If you hold customer emails, staff records, or a CRM full of contact details, UK GDPR applies to you — regardless of your size. The good news: for most small businesses, full compliance is a short, practical project, not a legal minefield. This guide walks through exactly what to do, in order, with no jargon and no scaremongering.
Does UK GDPR Apply to Your Small Business?
Direct answer: Yes, almost certainly. UK GDPR applies to any organisation that collects, stores, or uses personal data about identifiable individuals — customers, employees, or suppliers — regardless of turnover or headcount. There is no small business exemption from the law itself, only from certain administrative duties.
Personal data covers more than you might think: a customer’s name and email in your inbox, a supplier’s phone number in your CRM, CCTV footage outside your shop, or a spreadsheet of job applicants all count. If you decide why and how that data gets used, you’re a “data controller” under the law, and the rules apply.
UK GDPR vs. EU GDPR: What’s the Difference Post-Brexit?
Since 1 January 2021, the UK has run its own version of the law: UK GDPR, sitting alongside the Data Protection Act 2018. It’s built on the same foundations as EU GDPR but is a distinct legal regime, enforced by the UK’s Information Commissioner’s Office (ICO) rather than an EU body.
The practical differences that matter most to small businesses:
| Area | EU GDPR | UK GDPR |
|---|---|---|
| Regulator | National EU data protection authorities | Information Commissioner’s Office (ICO) |
| Governing legislation | EU Regulation 2016/679 | UK GDPR + Data Protection Act 2018 |
| International transfers | Standard Contractual Clauses (SCCs), EU adequacy decisions | UK International Data Transfer Agreement (IDTA), UK-US Data Bridge for transfers to certified US organisations |
| Maximum fine | €20 million or 4% of global turnover | £17.5 million or 4% of global turnover |
If you sell into the EU or hold data on EU residents, you may need to comply with both regimes at once — that’s a separate, more complex question worth getting specific advice on.
Does GDPR Apply to Sole Traders and Micro-Businesses?
Yes. A sole trader with one laptop and a client list is still a data controller. Size affects how much administrative burden you carry — smaller organisations get lighter record-keeping duties — but it doesn’t remove the obligation to handle data lawfully, securely, and transparently.
The Step-by-Step UK GDPR Compliance Checklist
Direct answer: A UK GDPR compliance checklist for small businesses covers eight core actions: mapping your data, documenting your lawful basis, writing a compliant privacy notice, registering with the ICO, securing contracts with vendors, handling access requests, locking down your security, and having a breach response plan ready before you need it.
Step 1: Conduct a Data Audit (Mapping Your Data)
Before you can protect data, you need to know where it lives. For a small business, this rarely means expensive software — it means an afternoon with a spreadsheet, listing:
- Customer records (CRM, order history, invoices)
- Email marketing lists
- Staff and payroll files
- Paper records — signed forms, filed invoices, sticky notes with phone numbers
- Cloud storage, shared drives, and old email inboxes
A one-person plumbing business might find data in a booking app, a WhatsApp thread, and a paper diary. An e-commerce store might find it spread across Shopify, a mailing list tool, and a spreadsheet of returns. Write down what you collect, where it sits, and who can access it — this becomes the backbone of everything else on this list. If you already keep structured records for tax purposes, you can build on that discipline rather than starting from scratch.
Step 2: Identify and Document Your Lawful Basis for Processing
You need a legal reason — a “lawful basis” — for every category of personal data you hold. The two most common for small businesses:
- Consent — the individual has actively agreed (needed for most marketing emails).
- Legitimate interests — you have a genuine business reason that doesn’t override the person’s rights (e.g. keeping a client’s details to deliver a service they’ve paid for).
Others include contractual necessity (fulfilling an order), legal obligation (payroll records for HMRC), and vital interests (rare, emergency situations). Write down which basis applies to each type of data you hold — this doesn’t need to be lengthy, just accurate and kept on file.
Step 3: Update or Create Your Privacy Notice
A privacy notice tells people what you do with their data. To be legally compliant, it must include:
- Who you are (business name and contact details)
- What data you collect and why
- Your lawful basis for each use
- Who you share data with (payment processors, delivery firms, email tools)
- How long you keep it
- The individual’s rights — access, correction, deletion, and how to complain to the ICO
Publish it on your website and link to it from any form that collects data. If you’re building or updating a site, this sits naturally alongside your standard website terms and conditions.
Step 4: Pay the ICO Data Protection Fee (Is Your Business Exempt?)
Most data controllers must register with the ICO and pay an annual fee. As of 2026, the fee has three tiers:
| Tier | Who it applies to | Annual fee | Fee by direct debit |
|---|---|---|---|
| Tier 1 | Turnover under £632,000 or 10 or fewer staff | £52 | £47 |
| Tier 2 | Turnover up to £36 million or up to 250 staff | £78 | £73 |
| Tier 3 | Above Tier 1 and 2 thresholds | £3,763 | £3,763 |
You only need to meet the turnover or the staff threshold, not both. A handful of narrow exemptions exist — for example, if you only process data for staff administration, or purely for marketing your own goods and services using name and address alone — but most trading businesses don’t qualify. Failing to pay when required can lead to a fixed penalty of up to £4,000, separate from your annual fee. Use the ICO’s free self-assessment tool before assuming you’re exempt; for a full breakdown of tiers and edge cases, see our ICO data protection fee guide, or start with the basics of ICO registration for small businesses.
Step 5: Put Data Processing Agreements (DPAs) in Place with Vendors
Any third party that processes personal data on your behalf — your email marketing platform, your accountant, your CRM provider, a cloud storage service — needs a Data Processing Agreement in place. Most established software vendors offer a standard DPA you can download or accept as part of their terms; you just need to check it exists and file it. If you’re choosing new tools, this is worth weighing up when comparing CRM platforms or email marketing software — reputable UK-focused providers make their DPA easy to find.
Step 6: Establish a Process for Subject Access Requests (SARs)
A Subject Access Request gives any individual the right to ask what personal data you hold about them and how you use it. You must respond within one calendar month of receiving the request (extendable by up to two further months for complex cases, with the individual told why). In practice, for a small business this usually means:
- Log the request the day it arrives — verbally or in writing both count.
- Search all locations from your Step 1 data audit.
- Redact any third-party personal data before sending.
- Respond free of charge, in a clear and accessible format.
Step 7: Secure Your Data (Cybersecurity Basics for SMBs)
GDPR requires “appropriate technical and organisational measures” — the law doesn’t mandate specific tools, but the basics for a small business are:
- Strong, unique passwords and two-factor authentication on email and admin accounts
- Encrypted laptops and devices, especially anything portable
- Access controls, so staff only see the data relevant to their role
- Regular software updates and reputable antivirus protection
- Secure, reputable cloud storage rather than personal devices or free consumer accounts
Many small businesses use Cyber Essentials certification as a structured way to prove these basics are in place, particularly if you tender for public sector or corporate contracts. For a broader view of the threat landscape, our guide to cybersecurity for small business covers common attack vectors worth defending against.
Step 8: Create a Data Breach Response Protocol
A breach isn’t just hacking — a misaddressed email with customer data attached, a lost laptop, or a lapsed permission setting all qualify. If a breach is likely to risk someone’s rights or freedoms, you must notify the ICO within 72 hours of becoming aware of it. If the risk is high, you must also tell the affected individuals directly, without undue delay.
Having a simple one-page protocol ready — who to call, what to check, how to log it — turns a 72-hour deadline from a panic into a checklist. Waiting until a breach happens to figure this out is the single most common mistake small businesses make.
Key Areas of Confusion for UK Small Businesses
Do I Need a Data Protection Officer (DPO)?
Direct answer: Most small businesses do not need to formally appoint a Data Protection Officer. A DPO is only a legal requirement if you’re a public authority, or your core activities involve large-scale, regular and systematic monitoring of individuals, or large-scale processing of special category data (health, biometric, ethnicity, and similar sensitive categories). A small retailer, tradesperson, or consultancy typically falls well outside these thresholds — though someone in the business should still be the named point of contact for data protection questions.
What is the Rule for Cold Emailing and Marketing (PECR)?
This is where most small businesses trip up, because GDPR and PECR (the Privacy and Electronic Communications Regulations) are separate rulebooks that overlap. GDPR governs how you handle data; PECR governs how you’re allowed to contact people electronically.
- B2C marketing emails generally need prior consent — an opt-in checkbox, not a pre-ticked box.
- B2B marketing to corporate email addresses (not personal ones) has more flexibility, though individual recipients can still opt out.
- Soft opt-in lets you email existing customers about similar products or services without fresh consent, provided you gave them a clear chance to opt out when you first collected their details, and every email after that includes an easy unsubscribe option.
- Cold emailing individuals with no prior relationship and no consent is generally not compliant under PECR, even if the data itself was gathered lawfully under GDPR.
Get this wrong and the ICO can act on PECR breaches independently of any GDPR issue — it’s a common blind spot in outbound sales.
Common Mistakes and Compliance Risks Worth Knowing
A few patterns show up again and again in small business GDPR failures, and most are avoidable:
- Assuming “we’re too small to matter.” The ICO regularly takes action against sole traders and micro-businesses, particularly around unpaid fees and unlawful marketing.
- Treating the privacy policy as a copy-paste job. A generic template that doesn’t reflect what you actually collect isn’t compliant — it just looks compliant until someone checks.
- No paper trail for consent. If you can’t show when and how someone opted in, you can’t defend a complaint.
- Forgetting old data. Spreadsheets from three years ago, held “just in case,” are still your legal responsibility and still need a lawful basis and a retention limit.
- Confusing GDPR compliance with cyber insurance. Having insurance doesn’t satisfy your legal obligations, and a breach caused by known negligence can affect a claim.
Free Tools and Resources for UK Small Businesses
- ICO Self-Assessment Tool — confirms whether you need to pay the data protection fee.
- ICO Interactive Signpost — a short questionnaire pointing you to relevant ICO guidance for your situation.
- Data Protection Fee Calculator — works out your exact tier based on turnover and staff numbers.
For businesses that want ongoing support rather than a one-off checklist, it’s worth comparing dedicated GDPR compliance tools for small businesses, which can automate privacy notices, consent logs, and SAR tracking as you grow.
What’s Changing: Future Regulatory Developments to Watch
UK data protection law is not frozen. The Data (Use and Access) Act, which received Royal Assent in 2025, is gradually introducing reforms — including simplified rules for some automated decision-making and adjustments to cookie consent requirements for low-risk analytics. None of this removes the core obligations in this checklist, but small businesses should expect incremental updates to ICO guidance over the next year rather than a one-off event. Checking the ICO’s website periodically, rather than relying on a single article, is the safest habit to build.
Summary FAQ
Do sole traders need to register with the ICO?
Yes, in most cases. If you’re a sole trader processing personal data as a controller — holding client records, running a mailing list, or using CCTV — you need to register and pay the relevant fee unless a specific exemption applies.
How much is the ICO registration fee for a small business?
Most small businesses fall into Tier 1 (£52, or £47 by direct debit) or Tier 2 (£78, or £73 by direct debit), depending on turnover and staff numbers.
How long do you have to report a data breach to the ICO?
72 hours from becoming aware of a breach that’s likely to risk someone’s rights or freedoms.
Do small businesses need a Data Protection Officer?
Only if you’re a public authority or carry out large-scale monitoring or large-scale processing of special category data — most small businesses don’t meet this threshold.
Can I still send marketing emails under UK GDPR?
Yes, but PECR governs the rules separately from GDPR. You generally need consent for consumer marketing emails, though a “soft opt-in” exception applies for existing customers under specific conditions.
How long do I have to respond to a Subject Access Request?
One calendar month from receiving the request, extendable by up to two more months for complex requests.
—
This guide provides general information and does not constitute legal advice. For complex situations — international data transfers, special category data, or public sector work — consult a data protection specialist.






