Understanding Data Protection Duties for Small Businesses

Image

Data protection applies to you, even if you are a team of one

There is a stubborn myth among small business owners that data protection is something for banks, hospitals and large online retailers to worry about. It is not. If you hold a customer's name and phone number, keep payroll records, run a mailing list, store CCTV footage or take card payments, you are processing personal data — and the UK GDPR and the Data Protection Act 2018 apply to you just as they do to a much larger organisation.

The good news is that the rules are built around principles rather than bureaucracy. You are expected to handle information lawfully, keep only what you need, store it securely, use it only for the reasons you told people about, and be able to show you are doing so. A sole trader with a tidy filing system can be just as compliant as a company with a legal department. What matters is that your habits are deliberate rather than accidental.

Know what you hold and why

You cannot protect information you have not accounted for. Start with a simple inventory: list the categories of personal data you collect, where each one lives, and the reason you need it. That might be a customer database, an accounting package, a diary app, a shared inbox, a box of paper invoices in the cupboard, or a WhatsApp group with your staff.

For each item, you should be able to answer two questions. First, what is your lawful basis for holding it? Most routine customer data rests on contract (you need the address to deliver the order) or legitimate interests (you need the email to answer an enquiry). Marketing emails usually need consent, which must be freely given, specific and easy to withdraw. Second, how long do you need it? A useful rule is to set a retention period for each category and actually delete things when the period ends.

  • Customer contact details: keep while the relationship is active, plus a defined period for tax and warranty purposes.
  • Job applicant records: usually a few months after the decision, longer only with a clear reason.
  • Payroll and tax records: statutory periods apply, typically six years.
  • Marketing lists: until the person withdraws consent or stops engaging.

Be transparent about what you do with it

People are entitled to know what happens to their information. A short privacy notice on your website, and a matching paragraph on your enquiry forms and contracts, covers most of this. It does not need to be written in legal jargon. Plain English that explains what you collect, why, who you share it with, how long you keep it, and how someone can complain is far more useful than a wall of borrowed text.

Watch the details. If you use an accountant, a cloud booking system, an email marketing platform or a courier, those organisations are likely to be processors acting on your instructions, and you should have a written agreement with them. If you send data overseas, check that the transfer is covered by an approved safeguard. Small print matters here more than most owners expect.

Keep information secure in daily operations

Most breaches involving small businesses are mundane rather than dramatic: a lost laptop, a misdirected email, a shared password, a phishing message that looked convincing. Security does not have to be expensive, but it does have to be consistent.

  • Use unique passwords and two-factor authentication on email, banking and any system holding customer data.
  • Encrypt laptops and phones, and set automatic screen locks.
  • Train everyone to check the recipient before hitting send, and to query unusual payment requests by phone.
  • Keep paper records in a locked cabinet and shred them when they are no longer needed.
  • Give staff access only to the data they genuinely need to do their job, and remove it promptly when they leave.

Special category data — health details, ethnicity, religious beliefs, trade union membership, biometrics — deserves extra care. If you handle it, you need a specific condition for doing so and tighter controls around who can see it.

Be ready to respond when someone asks, or something goes wrong

Individuals have rights you must honour. The most common request is a subject access request, where someone asks for a copy of the data you hold about them. You must respond within one month, and you normally cannot charge a fee. People can also ask you to correct inaccurate information, delete data, or stop using it for marketing. Having a named person responsible for handling these requests, and a simple log of what came in and when, keeps you calm when one arrives.

If personal data is lost, stolen or disclosed in error, you need to assess the risk. Where the breach is likely to result in a risk to people's rights and freedoms, you must report it to the Information Commissioner's Office within 72 hours of becoming aware of it. If the risk is high, you must also tell the individuals affected. Recording near-misses and minor incidents internally is good practice, even when reporting is not required.

Make good practice part of how you work

Compliance is not a one-off project. Build it into your routines: review your data inventory once a year, check your privacy notice when you change suppliers, and include data protection in staff inductions. Most businesses that need to register with the ICO pay a modest annual fee, and the process is straightforward.

If it all feels daunting, start small. Pick one area — your customer database, perhaps — and work through the questions above. Then move to the next. Handled steadily, data protection becomes what it should be: a natural part of running a business that people trust with their details.

About Author Graphic Designer

Centric Associates No rushing, no fuss — just thoughtful notes and practical help, written by people who care.

Showing 16 verified guest comments

0123456789 image

Soldman Kell

April 25, 2019 at 10:46 am

"The worst hotel ever"

Take in the iconic skyline and visit the neighbourhood hangouts that you've only ever seen on TV. Take in the iconic skyline and visit the neighbourhood.

image

Burson Lesson

April 25, 2019 at 10:46 am

"Was too noisy and not suitable for business meetings"

Take in the iconic skyline and visit the neighbourhood hangouts that you've only ever seen on TV. Take in the iconic skyline and visit the neighbourhood.

Write a Review

Subscribe To Our Newsletter

Want to be notified when we launch a new template or an udpate. Just sign up and we'll send you a notification by email.

Night
Day