, ,

GDPR for small businesses: a practical guide for the self-employed

data-protection-act-principles-for-small-business.jpg
Image credit: Drazen/stock.adobe.com

Quick answer: UK GDPR applies to any business that handles personal data – including sole traders. You don’t need a lawyer or a big budget to comply. The key steps are understanding the seven data protection principles, getting consent right, registering with the ICO if required, and knowing what to do if something goes wrong.

Running a business solo means wearing a lot of hats. Compliance officer probably wasn’t one you signed up for. But if you collect customer names, store email addresses, or keep staff records – even in a simple spreadsheet – UK GDPR applies to you.

The good news? Compliance is more manageable than it sounds. This guide cuts through the legal language and gives you a clear, step-by-step picture of what the rules actually mean for a small business or sole trader, what to do if things go wrong, and how the right insurance can help protect you if they do.

What is UK GDPR – and does it still apply after Brexit?

UK GDPR is the domestic version of the EU’s General Data Protection Regulation. When the UK left the EU, it incorporated GDPR into UK law through the Data Protection Act 2018. So yes – GDPR still applies in the UK, just under a different name.

The regulation covers any business that collects, stores, or uses personal data. That includes customer contact details, email addresses, IP addresses, staff records, and anything else that could identify a living person.

If you sell to customers in the EU or EEA, you may also need to comply with EU GDPR separately. Check the ICO’s guidance if you trade across borders.

Am I affected? You don’t need to be a limited company or have employees for UK GDPR to apply. If you hold personal data – even a basic client list – you’re responsible for protecting it.

The 7 data protection principles explained

UK GDPR is built around seven core principles. Every business that handles personal data must follow them. Here’s what each one means in practice.

1. Lawfulness, fairness, and transparency

You must have a valid legal reason to collect someone’s data, use it fairly, and be open about how you’re using it. That means telling people who you are, what you’re collecting, and why – usually through a privacy notice or policy.

What this means for you: Add a short, plain-English privacy notice to your website and any forms where you collect data. Don’t bury it in the footer – make it easy to find.

2. Purpose limitation

You can only use data for the specific reason you collected it. If you collect someone’s email address to send them an invoice, you can’t then add them to a marketing list without asking first.

What this means for you: Be clear upfront about what you’ll use someone’s data for. If your plans change, you need fresh consent.

3. Data minimisation

Only collect what you actually need. If a name and email address are enough, don’t ask for a phone number, date of birth, and home address as well.

What this means for you: Review your contact forms and intake processes. Strip out any fields you don’t genuinely need.

4. Accuracy

The data you hold must be accurate and kept up to date. If a customer moves house or changes their email, outdated records could cause problems – for them and for you.

What this means for you: Build in a simple process for customers to update their details, and review your records periodically.

5. Storage limitation

You can’t hold on to personal data indefinitely. Once you no longer need it for the purpose it was collected, you should delete it.

What this means for you: Set a data retention policy – even a basic one. For example, “we delete customer records three years after the last transaction.” Document it and stick to it.

6. Integrity and confidentiality

You must keep personal data secure. That means protecting it from unauthorised access, accidental loss, and damage – whether it’s stored on your laptop, in the cloud, or in a filing cabinet.

What this means for you: Use strong passwords, two-factor authentication, and up-to-date software. Encrypt sensitive files where you can.

7. Accountability

You’re responsible for complying with all of the above – and you must be able to show that you’re doing so. That doesn’t mean generating mountains of paperwork, but it does mean keeping basic records of what data you hold and why.

What this means for you: Keep a simple log of the personal data you process, your legal basis for doing so, and any third parties you share it with. A spreadsheet is fine.

Consent is one of the most misunderstood parts of GDPR. It’s not the only legal basis for processing data, but it’s the one most sole traders rely on for things like marketing.

Valid consent must be:

  1. Freely given – not bundled into terms and conditions
  2. Specific – people need to know exactly what they’re consenting to
  3. Informed – you must explain who you are and what you’ll do with their data
  4. Unambiguous – pre-ticked boxes don’t count

You also need to make it easy for people to withdraw consent at any time. If someone unsubscribes from your mailing list, you have to act on that promptly.

Keep a record of when consent was given, how, and what the person was told at the time. If you ever need to demonstrate compliance, this is your evidence.

Cheryl Hartung, Data Protection Analyst at Simply Business, says: “Don’t automatically default to consent when processing customer data. If you’re running a business, relying on ‘contractual necessity’ often makes much more sense.

“Remember that data deletion rights aren’t absolute either. If a customer requests to have their details erased, but you’re required by law to keep financial records for HMRC, you rely on legal obligation to retain that data, not consent.

“If a customer removes their consent for marketing, you must comply with this and stop sending them marketing emails. Keep records of your suppression list to make sure you don’t accidentally market to them in future.”

Takeaway: Don’t rely on assumptions or vague opt-ins. If in doubt, ask clearly – and document it.

Do you need to write a privacy policy?

If you collect personal data through a website, a contact form, or any other means, you need a privacy policy that explains:

  1. Who you are and how to contact you
  2. What data you collect and why
  3. Your legal basis for processing it
  4. How long you keep it
  5. Whether you share it with third parties
  6. How people can access, correct, or delete their data

It doesn’t need to be long or full of legal language. Short, clear, and honest is better than a wall of text that nobody reads. The ICO has a free privacy notice generator for small businesses that’s a good starting point.

Takeaway: Publish your privacy policy somewhere visible – your website footer is standard – and update it any time your practices change.

Do you need to register with the ICO?

Most businesses that process personal data need to pay an annual data protection fee to the ICO. As of 2026, the fee starts from £52.

Some businesses are exempt – including those that only process data for staff administration, payroll, or personal household use. Use the ICO’s online self-assessment tool to check whether you need to register.

Failing to register when you should isn’t a minor oversight. The ICO can issue fines for non-compliance, and the maximum penalty under UK GDPR is £17.5 million or 4% of annual global turnover – whichever is higher. For a sole trader, even a smaller penalty could be seriously damaging.

Takeaway: Check the ICO’s online tool, register if required, and set a reminder to renew each year.

What happens if you have a data breach?

A data breach isn’t just a hacker stealing your database. It includes accidentally emailing the wrong person, losing a USB stick with customer data on it, or leaving a laptop in a café.

If you have a breach, you need to act quickly. Here’s what the rules say:

  1. Assess the risk: does the breach pose a risk to people’s rights and freedoms? If data is encrypted and the risk is low, you may not need to report it.
  2. Report to the ICO within 72 hours: if the breach is likely to result in a risk to individuals, you must notify the ICO. Missing this window can lead to separate fines on top of any relating to the breach itself.
  3. Tell the people affected: if the breach is likely to result in a high risk to individuals – for example, financial data or health information has been exposed – you must also tell them directly and promptly.

Read our full guide about what to do during a cyber attack to learn more.

What a data breach could look like for the self employed

A freelance bookkeeper accidentally attaches the wrong client’s accounts to an email and sends it to another client. Both clients can now see each other’s financial data.

That’s a data breach. The bookkeeper would need to assess the risk, consider whether to report it to the ICO, and notify both clients. They’d also need to document what happened and what you did about it.

Breaches like this can damage client trust, lead to complaints, and – if the ICO investigates – result in fines. They can also trigger legal action from affected individuals which could result in compensation payments.

GDPR compliance checklist for sole traders and small businesses

Work through this list to get your data protection in order:

  • map your data – know what personal data you hold, where it comes from, where it’s stored, and who you share it with
  • check your legal basis – for each type of data you process, identify why you’re allowed to process it (for example: consent, contract, legal obligation)
  • write a privacy policy – publish it on your website and update it regularly
  • review your consent processes – make sure opt-ins are clear, specific, and documented
  • tighten your security – strong passwords, two-factor authentication, encrypted storage, and regular software updates
  • set retention periods – decide how long you’ll keep different types of data, and delete what you no longer need
  • register with the ICO – check whether you need to, and pay the annual fee if so
  • create a breach response plan – know who to call, what to document, and when to report to the ICO
  • review your insurance – check whether your policy covers data breaches and cyber incidents
  • train yourself (and any staff) – make sure everyone who handles data understands the basics

4 habits to stay compliant

UK GDPR can look intimidating on paper, but for most sole traders and small businesses, compliance comes down to a handful of practical habits:

  1. Collect only what you need
  2. Be honest about how you use it
  3. Keep it secure
  4. Have a plan for when things go wrong

You don’t need a data protection officer or a legal team to get this right. The ICO’s small business hub has free tools, templates, and guidance.

And if you want to make sure you’re protected financially if a data breach does happen, it’s worth reviewing your business insurance.

Frequently asked questions about UK GDPR

Does UK GDPR apply to sole traders?

Yes. UK GDPR applies to any business or individual that processes personal data, regardless of size. If you hold customer names, email addresses, or any other information that could identify a living person, you need to comply.

What personal data does a sole trader typically hold?

Most sole traders hold data such as client names, email addresses, phone numbers, bank details for invoicing, and sometimes health or financial information depending on the trade. All of it falls under UK GDPR.

How much does it cost to register with the ICO?

ICO fees start from £52 for registration in 2026. Some businesses are exempt – use the ICO’s online checker to find out if you need to register.

What’s the 72-hour rule for data breaches?

If you experience a data breach that poses a risk to individuals, you must report it to the ICO within 72 hours of becoming aware of it. Failing to report within this window can result in additional fines.

What should a small business privacy policy include?

Your privacy policy should cover who you are, what data you collect and why, your legal basis for processing it, how long you keep it, who you share it with, and how people can access or delete their data. Keep it clear and jargon-free.

Can cyber insurance help with a GDPR breach?

Cyber insurance can help to cover the cost of responding to a data breach, including legal advice, customer notification, regulatory defense costs, and business interruption. It’s worth checking whether your existing business insurance includes cyber cover, or adding it as an extra.

Useful guides for small businesses

Ready to set up your cover?

As one of the UK’s biggest business insurance providers, we specialise in public liability insurance and protect more trades than anybody else. Why not take a look now and build a quick, tailored quote?

Rosanna Parrish

Rosanna Parrish is a small business writer specialising in side hustles, freelancing, and early stage small businesses. Her work covers freelance tax and legislation, managing irregular income, and turning side hustles into sustainable businesses.

With 10 years’experience – including three years in the fintech sector – Rosanna has authored hundreds of in-depth guides on starting and managing side hustles. Rosanna has led webinars on small business growth, and worked on major small business campaigns including Business Boost and the Young Entrepreneur Fund. Connect with Rosanna on LinkedIn.