Mon–Fri 9am–5pm · Contract clients: urgent support 6am–10pm, every dayLeeds 0113 8000 192 · National 0330 1700 092

Business IT

Business IT Security and GDPR

UK GDPR and the Data Protection Act apply to every business that holds personal data. Compliance is mostly about sensible procedures and a few technical safeguards, and we put both in place.

Talk to usSee pricing

UK GDPR, alongside the Data Protection Act 2018, sets out how businesses must protect the personal data they hold. Fines for serious breaches can reach £17.5 million or 4% of annual global turnover, whichever is higher. For most small businesses the bigger risk is the damage to client trust.

Compliance is not about spending a lot of money. It is about knowing what data you hold, controlling who can reach it, and making sure the basics are in place: encryption, strong sign-in, malware protection and backup. QLine IT holds Cyber Essentials Plus and applies the same controls to the businesses we support.

Questions the ICO will ask after a breach

Is your data encrypted?

On laptops, phones, USB drives and in cloud storage.

Is two-factor sign-in switched on?

For email, Microsoft 365 and every online account that holds data.

Who can access what?

Can you show that staff only reach the data their role needs?

Is malware protection running?

On every computer, kept up to date and monitored.

Do you have a working backup?

And when was a restore last tested?

Are your procedures written down?

Starters, leavers and data requests, with a record of what was done.

Laptop secured to an office desk with a cable lock

Encryption

Encryption locks data so it cannot be read without the right key. If an encrypted, password-protected laptop is left on a train, the hardware is lost but the data is not exposed. Most modern computers and phones include encryption; it only needs switching on and managing properly, and the computers we look after carry on working normally with it enabled.

Passwords and two-factor sign-in

Passwords based on a pet's name, a birthday or a street are easily guessed. The UK's National Cyber Security Centre recommends long passwords, such as three random words, a different password for every account, and a password manager to remember them. Two-factor authentication, using an app such as Microsoft Authenticator, means a stolen password on its own is not enough.

Malware and ransomware protection

A virus, malware or ransomware attack can cost a business its data and days of work. Every computer we maintain has malware protection as standard, monitored centrally so threats are found and contained early, and our backup service means data can be recovered even if an attack gets through.

Questions we're asked

Does GDPR apply to small businesses?

Yes. UK GDPR applies to any business that holds personal data, including sole traders, although what is proportionate depends on the size of the business and the data it holds.

Do we have to report a lost laptop?

A personal data breach must be reported to the ICO within 72 hours if it is likely to put people at risk. If the laptop was encrypted and protected by a strong password, the risk is usually low, which is one of the best reasons to encrypt.

Can you help us get Cyber Essentials?

Yes. We hold Cyber Essentials Plus ourselves and can bring your systems in line with the five controls.

Find out where your business is exposed

Tell us how your business works and we will tell you plainly what needs attention.

Get a fixed price