Common questions
Do I really have to pay the ICO?
Most businesses that process personal data do, and it is an annual data protection fee rather than a registration in the old sense. The tiers are £52, £78 and £3,763 a year depending on size and turnover, in force from 17 February 2025, with most small firms on the £52 tier and £5 off for paying by direct debit. Exemptions exist but are narrow, and the common assumption — that a small business with a simple website is exempt — is usually wrong once you hold customer or staff records. Check your position rather than ignore it. Non-payment is the easiest enforcement the ICO does, because they can see exactly who has not paid.
Do I need a data protection officer?
Almost certainly not. A statutory DPO is only required where you are a public authority, where your core activities involve regular and systematic monitoring of people on a large scale, or where they involve large-scale processing of special category or criminal offence data. A normal small business selling to customers and employing staff meets none of those. You still have to comply with everything else, and someone internally should own data protection, but there is no requirement for a formal appointment — and appointing one carries obligations of its own, including genuine independence. We do not act as an appointed DPO for clients.
Is a privacy policy the same as a privacy notice?
In everyday use, yes. The document that matters is the public-facing one telling people what data you collect, why, on what lawful basis, who you share it with, how long you keep it and what rights they have. The name on it is irrelevant. Whether it is true is not. A copied notice describing systems you do not use, retention periods you do not apply and processes you have never tested is worse than useless — it is a set of published promises you are visibly failing to meet, in writing, on your own website. A short, accurate notice beats a long, borrowed one every time.
Can I email my existing customers without consent?
Sometimes, under the soft opt-in in the Privacy and Electronic Communications Regulations. It applies where you obtained the contact details in the course of a sale or negotiations for a sale, you are marketing your own similar products or services, and you gave a simple opt-out at the point of collection and in every message since. Cold-emailing individuals or sole traders you have no relationship with, or a bought-in list, generally needs consent. Corporate subscribers such as limited companies and LLPs are treated more permissively, though UK GDPR fairness rules still apply. Always include a working unsubscribe and honour it promptly, because failing to is the complaint that reaches the ICO.
What do I do if I have a data breach?
Contain it first, then assess the risk to the people affected rather than the embarrassment to you. If there is a risk to their rights and freedoms you must report it to the ICO within 72 hours of becoming aware, and where the risk is high you must also tell the individuals without undue delay. Not every breach is reportable, but you have to be able to make that judgement quickly and record it either way — you are required to keep an internal record of all breaches, including the ones you decide not to report. Write down what happened, what data was involved, who was affected and what you did. A one-page process agreed in advance turns a bad hour into a manageable one.
What is the shortest realistic compliance list for a small business?
Six things. Pay the ICO fee. Publish a privacy notice that describes what you actually do. Write down what personal data you hold, why, on what lawful basis and how long you keep it — a spreadsheet is fine. Put data processing agreements in place with the suppliers who handle data for you, which in practice means your CRM, email platform, accountant and IT provider. Have a process for a subject access request, because you have one month to respond and the first one always arrives at a bad time. And have a breach process. For a normal business that is most of it, and it is a day's work rather than a project.
Can Buzz Legal do this for us?
Yes — the documents and the process. Privacy notices, cookie policies and website terms written to match what your site and systems genuinely do; data processing agreements with your suppliers; a record of what personal data you hold, why and for how long; and a workable subject access request process so the first one does not cause panic. All of that is non-reserved work. What sits outside it: acting as your appointed Data Protection Officer, defending an ICO investigation or enforcement action, which goes to a regulated firm, and security or penetration testing, which is an IT job rather than a legal one.