Free • 15 questions • About 3 minutes
Free GDPR health check
A quick data protection self-audit for UK small businesses. Answer 15 questions to see where you stand on UK GDPR, with a score and a list of what to fix first. Nothing you answer leaves this page.
This health check is a quick self-assessment to help you spot gaps. It is not legal advice or a formal audit, and a perfect score does not mean you are fully compliant. For legal questions, speak to a data protection specialist or see the ICO’s advice for small organisations.
The full list
Your GDPR compliance checklist for small businesses
These are the 15 points the health check covers, in one place. Use it as a checklist for your own data protection audit, then work through anything you could not tick.
The basics
- Pay the ICO data protection fee each year, or confirm you are exempt.
- Know what personal data you hold, where it is, why and who you share it with.
- Keep a clear privacy notice that covers your lawful basis, sharing, retention and people’s rights.
People’s rights and consent
- Recognise subject access requests and answer within one month.
- Give people a way to complain and acknowledge complaints within 30 days.
- Ask for consent before setting non-essential cookies on your website.
Keeping data secure
- Use multi-factor authentication on email and every app that holds personal data.
- Encrypt laptops and phones and be able to wipe a lost one remotely.
- Back up automatically, keep a separate copy and test restores.
- Keep devices updated and protected, with Cyber Essentials as a baseline.
- Limit access to what each person needs and remove leavers on their last day.
- Train everyone who handles personal data at least once a year.
Suppliers, breaches and retention
- Have a written contract with every supplier that handles personal data for you.
- Have a plan to assess breaches and report to the ICO within 72 hours when needed, and log every breach.
- Set retention periods and delete data you no longer need.
What is new
What the Data (Use and Access) Act changed for small businesses
UK GDPR and the Data Protection Act 2018 still apply, but the Data (Use and Access) Act 2025 changed parts of them. Most of the changes for businesses took effect in 2026.
- 19 June 2025
The Act becomes law
The Data (Use and Access) Act receives Royal Assent. It confirms straight away that subject access searches only need to be reasonable and proportionate. Most other changes follow later.
- 5 February 2026
Most data protection changes start
- You can pause the subject access clock while you ask the person to clarify their request.
- A short list of recognised legitimate interests, such as crime prevention and safeguarding, no longer needs a balancing test. Others, such as direct marketing, still do.
- Some cookies used only for website statistics no longer need consent, if you explain them clearly and people can opt out.
- Fines under PECR, the cookie and marketing rules, can now reach UK GDPR levels.
- 19 June 2026
Complaints process becomes a legal duty
Every organisation must give people a clear way to make a data protection complaint, acknowledge it within 30 days, look into it properly and tell them the outcome.
Where IT comes in
Security is where IT support makes the biggest difference
UK GDPR says personal data must be protected with security that is appropriate to the risk. The ICO does not give a fixed list, but it points to encryption, backups you can restore from, regular testing, and Cyber Essentials as a good starting point. In practice, those are IT jobs.
We look after this for businesses across Sussex and Hampshire:
- Multi-factor authentication and Conditional Access across Microsoft 365, as part of our cyber security services.
- Encrypted, managed laptops and phones that can be wiped remotely if they are lost.
- Immutable backups with tested recovery, through our backup and disaster recovery service.
- Joiner and leaver processes so access is removed on someone’s last day, as part of managed Microsoft 365.
- Cyber Essentials certification support, from a team that is certified itself.
Sources: Cyber Security Breaches Survey 2025/26 (DSIT); ICO breach guidance; ICO.
Free • No obligation • Senior engineer • 30 minutes
Close the security gaps in your results
A senior engineer will look at your Microsoft 365 sign-in settings, devices, backups and leaver process with you, and tell you plainly which of your health check gaps are IT fixes and what it would take to close them.
What you get from the review
- Multi-factor authentication and sign-in settings checked
- Devices, encryption and backups reviewed
- Leaver access and admin accounts checked
- A plain-English list of what to fix first
If it is urgent, call us on 01903 255 159.
FAQ
GDPR for small businesses: common questions
A GDPR or data protection audit checks how your organisation collects, uses, stores, shares and deletes personal data against UK GDPR and the Data Protection Act 2018. A full audit is usually carried out by a data protection specialist. This health check is a quick self-assessment covering the same main areas, so you can see where to start.
Yes. UK GDPR applies to any organisation that handles personal data, whatever its size, including sole traders. Some duties are lighter for smaller organisations. For example, organisations with fewer than 250 staff do not have to record occasional, low-risk processing, although most will still need to record routine processing such as payroll and customer records. The core principles apply to everyone.
Most organisations that handle personal data must pay a yearly fee to the ICO unless they are exempt. It is £52 for micro organisations (up to 10 staff or turnover up to £632,000) and £78 for small and medium ones (up to 250 staff or turnover up to £36 million), with £5 off by direct debit. The ICO website has a short self-assessment to check whether you need to pay.
One month from receiving the request, which can be extended by up to two more months if the request is complex or the person has made several. Your search only needs to be reasonable and proportionate, and since February 2026 you can pause the clock while you ask the person to clarify what they want.
Within 72 hours of becoming aware of it, if the breach is likely to put people’s rights and freedoms at risk. If the risk to them is high, you must also tell the people affected without undue delay. You should record every breach, including the ones you decide not to report.
Most small businesses do not. You must appoint one if you are a public authority, or if your core activities involve large-scale, regular and systematic monitoring of people, or large-scale use of sensitive data such as health records or criminal convictions. Everyone else should still name someone to look after data protection, even if they are not a formal DPO.
It confirmed that subject access searches only need to be reasonable and proportionate. From 5 February 2026 it let you pause the subject access clock while you clarify a request, allowed some statistics cookies without consent if you explain them and people can opt out, and removed the balancing test for a short list of recognised legitimate interests. It also raised PECR fines to UK GDPR levels. From 19 June 2026 every organisation must have a data protection complaints process.
No. It is a quick self-assessment from an IT support company to help you spot gaps, particularly the security ones we can fix. A perfect score does not mean you are fully compliant. For legal questions, speak to a data protection specialist or use the ICO’s guidance for small organisations.


