GDPR Compliance for Small Businesses in Sussex: A Practical Checklist

GDPR compliance is often presented as something complex and expensive — a compliance programme requiring lawyers, consultants, and significant investment. For most small businesses in Sussex, that framing is unhelpful and wrong. GDPR is achievable, and the foundations are straightforward to implement if you know what you're looking at.

This checklist is designed for business owners and managers who want to understand their compliance position without working through hundreds of pages of regulatory guidance. It covers the essentials: what you need to have in place, how to assess where you are, and what to prioritise if you're starting from scratch.

Understanding What GDPR Actually Requires

Before the checklist, it's worth being clear on what GDPR is asking of small businesses. The regulation is fundamentally about three things: being transparent with people about how you use their data, processing data only for legitimate purposes in proportionate ways, and protecting the data you hold from unauthorised access, loss, or damage.

These are reasonable obligations. Most business owners, when they understand what's actually required, find that many of the foundations are already in place — they just haven't been documented or formalised.

The Checklist

1. Know what personal data you hold and why.

This is the foundation of compliance. Personal data means any information that can identify a living individual — names, email addresses, phone numbers, IP addresses, CCTV footage, employee records, customer purchase history. You need to know what you hold, where it's stored, how it was collected, what you use it for, and how long you keep it.

If you can't answer those questions, start with a data mapping exercise. Work through each part of your business — sales, marketing, HR, finance, operations — and document the personal data that flows through each area.

2. Have a lawful basis for each type of processing.

GDPR requires you to have a lawful basis for every use of personal data. The most common bases for small businesses are: consent (the individual agreed to their data being used), contract (processing is necessary to fulfil a contract), legal obligation (you're required to hold the data by law), and legitimate interests (your business has a genuine reason to use the data that isn't overridden by the individual's rights).

Marketing data is a common area of confusion. If you're sending marketing emails, you typically need either consent or a legitimate interests assessment. Bought-in marketing lists are frequently non-compliant.

3. Have a privacy notice on your website.

Your privacy notice must tell people what data you collect, why you collect it, how long you keep it, who you share it with, and what rights they have. It doesn't need to be long, but it needs to be accurate and written in plain English.

If your privacy notice is a generic template from five years ago that bears no resemblance to how you actually process data, it needs updating.

4. Manage consent properly.

Where you rely on consent as your lawful basis, that consent needs to be freely given, specific, informed, and unambiguous. Pre-ticked boxes don't constitute valid consent. Bundling consent with terms and conditions doesn't work. And you need to be able to demonstrate that consent was given — which means keeping records.

5. Handle data subject rights requests.

Individuals have the right to access their personal data, correct inaccurate data, request deletion, restrict processing, and receive their data in a portable format. You need to have a process for responding to these requests within one month.

For most small businesses, this doesn't require sophisticated tooling. It does require knowing where data is held so you can respond promptly and accurately.

6. Manage data processors and suppliers.

If you share personal data with third-party suppliers — your accountant, your CRM provider, your cloud storage service, your email marketing platform — you are required to have a data processing agreement in place with each of them. Most reputable cloud providers provide standard DPA documentation; you just need to sign it and keep a record.

Review your supplier list and identify any processor relationships that don't have documentation in place.

7. Train your staff.

GDPR breaches are frequently caused by human error: emails sent to the wrong address, unencrypted laptops left on trains, failure to recognise a phishing attack that results in a data breach. Your staff need to understand the basics of data protection and what to do if something goes wrong.

This doesn't require an expensive training programme. A clear internal policy, a short briefing session, and regular reminders go a long way.

8. Secure your systems.

GDPR requires you to implement "appropriate technical and organisational measures" to protect personal data. For a small business, this means at minimum: strong passwords and multi-factor authentication for systems holding personal data, up-to-date antivirus and endpoint protection, encrypted storage for sensitive data (particularly on laptops and mobile devices), and a secure email system.

Cyber Essentials certification is worth considering as a structured way to implement and evidence these controls.

9. Have a breach response process.

If a data breach occurs — whether through a cyberattack, an accidental email, a lost device, or anything else — you may need to notify the ICO within 72 hours. You'll also need to assess whether to notify affected individuals.

This requires knowing what constitutes a reportable breach (not all incidents require reporting), having a clear internal escalation process, and knowing how to log and document incidents.

A basic incident response plan doesn't need to be complex. A simple document that defines what a breach is, who to tell, what information to gather, and when to notify the ICO is a reasonable starting point.

10. Appoint responsibility.

Someone in your organisation needs to own data protection. In larger organisations this may be a Data Protection Officer (required in some circumstances). For most small businesses, it's the business owner or a designated senior manager. The key is that there's a clear owner who understands the obligations and can make decisions.

Common Gaps for Sussex Small Businesses

In our work with SMEs across West Sussex, the most common gaps we see are:

Marketing databases where consent was never properly obtained, supplier relationships without DPA documentation, privacy notices that don't reflect actual practice, no documented retention periods (data being held indefinitely "just in case"), and no breach response process.

If several of these apply to your business, prioritise them in this order: get your breach response process in place first (because the clock is ticking if a breach occurs), then address your marketing consent position (because this is where the ICO focuses enforcement attention on SMEs), then work through the documentation and supplier gaps.

Getting Help

GDPR compliance for a small business doesn't require legal counsel for every step. What it requires is a systematic approach and someone who understands what proportionate compliance looks like for an organisation of your size.

If you're unsure where to start, or if you've been through this checklist and identified gaps you're not sure how to close, get in touch. We work with businesses across Sussex to implement practical, proportionate data protection programmes that meet regulatory requirements without unnecessary cost or complexity.


 

Next
Next

Is Your Brighton or Worthing Business Ready for a Cyberattack?