Mon–Fri 9am–5pm · Contract clients: urgent support 6am–10pm, every dayLeeds 0113 8000 192 · National 0330 1700 092

Protecting Company Data

Every business that holds personal data has a legal duty to protect it, whether that is a sole trader with a handful of clients or a company with thousands of records.

Talk to usSee pricing

In the UK, two laws set out that duty: UK GDPR and the Data Protection Act 2018. Together they require you to collect personal data lawfully, keep it secure, keep it accurate and no longer than necessary, let people see what you hold about them, and report certain breaches to the Information Commissioner's Office within 72 hours.

You also have to be able to show that you comply. Saying you follow good practice is not enough; the ICO expects policies, procedures and evidence.

What the law requires

Lawful and fair

A lawful reason for holding each kind of personal data, and using it only for that purpose.

Secure

Protection against unauthorised access, loss and theft.

Not kept too long

Data reviewed, and deleted or anonymised when it is no longer needed (Article 5(1)(e)).

Access on request

Subject access requests answered, usually within one month.

Breaches reported

Reportable breaches notified to the ICO within 72 hours.

Evidence

Policies, procedures and records that show you comply.

Desk with a monitor showing a security shield next to a backup drive

Fines and consequences

Fines under UK GDPR can reach £17.5 million or 4% of annual global turnover, whichever is higher. For most small businesses, though, the larger cost is losing clients' trust: a single breach can undo years of reputation, and some businesses never fully recover.

How long should you keep data?

There is no single answer. Financial records must be kept for set periods for tax, and health and social care records have their own rules. Everything else should be kept only as long as it is needed for its purpose. We help you set retention periods that make sense for your business, and the technical means to delete data securely when the time comes.

Where to start

Know what you hold (data classification), control who can reach it (access control), secure the devices it lives on (hardware security), and write down how you handle it (company procedures).

Questions we're asked

Does GDPR apply to sole traders?

Yes. UK GDPR applies to anyone who holds personal data for business purposes, including sole traders.

What is the maximum GDPR fine in the UK?

£17.5 million or 4% of annual global turnover, whichever is higher, for the most serious breaches.

When must a data breach be reported?

Within 72 hours of becoming aware of it, if the breach is likely to put people's rights and freedoms at risk.

Want this done for your business?

We put these controls in place for small and medium businesses, and keep them there. Tell us how your business works.

Get a fixed price