For any business that holds information about customers, staff or suppliers, data protection is not optional. This guide gives small and medium businesses in England and Wales a practical, plain-English overview of the UK's data protection laws in 2026, what they require, what happens if you get it wrong, and the steps to stay compliant.
The legal framework
UK data protection rests on three pillars:
- the UK GDPR, the core rules for handling personal data;
- the Data Protection Act 2018, which supplements it; and
- PECR (the Privacy and Electronic Communications Regulations 2003), rules on electronic marketing and cookies.
The regulator is the Information Commissioner's Office (ICO). Note that the Data (Use and Access) Act 2025 has started to reform parts of the framework, so check current ICO guidance for the latest detail.
The core obligations
To comply, you must handle personal data in line with the data protection principles: process it lawfully, fairly and transparently; only for specified purposes; keep it minimal, accurate, and for no longer than necessary; and keep it secure. You must also be able to demonstrate your compliance (accountability).
In practice, that means:
- identifying a lawful basis for each use of data;
- publishing a clear privacy notice;
- keeping records of your processing;
- having processes to honour individuals' rights (access, correction, erasure, objection) within a month; and
- securing data and being ready to handle breaches.
Penalties for getting it wrong
The ICO can investigate complaints, issue enforcement notices, and impose fines, up to £17.5 million or 4% of global annual turnover, whichever is higher, for serious UK GDPR breaches. Beyond fines, breaches damage customer trust and can lead to compensation claims.
Breach response
If you suffer a personal data breach that poses a risk to people, you must usually notify the ICO within 72 hours, and inform affected individuals where the risk is high. A simple, written breach plan makes meeting that deadline realistic.
Practical tips for SMEs
- Map your data: what you hold, why, your lawful basis, and how long you keep it.
- Apply data minimisation, collect and keep less.
- Train staff, human error causes most breaches.
- Get marketing and cookie consent right under PECR.
- Use data processing agreements with suppliers who handle data for you.
- Review whether you need a DPO (most SMEs do not).
Key takeaways
- The framework is the UK GDPR + Data Protection Act 2018 + PECR, overseen by the ICO (and being reformed by the Data (Use and Access) Act 2025).
- Follow the principles, honour rights, keep data secure, and document your compliance.
- Serious breaches can cost up to £17.5m or 4% of global turnover.
- Report qualifying breaches to the ICO within 72 hours.
Sources
- UK GDPR; Data Protection Act 2018; Data (Use and Access) Act 2025
- Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
- Information Commissioner's Office (ICO) guidance and enforcement
--- This article is general information about the law of England & Wales as at 2026, not legal advice. For advice on your circumstances, consult a qualified solicitor.