The GDPR Compliance Checklist for UK Small Businesses: 2026 Update
Table of Contents
If you run a small business in the UK and collect personal data from customers, website visitors or staff, GDPR applies to you. There is no employee threshold, no turnover floor and no exemption for sole traders. Working through a GDPR compliance checklist remains the most practical way to understand your obligations, find the gaps and put processes in place before the Information Commissioner’s Office (ICO) has reason to contact you.
What has changed is the detail. The Data (Use and Access) Act 2025 amended UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR). Most provisions took effect on 5 February 2026, with a new complaints handling duty from 19 June 2026. Any GDPR compliance checklist written before those dates is out of date on cookies, fines and complaints.
This guide sets out the full GDPR compliance checklist for small businesses under UK GDPR, updated for the 2026 rules, covering how your website, marketing and AI tools create obligations you may not have considered.
Does GDPR Apply to My Small Business?
Yes. If you process the personal data of any UK or EU resident, GDPR applies regardless of business size. Personal data includes names, email addresses, IP addresses, phone numbers and anything else identifying a living individual. Before starting any GDPR compliance checklist, be clear on what you hold and which regime governs it.
Under UK GDPR, the version retained in domestic law after Brexit, the rules remain close to the EU version. If you sell to customers in the Republic of Ireland or elsewhere in Europe, you may need to satisfy both frameworks at once, a daily concern for businesses in Northern Ireland.
The UK-EU adequacy decision currently allows personal data to flow freely between the two without additional transfer mechanisms. Adequacy is granted for a fixed period and is subject to review, so watch ICO guidance rather than assume the position is permanent.
Do You Need a Data Protection Officer?
Most small businesses do not. A DPO is required only where core activities involve large-scale processing of special category data such as health records, criminal offence data or biometrics, or large-scale systematic monitoring of individuals.
If you run a local services business, an e-commerce shop or a professional practice collecting standard contact details, you almost certainly do not need one. You do still need someone named internally who owns data protection, a separate item on your GDPR compliance checklist.
What Changed for UK Businesses in 2026
The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025, with the bulk of its data protection provisions in force from 5 February 2026. It amends the existing framework rather than replacing it, so a business already compliant with UK GDPR is not starting again. Four changes warrant a line on every GDPR compliance checklist.
Cookie Consent Exemptions
Since 5 February 2026, new exemptions in PECR mean some cookies no longer require prior consent. The one that matters most to SMEs covers cookies used solely for statistical or analytics purposes where results are used only by the website operator to improve the service. Four of the five exemptions still require clear information about what is collected and a simple, free way for visitors to object.
The limits matter as much as the freedoms. If analytics data is shared with a third party for that party’s own purposes, consent is still required, and advertising and cross-site tracking cookies sit outside the exemptions entirely. Standard Google Analytics 4 setups, Meta Pixel and LinkedIn Insight Tag all still need consent before they fire.
Recognised Legitimate Interests
The Act introduced a new lawful basis called recognised legitimate interests, removing the balancing test for defined purposes such as safeguarding, crime prevention and emergency response. It does not cover commercial marketing, so treating it as a shortcut for your email list is a fast route to an ICO complaint.
The Complaints Handling Duty
Since 19 June 2026, every controller must operate a formal process for handling data protection complaints, acknowledging each within 30 days. This applies to organisations of every size, and your privacy notice must tell people they can complain to you directly and how.
Higher PECR Fines
The maximum PECR fine rose from £500,000 to £17.5 million or 4% of worldwide turnover, matching UK GDPR levels. PECR governs marketing emails, texts, calls and cookies, which is where small business exposure sits.
The GDPR Compliance Checklist: 10 Steps for UK Small Businesses

This GDPR compliance checklist covers the actions every small business needs to take. Work through the steps in order, because the earlier ones inform the later ones. If you only have a day, spend it on steps one, two and four.
Step 1: Conduct a Data Audit
You need to know what personal data you hold, where it came from, where it lives and who can access it. This data audit, sometimes called data mapping, is the foundation of the whole GDPR compliance checklist.
For each type of data, document what it is, why you collected it, where it is stored, who has access, how long you keep it and whether it is shared with third parties. A single spreadsheet is enough for most small businesses, and the map doubles as a foundation for digital strategy planning later. Common sources include website contact forms, email marketing lists, CRM systems, accounting software, booking platforms and social media tools.
Step 2: Establish a Lawful Basis for Processing
The second item on any GDPR compliance checklist is a lawful basis for every processing activity. UK GDPR now provides seven: consent, contract, legal obligation, vital interests, public task, legitimate interests and recognised legitimate interests. Most small business processing falls under consent, contract or legitimate interests.
| Common activity | Lawful basis |
|---|---|
| Sending a newsletter to subscribers | Consent |
| Storing a customer’s address to fulfil an order | Contract |
| Keeping payroll records | Legal obligation |
| Following up with a business prospect | Legitimate interests |
| Retargeting website visitors with ads | Consent |
Document the basis before processing begins. If you rely on consent, you must be able to prove it was freely given, specific and informed.
Step 3: Update Your Privacy Notice
Your privacy notice must explain what data you collect, why, the lawful basis, retention periods, who you share it with and how people exercise their rights. It must be plain language and easy to find, usually linked in the footer, and it now needs to set out your complaints process.
Most small business privacy notices are absent, outdated or copied from another site and never adapted. None of those satisfies UK GDPR, and if your site was built without data protection in mind, the notice and the professional website design behind it usually need fixing together.
Step 4: Audit Your Website’s Data Collection Points
Your website is probably your main data collection mechanism, which makes this the busiest section of any GDPR compliance checklist.
- Contact forms: every form collecting a name and email processes personal data. It must reference your privacy notice, and marketing consent needs a separate, unticked checkbox, which is a custom website build decision as much as a legal one.
- Cookie consent: review your banner against the February 2026 exemptions. Some businesses can now simplify, but advertising tags still need consent before they set.
- Secure hosting: your host is a data processor, so you need a Data Processing Agreement with them. Managed website hosting based in the UK or EU removes complications around international transfers.
- SSL certificate: all data transmitted through your site must be encrypted. HTTPS and regular website maintenance and security updates are a baseline, not an upgrade.
Step 5: Address Digital Marketing Compliance
Marketing is the most commonly missed area on a small business GDPR compliance checklist, and it now carries the higher PECR fines. Every contact on your email list needs a lawful basis. For B2C that is almost always consent. For B2B, legitimate interests may apply where you contact business contacts about relevant products and have completed a legitimate interests assessment (LIA).
Lead magnets need care. Consent to receive a free download does not grant consent to receive marketing emails, so those must be separate opt-ins with separate records, and every marketing email needs an unsubscribe link that works. The same rule applies to social media lead generation forms and to gated content sitting behind video marketing campaigns.
Step 6: Prepare for Subject Access Requests
Anyone whose data you hold can submit a Subject Access Request (SAR). You have one calendar month to respond, free of charge, with a copy of their personal data and an explanation of how it is used.
The 2025 Act put two practices into law: you can now formally pause the clock while verifying identity or asking the person to clarify a broad request, and your search only has to be reasonable and proportionate rather than exhaustive. Assign one person to own SARs and document the process.
Step 7: Establish Data Processing Agreements
Any organisation processing personal data on your behalf is a data processor: your hosting provider, email platform, CRM, payment processor, any AI-powered marketing tools and any agency or freelancer handling customer data. UK GDPR requires a written Data Processing Agreement with each.
Most reputable providers publish a standard DPA or supply one on request. Check you have signed one for every tool in your stack and keep the list current.
Step 8: Implement Data Security Measures
Personal data must be protected against unauthorised access, accidental loss and deliberate attack. For small businesses that means strong password policies, multi-factor authentication on every account holding personal data, access controls limited to staff who need it, regular software updates and encrypted storage for sensitive records. A breach may be reportable: you have 72 hours from becoming aware to notify the ICO where it poses a risk to individuals’ rights and freedoms.
Step 9: Train Your Team
Staff training sits on every serious GDPR compliance checklist and is usually the last item anyone reaches. Anyone handling personal data needs to recognise a SAR, know what counts as a breach and understand when not to share information, which is why digital training programmes often cover data protection alongside the tools themselves.
Training does not need to be lengthy, but it does need documenting and refreshing. Material written before February 2026 will teach your team the wrong cookie rules, so build the update into your next round of business skills training.
Step 10: Document Everything
UK GDPR asks you to demonstrate compliance, not simply achieve it. Keep a Record of Processing Activities (RoPA), your lawful bases, consent records, DPAs, any DPIAs for higher-risk processing and evidence of staff training. The ICO does not expect perfection, but it does expect good faith effort and documentation showing you took the regulation seriously.
GDPR, Your Website and Your Marketing Technology
A large share of GDPR compliance for small businesses flows directly from website and marketing decisions. Cookie consent, form structure, privacy notice placement, data storage and secure hosting are all user-focused web design and development choices, which is why the GDPR compliance checklist and the website brief should be the same conversation.
Analytics and Tracking After the Cookie Changes
The February 2026 exemptions created an opportunity most SMEs have not acted on. First-party analytics used solely to improve your own service can now run without a consent barrier, provided you inform users and offer a simple way to object. Tools such as Matomo, Plausible or Fathom in cookieless mode tend to fit the exemption by design.
The gain is measurement quality. Sites losing a large share of their analytics data to consent rejection can recover a fuller picture of organic performance, which makes search engine optimisation reporting far easier to trust, as long as advertising tags stay behind the banner.
AI Tools and Shadow AI
Staff pasting customer data into personal AI accounts is one of the most common uncontrolled data flows in UK SMEs. If an employee uploads a customer list to a consumer chatbot account, that is a transfer to a processor you have no agreement with, no retention control over and no record of.
Add three lines to your GDPR compliance checklist: an approved AI tools list, a rule on what data may never be entered into them, and business-tier accounts with a DPA for the tools you sanction. Customer-facing AI chatbot development needs the same treatment, since chatbots log conversations that often contain personal data, as does any AI marketing automation that scores or segments contacts. Where an AI tool heavily influences decisions about individuals, such as CV screening, you also need a DPIA and a route for human review.
“Most SMEs we work with are not failing on the legal principles, they are failing on the plumbing,” says Ciaran Connolly, founder of ProfileTree. “The consent banner does not talk to the tag manager, the form does not write to the CRM cleanly, and nobody knows which AI tool the sales team is using. Fix the technical layer and the paperwork gets much easier to defend.”
GDPR for Northern Ireland: The UK-EU Dimension
Businesses operating in Northern Ireland sit in a particular position. Under the Windsor Framework, Northern Ireland maintains alignment with certain EU single market rules, and data flows between Northern Ireland, the Republic of Ireland and the rest of the UK remain under regulatory attention.
For most NI small businesses the implication is simple. If you collect data from customers in the Republic of Ireland or elsewhere in the EU, you are subject to EU GDPR as well as UK GDPR. The 2026 UK reforms apply only to the UK side, so a business serving both markets cannot adopt the relaxed UK cookie position across the board.
The safest approach is a GDPR compliance checklist that satisfies the stricter regime for any given activity, with a documented note of where you diverge and why. The Irish Data Protection Commission is the supervisory authority for EU-side obligations.
What Happens If a Small Business Is Not Compliant
The ICO can fine up to £17.5 million or 4% of annual global turnover, whichever is higher, for serious UK GDPR breaches, and since February 2026 PECR carries the same ceiling. Enforcement focuses on organisations that cause real harm or show wilful disregard for the rules. Small businesses that make a genuine effort, document it and respond properly to incidents are rarely the subject of significant action, and the ICO advice for small organisations hub sets out what the regulator expects.
The more immediate risk is reputational. A breach or a complaint damages trust in ways that are hard to recover from, and since June 2026 complaints come to you first, making a mishandled response a compliance failure in its own right. A GDPR compliance checklist protects customer trust as much as it meets a legal obligation.
Quick Reference: GDPR Compliance Checklist Summary
Use this GDPR compliance checklist summary as a working audit. Anything you cannot evidence is a gap, not a maybe.
- Map all personal data you hold and document your processing activities
- Record a lawful basis for every activity
- Publish a plain-language privacy notice covering the complaints duty
- Re-audit cookie banners against the February 2026 PECR exemptions
- Check email lists for valid consent or a documented LIA
- Put DPAs in place with every processor, AI tools included
- Apply access controls, encryption and multi-factor authentication
- Set up a SAR process using the statutory stop-the-clock provisions
- Run a complaints process with 30-day acknowledgement
- Train staff on the 2026 rules and keep records of everything
Turning the GDPR Compliance Checklist Into a Working Process
A checklist completed once and filed is worth little, because your data footprint changes every time you add a tool, a form or a campaign. Set a quarterly review covering the data audit, the processor list and consent records, owned by whoever runs your website and marketing stack.
Three actions will move most small businesses further than anything else this quarter: complete the data audit in step one, re-audit your cookie banner against the 2026 exemptions, and stand up the complaints process required since June 2026. ProfileTree works with SMEs across Northern Ireland, Ireland and the UK on the technical side, from compliant form builds to digital strategy services that account for consent from the outset. If your website is the weak link in your GDPR compliance checklist, that is a fixable problem.
FAQs
Does GDPR apply to sole traders?
Yes. Any individual or organisation processing personal data of UK or EU residents must comply.
Do I still need a cookie banner in 2026?
Usually yes. First-party analytics cookies have been exempt since 5 February 2026, but advertising and tracking cookies still require consent, and exempt cookies still need clear information and an easy way to object.
What is the difference between UK GDPR and EU GDPR?
UK GDPR is the retained domestic version, amended by the Data (Use and Access) Act 2025. Core requirements are close, but UK cookie and SAR rules diverged in February 2026.
Can I cold-email other businesses under GDPR?
Yes, with care. B2B cold email needs a documented legitimate interests assessment and an easy opt-out in every message. B2C cold email generally requires prior consent.
How long can I keep customer data?
There is no fixed period. Keep data only as long as necessary for the purpose you collected it, document retention periods and delete or anonymise on expiry.
What happens if I have a data breach?
Notify the ICO within 72 hours of becoming aware if the breach risks individuals’ rights and freedoms. Where the risk is high, notify the affected people directly too.
What must I do about data protection complaints?
Run a formal complaints process and acknowledge each complaint within 30 days. Your privacy notice must explain how to complain to you directly.
Do I need a DPIA for AI tools?
Yes, if the tool makes or significantly influences decisions about individuals, or processes special category data at scale. Document the assessment and provide a route to human review.