Data protection law sounds like something for large companies with legal departments. In practice, UK GDPR asks small businesses to do a handful of sensible things and be able to show they have done them. Here is the practical version, in the order we would tackle it.
1. Know what personal data you hold
Make a simple list: what data (names, emails, addresses, payment details, staff records, CCTV), about whom (customers, staff, suppliers, website visitors), where it is stored (which systems, which folders, which laptops), why you hold it, and who it is shared with. This is your record of processing, and it drives everything else. Most businesses are surprised by how many places data lives; our cloud migration guide explains why consolidating systems helps.
2. Have a lawful reason for each use
Every use of personal data needs a basis: performing a contract (processing a customer's order), legal obligation (keeping tax records), legitimate interests (normal business communication with customers), or consent (marketing to individuals who signed up). Write the basis next to each item on your list. Consent is needed less often than people think, and legitimate interests more often.
3. Publish a privacy notice
A plain-English page on your website saying who you are, what data you collect, why, how long you keep it, who you share it with (including any overseas processors), and what rights people have. Link it from your contact forms and your footer. Templates are a starting point; it must reflect what you actually do.
4. Keep data secure
The security measures the law expects are proportionate to the risk. For most small businesses that means: multi-factor authentication on all accounts, strong unique passwords via a password manager, devices encrypted and updated, access limited to those who need it, leavers removed promptly, backups tested, and staff told what phishing looks like. Cyber Essentials, the government-backed scheme, is a good benchmark.
5. Delete what you no longer need
Set retention periods: how long you keep enquiries that did not become customers, customer records after the relationship ends, staff records after employment, CCTV footage. Then actually delete on schedule. Old data is a liability, not an asset.
6. Be ready for requests
Anyone can ask what data you hold about them (a subject access request), ask for it to be corrected or deleted, or object to how you use it. You have one month to respond. Decide who handles these, and how you would find everything about one person across your systems. Your data list from step one is what makes this possible.
7. Have a breach plan
If personal data is lost, stolen or exposed, you may need to notify the ICO within 72 hours and, in serious cases, the people affected. Write down who decides, how you assess severity and who you call. Rehearse it once.
8. Check your suppliers
Anyone who processes data on your behalf (hosting, email marketing, payroll, developers, cloud services) needs a written contract with data protection terms. Where they are outside the UK, there must be a valid transfer mechanism. Keep a list of them.
9. Marketing and cookies
Marketing to individuals by email or text needs consent or a valid soft opt-in, and an easy unsubscribe every time. Non-essential cookies (analytics, advertising) need consent before they are set. See our guides on email flows and GA4 basics for how this works in practice.
10. Name someone, document it, review it
Nominate a person responsible for data protection, even if it is you. Keep the documents from the steps above in one place. Review once a year and whenever you add a system or a supplier.
Where software fits
Well-designed systems make most of this easier: one customer record instead of five, access controls instead of shared spreadsheets, retention rules that run automatically, audit trails that show who did what. It is one of the quieter benefits of moving to an ERP or building a proper customer portal.
This article is general information, not legal advice; the ICO's website is the authoritative source and a solicitor can review your specific position. What we can help with is the systems side: making sure the software you run supports the obligations above. Read about our IT consulting service or request a quote.
Key takeaways
- UK GDPR applies to every business that holds personal data, which is every business.
- The practical essentials: know what data you hold, have a privacy notice, keep data secure, delete what you do not need, and have a plan for breaches and requests.
- Most of it is good housekeeping rather than legal complexity.
- Get the basics right, document them, and review annually.
Frequently asked questions
Need help with it consulting?
eSolution Hub is a UK company with its own engineering team in Lahore. Every project starts with a free 30 minute discovery call and a written quote. Read about our it consulting service or request a quote.
Request a quote