Role-based access
Permissions given by job role, so a new starter gets the right access on day one.
Not everyone needs to see everything. Access control means staff can reach the data their job needs, and nothing else, which limits the damage from mistakes, leavers and stolen passwords.
Every business holds data that should not be open to all staff: HR records, payroll and accounts, client records, and supplier details. Payroll, for example, should be visible to HR and finance, not to everyone.
Access on a need-to-know basis is one of the five Cyber Essentials controls and a core part of UK GDPR's security requirement. It also makes life simpler when someone leaves: one account switched off removes their access everywhere.
Permissions given by job role, so a new starter gets the right access on day one.
SharePoint, OneDrive and file shares set so each team sees its own data.
Certain data only reachable from company devices.
Sensitive systems kept on a separate part of the network.
A stolen password alone is not enough to get in.
Access checked and updated as people change roles or leave.

Start by knowing what kinds of data you hold and how sensitive each is (see data classification). Then decide which roles need which data, and set permissions to match. We set this up in Microsoft 365 and your file storage, and review it regularly as people join, move and leave.
Anyone whose personal data you hold, including clients, suppliers and staff, can ask for a copy of it. This is a subject access request, and you usually have one month to respond, in a clear and accessible format. Good access control and well-organised data make that much easier.
Giving people access to data according to their job role, rather than person by person, so permissions are consistent and easy to change.
Usually one month from receiving it, extendable in some complex cases.
We put these controls in place for small and medium businesses, and keep them there. Tell us how your business works.
See also
What UK GDPR and the Data Protection Act 2018 require of a small business, what the fines are, and the practical steps that protect client d
Secure business laptops, phones and tablets: encryption, two-factor sign-in, password managers and device management, for UK GDPR and Cyber
How to classify business data as public, internal, confidential or restricted, and protect each level properly to meet UK GDPR and Cyber Ess