Data Protection
UK GDPR & Data Protection Act 2018
In force
May 2018 (UK GDPR from 2021)
Applies to
Any UK business processing personal data
Sets rules for how personal data must be lawfully processed, with rights for individuals and substantial fines for non-compliance.
Key Points
- Lawful basis for processing (consent, contract, legal obligation, vital interests, public task, legitimate interests)
- Data subject rights: access, rectification, erasure, portability, objection
- Mandatory 72-hour breach notification to ICO
- Records of Processing Activities (ROPA) for organisations 250+ or higher-risk
Practical Steps For Your SME
- Maintain a current ROPA
- Publish a clear privacy notice on every data collection point
- Hold valid consent or another lawful basis for marketing
- Sign Data Processing Agreements with every supplier handling personal data
Penalties
ICO fines up to £17.5m or 4 percent of global annual turnover, whichever is higher.
Free Resource
Stay ahead of UK GDPR changes
Get the 2026 UK SME Compliance Pack, every regulation summary, every template, every April 2026 rate. Free.
Other regulations to know
Stop Tracking Regulations Manually
Infinity Connect members receive plain-English alerts whenever a regulation changes, plus the templates and workflows to comply. Included.