Data & Compliance

GDPR for small businesses: a plain-English guide

GDPR sounds daunting, but for a small business it comes down to a handful of sensible duties. Here’s the plain-English version.

Greater Manchester & UK-wide · free, no-obligation advice

Why Foresight

  • Cyber Essentials Plus certified
  • Supporting 130+ organisations since 2006
  • We reply within one working hour
  • Plain-English, no jargon

Quick answer

GDPR (and the UK Data Protection Act 2018) is the law on handling personal data. For a small business it boils down to: only collect the personal data you need, keep it secure, be clear with people about how you use it, let them access or delete it on request, and report serious data breaches to the ICO within 72 hours. You also need to be registered with the ICO — most businesses handling personal data must pay a small annual data-protection fee. Good security — MFA, backups, access control, Cyber Essentials — is a big part of “keeping it secure”.

Your key duties

What GDPR asks of a small business

DutyWhat it means in practice
Collect only what you needDon’t hoard personal data “just in case”
Keep it secureProtect it with access control, MFA, backups and good security
Be transparentA clear privacy notice telling people how you use their data
Honour people’s rightsLet people access, correct or delete their data on request
Report serious breachesTell the ICO within 72 hours if a breach risks people’s rights

Don’t forget

ICO registration

Most businesses that handle personal data must register with the ICO and pay a small annual data-protection fee. It’s a legal requirement and easy to overlook.

Security is half the battle

Compliance and protection go together

A huge part of GDPR is simply keeping personal data secure — which is exactly what good IT security delivers. Cyber Essentials, MFA, tested backups and proper access control don’t just protect you from attacks; they’re core to demonstrating you take data protection seriously. See our data protection services.

This is general guidance, not legal advice. For specific obligations, check the ICO’s guidance or speak to a data-protection specialist.

FAQs

Common questions

Does GDPR apply to small businesses?
Yes. GDPR and the UK Data Protection Act apply to any business that handles personal data, regardless of size — though what’s expected is proportionate to your size and the data you hold.
What are my main GDPR duties?
Collect only the personal data you need, keep it secure, be transparent about how you use it, honour people’s rights to access and deletion, and report serious breaches to the ICO within 72 hours.
Do I need to register with the ICO?
Most businesses that process personal data must register with the ICO and pay a small annual data-protection fee. It’s a legal requirement that’s easy to miss.
What happens if I have a data breach?
If it risks people’s rights and freedoms, you must report it to the ICO within 72 hours of becoming aware, and sometimes tell the affected people too. Having a plan and good security makes this far easier.
How does cyber security relate to GDPR?
Keeping personal data secure is a core GDPR requirement. Good security — Cyber Essentials, MFA, backups and access control — directly supports compliance and reduces breach risk.

Confident your data is handled properly?

We’ll help you secure personal data and demonstrate you take protection seriously. See our data protection services.