<15 min Response

Since 2015

Cyber Essentials Certified

Check Your IT Score

Remote SOS Support

Free • 15 questions • About 3 minutes

Free GDPR health check

A quick data protection self-audit for UK small businesses. Answer 15 questions to see where you stand on UK GDPR, with a score and a list of what to fix first. Nothing you answer leaves this page.

1The basics

1Have you paid the ICO data protection fee, or confirmed you are exempt?

Most organisations that handle personal data must pay it every year.

Pay the ICO data protection fee

Check on the ICO website whether you need to pay. For most small businesses it is £52 a year (up to 10 staff or turnover up to £632,000) or £78 (up to 250 staff or turnover up to £36 million), with £5 off by direct debit.

2Do you know what personal data you hold, where it is stored and who you share it with?

Customers, staff and contacts, in email, files, apps and on paper.

Map the personal data you hold

List each type of personal data, where it lives, why you hold it and who it goes to. A spreadsheet is fine. Organisations with fewer than 250 staff can skip occasional, low-risk processing, but most still need to record routine processing such as payroll and customer records.

3Is your privacy notice up to date, and does it say why you use people’s data and your lawful basis for it?

The notice on your website, and the one you give to staff.

Update your privacy notice

Your privacy notice should say what you collect, why, your lawful basis, who you share it with, how long you keep it and what rights people have. Review it whenever you start using data in a new way.

2People’s rights and consent

4Would your team recognise a subject access request and know the deadline?

A request can arrive by email, phone or social media, and does not have to use the words subject access.

Get ready for subject access requests

You normally have one month to respond, which can be extended by up to two more months if the request is complex or the person has made several. Your search only needs to be reasonable and proportionate, and since February 2026 you can pause the clock while you ask the person to clarify what they want. Make sure staff know who to pass requests to.

5Can people easily make a data protection complaint to you, and would you acknowledge it within 30 days?

This became a legal requirement in June 2026.

Set up a data protection complaints process

Give people a clear way to complain, such as an email address or online form named in your privacy notice. Acknowledge complaints within 30 days, look into them without undue delay, keep the person updated and tell them the outcome.

6Does your website ask for consent before setting non-essential cookies, such as advertising cookies?

Cookies are covered by PECR, the rules that sit alongside UK GDPR.

Fix your website cookie consent

Use a cookie banner that blocks non-essential cookies until people agree. Since February 2026 some cookies used only for website statistics can be set without consent, as long as you explain them clearly, give people a simple way to opt out and do not share the data for other purposes. PECR fines can now reach the same levels as UK GDPR fines.

3Keeping data secure

7Is multi-factor authentication switched on for email and every business app that holds personal data?

A code or app approval on top of the password.

Turn on multi-factor authentication everywhere

Turn on multi-factor authentication for every account, starting with email, admin accounts and finance systems, so a stolen password is not enough on its own.

ATS can do this for you

8Are laptops and phones that access business data encrypted, and could you wipe one remotely if it was lost?

Including personal phones that pick up work email.

Encrypt and manage laptops and phones

Encrypt every laptop, require a PIN on phones and manage devices centrally so a lost one can be wiped. The ICO recommends encryption for personal data you store or send over the internet.

ATS can do this for you

9Are backups automatic, kept separately from your main systems and tested with a real restore?

Including Microsoft 365 or Google Workspace data, not just files on a server.

Fix and test your backups

UK GDPR expects you to be able to restore personal data in a timely manner after an incident. Back up automatically, keep a copy separate from your live systems (the ICO gives the 3-2-1 approach as an example) and test restores regularly.

ATS can do this for you

10Are devices kept up to date and protected by security software, and do you hold Cyber Essentials?

Cyber Essentials is a government-backed scheme that certifies basic security controls.

Keep devices patched and protected

Install updates promptly, remove software that is no longer supported and run security software on every device. Cyber Essentials covers these basics, and the ICO describes it as a good starting point.

ATS can do this for you

11Does each person only have access to the data they need, and is a leaver’s access removed on their last day?

Shared logins and old accounts are a common way in.

Tighten access and remove leavers promptly

Review who can see what, keep admin accounts to a minimum and switch off a leaver’s access on their last day, including shared passwords and any personal devices that hold work data.

ATS can do this for you

12Has everyone who handles personal data had data protection and phishing training in the last 12 months?

Covering how to handle data, sending it to the right person and spotting phishing.

Train your team

Short yearly training on handling data, checking who an email is going to and spotting phishing makes a real difference. Our free phishing test is a quick way to start.

ATS can do this for you
4Suppliers, breaches and retention

13Do you have a written data processing agreement with every supplier that handles personal data for you?

For example your IT provider, payroll, CRM, email marketing and cloud apps.

Put contracts in place with your suppliers

UK GDPR requires a written contract whenever a supplier handles personal data on your behalf. Many cloud services include one in their terms, so check it is there, and keep a list of suppliers and where they store data, including outside the UK.

14If you had a data breach tomorrow, do you know how you would decide within 72 hours whether to report it to the ICO?

A breach can be as simple as an email sent to the wrong person.

Write a 72-hour breach plan

Write a one-page plan: who to tell internally, how to contain the breach, how to judge the risk to people and who reports to the ICO within 72 hours if it is needed. Log every breach, including the ones you do not report.

15Do you have set retention periods, and do you actually delete personal data you no longer need?

Old CVs, former customers, years of email.

Set retention periods and delete old data

Decide how long you keep each type of data, write it down and delete or anonymise it when the time is up. Retention settings in Microsoft 365 can do much of this automatically.

ATS can do this for you

This health check is a quick self-assessment to help you spot gaps. It is not legal advice or a formal audit, and a perfect score does not mean you are fully compliant. For legal questions, speak to a data protection specialist or see the ICO’s advice for small organisations.

The full list

Your GDPR compliance checklist for small businesses

These are the 15 points the health check covers, in one place. Use it as a checklist for your own data protection audit, then work through anything you could not tick.

The basics

  • Pay the ICO data protection fee each year, or confirm you are exempt.
  • Know what personal data you hold, where it is, why and who you share it with.
  • Keep a clear privacy notice that covers your lawful basis, sharing, retention and people’s rights.

People’s rights and consent

  • Recognise subject access requests and answer within one month.
  • Give people a way to complain and acknowledge complaints within 30 days.
  • Ask for consent before setting non-essential cookies on your website.

Keeping data secure

  • Use multi-factor authentication on email and every app that holds personal data.
  • Encrypt laptops and phones and be able to wipe a lost one remotely.
  • Back up automatically, keep a separate copy and test restores.
  • Keep devices updated and protected, with Cyber Essentials as a baseline.
  • Limit access to what each person needs and remove leavers on their last day.
  • Train everyone who handles personal data at least once a year.

Suppliers, breaches and retention

  • Have a written contract with every supplier that handles personal data for you.
  • Have a plan to assess breaches and report to the ICO within 72 hours when needed, and log every breach.
  • Set retention periods and delete data you no longer need.

What is new

What the Data (Use and Access) Act changed for small businesses

UK GDPR and the Data Protection Act 2018 still apply, but the Data (Use and Access) Act 2025 changed parts of them. Most of the changes for businesses took effect in 2026.

  1. 19 June 2025

    The Act becomes law

    The Data (Use and Access) Act receives Royal Assent. It confirms straight away that subject access searches only need to be reasonable and proportionate. Most other changes follow later.

  2. 5 February 2026

    Most data protection changes start

    • You can pause the subject access clock while you ask the person to clarify their request.
    • A short list of recognised legitimate interests, such as crime prevention and safeguarding, no longer needs a balancing test. Others, such as direct marketing, still do.
    • Some cookies used only for website statistics no longer need consent, if you explain them clearly and people can opt out.
    • Fines under PECR, the cookie and marketing rules, can now reach UK GDPR levels.
  3. 19 June 2026

    Complaints process becomes a legal duty

    Every organisation must give people a clear way to make a data protection complaint, acknowledge it within 30 days, look into it properly and tell them the outcome.

Where IT comes in

Security is where IT support makes the biggest difference

UK GDPR says personal data must be protected with security that is appropriate to the risk. The ICO does not give a fixed list, but it points to encryption, backups you can restore from, regular testing, and Cyber Essentials as a good starting point. In practice, those are IT jobs.

We look after this for businesses across Sussex and Hampshire:

43%of UK businesses had a cyber security breach or attack in the last 12 months.
72 hrsto report a notifiable personal data breach to the ICO.
£17.5mor 4% of annual worldwide turnover, whichever is higher: the maximum UK GDPR fine.
30 daysto acknowledge a data protection complaint, from June 2026.

Sources: Cyber Security Breaches Survey 2025/26 (DSIT); ICO breach guidance; ICO.

Free • No obligation • Senior engineer • 30 minutes

Close the security gaps in your results

A senior engineer will look at your Microsoft 365 sign-in settings, devices, backups and leaver process with you, and tell you plainly which of your health check gaps are IT fixes and what it would take to close them.

What you get from the review

  • Multi-factor authentication and sign-in settings checked
  • Devices, encryption and backups reviewed
  • Leaver access and admin accounts checked
  • A plain-English list of what to fix first

Book your free IT & cyber review

Free, no obligation. We only use your details to arrange the review. Privacy policy.

FAQ

GDPR for small businesses: common questions

A GDPR or data protection audit checks how your organisation collects, uses, stores, shares and deletes personal data against UK GDPR and the Data Protection Act 2018. A full audit is usually carried out by a data protection specialist. This health check is a quick self-assessment covering the same main areas, so you can see where to start.

Yes. UK GDPR applies to any organisation that handles personal data, whatever its size, including sole traders. Some duties are lighter for smaller organisations. For example, organisations with fewer than 250 staff do not have to record occasional, low-risk processing, although most will still need to record routine processing such as payroll and customer records. The core principles apply to everyone.

Most organisations that handle personal data must pay a yearly fee to the ICO unless they are exempt. It is £52 for micro organisations (up to 10 staff or turnover up to £632,000) and £78 for small and medium ones (up to 250 staff or turnover up to £36 million), with £5 off by direct debit. The ICO website has a short self-assessment to check whether you need to pay.

One month from receiving the request, which can be extended by up to two more months if the request is complex or the person has made several. Your search only needs to be reasonable and proportionate, and since February 2026 you can pause the clock while you ask the person to clarify what they want.

Within 72 hours of becoming aware of it, if the breach is likely to put people’s rights and freedoms at risk. If the risk to them is high, you must also tell the people affected without undue delay. You should record every breach, including the ones you decide not to report.

Most small businesses do not. You must appoint one if you are a public authority, or if your core activities involve large-scale, regular and systematic monitoring of people, or large-scale use of sensitive data such as health records or criminal convictions. Everyone else should still name someone to look after data protection, even if they are not a formal DPO.

It confirmed that subject access searches only need to be reasonable and proportionate. From 5 February 2026 it let you pause the subject access clock while you clarify a request, allowed some statistics cookies without consent if you explain them and people can opt out, and removed the balancing test for a short list of recognised legitimate interests. It also raised PECR fines to UK GDPR levels. From 19 June 2026 every organisation must have a data protection complaints process.

No. It is a quick self-assessment from an IT support company to help you spot gaps, particularly the security ones we can fix. A perfect score does not mean you are fully compliant. For legal questions, speak to a data protection specialist or use the ICO’s guidance for small organisations.