Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
Topic guide

Data Protection & UK GDPR for Small Businesses

A plain-English guide to UK GDPR for small businesses: ICO registration, lawful basis, SARs, DPIAs, privacy notices, cookies and international data transfers.

In short

If your business handles customer or staff data, UK GDPR applies to you — no matter how small you are. This hub explains the essentials in plain English: registering with the ICO, choosing a lawful basis, answering subject access requests, writing a privacy notice, cookies and PECR, and using US-hosted tools lawfully. Start here, then follow the detailed guides beneath.

What data protection actually means for a small business

If you hold information about people — customers, enquiries, staff, suppliers — then UK data protection law applies to you. It does not matter whether you have two employees or two hundred. The rules are set out in the UK GDPR and the Data Protection Act 2018, and they are overseen by the Information Commissioner’s Office (the ICO).

The good news is that compliance is mostly common sense written down: know what personal data you hold, have a good reason for using it, keep it secure, be honest with people about what you do, and respond properly when someone asks. This hub walks through each part in plain English and links to detailed guides where you need more depth.

If you are new to all of this, start with our plain-English guide to GDPR basics for UK small businesses, then come back here to fill in the specifics.

Registering with the ICO

Most businesses that process personal data must pay a data protection fee to the ICO and register their details. For small organisations this is usually a modest annual amount, and not paying it is one of the most common — and most avoidable — reasons small firms end up on the ICO’s radar. It takes a few minutes to sort out on the ICO website, and it is the first practical step towards being compliant.

Having a lawful reason to use data

You cannot use personal data just because you have it. Every use needs a lawful basis — one of six legal grounds such as consent, contract, legal obligation or legitimate interests. Choosing the right one matters, because it affects the rights people have and what you must tell them. Our guide to lawful basis for processing personal data, explained shows how to pick the right basis for everyday situations like taking orders, sending marketing or paying staff.

Being honest: your privacy notice

People have a right to know what you do with their information. A privacy notice is simply a clear page on your website that explains what you collect, why, how long you keep it, who you share it with and how someone can exercise their rights. It does not need to be full of legal jargon — plainer is better. Our guide on how to write a privacy notice for a small business gives you a practical structure to follow.

When someone asks to see their data

Anyone can ask you for a copy of the personal data you hold about them. This is called a subject access request, or SAR, and you normally have one month to respond, free of charge. SARs can feel daunting the first time — especially if the request is broad or comes from a disgruntled customer or ex-employee — but there is a clear process. Read how to handle a subject access request so you are not caught out.

Assessing risk before you start something new

When you plan something that could carry higher risk to people’s privacy — new CCTV, large-scale profiling, or a new system holding sensitive data — you may need a Data Protection Impact Assessment (DPIA). It is a short, structured way to think through the risks before you commit. Our DPIA guide explains when one is required and how to complete it without over-complicating things.

Do you need a Data Protection Officer?

Many small businesses do not legally need a formal Data Protection Officer, but some do — and everyone benefits from having someone clearly responsible. The guide on whether you need a Data Protection Officer helps you work out where you stand and what the alternatives are.

Websites, cookies and marketing rules

Data protection is not only about GDPR. If your website uses cookies or analytics, or you send marketing emails and texts, the Privacy and Electronic Communications Regulations (PECR) also apply. That means proper cookie consent and sensible marketing practices. Our guide to cookies and PECR for UK business websites covers what your cookie banner actually needs to do.

Using US-hosted tools and cloud services

Almost every small business uses tools hosted overseas — email, storage, CRM, accounting, marketing platforms. Sending personal data outside the UK is entirely lawful, provided you rely on an appropriate transfer mechanism such as the UK’s adequacy arrangements or the ICO’s International Data Transfer Agreement (IDTA). In practice, the reputable providers you already use have this covered; you just need to understand and document it. Our guide to international data transfers under UK GDPR clears up the common myths.

Data protection and security go together

Keeping data lawful is only half the job — you also have to keep it secure. Strong passwords, multi-factor authentication, backups and staff awareness are what turn a policy into real protection. It is worth reading these alongside our hubs on cyber security, email security and managed IT, since a breach is both a security incident and a data protection one. Our cyber security services can help you put the right safeguards in place.

Where to start

If all this feels like a lot, that is normal — you do not have to fix everything at once. Get registered with the ICO, write an honest privacy notice, know how you would answer a SAR, and make sure your systems are secure. From there, work through the guides above at your own pace.

Want a hand getting the basics right? Book a free IT and security review and we will help you find the gaps and prioritise the fixes — in plain English, with no jargon and no pressure.

In this topic

30 guides in this topic

Guide

IT and Cyber Security for Charities and Non-Profits in the UK

A plain-English guide to IT and cyber security for UK charities: protecting donor and beneficiary data, controlling volunteer access, and Cyber Essentials on a tight budget.

Read →
Guide

IT & Cyber Security for Solicitors and Law Firms: A Plain-English Guide

A practical guide to IT security for UK law firms: client confidentiality, SRA-aligned controls, secure email and documents, DMARC, backups and staying compliant.

Read →
Guide

IT Support for Recruitment Agencies in the UK

A plain-English guide to IT and cyber security for UK recruitment agencies: protecting candidate data, securing your CRM/ATS, mobile working and stopping placement invoice fraud.

Read →
Guide

Cyber Essentials Explained: A Plain-English Guide for UK Small Businesses

What Cyber Essentials is, the five controls, CE vs CE Plus, why it wins contracts and helps insurance, and how a small UK business gets certified.

Read →
Guide

IT and Cyber Security for Financial Advisers in the UK

A practical guide to IT and cyber security for UK financial advisers and IFAs: meeting FCA expectations, protecting client financial data, secure email, backups and Cyber Essentials.

Read →
Guide

IT Security for Dental and Healthcare Practices: A Practical Guide

How UK dental and healthcare practices can protect patient data under UK GDPR and the NHS DSPT, keep clinical software running, back up safely and control access.

Read →
Guide

IT Support for Nurseries and Childcare Settings in the UK

Plain-English IT and cyber security guidance for UK nurseries: protect children's and safeguarding data, control access, manage retention, and reassure parents.

Read →
Article

AI Tools at Work: The Real Security Risk Nobody Mentions

Staff are already using ChatGPT and other AI tools at work. The real danger isn't the robots — it's confidential data being pasted into public tools. Here's a sensible approach.

Read →
Guide

IT Support for Care Homes in the UK: A Practical Security Guide

A plain-English guide to IT for UK care homes: protecting resident and staff data, CQC-aware information governance, reliable Wi-Fi and devices, and business continuity.

Read →
Article

How to Securely Dispose of Old Computers and Data

Selling or scrapping an old work computer? Here's how to wipe data properly, when to destroy the drive, and how to recycle old kit legally — in plain English.

Read →
Article

GDPR Basics for UK Small Businesses: A Plain-English Guide

A jargon-free guide to UK GDPR for small businesses: what personal data is, lawful basis, ICO registration and fee, your security duty, and handling breaches.

Read →
Article

How to Report a Data Breach to the ICO: The 72-Hour Rule Explained

When a data breach is reportable, how the ICO's 72-hour rule works, what to include in your report and when to tell affected individuals. Plain-English UK guide.

Read →
Article

Data Retention and Records of Processing: A Plain-English Guide for Small Businesses

How UK small businesses can handle data retention, ROPA and data minimisation under UK GDPR — in plain English, with practical steps you can start this week.

Read →
Article

Insider Threats for Small Business: The Risk From People You Already Trust

Understand accidental and malicious insider risk, and how least privilege, careful offboarding and sensible monitoring protect your small business.

Read →
Article

How to Write a Password Policy for a Small Business (the Sensible Way)

An NCSC-aligned password policy for UK small businesses: length over complexity, no pointless forced changes, MFA everywhere and a password manager. A plain template.

Read →
Article

Cyber Security for a Small Ecommerce Business

How to protect a small UK online store: securing your platform and plugins, safe payments, customer data under UK GDPR, spotting fraud, and backups that actually restore.

Read →
Guide

International Data Transfers Under UK GDPR, Explained

A plain-English guide to UK GDPR international data transfers for small businesses using US-hosted tools — mechanisms, the UK-US bridge, IDTA and TRAs.

Read →
Article

Do I Need a Data Protection Officer (DPO)?

Do you need a Data Protection Officer? When a DPO is legally required under UK GDPR — and what most UK small businesses actually need instead.

Read →
Article

ICO Fines and Enforcement: What Small Businesses Should Know

A plain-English guide to ICO enforcement for UK small businesses: reprimands vs fines, the real maximum penalties, and what actually triggers action.

Read →
Article

How to Handle a Subject Access Request (SAR)

What a subject access request is, the one-month deadline, how to respond step by step, and the common mistakes UK small businesses make with SARs.

Read →
Article

How to Write a Privacy Notice for a Small Business

What must a privacy notice include under UK GDPR? A plain-English structure for UK small businesses, the required content, and the common gaps to avoid.

Read →
Article

Lawful Basis for Processing Personal Data, Explained

The six lawful bases under UK GDPR in plain English for small businesses: how to choose one, and when to use consent versus legitimate interests.

Read →
Article

Cookies and PECR for UK Business Websites

Cookie consent and PECR basics for UK small businesses — what needs consent, how to build a compliant banner, and how to handle analytics lawfully.

Read →
Article

CCTV and GDPR: Using Cameras Lawfully in Your Business

How to use CCTV lawfully under UK GDPR: signage, a clear purpose, sensible retention, handling footage requests, and what the ICO expects of you.

Read →
Guide

Data Protection Impact Assessment (DPIA): A Simple Guide

What a DPIA is, when UK GDPR requires one, and how a small business can complete a simple, practical Data Protection Impact Assessment step by step.

Read →
Article

Third-Party and Supply-Chain Risk for Small Businesses

The suppliers and software you rely on can become your security problem. A plain-English guide to supply-chain risk for UK small firms, plus what to ask vendors.

Read →
Article

Email Marketing for Small Business: Getting Started the Right Way

How to build a mailing list properly under UK PECR rules, pick the right tool, and get your emails delivered. A plain-English guide for small businesses.

Read →
Article

Cyber Insurance for UK Small Businesses: What It Covers and How to Avoid a Denied Claim

What cyber insurance actually covers, why UK insurers now check for MFA and DMARC, what to put in place first, and the common reasons small-business claims get denied.

Read →
Article

Cyber Essentials vs Cyber Essentials Plus: Which One Does Your Business Need?

The plain-English difference between Cyber Essentials and Cyber Essentials Plus, which one you need, what the audit involves, the cost and effort, and the 2026 MFA change.

Read →
Article

The IT Support Checklist for UK Accountancy Practices

A practical IT and cyber-security checklist for UK accountants: protecting client data, staying online through tax season, and meeting Cyber Essentials.

Read →

Browse all resources →

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review — no jargon, no pressure.