- UK GDPR applies to any business handling personal data, whatever its size
- Collect only what you need, and don't keep it longer than necessary
- Most businesses need to register with the ICO and pay the data protection fee
- Notifiable breaches must be reported to the ICO within 72 hours
What counts as personal data
Any information that could identify a living person — customer names, email addresses and even an IP address in some contexts all count.
The core principles
Collect only the data you need, be clear about why you're collecting it, keep it secure, and don't hold it longer than necessary — most compliance follows naturally from these.
Do you need to register with the ICO?
Most businesses processing personal data need to pay the ICO's data protection fee and register, with a small number of exemptions — check the ICO's self-assessment tool if unsure.
Handling a data breach
Notifiable breaches must be reported to the ICO within 72 hours of becoming aware of them — know who's responsible for this before it happens, not after.
Get a tailored business services quote in minutes.
Answer a few short questions and we'll match you with UK-regulated providers — no obligation, no phone spam.
Start your comparison