
If you run a small or medium-sized enterprise in the UK, you handle personal data every day. Customer names, email addresses, phone numbers, employee records, supplier contacts — all of it falls under the UK GDPR and the Data Protection Act 2018. These rules apply to you regardless of your size, whether you employ three people or thirty. The Information Commissioner's Office (ICO) does not exempt small businesses from compliance.
The good news is that the core obligations are practical and manageable. You do not need a legal team on retainer. You need to understand a handful of principles and apply them consistently. Here are the essentials every SME owner should know.
Before you collect or use someone's personal data, you need a lawful basis for doing so. There are six available under UK GDPR, but most small businesses rely on three:
The key point is that you cannot simply collect data because it might be useful one day. You need a specific reason that fits one of the lawful bases, and you should record which basis applies to each type of processing you do. If the ICO investigates a complaint, they will ask for this.
One of the most common mistakes SMEs make is holding onto data indefinitely. The storage limitation principle says you must not keep personal data for longer than you need it. This means having a retention schedule — even a simple one.
Ask yourself: how long do we genuinely need this information? For customer transaction records, HMRC typically requires you to keep financial data for six years. For marketing lists, you might review consent every two years. For unsuccessful job applicants, a common approach is to retain records for six months to a year, then delete them.
Write down your retention periods and stick to them. Set calendar reminders to review and delete data that has passed its retention date. This reduces your risk if a breach occurs, because there is less data to expose.
A personal data breach is any security incident that leads to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of personal data. This could be a cyber attack, but it could also be a misdirected email containing customer details or a lost laptop.
If a breach is likely to result in a risk to people's rights and freedoms, you must report it to the ICO within 72 hours of becoming aware of it. If the risk is high, you must also inform the affected individuals without undue delay.
Not every breach needs reporting. If the data was encrypted and the key was not compromised, or if the breach is unlikely to cause harm, you may not need to notify the ICO. But you should still document it internally. The ICO provides a self-assessment tool on its website to help you decide. The critical thing is to have a plan in place before a breach happens. Know who will assess the incident, who will contact the ICO, and how you will communicate with affected customers.
People have specific rights over their data, and you must be able to respond to requests. The most common are:
You do not have to comply with every request automatically. Some exemptions apply, particularly for legal claims or regulatory obligations. But you must assess each request and respond promptly. Having a simple internal process for handling these requests will save you time and stress.
You do not need to overhaul your entire operation. Start with these practical actions:
Compliance is not a one-off task. It is an ongoing practice, like bookkeeping or health and safety. Get the basics right, document your decisions, and review them regularly. That approach will keep you on the right side of the rules and protect your reputation with customers who trust you with their information.
New markets can bring growth but also risk. Test demand, adapt your offer and protect core business cash flow before scaling.
Comments
ALina Kelian
19th May 2018 ReplyBp Consulting Simple, genuine and looked after with care — the kind of place worth returning to. ullamco laboris nisi ut aliquip ex ea commodo consequat.
Rlex Kelian
19th May 2018 ReplyBp Consulting Written for people who value the details, and want honest guidance they can trust. ullamco laboris nisi ut aliquip commodo.
Roboto Alex
21th May 2018 ReplyBp Consulting An honest, everyday look at the things that make life a little better — with advice you can actually use. ullamco laboris nisi ut aliquip ex ea commodo consequat.