GDPR and Data Protection for UK Businesses

Free comprehensive guide: GDPR and Data Protection for UK Businesses. Practical information for UK entrepreneurs and small business owners.

By Sarah Johnson · Last updated 2026-06-08

Understanding UK GDPR

The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 govern how businesses collect, use, store, and share personal data in the UK. Since Brexit, the UK has its own version of GDPR (UK GDPR) which is largely equivalent to the EU GDPR but applies to processing of UK residents' data.

Compliance is not optional. The Information Commissioner's Office (ICO) can fine businesses up to £17.5 million or 4% of global annual turnover (whichever is higher) for serious breaches. Even small businesses have faced fines of tens of thousands of pounds.


Key Definitions

Personal data: Any information that can identify a living individual, directly or indirectly. This includes names, email addresses, phone numbers, IP addresses, location data, and much more.

Special category data: More sensitive personal data that requires extra protection, including health data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, sexual orientation, and criminal convictions.

Data subject: The individual whose personal data you hold.

Data controller: The organisation that determines why and how personal data is processed. If you collect customer data, you are a data controller.

Data processor: An organisation that processes personal data on behalf of a data controller (e.g., your email marketing platform, your cloud accounting software, your payroll provider).


The Six Lawful Bases for Processing

You must have a lawful basis for every type of personal data processing. The six bases are:

1. Consent: The individual has given clear, specific, informed, and unambiguous consent. Must be freely given, easily withdrawn, and documented. Cannot be a condition of service.

2. Contract: Processing is necessary to fulfil a contract with the individual, or to take steps at their request before entering a contract (e.g., processing a customer's address to deliver their order).

3. Legal obligation: Processing is necessary to comply with a legal requirement (e.g., keeping employee payroll records for HMRC).

4. Vital interests: Processing is necessary to protect someone's life (rare in business contexts).

5. Public task: Processing is necessary for a task in the public interest or official authority (mainly applies to public bodies).

6. Legitimate interests: Processing is necessary for your legitimate business interests, provided these are not overridden by the individual's rights and interests. The most flexible basis, but requires a balancing test.

Practical guidance: For most small businesses:

• Use contract for processing customer data to fulfil orders

• Use legal obligation for employee data required by HMRC

• Use legitimate interests for fraud prevention, security, and some marketing

• Use consent for email marketing to individuals (required under PECR — see below)


The Seven Principles of UK GDPR

All personal data processing must comply with these seven principles:

1. Lawfulness, fairness, and transparency: Process data lawfully, fairly, and in a transparent manner

2. Purpose limitation: Collect data for specified, explicit, and legitimate purposes; do not use it for incompatible purposes

3. Data minimisation: Only collect the data you actually need

4. Accuracy: Keep data accurate and up to date

5. Storage limitation: Do not keep data longer than necessary

6. Integrity and confidentiality: Protect data against unauthorised access, loss, or destruction

7. Accountability: Be able to demonstrate compliance with all the above


Individual Rights

Under UK GDPR, individuals have the following rights:

| Right | What It Means |

|---|---|

| Right to be informed | Individuals must be told how their data is used (via your Privacy Policy) |

| Right of access | Individuals can request a copy of all data you hold about them (Subject Access Request) |

| Right to rectification | Individuals can ask you to correct inaccurate data |

| Right to erasure | Individuals can ask you to delete their data ("right to be forgotten") |

| Right to restrict processing | Individuals can ask you to limit how you use their data |

| Right to data portability | Individuals can ask for their data in a portable format |

| Right to object | Individuals can object to processing based on legitimate interests or for direct marketing |

| Rights related to automated decision-making | Protections against solely automated decisions with significant effects |

Responding to requests: You must respond to Subject Access Requests within 1 month (extendable by 2 months for complex requests). You cannot charge a fee for most requests.


Privacy Policy

Every business that collects personal data must have a Privacy Policy. This must be:

• Written in clear, plain language

• Easily accessible (typically linked in your website footer)

• Specific about what data you collect, why, and how long you keep it

What your Privacy Policy must include:

• Who you are and your contact details

• What personal data you collect and why

• The lawful basis for each type of processing

• How long you keep data

• Who you share data with (third parties, processors)

• Individuals' rights and how to exercise them

• How to make a complaint to the ICO

• Details of any international data transfers


Cookie Consent

If your website uses cookies (almost all websites do), you must:

• Inform visitors about the cookies you use

• Obtain consent before setting non-essential cookies (analytics, marketing, preferences)

• Allow visitors to withdraw consent easily

• Not use pre-ticked consent boxes

Essential cookies (strictly necessary for the website to function) do not require consent. Non-essential cookies (analytics, advertising, personalisation) require explicit opt-in consent.

Use a cookie consent management platform (CookieYes, Cookiebot, OneTrust) to manage this correctly.


Email Marketing and PECR

The Privacy and Electronic Communications Regulations (PECR) govern electronic marketing (email, SMS, automated calls). Key rules:

Individuals (B2C): You must have explicit opt-in consent before sending marketing emails. Pre-ticked boxes do not count as consent. You must provide an easy unsubscribe mechanism in every email.

Businesses (B2B): You can send marketing emails to business email addresses (e.g., info@company.com) without prior consent, provided you have a legitimate interest and offer an opt-out. However, if the email goes to a named individual's work email, the same rules as B2C apply.

Soft opt-in: If someone has bought from you recently and you are marketing similar products/services, you can email them without new consent (soft opt-in), provided you offered an opt-out at the point of data collection.


Data Security

You must implement "appropriate technical and organisational measures" to protect personal data. For most small businesses, this means:

Technical measures:

• Strong, unique passwords for all accounts (use a password manager)

• Two-factor authentication (2FA) on all accounts containing personal data

• Encrypted storage for sensitive data

• Regular software updates and patches

• Secure Wi-Fi (not using public Wi-Fi for business data without a VPN)

• Regular backups

Organisational measures:

• A clear data protection policy for staff

• Staff training on data protection

• Access controls (only give staff access to the data they need)

• A process for identifying and reporting data breaches

• Contracts with data processors (your software providers, payroll bureau, etc.)


Data Breach Notification

If you suffer a personal data breach (unauthorised access, loss, or destruction of personal data), you must:

1. Assess the risk — Does the breach pose a risk to individuals' rights and freedoms?

2. Report to the ICO within 72 hours if the breach is likely to result in a risk to individuals (you can report online at ico.org.uk)

3. Notify affected individuals if the breach is likely to result in a high risk to their rights and freedoms (e.g., financial data, health data, passwords)

4. Document the breach — Keep a record of all breaches, even those you do not report


Do I Need to Register with the ICO?

Most organisations that process personal data must pay the ICO's data protection fee:

Tier 1 (micro-organisations, turnover under £632,000, fewer than 10 staff): £40/year

Tier 2 (small and medium organisations): £60/year

Tier 3 (large organisations, turnover over £36 million or more than 250 staff): £2,900/year

Some organisations are exempt (e.g., those processing data only for personal, family, or household purposes). Check the ICO's self-assessment tool at ico.org.uk.


Do I Need a Data Protection Officer (DPO)?

Most small businesses do not need a DPO. You are required to appoint a DPO if you:

• Are a public authority or body

• Carry out large-scale systematic monitoring of individuals

• Process special category data or criminal conviction data on a large scale

Even if not required, it is good practice to designate someone responsible for data protection compliance.


Practical Steps for Small Business Compliance

1. Audit your data: Map what personal data you collect, why, how you store it, and who has access

2. Identify your lawful bases: Document the lawful basis for each type of processing

3. Write or update your Privacy Policy: Make it clear, specific, and accessible

4. Implement cookie consent: Use a consent management platform

5. Review your email marketing: Ensure you have valid consent or legitimate interest

6. Secure your systems: Implement 2FA, strong passwords, and access controls

7. Train your staff: Ensure everyone handling personal data understands their obligations

8. Register with the ICO: Pay the annual data protection fee

9. Create a breach response plan: Know what to do if you suffer a breach

10. Review supplier contracts: Ensure data processors have appropriate data processing agreements

Frequently asked questions

Does GDPR apply to my small business?

Yes. UK GDPR applies to any organisation that processes personal data about UK residents, regardless of size. There is no small business exemption. However, the ICO takes a proportionate approach — the obligations on a small business are less onerous than those on a large corporation. The key is to understand your obligations and implement reasonable measures.

What is a Subject Access Request and how do I respond?

A Subject Access Request (SAR) is a request from an individual to receive a copy of all personal data you hold about them. You must respond within 1 month (extendable by 2 months for complex requests). You must provide the data free of charge in most cases. You must also tell the individual why you hold the data, who you share it with, and how long you keep it. Failing to respond to a SAR can result in ICO enforcement action.

Do I need consent to send marketing emails?

For marketing emails to individuals (B2C), you need explicit opt-in consent under PECR. Pre-ticked boxes do not count. For B2B emails to generic business addresses (info@company.com), you can rely on legitimate interests, but must offer an opt-out. If emailing a named individual's work address, the same rules as B2C apply. The 'soft opt-in' allows you to email existing customers about similar products without new consent.

What should I do if I suffer a data breach?

Act quickly. Contain the breach (change passwords, revoke access). Assess the risk to individuals. If the breach poses a risk to individuals' rights and freedoms, report it to the ICO within 72 hours at ico.org.uk. If the risk is high, notify affected individuals. Document everything, even if you decide not to report. Having a breach response plan in place before a breach occurs is strongly recommended.

How long can I keep customer data?

You should only keep personal data for as long as necessary for the purpose for which it was collected. There is no single answer — it depends on the type of data and purpose. For example: customer transaction records should be kept for at least 6 years (for tax purposes); employee records should be kept for 6 years after employment ends; marketing data should be deleted when consent is withdrawn or the individual opts out. Document your retention periods in your Privacy Policy.

Do I need a cookie banner on my website?

Yes, if your website uses non-essential cookies (analytics, advertising, personalisation — which almost all websites do). You must inform visitors about the cookies you use and obtain their consent before setting non-essential cookies. Essential cookies (strictly necessary for the website to function) do not require consent. Use a cookie consent management platform (CookieYes, Cookiebot) to implement this correctly.