Journey

Understanding UK GDPR from scratch

A complete introduction to UK data protection law for businesses. Learn the seven principles, six lawful bases, individual rights, ICO registration requirements, and what happens if you get it wrong. No prior knowledge required.

Starting a Business Updated 15 September 2026
7 milestones references 4 guides

Why data protection matters for your business

If your business holds information about people, UK data protection law applies to you. This includes customer names, employee records, supplier contacts, and even CCTV footage. Understanding UK GDPR is not optional - it is a legal requirement with serious consequences for non-compliance.

This learning path takes you from zero knowledge to confident understanding of your obligations.

  1. Learn the fundamentals

    Start with the core principles that govern all data processing. These seven principles shape every decision you make about personal data - from collection to deletion.

    Data protection for businesses: the complete guide

    Understand the seven principles, who must comply, what counts as personal data, and how to build compliance into your business operations.

  2. Understand your lawful basis options

    Before you process any personal data, you must identify a valid legal reason. UK GDPR provides six lawful bases (recently expanded to seven). Choosing the right one is critical - you cannot easily change it later.

  3. Know the rights individuals have

    People have rights over their personal data. When someone asks for a copy of their data or asks you to delete it, you must respond within one month. Knowing these rights helps you design compliant processes from the start.

  4. Register with the ICO

    Almost every business that processes personal data must register with the Information Commissioner's Office and pay an annual fee. This is a legal requirement - failure to register is a criminal offence.

    Register with the ICO: step-by-step

    How to check if you need to register, determine your fee tier, complete the registration process, and keep your registration current.

  5. Prepare for data breaches

    Data breaches happen to businesses of all sizes. When they do, you have just 72 hours to report to the ICO if individuals are at risk. Understanding the rules before a breach occurs means you can respond quickly when it matters.

    Data breach response requirements

    Learn what counts as a reportable breach, how to assess risk, the 72-hour notification deadline, and when you must tell affected individuals.

  6. Understand international transfer rules

    Sending personal data outside the UK requires additional safeguards. This includes using cloud services hosted abroad, sharing data with overseas suppliers, or having an international head office. Many businesses underestimate how many transfers they make.

    International data transfers explained

    Adequacy decisions, Standard Contractual Clauses, the UK IDTA, Transfer Risk Assessments - understand what applies to your business.

  7. Understand the consequences

    UK GDPR has teeth. The ICO can issue substantial fines, require you to stop processing data, conduct compulsory audits, and publicise your failings. Understanding the penalty framework helps you prioritise your compliance efforts.

You have completed this learning path

You now understand the fundamentals of UK data protection law. Your next steps are practical:

  • Register with the ICO if you have not already
  • Document your lawful basis for each type of data processing
  • Create or update your privacy notice
  • Establish processes for handling data subject requests
  • Prepare a data breach response plan

For ongoing compliance guidance, see our data protection compliance journey.