Last reviewed 29 August 2026
The UK GDPR and the Data Protection Act 2018 apply to businesses of every size. There is no small-company exemption from the core obligations, though some requirements — such as maintaining full records of processing — are lighter for organisations under 250 employees where processing is occasional and low risk.
For most startups the practical driver is commercial rather than regulatory. Enterprise customers send security and data protection questionnaires, investors ask about compliance in due diligence, and both expect documented answers.
This guide sets out what a growing UK business actually needs, in the order it makes sense to build it.
Map what you process before writing anything
Start with a data map: what personal data you hold, where it came from, why you have it, where it is stored, who has access, which third parties receive it and how long you keep it. Include employee and candidate data, not just customer data — HR processing is where smaller organisations most often fall short.
The map drives everything else. Your privacy notice, your record of processing activities, your retention schedule and your answers to customer questionnaires all come from it. Building the policies first, then trying to make reality match them, is the slower route.
Lawful bases and special category data
Every processing activity needs a lawful basis: consent, contract, legal obligation, vital interests, public task or legitimate interests. For B2B SaaS, contract and legitimate interests do most of the work; consent is mainly relevant to marketing and cookies.
Where you rely on legitimate interests, carry out and document a legitimate interests assessment weighing your purpose against the individual's rights. If you process special category data — health, biometrics, ethnicity, trade union membership and others — you also need a separate Article 9 condition and usually an appropriate policy document.
The documents you need
The core set is: an external privacy notice for customers and website visitors, an internal employee privacy notice, a record of processing activities, a data retention schedule, an information security policy, a data breach response procedure and a data subject request procedure.
Add a cookie policy and a compliant consent banner if your site uses non-essential cookies — the Privacy and Electronic Communications Regulations require consent for those, and 'implied consent' banners are not compliant. A data protection impact assessment is required for high-risk processing such as large-scale profiling or systematic monitoring.
Processors, sub-processors and transfers
Every supplier that processes personal data on your behalf — hosting, analytics, email, CRM, payroll, support tooling — needs a written contract meeting Article 28. Most large providers offer a standard data processing addendum; collect and file them rather than assuming they apply automatically.
For transfers outside the UK, identify the mechanism: adequacy regulations, the International Data Transfer Agreement, or the UK addendum to the EU standard contractual clauses, supported by a transfer risk assessment. Keep a current list of sub-processors, because customer contracts increasingly require notice of changes.
Security, breaches and the 72-hour clock
Article 32 requires appropriate technical and organisational measures. In practice that means access controls, multi-factor authentication, encryption in transit and at rest, logging, backups, patching, supplier due diligence and staff training — proportionate to the risk.
A personal data breach must be reported to the Information Commissioner's Office without undue delay and within 72 hours where it is likely to result in a risk to individuals, and affected individuals must be told where the risk is high. Write and rehearse the procedure in advance: the 72 hours starts when you become aware, not when you finish investigating.
Marketing, cookies and registration
Direct marketing is governed by PECR as well as the UK GDPR. Business-to-business email marketing to corporate subscribers is more permissive than B2C, but you still need a clear opt-out in every message and accurate sender identification. Marketing to individuals and sole traders generally requires consent or the narrow soft opt-in.
Most organisations that process personal data must pay the ICO's data protection fee and register. It is inexpensive, quickly done, and the register is public — which means customers and investors can check whether you have done it.
Key points
- Build a data map first; every other document flows from it.
- Document a legitimate interests assessment wherever you rely on that basis.
- Every processor needs an Article 28 contract — collect the addenda, do not assume.
- Non-essential cookies require genuine consent under PECR.
- The 72-hour breach clock starts at awareness, not at the end of the investigation.
- Most UK businesses must pay the ICO data protection fee.
Frequently asked questions
- Does a startup need a data protection officer?
- Only where processing meets the statutory triggers: a public authority, large-scale regular and systematic monitoring, or large-scale processing of special category or criminal offence data. Most early-stage companies do not need one but should name an accountable owner internally.
- Is UK GDPR different from EU GDPR?
- They are closely aligned but separate regimes. If you offer goods or services to individuals in the EU, or monitor their behaviour, EU GDPR can also apply and you may need an EU representative. Many businesses maintain a single compliance framework that satisfies both.
- How long can we keep personal data?
- No longer than necessary for the purpose. There is no fixed rule; you set retention periods by reference to the purpose and any legal obligations, document them in a retention schedule and actually delete on time.
- What do enterprise customers usually ask for?
- A data processing agreement, a sub-processor list, evidence of security measures, breach notification commitments, transfer mechanisms and often a completed security questionnaire. Preparing these in advance removes weeks from enterprise sales cycles.
