One of the most persistent myths in UK data protection is that small businesses sit outside GDPR requirements. The Information Commissioner’s Office has consistently rejected this idea. UK GDPR applies to any controller or processor handling the personal data of people in the UK, regardless of headcount or turnover, with only one narrow, specific exception related to record-keeping.
This guide explains what UK GDPR actually requires of a small business, obligations that sit alongside workplace health and safety duties, and how to build a genuinely defensible compliance position without an enterprise-level compliance team.
What UK GDPR Actually Is
UK GDPR is the retained version of the EU’s General Data Protection Regulation, applied in UK domestic law following Brexit, and it works alongside the Data Protection Act 2018, which tailors certain provisions for the UK context. It governs how organisations collect, store, use and share personal data, and is enforced by the Information Commissioner’s Office.
The Small Business Exemption Myth
There is no general small business exemption from UK GDPR. The only size-related relief sits in Article 30(5), a narrow exception around maintaining a formal record of processing activities, and even that exception does not apply if your processing is not occasional, poses a risk to individuals’ rights, or involves special category data. In practice, almost every small business still needs to understand and apply the core principles.
What Counts as Personal Data
Personal data covers far more than customer records. Employee files, supplier contact details, CCTV footage, cookies containing identifiers, and CVs sitting in a careers inbox all count as personal data under UK GDPR, a scope worth considering alongside your cyber security protections.
The Seven Core Principles
Every UK GDPR decision should trace back to seven core principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Building your compliance approach around these principles, rather than treating each requirement in isolation, keeps decisions consistent as your business grows.
Establishing a Lawful Basis
Every processing activity needs a named lawful basis under Article 6, such as consent, contract necessity, legal obligation, or legitimate interests. The list of recognised legitimate interests has recently been narrowed and codified, covering specific situations such as national security, crime prevention, safeguarding and emergency response; a business cannot simply invent its own category to justify processing.
Special Category Data Needs Extra Care
Processing special category data, such as health information, race, religious beliefs or political opinions, requires meeting an additional condition under Article 9, on top of your standard Article 6 lawful basis. For many small businesses, this most commonly arises in an employment context, such as recording health information related to sick leave.
Handling Subject Access Requests
Individuals have the right to request a copy of the personal data you hold about them. You generally cannot charge a fee for this in most cases, must respond within one month, and need a clear, prompt process for assessing and responding to requests, including explaining any refusal and informing the individual of their right to escalate a complaint.
Cookie Consent Rules Have Changed
Recent changes have adjusted the cookie consent landscape: low-risk analytics, functional display preferences such as language settings, and emergency geolocation can now run without prior consent, provided users are clearly informed. Advertising, A/B testing and personalisation cookies still require genuine opt-in consent, so cookie banners need to reflect this distinction accurately rather than treating all cookies the same way.
Preparing for a Data Breach
UK GDPR places a firm 72-hour window on reporting certain personal data breaches to the ICO. Having a defined internal process, clear ownership of who assesses and reports an incident, and the ability to move quickly makes a significant difference in how a breach is managed and perceived, both by the regulator and by affected individuals.
Do You Need a Data Protection Officer?
A Data Protection Officer is mandatory only in specific circumstances, including public authorities, or businesses carrying out large-scale, regular and systematic monitoring of individuals, such as certain online behaviour tracking. Most small businesses are not required to appoint one, though any business can choose to appoint an internal or external DPO voluntarily.
Comparing Key GDPR Obligations by Business Activity
| Activity | Key Obligation | Applies To |
|---|---|---|
| Collecting customer data | Establish and document a lawful basis | Nearly all small businesses |
| Processing employee health data | Meet an Article 9 special category condition | Businesses handling sick leave or adjustments |
| Website cookies | Accurate consent banner, opt-in where required | Any business with a website |
| Responding to a data request | Respond within one month, generally free | Any business holding personal data |
| Large-scale behaviour monitoring | Mandatory DPO appointment | A small subset of larger-scale operations |
Practical First Steps Toward Compliance
- Carry out a data audit to understand exactly what personal data your business actually holds and processes
- Identify and document a lawful basis for each significant processing activity
- Update your privacy notice and cookie consent banner to reflect current requirements accurately
- Put a clear, simple process in place for handling subject access requests within the one-month deadline
- Define who is responsible for assessing and reporting a data breach within the 72-hour window
Frequently Asked Questions
Are small businesses actually exempt from UK GDPR?
No. The only size-related relief is a narrow record-keeping exception under Article 30(5), and it does not apply to processing that is regular, poses risk to individuals, or involves special category data. Most core obligations apply regardless of business size.
What are the penalties for UK GDPR non-compliance?
Penalties can reach up to £17.5 million or 4% of annual global turnover, whichever is higher, though the ICO generally takes a proportionate approach, particularly with small businesses demonstrating genuine good faith efforts toward compliance.
Does UK GDPR apply to a business based outside the UK?
Yes, if that business is a controller or processor targeting goods or services to individuals in the UK, or monitoring their behaviour, even without having any UK office or branch.
Do all small businesses need a Data Protection Officer?
No. A DPO is only mandatory for public authorities or businesses conducting large-scale, systematic monitoring of individuals. Most small businesses can meet their obligations without one, though appointing one voluntarily is always an option.
Final Thoughts
UK GDPR compliance for a small business is less about a single certificate to obtain and more about an ongoing, structured approach to how personal data is collected, used and protected. Understanding the core principles, establishing clear lawful bases, and having a defined process for requests and breaches covers the large majority of what genuinely matters, without requiring an enterprise-level compliance function.
