Running a small company in the UK means handling personal data every single day, from client email addresses to payroll records. Meeting your legal obligations does not require a corporate legal department, but it does require a structured GDPR compliance checklist to keep your procedures audit-ready and defensible.

Here is what UK small business owners need to understand, organise, and implement across their operations.

This checklist is general information, not legal advice, and Ergora is not a law firm. Check current official guidance, and ask a qualified lawyer about anything unusual or high risk, including important supplier contracts.

Understanding UK GDPR and the Data (Use and Access) Act 2025

The core framework governing data handling in the UK is the UK General Data Protection Regulation (UK GDPR), which sits alongside the Data Protection Act 2018. If your UK business collects, stores or uses personal information about customers, staff or anyone else, these rules apply to you.

The regulatory environment continues to evolve. Parliament passed the Data (Use and Access) Act 2025, which amends UK GDPR. Its changes come into force in stages rather than all at once, so expect a series of updates rather than a single overhaul. You can monitor changes and standard interpretations through official UK GDPR guidance and resources published by the Information Commissioner's Office (ICO).

Whatever changes as the Act comes into force, the foundational duties remain: you must handle data lawfully, transparently, and securely.

The Core UK GDPR Checklist for Small Business Operations

To achieve compliance without drowning in administrative overhead, break your duties into practical operational workstreams.

1. Know and Document Your Data

You cannot protect information if you do not know where it lives. Create an internal Record of Processing Activities (ROPA) covering:

  • The types of data collected: Customer contact details, employee payroll data, website visitor IP addresses, or supplier account numbers.
  • The lawful basis for processing: Every data flow needs an identified legal basis, such as contract, legal obligation, legitimate interests or consent.
  • Retention windows: Define clear timeframes for data destruction so information is not kept indefinitely without justification.

2. Publish a Transparent Privacy Notice

Individuals have a legal right to know who is collecting their information and why. Your privacy notice should sit prominently on your website, written in clear, concise English. It must outline what information you process, your lawful bases, retention periods, third-party data sharing, and contact details for handling privacy enquiries.

3. Register with the Regulator

Most organisations that process personal data must pay the ICO data protection fee unless they are exempt. Check the ICO data protection fee guidance to confirm whether your business needs to pay or is exempt.

4. Implement Baseline Security Controls

Data security involves both technical systems and human habits. Ensure all company devices enforce full-disk encryption, strong password managers, and multi-factor authentication (MFA). Restrict internal file access so staff only access records necessary for their immediate roles. Back up critical business data regularly to separate, encrypted storage environments.

5. Review Suppliers and Data Processors

When you use cloud software, outsourced payroll providers, or external marketing agencies, those partners often act as data processors. You need a written contract with each processor that sets out how they must handle the data. Ergora's specialised legal tools can help you review these documents: the Contract Scanner reads a supplier agreement uploaded as a PDF and flags risky or unusual terms, while the Clause Library stores your approved wording. Note that Ergora provides automated assistance rather than legal advice, and unusual or high-risk contracts should always be examined by a qualified solicitor.

6. Manage Data Subject Rights

Individuals have rights regarding their information, including rectification, erasure, and access. When someone asks to see their information, they are using the right of access. You must normally respond to a data subject access request (DSAR) within one month, and the deadline can be extended in some cases.

7. Establish Incident and Breach Response Workflows

A personal data breach involves security incidents leading to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of personal information. Some personal data breaches must be reported to the ICO within 72 hours of becoming aware of them, so you need a way to assess an incident quickly and decide whether it has to be reported. Maintain an internal register of all security incidents, even minor ones that do not meet the notification threshold.

8. Audit Marketing Consent and Cookies

Ensure direct marketing practices comply with both the UK GDPR and the Privacy and Electronic Communications Regulations (PECR). B2B communications operate under different rules from consumer outreach, but you must always provide an easy opt-out mechanism. Check that your website's cookie banner and settings follow the ICO's current guidance on consent for non-essential cookies.

Small Business GDPR Compliance Checklist Table

Use this operational matrix to audit your operational readiness across core business systems.

Task Why it matters Done (Yes / No)
Information Audit Document data sources, processing purposes, and retention limits
Lawful Basis Log Map each processing activity to a lawful basis
Privacy Policy Publish an accessible, plain-English notice on all public portals
ICO Registration Pay the ICO data protection fee or confirm you are exempt
Security Protocols Enforce device encryption, MFA, and access segmentation
Processor Agreements Put written data processing contracts in place with every supplier that handles personal data for you
DSAR Procedures Set up a written procedure to answer subject access requests, normally within one month
Breach Protocol Define steps to identify and contain incidents, and report breaches to the ICO within 72 hours where required
Marketing Review Audit email lists and website cookie banners for valid permissions

Using Dedicated Software to Manage Data Obligations

For a small team, tracking regulatory obligations on paper or disconnected spreadsheets invites missed deadlines. Software can keep these compliance tasks visible with less manual effort.

Centralising your procedures helps stop things slipping through the cracks. Ergora's Compliance area holds GDPR, SOC 2 and ISO checklists, so you can work through the tasks above in one place. When customers or employees exercise their rights, the DSAR Tracker logs each subject access request and its deadline, so you can see which responses are due and answer them on time.

Pairing structured internal tracking with established internal protocols keeps lean businesses organised, accountable, and aligned with UK privacy standards.

Maintaining Defensible Data Practices

Data protection is an ongoing business practice rather than a one-time project. As your business introduces new software, hires team members, or launches marketing campaigns, review your processes against this GDPR checklist.

Schedule an operational review twice a year to update vendor agreements, audit user access lists, and refresh training. Demonstrating regular attention to personal data security protects your reputation and reduces the risk of regulatory action.

Frequently asked questions

What does a small business need to do to comply with GDPR?

A small business must identify what personal data it handles, document a lawful basis for processing it, and publish an accurate privacy notice. The company must also secure data with appropriate technical controls, put data processing contracts in place with suppliers that handle personal data for it, pay the ICO data protection fee unless exempt, and set up procedures to answer subject access requests and report breaches where required.

Does my small business need to pay the ICO fee?

Most organisations that process personal data must pay the ICO data protection fee unless they are exempt. Some processing is exempt, so check the ICO's data protection fee guidance to confirm whether your business needs to pay.

How long do I have to respond to a subject access request?

You must normally respond to a subject access request within one month of receiving it. The deadline can be extended in some cases, so check the ICO's right of access guidance before relying on an extension.

When do I have to report a data breach?

Some personal data breaches must be reported to the ICO within 72 hours of becoming aware of them. Not every breach has to be reported, so assess each incident quickly, record it either way, and use the ICO's guidance to decide whether it meets the threshold.

Does GDPR still apply in the UK?

Yes, GDPR still applies in the UK through the retained framework known as the UK GDPR, working alongside the Data Protection Act 2018. Following the UK's departure from the European Union, the domestic regime operates under UK jurisdiction and is enforced by the Information Commissioner's Office. The Data (Use and Access) Act 2025 is amending it in stages.

What is the Data (Use and Access) Act 2025?

The Data (Use and Access) Act 2025 is UK legislation that amends UK GDPR. Its changes come into force in stages rather than all at once, so check the ICO's current guidance to see which changes affect your business now.