The thing about UK GDPR compliance for small businesses is that most of the attention goes to the dramatic end — big fines, data breaches, names in the news. What gets less attention is the more mundane enforcement activity that the ICO increasingly directs at businesses that simply haven’t got basic processes documented.
You probably have a privacy policy on your website. You might even have done some GDPR training with your team a few years ago. But do you have a documented procedure for what happens when someone complains about how you’ve handled their data? Do you have a written record of what personal data you hold and why? Is there a named person responsible for data protection decisions?
If any of those questions made you pause, here’s a practical rundown of what’s actually required — and what the ICO is looking for when they investigate.
The Basics That Every Business Needs
A data processing record (Record of Processing Activities, or ROPA) — this is essentially a list of what personal data you hold, where it came from, what you use it for, and who you share it with. It doesn’t need to be a complex document. A spreadsheet with rows for each category of data (customer contact details, employee payroll information, marketing email list, etc.) and columns for purpose, legal basis, retention period, and third-party processors is perfectly adequate. You’re required to maintain this under Article 30 of UK GDPR, and the ICO may request it during an investigation.
A lawful basis for each processing activity — for every category of personal data you process, you need to have a legal reason. For most customer data, it’s either contract (you need the data to deliver what they paid for) or legitimate interests. For marketing, it’s usually consent. For employee data, it’s a combination of contract and legal obligation. You don’t need a lawyer to work this out, but you do need to have thought it through and documented it.
A privacy notice that tells people what you do with their data — most businesses have a website privacy policy, but it often hasn’t been updated since it was first created. Review yours against your actual current processing activities. If you’ve added a new CRM, changed how you use marketing data, or started using any new tools that process customer information, the notice needs to reflect that.
A procedure for responding to data subject requests — under UK GDPR, individuals have the right to request access to their data (Subject Access Request), ask for it to be deleted, correct inaccuracies, or object to certain uses. You have one month to respond. The ICO receives complaints from members of the public fairly frequently about businesses that simply don’t respond to these requests. Having a simple documented process — who receives the request, how you verify identity, where you look for the data, who signs off the response — keeps you on the right side of this.
The Complaint Handling Gap
One area where many small businesses are undercooked: a formal internal process for handling data protection complaints. This is distinct from a general customer complaints procedure. When someone says “I think you’ve handled my data improperly,” there needs to be a clear internal path for how that gets investigated and responded to.
That process doesn’t need to be elaborate. A one-page document that answers:
- Who receives and logs data protection complaints (usually whoever handles data protection generally)
- How you’ll acknowledge receipt (within 72 hours is reasonable)
- How you’ll investigate — who gets involved, what records you’ll check
- How you’ll respond — the timeframe and what the response will include
- How you’ll escalate if the complaint has merit (reporting to the ICO where required)
The ICO can request this kind of documentation when investigating a complaint against your business. Not having it is a compliance gap; having it shows you take your obligations seriously.
What About a Data Protection Officer?
Most small businesses don’t need a formal Data Protection Officer (DPO). The requirement only applies to public authorities, organisations that do large-scale systematic monitoring of individuals, or those that process special categories of data (health data, criminal records, biometric data) at scale.
What you do need is someone who is responsible for data protection in practice — someone who fields requests, makes decisions about new processing activities, and is the point of contact if the ICO gets in touch. That can be you, a senior employee, or an external consultant used part-time. The key is that it’s a named person with documented responsibility, not just a vague intention that everyone is responsible.
A Quick Practical Checklist
If you’re doing a compliance check today:
- Review your ROPA — if you don’t have one, create a basic version now
- Check your privacy policy is current and accurate
- Make sure there’s a named individual responsible for data protection decisions
- Draft a simple data subject request procedure if you don’t have one
- Add a data protection complaint process to your internal documentation
- Check your data retention periods are realistic and that you’re actually deleting data you no longer need (most businesses hold on to things far longer than they need to)
- Review any third-party processors you use (payroll, CRM, email marketing) — you should have Data Processing Agreements in place with any that process personal data on your behalf
None of this requires a solicitor for most small businesses. The ICO’s website has free templates and guidance specifically aimed at small organisations, and their self-assessment tool is genuinely useful. Fair enough, it takes a few hours — but it’s the kind of paperwork that sits quietly doing its job until you actually need it.
If the ICO Gets in Touch
An ICO investigation doesn’t automatically mean a fine. The majority of investigations into small businesses result in advisory letters rather than penalties — provided you can demonstrate that you’ve made a reasonable effort to understand and fulfil your obligations. Having documented processes and records, even imperfect ones, shows good faith.
What tends to attract harsher outcomes is a total absence of any data protection measures combined with a significant harm to individuals. A business that can show they have a ROPA, a privacy policy, and a complaint procedure — even if those aren’t perfect — is in a much better position than one that has nothing.
The ICO’s small business guidance is at ico.org.uk. The self-assessment questionnaire there takes about 20 minutes and will flag the gaps most relevant to your situation.