Data protection has a reputation for being either terrifying or tediously dull, and neither is quite fair. For most small UK firms it boils down to a handful of sensible habits: know what personal information you hold, look after it, be honest with people about how you use it, and have a plan for when something goes wrong. Get those right and you are most of the way there.

This checklist is built for the business owner who does not have a dedicated compliance team — the agency of six, the trades firm with a customer database, the consultancy chasing its first government contract. It walks through what UK GDPR and the Data Protection Act actually ask of you, and what public-sector buyers will want to see before they hand you their citizens' data.

This article is general information, not legal advice. Data protection law is enforced by the Information Commissioner's Office (ICO) and the detail can change. Check the current position at ico.org.uk or take professional advice before making decisions that carry real risk.

Start by knowing what data you actually hold

You cannot protect what you have not mapped. Before anything else, build a simple record of the personal data flowing through your business. It does not need to be a 40-page document — a spreadsheet is fine. For each type of data, note four things: what it is, where it lives, why you have it, and how long you keep it.

A typical small firm is usually surprised by how much there is. Customer contact details in a CRM. Staff records in a payroll system. CVs from a recruitment round you ran 18 months ago. Marketing lists in Mailchimp. CCTV footage. Card details a supplier holds on your behalf. Each of these is a small responsibility, and mapping them turns a vague worry into a concrete to-do list.

If you can answer “what personal data do we hold, and why?” in one clear paragraph, you are already ahead of most businesses your size.

Nail down your lawful basis

Under UK GDPR you need a lawful basis for every use of personal data. There are six, and you do not get to pick whichever sounds nicest — it has to genuinely fit. The common ones for small firms are consent (someone actively opts in), contract (you need the data to deliver what they bought), legal obligation (keeping tax records, say), and legitimate interests (a reasonable business use that does not override the person's rights).

A worked example: a plumbing firm holds a customer's address and phone number to carry out the booked job — that is contract. It keeps the invoice for six years — legal obligation. It emails past customers an annual boiler-service reminder — that is legitimate interests, and the customer can object. Three uses, three bases, all defensible. The mistake is reaching for “consent” for everything, because consent is the hardest basis to maintain and the easiest to get wrong.

Write a privacy notice people can actually read

People have a right to know what you do with their data, and the vehicle for that is a privacy notice (often a privacy policy page on your website). It should cover who you are, what you collect, why, your lawful basis, who you share it with, how long you keep it, and how someone exercises their rights. The ICO publishes a free template that takes the guesswork out of it.

Plain language wins here. A notice written in dense legalese technically ticks the box but fails the spirit of the rule, which is transparency. If a customer cannot understand it, it is not doing its job.

Secure the data — the unglamorous bit that matters most

The single most common cause of a reportable breach is not a sophisticated cyber-attack; it is a human slip. An email sent to the wrong person. A laptop left on a train. A weak password reused across five accounts. Practical security for a small firm looks like this:

  • Turn on multi-factor authentication everywhere it is offered — email, accounting, CRM.
  • Use a password manager so staff are not reusing “Summer2025!” across every login.
  • Encrypt laptops and phones, and keep software updated.
  • Limit access — not everyone needs to see everything.
  • Use bcc for group emails, and double-check the “to” field before sending sensitive files.
  • Back up regularly, and know how you would recover from ransomware.

None of this requires a big budget. Most of it is free or built into tools you already pay for.

Have a breach plan before you need one

If a personal data breach happens and it poses a risk to people, you may have to report it to the ICO within 72 hours of becoming aware. That is not long to be working out who does what. Write a one-page plan now: who gets told internally, who assesses the risk, who decides whether to report, and how you would notify affected people if needed. Keep a simple log of any incidents, even the ones you decide not to report — the ICO expects you to be able to show your reasoning.

Register with the ICO and pay the fee

Most organisations that process personal data must pay an annual data protection fee to the ICO unless a specific exemption applies. For small businesses the fee is modest, and not paying it when you should is an easy, avoidable penalty. Check whether you need to register using the ICO's self-assessment tool, and set a calendar reminder to renew.

What public-sector buyers expect from suppliers

If you bid for government or council work, data protection stops being a private housekeeping matter and becomes a scored requirement. Public bodies are accountable for any data they let you handle, so they push their duties down to you through the contract. Increasingly, tenders ask you to evidence ICO registration, a data protection policy, staff training, and your approach to breaches. Some require a Data Protection Impact Assessment for higher-risk processing, or specific clauses on where data is stored and who can access it.

This is one of those areas where being prepared genuinely wins points. If you are weighing up whether a contract is worth chasing, the data requirements feed straight into a sensible bid or no-bid decision. And if you want to gauge how ready you are for public work overall, Tendarix offers a free procurement-readiness check that flags the compliance gaps buyers care about. You can also search live UK tenders to see how data-handling requirements are worded in real notices for your sector.

A quick start: the 10-minute version

If you do nothing else this week, do these: list the personal data you hold; switch on multi-factor authentication; check your ICO registration; and read your own privacy notice as if you were a customer. Those four steps alone move you from “exposed” to “reasonably covered”, and they make every later improvement easier. For the underlying rules in more depth, our guide to GDPR basics for small businesses is a good companion, and your employment contracts should reference how staff data is handled too.

Frequently asked questions

Does UK GDPR apply to my one-person business?

Almost certainly, yes. The rules apply to anyone processing personal data in the course of business, regardless of size. A sole trader with a customer list is in scope. The obligations scale to your risk — a tiny firm holding ordinary contact details has far less to do than one handling health records — but you are not exempt simply because you are small.

What is the difference between a privacy notice and a data protection policy?

A privacy notice faces outwards: it tells customers and the public what you do with their data. A data protection policy faces inwards: it tells your staff how they must handle data day to day. Public-sector buyers often want to see both, so it is worth having each as a separate, clearly written document.

How much does it cost to comply?

For most small firms, surprisingly little in cash terms. The main fixed cost is the annual ICO fee, which is modest at the lower tier. The bigger investment is time — mapping your data, writing notices and policies, and training staff. Tools you already pay for usually cover the security side, so the cost is more about attention than money.

Data protection is not a one-off project — it is a habit you build into how the business runs. Tackle the checklist a section at a time, keep a record of what you have done, and you will be ready when a buyer asks. When you are, join our plain-English newsletter for practical updates on compliance and winning public-sector work.