How to understand your data protection duties
Handling personal data lawfully is a legal requirement that protects your customers and your business from day one.
Getting to grips with data protection
As soon as you start thinking about collecting customer details – whether it's an email for a newsletter, a name for a waiting list, or an address for a delivery – you step into the world of data protection. It might sound intimidating, but it’s really all about treating customer information with respect.
In the UK, the main set of rules is the General Data Protection Regulation (GDPR). Don't worry, you don't need to be a lawyer to understand the basics. Getting this right from the start shows customers you're a trustworthy business and protects you from potential fines.
What counts as 'personal data'?
It’s any information that can be used to identify a living person. The most common examples for a new business include:
- Names
- Email addresses
- Postal addresses
- Phone numbers
- Photographs or videos of people
The 7 Core Principles of GDPR
Think of these as the golden rules for handling personal data. You are responsible for following them.
- Be fair and transparent: Be open about what data you're collecting and why. No surprises.
- Have a specific purpose: Only use the data for the reason you collected it. If you collect an address for delivery, you can't then use it to send them birthday cards without asking.
- Collect only what you need: If you only need an email address for your newsletter, don't ask for their phone number and date of birth.
- Keep it accurate: Make sure the information you hold is correct and up to date.
- Don't keep it forever: Only store data for as long as you have a good reason to.
- Keep it secure: You must protect the data from being lost, stolen, or accessed by people who shouldn't see it. This means using strong passwords and locking your computer.
- Be accountable: You are responsible for complying with these principles and proving that you are.
Your Action Plan: Getting Started
Here are the essential first steps to take:
1. Work out what data you'll handle
Think about your business activities. Will you be sending newsletters? Delivering products? Taking bookings? Make a simple list of the personal data you will need to collect for each activity.
2. Know your reason for using the data
You must have a valid reason, known as a 'lawful basis', for collecting and using personal data. For most new businesses, this will be one of two things:
- Consent: The person has given you clear permission. For example, they actively ticked a box to join your email marketing list.
- Contract: You need their data to fulfil a contract with them. For example, you need their address to deliver a product they have bought from your website.
3. Create a simple Privacy Notice
A privacy notice (or privacy policy) is a public statement that explains how you handle personal data. You should have one on your website. It doesn't need to be complicated. It just needs to clearly state:
- Who you are
- What data you collect
- Why you collect it and what you do with it
- How long you will keep it
- A summary of their rights (like the right to ask for a copy of their data)
4. Think about security
How will you keep the data safe? Simple steps make a big difference. Use strong, unique passwords for your accounts, keep your computer's software up to date, and be careful not to leave customer lists open on your screen in a public place.
Top Tip: The Information Commissioner's Office (ICO) is the UK's data protection authority. Their website has a fantastic section with simple guides, checklists, and templates specifically for small businesses. It's your best source of official information.
Getting data protection right isn't about creating barriers; it's about building a professional and trustworthy business from the very beginning. By handling customer data with care, you show them you value their privacy as much as their custom.
Created by hatch. • Updated on December 19, 2025