Business Services

GDPR basics for small businesses

UK GDPR applies to any business handling personal data, regardless of size — but the practical requirements for a small business are far lighter than the regulation's reputation suggests, provided the basics are in place.

6 min readUpdated Jun 2026
Key points
  • UK GDPR applies to any business handling personal data, whatever its size
  • Collect only what you need, and don't keep it longer than necessary
  • Most businesses need to register with the ICO and pay the data protection fee
  • Notifiable breaches must be reported to the ICO within 72 hours

What counts as personal data

Any information that could identify a living person — customer names, email addresses and even an IP address in some contexts all count.

The core principles

Collect only the data you need, be clear about why you're collecting it, keep it secure, and don't hold it longer than necessary — most compliance follows naturally from these.

Do you need to register with the ICO?

Most businesses processing personal data need to pay the ICO's data protection fee and register, with a small number of exemptions — check the ICO's self-assessment tool if unsure.

Handling a data breach

Notifiable breaches must be reported to the ICO within 72 hours of becoming aware of them — know who's responsible for this before it happens, not after.

Ready to compare?

Get a tailored business services quote in minutes.

Answer a few short questions and we'll match you with UK-regulated providers — no obligation, no phone spam.

Start your comparison