Cybersecurity

Data Protection and Privacy: UK GDPR Guide for Businesses

UK GDPR imposes legally enforceable obligations on any organisation that processes personal data. This guide covers the core principles, what businesses must do in practice, common compliance mistakes and the technical controls that satisfy Article 32's requirement for appropriate security measures.

AT

AMVIA Team

Editorial

9 min read·Mar 2026

Most data protection failures are not exotic. They are missing paperwork, undefined retention periods, and unencrypted laptops. This guide covers what the UK GDPR actually requires, where SMEs slip up, and the practical controls that move you from "we think we comply" to "we can prove it". For the security side of that duty, see our managed cybersecurity services.

What does UK GDPR require of a business?

The UK GDPR governs how organisations collect, store, process and protect personal data, and it applies to almost every UK business that handles information about identifiable people. It was retained and adapted from the EU GDPR after Brexit, and the ICO is the regulator that enforces it.

The ICO can issue fines of up to £17.5 million or 4% of global annual turnover, whichever is higher, for serious violations (ICO enforcement powers). In practice the ICO focuses enforcement on material harm to data subjects and failures of transparency rather than purely technical breaches, but the financial and reputational fallout from a breach is real either way.

If you process personal data, the law treats you as either a controller (you decide why and how) or a processor (you act on a controller's instructions). Knowing which you are determines your obligations and the contracts you need in place.

What are the seven principles of UK GDPR?

UK GDPR is built on seven principles that apply to every act of personal data processing. They are the test the ICO applies, so treat them as a checklist rather than background theory. Six describe how you must handle data; the seventh, accountability, requires you to prove the other six.

  • Lawfulness, fairness and transparency: have a lawful basis, be honest about use, and do not process data in ways people would not reasonably expect.
  • Purpose limitation: data collected for one purpose cannot be repurposed for something unrelated later.
  • Data minimisation: only collect the data you genuinely need.
  • Accuracy: keep personal data accurate and up to date.
  • Storage limitation: do not retain personal data longer than necessary.
  • Integrity and confidentiality: process data securely against unauthorised access, loss or destruction — this is the security principle.
  • Accountability: demonstrate compliance with evidence, not assurances.

Which lawful basis should you use for processing?

Every act of processing personal data needs one of six lawful bases under UK GDPR. You must decide the basis before you process, document it, and use it consistently. Picking the wrong basis is one of the most common compliance failures the ICO sees, particularly the overuse of consent.

Lawful basisWhen it fitsWatch out for
ConsentMarketing, optional cookies, non-essential processingMust be freely given, specific, unambiguous; never bundled into T&Cs; creates withdrawal obligations
ContractDelivering a service or order to the data subjectOnly covers processing genuinely necessary for the contract
Legal obligationPayroll, tax, statutory reportingMust point to the specific UK law requiring it
Vital interestsLife-or-death situationsRare; almost never the right basis for normal business
Public taskFunctions of public authoritiesLargely irrelevant to private SMEs
Legitimate interestsFraud prevention, network security, B2B marketingRequires a documented Legitimate Interests Assessment (LIA)

Many businesses default to consent when contract or legitimate interests would be more appropriate and far less burdensome. Consent-based processing creates ongoing obligations to manage withdrawals that the other bases do not. The ICO lawful basis guidance walks through each one in detail.

What does Article 32 require for security?

Article 32 of UK GDPR requires "appropriate technical and organisational measures" to ensure a level of security proportionate to the risk. It is deliberately non-prescriptive, but the ICO expects measures that match the sensitivity of the data and the likelihood and severity of potential harm. Encryption, access control and tested recovery are the baseline it points to.

Technical measures the ICO commonly expects:

  • Encryption of personal data at rest and in transit
  • Ongoing confidentiality, integrity and availability of processing systems
  • The ability to restore access to personal data after an incident
  • Regular testing and evaluation of security measures

Organisational measures include staff training, role-based access controls, data processing agreements with suppliers, and documented policies. The NCSC's 10 Steps to Cyber Security maps closely to what Article 32 expects in practice, and certifying to Cyber Essentials is a recognised way to evidence the technical baseline. AMVIA holds Cyber Essentials Plus, so we implement these controls the same way we are independently assessed against them. Microsoft 365 customers can harden much of this through native tooling — see our Microsoft 365 security approach.

How do you handle a personal data breach?

A personal data breach likely to result in a risk to individuals must be reported to the ICO within 72 hours of becoming aware of it. Where the breach is likely to cause high risk, you must also tell the affected individuals without undue delay. The clock is tighter than most teams expect, so the process needs to exist before you need it.

Key points businesses often get wrong:

  • A breach is not just hacking — lost laptops, misdirected emails and unauthorised access by staff all qualify.
  • The 72-hour clock starts when you become aware, not when the breach occurred.
  • You do not need every fact within 72 hours — a partial notification followed by updates is acceptable.
  • Keep an internal register of all breaches, even those not reportable to the ICO.

A fast, well-run response depends on detection. If you cannot see an intrusion, you cannot start the clock — which is why managed cybersecurity monitoring and a rehearsed incident plan matter as much as the policy. The ICO breach reporting guidance sets out exactly what to submit.

What are the most common compliance mistakes?

Based on ICO enforcement trends and practical work across UK SMEs, the failures repeat. None of them require sophisticated attackers — they are gaps in documentation, retention and basic security hygiene that an audit surfaces quickly.

  • No lawful basis documentation: processing data without recording the legal basis or completing the required assessments.
  • Excessive data retention: data held indefinitely because no one defined retention periods or a deletion schedule.
  • Third-party processors without contracts: using cloud, marketing or payroll providers with no Data Processing Agreement (DPA).
  • Inadequate security for the data held: unencrypted laptops, shared passwords, or cloud storage with no access controls over customer databases.
  • Stale privacy notices: a copied notice that does not reflect what the business actually does with data.

Email remains the highest-frequency route to a reportable breach, from misdirected messages to phishing-led account takeover. Tightening it with phishing and email protection closes one of the biggest gaps.

What practical steps should a UK SME take?

Compliance does not require a large compliance department. The steps below cover the majority of what most UK SMEs need in place, and each one produces the evidence the accountability principle demands. Work through them in order and document as you go.

1. Run a data mapping exercise — what personal data you hold, where, why, and who it is shared with. 2. Document a lawful basis for each category of processing. 3. Update your privacy notice to reflect actual processing activities. 4. Define and implement retention schedules per data category. 5. Put DPAs in place with every processor — cloud, marketing tools, payroll. 6. Implement technical controls proportionate to risk — encryption, access controls, MFA. 7. Train staff on the basics and on spotting a potential breach. 8. Create an incident response procedure that includes the 72-hour ICO notification.

The accountability principle means documenting all of the above. The ICO expects to see evidence of compliance, not just a claim of it. A single accountable provider that runs your security and your Microsoft 365 estate makes that evidence far easier to keep current.

Are Your Technical Security Measures GDPR-Appropriate?

Article 32 requires appropriate technical controls for the personal data you process. AMVIA can assess your current security posture against UK GDPR requirements and recommend proportionate improvements.

Frequently Asked Questions