Data Protection for Small Businesses: The Basics You Cannot Skip
The ICO fee, lawful reasons and privacy notices, the 2026 cookie and marketing changes, security basics, 72-hour breach reporting, subject access and the new complaints duty.
On a busy Tuesday, the receptionist at Dev’s physiotherapy clinic in Nottingham emailed the week’s appointment list to “Sarah”. It was the wrong Sarah. Forty patients’ names, phone numbers and injury notes had gone to a stranger. Dev spent the next three days learning more about the law than in ten years of running the clinic. Data protection for small businesses is not only for big companies with legal teams. If you hold names, emails or phone numbers, it applies to you, and several rules changed in 2026.
| What changed | When | What it means |
|---|---|---|
| ICO fee rise | Feb 2025 | Most micro businesses pay £52 a year |
| Some cookies exempt from consent | 5 Feb 2026 | Basic analytics can run with clear info and an opt-out |
| Higher marketing fines | 5 Feb 2026 | Up to £17.5m or 4% of turnover |
| Data complaints process | 19 June 2026 | You must handle complaints yourself first |
What counts as personal data
Image source: pexels.com
Personal data is anything that identifies a living person, directly or indirectly: names, emails, phone numbers, addresses, photos, IP addresses and notes about someone. It includes your staff as well as your customers. Some types, called special category data, need extra care, including health information, ethnicity, religion and biometrics. That is why Dev’s breach was serious: injury notes are health data. Start by listing what you actually hold, where it is stored and who can see it. Most small businesses find copies in more places than expected, such as old laptops, personal phones, shared drives and email attachments sitting in sent folders for years.
Pay the ICO fee
Image source: pexels.com
Most businesses that handle personal data electronically must pay an annual data protection fee to the Information Commissioner’s Office. Since February 2025, tier 1 businesses, with turnover up to £632,000 or no more than ten staff, pay £52 a year, or a little less by direct debit. Tier 2 pays £78 and large organisations £3,763. Some businesses are exempt, for example if they only hold data for staff administration and their own accounts, and the ICO has a short online self-assessment to check. Not paying when you should can lead to a fine of up to £4,350, which is a lot to lose for a £52 fee.
Have a reason, and tell people
You need a lawful reason for each use of personal data. For most small firms it is simple: you need it to deliver what the customer asked for, the law requires it, or you have a genuine business interest that does not override the person’s own interests. Consent is only one option, and often not the best one. Then explain it in a plain-English privacy notice: what you collect, why, who you share it with, how long you keep it and how people can use their rights. Put it on your website and at the point where you collect details. Collect only what you need. Dev realised his booking form asked for dates of birth he never used, so it went.
Marketing and cookies: new rules in 2026
Image source: pexels.com
Email and text marketing to individuals generally needs their consent, unless they are existing customers who bought something similar and were given a clear chance to opt out each time. Since 5 February 2026, the maximum fine for breaking these rules has jumped from £500,000 to £17.5 million or 4% of global turnover. There is some good news on cookies: simple analytics cookies used only by you, and cookies that remember display or accessibility settings, no longer need consent, as long as you explain them clearly and let people opt out for free. Advertising cookies still need consent. Check your website banner, and see our guide to referrals for the refer-a-friend email rules.
Security basics that prevent most problems
Image source: pexels.com
The law expects “appropriate” security, which for a small business means sensible basics done well. The government’s 2025 Cyber Security Breaches Survey found 43% of UK businesses had identified a breach or attack in the previous year, most often phishing emails. Use strong, unique passwords with two-factor authentication, keep devices updated, encrypt laptops and phones, back up regularly and give staff access only to what they need. The government-backed Cyber Essentials scheme is a good checklist, and some customers now ask for it. Our guide to business fraud and scams covers phishing, and many firms add cover through business insurance.
When something goes wrong
Image source: pexels.com
A personal data breach is any loss, theft or wrongful sharing of personal data, including an email to the wrong person. If it is likely to put people at risk, you must report it to the ICO within 72 hours of becoming aware, and if the risk is high, tell the people affected too. Dev’s breach involved health data, so he reported it, asked the recipient to delete the email and confirm in writing, and wrote to every patient to apologise and explain. The ICO closed the case with advice, largely because he acted fast and changed his process. Keep a simple log of every breach, even minor ones you decide not to report, with your reasons.
Respecting people’s rights
Image source: pexels.com
Individuals can ask for a copy of the data you hold on them, known as a subject access request, and you normally have one month to respond, free of charge. They can also ask you to correct it, delete it in many cases, or stop using it for marketing. The law now confirms that you only need to carry out reasonable and proportionate searches, not turn the business upside down. Requests do not have to use special wording; an email saying “please send me everything you hold on me” counts. Make sure staff recognise one when it arrives, and keep your records organised so answering is quick. Good record keeping makes this much easier.
The new duty to handle data complaints
Image source: pexels.com
From 19 June 2026, people have a legal right to complain directly to your business if they think you have mishandled their data, and you must have a way for them to do it. In practice that means a simple process: an email address or online form, an acknowledgement within 30 days, a proper look at the complaint and a reply explaining the outcome. Mention it in your privacy notice. The idea is that most complaints get resolved between the business and the customer before anyone goes to the ICO. Dev added a short paragraph and a dedicated email address to his privacy notice in an afternoon.
Suppliers, software and keeping data too long
Your booking system, email provider, accountant and payroll bureau all handle personal data for you. You remain responsible, so choose reputable providers, check where they store data, and make sure a written contract covers how they protect it. Most large software firms include this in their standard terms. Our guide to choosing business software covers what to check. Finally, do not keep data forever. Decide how long you need each type, delete it when that time is up, and clear out old marketing lists. Data you no longer hold cannot be lost, stolen or requested.
What Dev changed
Dev paid the ICO fee, rewrote his privacy notice, removed data he did not need and turned on two-factor authentication for every account. Appointment lists are no longer emailed at all; staff check the booking system instead. He added a complaints email address and a one-page breach plan pinned by the reception desk. It took about two days in total. Data protection for small businesses is not about perfect paperwork. It is about knowing what you hold, keeping it safe and acting quickly and honestly when something goes wrong.
Frequently asked questions
Do small businesses have to pay the ICO fee?
Most do. Micro businesses with turnover up to £632,000 or up to ten staff pay £52 a year, unless an exemption applies.
How quickly must I report a data breach?
Within 72 hours of becoming aware, if it is likely to put people at risk. Tell the people affected too if the risk is high.
Do I still need a cookie banner in 2026?
For advertising cookies, yes. Basic analytics and preference cookies no longer need consent if you explain them and offer an opt-out.
How long do I have to answer a subject access request?
Normally one month, free of charge. You only need to carry out reasonable and proportionate searches for the information.
What is the new data complaints duty?
Since 19 June 2026, businesses must provide a way for people to complain about data handling and acknowledge complaints within 30 days.
Can I send marketing emails to my customers?
Usually, if they bought something similar and were given a simple opt-out when you collected their details and in every message.
This article is general information about UK data protection law as at September 2026, not legal advice. The Data (Use and Access) Act 2025 is still being phased in, so check the ICO website for the latest guidance.



