Buzz Legal
Non-reserved business legal services
Home / Blog / GDPR for small business, minus the jargon
Blog · Data protection

GDPR for small business, minus the jargon

You don't need a data protection officer or a 40-page policy. You do need to get a short list of basics right. Here's GDPR for a normal small business.

If your business holds names, email addresses, staff records or a marketing list, UK data protection law applies to you. There is no small-business exemption: a sole trader with a client list on a laptop is as squarely in scope as a company with a million records. The reassuring part is how short the real to-do list is — six things, no data protection officer, and no forty-page policy.

  1. Pay the ICO data protection fee.
  2. Publish a privacy notice that describes what you actually do.
  3. Write down what personal data you hold, why, on what lawful basis and how long you keep it.
  4. Put data processing agreements in place with the suppliers who handle data for you.
  5. Have a process for a subject access request.
  6. Have a breach process.

1. The ICO fee

Most organisations that process personal data must pay the Information Commissioner's Office an annual data protection fee. It is tiered by size and turnover: £52 a year for a micro organisation, £78 for a small or medium one and £3,763 at the top tier, with £5 off for paying by direct debit. Those amounts apply from 17 February 2025, when the Data Protection (Charges and Information) (Amendment) Regulations 2025 raised every tier. Most small businesses sit on the £52 tier.

Exemptions exist but are narrow, and the usual assumption — that a small firm with a simple website is exempt — is wrong once you hold customer or staff records. This is also the easiest enforcement the ICO does, because they can see exactly who has not paid.

2. A privacy notice that is true

The notice is the public-facing explanation of what data you collect, why, on what lawful basis, who you share it with, how long you keep it and what rights people have. It lives on your website, linked in the footer and on every form that collects data. Whether it is called a policy or a notice makes no difference; whether it is true does. A notice copied from another company's site, describing systems you do not use and retention periods you do not apply, is worse than having none — it is a set of published promises you are visibly failing to keep, in writing, on your own website. Read yours against what your business actually does and cut every line that is not accurate.

3. Know what you hold, and why

A spreadsheet is fine. One row per system — the inbox, the CRM, the accounts package, the shared drive, the email marketing tool — and for each: what personal data is in it, why you have it, which lawful basis applies (consent, contract, legitimate interests, legal obligation), and how long you keep it. That one document does most of the work when a request or a breach lands, because half the pain of both is not knowing where your own data lives.

4. Agreements with the suppliers who handle your data

Where another business processes personal data on your behalf, there needs to be a written data processing agreement setting out what they may do with it. In practice that means your CRM, your email platform, your IT provider and your accountant. Most large suppliers publish one you accept as part of their terms; the smaller ones often do not, and those are the ones to chase.

5. Subject access requests

People can ask for a copy of the personal data you hold about them. You generally have one month to respond and normally cannot charge. The first one almost always arrives at a bad moment — from a disgruntled customer or an ex-employee in a dispute, sent precisely to make life difficult — so settle the routine now: who receives it, which systems get searched, who checks the response before it goes out. If you did step 3, this is a search rather than a weekend-eating hunt.

6. When something goes wrong

A mislaid laptop, an email sent to the whole list with every address visible, a hacked account. Contain it first, then assess the risk to the people affected rather than the embarrassment to you. Where there is a risk to their rights and freedoms you must report it to the ICO within 72 hours of becoming aware; where the risk is high you must also tell the individuals without undue delay. Not every breach is reportable, but you must record every one internally, including the ones you decide not to report — what happened, what data was involved, who was affected and what you did. A one-page process agreed in advance turns a bad hour into a manageable one.

The one that catches most small businesses: marketing

Email and text marketing to individuals generally needs consent. The exception is the soft opt-in under the Privacy and Electronic Communications Regulations, and it is narrower than most people assume: you must have obtained the details in the course of a sale or negotiations for a sale, be marketing your own similar products, and have given a simple opt-out at the point of collection and in every message since. Corporate subscribers such as limited companies and LLPs are treated more permissively, though UK GDPR fairness rules still apply. So keep a record of how and when each person opted in, put a working unsubscribe in every message, and honour it promptly — failing to is the complaint that reaches the ICO.

In practice — illustrative example

The mailing list that was never consented

A boutique gym buys an email list and starts firing out promotions. The recipients never agreed to hear from the gym, several complain, and one reports it to the ICO. The gym has no lawful basis for the marketing and no record of consent for a single name on the list. A proper lawful basis, a genuine sign-up process and an honest privacy notice would have cost a small fraction of the reputational damage and the awkward correspondence with the regulator.

What to do next

Two jobs cover most small-business exposure on their own. Pay the ICO fee today if you have not. Then read your privacy notice against what your business actually does and note every line that is not true.

If you would rather have the documents done properly, privacy notices, cookie policies and website terms written to match your real systems, data processing agreements with your suppliers, the record of what you hold, and a workable subject access request process are all non-reserved work. Book a legal review and you get one fixed price for the job, agreed in writing before anything starts; prices are on fixed-fee work and there is more detail in our guide to website terms and privacy. Three things sit outside what we do: acting as your appointed Data Protection Officer, defending an ICO investigation, which goes to a regulated firm, and penetration testing, which is an IT job rather than a legal one.

This is general legal information, not advice on your situation. For advice tailored to your business, book a legal review. Buzz Legal provides non-reserved business legal support; reserved legal activities are carried out by RHF Solicitors, authorised and regulated by the SRA (no. 324115).

Common questions

Do I really have to pay the ICO?

Most businesses that process personal data do, and it is an annual data protection fee rather than a registration in the old sense. The tiers are £52, £78 and £3,763 a year depending on size and turnover, in force from 17 February 2025, with most small firms on the £52 tier and £5 off for paying by direct debit. Exemptions exist but are narrow, and the common assumption — that a small business with a simple website is exempt — is usually wrong once you hold customer or staff records. Check your position rather than ignore it. Non-payment is the easiest enforcement the ICO does, because they can see exactly who has not paid.

Do I need a data protection officer?

Almost certainly not. A statutory DPO is only required where you are a public authority, where your core activities involve regular and systematic monitoring of people on a large scale, or where they involve large-scale processing of special category or criminal offence data. A normal small business selling to customers and employing staff meets none of those. You still have to comply with everything else, and someone internally should own data protection, but there is no requirement for a formal appointment — and appointing one carries obligations of its own, including genuine independence. We do not act as an appointed DPO for clients.

Is a privacy policy the same as a privacy notice?

In everyday use, yes. The document that matters is the public-facing one telling people what data you collect, why, on what lawful basis, who you share it with, how long you keep it and what rights they have. The name on it is irrelevant. Whether it is true is not. A copied notice describing systems you do not use, retention periods you do not apply and processes you have never tested is worse than useless — it is a set of published promises you are visibly failing to meet, in writing, on your own website. A short, accurate notice beats a long, borrowed one every time.

Can I email my existing customers without consent?

Sometimes, under the soft opt-in in the Privacy and Electronic Communications Regulations. It applies where you obtained the contact details in the course of a sale or negotiations for a sale, you are marketing your own similar products or services, and you gave a simple opt-out at the point of collection and in every message since. Cold-emailing individuals or sole traders you have no relationship with, or a bought-in list, generally needs consent. Corporate subscribers such as limited companies and LLPs are treated more permissively, though UK GDPR fairness rules still apply. Always include a working unsubscribe and honour it promptly, because failing to is the complaint that reaches the ICO.

What do I do if I have a data breach?

Contain it first, then assess the risk to the people affected rather than the embarrassment to you. If there is a risk to their rights and freedoms you must report it to the ICO within 72 hours of becoming aware, and where the risk is high you must also tell the individuals without undue delay. Not every breach is reportable, but you have to be able to make that judgement quickly and record it either way — you are required to keep an internal record of all breaches, including the ones you decide not to report. Write down what happened, what data was involved, who was affected and what you did. A one-page process agreed in advance turns a bad hour into a manageable one.

What is the shortest realistic compliance list for a small business?

Six things. Pay the ICO fee. Publish a privacy notice that describes what you actually do. Write down what personal data you hold, why, on what lawful basis and how long you keep it — a spreadsheet is fine. Put data processing agreements in place with the suppliers who handle data for you, which in practice means your CRM, email platform, accountant and IT provider. Have a process for a subject access request, because you have one month to respond and the first one always arrives at a bad time. And have a breach process. For a normal business that is most of it, and it is a day's work rather than a project.

Can Buzz Legal do this for us?

Yes — the documents and the process. Privacy notices, cookie policies and website terms written to match what your site and systems genuinely do; data processing agreements with your suppliers; a record of what personal data you hold, why and for how long; and a workable subject access request process so the first one does not cause panic. All of that is non-reserved work. What sits outside it: acting as your appointed Data Protection Officer, defending an ICO investigation or enforcement action, which goes to a regulated firm, and security or penetration testing, which is an IT job rather than a legal one.

Legal housekeeping, once a month

A short note on the contracts, terms and employment paperwork worth sorting before they bite. No cookies, no tracking, unsubscribe any time.

Buzz Legal Ltd is not a firm of solicitors and is not regulated by the SRA. Reserved legal work is carried out by RHF Solicitors, SRA no. 324115.

Your address is used to send what you asked for and nothing else. See the privacy policy.

Get legal sorted before it bites.

Book a legal review

Clear scope · fixed fees available. Buzz Legal Ltd is not a firm of solicitors and is not regulated by the SRA.

Buzz Legal Ltd — non-reserved business legal services. Reserved legal work carried out by RHF Solicitors, SRA no. 324115. Buzz Money Coach · Privacy · Cookies · Complaints · Terms · · Developed by Chivvy
Chat with us on WhatsApp