UK GDPR for Small Businesses: Data Protection, Breaches and Records
Two things changed recently. The Data (Use and Access) Act 2025 updated UK data protection law, and all of its data protection changes were in force by 19 June 2026. And on 30 September 2026 the Information Commissioner’s Office became the Information Commission. The government says the regulator’s role, responsibilities and powers haven’t changed. It still calls itself the ICO, so this guide does too, and its guidance is still at ico.org.uk.
This guide explains what all of that means for a small business, in the order you’re likely to need it. It isn’t legal advice: for a specific situation, check the regulator’s guidance or speak to a data protection specialist.
Does UK GDPR apply to your business?
Almost certainly. UK GDPR covers “personal data”: anything that identifies a living person, directly or indirectly. Customer records, staff files, CCTV, email addresses with names in them and notes about a client’s affairs all count. It applies whatever your size, and to sole traders as well as companies.
A few duties are lighter for smaller organisations, and some are only triggered by particular kinds of processing. But the principles apply to everyone: use personal data lawfully, fairly and transparently, for a clear purpose, keep only what you need, keep it accurate, don’t keep it longer than necessary, and keep it secure.
Pay the data protection fee (unless you’re exempt)
Most organisations that use personal data have to pay the regulator an annual data protection fee. There are three tiers:
| Tier | Who | Fee |
|---|---|---|
| 1 | Turnover up to £632,000, or no more than 10 staff | £52 |
| 2 | Turnover up to £36 million, or no more than 250 staff | £78 |
| 3 | Everyone else | £3,763 |
Paying by direct debit takes £5 off. Some organisations are exempt, for example if you only use personal data for staff administration, your own accounts and records, or advertising your own goods and services. An exemption from the fee isn’t an exemption from the law: every other duty in this guide still applies.
Have a lawful basis for what you do
You need a lawful basis for each thing you do with personal data. The Data (Use and Access) Act added a seventh, recognised legitimate interests, so there are now seven:
- Contract: you need the data to provide what someone has asked for, such as delivering an order or doing their tax return.
- Legal obligation: the law requires it, such as keeping payroll records or carrying out anti-money laundering checks.
- Legitimate interests: you have a genuine reason, the processing is necessary for it, and it doesn’t override the person’s interests. The Act confirms that direct marketing and keeping your network secure can be legitimate interests, though you still have to weigh them up.
- Recognised legitimate interests: new, and narrow. A fixed list of purposes, such as preventing crime, safeguarding a vulnerable person or responding to an emergency, where you don’t need to do the balancing test.
- Consent: the person has freely agreed. Useful for some marketing, but easy to get wrong and easy to withdraw.
- Vital interests and public task: rarely relevant to a small business.
You’ll probably rely mainly on contract, legal obligation and legitimate interests. Write down which basis you use for each main activity, and say so in your privacy notice.
Know what you hold, and keep it only as long as you need it
You can’t protect, update or delete data you don’t know you have. Start with a simple list: what personal data you hold, where it lives (Microsoft 365, your case or accounts software, paper files, a payroll provider), who can open it, who you share it with and how long you keep it.
Organisations with fewer than 250 employees don’t have to keep full records of processing for everything, but they do for processing that isn’t occasional, could put people at risk, or involves special category data (such as health) or criminal offence data. Your core activities probably aren’t occasional, so a short written record is the safe choice. The regulator has basic templates.
The law doesn’t set fixed retention periods. It says personal data should be kept no longer than necessary. Where other rules set a period, such as tax records or a professional body’s file retention rules, follow those. For everything else, decide a period, write it down and delete things when it ends. Start with old mailboxes and forgotten shared folders.
From our work
Many of our clients are in regulated sectors, such as property, legal and accountancy, so records matter beyond UK GDPR. Their insurers ask for cyber security declarations, and their ISO 9001 and ISO 27001 audits ask for proof of records and disaster recovery testing. We prepare that evidence and complete it with the client’s final approval, so audits go quickly.
David Gilbey, Just Gilbey IT Solutions
Keep personal data secure
UK GDPR requires “appropriate technical and organisational measures” to protect personal data. It doesn’t list them, because what’s appropriate depends on the data and the risk. The regulator describes Cyber Essentials as a good starting point, while making clear it’s only a base set of controls.
For a small business, appropriate means at least:
- multi-factor authentication on email and every cloud service
- devices that are encrypted, updated and protected against malware
- access limited to the people who need it, and removed when they leave
- backups that are tested, so you can restore data as well as protect it
- staff who know how to spot phishing and what to do if they make a mistake
When the regulator fined DPP Law £60,000 in April 2025, it found that attackers had got in through an administrator account without multi-factor authentication, and that the firm took 43 days to report the breach. Simple mistakes count too: the regulator says sending bulk emails with every address visible, instead of in BCC, is one of the top data breaches reported to it every year.
Our guide to cyber security for small businesses covers these controls in more detail, and our guide to phishing and email scams covers the most common way in.
When something goes wrong: personal data breaches
A personal data breach is any security incident that affects personal data: data lost, stolen, sent to the wrong person, altered, or unavailable because of ransomware. The rule hasn’t changed with the new Act. If a breach is likely to result in a risk to people, you must report it to the ICO without undue delay, and where feasible within 72 hours of becoming aware of it. If the risk to people is high, you also have to tell them directly, without undue delay. And you must record every breach in your own log, including the ones you decide not to report, with what happened, its effects and what you did.
Reporting is done through the regulator’s online form, which has a self-assessment tool to help you decide whether to report. The regulator’s advice is to report early and update later, rather than wait until you know everything.
Data breach: your 72 hours
The clock starts when you become aware of the breach.
- Straight away: Contain it. Recall or ask for the deletion of a misdirected email, reset passwords, disconnect an affected device.
- Same day: Find out what happened. Which data, whose, how many people, and whether it’s lost, seen, changed or locked by ransomware.
- Assess the risk: Could it harm people? Think identity fraud, financial loss, distress or discrimination. The regulator’s self-assessment tool helps.
- Within 72 hours: Report it if there’s a risk. Use the ICO’s online form (the ICO is formally the Information Commission). Report early, and update later if you need to.
- If the risk is high: Tell the people affected. Directly and without undue delay, in plain language, with what they should do.
- Always: Log it. Record every breach, reported or not: what happened, its effects and what you did.
Not sure whether to report? Ask yourself whether anyone could be harmed, and write down why you decided.
If you’ve been told your details were caught up in someone else’s breach, our post on what to do when you’re told your data was breached covers that side.
Requests from individuals, and complaints
People have the right to a copy of their personal data (a subject access request), and to have it corrected or, in some cases, deleted. You have one calendar month to respond, which you can extend by two months for complex requests. It’s normally free.
The Data (Use and Access) Act made two practical changes. You only have to make reasonable and proportionate searches, rather than search every corner of every system. And if you genuinely need to clarify what someone is asking for, the clock stops while you wait for their answer.
The newest duty is about complaints. Since 19 June 2026, you must give people a way to complain to you about how you use their personal data, such as a form on your website. You must acknowledge a complaint within 30 days, deal with it without undue delay and tell the person the outcome. A short paragraph in your privacy notice and an email address that someone checks is a good start.
Cookies and marketing
Two changes affect your website and your marketing.
Cookies. You no longer need consent for cookies used only to collect statistics to improve your website, or to remember someone’s preferences for how it looks or works, as long as you tell people clearly and give them a simple, free way to object. Cookies used for advertising still need consent.
Marketing. Fines under the electronic marketing rules can now reach £17.5 million or 4% of global turnover, whichever is higher, the same as UK GDPR. The rules on business-to-business marketing haven’t changed: you can email companies and LLPs without consent as long as you identify yourself and offer an opt-out, but sole traders and some partnerships are treated like individuals, and UK GDPR still applies to the named person you’re emailing.
Suppliers, cloud services and data abroad
You probably use suppliers who handle personal data for you: Microsoft 365, a payroll bureau, case or accounts software, an IT provider. Where a supplier processes personal data on your behalf, UK GDPR requires a written contract with specific terms. For the big cloud providers, those terms are in their standard data protection agreement; for smaller suppliers, ask.
If data goes outside the UK, the new “data protection test” asks whether protection abroad is “not materially lower” than in the UK. Our post on cloud compliance for UK businesses explains transfers and the UK–US data bridge, and our checklist for vetting third-party apps covers what to ask a new supplier.
Do you need a data protection officer?
Usually not. You must appoint a data protection officer if you’re a public authority, or if your core activities involve large-scale, regular and systematic monitoring of people, or large-scale use of special category or criminal offence data. A typical small business doesn’t meet those tests.
You still need someone who owns data protection: who keeps the records, handles requests and complaints, and decides whether a breach is reported. In a small business that’s often a director or the office manager, with help from whoever looks after the IT.
AI tools and personal data
Putting client or staff details into an AI tool is processing personal data, and the same rules apply. Free and personal AI tools carry the most risk, because they may keep what you type. Our guide to using AI safely at work covers what’s safe to put into which tools, and our post on writing an AI policy has a starting point for your staff rules.
A short checklist
If you do nothing else this month:
- Check whether you’ve paid the data protection fee, or confirm you’re exempt.
- Write a one-page list of the personal data you hold, where it is and how long you keep it.
- Make sure multi-factor authentication is on for email and every cloud service.
- Agree who decides whether a breach is reported, and print the 72-hour checklist above.
- Add a line to your privacy notice explaining how people can complain to you.
Our 2026 UK privacy checklist goes into the Data (Use and Access) Act changes in more detail, and our post on writing an IT compliance policy covers the policies that sit behind all of this.
Questions people ask
Does UK GDPR apply to a small business?
Almost certainly. It applies to any organisation that uses personal data, whatever its size, and that includes sole traders. If you hold names, email addresses, phone numbers or staff records, it applies to you. Some duties are lighter for organisations with fewer than 250 employees, such as keeping records of processing, but the principles are the same.
Do we have to pay the data protection fee?
Most organisations that use personal data do, unless they only use it for exempt purposes such as staff administration, their own accounts and records, or advertising their own goods and services. For a micro organisation (turnover up to £632,000 or no more than 10 staff) the fee is £52 a year, or £47 by direct debit. Exempt organisations still have every other data protection duty.
How long do we have to report a data breach?
If a personal data breach is likely to result in a risk to people, you must report it to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. If the risk is high, you also have to tell the people affected without undue delay. Every breach goes in your own breach log, reported or not.
Do we need a data protection officer?
Usually not. You must appoint one if you’re a public authority, or if your core activities involve large-scale, regular and systematic monitoring of people, or large-scale processing of special category or criminal offence data. A typical small business doesn’t meet those tests, though someone should still own data protection.
Is the ICO still the regulator?
The Information Commission took over from the Information Commissioner’s Office on 30 September 2026. It’s run by a board rather than a single commissioner, but the government says its role, responsibilities and powers haven’t changed. It still uses the name ICO and the website ico.org.uk.
What did the Data (Use and Access) Act change for small businesses?
The main changes: a new lawful basis called recognised legitimate interests, subject access searches that only have to be reasonable and proportionate, fewer consent requirements for analytics and functional cookies, higher fines under the marketing rules, and a duty to handle data protection complaints yourself first. All the data protection changes were in force by 19 June 2026.
Sources
- GOV.UK: Information Commission succeeds the ICO as UK’s data protection regulator (30 September 2026)
- ICO: The Data (Use and Access) Act 2025
- ICO: The DUAA, summary of the changes to data protection
- Legislation.gov.uk: The Data (Use and Access) Act 2025 (Commencement No. 6) Regulations 2026
- ICO: The data protection fee
- ICO: Data protection fee exemptions
- ICO: A guide to lawful basis (updated 2 April 2026)
- ICO: Documentation (records of processing)
- ICO: Storage limitation
- ICO: A guide to data security
- ICO: Personal data breaches, a guide
- ICO: Report a breach
- ICO: Responding to a subject access request (updated 8 December 2025)
- ICO: New data protection complaints law now in force (23 June 2026)
- ICO: Statement on the commencement of the DUAA (5 February 2026)
- ICO: Business-to-business marketing
- ICO: Data protection officers
- ICO: Law firm fined £60,000 following cyber attack (16 April 2025)
- ICO: Guidance on sending bulk communications by email
- Legislation.gov.uk: Data (Use and Access) Act 2025, Schedule 7 (transfers abroad)
- Legislation.gov.uk: Data (Use and Access) Act 2025, Schedule 12 (cookies)