GDPR for Small Businesses 2025: What You Must Have in Place to Stay Compliant
Want the answer in seconds? Use our free calculator with your own numbers.
Check Your GDPR Compliance โSmall businesses often treat GDPR as something designed for large corporations with dedicated data protection teams. That view is expensive. The Information Commissioner's Office has fined sole traders, micro businesses and local companies, not just multinationals, and the most common violations are the basics: no privacy notice on the website, no ICO registration, no process for handling data requests. These are things any business can fix without a lawyer.
The UK GDPR, which came into effect at the end of the Brexit transition period in January 2021, is broadly the same as the EU version but is now a UK-specific framework maintained by Parliament and enforced by the ICO. If your business processes personal data, which almost every business does, you need to understand what it requires. This guide cuts through the complexity and focuses on what actually matters for a small business in 2025.
UK GDPR versus EU GDPR: what changed after Brexit
When the UK left the EU, it brought the EU GDPR into domestic law through the European Union (Withdrawal) Act 2018 and then modified it with the Data Protection Act 2018 to create UK GDPR. The two frameworks are substantially similar, which matters if you sell to customers in Europe, because you may need to comply with both.
The practical differences are modest. The UK has its own adequacy decisions (meaning data can flow between the UK and EU without additional safeguards, though this status is reviewed periodically). The UK also has slightly different rules around research, journalism and some public authority activities. For most small businesses selling domestically, the day-to-day obligations under UK GDPR look almost identical to those under the original EU regulation. If you sell to customers in EU member states, the EU GDPR applies to that processing and you may technically need a representative in the EU, though in practice the ICO cooperates with EU supervisory authorities and many small businesses with limited EU-facing activity operate under UK GDPR alone without incident. For businesses selling goods or services across Europe, the interaction with VAT rules adds another layer, which our EU VAT calculator can help you navigate.
ICO registration: almost every business needs to pay the fee
One of the most overlooked obligations is the requirement to register with the ICO and pay an annual data protection fee. This is separate from GDPR compliance itself, it is a statutory levy under the Data Protection (Charges and Information) Regulations 2018. Most organisations that process personal data must pay it. The fee is ยฃ40 per year for micro organisations (turnover under ยฃ632,000 and fewer than ten staff) and ยฃ60 per year for small and medium businesses.
The exemptions are narrower than people assume. Processing only for staff administration, accounts and records, advertising your own business, or non-automated processing are among the exempt categories, but the moment you have a website contact form, a mailing list, or a customer database, you almost certainly need to register. Failure to register is a criminal offence with fines of up to ยฃ4,350. The ICO publishes a self-assessment tool on its website to help you decide, but if you are unsure, the safe answer is to register.
The six lawful bases for processing personal data
Every time you collect, store, use or share personal data, you need a lawful basis for doing so under UK GDPR. There are six, and you must identify the right one before you start processing, you cannot switch basis retroactively if challenged. Choosing the wrong basis, or simply hoping no one asks, is a compliance failure even if the underlying processing is reasonable.
The six lawful bases under UK GDPR
Consent: the individual has given clear, specific, freely given agreement
Contract: processing is necessary to perform or prepare a contract with the person
Legal obligation: processing is required to comply with UK law
Vital interests: necessary to protect someone's life (rare in business contexts)
Public task: processing is necessary for a public authority's official function
Legitimate interests: your business has a genuine interest that is not overridden by the individual's rights
For small businesses, the most commonly applicable bases are contract, legal obligation, and legitimate interests. If you process a customer's address to deliver their order, that is contract. If you keep payroll records for HMRC, that is legal obligation. Legitimate interests is the most flexible but requires a balancing test: your interest must be genuine, the processing must be necessary to achieve it, and it must not be overridden by the individuals' rights and freedoms. You should document this test in writing.
Consent is often over-used. Many businesses default to asking for consent for everything, which sounds safe but creates problems: consent must be freely given, specific, informed and unambiguous. It must be as easy to withdraw as to give. If someone withdraws consent, you must stop processing. For most ordinary business processing, serving customers, managing staff, keeping accounts, consent is rarely the right basis and legitimate interests or contract is more appropriate.
Privacy notices: what your website must tell people
UK GDPR requires you to tell people what you are doing with their data at the point you collect it. For most businesses this means a privacy notice on their website, but the obligation extends to any collection point: paper forms, phone calls, staff recruitment and so on. The notice must be concise, transparent, intelligible and in plain language, not buried in legalese at the bottom of a 20-page document.
At minimum, your privacy notice needs to cover: who you are and your contact details; what personal data you collect and why; the lawful basis for each purpose; how long you keep data; who you share it with; where data is transferred outside the UK; and the individual's rights (access, rectification, erasure, restriction, portability and objection). If you use cookies that process personal data, your cookie notice must explain this separately and, for non-essential cookies, obtain consent.
The privacy notice must be easy to find. A link in your website footer labelled "Privacy Policy" is the standard approach. For forms that collect data, linking to the relevant section of the privacy notice directly from the form is best practice. What you cannot do is have a comprehensive privacy notice but process data for purposes not mentioned in it, everything you do with personal data must be disclosed.
Subject access requests: the 30-day clock
Any individual whose personal data you hold has the right to request a copy of it. This is a Subject Access Request (SAR), and when you receive one you have one calendar month to respond, not one working month. If the request is complex or numerous, you can extend by a further two months, but you must tell the individual within the first month that you are extending and explain why.
In most cases you cannot charge a fee for responding to a SAR. The fee exception applies only when requests are manifestly unfounded or excessive, which covers someone who submits dozens of identical requests to cause disruption, not a customer who wants to know what data you hold on them. Refusing a legitimate SAR or missing the deadline can result in a complaint to the ICO and potential enforcement action.
You must provide the data in a commonly used electronic format if the request is made electronically. You also need to tell the person the purposes for which you process their data, who you share it with, how long you keep it, and their rights to rectification, erasure and complaint. For small businesses with modest amounts of customer data, responding to a SAR is usually not onerous. The main risk is not knowing where all your data is, which is why having a simple data register, even a spreadsheet, is worth maintaining.
Data breach reporting: the 72-hour rule
A personal data breach is any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This includes things like sending an email to the wrong person, losing a laptop containing customer records, a ransomware attack that encrypts customer data, or a member of staff accessing records they should not have.
Not every breach needs to be reported to the ICO, but you need to assess every breach and document your assessment. The reporting threshold is a breach that is "likely to result in a risk to the rights and freedoms of individuals." If the breach is unlikely to result in such risk, for example, you accidentally sent an email to a wrong internal address and it contained no sensitive data, you document it internally but do not report it.
Data breach: when to report and to whom
Low risk breach: document internally only, no report to ICO required
High risk breach: report to ICO within 72 hours of becoming aware
Very high risk (risk to individuals): also notify the affected individuals without undue delay
All breaches must be logged internally regardless of severity
If the breach is reportable, the 72-hour clock starts from when you become aware of it, not when it occurred. You can submit an initial report to the ICO within 72 hours with the information you have and add further detail later. The 72-hour window is tight. Most small businesses find out about a breach on a Friday afternoon and spend the weekend deciding whether to report. Document your reasoning at the time, the ICO wants to see that you assessed the risk promptly and acted accordingly. If you are also selling into EU markets and are subject to EU GDPR, the same 72-hour rule applies under that framework as well, though the relevant supervisory authority would be in the EU member state where your EU establishment is located or where your EU customers primarily are.
Marketing emails and the soft opt-in rule
Email marketing to individuals is governed by both UK GDPR and the Privacy and Electronic Communications Regulations (PECR). The general rule under PECR is that you need prior consent before sending marketing emails to individuals. However, there is an important exception: the soft opt-in.
The soft opt-in allows you to email existing customers about your own similar products or services, provided you gave them a clear opportunity to opt out when you first collected their email address (and at every subsequent communication). The customer must have purchased from you or enquired seriously about a product or service, it does not cover cold contacts or people who merely visited your website. Every marketing email must include a clear, functioning unsubscribe mechanism. If someone unsubscribes, you must stop sending marketing emails promptly and remove them from your list. Sending one more email after an unsubscribe request is a PECR breach.
Free Tools Related to This Article
Sophie Chambers
UK Tax & Finance Writer
Sophie is a former tax consultant who worked at a mid-tier accountancy practice for six years before going freelance. She writes about UK personal tax, self-employment, property taxation and HMRC rules for TheCalcOra, with a focus on giving people the information they need without the jargon.
Try Our Free Calculator
Get an instant estimate based on your numbers. No sign-up, no cost.
Check Your GDPR Compliance โโ ๏ธ Important Disclaimer
TheCalcOra.com provides estimates for informational purposes only. Results are based on current UK law and EU regulations but may not reflect your exact circumstances. Always consult a qualified professional before making financial or legal decisions.