Guide

GDPR Compliance Checklist for Small Businesses (UK)

26 September 2026

This is a practical starting checklist, not legal advice. UK GDPR (and EU GDPR, if you handle any EU clients' data) applies to almost any business that holds client names, emails, or other personal data, regardless of size. The ICO (the UK's data protection regulator) expects proportionate measures, not the same programme a bank would run, but “we're small” is not itself a defence.

1. Know what data you hold, and why

List the personal data your business actually collects (client names, contact details, case files, payment details) and have a genuine, lawful reason for holding each category. This is the basis everything else builds on: you can't secure or govern data you haven't mapped.

2. Have a privacy notice, and mean it

A privacy notice on your website should say, honestly, what data you collect, why, how long you keep it, and who it might be shared with (a payroll provider, an accountant, a cloud host). A copy-pasted generic template that doesn't reflect what you actually do is a liability, not a shield.

3. Know your lawful basis for each use

UK GDPR requires a lawful basis for processing personal data, most commonly consent, a contract with the individual, or a legitimate interest you've genuinely weighed against their rights. If you can't name the basis for a given use of data, that's a gap worth closing before it's ever tested.

4. Be able to act on individual rights

People have the right to ask what data you hold on them, to have it corrected, and in many cases to have it erased. You need a real process for this, even if it's simple: who receives the request, how you verify identity, and how quickly you respond (typically within one month under UK GDPR).

5. Have a breach response plan, before you need one

Notifiable data breaches generally need to be reported to the ICO within 72 hours of becoming aware of them. Deciding your process (who assesses the breach, who reports it) after a breach has already happened is a bad position to be in. A one-page written plan is enough to start.

6. Check your processors and suppliers

Any third party that processes personal data on your behalf (a CRM, an email marketing tool, a bookkeeper) needs a data processing agreement in place, and you remain responsible for their handling of that data. “They're a big, well-known company” is not a substitute for actually checking this.

7. Match your security to the risk

GDPR's Article 32 requires “appropriate technical and organisational measures”, which in practice means things like keeping software and plugins updated, using HTTPS, setting sensible access controls, and not leaving obviously outdated systems (an end-of-life CMS, unpatched known vulnerabilities) exposed. This is the point where GDPR compliance and basic website security overlap directly.

Not sure where your exposure actually is?

The Proxaim Triptique includes a GDPR / Garante compliance grade alongside a real security scan, so you see the technical gaps as well as the paperwork ones.

Check your site free