Journey

Meet your data protection obligations

Ensure your business complies with UK GDPR and the Data Protection Act 2018. Covers ICO registration, lawful basis for processing, data subject rights, international transfers, breach notification, and electronic marketing rules under PECR.

Running a Business Updated 15 September 2026
8 milestones references 4 guides

Data protection compliance for UK businesses

Every business that processes personal data must comply with UK GDPR and the Data Protection Act 2018. This includes collecting customer details, managing employee records, operating CCTV, or running marketing campaigns.

The Information Commissioner's Office (ICO) enforces data protection law. Serious breaches can result in fines of up to 17.5 million pounds or 4% of annual worldwide turnover (whichever is higher). Beyond fines, poor data protection damages customer trust and can disrupt your business operations.

  1. Register with the Information Commissioner's Office

    Most businesses that process personal data must pay an annual data protection fee to the ICO. This applies whether you have one employee or thousands. The fee depends on your size and turnover.

    Register with the ICO and understand your obligations

    Learn about UK GDPR requirements, the seven data protection principles, and how to register your business with the ICO.

  2. Identify your lawful basis for processing

    You need a valid legal reason (lawful basis) for every type of personal data you process. The six lawful bases under UK GDPR are: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Choosing the wrong basis - or having no basis at all - is a fundamental breach.

  3. Respond to data subject rights requests

    Individuals have rights over their personal data. When someone makes a request - such as asking for a copy of their data or asking you to delete it - you must respond within one month. Failing to do so is a breach that individuals can complain to the ICO about.

    Data protection overview and compliance requirements

    Detailed guidance on handling Subject Access Requests, erasure requests, and other data subject rights.

  4. Ensure lawful international data transfers

    Transferring personal data outside the UK requires additional safeguards. This applies whenever you use cloud services hosted abroad, share data with overseas partners, or send employee information to a foreign head office. Many businesses underestimate how many international transfers they make.

    International data transfer requirements

    Understand adequacy decisions, Standard Contractual Clauses, the UK IDTA, Transfer Risk Assessments, and when exemptions apply.

  5. Report data breaches within 72 hours

    When a data breach occurs, you have just 72 hours to report it to the ICO if it poses a risk to individuals. Some breaches also require you to notify the affected individuals directly. Having a breach response plan before an incident occurs is essential - you will not have time to work out your process during a crisis.

    Data breach response requirements

    What counts as a reportable breach, how to assess risk, the 72-hour notification deadline, and what to tell affected individuals.

  6. Comply with electronic marketing rules (PECR)

    The Privacy and Electronic Communications Regulations (PECR) set additional rules for marketing emails, texts, and telephone calls. These work alongside UK GDPR. Getting consent wrong for marketing is one of the most common reasons for ICO enforcement action.

    Electronic marketing rules under PECR

    Consent requirements, the soft opt-in exception for existing customers, TPS screening for calls, and avoiding ICO penalties.

  7. Understand the consequences of non-compliance

    The ICO has significant enforcement powers. Beyond fines, the ICO can issue enforcement notices requiring you to stop processing data, conduct compulsory audits, and publicise your failings. Serious breaches damage your reputation and can result in legal action from affected individuals.

  8. Maintain ongoing compliance

    Data protection is not a one-off exercise. Review your processing activities regularly, update your privacy notices when things change, train new staff, and keep records of your compliance efforts. The ICO expects organisations to embed data protection into their operations.