Common GDPR Mistakes Small Businesses Make
27th November 2025
It’s easy to dismiss data protection as something that only large companies with thousands of customers need to worry about, but companies of all sizes should be aware of their obligations under data protection laws like the UK GDPR. Having a good awareness of data protection rules can help prevent data breaches, avoid legal issues and fines, and enhance your reputation with customers.
Here are some of the most common GDPR mistakes that small businesses make, and how they can be prevented.
Not having a clear privacy notice (aka privacy policy)
Even the smallest company will collect personal data. Some information is obviously personal data, for example, people’s names, email addresses, postal addresses and dates of birth, but other less obvious information may be collected, such as bank details, CCTV images and IP addresses. If you process personal data, you must tell individuals what information you are collecting and why – this is usually done via a privacy notice or privacy policy. This is a legal requirement under the UK GDPR and can get you into trouble with the Information Commissioner if you do not have one in place. A privacy policy will explain to customers what data you collect from them, why you collect it, who you share it with, your lawful basis for processing their data and how they can request access or deletion of their data.
You can create your own privacy policy using the ICO’s online generator here. Publish your privacy policy on your website and include a link to it in the footer, so it appears on every website page, and include the link on signup forms.
Invisible processing
Larger companies need to keep more extensive records of what data they process, and the way to do this is to maintain a RoPA or Record of Processing Activities. Most micro SMEs will not need to maintain a full RoPA, but they do need to keep a record of what data they are processing, where and for what reason. Just think about all the software you use to store or process information in, or manual records you might keep; a simple spreadsheet is fine for this.
Think about any databases or CRMs you might use on your computer or in the cloud. Do you use Excel or Word documents, or store data in platforms such as Microsoft 365, SharePoint or Google Drive? Think about emails and instant messengers, email broadcasts or HR and marketing platforms in the cloud.
If you process data and are unaware of it, how can you add it to your privacy notice?
Ensuring you have a lawful basis to process information
You do not always need permission to process personal data, but you must have a lawful reason. You cannot just wake up in the morning and think, I’m going to capture the details of 1,000 random individuals today! You have to have a lawful purpose for processing, demonstrate why it is necessary to hold that information and identify the lawful reason for processing that information. There are six lawful reasons for holding non-sensitive data, which are consent, contractual obligations, legal obligation, vital interests, public task, and legitimate interests. You can read more about these here. Many small companies are unaware that they must identify the lawful basis of processing and include it in their privacy notice.
A different set of lawful bases is available if you wish to process sensitive or special category data.
Using personal data for marketing purposes without explicit consent
Just because someone has given you their email address does not mean that you can use it for marketing purposes. If you want to send unsolicited electronic marketing messages, such as emails, to individual consumers or contacts, they usually must explicitly consent to it. The only exception to this is specified in Section 22 of the PECR or Privacy and Electronic Communications Regulations. This soft opt-in rule allows businesses to market similar products or services to customers who have already purchased them, provided their contact details were collected during the course of the sale, and the customer was given the chance to opt out at the time. You can send unsolicited emails to corporate individuals.
When asking for someone’s permission under the GDPR, consent must be freely given, for a specific purpose and in the affirmative. This can be done by adding a check box to your signup forms – make sure that the box is not pre-checked, as customers must take action for their consent to be considered explicit; it cannot be assumed by default.
Collecting too much personal data or keeping personal data for longer than necessary
These two mistakes often go hand in hand – businesses collect too much information in the first place, and then keep personal data for longer than they need to. This violates the data minimisation principle of the GDPR, which requires organisations to only collect the data they need, and the storage limitation principle to only keep data for as long as it is needed.
How much is ‘too much’ data, you might ask? This will vary depending on your business activities and other factors, but always bear in mind Article 5(1) of the UK GDPR, which states that collected personal data should be: “adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed”. Only ask what you actually need from customers or contacts to fulfil the specific task you are collecting the data for – don’t collect home addresses unless required for delivery, avoid asking for sensitive data, like health information, unless absolutely required, and regularly review any online forms you use to prevent the collection of unnecessary personal data.
As for retaining customers’ personal data, the retention period is variable depending on the nature of your business activities. If you are collecting personal data for a one-time, singular purpose, you should not retain the data once that purpose is fulfilled. Some types of personal data, such as financial or medical records, may be kept for longer as they could be required for future legal claims or auditing purposes. For example, a GP practice may retain its patients’ medical records for decades even after the patient’s last contact with them. This is a very exceptional circumstance and will not apply to most business activities. You should review stored personal data at least once a year to ensure you are not keeping personal data for longer than necessary, or use systems that will automatically anonymise or delete data if it has been stored and not accessed for a pre-set time period.
Remember, how long you intend to retain data for should be included in your privacy notice.
Sharing personal data with third parties without a data processing agreement
It’s very common for businesses to share personal data with third parties, such as delivery companies, payroll providers, CRM systems, marketing agencies, and others. This is not a problem in itself, unless there is no lawful reason; in addition, usually, but not always, a written data processing agreement should be in place between the sharing and receiving parties. Say, for example, a law firm stores personal data about its clients, including sensitive details like legal matters, contact information, and financial data. The firm decides to outsource its IT services to a third-party company to manage its data backups. The law firm would need a formal Data Processing Agreement (DPA) in place with the IT service provider to provide instructions and guidance on who can access the data and how it should be handled, stored, and protected.
Before sharing data with a third party, especially where the other party is a Processor, organisations should assess whether that third party can/is complying with the GDPR and if they are, a DPA should be put in place which outlines the nature of the data processing, the type of personal data involved, and both parties’ obligations in relation to data protection laws. This assessment is referred to as due diligence.
Inadequate security measures
Companies of any size can experience a personal data breach, but the risks are higher if inadequate security measures are present; for example, weak passwords, computers being left logged in while unattended, no encryption of sensitive data, a lack of access controls, and limited or zero employee training on data security.
Companies must have in place minimum security measures, and ensure third parties processing data on their behalf have similar technical measures in place. They include, as a minimum:
- Using multifactor authentication when logging into systems for an extra layer of security.
- Ensuring that all personal data stored on laptops, phones and external hard drives is protected through encryption, passwords and screen timeouts.
- Enabling mobile defence management systems that can remotely wipe a device if it goes missing or is stolen.
- Implementing a paperless workplace so that personal data can’t be left out on display or lost – if paper documents must be used, ensure they are filed correctly and shredded once no longer required.
- Using role-based access control, limiting access to personal data based on team members’ roles, so that it can only be seen or used by those who need it.
- Providing practical, up-to-date data protection training to all employees.
Griffin House Consultancy offers a range of courses in data protection, from introductory courses designed to give a basic understanding of data protection principles to more specific courses that offer greater insight to those with more responsibility for data processing. Get in touch to find out more using the form below, view our range of data protection courses here, or call us for a chat on 01673 885533.
Author: Mike Martin LLM
Mike is an information rights law specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.