Skip to main content
Dig IT Solutions logo

Cyber Security

UK GDPR: the IT controls a small business actually needs

The IT controls UK GDPR expects of a small business: access control, MFA, encryption, retention, backups, processor contracts and 72-hour breach reporting.

By Dig IT SolutionsUpdated 8 September 20267 min read

Short answer

UK GDPR does not list specific technologies, but it requires security appropriate to the risk and the ability to prove it. For a small business that means named accounts with MFA and least privilege, encrypted devices, tested backups, defined retention, contracts with any supplier processing personal data, ICO registration, and a process to report a breach within 72 hours.

UK GDPR is written in principles rather than instructions, which is why so many small businesses are unsure what it actually requires of their IT. The law says security must be "appropriate" to the risk, and that you must be able to demonstrate compliance. It does not say "use MFA" or "encrypt laptops". The ICO, which enforces it, is clearer in its guidance, and enforcement decisions show what "appropriate" means in practice. This article turns that into the concrete list of IT controls a business of up to 250 people needs, with the legal hook for each.

The obligations that touch IT

Six parts of UK GDPR and the Data Protection Act 2018 generate IT work.

  • Article 5(1)(f), the security principle: personal data must be protected against unauthorised access, loss and damage.
  • Article 32, security of processing: measures appropriate to the risk, with encryption, resilience, the ability to restore, and regular testing named as examples.
  • Article 28, processors: a written contract with anyone who handles personal data for you.
  • Article 30, records of processing: knowing what data you hold, where and why.
  • Articles 33 and 34, breach notification: report to the ICO within 72 hours, and tell affected people when the risk to them is high.
  • The Data Protection (Charges and Information) Regulations: register with the ICO and pay the annual fee.

Everything below maps back to one of those.

Register with the ICO and map your data

Any organisation processing personal data as a controller must register with the ICO and pay the data protection fee each year unless it falls within a narrow set of exemptions. Almost every trading business has employees and customers, so almost every business must pay. The fee is tiered by staff numbers and turnover, with the lowest tier costing just over £50 a year at the time of writing, and a small discount for direct debit. Check your tier with the ICO's self-assessment tool, pay it, and diarise the renewal. Not paying is a penalty in its own right, and the ICO cross-checks against Companies House.

Knowing what you hold. You cannot protect, retain or delete what you cannot find. Article 30 requires a record of processing, and while very small businesses have a partial exemption, the IT reality is that you need the map anyway: what categories of personal data you hold (staff, clients, suppliers, marketing contacts), which systems hold it (Microsoft 365, the CRM, the accounts package, the HR tool, paper), who can access each, and where backups go. This is usually a one-page spreadsheet. It is also the first thing the ICO asks for after a breach, and it drives everything else in this article.

Access control and MFA

The security principle is breached most often by the wrong person having access. The controls the ICO expects to see:

  • Named accounts for every user, no shared logins, so access can be attributed and removed.
  • Least privilege: people can reach the data their job needs and nothing more. The finance folder is not open to everyone.
  • Multi-factor authentication on email and every cloud system holding personal data. Enforcement decisions have repeatedly cited the absence of MFA as a failure to take appropriate measures. See what MFA is and why your business needs it.
  • A joiner, mover and leaver process so access is granted deliberately, reviewed when roles change and removed on the day someone leaves. Our offboarding checklist is the practical version.
  • Periodic access reviews, at least annually, with a record that they happened.

Encryption and device security

Article 32 names encryption explicitly. The ICO's position is that portable devices holding personal data should be encrypted, and that unencrypted lost devices are treated far more seriously than encrypted ones. The list:

  • Full-disk encryption on every laptop and desktop (BitLocker on Windows, FileVault on Mac), with recovery keys stored centrally, and encryption on phones with a PIN or biometric lock.
  • Encryption in transit: HTTPS for web systems, TLS for email, VPN or secure gateway for remote access, so data is not readable on public networks.
  • Managed personal devices where staff use their own phones for email, so that work data is encrypted and can be wiped. See BYOD security risks.
  • Secure disposal of old equipment with certificates of data destruction. A server sold on eBay with client files on it is a breach.
  • Patching and malware protection, because an unpatched system or an infected PC is the route to most unauthorised access. The five Cyber Essentials controls are a recognised way to demonstrate this.

Retention, deletion and backups

Personal data must not be kept longer than necessary, and you must be able to say how long that is. Some periods come from other law: many accounting and payroll records for six years, certain employment records for defined periods after someone leaves. Others are your decision, documented in a retention schedule.

The IT work is making deletion actually happen. Microsoft 365 retention policies can delete email and files automatically after a set period, or preserve them where law requires. The CRM, HR system and accounts package need their own settings or a scheduled clean-up. Backups complicate this: a backup is not a live copy, and it is acceptable for deleted data to persist in backups for the backup retention period, provided that period is defined and reasonable and the data is not restored for use.

Resilience. Article 32 specifically requires the ability to restore availability and access to personal data in a timely manner after an incident, and to test the effectiveness of your measures regularly. Losing personal data is a breach just as much as leaking it. That means:

  • Backups of every system holding personal data, including Microsoft 365, which Microsoft does not fully back up for you.
  • At least one copy that ransomware cannot reach: offline or immutable, with separate credentials.
  • Documented, periodic restore tests with the time to recover recorded.
  • Encryption of the backups themselves, particularly any copy that leaves the building.

Our backup and disaster recovery page describes the arrangement we run for clients, and the ransomware guide explains why the isolated copy matters.

Processor contracts and supplier due diligence

Anyone who processes personal data on your behalf is a processor: your IT support provider, cloud backup vendor, payroll bureau, email marketing platform, outsourced HR, and the cloud services themselves. Article 28 requires a written contract with each, covering documented instructions, confidentiality, security measures, sub-processors, assistance with rights requests and breaches, deletion or return at the end, and audit rights. Large platforms such as Microsoft include these terms in their standard agreements. Smaller suppliers should provide a data processing agreement, and if they cannot, that is a warning sign.

You also remain responsible for choosing processors that provide sufficient guarantees, so ask about their security. Cyber Essentials, ISO 27001 or a completed questionnaire are the usual evidence. Keep a list of processors as part of your record of processing.

Breach detection and 72-hour reporting

You cannot report a breach you have not noticed, and the 72-hour clock starts when you become aware. That has two IT consequences. First, you need the means to detect incidents: alerts on unusual sign-ins and mailbox rules, endpoint detection and response, and someone looking at them, which is the case for continuous monitoring. Second, you need logs that let you establish what happened, whose data was involved and whether it was actually accessed, because that determines whether the breach is reportable and what you tell the ICO.

Write a short breach procedure: who is told, who assesses, who decides on reporting, and where the breach log is kept. Record every incident, including those you decide not to report, with your reasoning. If the risk to individuals is high, such as exposed financial or health data, you must also tell them without undue delay. Rehearse it once with a tabletop scenario.

The practical checklist

ObligationIT controlEvidence to keep
RegistrationICO fee paid, correct tierReceipt, renewal date
Records of processingData and system inventoryThe spreadsheet, reviewed annually
Security of processingMFA, least privilege, patching, EDR, firewallsCyber Essentials certificate, patch and access reports
EncryptionFull-disk on all devices, TLS in transit, managed BYODIntune or MDM compliance report
Storage limitationRetention schedule, automated deletionRetention policy settings, disposal certificates
ResilienceIsolated backups, restore testsBackup reports, test records
ProcessorsContracts and due diligenceDPA for each supplier, processor list
Breach notificationDetection, logs, procedureBreach log, incident plan
AccountabilityWritten security and data policies, staff trainingPolicy with version date, training records

Most of this is the same work that makes a business resilient against ransomware and phishing. UK GDPR simply requires you to be able to prove it, which is why documentation matters as much as the controls. Our article on why you need a cyber security policy covers the written side. For sectors with additional obligations, such as law firms, accountants and healthcare practices, the regulator's expectations are higher and the same controls carry more weight.

What to do next

If you could not produce a patch report, an access review, a restore test record and a list of processor contracts this week, those are the gaps to close first. An IT health check assesses your systems against the controls above and gives you a prioritised list with the evidence each one produces.

Frequently asked questions

Do I have to report every data breach to the ICO within 72 hours?
You must report a personal data breach to the ICO within 72 hours of becoming aware of it unless it is unlikely to result in a risk to people's rights and freedoms. A lost encrypted laptop with the key protected is usually not reportable. A hacked mailbox full of client correspondence usually is. Record every breach, reportable or not, with your reasoning.
Does my small business have to pay the ICO fee?
Almost certainly. Any organisation that processes personal data as a controller must register with the ICO and pay an annual data protection fee unless exempt, and the exemptions are narrow. The fee is tiered by size and turnover, with the smallest tier costing just over £50 a year. Failing to pay is itself a penalty offence, and the ICO checks Companies House records.
Does UK GDPR require encryption?
It does not use the word as an absolute requirement, but it names encryption as an example of an appropriate measure, and the ICO's guidance expects it wherever personal data is stored on portable devices or transmitted over the internet. In practice that means BitLocker or FileVault on every laptop, encrypted phones, and encrypted connections, which are all standard and free.
Do we need a written contract with our IT provider under UK GDPR?
Yes. Any supplier that processes personal data on your behalf, including an IT support company with access to your systems, a cloud backup provider or a payroll bureau, is a processor, and Article 28 requires a written contract with specific terms covering instructions, confidentiality, security, sub-processors, assistance with breaches and deletion at the end. Reputable providers supply one as standard.
How long can we keep personal data?
Only as long as you need it for the purpose you collected it, and you must be able to say what that period is. Some periods are set by other law, such as six years for many accounting records. Others you decide and document. The IT task is to make deletion actually happen, through retention policies in Microsoft 365 and in your other systems, rather than keeping everything forever.
Is Cyber Essentials enough for UK GDPR compliance?
No, but it helps. Cyber Essentials covers the technical controls that the ICO would expect to see in place, so it is strong evidence of appropriate security. UK GDPR also requires lawful bases, privacy information, records of processing, handling of individuals' rights, retention and processor contracts, none of which Cyber Essentials addresses. Treat it as the security component of compliance.

Next step

Not sure how exposed you are?

An IT health check reviews your security, backups, Microsoft 365 and network and gives you a prioritised list, whether or not you work with us afterwards.

WhatsApp us