For most small UK businesses, data protection is a short list: only collect personal details you need, keep them safe, say what you do with them, and deal with it if someone asks to see or delete their information. If you hold names, emails, phone numbers or addresses, the UK GDPR and the Data Protection Act apply. Meeting that bar is mostly care and honesty, not a panic project. This is general guidance, not legal advice. The Information Commissioner’s Office (ICO) is the source of truth. Read their small-business material when your situation is not ordinary.
A website that collects a contact form is part of this. So is a spreadsheet of customers on a laptop. The law does not wait until you feel large.
What counts as personal data for a small firm?
Personal data is information that identifies a living person, or could identify them when combined with something else you hold. A name plus an email. A phone number. A delivery address. An invoice to a sole trader. A photo of a customer on a job. A van registration if you can tie it to a person.
Nearly every business holds some of that. A pad by the phone still counts. Putting it in Microsoft 365 does not make it “not personal data”.
Some data is treated more carefully: health, criminal records, children’s data. If you handle those, stop guessing from a blog. Use the ICO’s guidance and get advice that fits the work.
Staff data counts too: payroll, emergency contacts, sickness notes. Other companies that process data for you (email host, accountant, website) still leave you deciding what is collected. The ICO explains controllers and processors. Use that, not a forum thread.
What do the rules actually ask you to do?
In everyday English, not in recital numbers:
- Collect less. A contact form does not need a date of birth. A quote request does not need a National Insurance number. If you cannot say why a field exists, remove it.
- Have a reason. You should be able to explain why you hold each kind of information. “It might be useful one day” is a weak reason. The ICO sets out lawful bases. Do not pick one from a hat. Read theirs.
- Be honest. Tell people what you collect and what you do with it, in language they can read. That is the privacy notice, not a ten-page paste from another site.
- Keep it safe. Passwords, MFA, a backup you can restore, and a habit of not emailing customer lists to a personal Gmail. Device protection is only one slice; see do I need antivirus in 2026.
- Do not keep it forever. When the job is long finished and you have no need and no legal reason to retain a record, delete it. Old inboxes used as a museum are how you hold data you forgot you had.
- Respect requests. If someone asks what you hold, or asks you to delete it, you need a way to find their records and reply. The ICO publishes how those rights work and what the usual timescales are. Follow that, not a guess.
None of that requires a poster in the kitchen. It does require that someone in the business can answer “what do we hold, and why” without a treasure hunt.
What does a typical small business need in writing?
Keep the paperwork short enough that you will update it.
A privacy notice that matches reality. If the form asks for a phone number so you can call back, say so. If you do not run a newsletter, do not claim you do.
A simple record of what you hold. A notebook page is enough: customers in X, invoices in Y, staff files in Z, CCTV if you have it, how long you keep each.
A way to handle a request. Who opens the email, where they look, who says yes to deletion when the accounts still need the invoice. Write that before Friday.
Marketing consent if you market. A quote you were asked for is not a monthly offer list. If you send promotional mail, people should have agreed and be able to stop. Use the ICO’s direct-marketing guidance.
Who processes data for you. Email suite, website, accountant, payments. Know they exist. You do not need their 40-page terms on your site.
If you use CCTV that records people, follow the ICO’s notes, including signs if they say you should.
How does this show up on your website?
A few website habits catch small firms out. They are fixable.
Contact forms are collection. The privacy notice should mention them. The form itself should only ask for what you use. A “how did you hear about us” dropdown is optional. A copy of someone’s passport is not a web form field.
Cookies and analytics. If you drop analytics or advertising cookies, tell people, and give them a choice where the rules require it. The ICO’s cookies guidance is the place to check, because details move and this post will not track every exemption. A site with no extra tracking is simpler. That is a valid design choice.
HTTPS. The padlock is basic care for anything typed into a form. A modern host does this as standard. If yours does not, that is a site problem, not a GDPR essay.
Chat widgets and booking tools. If a third-party chat or diary collects names, you have added a processor. Read what you switched on.
Getting these right when the site is built is cheaper than bolting a contradictory policy on later. We are not your solicitor and we do not certify compliance.
What should you do if someone asks about their data, or if something goes wrong?
Treat a request as a normal job. Confirm who they are. Search the places in your short record. Reply in plain English. If you cannot delete a live invoice, say so and use the ICO’s explanation of rights rather than inventing a reason.
If you think data has been lost or seen by the wrong person, contain what you can: change passwords, revoke access. Then follow the ICO’s breach guidance for what, if anything, you must tell them and the people affected. I am not going to give you a homemade flowchart. Their page is the process.
Prevention is still cheaper: unique passwords, MFA, a backup you have tested, and not posting a customer list into a public AI tool.
When is “the basics” not enough?
When the work is not a typical local firm with a form and a job book: health notes, children’s data, bought mailing lists, systematic monitoring, or selling data on. Also if you are outside the UK and targeting UK people. Those cases have extra rules. Get advice that looks at your files.
For everyone else, the failure is ignoring the lot, or copying a notice that describes a business you do not run. Fewer fields, a true notice, safer logins, a deletion habit, and a way to answer a request.
Page Forge can set a site so the form and the notice match. That is project work, not a GDPR retainer or a helpdesk. See IT and AI consulting if the question is how the tools are set, not what the law means in a dispute.
Frequently asked questions
Does UK GDPR apply to my small business?
If you hold personal data about customers or staff, yes. Almost every business does. For a typical small firm the practical work is collect less, keep it safe, be honest, and handle requests. Check the ICO if you are unsure whether something you hold counts.
Do I need a privacy policy on my website?
If the site collects personal data, a contact form being the usual case, you should publish a plain notice that matches what you actually do. It does not need to be a wall of jargon copied from a bank.
Is this legal advice?
No. This is practical orientation for a typical small UK business. For anything complex, or if you handle sensitive or large amounts of personal data, get advice that looks at your situation. The ICO’s site is the public reference I would start with.
Do I need consent for every email I send?
No. A message that is part of doing the job, such as a quote you were asked for, is not the same as a promotional list. Marketing has its own rules. Read the ICO on direct marketing rather than treating every email as a pop-up checkbox.
What if I use a bookkeeper or Microsoft 365?
You can use other companies to store or process data. You still decide what is collected and you still need to keep access sensible. Know who they are. Do not assume a well-known brand removes your responsibility for the spreadsheet you uploaded.
Will Page Forge keep me “GDPR compliant”?
No. Nobody honest sells a stamp that says that from a website build. We can make the site and the basic notices match the business, as a project. We will not act as your data-protection officer or your lawyer.
If you want the website side handled without theatre, or a plain conversation about how the tools are set, get in touch. For tool setup as a scoped job, see IT and AI consulting. For what the law requires in your case, use the ICO and, if needed, a solicitor.