Data protection is one of those topics that tends to get attention in bursts, a new starter needs a privacy notice explained, a client asks about your data handling before signing a contract, or a headline about a fine somewhere reminds everyone it’s still worth taking seriously. The rest of the time, it’s easy to assume it’s sorted and move on.
This guide sets out, in plain English, what UK GDPR actually requires of a small or growing business, and what’s changed recently that’s worth knowing about.
UK GDPR, Not EU GDPR
Since the UK left the EU, data protection law hasn’t disappeared or reverted to something looser, it was carried over into UK law in its own right, now known as the UK GDPR, sitting alongside the Data Protection Act 2018. The core principles are largely the same ones introduced back in 2018: personal data must be processed lawfully, fairly, and transparently, collected for specific purposes, kept accurate and secure, and not held for longer than necessary.
If your understanding of GDPR is still rooted in the original 2018 rollout, it’s worth knowing the framework has moved on since then, most recently and significantly through the Data (Use and Access) Act 2025.
What Changed: The Data (Use and Access) Act 2025
The Data (Use and Access) Act 2025 became law in June 2025 and doesn’t replace UK GDPR, it amends and updates it, along with the Data Protection Act 2018 and PECR (the regulations covering electronic communications and cookies). The main reforms came into force in February 2026, with a further, particularly practical change landing in June 2026.
A few of the changes most likely to affect a small or growing business:
- A new right to complain. From 19th June 2026, every organisation processing personal data, with no exemption for small businesses, must provide a clear way for people to raise a complaint about how their data has been handled, acknowledge it within 30 days, and respond without undue delay. This needs to be a genuine, documented process, not just a line in a privacy policy nobody follows.
- A narrower category of “recognised legitimate interests”. For specific, limited purposes such as crime prevention or safeguarding, businesses no longer need to carry out the usual legitimate interests balancing exercise. For most everyday commercial processing, though, the standard legitimate interests test still applies as before.
- Limited new cookie exemptions. Certain low-risk analytics and functional cookies now have narrower exemptions from consent requirements, though transparency and opt-out mechanisms are still expected in most cases.
- A stronger ICO. The Information Commissioner’s Office has been given expanded investigatory and audit powers, including the ability to compel witnesses to interview. Enforcement expectations are rising alongside these new powers.
None of this is a reason to panic, but it is a reason to review your current privacy processes rather than assume whatever was put in place back in 2018 still fully covers you.
What a Small Business Should Actually Have in Place
Full compliance can sound daunting, but for most small and growing businesses, it comes down to a manageable set of practical basics.
- A clear, accurate privacy notice: explaining what personal data you collect, why, and how long you keep it, written in plain language rather than dense legal text.
- A documented lawful basis for processing: knowing, and being able to explain, why you’re allowed to hold and use the personal data you have.
- A genuine complaints process: now a legal requirement rather than good practice, per the June 2026 change above.
- A breach response plan: knowing what to do, and who to notify, if personal data is lost or exposed. Serious breaches must still be reported to the ICO within 72 hours.
- Staff awareness: having someone in the business who owns data protection, even informally, and making sure the wider team knows the basics of handling personal data responsibly.
- Regular access reviews: checking who can access what personal data, and removing access that’s no longer needed. Worth pairing with a wider cyber security review rather than treating data protection and security as entirely separate concerns.
Getting Support Without Overcomplicating It
Most small businesses don’t need a dedicated Data Protection Officer or a full-time compliance function, that level of formality is generally reserved for larger organisations or those handling particularly sensitive data at scale. What genuinely helps is having someone, internally or externally, who understands the practical side of data protection and can keep policies current as the law continues to evolve, rather than leaving them to quietly go stale.
Not sure your current data protection setup reflects the 2026 changes?
Techrelate helps growing businesses across London and the UK put practical, proportionate data protection and security measures in place, no jargon, no unnecessary overhead.
BOOK A CALL
Get in touch for a free, no-obligation conversation



