Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

GDPR Basics for UK Small Businesses: A Plain-English Guide

In short

UK GDPR sounds daunting but the basics are manageable for any small business. This guide explains, in plain English, what counts as personal data, why you need a lawful basis to use it, when you must register and pay the ICO fee, your legal duty to keep data secure, and what to do if a breach happens, including the 72-hour reporting rule.

Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.

GDPR without the jargon

For a lot of small business owners, “GDPR” is one of those terms that arrives with a sense of dread, a mix of vague warnings about fines and forms nobody quite understands. The reality is much more manageable. UK GDPR is really a set of common-sense rules about handling information about people responsibly, and the basics are well within reach of any small business.

This guide explains the essentials in plain English: what counts as personal data, why you need a reason to use it, when you have to register with the regulator, your duty to keep data safe, and what to do if something goes wrong. It is a general overview, not legal advice, but it will help you understand what matters and where to focus.

What counts as personal data

Personal data is any information that relates to a living person who can be identified from it, directly or indirectly. That is broader than many people expect. It includes obvious things like:

  • names, addresses, email addresses and phone numbers
  • payroll and bank details for staff
  • customer records and order history

And less obvious things like IP addresses, photos, and CCTV footage.

Some categories are treated as more sensitive and need extra care, known as special category data. This includes information about health, race or ethnicity, religious beliefs, sexual orientation and similar. If you handle any of this, for example a healthcare provider or a care home, the bar is higher and you need to be especially careful.

The practical takeaway: if you have customers, employees, suppliers or a mailing list, you are handling personal data, and UK GDPR applies to you. There is no exemption for being small.

You need a lawful basis to use it

Under UK GDPR you cannot just collect and use personal data because it is handy. You need a lawful basis, a legitimate reason, for each thing you do with it. There are six to choose from, and at least one must apply:

  • Consent the person has clearly agreed (common for marketing emails).
  • Contract you need the data to provide something they asked for, such as delivering an order.
  • Legal obligation the law requires it, such as keeping certain tax records.
  • Vital interests to protect someone’s life (rare in business).
  • Public task for official functions (mainly public bodies).
  • Legitimate interests you have a genuine business reason that does not override the person’s rights.

For most small businesses, consent, contract, legal obligation and legitimate interests cover almost everything. The key habit is to decide and write down which basis applies to each activity, marketing, payroll, customer records, before you start, and to be honest with people about how you use their data, usually through a simple privacy notice on your website.

You do not need to be a lawyer to get the basics right. Most of UK GDPR comes down to a simple idea: only collect the personal data you genuinely need, be honest about how you use it, and keep it safe.

Registering with the ICO and paying the fee

The Information Commissioner’s Office (ICO) is the UK regulator for data protection. Most organisations that handle personal data must register with the ICO and pay an annual data protection fee, unless they qualify for a specific exemption.

The fee is tiered according to the size of your organisation and your turnover, and the large majority of small businesses fall into the lower tiers. It is a modest annual cost, and not paying when you should can itself lead to a fine, so it is worth getting right.

The simplest way to check is the self-assessment tool on the ICO website, which tells you whether you need to register and which fee applies. Always confirm the current amount there directly, as fees are set by the ICO and can change.

Your duty to keep data secure

One of the core requirements of UK GDPR is that you keep personal data secure. The law expects you to have “appropriate technical and organisational measures” in place, which in plain terms means sensible, proportionate security for the kind of data you hold.

For a small business, that usually means the fundamentals done properly:

  • Strong, unique passwords and a password manager, so staff are not reusing weak passwords across accounts. Our password manager guide explains how to do this simply.
  • Multi-factor authentication (MFA) on email and key systems, so a stolen password alone is not enough to get in.
  • Keeping software and devices updated, so known weaknesses are patched.
  • Secure email and file storage, particularly if you handle sensitive information. Tools like Proton Mail and Proton Drive offer encrypted email and file storage that keep data private, which is one straightforward way to raise your security.
  • Controlling who has access to what, and removing access promptly when someone leaves.
  • Backups that are tested, so you can recover if data is lost or held to ransom.

A great way to structure all of this is to work towards Cyber Essentials, the UK government-backed scheme covering exactly these basics. It helps you meet your security duty and reassures clients at the same time. Our cyber security services can help you get there, and our 30-day security hardening playbook is a practical starting point.

When things go wrong: data breaches

A personal data breach is any security incident that leads to personal data being lost, stolen, destroyed, altered or exposed. That includes a stolen laptop, an email sent to the wrong person, a ransomware attack, or a lost paper file.

UK GDPR sets clear expectations for how you respond:

  1. Contain and assess. Work out what happened, what data is involved and who is affected.
  2. Report to the ICO within 72 hours if the breach is likely to pose a risk to people’s rights and freedoms. The clock starts when you become aware of it, so speed matters.
  3. Tell affected individuals if the breach is likely to result in a high risk to them, so they can protect themselves.
  4. Keep a record of all breaches, even minor ones you decide not to report, together with the reasons for your decision.

Having a simple plan for this in advance, who does what, who to contact, makes a stressful situation far more manageable. Preparation is what separates a contained incident from a crisis.

Getting started

UK GDPR compliance is a journey, not a single box to tick, but you can make solid progress quickly:

  1. Know what you hold. Make a simple list of the personal data you have and where it lives.
  2. Check your ICO registration and pay the fee if you need to.
  3. Write down your lawful basis for the main things you do, and have a clear privacy notice.
  4. Tighten your security with passwords, MFA, updates and backups.
  5. Have a breach plan so you know what to do if the worst happens.

If you would like help with the security side of GDPR, the part that protects you from the breaches that cause the real damage, get in touch. We help small businesses across Leeds and Yorkshire put sensible, proportionate protections in place, explained in plain English.

Frequently asked questions

Does GDPR apply to my small business?

Almost certainly yes. UK GDPR applies to any organisation that handles personal data about living people, and there is no exemption for being small. If you have customers, employees, suppliers or a mailing list, you are handling personal data and the rules apply. The size of your business affects how much you need to do in practice, but not whether the law applies to you at all.

Do I have to pay a fee to the ICO?

Most organisations that process personal data must register with the ICO and pay an annual data protection fee, unless they qualify for an exemption. The fee is tiered based on your size and turnover, and most small businesses fall into the lower tiers. You can check whether you need to pay, and the current fee amount, using the self-assessment tool on the ICO website.

What counts as a lawful basis for using personal data?

UK GDPR sets out six lawful bases, and you need at least one before you use someone's personal data. The most common for small businesses are consent, contract (you need the data to provide a service someone asked for), legal obligation, and legitimate interests. You should decide and record which basis applies to each activity, such as marketing or payroll, before you start.

What do I do if we have a data breach?

First contain it and assess what happened and who is affected. If the breach is likely to pose a risk to people's rights and freedoms, you must report it to the ICO within 72 hours of becoming aware of it. If the risk is high, you also need to tell the affected individuals. Keep a record of all breaches, even minor ones you decide not to report, along with your reasoning.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.