What does data protection law actually require of a small business?
Less bureaucracy than most small businesses fear and more discipline about basic practice than most currently apply. The obligations scale with what you do with personal data, not with your size — but the regime is explicitly risk-based, so a small business doing ordinary things faces a light load.
What triggers the rules. Processing personal data — any information relating to an identifiable living person. Customer records, staff files, CCTV, marketing lists, and an email address are all personal data.
The core obligations:
Have a lawful basis for each processing purpose. Consent is one of six and frequently the worst choice, because it must be freely given and can be withdrawn. Contract and legitimate interests cover most ordinary business activity.
Tell people what you do, through an accessible privacy notice written in plain language.
Collect only what you need, and keep it only as long as you need it. A written retention schedule is unglamorous and is the fix for a large share of risk.
Keep it secure, with measures proportionate to the risk — access control, encryption of portable devices, patched systems, and staff awareness.
Honour individual rights, including access, correction, erasure and objection, generally within one month.
Report serious breaches to the regulator within 72 hours where the criteria are met, and to affected individuals where the risk is high.
Register with the regulator and pay the data protection fee, which most organisations must do.
Contracts with processors — anyone handling data on your behalf, including most cloud services — must contain specified terms.
Where small businesses actually get caught:
Marketing rules, which are separate and stricter: unsolicited electronic marketing to individuals generally needs consent, and enforcement here is frequent and expensive.
Subject access requests, which are free, must be answered, and are frequently used in employment disputes.
Old data kept indefinitely with no reason.
Unsecured personal devices and shared logins.
General information, not legal advice.