The general data protection regulation is still UK law, even though we left the EU. It got copied into UK law as the “UK GDPR” and sits alongside the Data Protection Act 2018. If you handle anyone’s personal information, whether that’s customer details, employee records, or a mailing list, this applies to you. Not just to big companies with legal teams. Small businesses get caught out by this more than most, usually because someone assumes GDPR was an EU thing that stopped mattering after Brexit. It didn’t.

What follows is a practical look at what actually needs doing, rather than the theory you’ll find in most compliance guides.

Working Out What Personal Data You Actually Hold

Start here, before anything else. Personal data means any information that identifies a living person, so names, email addresses, phone numbers, IP addresses, and even things like a photo or a CCTV recording. Most businesses have more of this scattered around than they think. Spreadsheets on someone’s desktop, old CRM exports, a folder of CVs from three years ago that nobody’s deleted.

Do an honest audit. Where does personal data come in (website forms, email, phone calls), where does it live (which systems, which folders), and who can get at it. You can’t protect what you haven’t mapped, and you can’t answer a subject access request quickly if you don’t know where the data is sat.

Getting a Lawful Basis for Everything You Do With Data

Under the general data protection regulation, you need a legal reason to process personal data, and there are six of them. Consent is the one most people default to, but it’s often the wrong choice because consent has to be freely given and easy to withdraw. For most business processing, “legitimate interests” or “contract” fit better. If you’re emailing a customer to confirm an order, that’s contract. If you’re sending marketing emails to people who’ve never bought from you, you need a proper consent mechanism, not a pre-ticked box.

Write down which basis applies to each type of processing you do. It’s a small piece of admin, but it’s exactly what you’ll be asked for if the Information Commissioner’s Office (ICO’s guide to lawful basis) ever comes knocking, and it forces you to actually think about whether you should be collecting something in the first place.

Understanding the ICO’s Role Before You Need To

The ICO is the UK’s data protection regulator, and it’s worth knowing what it does and doesn’t do before you’re dealing with it under pressure. Most businesses only think about the ICO when something’s gone wrong, a data breach, a complaint from a customer, an angry email about unwanted marketing. By that point you’re reacting rather than preparing.

It’s worth reading through what the ICO actually is and what it can do before you need to deal with them directly. Most businesses also need to pay the ICO’s data protection fee annually, based on size and turnover, and it’s a separate requirement from GDPR compliance itself, so don’t assume one covers the other.

Building Breach Response Into Your Plans, Not Just Your Policy Document

If personal data is lost, stolen, or exposed, you may have 72 hours to report it to the ICO, depending on the risk to the people affected. Seventy-two hours sounds like plenty of time until you’re trying to work out what happened, who’s affected, and what to say, all at once, usually with no clear process in place.

Write the plan before you need it. Who makes the call on whether to report. Who talks to affected customers. Who documents what happened, because you need to keep records even for breaches you decide not to report. A one-page plan that everyone’s read beats a detailed policy nobody’s looked at since it was written.

Making Data Protection Practical for Small Businesses

Full compliance with the general data protection regulation isn’t about hiring a data protection officer or building an enterprise-grade compliance programme if you’re a ten-person business. It’s about proportionate, sensible steps: knowing what data you hold, only keeping what you need, having a basic privacy notice on your website, and making sure staff understand not to email customer spreadsheets to their personal accounts.

There’s a fuller breakdown of what this looks like in practice over on the guide to GDPR compliance for UK small businesses, including the specific documents and processes worth having in place. Most of the risk in this area comes from ordinary carelessness rather than anything sophisticated, so the fixes tend to be ordinary too.

Keeping Compliance Alive Rather Than Filed Away

The businesses that struggle with GDPR tend to be the ones that did a big push once, wrote some policies, and then never looked at them again. Data protection isn’t a project with an end date, it’s an ongoing habit. New tools get adopted, new staff join, new types of data start getting collected, and the compliance work needs to keep pace.

Set a date every six months to review what’s changed. New software you’re using, new data you’re collecting, whether your privacy notice still matches what you actually do. It takes an afternoon and it’s a lot cheaper than finding out the gap existed after something’s gone wrong.

If you’re not sure where your business stands on data protection, the practical guide to GDPR compliance for UK small businesses is a good place to start.