For your business
For your business6 min read·Updated July 2026

GDPR for a one-person business: what you actually have to do

GDPR applies to a one-person business, but almost nothing about it requires a lawyer. Here's the genuinely proportionate version of what you have to do.

Quick answer

There's no small-business exemption from UK or EU GDPR — if you hold customer data, it applies. But the obligations scale with what you actually do, and for a typical sole trader the realistic list is short: know what data you hold and why, have a lawful basis for each purpose, publish a privacy notice, keep data securely and no longer than you need it, be able to handle an access or deletion request, pay the ICO fee if due, and be able to report a serious breach within 72 hours.

What applies to a sole trader and what doesn't

ObligationApplies to a one-person business?
Lawful basis for each purposeYes
Privacy notice on your websiteYes
Security and sensible retentionYes
Handle access / deletion requestsYes
ICO data protection fee (UK)Usually
72-hour breach reportingYes, if it risks people's rights
Formal Record of Processing (ROPA)Usually not required, but useful
Appoint a Data Protection OfficerAlmost never

Step-by-step

  1. 1

    Write down what you hold, where it lives, and why

    Half an hour with a sheet of paper does most of the work. List every place customer data sits: your email inbox, your phone contacts, a booking system, an invoicing tool, a mailing list, WhatsApp chats, a paper diary. For each, note what you hold, why you have it, and how long you keep it. A full Record of Processing Activities is generally only mandatory for larger organisations or riskier processing, but this informal version is what every other obligation depends on.

  2. 2

    Pick a lawful basis for each purpose

    Every processing purpose needs one of the six Article 6 bases. Three cover almost everything a sole trader does: contract, for delivering the work someone has hired you for; legal obligation, for keeping invoices and tax records; and legitimate interests, for things like following up an enquiry. Consent is the right basis for marketing emails to people who aren't customers — and remember consent must be freely given and as easy to withdraw as to give.

  3. 3

    Publish a privacy notice and make it findable

    You must tell people what you do with their data at the point you collect it. A privacy notice covering who you are, what you collect, why, your lawful basis, who you share it with, how long you keep it and how to exercise their rights is enough for a typical service business. Link it in your footer and next to your contact form. This is an hour of work, not a legal engagement.

  4. 4

    Get the security basics right

    Proportionate security for a one-person business means: unique passwords in a password manager, two-factor authentication on email and anything holding customer data, an encrypted and locked laptop and phone, no customer lists in unsecured cloud folders, and HTTPS on your website. Email is the highest-risk asset almost every sole trader owns, because it usually contains years of client information.

  5. 5

    Delete things on a schedule

    Indefinite retention is one of the most common failures and one of the easiest to fix. Decide a period for each category — enquiries that went nowhere after a year or two, financial records for the period tax rules require, marketing contacts until they unsubscribe — and actually apply it. Less data held means less to lose, less to report, and less to hand over on a request.

  6. 6

    Be ready for a rights request

    Anyone can ask what data you hold about them, ask for it to be corrected, or ask for it to be deleted. You generally have one month to respond and you can't normally charge. This is why the inventory in step one matters: if you know where data lives, a request is an afternoon; if you don't, it's a crisis. Deletion isn't absolute — you can keep what you're legally required to, such as invoices.

  7. 7

    Know the 72-hour breach rule

    If you suffer a personal data breach likely to result in a risk to people's rights and freedoms, you must notify the ICO within 72 hours of becoming aware of it, and tell the affected individuals if the risk is high. A lost unencrypted laptop with client records counts. Encryption is what usually turns a reportable breach into a non-event, which is the strongest practical argument for turning it on.

  8. 8

    Pay the ICO fee if it's due, and keep the receipt

    In the UK, most sole traders processing personal data electronically owe the data protection fee — £52 a year at tier 1, or £47 by direct debit. It's a separate obligation from everything above and doesn't make you compliant on its own, but not paying it is the most visible and most easily penalised failure on this list.

Tips & best practices

  • There is no exemption for being small. There is, correctly, an expectation that your response is proportionate.
  • The data inventory is the foundation — every other obligation gets easier once it exists.
  • Consent is only the right basis for marketing to non-customers; contract and legitimate interests cover most of the rest.
  • Two-factor authentication on your email is the single highest-value security step for a sole trader.
  • Encryption on your laptop and phone is what converts a lost device from a reportable breach into an inconvenience.
  • The UK framework was updated by the Data (Use and Access) Act 2025, but the core principles above are unchanged. Verified July 2026; general information, not legal advice.

Common questions

Does GDPR apply to a sole trader?

+

Yes. There's no exemption based on business size. If you hold personal data about customers, enquirers, suppliers or staff, UK and EU GDPR apply. What scales down is the response: the obligations are proportionate to the volume and sensitivity of what you process, and for most sole traders that means a short, practical list rather than a compliance programme.

Do I need a data protection officer?

+

Almost certainly not. A DPO is required only where you're a public authority, or your core activities involve large-scale regular monitoring or large-scale processing of special category data. A one-person service business essentially never meets that threshold. You remain responsible for compliance yourself.

What lawful basis should I use for customer data?

+

For delivering work someone has hired you for, contract. For keeping invoices and records that tax law requires, legal obligation. For following up enquiries or basic customer administration, legitimate interests. For marketing emails to people who aren't already customers, consent. Pick a basis per purpose and note it in your privacy notice.

Can a sole trader be fined under GDPR?

+

Yes — the law applies to you and enforcement doesn't exclude small businesses. In practice the ICO's approach to a small business acting in good faith usually focuses on putting things right rather than large fines, but the most commonly penalised failure is simply not paying the data protection fee, which is easy and cheap to avoid.

How long should I keep customer data?

+

Only as long as you need it for the purpose you collected it, with financial records kept for the period tax rules require. Set a period per category — for example, unconverted enquiries after a year or two, marketing contacts until they unsubscribe — write it in your privacy notice, and actually delete on schedule. There's no single legal number.

Read next

Ready to build your site?

Free to start. No credit card required. Live in under 60 seconds.

Get started free