0%
HomeAboutSolutionsProjectsResearchIndustriesCareersInsightsContact
← Back to Blog

Community · Technical Insight

The UK GDPR Requirements Small Businesses Get Wrong, and the Vulnerabilities You Need to Fix Now

Most small businesses assume GDPR fines are reserved for companies much bigger than them. The ICO's own enforcement record says otherwise. In April 2025 the ICO fined a Merseyside law firm, DPP Law, £60,000 after attackers got into the firm's network through an admin account that had no multi-factor authentication on it at all. Three months later, in July 2025, the ICO fined the Scottish charity Birthlink £18,000 for destroying around 4,800 personal records, some of them irreplaceable birth records, because nobody had a policy distinguishing what could safely be deleted from what couldn't. Neither business is a household name. Neither fine required a sophisticated attack or a dramatic failure. Both came down to a basic control that was cheap to have in place and expensive to skip.

The wider numbers back this up. The government's Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses experienced a cyber security breach or attack in the past year, and breach rates for micro businesses, 42%, and small businesses, 46%, are barely lower than medium-sized firms at 65%. Small doesn't mean overlooked. It usually just means less prepared.

The real cost of ICO non-compliance for small firms

The DPP Law and Birthlink fines share a pattern worth sitting with: neither business was targeted because it was interesting. DPP Law was breached through a routine credential attack that multi-factor authentication, a second login step beyond a password, would very likely have stopped outright. Birthlink's failure wasn't a hack at all. It was a records-management gap that had existed quietly for years before a routine inspection surfaced it. Fines aside, both businesses also absorbed the cost of an ICO investigation, remediation work done under pressure, and the reputational cost of a public enforcement notice with their name on it. The fine is rarely the most expensive part.

3 most common security gaps in UK small businesses

1. Unencrypted customer files. Spreadsheets and documents containing customer data stored without encryption, often on a single laptop or shared drive with no access controls around who can open them.
2. Loose password sharing between staff. One login shared across a team, or the same password reused across several business tools, with no additional login step to catch a stolen password before it's used.
3. Insecure remote laptops. Company devices used outside the office without full-disk encryption, automatic screen locking, or a way to remotely wipe the device if it's lost or stolen.

How the ICO decides what to fine you

It's worth understanding the mechanics here, because they explain why DPP Law landed at £60,000 rather than a headline-grabbing millions figure, and why that's more relevant to you than the record-breaking fines you see in the news. The ICO's own statutory guidance on its regulatory action sets out a five-step process: assess how serious the infringement was, factor in the organisation's turnover or an equivalent financial measure, calculate a starting point from those two things, adjust up or down for aggravating or mitigating factors, cooperation, prior history, technical safeguards already in place, then apply a final proportionality check to make sure the fine is effective and dissuasive without being punitive for its own sake.

The statutory ceilings sound enormous, up to £8.7 million or 2% of global turnover for the standard tier, up to £17.5 million or 4% for the most serious infringements, but those are caps built for organisations the size of Capita, not a small firm. A small business's realistic exposure sits almost entirely in that second step, the turnover-proportionate calculation, which is exactly why Birthlink, a small charity, was fined £18,000 rather than a number with more zeros. That doesn't make the fine trivial. It makes it precisely calibrated to sting a small organisation the same way a much larger fine stings a much larger one.

What a breach costs before any fine even enters the picture

Fines are the visible cost. The invisible one is usually bigger. IBM's 2025 Cost of a Data Breach report put the average UK breach cost at £3.78 million without strong AI-driven security automation in place, falling to £3.11 million with it, a gap of roughly £670,000. Those averages skew heavily toward large enterprises with far more data and far more exposure than a typical small business, so treat the figure as a signal of scale rather than a prediction for your own business. What translates directly, regardless of size, is the timeline: organisations without strong detection tooling took an average of 168 days to identify a breach and a further 64 days to contain it, against 148 and 42 days respectively for those with better tooling. That's the better part of a year, in the slower case, between a breach happening and it being brought under control, which is a long time for customer data to sit somewhere it shouldn't.

Step-by-step fixes with minimal software investment

Implementing free or low-cost multi-factor authentication. Most business software you already pay for, your email provider, your accounting platform, your CRM, includes multi-factor authentication at no extra cost. It usually just isn't switched on by default. Turning it on for every account that touches customer data or money is the single highest-value security step a small business can take this week, and it's the exact gap that led to the DPP Law fine.

The 15-minute data audit

Set a recurring 15 minutes, monthly is enough, to work through the customer data you hold, one system at a time, rather than treating it as one intimidating annual project. Data minimisation, the principle of keeping only what you need, is a core requirement under UK GDPR, and it's also the cheapest insurance against a Birthlink-style records failure, since data that's been properly reviewed and retired can't later be mishandled.
1. List what you're actually holding. Not what you think you hold, what's really sitting in each system, spreadsheet, and shared drive right now.
2. Ask whether you still need it. For each category, would the business suffer if this were deleted today. If the honest answer is no, it's a deletion candidate, not a “maybe useful later” exception.
3. Check who can currently see it. Access that made sense for a team of three often hasn't been revisited since the team became fifteen. Old joiners, old contractors, and old integrations tend to accumulate access nobody remembers granting.
4. Set a retention rule, and follow it consistently. Birthlink's failure wasn't retaining data too long. It was destroying records without distinguishing which ones safely could be, and applying that inconsistently is often riskier than being slightly too cautious either way.

What changed under the Data (Use and Access) Act 2025

Two sets of changes under the Data (Use and Access) Act 2025 are worth knowing about, because they change what compliance looks like day to day. From February 2026, businesses responding to a subject access request, a request from someone to see the personal data you hold on them, only need to carry out a “reasonable and proportionate” search rather than an exhaustive one, and can pause the clock to ask the requester to clarify a vague request. That's a genuine easing for small teams who previously had to treat every request as an open-ended search. From 19 June 2026, businesses also need a clear, accessible process for people to raise a concern about how their data is handled, a formal complaints route rather than whatever informal arrangement existed before. For most small businesses that's a case of writing down a process that was already happening ad hoc, not building something new from scratch.

Frequently asked questions

Can the ICO really fine a business with fewer than 10 employees?
Yes. Fine size is generally proportionate to turnover and severity, but the ICO has fined organisations of all sizes, including small charities and small law firms, when the failure is serious enough, as both the DPP Law and Birthlink cases show.

Do I need a Data Protection Officer?
Most small businesses don't meet the threshold that legally requires a formal Data Protection Officer, but someone in the business still needs clear ownership of data protection decisions, even if it's a part of a wider role rather than a dedicated position.

Is Cyber Essentials worth it for a small business?
For most small firms, yes. NCSC's Cyber Essentials scheme starts at £320 plus VAT for the smallest organisations and covers exactly the fundamentals, firewalls, secure configuration, patching, access control and malware protection, that show up repeatedly in ICO enforcement cases.

None of this required DPP Law or Birthlink to be careless

That's the uncomfortable aspect of both cases. These weren't businesses ignoring security on purpose. They were ordinary organisations that hadn't gotten round to a handful of unglamorous basics, the kind that rarely feel urgent until an ICO investigation makes them retroactively so. Phexara builds those fundamentals into client work as standard, not as an optional add-on priced separately from the actual project.

Talk to our security team about where you stand, or see the fuller picture on our cybersecurity and cloud security solutions page.

Want to talk about how this applies to your organisation?

Contact Us