A practical guide to UK GDPR compliance for small and growing businesses

Close-up of Union Jack flags decorating a London street on a sunny day

The UK General Data Protection Regulation, usually known as the UK GDPR, can feel like a difficult place to start. There are legal terms to understand, documents to prepare, supplier arrangements to review and security measures to consider.

For a small or growing business, the hardest part is often working out which requirements apply and what a reasonable first action looks like. Many businesses collect personal information through their websites, email accounts, accounting systems, customer platforms and cloud services, but have never had a clear view of how all that information moves through the business.

A practical approach begins with understanding the personal data your business handles, why you use it, where it goes and how it is protected. Once that foundation is clear, the individual requirements of UK data protection law become easier to organise and address.

This article provides general information and should not be treated as legal advice. Businesses should seek specialist legal advice where the application or interpretation of UK data protection law is uncertain.

What the UK GDPR covers

The UK GDPR governs how organisations collect, use, store, share and protect personal data. It also gives individuals rights over information that relates to them.

It works alongside the Data Protection Act 2018, which supplements the UK GDPR and provides additional rules, exemptions and enforcement provisions. Electronic marketing, cookies and similar technologies may also be covered by the Privacy and Electronic Communications Regulations, usually known as PECR.

The Data (Use and Access) Act 2025 has made a number of changes to the UK’s data protection framework. All of its data protection provisions were in force by 19 June 2026. Many of the changes clarify or provide flexibility around existing requirements, while others create new responsibilities, including a requirement for organisations to operate a data protection complaints process.

Personal data is information relating to an identified or identifiable living person. This can include obvious information such as a name, email address or telephone number, along with information such as an IP address, device identifier, account history or location data.

In a small business, personal data may be found in:

  • Customer and prospect records.
  • Employee and contractor files.
  • Email accounts and shared mailboxes.
  • Accounting, payroll and payment systems.
  • Website forms and analytics platforms.
  • Marketing and newsletter systems.
  • Support tickets and project management tools.
  • Cloud storage and shared documents.
  • Security logs and access records.

The UK GDPR applies to controllers and processors. A controller decides why and how personal data is used, while a processor handles personal data on behalf of a controller. Both can have direct legal obligations, although their responsibilities are different.

The law can apply to small businesses as well as large organisations. The amount of work involved should reflect the nature of the business, the information being handled and the risks the processing creates for individuals.

Does the UK GDPR apply to businesses outside the UK?

A business does not have to be located in the United Kingdom for the UK GDPR to apply.

A business based in Australia, New Zealand, the European Union, the United States or another country may come within its scope when it:

  • Has an establishment in the UK and processes personal data in connection with that establishment’s activities.
  • Offers goods or services to people located in the UK.
  • Monitors the behaviour of people located in the UK.

Where a business has a UK establishment, the UK GDPR can apply to processing connected with that establishment even when the personal data is handled elsewhere. Where there is no UK establishment, the overseas business is generally brought within scope through activities directed towards people in the UK.

The important wording is people located in the UK, rather than UK citizens.

The individual must generally be physically present in the UK when the relevant offering or monitoring takes place. They may be a UK resident, a visitor or a citizen of another country. A UK citizen living in Australia is not automatically protected by the UK GDPR simply because of their citizenship.

For example, an Australian software company that actively promotes subscriptions to UK businesses, lists prices in pounds and provides support arrangements for UK customers may be offering services to people in the UK.

An Australian consultancy with a locally focused website does not necessarily fall within the UK GDPR simply because someone in the UK can access the site or makes an incidental enquiry. There must usually be evidence that the business intends to target customers in the UK.

Indicators of UK targeting can include:

  • Running a marketing campaign directed at the UK.
  • Using a .co.uk domain.
  • Listing prices in pounds sterling.
  • Publishing testimonials from UK customers.
  • Providing delivery arrangements specifically for the UK.
  • Offering UK contact details or customer support.
  • Paying for search advertising directed at people in the UK.

One indicator may be enough in some circumstances, but the overall activities and intentions of the organisation must be considered. Website accessibility on its own is not usually sufficient.

Monitoring can include collecting information about a person’s behaviour with the intention of analysing it, building a profile or making decisions about them. This may include some forms of online tracking, behavioural advertising, location monitoring and profiling. Simply identifying that someone visited a website does not necessarily amount to monitoring in every situation.

An overseas organisation that falls within the UK GDPR because it offers goods or services to people in the UK or monitors their behaviour will generally need to appoint a representative in the UK. An exception may apply to public authorities and to occasional processing that is low risk and does not involve large-scale use of sensitive information or criminal records.

The UK representative acts as a local point of contact for individuals and the Information Commissioner’s Office, usually known as the ICO.

Where the territorial position is unclear, legal advice is worthwhile. Establishing whether the UK GDPR applies is a sensible first step before building a wider compliance program.

The UK GDPR and EU GDPR are separate regimes

The UK GDPR developed from the EU GDPR, and many of their principles and requirements remain similar. They are now separate legal regimes, however, and are enforced by different regulators.

A business may be subject to:

  • The UK GDPR because it operates in the UK or targets people there.
  • The EU GDPR because it operates in the European Economic Area or targets people there.
  • Both regimes because it serves people in the UK and the EEA.

For example, an Australian online business actively selling to customers in both the UK and France may need to consider both laws. Depending on its operations, it may also require a representative in the UK and a separate representative in the EEA.

The European Commission renewed its adequacy decision for the UK in December 2025. The UK also has adequacy regulations covering the EEA. These arrangements allow personal data to flow between the UK and EEA without a separate transfer safeguard being required for that particular transfer.

This does not mean compliance with one regime automatically satisfies every requirement of the other. Privacy notices, representative details, contracts, data transfer arrangements and regulatory responsibilities should reflect which laws apply.

Start by understanding the personal data you hold

A clear picture of your data is the foundation for most UK GDPR work.

Without that picture, it is difficult to write an accurate privacy notice, establish suitable retention periods, respond to someone requesting their information or understand the effect of a data breach.

A sensible first action is to create a simple data inventory. For each important business activity, record:

  • What personal data is collected.
  • Whose information it is.
  • Where the information comes from.
  • Why the business uses it.
  • Which systems store it.
  • Who can access it.
  • Which service providers receive it.
  • How long it is kept.
  • Whether it is transferred outside the UK.

This does not have to begin as a complicated governance system. A structured spreadsheet can provide enough visibility to identify gaps and guide the next steps.

The inventory can also support the business’s record of processing activities. Some organisations are legally required to maintain formal processing records, while others benefit from keeping a proportionate record as evidence of how they meet their responsibilities.

The most useful record is one that reflects what the business actually does. A detailed template that is never updated offers less value than a straightforward record that people understand and maintain.

Be clear about why you use personal data

Every use of personal data must have an appropriate lawful basis. This is the legal reason the business is permitted to collect or use the information.

The main lawful bases include:

  • Processing that is necessary to perform a contract.
  • Processing required to meet a legal obligation.
  • Processing based on the organisation’s legitimate interests.
  • Processing for which the individual has given valid consent.
  • Processing necessary to protect someone’s vital interests.
  • Processing necessary for a task carried out in the public interest.

Consent is only one possible lawful basis. A business does not have to request consent every time it handles personal information.

For example, an online retailer may need a customer’s delivery address to fulfil an order. That processing may be necessary to perform its contract with the customer. Employee payroll records may be needed to comply with taxation and employment obligations.

Where a business relies on legitimate interests, it should identify the interest it is pursuing, consider whether the processing is necessary and balance that interest against the person’s rights and reasonable expectations.

The Data (Use and Access) Act has also introduced the concept of a recognised legitimate interest for certain activities specified in the legislation. This can remove the need for the usual balancing test in limited circumstances, but the processing must still be necessary and comply with the other data protection principles. Businesses should be careful about assuming that an activity falls within this category without checking the specific conditions.

The lawful basis should be selected before processing begins and recorded as part of the business’s data inventory or processing record.

This review also helps the business apply two important principles:

  • Collect only the personal data genuinely required for the purpose.
  • Keep it only for as long as there is a valid reason to retain it.

The choice of lawful basis can affect the rights available to individuals, so it should be based on the actual purpose and circumstances rather than convenience.

Make your privacy information clear and accurate

A privacy notice explains how the business handles personal data. It gives customers, employees and other individuals the information they need to understand what is happening to their information.

Depending on the context, a privacy notice will usually explain:

  • Who is responsible for the processing.
  • What personal data is collected.
  • Why the data is used.
  • Which lawful basis applies.
  • Who receives or has access to the data.
  • How long the data is retained.
  • Whether it is transferred outside the UK.
  • What rights the individual has.
  • How the business can be contacted.
  • How a person can make a data protection complaint.
  • How the person can raise a concern with the ICO.

The notice should reflect what the business actually does. A generic policy copied from another website may describe systems or activities that do not exist while overlooking important processing that does.

It also helps to consider when information is presented. A website privacy notice may act as the main reference document, while shorter explanations can be placed near enquiry forms, account registration pages and other collection points.

The ICO provides a privacy notice generator designed for sole traders, start-ups, charities and small and medium-sized organisations. A generated notice still needs to be checked against the business’s actual practices and kept current as those practices change.

Privacy information should be clear, concise and accessible. People should be able to understand how their information is used without having to interpret dense legal language.

Prepare to respond when people exercise their rights

The UK GDPR gives individuals a number of rights over their personal data. Depending on the circumstances, a person may ask a business to:

  • Confirm whether their information is being processed.
  • Provide access to their personal data.
  • Correct incomplete or inaccurate information.
  • Delete information where the right to erasure applies.
  • Restrict how information is used.
  • Provide eligible information in a portable format.
  • Stop certain processing.
  • Stop using their information for direct marketing.
  • Obtain safeguards relating to certain automated decisions.

The ICO identifies eight individual rights. For many smaller businesses, the rights most commonly encountered include the right to be informed, the right of access, the right to object and the right to erasure.

These rights do not apply in exactly the same way in every situation. For example, a deletion request does not always require the business to remove records that it has a legal obligation to retain.

The practical starting point is to establish a simple process that covers:

  • Where requests should be sent.
  • Who is responsible for managing them.
  • How the person’s identity will be confirmed.
  • How relevant systems and records will be searched.
  • How decisions and correspondence will be documented.
  • When legal advice or escalation is required.

A business will generally have one month to respond to a subject access request. The applicable timeframe can depend on the type and complexity of the request, so requests should be recognised and logged promptly.

A central request log helps prevent an email from being overlooked and gives the business a record of how each matter was handled.

Put a data protection complaints process in place

Since June 2026, organisations subject to UK data protection law must provide a process through which people can raise complaints about how their personal information has been handled.

This is separate from an individual rights request, although the same communication may contain both a complaint and a request to exercise a right.

The new requirements mean that an organisation must:

  • Give people a clear way to make a data protection complaint.
  • Acknowledge the complaint within 30 days.
  • Take appropriate steps to investigate it without undue delay.
  • Keep the complainant informed about the progress of the investigation.
  • Tell the complainant about the outcome.

The requirement applies to organisations generally, including small and medium-sized businesses.

A sensible first action is to nominate a person or role to receive complaints, provide a clear email address or online form and maintain a complaint log.

The process does not have to be complicated. It should make it easy for someone to explain their concern and give the business a consistent way to investigate and respond.

Review the businesses that process data for you

Small businesses often rely on other organisations to store or process personal data. These may include:

  • Cloud hosting providers.
  • Microsoft 365 or Google Workspace.
  • Payroll and accounting platforms.
  • Customer relationship management systems.
  • Email marketing providers.
  • Website hosting and analytics services.
  • Managed IT and support providers.
  • Payment and e-commerce platforms.

Under the UK GDPR, the organisation that decides why and how personal data is used is generally the controller. A supplier that processes the information on the controller’s behalf is generally a processor.

Using a processor does not remove the controller’s responsibilities. The controller should choose providers that can provide appropriate privacy and security assurances and must ensure that the contractual arrangement meets UK GDPR requirements. Processors also have direct legal obligations of their own.

The agreement should address matters such as:

  • The subject and duration of the processing.
  • The nature and purpose of the processing.
  • The types of personal data and people involved.
  • Confidentiality.
  • Security arrangements.
  • Assistance with individual rights.
  • Personal data breach notification.
  • Deletion or return of information.
  • The appointment of subprocessors.
  • Audit and compliance information.

A sensible supplier review should focus first on providers that hold sensitive information, support important business functions or have broad access to company systems.

The review should also look beyond the contract. A provider may have suitable written terms but still be configured in a way that gives too many people access or retains information longer than the business requires.

Understand where personal data is transferred

Cloud services can make the location of personal data less obvious. A provider may be headquartered in one country, store information in another and provide support from several additional locations.

The UK GDPR contains rules for certain transfers of personal data to separate organisations outside the UK. These are referred to as restricted transfers.

A restricted transfer must generally be covered by:

  • UK adequacy regulations.
  • An appropriate safeguard.
  • A permitted exception.

Appropriate safeguards can include the UK International Data Transfer Agreement, known as the IDTA, or the UK Addendum to the European Commission’s Standard Contractual Clauses. The EU clauses do not, by themselves, provide a valid safeguard for a restricted transfer under the UK GDPR.

Where a business relies on an appropriate safeguard, it must also consider whether the information will continue to receive a level of protection that is not materially lower than the protection provided in the UK. This assessment is commonly described by the ICO as a transfer risk assessment and reflects the statutory data protection test introduced through the Data (Use and Access) Act.

A useful starting action is to ask important providers:

  • Where personal data is stored.
  • From which countries support staff can access it.
  • Which international transfers take place.
  • Which adequacy decision or contractual safeguard supports each transfer.
  • Which subprocessors are involved.

International transfer arrangements can become legally complex, particularly where multiple suppliers and countries are involved. This is an area where specialist privacy advice may be appropriate.

Protect personal data with appropriate security

Privacy compliance and cybersecurity are closely connected. A business cannot handle personal information responsibly if its accounts, devices and cloud services are poorly protected.

The UK GDPR does not prescribe one security product or checklist for every organisation. The measures should reflect the type of personal data involved, the way it is used and the potential effect on people if the information is lost, changed, exposed or made unavailable.

For many small and growing businesses, the practical foundations include:

  • Enabling multi-factor authentication on important accounts.
  • Limiting administrative access.
  • Giving employees access only to the information required for their work.
  • Removing access promptly when someone leaves or changes roles.
  • Keeping operating systems, applications and devices updated.
  • Encrypting suitable devices and information.
  • Maintaining reliable backups and testing recovery.
  • Configuring Microsoft 365, Google Workspace and other cloud services securely.
  • Training employees in secure and appropriate data handling.
  • Reviewing account activity and important security alerts.
  • Documenting security responsibilities and essential procedures.

The measures should reflect the risks involved. A consultancy storing ordinary business contact details will have a different risk profile from a healthcare provider holding medical information or a software service processing large amounts of customer data.

Security also needs to remain current. Access arrangements, systems and suppliers change over time, which means safeguards should be reviewed rather than treated as a one-off project.

Prepare for personal data breaches

A personal data breach is not limited to a cyberattack. It can occur whenever personal data is accidentally or unlawfully lost, destroyed, changed, disclosed or accessed.

Examples include:

  • An employee sending a document to the wrong recipient.
  • A laptop containing personal data being lost or stolen.
  • An attacker gaining access to an email account.
  • A customer being given access to another customer’s information.
  • Important records being deleted without a usable backup.
  • A supplier exposing information through an incorrectly configured system.

The business should have a process for containing the incident, preserving evidence, identifying the affected information and assessing the possible effect on individuals.

Where a breach meets the reporting threshold, it must be reported to the ICO without undue delay and within 72 hours of the organisation becoming aware of it. The clock starts when the breach is discovered, rather than when the underlying incident occurred.

The organisation may not have every detail within the first 72 hours. It should begin gathering information, contain the problem and keep a written log while the investigation continues.

Where the breach is likely to create a high risk for affected individuals, the organisation may also need to inform those people without undue delay.

Breaches should be documented even where the business decides that an ICO report is not required. The record should explain what happened, the potential consequences, the response and the reasons behind the notification decision.

Preparing a short response procedure and assigning responsibility before an incident occurs makes these decisions much more manageable.

Recognise when additional requirements may apply

Some businesses will need more formal privacy arrangements because of the nature or scale of their activities.

Additional requirements may arise when a business:

  • Processes health, biometric or other special category data.
  • Regularly monitors or profiles large numbers of people.
  • Uses personal data in ways likely to create a high risk for individuals.
  • Provides an online service likely to be accessed by children.
  • Makes significant decisions using automated systems.
  • Handles criminal offence data.
  • Operates across both the UK and EEA.

Depending on the circumstances, the business may need to complete a Data Protection Impact Assessment, appoint a Data Protection Officer or obtain specialist legal advice.

The Data (Use and Access) Act has changed parts of the UK framework relating to automated decision making. It has also made children’s needs an explicit consideration when designing online services likely to be accessed by them. All of these provisions are now in force, although detailed ICO guidance continues to develop in some areas.

A Data Protection Officer is not required for every small business. The requirement usually depends on the nature of the organisation’s core activities, including whether it carries out large-scale regular and systematic monitoring or large-scale processing of special category or criminal offence data.

The aim is to recognise when ordinary business processing has moved into an area that deserves closer assessment.

A practical UK GDPR starting checklist

UK GDPR compliance is easier to manage when the work is arranged in a sensible order. The following sequence helps establish the foundation before moving into more specialised questions.

  1. Confirm whether the UK GDPR applies. Consider where the business operates, who it serves and whether it targets or monitors people in the UK.
  2. Check whether the EU GDPR also applies. Businesses operating in or targeting both markets may have responsibilities under both regimes.
  3. Map the personal data you handle. Record what is collected, why it is used, where it is stored, who can access it and which suppliers receive it.
  4. Identify the lawful basis for important processing. Document why each main activity is permitted and check whether additional conditions apply to special category information.
  5. Review what you collect and retain. Remove information that is no longer needed and establish reasonable retention periods.
  6. Update your privacy information. Make sure notices clearly and accurately explain the business’s current practices.
  7. Prepare for individual rights requests. Assign responsibility and establish a process for locating information and responding within the required timeframe.
  8. Establish a complaints process. Give people a clear way to complain, acknowledge complaints within 30 days and document how they are investigated and resolved.
  9. Review important suppliers. Check data processing terms, security arrangements, subprocessors and international transfers.
  10. Strengthen access and security controls. Prioritise account protection, device security, cloud configuration, backups and employee access.
  11. Prepare for personal data breaches. Document how incidents will be contained, assessed, recorded and reported.
  12. Identify higher-risk activities. Determine whether a Data Protection Impact Assessment, Data Protection Officer or specialist advice may be required.
  13. Assign ongoing responsibility. Privacy arrangements should be reviewed when systems, suppliers, products or business activities change.

This provides a workable foundation without trying to answer every possible privacy question at the same time.

A clearer path to UK GDPR compliance

UK GDPR compliance can look broad when it is viewed as one large legal project. It becomes more practical when the work begins with a few clear questions: what information does the business hold, why is it needed, where does it go, who can access it and how is it protected?

From there, the business can improve its notices, complaints process, supplier arrangements, security controls and incident preparation in a sensible order.

The goal is not to produce paperwork that sits untouched. Good privacy practices should give the business a clearer understanding of its information, better control over its systems and a reliable way to respond when customers, employees or regulators raise questions.

BrightShield can help turn those responsibilities into a prioritised plan and provide the level of support needed to carry the work through to completion.

Subscribe to our newsletter

Every week we publish a short email on a topic we think you'll find interesting. We know you're busy, so we keep it short, snappy, and relevant.

Let's Begin

Ready to understand your security risks?

Get a clear, practical view of your risks and a plan to fix them with a BrightShield Security Audit.