Data Protection Basics for SMEs
Almost every UK business handles personal data — whether collecting customer email addresses, managing employee records, or running a mailing list. UK GDPR and the Data Protection Act 2018 impose legal obligations on all organisations that handle personal data, regardless of size.
Important
Key points
- Most businesses that process personal data must register with the ICO and pay an annual data protection fee (from £40 per year).
- UK GDPR requires you to have a lawful basis for every type of personal data processing.
- You must tell people what you are doing with their data — typically through a privacy notice on your website.
- Data breaches that are likely to result in a risk to individuals must be reported to the ICO within 72 hours.
- Individuals have rights over their data, including the right to access, rectify, and erase it.
- Fines for serious UK GDPR breaches can reach £17.5 million or 4% of global annual turnover.
The Six UK GDPR Principles
UK GDPR is built around six core data protection principles. Every business handling personal data must ensure their processing complies with all six:
- Lawfulness, fairness and transparency: You must have a lawful basis for processing; you must be open about what you do with data
- Purpose limitation: Collect data for specific, explicit and legitimate purposes — and do not use it for something incompatible with those purposes
- Data minimisation: Only collect data you actually need — do not gather information "just in case"
- Accuracy: Keep personal data accurate and up to date; correct inaccuracies promptly
- Storage limitation: Do not keep personal data longer than necessary — define and apply retention periods
- Integrity and confidentiality (security): Protect personal data against unauthorised access, loss, or destruction using appropriate technical and organisational measures
A seventh principle — accountability — requires you to be able to demonstrate compliance. This is why documentation such as privacy notices, processing records, and data protection policies matter.
Lawful Bases for Processing
Before you can process personal data, you need a lawful basis. UK GDPR provides six lawful bases:
- Consent: The individual has given clear, freely given, specific, informed consent. Consent must be documented and easy to withdraw.
- Contract: Processing is necessary to perform a contract with the individual, or to take steps before entering a contract.
- Legal obligation: Processing is required to comply with a legal duty (e.g. payroll records for HMRC).
- Vital interests: Protecting someone's life — rarely used in business contexts.
- Public task: Mainly relevant to public authorities.
- Legitimate interests: Processing is necessary for your legitimate interests (or those of a third party), balanced against the rights of the individual. A common basis for business-to-business marketing and fraud prevention.
For special category data (health, race, religion, sexual orientation, trade union membership, biometrics, criminal records), you need both a lawful basis and an additional condition. Most businesses use the "employment law obligations" condition for health data about employees.
Individual Rights You Must Respect
UK GDPR grants individuals a number of rights over their personal data. As a business, you must be able to respond to these rights requests within one month:
- Right of access (Subject Access Request): The right to receive a copy of all personal data held about them, free of charge
- Right to rectification: Correct inaccurate or incomplete personal data
- Right to erasure ("right to be forgotten"): In certain circumstances, delete personal data — though this is not an absolute right
- Right to restrict processing: Pause processing in certain circumstances while a dispute is resolved
- Right to data portability: Receive data in a portable format (applies mainly to automated processing based on consent or contract)
- Right to object: Object to processing based on legitimate interests or for direct marketing — direct marketing objections must always be honoured
You should have a clear process for receiving and responding to data rights requests. Document each request and your response.
Data Breaches and Reporting Obligations
A personal data breach is any event that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. Examples include:
- Sending an email containing personal data to the wrong recipient
- A cyberattack resulting in customer data being stolen
- A laptop containing unencrypted personal data being stolen
- Accidentally deleting important records
Not every breach needs to be reported to the ICO. You must report a breach within 72 hours only if it is likely to result in a risk to individuals' rights and freedoms. If the risk is high, you must also notify the affected individuals without undue delay.
You must keep a record of all data breaches — even those that do not need to be reported to the ICO. This internal breach log should describe what happened, the data involved, the impact, and the remedial action taken. The ICO can request to see it during an investigation.
Frequently asked questions
Do I need to register with the ICO?
Can I send marketing emails to customers without consent?
A customer has asked me to delete their data. Do I have to?
I use a third party to process data (e.g. a cloud provider or email marketing platform). Do I need a contract with them?
Do you need to register with the ICO?
What is a Data Protection Impact Assessment?
What to do next
- 1
- 2
- 3
- 4
Official bodies and resources
Information Commissioner's Office
RegulatorThe UK's independent authority for data protection and information rights, enforcing the UK GDPR and Data Protection Act 2018.
Was this page helpful?
Related guides
Privacy Policy and Cookies
If your business has a website that collects any personal data — including via analytics, contact forms, or simply cookies — you need compliant privacy and cookie notices. Getting these wrong can attract ICO enforcement and damage customer trust.
5 min
Employment Records for Small Businesses
Once you employ someone, you take on a range of record-keeping obligations. Proper employment records protect you in disputes, ensure you meet HMRC requirements, and demonstrate compliance with data protection law.
5 min
Business Record Keeping
Keeping good business records is both a legal requirement and essential for running your business effectively. HMRC can inspect your records for up to six years — and poor records can result in tax investigations, penalties, and unnecessary stress.
5 min
Data Breach Complaints
A data breach occurs when your personal information is accessed, disclosed, lost, or stolen in a way that was not authorised. Whether the breach involved your financial details, health records, or contact information, you have rights under UK GDPR and the Data Protection Act 2018 — including the right to complain to the Information Commissioner's Office (ICO) and to claim compensation.
5 min
Disclaimer