Is your data encrypted?
On laptops, phones, USB drives and in cloud storage.
Business IT
UK GDPR and the Data Protection Act apply to every business that holds personal data. Compliance is mostly about sensible procedures and a few technical safeguards, and we put both in place.
UK GDPR, alongside the Data Protection Act 2018, sets out how businesses must protect the personal data they hold. Fines for serious breaches can reach £17.5 million or 4% of annual global turnover, whichever is higher. For most small businesses the bigger risk is the damage to client trust.
Compliance is not about spending a lot of money. It is about knowing what data you hold, controlling who can reach it, and making sure the basics are in place: encryption, strong sign-in, malware protection and backup. QLine IT holds Cyber Essentials Plus and applies the same controls to the businesses we support.
On laptops, phones, USB drives and in cloud storage.
For email, Microsoft 365 and every online account that holds data.
Can you show that staff only reach the data their role needs?
On every computer, kept up to date and monitored.
And when was a restore last tested?
Starters, leavers and data requests, with a record of what was done.

Encryption locks data so it cannot be read without the right key. If an encrypted, password-protected laptop is left on a train, the hardware is lost but the data is not exposed. Most modern computers and phones include encryption; it only needs switching on and managing properly, and the computers we look after carry on working normally with it enabled.
Passwords based on a pet's name, a birthday or a street are easily guessed. The UK's National Cyber Security Centre recommends long passwords, such as three random words, a different password for every account, and a password manager to remember them. Two-factor authentication, using an app such as Microsoft Authenticator, means a stolen password on its own is not enough.
A virus, malware or ransomware attack can cost a business its data and days of work. Every computer we maintain has malware protection as standard, monitored centrally so threats are found and contained early, and our backup service means data can be recovered even if an attack gets through.
Yes. UK GDPR applies to any business that holds personal data, including sole traders, although what is proportionate depends on the size of the business and the data it holds.
A personal data breach must be reported to the ICO within 72 hours if it is likely to put people at risk. If the laptop was encrypted and protected by a strong password, the risk is usually low, which is one of the best reasons to encrypt.
Yes. We hold Cyber Essentials Plus ourselves and can bring your systems in line with the five controls.
Tell us how your business works and we will tell you plainly what needs attention.
Business IT
Cyber security services for Leeds and UK businesses: data protection, GDPR compliance, Cyber Essentials, access control and encrypted backup
Automatic, encrypted backup of business computers, email and SharePoint, stored in the UK, with 30-day versioning to recover from mistakes a
Every price, published in full