The Information Commissioner's Office can fine a UK business up to £17.5 million or 4% of global annual turnover for the most serious data protection failures — and unlike many comparable privacy regimes, UK GDPR applies to every organisation handling personal data, regardless of headcount, turnover, or whether it's a sole trader working from a spare room. The idea that small size buys you an exemption is, according to the ICO itself, one of the most persistent and costly myths in UK data protection — and it's been disproven repeatedly through real enforcement, including a £60,000 fine against a small legal-sector firm in 2025 after a ransomware attack exposed client data.
This guide covers what UK GDPR and the Data Protection Act 2018 actually require of a small business, how the ICO's fine structure really works in practice for organisations far smaller than the household names that make headlines, what's changing under the 2025-2026 Data (Use and Access) Act reforms, and a practical compliance sequence for businesses that haven't yet built a proper data protection program.
A note before we start
This article is general information to help UK small business owners understand the landscape and ask better questions of a data protection solicitor or the ICO — it is not legal advice. UK data protection law is actively evolving through the Data (Use and Access) Act 2025's phased rollout, so confirm current requirements directly with the ICO (ico.org.uk) before relying on any specific detail in this guide as final.
UK GDPR and the Data Protection Act 2018, in Plain Language
After Brexit, the EU's General Data Protection Regulation as it applied in the UK was retained in domestic law as UK GDPR, sitting alongside the Data Protection Act 2018 (DPA 2018), which supplements it with UK-specific detail — exemptions, the framework for law enforcement processing, and the enforcement powers of the regulator. Together they set out the rules for how any organisation collects, stores, uses, and shares personal data belonging to people in the UK. The regulator responsible for enforcement is the Information Commissioner's Office (ICO).
Critically, UK GDPR is no longer simply "EU GDPR with a different regulator." The two regimes started identical but have begun to diverge — most significantly through the Data (Use and Access) Act 2025, covered later in this guide — meaning a business trading both in the UK and the EU may need to track two related but no longer perfectly matching sets of obligations.
No Small Business Exemption — and the ICO Means It
Unlike Australia's private-sector privacy regime, which has historically exempted businesses under a turnover threshold, UK GDPR draws no such line. A single-person consultancy, a five-person café, or a fifty-person accounting firm are all "controllers" or "processors" the moment they handle personal data — customer names and emails, employee records, supplier details — and all of them carry the same fundamental obligations as a multinational, scaled to what's actually "appropriate" for their size and risk.
The ICO's own guidance and enforcement pattern reflect this directly: fines are proportionate to the organisation and its ability to pay, but the underlying legal obligations don't disappear just because a business is small. This is the single biggest misconception UK small business owners carry into a data protection review — assuming "we're too small to matter" is a legal defence rather than simply a factor the ICO weighs in enforcement discretion.
Not sure whether your data handling actually meets UK GDPR's standard?
IT Cares provides remote cybersecurity consulting to businesses navigating exactly this kind of compliance question.
How ICO Fines Actually Work
| Tier | Applies to | Maximum fine |
|---|---|---|
| Standard tier | Less severe infringements (e.g. record-keeping failures, certain procedural breaches) | Higher of £8.7 million or 2% of global annual turnover |
| Higher tier | The most serious infringements (e.g. breaches of core data protection principles, inadequate security leading to a major incident) | Higher of £17.5 million or 4% of global annual turnover |
| PECR (marketing/electronic communications) | Unlawful marketing calls, texts, and emails | Raised to the same £17.5 million/4% ceiling under the DUAA (previously capped at £500,000) |
Because the rule takes the higher of the fixed amount or the percentage, a small business with modest turnover technically still faces the full fixed-amount ceiling on paper — a percentage of a small company's revenue would be tiny, so the fixed floor effectively becomes the applicable maximum. In practice, the ICO has never come close to imposing that on a genuinely small operator; its stated approach is proportionality, weighing what an organisation can reasonably absorb, and it typically works through a resolution process — engagement, corrective action, formal reprimands — before escalating to a monetary penalty against a cooperative small business.
That doesn't mean small businesses are safe from fines. Recent real-world examples tell a more nuanced story:
| Organisation type | What happened | Fine |
|---|---|---|
| Legal sector SME | Ransomware attack exfiltrated 32.4 GB of client data (April 2025) | £60,000 |
| Small marketing firm | 2.6 million unlawful marketing calls | £150,000 |
| Small home services company | 600,000 unlawful marketing calls | £100,000 |
| Small marketing agency | 31,329 unsolicited marketing text messages | £50,000 |
| Large outsourcing firm (context) | Inadequate cybersecurity measures (October 2025) | £14 million |
Total ICO penalties under UK GDPR have accumulated to more than £65 million since 2019, and enforcement in 2025 shifted toward fewer but materially larger actions targeting systemic security failures — a trend that raises the stakes for any business, small or large, that treats data security as an afterthought.
The Data (Use and Access) Act 2025: What's Changing
The Data (Use and Access) Act 2025 (DUAA) received Royal Assent on 19 June 2025. It amends — rather than replaces — UK GDPR, the DPA 2018, and PECR, with implementation phased over roughly a year, with a significant tranche of provisions taking effect on 5 February 2026. The changes most relevant to a small business include:
A seventh lawful basis: "recognised legitimate interests" (RLI)
Alongside the existing six lawful bases for processing, the DUAA introduces a narrower, pre-approved category of legitimate interest (covering things like crime prevention, safeguarding, and certain public-interest processing) that doesn't require the usual balancing test — potentially simplifying compliance for businesses whose processing falls within these specific categories.
Reworked automated decision-making rules
Article 22 of UK GDPR, which restricted solely automated decisions with legal or similarly significant effects, is replaced with four new articles (22A-22D) — a more permissive framework than the old Article 22, but one businesses using automated tools (including many AI-assisted HR or credit decisions) will need to re-map their processes against.
ICO restructured into the "Information Commission"
The DUAA reorganises the regulator's governance structure, moving from a single Information Commissioner to a commission model — a structural change that doesn't alter day-to-day compliance obligations but affects how the regulator makes decisions and issues guidance going forward.
PECR fine cap aligned with UK GDPR
The maximum fine for unlawful direct marketing under PECR rises from £500,000 to the same £17.5 million/4% ceiling as UK GDPR — a substantial increase directly relevant to any small business running email or SMS marketing campaigns without proper consent records.
IT Cares field note
Most small businesses we see underestimate how much of their day-to-day marketing activity — cold email outreach, SMS promotions, even some cookie-consent setups — falls under PECR rather than UK GDPR directly. With the PECR fine ceiling now matching UK GDPR's, treating marketing compliance as a lower priority than "real" data protection is no longer a safe assumption.
Do You Need a Data Protection Officer?
Most small businesses do not need a statutory Data Protection Officer (DPO). A DPO is legally required only where an organisation is a public authority, or where its core activities involve either large-scale systematic monitoring of individuals (e.g. certain ad-tech or tracking-heavy businesses) or large-scale processing of special category data such as health records, biometric data, or criminal records. Outside those triggers, what's actually required is an accountable individual — someone within the business responsible for data protection decisions day to day, which for most SMBs is simply the owner or a designated manager, without the formal independence and direct-reporting-line requirements a statutory DPO carries.
Building a UK GDPR-Compliant Program
Build a record of processing activities
Document what personal data you collect, why, the lawful basis you're relying on, where it's stored, who can access it, and how long you keep it. This single document underpins almost every other obligation.
Write (or update) a clear privacy notice
Tell people, in plain English, what you collect and why, at or before the point of collection — covering your website, booking forms, job applications, and any customer-facing data collection point.
Confirm your lawful basis for each processing activity
Consent, contract necessity, legal obligation, vital interests, public task, or legitimate interests (now joined by the narrower "recognised legitimate interests" category) — pick the one that genuinely applies and document why, rather than defaulting to consent for everything.
Put reasonable security measures in place
Access controls, encryption where practical, multi-factor authentication on business accounts, and a basic patching routine — "appropriate technical and organisational measures" scales with your size and risk, but "we did nothing" is never defensible.
Build a breach response plan with the 72-hour clock in mind
UK GDPR requires notifying the ICO within 72 hours of becoming aware of a breach likely to result in a risk to individuals, and notifying affected individuals without undue delay if the risk is high. A pre-built response plan — who assesses, who decides, who notifies — is the difference between meeting that window and missing it.
Prepare for subject access requests
You have one month to respond to a request for someone's personal data (extendable by up to two more months for complex requests), so knowing where an individual's data actually lives across your systems in advance saves real time under deadline pressure.
Review marketing consent records against PECR
Given the newly aligned PECR fine ceiling, confirm your email/SMS marketing lists have proper, documented consent (or a valid soft opt-in) and that unsubscribe requests are honoured promptly.
Real-World Scenarios
The following are composite, fictional scenarios illustrating common patterns among UK small businesses — not specific real companies.
Scenario: a small independent law firm
A four-partner law firm outside London had never formally documented its lawful basis for processing client data, relying on an informal understanding that "client confidentiality covers it." A cyber insurance renewal application required evidence of a data protection policy and breach response plan, prompting the firm to engage a data protection consultant to build both, alongside basic staff training, for approximately £2,800.
Scenario: a regional recruitment agency
A 15-person recruitment agency had accumulated years of candidate CVs and personal details in shared inboxes with no retention policy or access controls. Following a routine subject access request from a former candidate, the agency discovered it could not efficiently locate all of that person's data across its systems, taking nearly the full three-month extended window to respond. The agency subsequently invested in a proper applicant tracking system with built-in retention rules, at a cost of roughly £3,500 for setup and data migration.
Scenario: an e-commerce retailer running email marketing
A home goods e-commerce business had built its marketing list partly through a "pre-ticked" newsletter signup box on checkout — a practice that doesn't meet UK GDPR's consent standard. After learning about the PECR fine increase under the DUAA, the retailer's founder reviewed and rebuilt its consent flow with an unticked opt-in checkbox and clear unsubscribe options, and ran a re-permission campaign for its existing list, at minimal direct cost but a temporary reduction in list size.
Budget Reality Check
Compliance costs for UK small businesses scale with existing infrastructure and data volume:
- Micro business (under 5 staff, simple data flows): Often achievable in the £800-£2,500 range for a privacy notice, record of processing, and basic breach response plan using templates plus limited professional review.
- Small business (5-30 staff, customer database or marketing lists): Typically lands in the £2,500-£8,000 range, including a data mapping exercise, consent audit, and staff training.
- Larger small business (30+ staff, sensitive data or complex vendor relationships): Can scale into the £8,000-£20,000+ range, particularly where legacy CRM or marketing systems need rebuilding rather than just documenting.
These are directional figures for budgeting conversations, not fixed quotes. Every scenario above shares the same pattern: proactive compliance work costs a fraction of what a post-incident scramble or a reactive response to an ICO enquiry typically costs — and nowhere near the £14 million fines now being handed down for systemic security failures.
UK Government and Regulator Resources
- Information Commissioner's Office (ICO, ico.org.uk): The UK's data protection regulator — guidance, self-assessment tools, and breach reporting.
- National Cyber Security Centre (NCSC, ncsc.gov.uk): Practical security guidance and the Cyber Essentials certification scheme, relevant to meeting UK GDPR's security expectations.
For a certification that demonstrates baseline technical security to customers and government contracts alike, see our companion guide on UK Cyber Essentials certification.
Want a second set of eyes on your data security setup?
IT Cares provides remote cybersecurity consulting and security reviews for businesses outside Canada too — entirely remote, no local office required. We can review your technical safeguards even if the legal sign-off still needs a UK solicitor.
Frequently Asked Questions
Need Help Reviewing Your Data Security Setup?
IT Cares reviews technical safeguards remotely for businesses worldwide — a practical second opinion on your UK GDPR security posture.

Comments (3)
We always assumed being a 6-person business meant GDPR "didn't really apply" to us in practice. This laid it out clearly enough that we're finally writing an actual privacy notice instead of copy-pasting one from a template site.
Didn't know PECR fines had been bumped up to match GDPR. We do a fair bit of email marketing and this is pushing us to actually audit our consent records properly.
The DPO section finally clarified something I've been confused about for ages — we don't need one, we just need someone accountable. Useful distinction that most articles gloss over.
Leave a Comment