Compliance

UK GDPR and Data Protection Compliance Support

Data protection done as a working process, not a policy document. We map what you actually hold, fix what is indefensible, and leave you with procedures that survive contact with a busy week.

LAW
UK GDPR & Data Protection Act 2018
REGULATOR
Information Commissioner's Office
BREACH CLOCK
72 Hours from Awareness
SAR DEADLINE
One Month, Free of Charge
In short

What does a small business need to do to comply with UK GDPR?

Know what personal data you hold and why, have a lawful basis for each use, publish an accurate privacy notice, keep a record of processing activities, be able to answer subject access requests within one month, secure the data appropriately, and be able to report a breach to the ICO within 72 hours.

Start by finding the data

Almost every compliance problem we encounter traces back to the same root cause: the business does not know what personal data it holds. Data accumulates in mailboxes, in a shared drive nobody has audited, in a CRM, in a spreadsheet on someone's laptop, in an old backup, and in half a dozen SaaS tools signed up for on a company card.

Data mapping fixes that. It is not glamorous work, but it is the foundation for everything else — you cannot write an accurate privacy notice, respond properly to a subject access request, assess a breach or defend a retention practice without it. It also routinely finds data the business should have deleted years ago, which is free risk reduction.

  • What categories of personal data you hold, including any special category data
  • Where each category physically and logically lives, including in email
  • Who has access, internally and among suppliers
  • Your lawful basis for each processing purpose
  • How long you keep it and what triggers deletion
  • Whether any of it leaves the UK, and on what transfer mechanism

Subject access requests without the panic

A subject access request must generally be answered within one calendar month, free of charge, and can arrive by any route — including a comment on social media or a verbal request to a member of staff who does not recognise what it is. Requests from disgruntled former employees are common and are frequently the most demanding.

What makes them manageable is preparation: staff who can recognise a request, a single internal route for logging it, a documented search process across the systems your data map identified, and templates for the response and for common exemptions such as third-party personal data and legal privilege.

  • Staff trained to recognise and escalate a request however it arrives
  • Central log with the one-month clock started on receipt
  • Documented search process covering email, file storage and business systems
  • Redaction approach for third-party data and applicable exemptions
  • Response templates and a record of what was disclosed and why

Breach reporting and the 72-hour clock

If a personal data breach poses a risk to the individuals affected, it must be reported to the ICO within 72 hours of the organisation becoming aware of it. Where the risk is high, affected individuals must also be told without undue delay.

Two points cause the most trouble. First, the clock starts at awareness, not at the end of the investigation — so a partial report followed by an update is the correct approach, not a delayed complete one. Second, not every incident is reportable, but every incident must be recorded internally with the reasoning, because the ICO can ask to see that record and its absence looks considerably worse than a marginal decision not to report.

  • Documented risk assessment to decide whether the reporting threshold is met
  • Internal breach register recording every incident and the decision made
  • ICO notification process and template with the required content
  • Individual notification template for high-risk breaches

Security is a legal requirement, not just good practice

Article 32 requires appropriate technical and organisational measures to secure personal data, taking account of the risk. That is where data protection and cyber security meet: MFA, encryption, access control, patching, backup and staff training are not merely sensible, they are how you evidence compliance with a legal duty.

It is also what the ICO looks at after a breach. Enforcement action frequently turns on whether basic, well-known measures were in place — not on whether the organisation was defeated by something sophisticated.

What you receive

Included in every engagement

Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.

Frequently asked questions

UK GDPR Compliance — your questions answered

Does UK GDPR apply to a small business?
Yes. There is no small-business exemption. Some obligations scale with size and risk — for example the record-keeping requirement is lighter for organisations under 250 staff — but the core duties around lawful basis, transparency, security, individual rights and breach reporting apply regardless.
Do we need a Data Protection Officer?
A formal DPO is mandatory only for public authorities, or where core activities involve large-scale regular monitoring or large-scale special category data. Most SMEs do not need one, but should name someone accountable for data protection.
How long do we have to respond to a subject access request?
One calendar month from receipt, free of charge. It can be extended by a further two months for complex or numerous requests, but you must tell the individual within the first month that you are extending, and why.
Do we have to report every data breach to the ICO?
No — only those posing a risk to the rights and freedoms of affected individuals, within 72 hours of awareness. You must, however, record every breach internally with your reasoning, including those you decide not to report.
Do we need to register with the ICO?
Most organisations processing personal data must pay the annual data protection fee to the ICO unless a specific exemption applies. The fee is banded by size and turnover, and failing to pay it is itself an enforceable matter.
Is Cyber Essentials enough to demonstrate GDPR security compliance?
It helps considerably and is good evidence of baseline technical measures under Article 32, but it is not a data protection framework. It says nothing about lawful basis, transparency, retention or individual rights, which are equally enforceable.

Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.

Ready to talk about uk gdpr compliance?

Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.