UK GDPR Small Business Guide: What to Do First in 2026
A practical UK GDPR small business guide: map personal data, choose lawful bases, write usable records, handle rights, secure data and review the system.

A customer questionnaire asks for the company's lawful bases, retention schedule, incident process and DPO contact. Sales needs it by Thursday. Nobody owns the answers, but customer and staff data already live across inboxes, payroll, a booking tool and two cloud platforms. This UK GDPR small business guide turns that moment into an evidence plan rather than a policy-shopping exercise.
Quick Answer. A UK GDPR small business guide should produce evidence: a processing map, defined purposes and lawful bases, privacy information, supplier controls, retention rules, rights and breach procedures, security and named owners. Check the ICO fee separately. Small businesses do not need a certificate or consent for everything; records must match real work 1,3,5.
UK GDPR operating record │ ├─ Map real processing │ ├─ Follow customer journeys │ ├─ Name systems and owners │ └─ Mark unknowns explicitly │ ├─ Operate core controls │ ├─ Choose lawful bases │ ├─ Inform people accurately │ └─ Handle rights and breaches │ └─ Review proportionately ├─ Test suppliers and security ├─ Delete on real triggers └─ Reopen records after change
The tree follows the article's operating logic: map real processing and name owners; run lawful-basis, transparency, supplier, rights, retention, security and breach controls; then reopen the relevant records when processing changes 1,3,5.
Treat compliance as an operating record, not a certificate
UK GDPR does not create a universal certificate that makes processing compliant. It sets principles, rights and obligations that must be reflected in decisions and day-to-day controls 1,2,3. Accountability means taking responsibility for compliance and being able to demonstrate it.
For a small business, demonstration is concrete. A privacy notice matches the booking form. The customer platform has an owner and retention rule. A former worker can be located across payroll and files. A marketing objection reaches the mailing tool. A supplier contract identifies its role. An incident record shows when risk was assessed.
The first baseline should answer six questions:
| Question the business must answer | Evidence that answers it |
|---|---|
| What personal data do we use? | System-and-data map with sources and recipients |
| Why are we using it? | Purpose and lawful-basis record |
| What have people been told? | Current notices tied to collection points |
| Who receives or hosts it? | Supplier, processor, sharing and transfer register |
| How do rights and incidents work? | Tested procedures, logs and owners |
| How is it protected and removed? | Security actions, access controls and retention schedule |
These are not six documents imposed by name. One well-designed register can carry several answers; a complex service may need supporting assessments. The test is whether someone can find evidence and operate the decision, not how many files exist.
Map the data by following real work
A useful inventory starts with events, not abstract data categories. A customer requests a quote, accepts a contract, pays an invoice, contacts support and closes an account. A worker applies, joins, receives pay, takes leave and leaves. Each event exposes systems, people, purposes and retention triggers.
Evidence improves when the people doing the work are interviewed while looking at the systems they use. The office manager knows about a shared drive that procurement forgot, sales exports contact lists into a campaign tool, finance keeps invoice attachments in email, and a supplier has administrator access that is absent from the contract register.
| Field | Practical question |
|---|---|
| Processing activity | What action happens to whose data? |
| Purpose | What specific outcome requires it? |
| Data and people | Which fields and which groups are involved? |
| Source | Person, employer, public source, device or another organisation? |
| Systems and locations | Where is it entered, copied, backed up or viewed? |
| Recipients | Staff, suppliers, group entities, customers or authorities? |
| Owner | Who can explain and change the operation? |
| Trigger | What change or date requires review or deletion? |
“CRM data” is not a complete entry because the same platform may contain delivery contacts, support history, fraud notes and optional marketing preferences with different purposes and periods. The record should split when a rights request, deletion or change of use would produce a different answer.
The map should include paper, messaging tools, local devices, archives, recordings and supplier access. It does not need field-level perfection before action begins. Mark unknowns explicitly, assign owners and close the highest-risk gaps first.
Give every purpose a lawful basis before processing
Current UK law provides seven lawful bases: consent, contract, legal obligation, vital interests, public task, legitimate interests and recognised legitimate interest for five pre-approved public-interest conditions 1,4,9. A business does not select one basis for the company. It identifies the purpose and processing operation, then chooses the basis that genuinely fits those facts.
Contract applies only where processing is necessary to perform a contract with the person or take requested steps before it. Legal obligation needs an actual legal duty. Legitimate interests needs a specific purpose, necessity and balance against people's interests, rights and freedoms. Consent needs a genuine, informed choice and effective withdrawal. Public task and vital interests have their own narrower contexts 1,4.
| Purpose | Evidence to keep |
|---|---|
| Deliver a purchased service | Contract necessity and fields actually required |
| Meet tax or employment duty | Instrument or duty, data and period |
| Prevent account fraud | Legitimate purpose, necessity and balancing assessment |
| Send optional promotion | PECR position plus UK GDPR basis and preference evidence |
| Publish an optional case study | Consent wording, action, version and withdrawal path |
Do not ask for consent where the business will process regardless of the answer. That converts a duty or necessary operation into a fictional choice. Conversely, legitimate interests should not become a label for activities the business has never tested against expectations and impact.
Recognised legitimate interest removes the balancing test only for its five pre-approved conditions. Necessity still has to be shown, and the basis is not an exemption from transparency, individual rights or the data-protection principles. Ordinary direct marketing remains under standard legitimate interests where appropriate, with the full purpose, necessity and balancing test and a separate PECR analysis 4,9.
Record the basis before processing and expose it through the required privacy information. If the purpose changes, reassess compatibility and the basis rather than relabelling after a complaint. The lawful-basis record is a design input, not a defence written at the end.
Put accurate information at every collection point
People should not need to discover an unseen privacy policy after data has been collected. Information must match how data arrives: website form, phone call, application, CCTV area, referral, supplier import or connected service 1. The full notice and layered explanation should be consistent.
Useful information identifies the controller and contact route, purposes, lawful bases, recipients, retention approach, rights, complaint route and relevant transfer information. Where data comes from another source, additional source information can be required. The words should describe the live systems, not a template's possible future.
A collection-point audit compares the live workflow with the notice:
- Open the form, script or workflow as a new user.
- Capture the fields, defaults, trackers and actual recipients.
- Compare each purpose and basis with the register.
- Check that optional choices are genuinely optional and recorded.
- Confirm the notice version and update route.
- Test what happens after refusal or withdrawal.
Privacy information is not consent. A notice explains processing; it does not turn a mandatory field into an optional choice. Advertising, tracking and other consent-required storage or access technologies must not run before valid consent; qualifying statistical purposes use a separate narrow exception, not the notice itself 11. Keep transparency, lawful basis and any PECR condition separate.
Work one customer journey through all six records
Consider a two-person training company that takes bookings through its website. A buyer enters a name, work email, accessibility request and card-payment details. The booking platform sends confirmations, a payment provider processes the card, a trainer sees the attendance list, finance keeps the invoice and marketing wants to offer another course.
The data map separates those operations. Delivery needs contact and course information; payment goes to a specialist provider; an accessibility request may reveal more protected information and needs narrower access; finance keeps the transaction under its own driver; optional promotion receives a separate channel and preference analysis. “Booking data” is too broad to operate any of those outcomes.
The purpose-and-basis record then assigns facts rather than one label. Contract necessity may support information genuinely needed to deliver the booked course. A legal obligation can support defined financial records where the actual duty is recorded. Optional marketing is not made necessary by placing it in the same form, and any PECR requirement remains separate 1,4.
Privacy information appears where the data is collected and explains the relevant purposes, recipients and periods. The supplier register identifies the booking and payment services, their roles, access and deletion. The retention schedule begins from useful triggers: course completion, end of financial period or withdrawal of an optional preference, not one date for the whole customer.
Now test rights. An access request should find the booking, support email, attendance list, invoice and relevant supplier-held data. Erasure may remove optional marketing and expired support data while a justified financial record remains. The response explains the distinction instead of promising that one delete button erases every legal and operational record 1,7.
Finally test an incident. If the trainer sends the attendance and accessibility list to the wrong venue, the urgent route should preserve the message, contain disclosure, set awareness and assess consequences. The same map already identifies data, people, supplier and owner. Good accountability makes incident work faster because the organisation is not discovering its own system during the clock.
This journey is the operating model in miniature. One factual map feeds notices, suppliers, retention, rights, security and breaches without turning them into one undifferentiated document. When the business adds recorded online sessions, that new operation reopens the affected records rather than forcing a complete restart.
Control suppliers, sharing and international access
Small businesses often outsource more processing than larger organisations. Payroll, booking, support, email, storage, website analytics and recruitment may all involve suppliers. The controller remains responsible for choosing suitable processors and using appropriate terms 1,5,6.
A supplier record should contain service, data, people, purpose, role, locations, subprocessors, access, security evidence, retention, deletion and exit route. It distinguishes a processor acting on instructions from a separate controller using data for its own purposes, so contract language can follow the real relationship.
Access from another country can create a transfer question even when the supplier advertises UK hosting. Map legal entities, support locations and subprocessor access. Identify the applicable UK transfer route for each separate recipient rather than accepting “global infrastructure” as the analysis 1.
Before procurement, answer operational questions. Can the business export data for a subject access request? Can it delete an account and know what remains in backups? Are administrator actions logged? Who owns encryption keys? What happens to data when the contract ends? A low monthly price can conceal expensive rights and exit work.
| Supplier event | Required response |
|---|---|
| New tool proposed | Privacy, security, role, transfer and contract review before upload |
| Subprocessor changes | Assess new recipient, location and objections or exit rights |
| Security incident | Processor alert route, evidence and controller decision owner |
| Rights request | Search, export, correction, restriction and deletion assistance |
| Contract ends | Return, deletion, residual backups and access removal evidence |
High-impact suppliers come first because a brochure tool holding public business contacts differs materially from a payroll service, health platform or system with broad production access. Proportionate diligence means the evidence follows risk, not that supplier review disappears for small organisations.
Build rights handling around ordinary channels
People do not have to use a legal phrase or dedicated form to exercise a right. A request may reach support, a manager, social media or an employee inbox. Staff need a recognition and routing rule so the business does not lose time while deciding whether the message “counts” 1,7.
The Data (Use and Access) Act 2025 also creates a specific complaints-handling duty. The organisation must facilitate data-protection complaints through appropriate steps, which could include an electronically completable complaint form or another suitable means. It must acknowledge a complaint within 30 days, make appropriate enquiries and tell the complainant about progress and the outcome without undue delay. Complaint handling should have an owner and record the original message, acknowledgement, enquiries, progress, outcome and response 9,10.
For access requests, record receipt, identity steps, scope, systems searched, recipients, exemptions or restrictions considered, redaction, response and delivery 7. The one-month period has specific rules and any extension requires conditions and timely communication; a difficult search is not automatic permission to delay.
Other rights require their own outcomes. Rectification changes inaccurate data and may require recipient action. Erasure is not absolute where another lawful need remains. Restriction limits use while an issue is resolved. Objection has different consequences for direct marketing and other processing. Portability applies only in defined circumstances 1.
| Day-one rights step | Evidence |
|---|---|
| Recognise and route | Original request, time, channel and owner |
| Confirm identity proportionately | Risk, information requested and result |
| Preserve relevant material | Systems, holds and routine deletion paused where necessary |
| Clarify without narrowing unfairly | Scope conversation and agreed searches |
| Search and decide | Sources, recipients, restrictions and reviewer |
| Respond securely | Content, format, verified route and date |
A rehearsal before a request arrives can trace one real customer record through sales, billing, support, files and suppliers without sending or exposing it. Gaps become backlog items with owners, and the exercise often reveals the same inventory and access weaknesses that affect retention and incidents.
Give retention a trigger, period and end action
UK GDPR does not prescribe one universal period. Storage limitation requires personal data to be kept no longer than necessary for the purpose 1,3. Other law, claims, contracts and regulators can supply specific drivers, so “GDPR says six years” is not a retention rule.
A usable schedule names the record, owner, purpose, trigger, active period, any hold, end action and evidence of disposal. “Seven years from creation” may be wrong if the business relationship lasts six years. “Six years after contract end” creates a calculable trigger.
Backups need a practical explanation. Immediate selective deletion may not be possible in immutable backup sets, but restored data should not quietly return to live use. Document isolation, access, overwrite cycle and restoration controls. Delete uncontrolled exports and local copies rather than treating the backup design as permission to keep everything.
Review exceptions. A complaint, legal claim, fraud investigation or rights request can require a bounded hold. Record scope, reason, owner and review date. When the hold ends, the normal schedule resumes; exceptions do not become a permanent archive.
The schedule should drive system configuration. Automatic deletion, mailbox rules, account closure and supplier instructions are stronger than reminders. Sample records after the deletion date and verify what happened, including downstream copies.
Make security proportionate and observable
UK GDPR requires appropriate technical and organisational measures, assessed against risk 1,6. A small organisation may not need an enterprise security department, but it does need controls that match the data, access and likely consequences.
Identity and access provide the first security layer: individual accounts, strong authentication, role-based permissions, prompt leaver removal and administrator separation. Shared passwords erase accountability, while an export-permission review shows who can remove entire customer, payroll or support datasets.
Maintained systems and devices require supported software, timely patches, encrypted portable devices, protected backups, configured logs, restricted remote access and tested restoration. Security descriptions should be verified through settings and tests rather than copied from supplier marketing 6.
Human controls need workflow design. A warning about misdirected email is weaker than recipient confirmation for sensitive attachments, restricted autofill, secure portals and delayed send. Training is most useful when paired with a control and an incident route.
| Risk | Observable control |
|---|---|
| Former worker retains access | Leaver checklist plus account review evidence |
| Export sent to wrong recipient | Approved secure channel and recipient verification |
| Device lost | Encryption, remote response and asset ownership |
| Ransomware affects availability | Segregated backups and completed restore test |
| Supplier account compromised | MFA, least privilege, alerts and access logs |
| Sensitive file overshared | Default restrictions and periodic sharing review |
Maintain an improvement record with risk, action, owner, date and verification. “Enable MFA” is incomplete until coverage is measured and exceptions are closed. The aim is evidence that the control operates.
Prepare for personal data breaches before the clock starts
A personal data breach can affect confidentiality, integrity or availability; it is not limited to hacking 1. Misdirected email, lost equipment, incorrect permissions, accidental deletion and unavailable services can all require assessment.
The response procedure names an urgent channel, incident owner, containment roles, awareness timestamp, risk assessment, ICO decision, individual-notification decision, processor coordination and evidence log. The 72-hour period for ICO notification runs from awareness where the reporting threshold is met, not from completion of root-cause analysis 1.
Every breach is documented, including facts, effects and remedial action. For non-reporting, preserve why risk was unlikely. For reporting, preserve phased submissions, receipts and updates. The decision can change when new evidence appears, so version the record.
A short exercise exposes whether the procedure works: a staff member reports a public sharing link at 10:00, and the team must disable it, preserve logs, identify data, set awareness, assess risk and assign the next checkpoint without debating ownership for an hour. The exercise tests routing as much as legal knowledge.
Check the ICO fee and statutory roles separately
The data protection fee is a separate administrative obligation, not a GDPR certificate. Controllers may need to pay unless an exemption applies. Use the ICO's live fee assessment for the organisation's current processing, record the result and date, and review it when activities or structure change 8.
Do not infer exemption from company size, low revenue or being a charity without applying the actual conditions. Equally, paying the fee does not prove compliance with principles, rights or security. Keep the receipt with the accountability record, but do not present it as approval.
A statutory data protection officer is also not automatic. The mandatory tests include public authorities or bodies and particular core activities involving large-scale regular and systematic monitoring or large-scale processing of protected data 1,2. A supplier to a public body does not become one merely through the contract.
Where no statutory DPO is required, assign a privacy owner with authority, time, access to management and expertise. Do not call that person a DPO casually if the organisation intends none of the statutory position's independence and protections. Record the assessment and revisit it when core activities change.
Know what a small business does not automatically need
Proportionate compliance removes fictional work without removing real duties. A small business does not automatically need:
- a purchased GDPR certificate;
- consent for every processing operation;
- a statutory DPO;
- enterprise-scale committees or policy libraries;
- indefinite deletion of every historic record;
- a full-time privacy employee;
- identical controls for low-risk contact data and high-impact payroll or health data.
It does need decisions that survive a question. A short legitimate-interests assessment based on real facts is stronger than a long generic policy. A two-page retention schedule connected to system deletion is stronger than a forty-page standard nobody operates.
Limited exemptions must be applied to the actual provision and facts. They should not be converted into a general “under 250 employees” escape. The organisation still needs enough records to manage purposes, rights, security, incidents and suppliers even where a particular documentation obligation is reduced 1,5.
The honest proportionality test is impact. Spend more effort where data is sensitive, people are vulnerable, monitoring is systematic, decisions have consequences, access is broad or recovery is difficult. Spend less where use is narrow, expected, short-lived and well controlled. Record the reason in both cases.
Turn the first questionnaire into a 30-day plan
A customer questionnaire should never be answered from memory. Each question belongs in a working evidence table marked evidenced, partly evidenced, not applicable with reason or action required, with the source attached for every green answer.
| Days | Outcome |
|---|---|
| 1–3 | Owner named, systems listed, urgent risks and fee position checked |
| 4–10 | Processing map, purposes, bases, suppliers and notices reconciled |
| 11–17 | Rights, retention and incident workflows written and tested |
| 18–24 | High-risk access, security and supplier gaps closed or owned |
| 25–30 | Evidence reviewed, questionnaire answered and review cycle scheduled |
Unsupported high-impact claims receive priority. A question about encrypted portable devices requires measured coverage, while a question about supplier assessment requires the current supplier record; a planned action cannot become “yes” merely because the contract is valuable.
The output is not a clean score. It is a dated evidence pack and prioritised gap list with owners. Some controls already work and need documenting; others need repair. The customer receives answers that match reality, and management receives a plan tied to actual risk.
Follow each open branch into the deeper decision
This cornerstone establishes the common evidence, but it should not force every specialist decision into one oversized checklist. Each branch below begins when the baseline uncovers a fact that needs its own test, examples and operating record. The same map, owner and evidence pack feed those decisions, so deeper work extends the system instead of starting another compliance project.
Lawful basis
The lawful-basis term page becomes useful when a questionnaire or register uses the phrase and the reader cannot distinguish it from consent. It defines all seven bases, what the choice covers and what it cannot cure. The decision page on legitimate interests versus consent begins one step later, where a real campaign or feature must choose between a genuine optional choice and a documented purpose, necessity and balance, with PECR treated as an additional channel rule 1,4,9.
The handoff is visible in the register. A row marked “legitimate interests” without an attached assessment opens the decision branch. A row marked “consent” where processing continues after refusal does the same. The deeper record returns a corrected basis, tested rights path and system configuration to the baseline rather than creating a free-standing legal memo.
Personal data breaches
The breach definition page answers whether the event counts at all, including loss of availability or integrity and ordinary errors that involve no attacker. The reportable-breach decision page takes over once a breach exists: it fixes awareness time, assesses risk to people, distinguishes the ICO threshold from the higher individual-notification threshold and records a defensible no-report decision where risk is unlikely 1.
An incident procedure that links only to “report within 72 hours” has skipped the first branch and compressed two thresholds into one slogan. The baseline should point staff to the urgent route, while the deeper decision record carries the chronology, evidence, staged notification and changing risk conclusion.
Subject access requests
The subject-access term page begins when an ordinary message asks for personal data without using a form or legal phrase. It explains recognition, the one-month clock, limited extension and the difference from freedom of information or erasure 7. The baseline rights procedure then supplies the organisation's systems, owners, identity control, search record, redaction decision and secure response.
A test request feeds practical findings back into the map. If support searches tickets but misses call recordings, the problem is not confined to the access response; the inventory, notice, retention and supplier records are incomplete too. Rights testing therefore improves the shared evidence system.
Retention
The retention procedure begins where the baseline cannot name a calculable trigger or where several legal and business drivers have been collapsed into “keep for six years”. It separates UK GDPR's storage-limitation principle from tax, employment, claims and sector periods, then works those drivers into a schedule with holds, backups, deletion and verification 1,3.
The completed schedule returns system settings and evidence to the baseline. A booking platform may automatically remove routine account data after the documented event while finance records follow a separate driver and an active dispute receives a bounded hold. One customer no longer implies one deletion date.
Cookies and electronic choices
The cookie procedure opens when the website map finds analytics, advertising, embedded media or similar storage and access technologies. It starts with PECR and separates consent-required advertising, tracking and other technologies from strictly necessary uses and the narrow statistical-purposes exception. Advertising, tracking and other consent-required code must be blocked before a valid choice 11. The UK GDPR record still needs purposes, basis, recipients and retention, but it cannot authorise a channel that PECR does not permit.
Qualifying statistics may run without consent only when they are used solely to improve the site or service, produce aggregate information that cannot identify anyone, do not support decisions about or track individuals, come with clear information and a simple free objection, and involve a third party only as a processor 11. This branch should return technical evidence, not only banner wording: a pre-consent scan, exception-conditions record, consent-state behaviour, equal withdrawal route and vendor configuration. Those results update the supplier register, notice, campaign record and future release test.
Workplace CCTV
The CCTV procedure opens when a theft, insurer or safety concern becomes a camera proposal. It replaces “put up a sign” with a defined event, alternatives, basis, DPIA screening, worker information, field-of-view controls, access, retention and rights handling. Audio, covert monitoring and analytics remain separate higher-impact decisions rather than default device features 1,3,6.
The approved camera settings and review trigger return to the security and processing records. If a manager later wants productivity footage from a theft-prevention camera, the baseline makes that purpose change visible before informal viewing becomes the new normal.
Territorial scope and overseas customers
The territorial-scope decision page opens when customer location, a new market, overseas staff or foreign supplier access leads someone to ask whether UK GDPR applies. It tests establishment and connected activity first, then UK-directed offers or behaviour monitoring for non-UK organisations. Representatives, parallel EU scope and international transfers are separate outputs, not shortcuts based on a country field 1,2.
Its result updates entity, notice, supplier and transfer records. A UK business with only overseas customers may remain within UK GDPR through its establishment, while a non-UK provider can create UK scope through intentional UK activity. The baseline should preserve the facts and review triggers that make either conclusion true.
The common return path
Each specialist page must return something operable: a basis and assessment, breach chronology, access-search record, retention trigger, cookie configuration, camera settings or territorial decision. If the output is merely more prose, the branch has not rejoined the business. The central owner links that evidence to systems and schedules the trigger that reopens it.
This is also how a small organisation keeps the programme proportionate. It does not perform every deep analysis for every low-impact activity. It recognises which fact opens a branch, runs the relevant method and brings the result back into one maintained evidence set. Complexity follows the processing rather than the size of the policy library.
Keep the system current after the first pass
Compliance drifts when the business changes. New products, data, suppliers, markets, monitoring, automated decisions and campaigns can alter purposes, bases, notices, transfers and risk. Make privacy review part of procurement, product change, marketing launch and employee onboarding rather than an annual legal event.
Triggers and cadence work together: high-impact systems receive scheduled access, retention and supplier checks; every new tool receives pre-use review; rights and incident logs are reviewed for repeated causes; and notices are compared with live collection points after material change.
| Trigger | Record to reopen |
|---|---|
| New data field or inference | Purpose, basis, minimisation, notice and risk |
| New supplier or support country | Role, contract, security, transfer and exit |
| New campaign or tracker | PECR, basis, choice and preference evidence |
| New market | Territorial scope, representatives, notices and transfers |
| Complaint or rights pattern | Process, training, system search and root cause |
| Incident | Security, retention, supplier and design actions |
Management review should ask for evidence and unresolved decisions, not a colour alone. Which systems have no owner? Which processor cannot delete? Which retention trigger is not implemented? Which access request missed a source? These questions make accountability useful.
The first action today is to name one owner and schedule a ninety-minute data walk with sales, operations, finance and whoever administers systems. Follow one customer and one worker through the business. The resulting map is the foundation for every other article in this wave: lawful basis, breach, access, retention, cookies, monitoring, territorial scope and the decisions between them.
Last updated: 26 August 2026.
Frequently Asked Questions
Does every UK small business have to comply with UK GDPR?
Do small businesses need to register with the ICO?
Does a small business need a data protection officer?
Is customer consent required for all personal-data use?
What documents should a small business create first?
How long does UK GDPR compliance take?
Do we need to delete all old personal data?
What is the first thing to do after receiving a GDPR questionnaire?
Sources
- 1.UK GDPR (retained) — legislation.gov.uk · 2026
- 2.Data Protection Act 2018 — legislation.gov.uk · 2026
- 3.A guide to the data protection principles — Information Commissioner's Office · 2026
- 4.A guide to lawful basis — Information Commissioner's Office · 2026
- 5.Documentation — Information Commissioner's Office · 2026
- 6.A guide to data security — Information Commissioner's Office · 2026
- 7.Right of access — Information Commissioner's Office · 2026
- 8.Data protection fee — Information Commissioner's Office · 2026
- 9.Data (Use and Access) Act 2025 — legislation.gov.uk · 2026
- 10.How to deal with data protection complaints — Information Commissioner's Office · 2026
- 11.What are the exceptions? — Information Commissioner's Office · 2026
Want this run on your business?
AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.
You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.