Quick answer: GDPR is the UK and EU law that governs how organisations collect, use, and protect personal data. Since Brexit, the UK runs its own version, "UK GDPR," sitting alongside the Data Protection Act 2018. If your business collects any personal information, from customer emails to employee records, GDPR applies to you, regardless of your size or sector.
GDPR stands for General Data Protection Regulation. It's the law that sets out how organisations are allowed to collect, store, use, and get rid of personal data, anything that identifies a living person, from a name and email address to an IP address or a photo.
The original GDPR came from the EU in 2018. After Brexit, the UK kept almost all of it and folded it into domestic law as the UK GDPR, which now works together with the Data Protection Act 2018 (DPA 2018). In practice, the two laws do the same job: they tell you what you can and can't do with people's data, and what you owe the people whose data you hold.
It's worth saying plainly: GDPR isn't a checklist you complete once and forget. It's an ongoing set of obligations that follows your business as it grows, hires, launches new products, and starts collecting new kinds of data. That's exactly why "one-off compliance project" and "ongoing compliance" are two different things, more on that later.
If you want the fuller picture of what compliance actually involves day to day, Trust Keith's GDPR compliance checklist for UK scale-ups is a good next stop after this one.
Short version: almost everyone. If your organisation is based in the UK and processes personal data, GDPR applies. It doesn't matter if you're a five-person startup or a 250-person scale-up. It doesn't matter if you're B2B and think you "don't really hold much personal data" (you almost certainly hold more than you think: employee records, customer contacts, marketing lists, supplier details). There's no small business exemption. There's no "we're pre-revenue so it doesn't count yet" clause. What changes with size and risk isn't whether GDPR applies, it's how much documentation and structure you need around it. A 10-person company handling low-risk data has a lighter job than a 200-person healthtech processing special category health data. But both are covered.
A few situations worth flagging specifically:
Everything in GDPR traces back to seven core principles. Get these right and most of the detailed rules fall into place naturally.
That last one, accountability, is the principle that trips up the most scale-ups. It's not enough to be doing the right thing quietly in the background. You need it written down, evidenced, and ready to show a regulator, an investor, or a customer's due diligence team if asked.
Beyond the seven principles, GDPR sets out some concrete, practical obligations that scale-ups need in place. These are the things an auditor, a regulator, or an investor's due diligence questionnaire will actually ask about.
If you're wondering what a DPO actually spends their time doing day to day, Trust Keith has a full breakdown in What Does a DPO Actually Do?
GDPR isn't only about what you're allowed to do with data, it's also about what the people behind that data are entitled to ask for. These are usually called "data subject rights," and every business needs a process for handling them, not just an awareness that they exist.
DSARs in particular catch a lot of scale-ups off guard. A single request can be entirely reasonable and still take real time to fulfil properly if you don't already know where all your data lives, which is exactly what a decent ROPA and data map are for.
The headline risk everyone thinks of is fines, and they're real. Under Article 83, the ICO can issue administrative fines of up to £17.5 million or 4% of global annual turnover, whichever is higher, for the most serious breaches. The ICO also publishes its enforcement actions publicly, so you can see exactly what kinds of failures tend to get penalised.
But fines aren't actually the most common consequence, and in some ways they're not the most damaging one either. The costs that hit scale-ups more often are quieter: a due diligence process that stalls because you can't produce a ROPA on request, a lost enterprise customer whose procurement team wanted evidence of compliance you didn't have, weeks of internal time spent scrambling to answer a DSAR you weren't set up to handle, or a data breach that costs far more in customer trust than in any fine.
Trust Keith has written more on this in The Hidden Costs of Getting Data Protection Wrong, and if you're worried about what an actual regulatory investigation looks like, How to Prepare for an ICO Investigation walks through it step by step. For general ICO guidance on any of this, their guidance hub is the primary source worth bookmarking.
People often use "GDPR" and "data protection" interchangeably, and it's close enough most of the time, but there's a useful distinction worth knowing.
GDPR is the law. It's the specific regulation (alongside the DPA 2018 in the UK) that sets out the rules. Data protection is the broader practice of actually keeping personal data safe, well-governed, and used appropriately, day in, day out. You can be legally compliant on paper and still have a genuinely weak data protection culture if nobody actually follows the policies you've written. That's really the difference between having a document and having a functioning privacy programme. A lot of scale-ups have the document. Fewer have the second thing, an actual, ongoing operating rhythm: data mapped and kept current, DPIAs done before new tools launch, DSARs answered on time, staff who actually know what to do if something goes wrong.
This is exactly the gap that shows up as a company grows past its early stage. If any of this is starting to feel familiar, 5 Signs Your Scale-Up Has Outgrown Its Data Protection Approach is worth a read.
Yes. The UK created its own version, the UK GDPR, which is almost identical to the EU version and sits alongside the Data Protection Act 2018. If you're a UK business, this is the version that applies to you.
It applies regardless of size. There's no exemption for smaller organisations. What changes with size is the scale and complexity of what you need in place, not whether the law applies at all.
Under Article 83, the ICO can fine organisations up to £17.5 million or 4% of global annual turnover, whichever is higher, for the most serious infringements. Lower-tier breaches carry lower maximum fines.
It's mandatory in specific situations, such as large-scale processing of special category data or systematic monitoring of individuals, under Article 37. Plenty of businesses that aren't legally required to appoint one still choose to, because it's genuinely useful to have someone owning the role.
A controller decides why and how personal data is processed. A processor handles data on the controller's behalf, following their instructions. Most businesses are controllers for at least some of their data, and processors for other parts (for example, if you build software that handles data for your customers).
One calendar month from receiving the request, with the option to extend by a further two months for particularly complex requests, as long as you tell the person why within the first month.
Reading through all of this, the key takeaway is that GDPR compliance isn't really a single project with an end date. It's an ongoing discipline, and the businesses that handle it well tend to be the ones who've built it into how they operate, rather than treating it as a box ticked once a year before an audit.
If you want to start with the practical side, Trust Keith's GDPR compliance checklist is a solid place to check where the gaps are, and What Does a DPO Actually Do? is useful if you're weighing up whether you need someone dedicated to this.
Whether you're just getting your head around GDPR for the first time or you already know the rules and are wondering whether your actual practice matches them, it's worth being honest with yourself about which camp you're in. If any of this still feels uncertain, or you'd like to talk it through with someone who's handled this before, you're welcome to book some time with our team. We're happy to see how we can help.