DxtraBETA
Back to blog
GuidesUKSmall Business July 2026 6 min read

The Small Business Guide to the United Kingdom in 2026

A plain-English walkthrough of what UK data protection law asks of a small business in 2026 — the ICO fee almost everyone misses, cookie consent, access requests, breaches, and what the Data (Use and Access) Act 2025 actually changed.

What the law actually asks of a small business

If you sell online or keep a customer list, UK data protection law already applies to you. There is no headcount threshold and no turnover cutoff that quietly excuses a two-person business. That sounds heavier than it is in practice. Most of what follows is a short set of decisions you make once, write down, and revisit when something about your business changes.

The rules come from three places. The UK GDPR and the Data Protection Act 2018 sit together and govern personal data generally — meaning any information that identifies a living person, from an email address to an order history to a delivery note. The Privacy and Electronic Communications Regulations, almost always shortened to PECR, sit on top and deal specifically with cookies and electronic marketing. The regulator for all of it is the Information Commissioner's Office, the ICO, at ico.org.uk.

Who this applies to

You are in scope if you hold personal data about people in the UK — customers, enquiries, newsletter subscribers, job applicants, or your own staff. That covers the obvious cases, like a Shopify store with a mailing list, and the less obvious ones: a consultancy with a CRM, a cafe running a loyalty scheme, a tradesperson keeping quotes and addresses in a spreadsheet.

It applies whether or not you have a website. It applies whether or not you sell to consumers. And it applies even if you use someone else's platform to do the collecting — your shop's platform is responsible for its own systems, but the customer data you gather through it is yours to account for. Being small changes how much work each obligation involves. It does not remove the obligation.

What you actually have to do

Pay the ICO data protection fee. This is the single most common thing UK small businesses miss, and it is the easiest to fix. Nearly every business that processes personal data electronically has to pay an annual fee to the ICO unless it qualifies for an exemption. For tier 1, which covers micro organisations, the fee is £52 a year, reduced to £47 if you pay by direct debit. Not paying is not a grey area — it attracts a fixed penalty, £400 at the lowest tier. Plenty of owners have run a perfectly careful business for years while sitting on this one unresolved item, usually because nobody ever mentioned it. Check whether you need to pay, and if you do, set up the direct debit so it renews without you thinking about it again.

Know your lawful basis for each thing you do. Every use of personal data needs a reason the law recognises — performing a contract, meeting a legal obligation, consent, or legitimate interests, among others. You do not need a lawyer to pick one, but you do need to actually pick, and to write down what you chose and why. The useful habit is to go activity by activity rather than trying to label your whole business at once: fulfilling orders, sending marketing, keeping accounts, and handling job applications may each land on a different basis.

Tell people what you are doing, in language they can read. A privacy notice is not decoration. It should say what you collect, why, who you share it with, how long you keep it, and how someone exercises their rights. The common failure is not omission but inheritance — a template copied from a much larger company, describing systems you do not run and transfers you do not make. A short, accurate notice that matches your actual business is worth more than a long one that does not.

Get cookies and electronic marketing right under PECR. You need consent before you set non-essential cookies — analytics and advertising trackers included. The rule that catches most sites is a design one: rejecting must be as easy as accepting. A prominent "Accept all" button next to a greyed-out link buried in a settings panel does not meet that bar, and neither does a banner that starts the trackers before anyone clicks. This is not a theoretical risk. The ICO has been actively writing to the UK's most-visited websites about non-compliant cookie banners. Electronic marketing sits under the same regulations, so your consent practices there matter just as much as your lawful basis under the UK GDPR.

Be ready to answer an access request. Anyone can ask what personal data you hold about them. You have one month to respond, extendable by up to two further months where the request is complex or where someone has made numerous requests, and in normal cases you cannot charge for it. The practical work is knowing where the data lives before the request arrives. If a request would send you hunting through four inboxes, a spreadsheet, and an old booking system, that is worth solving now rather than under a one-month clock.

Have a plan for a breach before you have one. If personal data is lost, exposed, or accessed by the wrong person, and the breach poses a risk to people's rights and freedoms, you must notify the ICO within 72 hours of becoming aware of it. Where the risk to individuals is high, you also have to tell the affected people. Seventy-two hours is not long if you are simultaneously working out what happened. Decide in advance who makes the call, what you would need to establish, and where you would record it.

What changed: the Data (Use and Access) Act 2025

If you searched this topic a couple of years ago, you may have read about the Data Protection and Digital Information Bill. That bill fell when Parliament was dissolved in 2024. Its successor, the Data (Use and Access) Act 2025, received Royal Assent and is being commenced in stages, with a set of provisions commencing on 5 February 2026. The framework you already know did not get replaced; it got adjusted.

Four changes are worth naming. The Act introduces a list of recognised legitimate interests — purposes you can rely on without carrying out the usual balancing test. These cover things like national security, emergencies, crime prevention and safeguarding. The rules on solely automated decision-making are relaxed outside special category data, which matters if you use automated scoring or filtering anywhere in your process. There is a new complaints route, which requires controllers to have a complaints process, so a customer can raise a data protection concern with you directly. And the research provisions have changed, which is relevant if you use customer data for analysis or product development.

One point of housekeeping. The Act provides for the ICO to be reconstituted as the Information Commission, but that has not yet taken effect. The regulator you deal with today is still the Information Commissioner's Office, and it will become the Information Commission when the relevant provisions commence.

Common mistakes

The most widespread error right now is the belief that direct marketing is a recognised legitimate interest under the new Act. It is not, and you will find this stated confidently across a lot of otherwise reasonable writing. Direct marketing remains a legitimate interest that still requires a balancing test, and PECR's consent rules still apply on top of it. If you have relaxed your marketing practices on the strength of that claim, it is worth revisiting.

The second is assuming the fee does not apply because the business is small. Size affects the tier, not whether you pay. The third is treating the cookie banner as a visual component rather than a legal one — copying a banner that looks like everyone else's without checking that rejection is genuinely as easy as acceptance. The fourth is writing a privacy notice once at launch and never touching it again, so it describes a business you no longer run.

Where Dxtra fits

Dxtra generates a privacy program from a questionnaire: a privacy policy, a cookie notice, consent records, processing records, a public Transparency Center, and DSAR handling. It covers more than 500 obligations across over 140 countries, and starts at $10 a month. It is a way to get the paperwork built and kept current without assembling it yourself; it does not replace judgement about how your business actually runs.

Where to start

Do the fee first, because it is a five-minute answer with a fixed penalty attached. Then open your own site in a private window and watch what the cookie banner actually does. Then write down, for each of the three or four things you use customer data for, which lawful basis you are relying on. Then decide who handles an access request and who makes the breach call. That is most of it, and none of it needs a legal team.

If you want a quick outside read before you begin, Dxtra's free scan reads your site's public pages in about two minutes with no signup and returns a risk band with findings mapped to named sources — it points you at what to look at, and does not determine whether you are compliant.

This article is general information, not legal advice. Rules change; confirm anything that matters with the ICO (ico.org.uk) or a qualified adviser before you rely on it.

Ready to get compliant?

Start your privacy program today — from $10/month.