Is GDPR Really a Problem for a Small Business in the UK?
Is GDPR really a problem for small business? See what 99 recent ICO actions show, what usually goes wrong, and which minimum UK controls matter in practice.

Most small businesses are not what dominates the Information Commissioner's Office (ICO) enforcement register. In a reproducible newest-first sample of 99 published actions, only 11 carried the ICO's General business sector tag. That is 11 tagged actions, not “one in ten businesses”, and it does not predict the odds of trouble for any firm 1.
Quick Answer: GDPR can be a problem for a small business, but not in the way fear-led sales copy suggests. Only 11 of 99 sampled ICO actions carried the General business tag. Most firms need a few working controls for complaints, marketing, staff access, incidents and deletion, not an enterprise compliance programme.
GDPR without fear │ ├─ Read evidence carefully │ ├─ Actions are not odds │ ├─ Complaints usually come first │ └─ Serious cases may escalate │ ├─ Control ordinary risks │ ├─ Route complaints and rights │ ├─ Limit staff access │ └─ Preserve marketing objections │ └─ Buy only after proof ├─ Use existing tools ├─ Repair named gaps └─ Review after change
The tree follows the article's proportionate answer: treat enforcement counts as published actions rather than business odds, keep complaints, access and marketing controls working, use existing tools where they suffice, and repair a named gap when a test fails 1,2,3.
Last updated: 26 August 2026. Research checked through 20 August 2026.
What the ICO register actually shows
The useful starting point is the published evidence, with the method visible. On 19 and 20 August 2026, the ICO register returned 220 enforcement actions. The sample queried the official search endpoint under root page ID 17222, ordered the results by newest, took pages 1 to 4 at 25 results per page, kept the first 99 returned records and excluded record 100 1.
The boundary is reproducible. Record 99 was the Devon and Cornwall Police reprimand dated 2 February 2024. Record 100, which was not counted, was the Dorset Police reprimand dated the same day. Anyone repeating the exercise against a later register may see a different first four pages, which is precisely why the cut-off and boundary records matter.
| Sample element | Rule used |
|---|---|
| Register | ICO enforcement register |
| Order | Newest first |
| Pages | 1–4, requesting 25 results per page |
| Included | First 99 returned records |
| Excluded boundary | Record 100 |
| Share of register at the time | 99 of 220, about 45% |
The type tags show what sort of published action the records carried. They do not describe 100 separate actions even though the numbers add to 100.
| ICO type tag | Tags in the 99-action sample |
|---|---|
| Monetary penalties | 36 |
| Reprimands | 29 |
| Enforcement notices | 29 |
| Prosecutions | 6 |
The reason is one double-tagged record. The Police Service of Scotland action carried both Monetary penalties and Reprimands. It is one action with two type tags, so adding the four rows without that explanation creates a false hundredth action.
Sector tags provide the more important concession for a sceptical owner. Criminal justice led the sample, while General business appeared on 11 records.
| Leading ICO sector tag | Tags in the sample |
|---|---|
| Criminal justice | 13 |
| General business | 11 |
| Finance, insurance and credit | 9 |
| Marketing | 8 |
| Local government | 7 |
| Utilities | 6 |
| Central government | 4 |
| Online, technology and telecoms | 4 |
| Health | 4 |
Other sector tags make up the remainder. The visible pattern is a register led by public bodies, regulated sectors and marketing rather than by an ordinary private company selling routine goods or services.
The sample does not measure business risk
The honest conclusion is narrow: ordinary business was not the modal sector in this sample. Eleven of the 99 sampled actions carried the ICO's General business label. That observation rebuts the idea that the published register is primarily a parade of ordinary small firms.
It does not establish the probability that a business will breach the UK GDPR, receive a complaint or face action. Published enforcement counts show what the ICO chose to publish and tag. They cannot reveal unnoticed non-compliance, matters resolved through other routes, future priorities or the denominator of organisations operating in each sector.
There are four limits worth keeping beside every interpretation:
- The sample covers 99 of 220 records, about 45%, rather than the whole register.
- It is newest-first, so it describes a period-shaped slice rather than a random sample.
- The ICO controls the type and sector labels, and a record may carry more than one tag.
- Enforcement counts are records of published action, not a model of infringement or fine risk.
The distinction also prevents a tempting but false sentence. “Eleven of 99 sampled actions carried General business” does not mean “one in ten businesses gets acted against”. No population of businesses was counted, and the sample contains actions rather than firms selected from that population.
The useful middle position is therefore neither panic nor dismissal. The register offers little support for an inspection-scare pitch aimed at every shop, studio or small employer. It still shows that failures involving complaints, marketing and access can become serious when their underlying controls are absent or ignored.
A complaint usually starts before enforcement
For an ordinary firm, the first practical contact is more likely to be a complaint pathway than a monetary penalty. The ICO's small-organisation guidance and complaints framework describe several possible early outcomes: a complaint may be recorded only, the organisation may be asked to review the matter, guidance may be signposted, or a case officer may be allocated 2 3.
That sequence matters because it identifies what the business can actually control. A clear intake route, a named owner, the relevant records and a reasoned response give the organisation something useful to show when asked to review a concern. Silence, delay and contradictory explanations turn a manageable customer problem into evidence that the process is not working.
| Possible stage | What it means operationally | Evidence a small firm should be able to retrieve |
|---|---|---|
| Complaint recorded | The ICO may retain the concern without further intervention | Original message, date received and responsible owner |
| Organisation asked to review | The firm gets an opportunity to reconsider its handling | Facts checked, decision, correction and reply |
| Guidance signposted | The issue may be routed towards published help | Guidance reviewed and resulting action recorded |
| Case officer allocated | The matter receives closer individual handling | Complete timeline, relevant records and contact person |
| Regulatory action considered | Formal powers become one possible later route | Evidence of the underlying controls and remedial work |
Regulatory action remains possible, but it is not the automatic first response to every complaint. The ICO's Regulatory Action Policy frames action as effective, proportionate and targeted; monetary penalties are reserved for serious cases rather than serving as a routine opening move 4.
This is good news with a condition attached. A complaint pathway is less dramatic than an inspection, but it tests whether the business can find facts, explain a decision and correct a failure. A shelf of policies does not answer that test if no one knows which record is current or who has authority to respond.
Employees change the practical question
Some prosecutions in the register concern employees who unlawfully used access, not regulators punishing an employer for merely existing. That shifts the useful question from “Will inspectors arrive?” to “Can one person see, copy or retain more personal information than the job requires?”
In July 2026, the ICO reported that Herefordshire employee Geoffrey Smith had accessed about 490 records and downloaded 94 documents. The case concerned an individual using workplace access unlawfully, and it resulted in a suspended sentence 6. The control lesson is not to treat every member of staff as a suspect. It is to make legitimate access narrow enough that abnormal use can be identified and investigated.
In June 2026, the ICO reported confiscation orders totalling £118,852.32 against two former RAC employees who had copied and sold almost 30,000 lines of personal information. The employer reported the matter and supported the investigation 7. Here, too, the useful evidence points towards access design, logs, prompt departure handling and an incident route.
| Case | What happened | Proportionate control lesson |
|---|---|---|
| Herefordshire employee | About 490 records accessed and 94 documents downloaded | Least privilege plus logs that make unusual access reviewable |
| Former RAC employees | Almost 30,000 lines copied and sold; £118,852.32 confiscation orders | Offboarding, export controls, useful logging and a reporting route |
Least privilege means that a role receives the records and functions needed for its work, not every permission that is convenient to grant. A sales employee may need current customer contact details without needing an export of all former customers. A temporary payroll cover may need time-limited access rather than a permanent role inherited from the previous jobholder.
Logs also need a purpose. Collecting an enormous trail nobody can query creates cost without control. A smaller firm should know which systems contain the most sensitive or exportable information, whether those systems record meaningful access and who can look at the trail after a concern. The answer may be a feature already included in the existing service.
Offboarding closes the final gap. Departures and role changes should trigger access removal, shared-password changes where any remain, return of devices and review of unusual downloads when the circumstances warrant it. None of these steps requires an assumption that a prosecution is likely. They reduce a concrete opportunity for misuse while improving the evidence available after an incident.
Three patterns deserve serious attention
Most routine imperfections do not resemble the hardest cases. The problems that deserve attention are repeated, scalable or difficult to correct after the data has moved.
| Trouble pattern | Early warning | Minimum response |
|---|---|---|
| Ignored or obstructed complaints and rights requests | Messages have no owner, deadlines are missed, or replies contradict records | One intake route, owner, decision log and correction path |
| Scaled nuisance or direct marketing | Suppression preferences are lost, campaigns repeat objections, or lists have unclear origins | Working preference controls, source records and pre-send checks |
| Uncontrolled staff access or exfiltration | Broad roles, shared credentials, bulk exports or access surviving a departure | Least privilege, individual accounts, logs and prompt offboarding |
The first pattern grows through inaction. A customer asks for access, correction or an explanation; the message bounces between inboxes; nobody records the decision; and a later response cannot reconstruct what happened. The ICO's own common-mistakes guidance puts practical correction, security, retention and rights handling in the small-organisation frame rather than demanding an abstract compliance industry 8.
The second pattern scales a defect. One poorly handled marketing preference may be corrected quickly. A list repeatedly used without working suppression or a process that ignores objections can reproduce the same problem across many people. The necessary control is close to the sending system: the preference must survive exports, supplier hand-offs and the next campaign.
The third pattern combines reach with weak evidence. Broad access allows a person to see more than the job needs, while absent or unusable logs make abnormal behaviour difficult to establish. Role changes and departures expose the same weakness because permissions often outlive the reason for granting them.
These patterns share one feature: they are operational. They cannot be solved by changing the date on a policy or asking staff to sign that they have read a generic handbook. Each needs an owner, a working route in the actual system and enough evidence to show what happened.
The minimum cost is smaller than the fear pitch
There is no universal statutory price for “being GDPR compliant”. If an organisation is not exempt from the ICO data protection fee, the current charge is £52 for tier 1 or £78 for tier 2, with a £5 discount for payment by direct debit 5. Those are regulatory fee figures, not the price of a compliance product.
The rest is variable. A simple firm may spend staff time mapping a few systems, correcting a privacy notice and assigning complaint ownership. Another may discover that former staff still have access, deletion is technically difficult or a marketing supplier cannot preserve preferences. Fixing those real systems costs what the problem requires; no responsible article can turn it into one flat number.
| Cost area | Fixed or variable | Honest expectation |
|---|---|---|
| ICO data protection fee, if not exempt | Fixed by tier | £52 tier 1 or £78 tier 2; £5 direct-debit discount |
| Staff time | Variable | Time to map processing, answer requests, review access and maintain evidence |
| System correction | Variable | Cost only where a real access, deletion, security or preference gap exists |
| External advice | Conditional | Useful for a defined difficult question, not an automatic subscription |
| New platform | Optional | Justified only when current tools cannot handle the proven need |
A realistic first review can fit around a short list: where personal information enters, who uses it, which suppliers receive it, how long it remains, how a person exercises rights, who handles an incident and what happens when staff leave. The list may expose work, but it also prevents buying tools for a problem the firm does not have.
The distinction between fixed and variable cost protects both sides of the answer. “It costs only £52” would hide staff time and genuine repair. “Compliance requires an expensive programme” would convert every possible difficulty into a purchase before the processing is understood.
A compact control system for an ordinary firm
The minimum is a connected operating system, not a thick document pack. Six control areas cover the ordinary routes described in the published ICO evidence.
| Control | Smallest useful form | Evidence it is working |
|---|---|---|
| Processing and ownership | One current map of purposes, data, systems, suppliers, retention and owners | A named person can explain each material row |
| Truthful privacy information | Notices matching each real collection route | The notice agrees with forms, systems and supplier use |
| Rights and complaints | One recognised intake route and decision record | Requests can be found, assigned, answered and corrected |
| Staff access and departures | Role-based access, individual accounts, logs and an offboarding trigger | Access reviews and departure closures are retrievable |
| Marketing preferences | Suppression and source controls connected to campaigns | An objection remains effective in the next send |
| Incidents and deletion | A reporting route plus practical deletion triggers | Staff know where to report, and expired data can be removed |
The processing map is the index. It does not need elaborate software, but it must contain facts rather than slogans: why the firm uses the information, which people and systems touch it, where a supplier enters the chain, who owns the activity and what event ends retention. If nobody can name the activity, the surrounding policies cannot be checked against reality.
Privacy information then becomes a comparison exercise. The statement given to a customer or worker should match the collection route and the map. A notice copied from another organisation often describes systems, purposes or sharing that do not exist, while omitting the ones that do.
Rights, complaints, access, marketing and incidents each need a route into named hands. They do not require separate departments. In a five-person business, the owner and an alternate may cover several routes, provided messages do not depend on one private inbox and evidence remains available during absence.
Deletion completes the system because indefinite retention expands every other problem. A workable schedule uses real triggers such as the end of a service, expiry of a justified business need or closure of an account. Universal numbers copied from a template are weaker than a smaller set of justified triggers the systems can actually execute.
Rights and complaints need ownership, not theatre
A business can prepare for complaints without rehearsing litigation. The useful work is mundane: recognise the message, preserve it, identify the person responsible, find the relevant data and decisions, reply consistently, and record any correction.
One public contact route is often enough if staff know what belongs there. The fragile point is recognition: an ordinary message about access, correction, marketing or a previous reply can arrive without formal legal language. Front-line staff need a short set of examples, a safe forwarding route and an alternate owner for absences.
The owner of the route needs access to facts rather than only a template response. That includes the source of the information, what systems contain it, which supplier may need to help, what was previously said to the person and whether a correction has propagated. A short case log should preserve dates, decisions and evidence without becoming a second uncontrolled copy of every record.
The sequence should mirror the ordinary ICO pathway rather than anticipate punishment. First preserve the message and assign the review. Then collect the relevant facts, compare them with the notice and earlier response, make a reasoned decision, send the reply and record any correction. If the ICO later asks the firm to review the matter, the same file already contains the useful chronology 2 3.
A small rehearsal can expose weakness without creating another policy. Using one closed customer query, the alternate owner can locate the collection route, relevant system, earlier reply and any correction, then check whether the case log explains the result. The exercise tests recognition, retrieval and ownership together. Its purpose is process evidence, not a prediction that the ICO will become involved.
Complaint handling also benefits from a correction lane. If the review finds inaccurate information, an unclear notice or a broken preference, the response should connect to the person who can repair the source process. An apology without a system change leaves the same defect ready for the next person.
The no-drama test is simple. If the ICO asks the organisation to review a concern, can the business reconstruct the message, the facts checked, the decision made, the response sent and any correction completed? If yes, the complaint pathway is an ordinary operating process rather than a scramble.
Marketing needs a separate, short lane
Marketing deserves separate attention because a preference failure can be repeated at scale. The practical control is not a long marketing policy. It is the reliable movement of source and suppression information through every list, export, supplier and campaign.
A small firm should be able to answer where an address came from, which preferences and objections attach to it, and how the next send excludes those people. The answer needs to survive a spreadsheet export and a change of provider, not remain trapped in the current tool's interface.
Suppression is different from simple deletion. If an objector's address is erased from one list but not retained in a form that prevents re-import, the next purchased or restored list may add it again. The control should preserve enough information to respect the preference without turning the suppression record into a fresh marketing asset.
Volume changes the consequence of a small mistake. A wrong field on one manual message may affect one person; the same error in an automated campaign may affect thousands. That is why marketing appears prominently in the sampled sector tags even though the sample cannot translate that count into risk 1.
No new platform follows automatically. Existing campaign tools may already hold source, suppression and export controls. The first task is to test whether those features work across the business's actual route, including any agency or supplier hand-off.
What to ignore, and when to buy nothing
Several common purchases solve the appearance of compliance rather than the observed problem. A sceptical owner is right to reject them when they are detached from real processing.
| Ignore this | Why it is weak | Better question |
|---|---|---|
| Fear-led enterprise packs | They assume every possible control belongs in every small firm | Which current processing creates a real gap? |
| A DPO title where the law does not require one | A title does not create ownership or working routes | Who already has authority to own each control? |
| Certification as a substitute for controls | Certification is not proof that today's access, deletion or complaints work | Can the business retrieve current evidence? |
| Large speculative policy libraries | Nobody can connect them to live systems and decisions | Which short record supports an actual task? |
| Universal retention numbers | They ignore purpose, system capability and justified triggers | What event ends the need for this data? |
| A platform bought before discovery | Software may automate the wrong process | Which measured volume or complexity exceeds current tools? |
The no-purchase branch is real. A straightforward business may use a maintained spreadsheet for the processing map, a shared mailbox for rights and complaints, calendar triggers for reviews, and identity features already supplied by its systems. The arrangement is adequate if ownership is clear, access is controlled, evidence is retrievable and the routes work when tested.
Buying becomes rational when a defined limitation appears. Examples include a volume of requests that a shared log cannot safely track, many systems whose access changes cannot be coordinated manually, or deletion work that existing products cannot execute reliably. The requirement should be written before any vendor is chosen.
External advice follows the same rule. It can be valuable for a disputed legal classification, a high-impact incident or a difficult system design. It should answer that named question. An indefinite advisory package is not the default answer to the fact that a business handles names, email addresses or staff records.
Specific refusal is more useful than vague warnings against over-engineering. The owner can decline a DPO badge, a generic policy volume or a platform demo today while still fixing a broken suppression list or closing former-worker access this afternoon.
The controls should follow real events
Maintenance works best when tied to change. A static annual review can miss a new supplier introduced the following week, while repeatedly rewriting unchanged policies consumes time without improving the system.
Useful review triggers include:
- a new product, collection form, system or supplier;
- a material change in purpose, sharing or location;
- a marketing channel expanding in volume or audience;
- a staff member joining, changing role or leaving;
- a rights request or complaint exposing a weak route;
- an incident showing that access, logging or escalation failed; and
- a retention trigger that systems cannot carry out as expected.
Each trigger should point to the affected part of the compact control set. A new payroll provider calls for an update to the processing map, supplier facts, privacy information and access. It does not require every policy in the business to be reformatted.
Tests can stay small. Send a sample complaint to the public route and see whether it reaches the owner. Remove access for a test account or departed role and verify the result. Trace one marketing objection into the next campaign. Select one expired record and confirm that the deletion route works. These checks produce evidence about the system rather than confidence about the wording of a document.
The ICO's common-mistakes guidance supports this practical emphasis: correct the routines around security, rights, retention and transparency rather than treating data protection as a decorative file 8. A triggered review also makes variable cost visible because the business spends time where a change has actually occurred.
A proportionate answer for the sceptic
The sceptical opening position is partly right. The newest 99 actions in the disclosed sample were not dominated by ordinary general business. Public bodies, regulated sectors and marketing feature heavily, and enforcement counts cannot be converted into the odds that a small firm will be fined.
The stronger conclusion is not that the UK GDPR can be ignored. Ordinary firms encounter the subject through customer complaints, marketing preferences, staff permissions, incidents, supplier changes and deletion. Those are familiar management problems with a data-protection dimension, not reasons to assume an inspection is imminent.
A proportionate business can therefore keep the control surface small: one map, truthful notices, a complaint and rights route, controlled staff access and departures, working marketing preferences, an incident path and deliberate deletion. The fixed fee, where payable, is visible; time and system repair remain variable 5.
There are two honest branches from that list. If processing is simple, the named owners can retrieve current evidence, departures close access, preferences survive the next campaign and the complaint route works, the answer is buy nothing. Maintain the controls with existing tools and revisit them when a real event changes the processing.
If a test fails, the answer is repair the named gap. Former-worker access calls for an identity and offboarding fix. A lost objection calls for a suppression fix. An unanswered complaint calls for ownership and case evidence. New software or advice enters only when the defined repair cannot be carried safely by the people and systems already available.
The review trigger is change, friction or failure, not fear generated by a register count. That rule keeps the response proportionate while leaving no excuse to ignore a broken control.
The register sample is useful precisely because its limits remain attached. It removes the weakest fear pitch while leaving a practical reason to care: a few controls solve problems a small employer can genuinely meet, and they create the evidence needed when an ordinary complaint asks the business to explain itself.
Frequently Asked Questions
Is GDPR really a problem for a small UK business?
Does the ICO usually fine a small business after a complaint?
What does the sample of 99 ICO actions prove?
How much does basic GDPR compliance cost a small business?
Does every small business need a data protection officer?
What are the most important GDPR controls for a small employer?
Should a small business buy GDPR software or a template pack?
When should a small business review its GDPR controls?
Sources
- 1.ICO enforcement register — Information Commissioner's Office
- 2.ICO small-business common topics, including first complaint outcomes and cost — Information Commissioner's Office
- 3.ICO data-protection complaints framework — Information Commissioner's Office
- 4.ICO Regulatory Action Policy — Information Commissioner's Office
- 5.ICO data protection fee guide — Information Commissioner's Office
- 6.Herefordshire employee prosecution, 21 July 2026 — Information Commissioner's Office · 2026
- 7.Former RAC employee confiscation orders, 4 June 2026 — Information Commissioner's Office · 2026
- 8.ICO common mistakes for small organisations — Information Commissioner's Office
Want this run on your business?
AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.
You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.