Skip to main content

Blog

A UK professional at a desk reviewing a printed UK GDPR compliance document with a pen in hand

UK GDPR Basics for a 10-Person Business in 2026

UK GDPR Basics for a 10-Person Business in 2026

GDPR has been law in the UK since 2018, renamed UK GDPR after Brexit but largely unchanged in substance. Seven years later, a surprising number of small businesses still treat it as something that applies to other people: large companies, healthcare organisations, firms that "really deal with personal data."

If your business has employees, sends marketing emails, manages client records, or uses a CRM, it processes personal data. UK GDPR applies to you. Here is a plain-English breakdown of what you need to have in place.

What "processing personal data" actually means

Personal data is any information that can identify a living individual: name, email address, phone number, IP address, employment records, client records. Processing means doing virtually anything with it: collecting, storing, using, sharing, deleting.

Almost every small business processes personal data in multiple ways daily. The question is not whether GDPR applies but whether your business is doing what it requires.

The six key obligations for a small business

1. Know what data you hold and why

You need a record of what personal data your business holds, where it came from, what you use it for, how long you keep it, and who you share it with. This is called a Record of Processing Activities (ROPA). For a small business it does not need to be complicated: a spreadsheet with one row per data type is sufficient.

2. Have a lawful basis for every use of personal data

You cannot just collect and use people data because it is convenient. Every use needs a legal basis. For most small business uses, the relevant bases are: contract (you need the data to fulfil a contract), legitimate interests (you have a genuine business reason that is not outweighed by the individual rights), or consent (the person has actively opted in).

Marketing emails to people who did not opt in are a common area where small businesses get this wrong. If you are sending marketing to a list purchased from somewhere, or to people who gave you their business card five years ago, you likely do not have a valid lawful basis.

3. Tell people what you do with their data

Your privacy notice explains to customers, staff, and website visitors what data you collect, why, how long you keep it, and their rights. It needs to be accessible (usually on your website) and written in plain English. If you have not reviewed yours since 2018, it probably needs updating.

4. Respond to data subject requests

Individuals have rights under UK GDPR: to see what data you hold about them, to have it corrected, to have it deleted (in certain circumstances), and to object to its use. Requests must be responded to within one month, free of charge. You need a procedure for handling them, even if it is just knowing who in the business would deal with one and how.

5. Keep data secure

Technical security is a GDPR requirement, not just good practice. That means appropriate access controls, encryption of personal data at rest and in transit, MFA on accounts that hold personal data, and secure disposal of data when it is no longer needed. If you store client records in a shared OneDrive folder with no access controls, that is a compliance gap.

6. Report breaches to the ICO

If personal data is lost, stolen, or accessed without authorisation, and if there is a risk to the individuals concerned, you must report it to the Information Commissioner Office (ICO) within 72 hours. This is a hard legal deadline. Most small businesses do not have a breach response procedure. You should have one, even if it is just a simple one-page document.

What the IT side of GDPR compliance looks like

IT plays a direct role in GDPR compliance. From an IT perspective, the key actions are:

  • Ensuring personal data is stored in systems with appropriate access controls
  • Implementing MFA on all accounts that can access personal data
  • Ensuring devices that could hold personal data are encrypted (BitLocker on Windows, FileVault on Mac)
  • Having a process for revoking access when a member of staff leaves
  • Ensuring backups of personal data are handled securely
  • Using a processor agreement with any third party that processes personal data on your behalf

The pragmatic approach

UK GDPR compliance does not require a legal team. A small business needs: a ROPA document, a privacy notice, a breach response procedure, and appropriate technical security. That is a few hours of work to get right, with an annual review to keep it current.

The ICO website has free guidance and templates for small businesses. Start there, and get IT security in order alongside the paperwork.

If you would like to discuss the IT security side of GDPR compliance, get in touch.

Cyber security and compliance support

ClearPath IT Services supports small businesses in Kent, Medway and South East London with practical IT security and compliance.

ClearPath IT Services

Personal, reliable IT support for small businesses across Kent, Medway and South East London.

Clear IT. Sorted.

Get in Touch

Based in Kent, serving businesses across Medway, Dartford, Gravesend, Sidcup, Bexley and South East London.

Call: 0333 360 8308

Visit: 1a Saddington Street, Gravesend, DA12 1ED

Email: This email address is being protected from spambots. You need JavaScript enabled to view it.

Contact me


© 2026 ClearPath IT Services Limited. All rights reserved. | Privacy Policy