Lawful and fair
A lawful reason for holding each kind of personal data, and using it only for that purpose.
Every business that holds personal data has a legal duty to protect it, whether that is a sole trader with a handful of clients or a company with thousands of records.
In the UK, two laws set out that duty: UK GDPR and the Data Protection Act 2018. Together they require you to collect personal data lawfully, keep it secure, keep it accurate and no longer than necessary, let people see what you hold about them, and report certain breaches to the Information Commissioner's Office within 72 hours.
You also have to be able to show that you comply. Saying you follow good practice is not enough; the ICO expects policies, procedures and evidence.
A lawful reason for holding each kind of personal data, and using it only for that purpose.
Protection against unauthorised access, loss and theft.
Data reviewed, and deleted or anonymised when it is no longer needed (Article 5(1)(e)).
Subject access requests answered, usually within one month.
Reportable breaches notified to the ICO within 72 hours.
Policies, procedures and records that show you comply.

Fines under UK GDPR can reach £17.5 million or 4% of annual global turnover, whichever is higher. For most small businesses, though, the larger cost is losing clients' trust: a single breach can undo years of reputation, and some businesses never fully recover.
There is no single answer. Financial records must be kept for set periods for tax, and health and social care records have their own rules. Everything else should be kept only as long as it is needed for its purpose. We help you set retention periods that make sense for your business, and the technical means to delete data securely when the time comes.
Know what you hold (data classification), control who can reach it (access control), secure the devices it lives on (hardware security), and write down how you handle it (company procedures).
Yes. UK GDPR applies to anyone who holds personal data for business purposes, including sole traders.
£17.5 million or 4% of annual global turnover, whichever is higher, for the most serious breaches.
Within 72 hours of becoming aware of it, if the breach is likely to put people's rights and freedoms at risk.
We put these controls in place for small and medium businesses, and keep them there. Tell us how your business works.
See also
Role-based access control for small businesses: staff see only the data their job needs. Meets UK GDPR and Cyber Essentials access control r
Secure business laptops, phones and tablets: encryption, two-factor sign-in, password managers and device management, for UK GDPR and Cyber
How to classify business data as public, internal, confidential or restricted, and protect each level properly to meet UK GDPR and Cyber Ess