Data protection touches almost every business, if you hold information about customers, staff or suppliers, the rules apply to you. This guide gives a plain-English overview of the UK's data protection framework as it stands in 2026, and the practical steps to stay compliant. Note that the framework (UK GDPR, Data Protection Act 2018) applies across the UK, not specifically to England and Wales, although this guide is written for readers operating in England and Wales.
The framework: UK GDPR, the DPA 2018 and PECR
UK data protection is built on three main pieces:
- The UK GDPR, the core rules on handling personal data (any information about an identifiable living person).
- The Data Protection Act 2018, supplements the UK GDPR and deals with areas like law-enforcement processing and exemptions.
- PECR (the Privacy and Electronic Communications Regulations 2003), specific rules on electronic marketing and cookies.
The framework is overseen by the Information Commissioner's Office (ICO). Note that the Data (Use and Access) Act 2025 has begun reforming parts of this framework, so check current ICO guidance for the latest detail.
The core principles
Under the UK GDPR you must handle personal data:
- lawfully, fairly and transparently (you need a lawful basis and must tell people what you do);
- for specified purposes only (purpose limitation);
- keeping it adequate and minimal (data minimisation);
- accurate and up to date;
- for no longer than necessary (storage limitation); and
- securely (integrity and confidentiality).
You must also be able to demonstrate compliance (accountability).
People's rights
Individuals have rights you must honour, including to: be informed; access their data; have inaccurate data corrected; have data erased in some cases; restrict or object to processing; and rights around automated decision-making. You generally must respond to a request within one month.
Do you need a Data Protection Officer?
Most small businesses don't need a formal DPO. One is mandatory for public authorities (subject to limited exceptions), or where your core activities consist of processing requiring regular and systematic monitoring of data subjects on a large scale, or large-scale processing of special category or criminal-offence data (UK GDPR, Article 37). If you don't need one, appoint a privacy lead instead.
Marketing and cookies (PECR)
Electronic marketing (emails, texts) to individuals generally needs consent, subject to the limited soft opt-in for existing customers. Non-essential cookies need consent too. Always offer an easy opt-out and honour the right to object.
Data breaches
If you suffer a personal data breach that risks people's rights, you must usually notify the ICO within 72 hours, and tell affected individuals where the risk is high. Have a breach plan ready.
A note on EU data
If you offer goods or services to people in the EU, or monitor their behaviour, the EU GDPR may also apply to you, alongside the UK rules, so cross-border businesses often have to satisfy both.
Practical compliance checklist
- Map your data and document your processing and lawful bases.
- Publish a clear privacy notice; train staff.
- Apply data minimisation and secure your systems.
- Honour individuals' rights within a month; have a breach plan.
- Get marketing and cookie consent right (PECR).
Key takeaways
- The framework is the UK GDPR + Data Protection Act 2018 + PECR, overseen by the ICO (and being reformed by the Data (Use and Access) Act 2025).
- Follow the core principles, honour individuals' rights, and keep data secure.
- Most SMEs don't need a DPO; marketing/cookies need consent under PECR.
- Report serious breaches to the ICO within 72 hours; EU GDPR may also apply to cross-border activity.
Sources
- UK GDPR; Data Protection Act 2018; Data (Use and Access) Act 2025
- Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
- Information Commissioner's Office (ICO) guidance
--- This article is general information about the law of England & Wales as at 2026, not legal advice. For advice on your circumstances, consult a qualified solicitor.