Skip to main content

GDPR Data Protection Basics for Small Businesses

Plain-English data protection duties for a small firm, plus the practical IT steps that keep customer data safe. Not legal advice — a working checklist.

7 min read By Adnan R.
Data and information security concept

If you run a small business, you already handle personal data — customer names, emails, invoices, staff records. This is a plain-English guide to your data protection duties and the practical IT steps that back them up. It is not legal advice, but it will get your house in order.

Share this article:

Table of Contents

What GDPR actually asks of a small firm

There is a myth that GDPR (and the UK version, UK GDPR, sitting alongside the Data Protection Act 2018) is only for large companies. It is not. If you hold personal data about customers, suppliers or staff — and every business does — the rules apply to you. The good news is that the core duties are common sense, and most of the work is practical IT hygiene rather than paperwork.

At its heart, the law asks you to do a handful of things: only collect data you genuinely need, keep it accurate and secure, don’t hang on to it forever, and be honest with people about what you hold. You also need to be able to hand someone their data, or delete it, if they ask. None of that requires a legal team. It requires knowing where your data lives and putting sensible controls around it.

This is not legal advice — if you handle special category data (health, biometrics) or do large-scale profiling, take proper professional advice. For a typical shop, tradesperson, clinic or small office, the steps below cover the ground.

Step one: know what personal data you hold

You cannot protect data you can’t find. Spend an hour writing a simple list — often called a data inventory — of every place personal data sits in your business:

  • Email inboxes (by far the most common weak spot — years of customer correspondence, attachments and invoices)
  • Accounting and invoicing software
  • Your website contact forms and any customer database
  • Spreadsheets on laptops and USB sticks
  • Phones with customer contacts and WhatsApp chats
  • Paper — signed forms, delivery notes, old files in a cupboard

For each one, note roughly what it contains and who can access it. This single exercise usually reveals the biggest risks: the old laptop nobody has wiped, the shared login three people use, the spreadsheet of customer details emailed around unencrypted.

Step two: lock down the basics

Most data breaches at small firms are not sophisticated attacks — they are stolen laptops, guessed passwords and phishing emails. The practical controls that matter most are also the cheapest:

  • Turn on multi-factor authentication (MFA) for email, accounting and any cloud service. This is the single most effective step you can take. A stolen password becomes almost useless without the second factor.
  • Use a password manager so every account has a strong, unique password. Reused passwords are how one breach becomes five.
  • Encrypt your devices. BitLocker on Windows Pro and FileVault on macOS are free and built in. If a laptop is lost, encryption means the data goes with it, not to a stranger.
  • Keep software updated. Unpatched Windows, macOS and browsers are the routes most malware uses. A slow, sensible patching routine beats a heroic clear-up later.
  • Separate accounts. Staff should not share one login, and day-to-day work should not run on an administrator account.

Sensible antivirus, a properly configured firewall and staff who can spot a phishing email round this out. This is the territory our cybersecurity work covers, and most of it can be set up in an afternoon.

Step three: back up so a breach isn’t a disaster

Data protection is not only about keeping data out of the wrong hands — it is also about not losing it. Ransomware, a failed drive or an accidental deletion can wipe out the records you are legally required to keep. A reliable, tested backup is part of your GDPR duty to keep data available and recoverable, not an optional extra.

Follow the 3-2-1 approach: three copies, on two types of media, with one kept offsite or in the cloud. Crucially, test that you can actually restore from it. A backup nobody has ever restored is a hope, not a safeguard. If ransomware encrypts your live files, a clean offline backup is often the difference between a bad afternoon and a business-ending week.

Step four: think before you move data to the cloud

Cloud tools — Microsoft 365, Google Workspace, online accounting — are genuinely good for security when set up properly, because the provider handles patching and resilience. But moving data to the cloud does not move your responsibility for it. You are still the “data controller”.

When choosing or moving to a cloud service, check where the data is stored, that the provider offers a data processing agreement, and that access is limited to the people who need it. A tidy cloud migration is a good moment to clear out old data you no longer need and set proper permissions from the start, rather than dragging years of clutter across.

Step five: have a plan for requests and breaches

Two things will eventually land on your desk. First, a subject access request — someone asking for a copy of the data you hold on them. You have one month to respond, so knowing where data lives (step one) makes this manageable rather than panic-inducing. Second, a breach: if personal data is lost or exposed in a way that risks harm, you may need to report it to the ICO within 72 hours. Write down, in advance, who does what if it happens. A one-page plan beats improvising during a crisis.

A realistic starting point

You do not need to do all of this at once. If you only do three things this month, make them: switch on MFA everywhere, encrypt your laptops, and set up a backup you have actually tested. Those three cover the failures we see most often.

If you would like a hand getting the practical side in order — securing devices, setting up backups, or reviewing how your firm handles customer data — call us on 020 7610 0500, drop into the Putney workshop, or use the contact form. We can walk through sensible, jargon-free cybersecurity steps that fit how your business actually works.

Helpful Internal Links

Need Help With This Issue?

Speak with our support team for practical help and next steps.

Author

Adnan R.

Principal IT & Security Consultant

CISSP-certified IT and security consultant with an MSc in Information Security from Royal Holloway, University of London, and 20+ years across systems administration, networking and cybersecurity. Professional member of the British Computer Society (BCS).

Explore more

Related Posts

View all

How to Secure Your Home Wi-Fi Network

A practical guide to securing your home Wi-Fi: strong passwords, WPA3 encryption, a guest network, router firmware updates and keeping smart devices apart.