GDPR Basics for Small-Business IT
The practical, IT side of UK GDPR for small businesses — the everyday technical habits that keep personal data safe and keep you on the right side of the rules, without the legal waffle.
A Streatham accountancy firm we spoke with had a near-miss that should be familiar to a lot of small businesses. A staff member left, and three weeks later someone realised her old laptop had never been collected — and her logins still worked. It held client tax records, bank details, the lot. Nothing bad happened in the end, but for those three weeks a former employee had full access to a pile of other people’s personal data, and nobody had noticed. That, in a nutshell, is where GDPR meets IT: not in the legal small print, but in the ordinary, forgettable jobs that quietly go undone.
UK GDPR often gets treated as a legal or paperwork problem. Much of it is. But a large share of staying compliant is simply good IT hygiene — the same practical habits that protect you from ransomware and downtime also keep personal data safe and keep you on the right side of the rules. This guide focuses on that IT side: what you should actually be doing, in plain English.
What “personal data” really means for you
Personal data is any information about a living, identifiable person. That’s far broader than most owners assume. Customer email addresses, staff National Insurance numbers, a supplier’s mobile number, CCTV footage, even the notes in your CRM — all of it counts. If you can tie information to a named individual, GDPR applies to how you store it, who can reach it, and how well you protect it.
The core duty is straightforward to state: hold only the personal data you genuinely need, keep it secure, and be able to show you’re doing so. The technical work sits under that last part — “keep it secure” is where IT does the heavy lifting.
The IT duties that matter most
You don’t need to memorise the regulation. You do need a handful of technical basics working reliably:
Control who can see what. Not everyone in the business needs access to everything. Sensible access controls — so the sales team can’t open HR files and a junior can’t export the whole customer database — are one of the simplest, highest-value steps you can take. This is bread-and-butter cyber security work, and it directly limits the damage any single mistake or stolen password can do.
Protect the front door. Strong, unique passwords and multi-factor authentication on email and key systems stop the most common cause of breaches: someone guessing or phishing a login. If a former employee’s credentials still work weeks after they’ve gone, MFA won’t save you — which brings us to leavers.
Have a proper joiner-and-leaver process. When someone leaves, their access should be switched off the same day, devices collected or remotely wiped, and shared passwords changed. When someone joins, they should get only the access their role needs. Managed environments make this a two-minute job instead of a scramble — it’s a routine part of managed IT support.
Encrypt the things that walk out of the office. Laptops, phones and USB drives get lost and stolen. Full-disk encryption means a lost device is an inconvenience, not a reportable breach. On modern Microsoft 365 and Google Workspace setups this can be switched on and enforced centrally.
Back up — and be able to restore. GDPR includes the right to availability of data, and a ransomware attack or failed drive can wipe records you’re legally required to keep. Reliable, tested backup and continuity is both a compliance safeguard and plain common sense. A backup you’ve never test-restored is a hope, not a plan.
Keep things patched. Out-of-date software is the open window burglars climb through. Automatic updates on operating systems, browsers and business apps close known holes before they’re used against you.
A practical GDPR-IT checklist
Run through this with whoever looks after your systems:
- Know what you hold and where. A simple list of what personal data you keep, in which systems, and why.
- Access is need-to-know. Permissions match roles; no shared logins for sensitive systems.
- MFA is on for email and anything holding personal data.
- Leaver process is written down and actually followed the day someone departs.
- Devices are encrypted — every laptop and phone that touches business data.
- Backups run automatically and are tested — you’ve actually restored a file to prove it works.
- Software updates are enabled across machines and key applications.
- You know your 72-hour plan — who assesses a suspected breach, and who contacts the ICO if needed.
- Old data is cleared out — you’re not hoarding personal data you no longer need.
None of these are exotic. They’re the same steps that make a business resilient generally — which is rather the point. Good IT security and GDPR compliance pull in the same direction.
Where to start
If reading that list made you slightly uneasy, that’s normal — most small businesses have a few gaps, and the point isn’t perfection, it’s steady, sensible cover. The riskiest position is not knowing where you stand.
If you’d like a hand, we’re happy to review your setup against the basics above and tell you honestly what’s solid and what needs attention — no jargon, no scare tactics, just a clear picture and a short list of what’s worth doing. Get in touch and we’ll take a look.
Frequently asked questions
Does UK GDPR apply to a small business with only a few staff?
Yes. There's no minimum size. If you hold personal data about customers, staff or suppliers — names, emails, phone numbers, payment details — the rules apply to you, whether you have three employees or three hundred. What changes with size is how much record-keeping is proportionate, not whether the law applies.
Do we have to report every data breach to the ICO?
Not every one, but you must assess each incident. A personal-data breach that's likely to risk people's rights or freedoms has to be reported to the ICO within 72 hours of you becoming aware of it. Even breaches you don't report should be logged internally, with what happened and what you did. When in doubt, take advice quickly — the clock starts when you find out, not when you finish investigating.
Is switching to Microsoft 365 or Google Workspace enough to be compliant?
It helps, but it isn't a tick-box. Reputable cloud platforms give you strong tools — encryption, access controls, audit logs — but they're only as good as how they're set up and used. Default settings, shared logins and unmanaged devices can undo all of it. The platform is the foundation; the configuration and day-to-day habits are what actually keep data safe.
Related services
Want a hand with any of this?
Tell us what you're trying to sort out and we'll come back with a clear, no-obligation plan and price.
