Data Protection & UK GDPR for Small Businesses
A plain-English guide to UK GDPR for small businesses: ICO registration, lawful basis, SARs, DPIAs, privacy notices, cookies and international data transfers.
If your business handles customer or staff data, UK GDPR applies to you — no matter how small you are. This hub explains the essentials in plain English: registering with the ICO, choosing a lawful basis, answering subject access requests, writing a privacy notice, cookies and PECR, and using US-hosted tools lawfully. Start here, then follow the detailed guides beneath.
What data protection actually means for a small business
If you hold information about people — customers, enquiries, staff, suppliers — then UK data protection law applies to you. It does not matter whether you have two employees or two hundred. The rules are set out in the UK GDPR and the Data Protection Act 2018, and they are overseen by the Information Commissioner’s Office (the ICO).
The good news is that compliance is mostly common sense written down: know what personal data you hold, have a good reason for using it, keep it secure, be honest with people about what you do, and respond properly when someone asks. This hub walks through each part in plain English and links to detailed guides where you need more depth.
If you are new to all of this, start with our plain-English guide to GDPR basics for UK small businesses, then come back here to fill in the specifics.
Registering with the ICO
Most businesses that process personal data must pay a data protection fee to the ICO and register their details. For small organisations this is usually a modest annual amount, and not paying it is one of the most common — and most avoidable — reasons small firms end up on the ICO’s radar. It takes a few minutes to sort out on the ICO website, and it is the first practical step towards being compliant.
Having a lawful reason to use data
You cannot use personal data just because you have it. Every use needs a lawful basis — one of six legal grounds such as consent, contract, legal obligation or legitimate interests. Choosing the right one matters, because it affects the rights people have and what you must tell them. Our guide to lawful basis for processing personal data, explained shows how to pick the right basis for everyday situations like taking orders, sending marketing or paying staff.
Being honest: your privacy notice
People have a right to know what you do with their information. A privacy notice is simply a clear page on your website that explains what you collect, why, how long you keep it, who you share it with and how someone can exercise their rights. It does not need to be full of legal jargon — plainer is better. Our guide on how to write a privacy notice for a small business gives you a practical structure to follow.
When someone asks to see their data
Anyone can ask you for a copy of the personal data you hold about them. This is called a subject access request, or SAR, and you normally have one month to respond, free of charge. SARs can feel daunting the first time — especially if the request is broad or comes from a disgruntled customer or ex-employee — but there is a clear process. Read how to handle a subject access request so you are not caught out.
Assessing risk before you start something new
When you plan something that could carry higher risk to people’s privacy — new CCTV, large-scale profiling, or a new system holding sensitive data — you may need a Data Protection Impact Assessment (DPIA). It is a short, structured way to think through the risks before you commit. Our DPIA guide explains when one is required and how to complete it without over-complicating things.
Do you need a Data Protection Officer?
Many small businesses do not legally need a formal Data Protection Officer, but some do — and everyone benefits from having someone clearly responsible. The guide on whether you need a Data Protection Officer helps you work out where you stand and what the alternatives are.
Websites, cookies and marketing rules
Data protection is not only about GDPR. If your website uses cookies or analytics, or you send marketing emails and texts, the Privacy and Electronic Communications Regulations (PECR) also apply. That means proper cookie consent and sensible marketing practices. Our guide to cookies and PECR for UK business websites covers what your cookie banner actually needs to do.
Using US-hosted tools and cloud services
Almost every small business uses tools hosted overseas — email, storage, CRM, accounting, marketing platforms. Sending personal data outside the UK is entirely lawful, provided you rely on an appropriate transfer mechanism such as the UK’s adequacy arrangements or the ICO’s International Data Transfer Agreement (IDTA). In practice, the reputable providers you already use have this covered; you just need to understand and document it. Our guide to international data transfers under UK GDPR clears up the common myths.
Data protection and security go together
Keeping data lawful is only half the job — you also have to keep it secure. Strong passwords, multi-factor authentication, backups and staff awareness are what turn a policy into real protection. It is worth reading these alongside our hubs on cyber security, email security and managed IT, since a breach is both a security incident and a data protection one. Our cyber security services can help you put the right safeguards in place.
Where to start
If all this feels like a lot, that is normal — you do not have to fix everything at once. Get registered with the ICO, write an honest privacy notice, know how you would answer a SAR, and make sure your systems are secure. From there, work through the guides above at your own pace.
Want a hand getting the basics right? Book a free IT and security review and we will help you find the gaps and prioritise the fixes — in plain English, with no jargon and no pressure.
30 guides in this topic
IT and Cyber Security for Charities and Non-Profits in the UK
A plain-English guide to IT and cyber security for UK charities: protecting donor and beneficiary data, controlling volunteer access, and Cyber Essentials on a tight budget.
Read → GuideIT & Cyber Security for Solicitors and Law Firms: A Plain-English Guide
A practical guide to IT security for UK law firms: client confidentiality, SRA-aligned controls, secure email and documents, DMARC, backups and staying compliant.
Read → GuideIT Support for Recruitment Agencies in the UK
A plain-English guide to IT and cyber security for UK recruitment agencies: protecting candidate data, securing your CRM/ATS, mobile working and stopping placement invoice fraud.
Read → GuideCyber Essentials Explained: A Plain-English Guide for UK Small Businesses
What Cyber Essentials is, the five controls, CE vs CE Plus, why it wins contracts and helps insurance, and how a small UK business gets certified.
Read → GuideIT and Cyber Security for Financial Advisers in the UK
A practical guide to IT and cyber security for UK financial advisers and IFAs: meeting FCA expectations, protecting client financial data, secure email, backups and Cyber Essentials.
Read → GuideIT Security for Dental and Healthcare Practices: A Practical Guide
How UK dental and healthcare practices can protect patient data under UK GDPR and the NHS DSPT, keep clinical software running, back up safely and control access.
Read → GuideIT Support for Nurseries and Childcare Settings in the UK
Plain-English IT and cyber security guidance for UK nurseries: protect children's and safeguarding data, control access, manage retention, and reassure parents.
Read → ArticleAI Tools at Work: The Real Security Risk Nobody Mentions
Staff are already using ChatGPT and other AI tools at work. The real danger isn't the robots — it's confidential data being pasted into public tools. Here's a sensible approach.
Read → GuideIT Support for Care Homes in the UK: A Practical Security Guide
A plain-English guide to IT for UK care homes: protecting resident and staff data, CQC-aware information governance, reliable Wi-Fi and devices, and business continuity.
Read → ArticleHow to Securely Dispose of Old Computers and Data
Selling or scrapping an old work computer? Here's how to wipe data properly, when to destroy the drive, and how to recycle old kit legally — in plain English.
Read → ArticleGDPR Basics for UK Small Businesses: A Plain-English Guide
A jargon-free guide to UK GDPR for small businesses: what personal data is, lawful basis, ICO registration and fee, your security duty, and handling breaches.
Read → ArticleHow to Report a Data Breach to the ICO: The 72-Hour Rule Explained
When a data breach is reportable, how the ICO's 72-hour rule works, what to include in your report and when to tell affected individuals. Plain-English UK guide.
Read → ArticleData Retention and Records of Processing: A Plain-English Guide for Small Businesses
How UK small businesses can handle data retention, ROPA and data minimisation under UK GDPR — in plain English, with practical steps you can start this week.
Read → ArticleInsider Threats for Small Business: The Risk From People You Already Trust
Understand accidental and malicious insider risk, and how least privilege, careful offboarding and sensible monitoring protect your small business.
Read → ArticleHow to Write a Password Policy for a Small Business (the Sensible Way)
An NCSC-aligned password policy for UK small businesses: length over complexity, no pointless forced changes, MFA everywhere and a password manager. A plain template.
Read → ArticleCyber Security for a Small Ecommerce Business
How to protect a small UK online store: securing your platform and plugins, safe payments, customer data under UK GDPR, spotting fraud, and backups that actually restore.
Read → GuideInternational Data Transfers Under UK GDPR, Explained
A plain-English guide to UK GDPR international data transfers for small businesses using US-hosted tools — mechanisms, the UK-US bridge, IDTA and TRAs.
Read → ArticleDo I Need a Data Protection Officer (DPO)?
Do you need a Data Protection Officer? When a DPO is legally required under UK GDPR — and what most UK small businesses actually need instead.
Read → ArticleICO Fines and Enforcement: What Small Businesses Should Know
A plain-English guide to ICO enforcement for UK small businesses: reprimands vs fines, the real maximum penalties, and what actually triggers action.
Read → ArticleHow to Handle a Subject Access Request (SAR)
What a subject access request is, the one-month deadline, how to respond step by step, and the common mistakes UK small businesses make with SARs.
Read → ArticleHow to Write a Privacy Notice for a Small Business
What must a privacy notice include under UK GDPR? A plain-English structure for UK small businesses, the required content, and the common gaps to avoid.
Read → ArticleLawful Basis for Processing Personal Data, Explained
The six lawful bases under UK GDPR in plain English for small businesses: how to choose one, and when to use consent versus legitimate interests.
Read → ArticleCookies and PECR for UK Business Websites
Cookie consent and PECR basics for UK small businesses — what needs consent, how to build a compliant banner, and how to handle analytics lawfully.
Read → ArticleCCTV and GDPR: Using Cameras Lawfully in Your Business
How to use CCTV lawfully under UK GDPR: signage, a clear purpose, sensible retention, handling footage requests, and what the ICO expects of you.
Read → GuideData Protection Impact Assessment (DPIA): A Simple Guide
What a DPIA is, when UK GDPR requires one, and how a small business can complete a simple, practical Data Protection Impact Assessment step by step.
Read → ArticleThird-Party and Supply-Chain Risk for Small Businesses
The suppliers and software you rely on can become your security problem. A plain-English guide to supply-chain risk for UK small firms, plus what to ask vendors.
Read → ArticleEmail Marketing for Small Business: Getting Started the Right Way
How to build a mailing list properly under UK PECR rules, pick the right tool, and get your emails delivered. A plain-English guide for small businesses.
Read → ArticleCyber Insurance for UK Small Businesses: What It Covers and How to Avoid a Denied Claim
What cyber insurance actually covers, why UK insurers now check for MFA and DMARC, what to put in place first, and the common reasons small-business claims get denied.
Read → ArticleCyber Essentials vs Cyber Essentials Plus: Which One Does Your Business Need?
The plain-English difference between Cyber Essentials and Cyber Essentials Plus, which one you need, what the audit involves, the cost and effort, and the 2026 MFA change.
Read → ArticleThe IT Support Checklist for UK Accountancy Practices
A practical IT and cyber-security checklist for UK accountants: protecting client data, staying online through tax season, and meeting Cyber Essentials.
Read →Other guide hubs
Cyber Security for UK Small Businesses
A plain-English guide to cyber security for UK small businesses: the real threats, the essential controls that stop most attacks, and where to get help.
Explore →Email Security & Fraud Protection for Small Business
Protect your business from invoice fraud, phishing and email scams. A plain-English guide to SPF, DKIM, DMARC, BEC and secure email for UK firms.
Explore →Managed IT & Cloud Support for Small Businesses
A plain-English guide to managed IT, Microsoft 365, cloud, VoIP and scaling technology for UK small businesses. Start here, then explore the detail.
Explore →Want this handled for you?
Dacros runs the IT and security for UK small businesses. Book a free review — no jargon, no pressure.