What Documents Does a Small Business Actually Need Under GDPR and the Data (Use and Access) Act 2025?
Updated: 1 day ago
Many small business owners assume that GDPR compliance requires hundreds of pages of policies, endless paperwork, and a dedicated compliance team. The reality is much simpler.
If you're a sole trader, consultant, freelancer, or small limited company with only one or two people, your compliance obligations are still important. However, they should be proportionate to the size and nature of your business. The UK GDPR accountability principle requires organisations to demonstrate compliance, but it does not prescribe a one-size-fits-all set of documents. The Data (Use and Access) Act 2025 (DUAA) has introduced some changes to UK data protection law, but it has not removed the need for businesses to be able to demonstrate good data protection practices. gov.uk, ico.org.uk
So, what documents do you actually need?

1. A Privacy Notice
If you collect personal information from customers, prospects, suppliers, website visitors, or business contacts, you should have a privacy notice. This document explains:
Who you are
What information you collect
Why you collect it
Your lawful basis for processing
Who you share information with
How long you keep data
Individual rights
How to complain
For many small businesses, this is the single most important GDPR document. It helps ensure transparency and provides individuals with the information they need about how their data is used.
2. A Record of Processing Activities (ROPA)
Many business owners have heard that small organisations are exempt from maintaining records of processing activities. However, the exemption is often misunderstood.
If your processing is regular, includes special category data, or could present risks to individuals, keeping a simple processing record is still advisable. Even where a formal Article 30 record may not be strictly required, maintaining one is often the easiest way to demonstrate compliance if questioned by a client or regulator. ico.org.uk
A simple ROPA might include:
Client management
Marketing activities
Financial records
Supplier management
3. A Data Protection Policy
Although the law does not specifically require a document called a "Data Protection Policy," organisations must be able to demonstrate their compliance arrangements.
A good policy explains:
Your approach to GDPR compliance
Roles and responsibilities
Security expectations
Breach reporting requirements
Data subject rights procedures
Data retention practices
For professional service businesses, this document helps demonstrate accountability and serves as evidence of your commitment to data protection.
4. A Data Retention Schedule
One of the most common compliance failures is keeping information longer than necessary. A retention schedule helps you document:
What records you hold
Why you hold them
How long they are retained
When they are deleted or securely destroyed
Examples include client records, marketing databases, employee records, and financial information.

5. A Data Breach Procedure
No organisation plans to experience a data breach, but every organisation should be prepared for one. A breach procedure should outline:
What constitutes a personal data breach
How incidents are reported internally
How risks are assessed
When the ICO may need to be notified
How breaches are recorded
This does not need to be complicated, but it should be documented and understood.
6. A Data Subject Rights and Complaints Procedure
Individuals have a range of rights under UK GDPR. These include the right to access their personal data, request corrections, and object to certain processing activities. The DUAA introduced additional requirements around how organisations handle complaints. This makes it increasingly important for businesses to have a clear and documented process for managing these requests. gov.uk, ico.org.uk
A procedure should explain how you handle:
Subject Access Requests
Rectification requests
Erasure requests
Objections
Restrictions
Complaints

7. Contracts with Suppliers Who Process Personal Data
If you use third-party providers to process personal data on your behalf, appropriate contractual arrangements must be in place. Examples include:
Microsoft 365
CRM platforms
Email marketing systems
Accounting software
Cloud storage providers
Most reputable providers include Data Processing Agreements as part of their service terms. However, businesses should ensure these arrangements are documented.
8. A Record of Security Measures
The UK GDPR requires organisations to implement appropriate technical and organisational measures. For a small business, this may include:
Multi-factor authentication
Device encryption
Anti-virus software
Password management
Secure backups
Access controls
Documenting these measures demonstrates that security has been considered and implemented proportionately.
What About DPIAs and Legitimate Interests Assessments?
Not every business needs these for every activity.
Data Protection Impact Assessments (DPIAs)
A DPIA is generally required where processing is likely to result in a high risk to individuals. Examples include:
Employee monitoring
Large-scale special category data processing
AI-driven profiling
Extensive CCTV monitoring
Legitimate Interests Assessments (LIAs)
If your lawful basis for processing is legitimate interests, an LIA helps demonstrate that you have considered the impact on individuals. It balances their rights against your business interests. Common examples include:
Networking follow-ups
Direct marketing to business contacts
Client relationship management
Don't Forget the ICO Fee
Many small businesses overlook the requirement to pay the Information Commissioner's Office data protection fee. If your business processes personal data electronically, you may need to pay an annual fee unless a specific exemption applies. The ICO provides a self-assessment tool to help organisations determine whether they must register and pay the fee. ico.org.uk
The Bottom Line
For most small businesses, GDPR compliance does not require dozens of policies and procedures. A practical compliance framework will usually consist of:
Privacy Notice
Record of Processing Activities
Data Protection Policy
Retention Schedule
Breach Procedure
Data Subject Rights and Complaints Procedure
Processor Agreements
Security Measures Record
ICO Registration Evidence (where required)
The key is not having the largest compliance folder. The key is having the right documents that accurately reflect how your business handles personal data and that demonstrate accountability when required.
Need Help?
At ByDesign Privacy Ltd, we help SMEs implement practical, proportionate GDPR compliance without unnecessary paperwork or legal jargon. Whether you need a privacy notice, a full compliance review, or outsourced Data Protection Officer support, we can help you build a framework that is both compliant and workable for your business.
Contact us today for a free initial consultation and discover how straightforward data protection compliance can be.
Understanding GDPR Compliance
Navigating GDPR compliance can feel overwhelming. However, it’s essential to understand that it’s about protecting personal data and building trust with your clients. By implementing the right documents and processes, you can create a culture of privacy within your business. This not only helps you comply with regulations but also enhances your reputation.
In the end, GDPR compliance is not just a legal requirement; it’s an opportunity to show your clients that you value their privacy. So, take the time to get it right. Your clients will appreciate it, and your business will benefit in the long run.



Comments