Data protection duties for small businesses

Data protection duties for small businesses

Yes, this applies to you too

Plenty of small business owners assume data protection is a problem for banks and tech giants, not for a five-person firm in a converted barn. That isn't the case. UK GDPR applies to any organisation that processes personal data, from a sole trader with a mailing list to a shop with a staff rota and a CCTV camera. If you hold names, contact details, payroll records or customer order histories, you are a data controller and the duties apply to you.

The reassuring part is that the law is scalable. Nobody expects a small firm to employ a data protection officer or match a corporate security budget. What's expected is that you know what you hold, understand why you hold it, keep it secure, and can answer people who ask questions about it. Start with one practical check: whether you need to pay the ICO's annual data protection fee. Many small businesses are exempt if they only process personal data for core purposes such as staff administration, accounts and advertising, but plenty are not, and the entry fee is £40 a year.

Know what you hold, and why

You cannot protect what you have never mapped. Set aside an afternoon and write down, for each category of personal data you hold: where it came from, where it lives, who you share it with, how long you keep it, and the lawful basis for processing it. Most small businesses rely on a handful of bases — contract for fulfilling orders and employing staff, legal obligation for tax and payroll records, and legitimate interests for things like fraud prevention. Consent is only one option and is often the wrong one, because it can be withdrawn at any time.

Special category data — health information, ethnicity, religion, sexual orientation, biometrics — needs extra care and an additional condition before you can process it. Keep a short, plain-English privacy notice on your website covering what you collect, why, how long you keep it, who receives it, and how someone can complain. If you use suppliers who handle data on your behalf, such as payroll providers, cloud accounting software or IT support, you need a written processing agreement with each of them.

Answering a subject access request

Anyone can ask to see the personal data you hold about them, and it is easier to make such a request than many people realise. It does not have to be in writing, does not have to mention data protection law, and can be made to any member of staff. "Can I see everything you've got on me?" is enough to trigger your obligations.

  • Recognise it and log the date. Train staff to pass anything like this to one named person straight away.
  • Verify identity if you have genuine doubts. It is reasonable to ask for ID when a request arrives from an unfamiliar email address.
  • Respond within one month. You can extend by up to two further months for complex requests, but you must explain why inside the first month.
  • Search properly. Emails, spreadsheets, CRM records, backups, handwritten notes and messages all count.
  • Redact other people's data and anything covered by an exemption, such as legally privileged advice.
  • Do not charge a fee unless the request is manifestly unfounded or excessive, and do not refuse one without solid grounds.

The everyday duties that slip

Beyond requests, a few habits keep you on the right side of the law. Decide retention periods and actually delete or anonymise data when they pass, rather than keeping it forever "just in case". Correct inaccurate records promptly. Limit access so that only the people who need a file can open it, use two-factor authentication, encrypt laptops and phones, and have a plan for when a device is lost. If you transfer personal data outside the UK, check there is a valid safeguard in place, such as UK adequacy regulations or an international data transfer agreement. And if you launch a project involving risky processing — large-scale profiling, for instance — carry out a data protection impact assessment first.

When something goes wrong

A personal data breach is any security incident involving accidental or unlawful loss, destruction, alteration or unauthorised disclosure of personal data. A mis-addressed email, a stolen laptop and a ransomware attack all qualify. If the breach is likely to risk people's rights and freedoms, you must report it to the ICO within 72 hours of becoming aware of it. You do not need every detail to hand — report what you know and update it as the picture becomes clearer. Where the risk to individuals is high, for example where bank details or passwords are exposed, you must also tell those affected without undue delay, in clear language.

Keep an internal record of every breach, including the ones you decide not to report, noting what happened, the likely consequences and the action taken. Regulators can and do ask to see that log. Hiding a problem almost always makes it worse.

Making it manageable

You do not need a thick manual. A one-page data map, an honest privacy notice, a retention schedule, a short breach procedure and staff who know to escalate requests and incidents will cover the vast majority of what a small business faces. Review it once a year, or whenever you change systems or suppliers. If a decision feels genuinely difficult, the ICO publishes free guidance and runs a helpline, and a solicitor who specialises in data protection can help you make the call. A short conversation now is nearly always cheaper than untangling the consequences later.