What Is GDPR? The Plain-English Guide for UK Business Leaders

Quick answer: GDPR is the UK and EU law that governs how organisations collect, use, and protect personal data. Since Brexit, the UK runs its own version, "UK GDPR," sitting alongside the Data Protection Act 2018. If your business collects any personal information, from customer emails to employee records, GDPR applies to you, regardless of your size or sector.


 

What Is GDPR, Exactly?

GDPR stands for General Data Protection Regulation. It's the law that sets out how organisations are allowed to collect, store, use, and get rid of personal data, anything that identifies a living person, from a name and email address to an IP address or a photo.

The original GDPR came from the EU in 2018. After Brexit, the UK kept almost all of it and folded it into domestic law as the UK GDPR, which now works together with the Data Protection Act 2018 (DPA 2018). In practice, the two laws do the same job: they tell you what you can and can't do with people's data, and what you owe the people whose data you hold.

It's worth saying plainly: GDPR isn't a checklist you complete once and forget. It's an ongoing set of obligations that follows your business as it grows, hires, launches new products, and starts collecting new kinds of data. That's exactly why "one-off compliance project" and "ongoing compliance" are two different things, more on that later.

If you want the fuller picture of what compliance actually involves day to day, Trust Keith's GDPR compliance checklist for UK scale-ups is a good next stop after this one.


 

Who Does GDPR Apply To?

Short version: almost everyone. If your organisation is based in the UK and processes personal data, GDPR applies. It doesn't matter if you're a five-person startup or a 250-person scale-up. It doesn't matter if you're B2B and think you "don't really hold much personal data" (you almost certainly hold more than you think: employee records, customer contacts, marketing lists, supplier details). There's no small business exemption. There's no "we're pre-revenue so it doesn't count yet" clause. What changes with size and risk isn't whether GDPR applies, it's how much documentation and structure you need around it. A 10-person company handling low-risk data has a lighter job than a 200-person healthtech processing special category health data. But both are covered.

A few situations worth flagging specifically:

  • You process special category data, things like health information, biometric data, or data about someone's sex life or ethnicity. This carries extra obligations under UK GDPR Article 9, and usually pushes you towards needing a dedicated Data Protection Officer.
  • You process data on a large scale, lots of individuals, or continuous monitoring of people (think adtech, HR platforms, health apps).
  • You're a data controller or a data processor, either deciding how data is used, or processing it on someone else's behalf. Both roles carry obligations, just slightly different ones.

 

The 7 Principles of GDPR, Explained Simply

Everything in GDPR traces back to seven core principles. Get these right and most of the detailed rules fall into place naturally.

  • Lawfulness, fairness, and transparency, you need a proper legal basis to process data (more on this under Article 6), and you need to be upfront with people about what you're doing with their information.
  • Purpose limitation, collect data for a specific, stated reason, and don't repurpose it for something unrelated later.
  • Data minimisation, only collect what you actually need. If a sign-up form asks for a date of birth you'll never use, that's a problem, not just good UX advice.
  • Accuracy, keep data correct and up to date, and fix or delete it when it's wrong.
  • Storage limitation, don't keep personal data forever "just in case." Set retention periods and actually stick to them.
  • Integrity and confidentiality, keep data secure, technically and organisationally, against loss, misuse, or unauthorised access.
  • Accountability, you need to be able to demonstrate compliance, not just claim it. This is where documentation, records of processing, and DPIAs come in.

That last one, accountability, is the principle that trips up the most scale-ups. It's not enough to be doing the right thing quietly in the background. You need it written down, evidenced, and ready to show a regulator, an investor, or a customer's due diligence team if asked.

Trust Keith Office Hours


 

Your Key Obligations Under GDPR

Beyond the seven principles, GDPR sets out some concrete, practical obligations that scale-ups need in place. These are the things an auditor, a regulator, or an investor's due diligence questionnaire will actually ask about.

  • Keep records of processing activities (a ROPA), a document showing what personal data you hold, why, where it's stored, and who you share it with, as required under Article 30.
  • Carry out Data Protection Impact Assessments (DPIAs) for higher-risk processing, new tools, new data types, or anything involving large-scale monitoring, per Article 35.
  • Report breaches within 72 hours, if a breach poses a risk to individuals, you're required to notify the ICO within 72 hours of becoming aware of it.
  • Have a lawful basis for every use of data, and be able to point to it, not just assume consent covers everything (it usually doesn't).
  • Manage third parties properly, your suppliers and vendors who touch personal data need contracts and oversight, because their mistakes can become your liability.
  • Appoint a DPO where required, mandatory in certain cases under Article 37, and a genuinely good idea in plenty of others even when it's not strictly mandatory.

If you're wondering what a DPO actually spends their time doing day to day, Trust Keith has a full breakdown in What Does a DPO Actually Do?


 

The Rights Your Customers and Employees Have

GDPR isn't only about what you're allowed to do with data, it's also about what the people behind that data are entitled to ask for. These are usually called "data subject rights," and every business needs a process for handling them, not just an awareness that they exist.

  • The right to be informed, people have a right to know what you're doing with their data, in plain language, not buried in an 8,000-word privacy policy nobody reads.
  • The right of access, anyone can ask what personal data you hold on them (a Data Subject Access Request, or DSAR), and you need to respond within a month.
  • The right to rectification, correcting inaccurate data when asked.
  • The right to erasure, sometimes called "the right to be forgotten," letting people ask you to delete their data in certain circumstances.
  • The right to restrict processing, and the right to object to certain uses of data, like direct marketing.
  • The right to data portability, letting people take their data with them, in a usable format, if they move to another provider.

DSARs in particular catch a lot of scale-ups off guard. A single request can be entirely reasonable and still take real time to fulfil properly if you don't already know where all your data lives, which is exactly what a decent ROPA and data map are for.


 

What Happens If You Get GDPR Wrong

The headline risk everyone thinks of is fines, and they're real. Under Article 83, the ICO can issue administrative fines of up to £17.5 million or 4% of global annual turnover, whichever is higher, for the most serious breaches. The ICO also publishes its enforcement actions publicly, so you can see exactly what kinds of failures tend to get penalised.

But fines aren't actually the most common consequence, and in some ways they're not the most damaging one either. The costs that hit scale-ups more often are quieter: a due diligence process that stalls because you can't produce a ROPA on request, a lost enterprise customer whose procurement team wanted evidence of compliance you didn't have, weeks of internal time spent scrambling to answer a DSAR you weren't set up to handle, or a data breach that costs far more in customer trust than in any fine.

Trust Keith has written more on this in The Hidden Costs of Getting Data Protection Wrong, and if you're worried about what an actual regulatory investigation looks like, How to Prepare for an ICO Investigation walks through it step by step. For general ICO guidance on any of this, their guidance hub is the primary source worth bookmarking.

Trust Keith Resources


 

GDPR vs Data Protection: What's the Difference?

People often use "GDPR" and "data protection" interchangeably, and it's close enough most of the time, but there's a useful distinction worth knowing.

GDPR is the law. It's the specific regulation (alongside the DPA 2018 in the UK) that sets out the rules. Data protection is the broader practice of actually keeping personal data safe, well-governed, and used appropriately, day in, day out. You can be legally compliant on paper and still have a genuinely weak data protection culture if nobody actually follows the policies you've written. That's really the difference between having a document and having a functioning privacy programme. A lot of scale-ups have the document. Fewer have the second thing, an actual, ongoing operating rhythm: data mapped and kept current, DPIAs done before new tools launch, DSARs answered on time, staff who actually know what to do if something goes wrong.

This is exactly the gap that shows up as a company grows past its early stage. If any of this is starting to feel familiar, 5 Signs Your Scale-Up Has Outgrown Its Data Protection Approach is worth a read.


 

Frequently Asked Questions

Is GDPR still relevant in the UK after Brexit?

Yes. The UK created its own version, the UK GDPR, which is almost identical to the EU version and sits alongside the Data Protection Act 2018. If you're a UK business, this is the version that applies to you.

Does GDPR apply to small businesses and scale-ups, or just large enterprises?

It applies regardless of size. There's no exemption for smaller organisations. What changes with size is the scale and complexity of what you need in place, not whether the law applies at all.

What's the maximum fine for a GDPR breach?

Under Article 83, the ICO can fine organisations up to £17.5 million or 4% of global annual turnover, whichever is higher, for the most serious infringements. Lower-tier breaches carry lower maximum fines.

Do I need a Data Protection Officer?

It's mandatory in specific situations, such as large-scale processing of special category data or systematic monitoring of individuals, under Article 37. Plenty of businesses that aren't legally required to appoint one still choose to, because it's genuinely useful to have someone owning the role.

What's the difference between a data controller and a data processor?

A controller decides why and how personal data is processed. A processor handles data on the controller's behalf, following their instructions. Most businesses are controllers for at least some of their data, and processors for other parts (for example, if you build software that handles data for your customers).

How long do I have to respond to a Data Subject Access Request?

One calendar month from receiving the request, with the option to extend by a further two months for particularly complex requests, as long as you tell the person why within the first month.


 

Reading through all of this, the key takeaway is that GDPR compliance isn't really a single project with an end date. It's an ongoing discipline, and the businesses that handle it well tend to be the ones who've built it into how they operate, rather than treating it as a box ticked once a year before an audit.

If you want to start with the practical side, Trust Keith's GDPR compliance checklist is a solid place to check where the gaps are, and What Does a DPO Actually Do? is useful if you're weighing up whether you need someone dedicated to this.

Whether you're just getting your head around GDPR for the first time or you already know the rules and are wondering whether your actual practice matches them, it's worth being honest with yourself about which camp you're in. If any of this still feels uncertain, or you'd like to talk it through with someone who's handled this before, you're welcome to book some time with our team. We're happy to see how we can help.

chat to an expert

Trust Keith - take data protection off your plate, for good