
UK GDPR Basics for a 10-Person Business in 2026
UK GDPR Basics for a 10-Person Business in 2026
GDPR has been law in the UK since 2018, renamed UK GDPR after Brexit but largely unchanged in substance. Seven years later, a surprising number of small businesses still treat it as something that applies to other people: large companies, healthcare organisations, firms that "really deal with personal data."
If your business has employees, sends marketing emails, manages client records, or uses a CRM, it processes personal data. UK GDPR applies to you. Here is a plain-English breakdown of what you need to have in place.
What "processing personal data" actually means
Personal data is any information that can identify a living individual: name, email address, phone number, IP address, employment records, client records. Processing means doing virtually anything with it: collecting, storing, using, sharing, deleting.
Almost every small business processes personal data in multiple ways daily. The question is not whether GDPR applies but whether your business is doing what it requires.
The six key obligations for a small business
1. Know what data you hold and why
You need a record of what personal data your business holds, where it came from, what you use it for, how long you keep it, and who you share it with. This is called a Record of Processing Activities (ROPA). For a small business it does not need to be complicated: a spreadsheet with one row per data type is sufficient.
2. Have a lawful basis for every use of personal data
You cannot just collect and use people data because it is convenient. Every use needs a legal basis. For most small business uses, the relevant bases are: contract (you need the data to fulfil a contract), legitimate interests (you have a genuine business reason that is not outweighed by the individual rights), or consent (the person has actively opted in).
Marketing emails to people who did not opt in are a common area where small businesses get this wrong. If you are sending marketing to a list purchased from somewhere, or to people who gave you their business card five years ago, you likely do not have a valid lawful basis.
3. Tell people what you do with their data
Your privacy notice explains to customers, staff, and website visitors what data you collect, why, how long you keep it, and their rights. It needs to be accessible (usually on your website) and written in plain English. If you have not reviewed yours since 2018, it probably needs updating.
4. Respond to data subject requests
Individuals have rights under UK GDPR: to see what data you hold about them, to have it corrected, to have it deleted (in certain circumstances), and to object to its use. Requests must be responded to within one month, free of charge. You need a procedure for handling them, even if it is just knowing who in the business would deal with one and how.
5. Keep data secure
Technical security is a GDPR requirement, not just good practice. That means appropriate access controls, encryption of personal data at rest and in transit, MFA on accounts that hold personal data, and secure disposal of data when it is no longer needed. If you store client records in a shared OneDrive folder with no access controls, that is a compliance gap.
6. Report breaches to the ICO
If personal data is lost, stolen, or accessed without authorisation, and if there is a risk to the individuals concerned, you must report it to the Information Commissioner Office (ICO) within 72 hours. This is a hard legal deadline. Most small businesses do not have a breach response procedure. You should have one, even if it is just a simple one-page document.
What the IT side of GDPR compliance looks like
IT plays a direct role in GDPR compliance. From an IT perspective, the key actions are:
- Ensuring personal data is stored in systems with appropriate access controls
- Implementing MFA on all accounts that can access personal data
- Ensuring devices that could hold personal data are encrypted (BitLocker on Windows, FileVault on Mac)
- Having a process for revoking access when a member of staff leaves
- Ensuring backups of personal data are handled securely
- Using a processor agreement with any third party that processes personal data on your behalf
The pragmatic approach
UK GDPR compliance does not require a legal team. A small business needs: a ROPA document, a privacy notice, a breach response procedure, and appropriate technical security. That is a few hours of work to get right, with an annual review to keep it current.
The ICO website has free guidance and templates for small businesses. Start there, and get IT security in order alongside the paperwork.
If you would like to discuss the IT security side of GDPR compliance, get in touch.
Cyber security and compliance support
ClearPath IT Services supports small businesses in Kent, Medway and South East London with practical IT security and compliance.