GLOBAL BRIDGE LABS
← All posts/BPO & Operations

Who is responsible for data protection in a small firm?

Who is responsible for data protection in a small business? The business is. See what that means in practice and how to assign it when nobody owns it.

By Dhanushka Pinto, Co-founder / DirectorPublished 6 min read
Who is responsible for data protection in a small business: key takeaways infographic by Global Bridge Labs
Key takeaways from this article. Share it with the link and credit Global Bridge Labs.
On this page

Key takeaways

The business itself is responsible for data protection, as the controller of the personal data it holds. In practice that means the owner or directors. Most small businesses do not need a formal data protection officer, but every business needs a named person who looks after it. When nobody does, the cost is hidden until something goes wrong.

  • The business is the controller and is legally responsible.
  • Most small firms do not need a formal data protection officer.
  • Every firm needs 1 named person who owns data protection.
  • Most organisations handling personal data must pay the ICO a data protection fee.

Nobody owning data protection in your business? Message us on WhatsApp and we will help you set up the basics.

Chat on WhatsApp →

Who is legally responsible?

Under UK GDPR the controller is responsible: the organisation that decides why and how personal data is used. The Information Commissioner's Office explains that controllers carry the main obligations, including when they use processors such as software providers or outsourced teams. Responsibility cannot be delegated away.

Does a small business need a data protection officer?

Usually not. A formal data protection officer is required only in certain cases, such as public authorities and organisations whose core activities involve large-scale monitoring or large-scale processing of special category data. The ICO still expects every organisation to have enough knowledge and resource to comply.

What goes wrong when nobody owns it?

When nobody owns data protection, the basics are missed. Each is small, and together they create real exposure.

  • The ICO data protection fee is not paid.
  • Privacy information is out of date.
  • Old customer data is never deleted.
  • Requests from individuals are not recognised or answered in time.
  • A breach is not spotted, recorded or reported.
  • Suppliers handle data without a written agreement.

How do you assign responsibility?

Assign a named lead, give them a short list and an hour a month. The ICO publishes advice for small organisations that covers the essentials.

  • Name the lead and tell the team.
  • List the personal data you hold and where.
  • Check the fee, privacy notice and retention periods.
  • Write down what to do with a request or a breach.
  • Check contracts with anyone who processes data for you.
  • Review once a year.

When should you get outside help?

Get outside help if you handle special category data such as health information, process data at scale, transfer it overseas or have had a breach. A few hours of specialist advice costs less than getting those wrong.

What does the role take in time?

For a typical small business, looking after data protection takes a day or two to set up and about an hour a month to maintain. Setup covers mapping what personal data you hold, checking the ICO fee, updating the privacy notice and writing short procedures for requests and breaches. The monthly hour is for reviewing new tools and suppliers, checking that old data is being deleted and answering staff questions.

Who is the right person?

The right person is organised, has some authority and sees how data moves through the business. In most small firms that is the operations manager, office manager or a director. It should not be the newest or most junior member of staff, and it should not be left to an outside supplier, because the responsibility remains yours.

  • Senior enough to change how things are done.
  • Close enough to operations to know where data goes.
  • Given time in their role, not asked to fit it in.
  • Supported with access to advice when needed.

How does this work when a provider handles your data?

When a provider handles personal data for you, they act as your processor and you remain the controller. The ICO expects a written contract setting out what they may do, how they keep data secure and what happens at the end. You should also know where the data is processed. A provider who cannot answer those questions clearly is a risk, wherever they are based.

What does this look like in practice?

A pattern we see: a former customer emails asking for a copy of their data. The message sits in a shared inbox for six weeks because nobody recognises it as a formal request with a legal time limit.

Data protection ownership checklist

Work through this in an afternoon.

  • Name a data protection lead.
  • Confirm the ICO fee position.
  • Map what personal data you hold.
  • Publish an accurate privacy notice.
  • Set retention periods.
  • Brief staff on requests and breaches.

Next step

Tell us how customer data moves through your business. We will show how we handle it securely for clients and where a named owner makes the difference, in a 30-minute call.

Message us on WhatsApp about handling customer data safely, or book a 30-minute consultation.

Chat on WhatsApp →

Sources and further reading

Frequently asked questions

Is the business owner personally responsible for GDPR?

The organisation is the controller and carries the legal responsibility. For a sole trader, that is the individual. In a company, directors are accountable for ensuring it complies, even where day-to-day tasks are given to a member of staff. Name someone for the day-to-day work.

Do all small businesses have to pay the ICO fee?

The ICO states that organisations, including sole traders, that use personal information need to pay a data protection fee unless they are exempt. The ICO website has a self-assessment tool to check whether an exemption applies to you. Check yours today.

Can I outsource data protection responsibility?

No. You can use processors and advisers, but as controller you remain responsible. You must have a written contract with any processor and satisfy yourself that they protect the data properly. Choose processors who can show how they comply and put it in the contract.

How long do I have to respond to a data request?

Generally one month from receipt for a subject access request, with limited scope to extend for complex cases. Staff need to recognise a request when they see one, because the clock starts whether or not it is labelled as such.

Written by

Dhanushka Pinto
Dhanushka Pinto
Co-founder / Director

Global Bridge Labs (GBL) is a UK–Sri Lanka partner for social media, websites and BPO. Everything here comes from client delivery, not theory.

Share this article

Reading is good.
Fixing is better.

30 minutes with our team and you'll leave knowing which of the three problems to fix first.

Book a 30-Minute Consultation →
Keep reading