Close Menu
  • News
  • Home
  • In Profile
  • Finance
  • Legal
  • Technology
  • Events
  • Features
  • Wellbeing & Mental Health
  • Marketing
  • HR & Recruitment
  • About
  • Advertise
  • Events Calendar
  • Business Wall
  • Subscribe
  • Contact
  • 0843 289 4634
X (Twitter) LinkedIn YouTube
Trending
  • Whistleblowing and the Cost of Silence: Why SMEs Must Have Policies in Place
  • Rewiring the UK’s investment landscape with AI
  • What Swedish SME Managers Can Teach UK Businesses About Remote Work
  • The 5 biggest VC negotiation mistakes and how to avoid them
  • Entrepreneurs Circle Makes £5M move with 15,000 sq ft HQ acquisition
  • An Interview with Noreena Hertz
  • Why legal thinking belongs in your growth strategy
  • The Importance of Being Liquid
X (Twitter) LinkedIn YouTube
SME Today
  • About
  • Advertise
  • Events Calendar
  • Business Wall
  • Subscribe
  • Contact
  • 0843 289 4634
  • News
  • Home
  • In Profile
  • Finance
  • Legal
  • Technology
  • Events
  • Features
  • Wellbeing
  • Marketing
  • HR & Recruitment
SME Today
  • About
  • Advertise
  • Events Calendar
  • Business Wall
  • Subscribe
  • Contact
  • 0843 289 4634
  • Twitter
  • LinkedIn
  • YouTube
  • RSS
You are at:Home»Legal»UK SMEs are risking fines of up to £17.5 million for serious breaches of GDPR principles. 
GDPR General Data Protection Regulation for European Union concept, internet
GDPR General Data Protection Regulation for European Union concept, security of personal information and identity on internet

UK SMEs are risking fines of up to £17.5 million for serious breaches of GDPR principles. 

0
Posted By sme-admin on July 30, 2024 Features, Legal, Marketing

Research from business intelligence consultancy Catalyst BI has found that 18% of organisations processing personal data struggle to understand ICO regulatory guidance.

The data was collected using the UK Business Data Survey, which also revealed that a combined 21% of SMEs found it difficult to understand regulatory guidance published by the ICO.

Becky Stables, data management expert at Catalyst BI explains where your business is going wrong in terms of GDPR compliance and how to avoid the most common mistakes that could cost SMEs time and money.

“There are 5.51 million SMEs in the UK, which make up 99.9% of private sector businesses, but they often struggle with GDPR compliance due to a lack of awareness and understanding of the regulation’s requirements, resulting in inadequate data protection measures.

Some businesses, particularly small ones, may not fully understand the regulations or might mistakenly believe that GDPR does not apply to them because the UK left the EU. However, the UK has its version, known as the UK GDPR, which has similar rules.”

  1. Retaining unnecessary data: “The more personal data you collect, the more you’ll need to invest in storage space and data protection, which will cost you both time and money. Additionally, under the GDPR, personal data should only be retained for as long as it is needed to fulfil the purposes for which it was originally collected. If you must keep certain types of records for a specific period, such as financial, medical, or legal documents, implement a data retention policy. This policy should outline how long various types of data are kept and detail your processes for managing, storing, and disposing of records. Regularly review your data and securely destroy personal information once it’s no longer needed.”
  2. Failing to renew your ICO registration: “If you handle or use personal information, you will need to register with the ICO and pay a fee. Processing means taking action with a person’s personal data, from storing IP or MAC addresses to shredding documents containing personal data. These data protection fees are due annually and failure to pay can result in fines of up to £4,000. However, most SMEs only need to pay £40 to £60 per year. To avoid fees, set a reminder for your ICO registration renewal date well in advance. If possible, set up an automatic renewal to save you from having to remember and regularly review your organisation’s data protection practices to ensure compliance with ICO requirements.”
  3. Not properly complying with Subject Access Request: “GDPR states that those using your service or product have the “right of access” to their personal information. This allows them to request any personal data you hold about them, known as a subject access request (SAR). Your organisation must know how to properly comply with SAR requests, otherwise the requester may use a court order for you to comply or seek compensation. You need to respond to a SAR within one month of receiving it. The first step is to designate a data protection lead. Verify the requester as soon as possible by asking specific security questions, like reference numbers. Make sure there is a mutual understanding of what they’re asking to see. If someone other than the data subject submits the SAR, ensure they have the authority to access the information. Identify and redact any information related to third parties to protect their privacy. Alongside providing the requester’s personal data, include your privacy information in your reply to explain why and how their data is held.”
  4. Emailing sensitive information to the wrong person: “This is a common problem, as the autofill feature in the ‘To’ field predicts who the recipient of the email is as soon as you start typing. This makes it more convenient to navigate your address book but you also risk accidentally sending personal information to the wrong person if you’re not careful. By law, you must report any personal data breaches to the ICO within 72 hours. And attempt to recall the email in the ‘Sent Items’ folder. If you can’t recall it, don’t be afraid to follow up and ask the contact to delete the original email. In the future, consider disabling autofill for work emails. Additionally, use Data Loss Prevention tools like Email DLP to scan emails for sensitive data or block emails from being sent to unintended recipients.”
  5. Opening suspicious links and attachments: “Occasionally, you might receive emails from unknown senders or encounter suspicious links and attachments. These could be phishing attempts or other forms of cybercrime that can damage your computer and systems. To protect your devices, use antivirus software on all work computers and laptops and restrict staff from downloading third-party apps from unknown sources as these are not vetted for security. Furthermore, ensure that all your IT equipment is running the latest software and firmware updates from developers and vendors. To ensure software is consistently updated, you can set operating systems to automatically update. Make sure every device has a firewall enabled to provide security between your internal and external networks.”
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Whistleblowing and the Cost of Silence: Why SMEs Must Have Policies in Place

The 5 biggest VC negotiation mistakes and how to avoid them

Why legal thinking belongs in your growth strategy

Comments are closed.

Follow SME Today on Linkedin and share all the topics you find interesting
Get £100 of free trades - ii trading account

The Newsletter

Join our mailing list for the best SME stories, handpicked and delivered direct to your inbox every two weeks!

Sign Up
Events Calendar
    • Marketing
    June 5, 2025

    Why marketing budgets are wasted without sales alignment

    June 4, 2025

    Industry Shift at Royal Ascot 2025 Turns Hospitality into Serious Networking Ground

    • Finance
    June 13, 2025

    Rewiring the UK’s investment landscape with AI

    June 12, 2025

    The 5 biggest VC negotiation mistakes and how to avoid them

    • Health & Safety
    January 29, 2025

    UK takeaways guilty of shocking hygiene failures:

    December 18, 2024

    Comment on Covid Corruption Commissioner Investigation

    • Events
    May 27, 2025

    Jose Ucar Confirmed for Leadership Live 2025 Speaker Line-Up

    November 19, 2024

    Seventeenth Global Entrepreneurship Week (GEW)

    • Community
    June 2, 2025

    National Charity Accelerates Children’s Reading Through New Corporate Partnership

    May 14, 2025

    Social care experts launch an online marketplace to disrupt a sector in crisis.

    • Food & Drink
    June 4, 2025

    Creative Nature Launches Its First-Ever Kids’ Snack Bar Range in Tesco Nationwide

    April 16, 2025

    Cutting Down on Business Costs in Your Cafe

    • Books
    April 24, 2025

    Values-Driven Professionalism: A Path to Client Loyalty

    December 2, 2024

    Banish the banshee boss: how to lead without fear – addressing the issue of fear-based management and how NOT to be this manager

    About

    SME Today is published by the same team who deliver The Great British Expos’. We have been organising various corporate events for the last 10 years, with a strong track record of producing well managed and attended business events across the UK.

    Join Our Mailing List

    Receive the latest news and updates from SMEToday.
    Read our Latest Newsletter:


    Sign Up
    X (Twitter) YouTube LinkedIn
    Most Recent Posts
    June 13, 2025

    Whistleblowing and the Cost of Silence: Why SMEs Must Have Policies in Place

    June 13, 2025

    Rewiring the UK’s investment landscape with AI

    June 12, 2025

    What Swedish SME Managers Can Teach UK Businesses About Remote Work

    June 12, 2025

    The 5 biggest VC negotiation mistakes and how to avoid them

    June 11, 2025

    Entrepreneurs Circle Makes £5M move with 15,000 sq ft HQ acquisition

    Categories
    • Books
    • Community & Charity
    • Education and Training
    • Environment
    • Events
    • Features
    • Finance
    • Food and Drink
    • Health & Safety
    • HR & Recruitment
    • In Profile
    • Legal
    • Marketing
    • News
    • Property & Development
    • Sponsored Content
    • Technology
    • Transport & Tourism
    • Wellbeing & Mental Health

    Copyright © 2020 SME Today.

    • ABOUT SME TODAY: THE GO TO RESOURCE FOR UK BUSINESSES
    • Privacy
    • Contact
    Copyright © 2025 SME Today.
    • ABOUT SME TODAY: THE GO TO RESOURCE FOR UK BUSINESSES
    • Privacy
    • Contact

    Type above and press Enter to search. Press Esc to cancel.