There is a stubborn myth among small business owners that data protection is something for banks, hospitals and large online retailers to worry about. It is not. If you hold a customer's name and phone number, keep payroll records, run a mailing list, store CCTV footage or take card payments, you are processing personal data — and the UK GDPR and the Data Protection Act 2018 apply to you just as they do to a much larger organisation.
The good news is that the rules are built around principles rather than bureaucracy. You are expected to handle information lawfully, keep only what you need, store it securely, use it only for the reasons you told people about, and be able to show you are doing so. A sole trader with a tidy filing system can be just as compliant as a company with a legal department. What matters is that your habits are deliberate rather than accidental.
You cannot protect information you have not accounted for. Start with a simple inventory: list the categories of personal data you collect, where each one lives, and the reason you need it. That might be a customer database, an accounting package, a diary app, a shared inbox, a box of paper invoices in the cupboard, or a WhatsApp group with your staff.
For each item, you should be able to answer two questions. First, what is your lawful basis for holding it? Most routine customer data rests on contract (you need the address to deliver the order) or legitimate interests (you need the email to answer an enquiry). Marketing emails usually need consent, which must be freely given, specific and easy to withdraw. Second, how long do you need it? A useful rule is to set a retention period for each category and actually delete things when the period ends.
People are entitled to know what happens to their information. A short privacy notice on your website, and a matching paragraph on your enquiry forms and contracts, covers most of this. It does not need to be written in legal jargon. Plain English that explains what you collect, why, who you share it with, how long you keep it, and how someone can complain is far more useful than a wall of borrowed text.
Watch the details. If you use an accountant, a cloud booking system, an email marketing platform or a courier, those organisations are likely to be processors acting on your instructions, and you should have a written agreement with them. If you send data overseas, check that the transfer is covered by an approved safeguard. Small print matters here more than most owners expect.
Most breaches involving small businesses are mundane rather than dramatic: a lost laptop, a misdirected email, a shared password, a phishing message that looked convincing. Security does not have to be expensive, but it does have to be consistent.
Special category data — health details, ethnicity, religious beliefs, trade union membership, biometrics — deserves extra care. If you handle it, you need a specific condition for doing so and tighter controls around who can see it.
Individuals have rights you must honour. The most common request is a subject access request, where someone asks for a copy of the data you hold about them. You must respond within one month, and you normally cannot charge a fee. People can also ask you to correct inaccurate information, delete data, or stop using it for marketing. Having a named person responsible for handling these requests, and a simple log of what came in and when, keeps you calm when one arrives.
If personal data is lost, stolen or disclosed in error, you need to assess the risk. Where the breach is likely to result in a risk to people's rights and freedoms, you must report it to the Information Commissioner's Office within 72 hours of becoming aware of it. If the risk is high, you must also tell the individuals affected. Recording near-misses and minor incidents internally is good practice, even when reporting is not required.
Compliance is not a one-off project. Build it into your routines: review your data inventory once a year, check your privacy notice when you change suppliers, and include data protection in staff inductions. Most businesses that need to register with the ICO pay a modest annual fee, and the process is straightforward.
If it all feels daunting, start small. Pick one area — your customer database, perhaps — and work through the questions above. Then move to the next. Handled steadily, data protection becomes what it should be: a natural part of running a business that people trust with their details.
April 25, 2019 at 10:46 am
Take in the iconic skyline and visit the neighbourhood hangouts that you've only ever seen on TV. Take in the iconic skyline and visit the neighbourhood.
Want to be notified when we launch a new template or an udpate. Just sign up and we'll send you a notification by email.
Soldman Kell
April 25, 2019 at 10:46 am
Take in the iconic skyline and visit the neighbourhood hangouts that you've only ever seen on TV. Take in the iconic skyline and visit the neighbourhood.