UK GDPR & the Data Protection Act 2018: The Small Business Guide Nobody Is Exempt From

Reviewed by IT Cares · Updated August 2026

Digital shield and padlock over a stylized map of the British Isles, representing UK GDPR and Data Protection Act 2018 compliance for small business
UK GDPR applies regardless of company size — there is no small-business carve-out.
🇬🇧
This guide is general information for UK small businesses, not legal advice. IT Cares supports businesses remotely from Canada and does not operate an office in the UK — for formal compliance sign-off, confirm details with a UK data protection solicitor or the ICO directly.

The Information Commissioner's Office can fine a UK business up to £17.5 million or 4% of global annual turnover for the most serious data protection failures — and unlike many comparable privacy regimes, UK GDPR applies to every organisation handling personal data, regardless of headcount, turnover, or whether it's a sole trader working from a spare room. The idea that small size buys you an exemption is, according to the ICO itself, one of the most persistent and costly myths in UK data protection — and it's been disproven repeatedly through real enforcement, including a £60,000 fine against a small legal-sector firm in 2025 after a ransomware attack exposed client data.

This guide covers what UK GDPR and the Data Protection Act 2018 actually require of a small business, how the ICO's fine structure really works in practice for organisations far smaller than the household names that make headlines, what's changing under the 2025-2026 Data (Use and Access) Act reforms, and a practical compliance sequence for businesses that haven't yet built a proper data protection program.

A note before we start

This article is general information to help UK small business owners understand the landscape and ask better questions of a data protection solicitor or the ICO — it is not legal advice. UK data protection law is actively evolving through the Data (Use and Access) Act 2025's phased rollout, so confirm current requirements directly with the ICO (ico.org.uk) before relying on any specific detail in this guide as final.

UK GDPR and the Data Protection Act 2018, in Plain Language

After Brexit, the EU's General Data Protection Regulation as it applied in the UK was retained in domestic law as UK GDPR, sitting alongside the Data Protection Act 2018 (DPA 2018), which supplements it with UK-specific detail — exemptions, the framework for law enforcement processing, and the enforcement powers of the regulator. Together they set out the rules for how any organisation collects, stores, uses, and shares personal data belonging to people in the UK. The regulator responsible for enforcement is the Information Commissioner's Office (ICO).

Critically, UK GDPR is no longer simply "EU GDPR with a different regulator." The two regimes started identical but have begun to diverge — most significantly through the Data (Use and Access) Act 2025, covered later in this guide — meaning a business trading both in the UK and the EU may need to track two related but no longer perfectly matching sets of obligations.

No Small Business Exemption — and the ICO Means It

Unlike Australia's private-sector privacy regime, which has historically exempted businesses under a turnover threshold, UK GDPR draws no such line. A single-person consultancy, a five-person café, or a fifty-person accounting firm are all "controllers" or "processors" the moment they handle personal data — customer names and emails, employee records, supplier details — and all of them carry the same fundamental obligations as a multinational, scaled to what's actually "appropriate" for their size and risk.

The ICO's own guidance and enforcement pattern reflect this directly: fines are proportionate to the organisation and its ability to pay, but the underlying legal obligations don't disappear just because a business is small. This is the single biggest misconception UK small business owners carry into a data protection review — assuming "we're too small to matter" is a legal defence rather than simply a factor the ICO weighs in enforcement discretion.

Not sure whether your data handling actually meets UK GDPR's standard?

IT Cares provides remote cybersecurity consulting to businesses navigating exactly this kind of compliance question.

How ICO Fines Actually Work

Tier Applies to Maximum fine
Standard tier Less severe infringements (e.g. record-keeping failures, certain procedural breaches) Higher of £8.7 million or 2% of global annual turnover
Higher tier The most serious infringements (e.g. breaches of core data protection principles, inadequate security leading to a major incident) Higher of £17.5 million or 4% of global annual turnover
PECR (marketing/electronic communications) Unlawful marketing calls, texts, and emails Raised to the same £17.5 million/4% ceiling under the DUAA (previously capped at £500,000)

Because the rule takes the higher of the fixed amount or the percentage, a small business with modest turnover technically still faces the full fixed-amount ceiling on paper — a percentage of a small company's revenue would be tiny, so the fixed floor effectively becomes the applicable maximum. In practice, the ICO has never come close to imposing that on a genuinely small operator; its stated approach is proportionality, weighing what an organisation can reasonably absorb, and it typically works through a resolution process — engagement, corrective action, formal reprimands — before escalating to a monetary penalty against a cooperative small business.

That doesn't mean small businesses are safe from fines. Recent real-world examples tell a more nuanced story:

Organisation type What happened Fine
Legal sector SME Ransomware attack exfiltrated 32.4 GB of client data (April 2025) £60,000
Small marketing firm 2.6 million unlawful marketing calls £150,000
Small home services company 600,000 unlawful marketing calls £100,000
Small marketing agency 31,329 unsolicited marketing text messages £50,000
Large outsourcing firm (context) Inadequate cybersecurity measures (October 2025) £14 million

Total ICO penalties under UK GDPR have accumulated to more than £65 million since 2019, and enforcement in 2025 shifted toward fewer but materially larger actions targeting systemic security failures — a trend that raises the stakes for any business, small or large, that treats data security as an afterthought.

The Data (Use and Access) Act 2025: What's Changing

The Data (Use and Access) Act 2025 (DUAA) received Royal Assent on 19 June 2025. It amends — rather than replaces — UK GDPR, the DPA 2018, and PECR, with implementation phased over roughly a year, with a significant tranche of provisions taking effect on 5 February 2026. The changes most relevant to a small business include:

1

A seventh lawful basis: "recognised legitimate interests" (RLI)

Alongside the existing six lawful bases for processing, the DUAA introduces a narrower, pre-approved category of legitimate interest (covering things like crime prevention, safeguarding, and certain public-interest processing) that doesn't require the usual balancing test — potentially simplifying compliance for businesses whose processing falls within these specific categories.

2

Reworked automated decision-making rules

Article 22 of UK GDPR, which restricted solely automated decisions with legal or similarly significant effects, is replaced with four new articles (22A-22D) — a more permissive framework than the old Article 22, but one businesses using automated tools (including many AI-assisted HR or credit decisions) will need to re-map their processes against.

3

ICO restructured into the "Information Commission"

The DUAA reorganises the regulator's governance structure, moving from a single Information Commissioner to a commission model — a structural change that doesn't alter day-to-day compliance obligations but affects how the regulator makes decisions and issues guidance going forward.

4

PECR fine cap aligned with UK GDPR

The maximum fine for unlawful direct marketing under PECR rises from £500,000 to the same £17.5 million/4% ceiling as UK GDPR — a substantial increase directly relevant to any small business running email or SMS marketing campaigns without proper consent records.

IT Cares field note

Most small businesses we see underestimate how much of their day-to-day marketing activity — cold email outreach, SMS promotions, even some cookie-consent setups — falls under PECR rather than UK GDPR directly. With the PECR fine ceiling now matching UK GDPR's, treating marketing compliance as a lower priority than "real" data protection is no longer a safe assumption.

Do You Need a Data Protection Officer?

Most small businesses do not need a statutory Data Protection Officer (DPO). A DPO is legally required only where an organisation is a public authority, or where its core activities involve either large-scale systematic monitoring of individuals (e.g. certain ad-tech or tracking-heavy businesses) or large-scale processing of special category data such as health records, biometric data, or criminal records. Outside those triggers, what's actually required is an accountable individual — someone within the business responsible for data protection decisions day to day, which for most SMBs is simply the owner or a designated manager, without the formal independence and direct-reporting-line requirements a statutory DPO carries.

Building a UK GDPR-Compliant Program

1

Build a record of processing activities

Document what personal data you collect, why, the lawful basis you're relying on, where it's stored, who can access it, and how long you keep it. This single document underpins almost every other obligation.

2

Write (or update) a clear privacy notice

Tell people, in plain English, what you collect and why, at or before the point of collection — covering your website, booking forms, job applications, and any customer-facing data collection point.

3

Confirm your lawful basis for each processing activity

Consent, contract necessity, legal obligation, vital interests, public task, or legitimate interests (now joined by the narrower "recognised legitimate interests" category) — pick the one that genuinely applies and document why, rather than defaulting to consent for everything.

4

Put reasonable security measures in place

Access controls, encryption where practical, multi-factor authentication on business accounts, and a basic patching routine — "appropriate technical and organisational measures" scales with your size and risk, but "we did nothing" is never defensible.

5

Build a breach response plan with the 72-hour clock in mind

UK GDPR requires notifying the ICO within 72 hours of becoming aware of a breach likely to result in a risk to individuals, and notifying affected individuals without undue delay if the risk is high. A pre-built response plan — who assesses, who decides, who notifies — is the difference between meeting that window and missing it.

6

Prepare for subject access requests

You have one month to respond to a request for someone's personal data (extendable by up to two more months for complex requests), so knowing where an individual's data actually lives across your systems in advance saves real time under deadline pressure.

7

Review marketing consent records against PECR

Given the newly aligned PECR fine ceiling, confirm your email/SMS marketing lists have proper, documented consent (or a valid soft opt-in) and that unsubscribe requests are honoured promptly.

Real-World Scenarios

The following are composite, fictional scenarios illustrating common patterns among UK small businesses — not specific real companies.

Scenario: a small independent law firm

A four-partner law firm outside London had never formally documented its lawful basis for processing client data, relying on an informal understanding that "client confidentiality covers it." A cyber insurance renewal application required evidence of a data protection policy and breach response plan, prompting the firm to engage a data protection consultant to build both, alongside basic staff training, for approximately £2,800.

Scenario: a regional recruitment agency

A 15-person recruitment agency had accumulated years of candidate CVs and personal details in shared inboxes with no retention policy or access controls. Following a routine subject access request from a former candidate, the agency discovered it could not efficiently locate all of that person's data across its systems, taking nearly the full three-month extended window to respond. The agency subsequently invested in a proper applicant tracking system with built-in retention rules, at a cost of roughly £3,500 for setup and data migration.

Scenario: an e-commerce retailer running email marketing

A home goods e-commerce business had built its marketing list partly through a "pre-ticked" newsletter signup box on checkout — a practice that doesn't meet UK GDPR's consent standard. After learning about the PECR fine increase under the DUAA, the retailer's founder reviewed and rebuilt its consent flow with an unticked opt-in checkbox and clear unsubscribe options, and ran a re-permission campaign for its existing list, at minimal direct cost but a temporary reduction in list size.

Budget Reality Check

Compliance costs for UK small businesses scale with existing infrastructure and data volume:

These are directional figures for budgeting conversations, not fixed quotes. Every scenario above shares the same pattern: proactive compliance work costs a fraction of what a post-incident scramble or a reactive response to an ICO enquiry typically costs — and nowhere near the £14 million fines now being handed down for systemic security failures.

UK Government and Regulator Resources

For a certification that demonstrates baseline technical security to customers and government contracts alike, see our companion guide on UK Cyber Essentials certification.

Want a second set of eyes on your data security setup?

IT Cares provides remote cybersecurity consulting and security reviews for businesses outside Canada too — entirely remote, no local office required. We can review your technical safeguards even if the legal sign-off still needs a UK solicitor.

Frequently Asked Questions

Is my small business exempt from UK GDPR because we only have a few employees?
No. UK GDPR and the Data Protection Act 2018 apply to any organisation processing personal data of people in the UK, regardless of headcount, turnover, or legal structure — sole traders included. The ICO has repeatedly and explicitly rejected the idea that small size exempts a business, and this remains one of the most common and costly misconceptions among UK SMBs.
What's the difference between UK GDPR and EU GDPR?
UK GDPR is a distinct legal regime that came into being after Brexit — it started as a copy of the EU GDPR retained in UK domestic law, sitting alongside the Data Protection Act 2018, and enforced by the UK's Information Commissioner's Office (ICO) rather than an EU data protection authority. The two regimes have started to diverge, most significantly through the Data (Use and Access) Act 2025, which introduces a new lawful basis for processing and changes automated decision-making rules in ways that don't exist under EU GDPR. A UK business serving only UK customers is governed by UK GDPR; a business also serving EU customers may need to comply with both regimes, which remain broadly similar but no longer identical.
How much can the ICO actually fine a small business?
The formal maximum is up to £8.7 million or 2% of global annual turnover for standard infringements, and up to £17.5 million or 4% of global annual turnover for the most serious ones — the fine is the higher of the fixed amount or the percentage, which for a small business with modest turnover typically means the fixed amount is technically the applicable ceiling even though the ICO would never impose anywhere near that on a small operator in practice. Real-world SME fines have ranged much lower — for example, a legal sector SME was fined £60,000 in 2025 after a ransomware attack exposed client data, and several small businesses have received fines in the £50,000-£150,000 range for unlawful marketing calls and messages under PECR.
Does the ICO actually go after small businesses, or just large corporations?
Both, though the ICO's stated approach favours proportionality — fines are calibrated to what an organisation can reasonably pay, and the regulator typically pursues a resolution process (engagement, corrective action, reprimands) with cooperative small businesses before escalating to a formal penalty. That said, SMEs have received real fines in recent years, particularly for unlawful direct marketing under PECR and for inadequate security following a breach, so "too small to notice" is not a safe assumption.
Do I need to appoint a Data Protection Officer (DPO)?
Most small businesses do not need a statutory DPO. A formal DPO is required only for public authorities, or organisations whose core activities involve large-scale systematic monitoring of individuals, or large-scale processing of special category data (health, biometric, criminal records, etc.). Most SMBs instead need someone accountable for data protection day-to-day — often the owner or a designated manager — without the formal DPO title or its specific independence and reporting requirements.
How long do I have to respond to a subject access request?
One calendar month from receipt, extendable by up to two further months for complex or numerous requests, provided you notify the individual of the extension and the reason within the first month. Most small businesses' biggest practical challenge with subject access requests isn't the legal deadline itself but simply not knowing where all the requested individual's data actually lives across their systems — which is why a basic data map matters well beyond breach response.
What is the Data (Use and Access) Act 2025 and does it affect small businesses?
The DUAA, which received Royal Assent on 19 June 2025, amends (but doesn't replace) UK GDPR, the Data Protection Act 2018, and PECR, with many provisions taking effect in phases through 5 February 2026 and beyond. For small businesses, the most practically relevant changes are a new seventh lawful basis for processing called "recognised legitimate interests" that can simplify some routine processing, updated rules on automated decision-making, and a significant increase to the maximum PECR fine (from £500,000 to the same £17.5 million/4% ceiling as UK GDPR) — relevant to any business doing email or SMS marketing.
What's the single most practical first step for a UK small business?
Write down what personal data you collect, why, where it's stored, and who can access it — a simple record of processing activities. Nearly every other UK GDPR obligation (privacy notices, lawful basis assessments, breach response, subject access requests, DPIAs) becomes dramatically easier once this exists, and its absence is the most common reason small businesses struggle when the ICO or a customer actually asks a specific question about their data handling.

Need Help Reviewing Your Data Security Setup?

IT Cares reviews technical safeguards remotely for businesses worldwide — a practical second opinion on your UK GDPR security posture.

Comments (3)

EW
Emma W., Manchester
August 3, 2026

We always assumed being a 6-person business meant GDPR "didn't really apply" to us in practice. This laid it out clearly enough that we're finally writing an actual privacy notice instead of copy-pasting one from a template site.

JP
James P., Leeds
July 30, 2026

Didn't know PECR fines had been bumped up to match GDPR. We do a fair bit of email marketing and this is pushing us to actually audit our consent records properly.

CO
Chloe O., Bristol
July 27, 2026

The DPO section finally clarified something I've been confused about for ages — we don't need one, we just need someone accountable. Useful distinction that most articles gloss over.

Leave a Comment