Does my small business need a privacy policy in the UK?
Short answer: almost certainly yes. "We're too small for GDPR" is one of the most common — and most costly — assumptions a small business makes. UK GDPR does not carve out an exemption for size. If you hold a customer list, an email newsletter, staff records, or a booking system, you are already a data controller, and the law expects you to tell people what you do with their data.
This guide sets out what actually depends on your size (the ICO fee) versus what doesn't (the duty to have a compliant privacy notice), and the mistakes that show up again and again in small-business policies.
1. Why "small business" isn't an exemption
UK GDPR and the Data Protection Act 2018 apply to any organisation that processes personal data — a sole trader with a spreadsheet of customer emails is a data controller in exactly the same sense as a large retailer. Two separate things get confused here, and it's worth untangling them:
- The duty to be transparent (have a privacy notice, have a lawful basis, respect data-subject rights) — applies regardless of size or turnover.
- The ICO registration fee — does scale with size, in tiers (see section 3). This is the only part of the picture that is genuinely size-dependent.
A handful of narrow exemptions from the fee exist (for example, processing limited to core staff administration such as payroll, with no other use of personal data) — these are specific and should be checked against the ICO's self-assessment tool, not assumed.
2. What a privacy notice must say
Articles 13 and 14 of UK GDPR set out what a data subject must be told, typically at or before the point data is collected (Article 13) or, if collected indirectly, within a reasonable time (Article 14):
- Who the controller is, and how to contact them.
- What personal data is collected, and why (the purposes).
- The lawful basis relied on for each purpose (consent, contract, legitimate interests, legal obligation, etc.).
- How long the data is retained.
- Who the data is shared with — payment processors, couriers, email marketing tools, accountants.
- Whether data is transferred outside the UK, and what safeguard applies.
- The individual's rights — access, rectification, erasure, objection, and the right to complain to the ICO.
A cookie policy sits alongside this and is a separate PECR obligation (consent for non-essential cookies) — the two are often combined into one page, but they answer different legal questions.
3. The ICO data protection fee — this part IS size-based
Under the Data Protection (Charges and Information) Regulations 2018, most organisations that process personal data must pay an annual fee to the ICO, in three tiers:
| Tier | Roughly who it covers |
|---|---|
| Tier 1 (micro) | Turnover/budget under about £632,000 and fewer than 10 staff (most sole traders and small shops) |
| Tier 2 (small/medium) | Larger turnover or staff count, up to certain thresholds |
| Tier 3 (large) | Large organisations and public authorities |
4. The mistakes that get flagged
The most common failure mode isn't having no policy at all — it's having an out of date, copied one. Real examples we've seen on live UK retail sites:
- Citing the Data Protection Act 1998, which was repealed and replaced by UK GDPR / the Data Protection Act 2018.
- Naming the regulator as the "Data Commissioner's Office" — it's the ICO (Information Commissioner's Office).
- Saying subject access requests "may be subject to a fee" — under UK GDPR, SARs are free as a general rule.
- Relying on browser-settings or implied consent for third-party tracking cookies, when PECR and UK GDPR require an opt-in cookie banner.
- Bundled consent — one tick box covering marketing, cookies and data sharing together, when each needs its own clear opt-in.
- Missing lawful bases, retention periods, international-transfer safeguards, or the right to complain to the ICO altogether.
A policy copied from another company's website usually carries that company's answers, not yours — and, as above, sometimes carries their mistakes too.
5. Quick compliance checklist
- Privacy notice covering Article 13/14 items, published and easy to find?
- Cookie policy + a real opt-in banner for non-essential cookies?
- Lawful basis identified for every purpose you process data for?
- Retention periods defined, not left open-ended?
- ICO data protection fee paid, at the correct tier?
- SAR process that doesn't default to charging a fee?
- Marketing consent collected separately from other consents?
- Policy reflects what your business actually does — not copied from elsewhere?
How many of those eight can you tick off today?
Run the free vrisk data-protection readiness check: answer a few questions and see where your business stands against UK GDPR — and generate a privacy policy and cookie policy tailored to what you actually do, ready for professional review.
Run my free GDPR check →6. FAQ
Is a small business exempt from UK GDPR?
No. There is no general small-business exemption from the transparency duties. Any organisation processing personal data is a controller and needs a privacy notice.
Do sole traders need a privacy policy?
Yes, if you collect any personal data — customer names, emails, order details, or a mailing list. The obligation follows from processing data, not from company size.
Do I have to pay the ICO data protection fee?
Most organisations processing personal data must, in one of three tiers based on turnover and staff numbers. A small number of narrow exemptions exist — check the ICO's self-assessment tool rather than assuming.
What must a UK privacy notice include?
Who the controller is, what's collected and why, the lawful basis, retention periods, who data is shared with, any international transfers, and the individual's rights including the right to complain to the ICO.
Can I charge for a subject access request?
Not as a general rule — SARs are free under UK GDPR. A fee only applies to manifestly unfounded/excessive requests or extra copies.
Can I just copy another company's privacy policy?
No — it will describe their data practices, not yours, and can carry forward their mistakes. It needs to reflect what your business actually does.