GDPR and data protection for small businesses
If you collect names, emails, payment details, health data, employment records, analytics or support tickets, data protection applies. This checklist turns compliance into practical operating habits.
Data map
Names, emails, phone numbers, addresses, payment data, usage data, HR files, health or special-category data.
Contract delivery, legal obligation, consent, legitimate interests, employment, safeguarding or marketing.
CRM, email, analytics, spreadsheets, cloud storage, payment tools, support desk and backups.
Founders, staff, freelancers, processors, accountants, CRM providers and overseas tools.
Minimum compliance checklist
- Publish a clear privacy notice before collecting data.
- Use cookie consent for non-essential analytics/marketing cookies.
- Keep a lawful-basis record for each type of processing.
- Collect only what you need and delete data when it is no longer required.
- Use strong passwords, MFA and role-based access.
- Sign data-processing terms with suppliers that process personal data.
- Prepare a breach response plan and know the ICO 72-hour reporting rule.
- Check whether you need to pay the ICO data protection fee.
Special-category and high-risk data
Healthtech, HR, children’s services, AI profiling, finance and identity-verification businesses need a higher standard. Consider a Data Protection Impact Assessment and specialist advice before launch.