If your business collects names, email addresses, phone numbers, or any other personal data, you must comply with the UK GDPR and the Data Protection Act 2018. There are no exemptions based on business size.
The 7 principles
Every data processing activity must comply with these principles:
- Lawfulness, fairness, and transparency - Have a lawful basis, be fair, and tell people what you're doing with their data
- Purpose limitation - Only use data for the specific purpose you collected it for
- Data minimisation - Don't collect more data than you need
- Accuracy - Keep data accurate and up to date
- Storage limitation - Don't keep data longer than necessary
- Integrity and confidentiality - Keep data secure
- Accountability - Be able to demonstrate your compliance
Lawful bases for processing
You need at least one lawful basis for every type of processing:
- Consent - The individual has given clear consent (must be freely given, specific, informed, and unambiguous)
- Contract - Processing is necessary to fulfil a contract
- Legal obligation - You're required by law to process the data
- Vital interests - To protect someone's life
- Public task - For official functions or tasks in the public interest
- Legitimate interests - You have a legitimate reason that doesn't override the individual's rights
Data breach reporting
If you suffer a personal data breach, you must:
- Assess the risk - Could it result in harm to individuals?
- Report to the ICO within 72 hours if there's a risk to individuals' rights and freedoms
- Notify affected individuals without undue delay if there's a high risk
- Document everything - Even breaches you don't report must be documented internally
Individual rights
Under UK GDPR, individuals have the right to: - Access their data (Subject Access Request - you have 1 month to respond) - Have inaccurate data corrected - Have their data erased ("right to be forgotten") - Restrict processing - Data portability - Object to processing
Practical steps for SMEs
- Map your data - Know what personal data you hold and why
- Write a privacy notice - Tell people how you use their data
- Review your consent mechanisms - Pre-ticked boxes don't count
- Implement security measures - Encryption, access controls, regular backups
- Train your staff - Everyone who handles personal data needs to know the rules
- Appoint a DPO if required - Mandatory for public bodies and large-scale processing
- Register with the ICO - Most organisations that process personal data must pay the data protection fee (from £40/year)