plan for what to do if there's a breach.

A data breach doesn't automatically mean you've violated GDPR. What matters is whether you had appropriate measures in place and whether you report serious breaches to the ICO within 72 hours of becoming aware of them.

GDPR and your business software

If you're using a CRM or business platform to manage client data, you're a data controller and the software provider is a data processor. You should have a Data Processing Agreement with any provider who processes personal data on your behalf.

Reputable UK software providers will have DPAs available. If your provider can't produce one, that's a concern worth taking seriously. All WeekOne customers receive a Data Processing Agreement as standard.

WeekOne

Run your whole business in one place

CRM, invoicing, projects, and support, built for UK small businesses.