top of page
Search

What Documents Does a Small Business Actually Need Under GDPR and the Data (Use and Access) Act 2025?

Writer: Gayle Parker
Gayle Parker
Aug 19
5 min read

Updated: 1 day ago

Many small business owners assume that GDPR compliance requires hundreds of pages of policies, endless paperwork, and a dedicated compliance team. The reality is much simpler.


If you're a sole trader, consultant, freelancer, or small limited company with only one or two people, your compliance obligations are still important. However, they should be proportionate to the size and nature of your business. The UK GDPR accountability principle requires organisations to demonstrate compliance, but it does not prescribe a one-size-fits-all set of documents. The Data (Use and Access) Act 2025 (DUAA) has introduced some changes to UK data protection law, but it has not removed the need for businesses to be able to demonstrate good data protection practices. gov.uk, ico.org.uk


So, what documents do you actually need?


Small business owner

1. A Privacy Notice


If you collect personal information from customers, prospects, suppliers, website visitors, or business contacts, you should have a privacy notice. This document explains:


  • Who you are

  • What information you collect

  • Why you collect it

  • Your lawful basis for processing

  • Who you share information with

  • How long you keep data

  • Individual rights

  • How to complain


For many small businesses, this is the single most important GDPR document. It helps ensure transparency and provides individuals with the information they need about how their data is used.


2. A Record of Processing Activities (ROPA)


Many business owners have heard that small organisations are exempt from maintaining records of processing activities. However, the exemption is often misunderstood.


If your processing is regular, includes special category data, or could present risks to individuals, keeping a simple processing record is still advisable. Even where a formal Article 30 record may not be strictly required, maintaining one is often the easiest way to demonstrate compliance if questioned by a client or regulator. ico.org.uk


A simple ROPA might include:


  • Client management

  • Marketing activities

  • Financial records

  • Supplier management


3. A Data Protection Policy


Although the law does not specifically require a document called a "Data Protection Policy," organisations must be able to demonstrate their compliance arrangements.


A good policy explains:


  • Your approach to GDPR compliance

  • Roles and responsibilities

  • Security expectations

  • Breach reporting requirements

  • Data subject rights procedures

  • Data retention practices


For professional service businesses, this document helps demonstrate accountability and serves as evidence of your commitment to data protection.


4. A Data Retention Schedule


One of the most common compliance failures is keeping information longer than necessary. A retention schedule helps you document:


  • What records you hold

  • Why you hold them

  • How long they are retained

  • When they are deleted or securely destroyed


Examples include client records, marketing databases, employee records, and financial information.


Data Protection Policies

5. A Data Breach Procedure


No organisation plans to experience a data breach, but every organisation should be prepared for one. A breach procedure should outline:


  • What constitutes a personal data breach

  • How incidents are reported internally

  • How risks are assessed

  • When the ICO may need to be notified

  • How breaches are recorded


This does not need to be complicated, but it should be documented and understood.


6. A Data Subject Rights and Complaints Procedure


Individuals have a range of rights under UK GDPR. These include the right to access their personal data, request corrections, and object to certain processing activities. The DUAA introduced additional requirements around how organisations handle complaints. This makes it increasingly important for businesses to have a clear and documented process for managing these requests. gov.uk, ico.org.uk


A procedure should explain how you handle:


  • Subject Access Requests

  • Rectification requests

  • Erasure requests

  • Objections

  • Restrictions

  • Complaints


ByDesign Privacy SME Starter Pack

7. Contracts with Suppliers Who Process Personal Data


If you use third-party providers to process personal data on your behalf, appropriate contractual arrangements must be in place. Examples include:


  • Microsoft 365

  • CRM platforms

  • Email marketing systems

  • Accounting software

  • Cloud storage providers


Most reputable providers include Data Processing Agreements as part of their service terms. However, businesses should ensure these arrangements are documented.


8. A Record of Security Measures


The UK GDPR requires organisations to implement appropriate technical and organisational measures. For a small business, this may include:


  • Multi-factor authentication

  • Device encryption

  • Anti-virus software

  • Password management

  • Secure backups

  • Access controls


Documenting these measures demonstrates that security has been considered and implemented proportionately.


What About DPIAs and Legitimate Interests Assessments?


Not every business needs these for every activity.


Data Protection Impact Assessments (DPIAs)


A DPIA is generally required where processing is likely to result in a high risk to individuals. Examples include:


  • Employee monitoring

  • Large-scale special category data processing

  • AI-driven profiling

  • Extensive CCTV monitoring


Legitimate Interests Assessments (LIAs)


If your lawful basis for processing is legitimate interests, an LIA helps demonstrate that you have considered the impact on individuals. It balances their rights against your business interests. Common examples include:


  • Networking follow-ups

  • Direct marketing to business contacts

  • Client relationship management


Don't Forget the ICO Fee


Many small businesses overlook the requirement to pay the Information Commissioner's Office data protection fee. If your business processes personal data electronically, you may need to pay an annual fee unless a specific exemption applies. The ICO provides a self-assessment tool to help organisations determine whether they must register and pay the fee. ico.org.uk


The Bottom Line


For most small businesses, GDPR compliance does not require dozens of policies and procedures. A practical compliance framework will usually consist of:


  • Privacy Notice

  • Record of Processing Activities

  • Data Protection Policy

  • Retention Schedule

  • Breach Procedure

  • Data Subject Rights and Complaints Procedure

  • Processor Agreements

  • Security Measures Record

  • ICO Registration Evidence (where required)


The key is not having the largest compliance folder. The key is having the right documents that accurately reflect how your business handles personal data and that demonstrate accountability when required.


Need Help?


At ByDesign Privacy Ltd, we help SMEs implement practical, proportionate GDPR compliance without unnecessary paperwork or legal jargon. Whether you need a privacy notice, a full compliance review, or outsourced Data Protection Officer support, we can help you build a framework that is both compliant and workable for your business.


Contact us today for a free initial consultation and discover how straightforward data protection compliance can be.


Understanding GDPR Compliance


Navigating GDPR compliance can feel overwhelming. However, it’s essential to understand that it’s about protecting personal data and building trust with your clients. By implementing the right documents and processes, you can create a culture of privacy within your business. This not only helps you comply with regulations but also enhances your reputation.


In the end, GDPR compliance is not just a legal requirement; it’s an opportunity to show your clients that you value their privacy. So, take the time to get it right. Your clients will appreciate it, and your business will benefit in the long run.

 
 
 

Comments


bottom of page