What GDPR actually asks of a small firm
There is a myth that GDPR (and the UK version, UK GDPR, sitting alongside the Data Protection Act 2018) is only for large companies. It is not. If you hold personal data about customers, suppliers or staff — and every business does — the rules apply to you. The good news is that the core duties are common sense, and most of the work is practical IT hygiene rather than paperwork.
At its heart, the law asks you to do a handful of things: only collect data you genuinely need, keep it accurate and secure, don’t hang on to it forever, and be honest with people about what you hold. You also need to be able to hand someone their data, or delete it, if they ask. None of that requires a legal team. It requires knowing where your data lives and putting sensible controls around it.
This is not legal advice — if you handle special category data (health, biometrics) or do large-scale profiling, take proper professional advice. For a typical shop, tradesperson, clinic or small office, the steps below cover the ground.
Step one: know what personal data you hold
You cannot protect data you can’t find. Spend an hour writing a simple list — often called a data inventory — of every place personal data sits in your business:
- Email inboxes (by far the most common weak spot — years of customer correspondence, attachments and invoices)
- Accounting and invoicing software
- Your website contact forms and any customer database
- Spreadsheets on laptops and USB sticks
- Phones with customer contacts and WhatsApp chats
- Paper — signed forms, delivery notes, old files in a cupboard
For each one, note roughly what it contains and who can access it. This single exercise usually reveals the biggest risks: the old laptop nobody has wiped, the shared login three people use, the spreadsheet of customer details emailed around unencrypted.
Step two: lock down the basics
Most data breaches at small firms are not sophisticated attacks — they are stolen laptops, guessed passwords and phishing emails. The practical controls that matter most are also the cheapest:
- Turn on multi-factor authentication (MFA) for email, accounting and any cloud service. This is the single most effective step you can take. A stolen password becomes almost useless without the second factor.
- Use a password manager so every account has a strong, unique password. Reused passwords are how one breach becomes five.
- Encrypt your devices. BitLocker on Windows Pro and FileVault on macOS are free and built in. If a laptop is lost, encryption means the data goes with it, not to a stranger.
- Keep software updated. Unpatched Windows, macOS and browsers are the routes most malware uses. A slow, sensible patching routine beats a heroic clear-up later.
- Separate accounts. Staff should not share one login, and day-to-day work should not run on an administrator account.
Sensible antivirus, a properly configured firewall and staff who can spot a phishing email round this out. This is the territory our cybersecurity work covers, and most of it can be set up in an afternoon.
Step three: back up so a breach isn’t a disaster
Data protection is not only about keeping data out of the wrong hands — it is also about not losing it. Ransomware, a failed drive or an accidental deletion can wipe out the records you are legally required to keep. A reliable, tested backup is part of your GDPR duty to keep data available and recoverable, not an optional extra.
Follow the 3-2-1 approach: three copies, on two types of media, with one kept offsite or in the cloud. Crucially, test that you can actually restore from it. A backup nobody has ever restored is a hope, not a safeguard. If ransomware encrypts your live files, a clean offline backup is often the difference between a bad afternoon and a business-ending week.
Step four: think before you move data to the cloud
Cloud tools — Microsoft 365, Google Workspace, online accounting — are genuinely good for security when set up properly, because the provider handles patching and resilience. But moving data to the cloud does not move your responsibility for it. You are still the “data controller”.
When choosing or moving to a cloud service, check where the data is stored, that the provider offers a data processing agreement, and that access is limited to the people who need it. A tidy cloud migration is a good moment to clear out old data you no longer need and set proper permissions from the start, rather than dragging years of clutter across.
Step five: have a plan for requests and breaches
Two things will eventually land on your desk. First, a subject access request — someone asking for a copy of the data you hold on them. You have one month to respond, so knowing where data lives (step one) makes this manageable rather than panic-inducing. Second, a breach: if personal data is lost or exposed in a way that risks harm, you may need to report it to the ICO within 72 hours. Write down, in advance, who does what if it happens. A one-page plan beats improvising during a crisis.
A realistic starting point
You do not need to do all of this at once. If you only do three things this month, make them: switch on MFA everywhere, encrypt your laptops, and set up a backup you have actually tested. Those three cover the failures we see most often.
If you would like a hand getting the practical side in order — securing devices, setting up backups, or reviewing how your firm handles customer data — call us on 020 7610 0500, drop into the Putney workshop, or use the contact form. We can walk through sensible, jargon-free cybersecurity steps that fit how your business actually works.




