190 C Mumbai

Data Protection Rules Every Small Business Should Know

  • 100 Views
  • 35 Comments
  • 24th March 2019
Data Protection Rules Every Small Business Should Know

Why Data Protection Matters for Small Businesses

If you run a small or medium-sized enterprise in the UK, you handle personal data every day. Customer names, email addresses, phone numbers, employee records, supplier contacts — all of it falls under the UK GDPR and the Data Protection Act 2018. These rules apply to you regardless of your size, whether you employ three people or thirty. The Information Commissioner's Office (ICO) does not exempt small businesses from compliance.

The good news is that the core obligations are practical and manageable. You do not need a legal team on retainer. You need to understand a handful of principles and apply them consistently. Here are the essentials every SME owner should know.

You Must Have a Lawful Basis for Processing Data

Before you collect or use someone's personal data, you need a lawful basis for doing so. There are six available under UK GDPR, but most small businesses rely on three:

  • Consent: The individual has given you clear, specific permission. This must be freely given, and you must be able to prove it. If you rely on consent, people can withdraw it at any time.
  • Contract: Processing is necessary to fulfil a contract with the individual, such as delivering a product they ordered.
  • Legitimate interests: Processing is necessary for your business purposes, provided it does not override the individual's rights. You must document why your interest outweighs theirs.

The key point is that you cannot simply collect data because it might be useful one day. You need a specific reason that fits one of the lawful bases, and you should record which basis applies to each type of processing you do. If the ICO investigates a complaint, they will ask for this.

Keep Data for No Longer Than Necessary

One of the most common mistakes SMEs make is holding onto data indefinitely. The storage limitation principle says you must not keep personal data for longer than you need it. This means having a retention schedule — even a simple one.

Ask yourself: how long do we genuinely need this information? For customer transaction records, HMRC typically requires you to keep financial data for six years. For marketing lists, you might review consent every two years. For unsuccessful job applicants, a common approach is to retain records for six months to a year, then delete them.

Write down your retention periods and stick to them. Set calendar reminders to review and delete data that has passed its retention date. This reduces your risk if a breach occurs, because there is less data to expose.

Report Serious Breaches Within 72 Hours

A personal data breach is any security incident that leads to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of personal data. This could be a cyber attack, but it could also be a misdirected email containing customer details or a lost laptop.

If a breach is likely to result in a risk to people's rights and freedoms, you must report it to the ICO within 72 hours of becoming aware of it. If the risk is high, you must also inform the affected individuals without undue delay.

Not every breach needs reporting. If the data was encrypted and the key was not compromised, or if the breach is unlikely to cause harm, you may not need to notify the ICO. But you should still document it internally. The ICO provides a self-assessment tool on its website to help you decide. The critical thing is to have a plan in place before a breach happens. Know who will assess the incident, who will contact the ICO, and how you will communicate with affected customers.

Individuals Have Rights You Must Honour

People have specific rights over their data, and you must be able to respond to requests. The most common are:

  • Right of access: Individuals can ask for a copy of the personal data you hold about them. You must respond within one month, free of charge.
  • Right to rectification: If data is inaccurate, they can ask you to correct it.
  • Right to erasure: Also known as the "right to be forgotten," this allows individuals to ask you to delete their data in certain circumstances.
  • Right to object: They can object to processing based on legitimate interests or for direct marketing.

You do not have to comply with every request automatically. Some exemptions apply, particularly for legal claims or regulatory obligations. But you must assess each request and respond promptly. Having a simple internal process for handling these requests will save you time and stress.

Practical Steps to Stay Compliant

You do not need to overhaul your entire operation. Start with these practical actions:

  • Create a simple record of what personal data you hold, where it came from, and who you share it with.
  • Review your privacy notices to ensure they are clear, accurate, and easy to understand.
  • Train your staff on basic data protection — what to do with a subject access request, how to spot a phishing email, and when to report a breach.
  • Check that any third-party suppliers who handle data on your behalf, such as payroll providers or cloud storage services, have appropriate safeguards in place.
  • Review your data retention schedule at least once a year and delete what you no longer need.

Compliance is not a one-off task. It is an ongoing practice, like bookkeeping or health and safety. Get the basics right, document your decisions, and review them regularly. That approach will keep you on the right side of the rules and protect your reputation with customers who trust you with their information.

Related Post

Expanding into New Markets Without Overstretching

Bp Consulting Written for people who value the details, and want honest guidance they can trust.

Using Customer Feedback to Shape Strategy

Bp Consulting Real stories, useful guides and the occasional recommendation, all in one calm corner of the web.

Rosalina William

New markets can bring growth but also risk. Test demand, adapt your offer and protect core business cash flow before scaling.

Comments
ALina Kelian
19th May 2018 Reply

Bp Consulting Simple, genuine and looked after with care — the kind of place worth returning to. ullamco laboris nisi ut aliquip ex ea commodo consequat.

Rlex Kelian
19th May 2018 Reply

Bp Consulting Written for people who value the details, and want honest guidance they can trust. ullamco laboris nisi ut aliquip commodo.

Roboto Alex
21th May 2018 Reply

Bp Consulting An honest, everyday look at the things that make life a little better — with advice you can actually use. ullamco laboris nisi ut aliquip ex ea commodo consequat.

Leave a Reply

Your email address will not be published. Required fields are marked *