UK GDPR and the Data Protection Act 2018 apply to almost every business that holds personal information about customers, staff or suppliers, whatever its size. If your business collects names, email addresses, employee records or any other personal data, and nearly all businesses do, you have specific legal duties around how that data is collected, used, stored and deleted, and the penalties for getting it wrong can run into millions of pounds. As data protection solicitors acting for SMEs and owner-managed businesses across the UK, the question we are asked most often is not whether GDPR applies, but what it actually requires in day-to-day practice.

The framework has also just changed. The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025 and reforms, rather than replaces, UK GDPR and the Data Protection Act 2018. A significant tranche of its provisions came into force on 5 February 2026, with further changes, including a new right for individuals to complain directly to organisations, taking effect from 19 June 2026. Both dates have now passed, so most of the reformed regime is live. This guide sets out what the current law requires, what has changed, and how our regulatory compliance team can help you comply without over-engineering it.

Business owner reviewing a data protection policy document in a modern UK office

Do You Need to Register With the ICO?

Most organisations that process personal data must register with the Information Commissioner’s Office (ICO) and pay an annual data protection fee. The fee is tiered by turnover and staff numbers, and the tier you fall into is worth checking properly, since paying the wrong amount, or not registering at all, is itself an enforcement risk that catches out a surprising number of otherwise compliant SMEs.

TierAnnual feeWho it applies to
Tier 1 (micro)£52Maximum turnover of £632,000, or no more than 10 staff
Tier 2 (small and medium)£78Maximum turnover of £36 million, or no more than 250 staff
Tier 3 (large)£3,763Turnover or staff numbers above the Tier 2 thresholds

Staff numbers are calculated as the average number of people working for you during your financial year, including employees, workers, office holders and partners, with part-time staff counted the same as full-time. Charities pay the Tier 1 fee regardless of their size, as do small occupational pension schemes, and a small number of not-for-profit organisations that process data only for their own members or regular supporters are exempt from the fee altogether. Paying by direct debit gets you an automatic £5 discount.

Your Core Obligations Under UK GDPR and the Data Protection Act 2018

Registration is only the starting point. Beyond that, every business handling personal data needs to be able to show, not just assert, that it is complying with the law. In practice, that means:

  • A lawful basis for every use of personal data, whether that is consent, a contract with the individual, a legal obligation, or your legitimate interests, recorded and ready to justify if challenged.
  • A record of processing activities setting out what personal data you hold, why, where it came from, who you share it with, and how long you keep it.
  • Data protection impact assessments for any processing likely to result in a high risk to individuals, such as large-scale monitoring or processing special category data (health, biometric or similar sensitive information).
  • Data processing agreements with every supplier or contractor that handles personal data on your behalf, from your payroll provider to your marketing agency.
  • Appropriate technical and organisational security measures, proportionate to the risk, covering everything from access controls to how quickly you can detect and contain a breach.
  • A privacy policy that reflects what you actually do, not a generic template, since the ICO’s own enforcement history shows a mismatch between a privacy notice and real practice is one of the easiest infringements to establish.

This applies whichever side of a data relationship you sit on. Many of our SME clients are simultaneously a data controller for their own customer and staff records and a data processor for a client whose data they handle under contract, and the obligations, and the contractual protections worth negotiating, differ depending on which hat you are wearing on a given piece of processing.

The Data (Use and Access) Act 2025: What Has Changed

The Data (Use and Access) Act 2025 is the most significant reform to UK data protection law since the Data Protection Act 2018. It amends UK GDPR and the Data Protection Act 2018 rather than replacing them, but several of the changes are practical enough to affect how SMEs handle data day to day:

  • A new right to complain directly to organisations, in force from 19 June 2026. Individuals can now raise a data protection complaint with you before going to the ICO, and you must acknowledge it within 30 days and take appropriate steps to resolve it without undue delay.
  • A narrower restriction on automated decision-making. The strict prohibition on solely automated decisions now applies only to significant decisions based on special category data. Other automated decisions are permitted, but you still need safeguards such as transparency about the decision and a way for the individual to challenge it.
  • New cookie consent exemptions for limited categories such as basic website statistics and cookies that remember display preferences, though you must still offer a clear, no-cost opt-out for these.
  • Higher penalties under the Privacy and Electronic Communications Regulations (PECR), the rules governing electronic marketing and cookies, now aligned with the same maximum fine levels as UK GDPR rather than the previous, much lower cap.
  • A “recognised legitimate interests” category for specific purposes such as safeguarding and crime prevention, which reduces the need for a full legitimate interests assessment in those narrow circumstances.

None of this reduces your underlying obligations. If anything, the new direct complaints route means individuals are more likely to raise an issue with you first, and having a clear, working complaints process is now a practical necessity rather than good practice.

Three colleagues at an SME reviewing a data protection compliance issue together on a laptop

Responding to Subject Access Requests

Anyone whose personal data you hold can ask what data you have about them and how it is used. You must respond without undue delay and within one calendar month of receiving the request. That deadline can be extended by a further two months where the request is complex or you have received a number of requests from the same person, but if you rely on the extension you must tell the requester and explain why within the first month, not simply let the deadline slip. The clock also pauses if you reasonably need to ask the requester to clarify what they want, resuming the day after they respond.

Businesses that treat subject access requests as an occasional administrative task, rather than a process someone owns, are the ones that miss the deadline. A short internal procedure, covering who logs a request the day it arrives and who is responsible for the search, avoids most of the risk. For a sector-specific example of how demanding this can get in practice, our guide to handling DSARs in GP practices covers the same one-month clock in an environment with particularly high request volumes.

Data Breaches: Reporting Duties and Timelines

If a personal data breach is likely to result in a risk to individuals’ rights and freedoms, you must report it to the ICO without undue delay and, in any event, within 72 hours of becoming aware of it. That clock starts when you discover the breach, not when it happened, so an incident that occurred weeks earlier but was only just found still has to be reported within 72 hours of discovery. Where the initial 72-hour report cannot include everything, the ICO expects you to report what you know and follow up with further detail rather than delaying the first notification.

Where the breach is likely to result in a high risk to the individuals affected, such as a realistic risk of identity theft or significant distress, you must also notify those individuals directly, without undue delay. A low-risk incident, such as a misdirected email that was recalled and confirmed deleted, will not usually meet that threshold, but the assessment needs to be made and documented in every case, not assumed.

Do You Need a Data Protection Officer?

You are legally required to appoint a Data Protection Officer (DPO) if any of the following applies to your organisation as a controller or a processor:

  • You are a public authority or body (other than a court acting in its judicial capacity).
  • Your core activities involve regular and systematic monitoring of individuals on a large scale, such as behavioural tracking or profiling.
  • Your core activities involve large-scale processing of special category data, or data relating to criminal convictions and offences.

“Core activities” means the processing that is central to what your organisation actually does, not incidental administrative processing such as running payroll. Most SMEs will not meet this threshold and are not legally required to appoint a DPO, but many still choose to designate someone internally, backed by clear HR policies on data handling, or use an outsourced data protection lead, so that GDPR compliance has a clear owner rather than sitting with whoever happens to notice a problem first. Getting this appointment wrong carries its own risks, as we set out in our guide on the risks of getting a DPO appointment wrong.

The Cost of Getting It Wrong: ICO Fine Tiers

UK GDPR and the Data Protection Act 2018 set out two tiers of maximum fine, and it is worth understanding the scale involved even though the largest fines are reserved for the most serious cases.

TierMaximum fineTypical trigger
Standard maximum£8.7 million, or 2% of global annual turnover if higherMore administrative infringements, such as failing to keep adequate records, failing to carry out a required impact assessment, or failing to report a breach on time
Higher maximum£17.5 million, or 4% of global annual turnover if higherBreaches of the core data protection principles, such as processing personal data without a lawful basis, or failing to respect individuals’ rights

The percentage-based figure only comes into play for very large organisations, since it only exceeds the fixed amount once global turnover passes roughly £435 million (standard tier) or £437.5 million (higher tier). For the overwhelming majority of SMEs, the practical risk is the fixed maximum, which is still a figure large enough to end a smaller business, alongside the reputational damage of a public ICO enforcement notice.

A Practical GDPR Compliance Checklist

  • Confirm your ICO registration is current and you are paying the correct fee tier.
  • Keep a record of processing activities and review it at least annually, or whenever you start using data in a new way.
  • Make sure your privacy policy matches what you actually do with personal data, not a generic template.
  • Put a data processing agreement in place with every supplier, contractor or platform that handles personal data on your behalf.
  • Have a breach response plan that can realistically meet the 72-hour ICO reporting deadline, including who decides whether the risk threshold is met.
  • Assign clear ownership of subject access requests so the one-month deadline is never missed by accident.
  • Assess whether you meet the criteria for a mandatory DPO, and if not, decide who owns data protection internally.
  • Update your internal complaints process to meet the new 30-day acknowledgement requirement introduced by the Data (Use and Access) Act 2025.
  • Review your cookie banner and marketing consents, including whether the new limited cookie exemptions apply to you.
  • Train staff who handle personal data regularly, not as a one-off induction exercise.

How Our GDPR and Data Protection Solicitors Can Help

We advise SMEs and owner-managed businesses on the full range of UK GDPR and data protection issues, including drafting and reviewing privacy policies and data processing agreements, carrying out data protection impact assessments, advising on and supporting breach response, handling complex subject access requests, and acting as or supporting an appointed DPO where one is required. Because we act for both data controllers and data processors, we can put contractual protections in place from whichever side of the relationship you sit on, whether you are the business relying on external suppliers or the business processing data on behalf of clients.

If your business has not reviewed its data protection compliance since the Data (Use and Access) Act 2025 changes came into force, now is a sensible time to do so. Speak to our GDPR solicitors about a compliance review, or get in touch on +44 207 566 1188 or info@gurvelegal.com.