Does my small business need a privacy policy in the UK?

Updated August 2026 · 7-minute read · General information, not legal advice

Short answer: almost certainly yes. "We're too small for GDPR" is one of the most common — and most costly — assumptions a small business makes. UK GDPR does not carve out an exemption for size. If you hold a customer list, an email newsletter, staff records, or a booking system, you are already a data controller, and the law expects you to tell people what you do with their data.

This guide sets out what actually depends on your size (the ICO fee) versus what doesn't (the duty to have a compliant privacy notice), and the mistakes that show up again and again in small-business policies.

In this guide 1. Why "small business" isn't an exemption 2. What a privacy notice must say 3. The ICO data protection fee — this part IS size-based 4. The mistakes that get flagged 5. Quick compliance checklist 6. FAQ

1. Why "small business" isn't an exemption

UK GDPR and the Data Protection Act 2018 apply to any organisation that processes personal data — a sole trader with a spreadsheet of customer emails is a data controller in exactly the same sense as a large retailer. Two separate things get confused here, and it's worth untangling them:

A handful of narrow exemptions from the fee exist (for example, processing limited to core staff administration such as payroll, with no other use of personal data) — these are specific and should be checked against the ICO's self-assessment tool, not assumed.

2. What a privacy notice must say

Articles 13 and 14 of UK GDPR set out what a data subject must be told, typically at or before the point data is collected (Article 13) or, if collected indirectly, within a reasonable time (Article 14):

A cookie policy sits alongside this and is a separate PECR obligation (consent for non-essential cookies) — the two are often combined into one page, but they answer different legal questions.

3. The ICO data protection fee — this part IS size-based

Under the Data Protection (Charges and Information) Regulations 2018, most organisations that process personal data must pay an annual fee to the ICO, in three tiers:

TierRoughly who it covers
Tier 1 (micro)Turnover/budget under about £632,000 and fewer than 10 staff (most sole traders and small shops)
Tier 2 (small/medium)Larger turnover or staff count, up to certain thresholds
Tier 3 (large)Large organisations and public authorities
This is the one place size genuinely matters — but it changes what you pay the ICO, not whether you need a privacy notice. Trading without paying a required fee can itself attract a penalty, separate from any transparency failing.

4. The mistakes that get flagged

The most common failure mode isn't having no policy at all — it's having an out of date, copied one. Real examples we've seen on live UK retail sites:

A policy copied from another company's website usually carries that company's answers, not yours — and, as above, sometimes carries their mistakes too.

5. Quick compliance checklist

  1. Privacy notice covering Article 13/14 items, published and easy to find?
  2. Cookie policy + a real opt-in banner for non-essential cookies?
  3. Lawful basis identified for every purpose you process data for?
  4. Retention periods defined, not left open-ended?
  5. ICO data protection fee paid, at the correct tier?
  6. SAR process that doesn't default to charging a fee?
  7. Marketing consent collected separately from other consents?
  8. Policy reflects what your business actually does — not copied from elsewhere?

How many of those eight can you tick off today?

Run the free vrisk data-protection readiness check: answer a few questions and see where your business stands against UK GDPR — and generate a privacy policy and cookie policy tailored to what you actually do, ready for professional review.

Run my free GDPR check →

6. FAQ

Is a small business exempt from UK GDPR?

No. There is no general small-business exemption from the transparency duties. Any organisation processing personal data is a controller and needs a privacy notice.

Do sole traders need a privacy policy?

Yes, if you collect any personal data — customer names, emails, order details, or a mailing list. The obligation follows from processing data, not from company size.

Do I have to pay the ICO data protection fee?

Most organisations processing personal data must, in one of three tiers based on turnover and staff numbers. A small number of narrow exemptions exist — check the ICO's self-assessment tool rather than assuming.

What must a UK privacy notice include?

Who the controller is, what's collected and why, the lawful basis, retention periods, who data is shared with, any international transfers, and the individual's rights including the right to complain to the ICO.

Can I charge for a subject access request?

Not as a general rule — SARs are free under UK GDPR. A fee only applies to manifestly unfounded/excessive requests or extra copies.

Can I just copy another company's privacy policy?

No — it will describe their data practices, not yours, and can carry forward their mistakes. It needs to reflect what your business actually does.

Disclaimer: this guide is general information about UK data protection law and is not legal advice. For advice on your specific circumstances, consult a qualified UK solicitor or data-protection professional.