GDPR compliance

Following the EU's data privacy rules on how businesses collect, use, store and protect personal information, including staff data.
Glossary >
GDPR compliance

What is GDPR compliance?

GDPR stands for the General Data Protection Regulation. It is a major data privacy law created by the European Union to protect personal information. GDPR compliance means following the rules around how businesses collect, use, store, and protect personal data.

If your business handles information relating to EU or UK individuals, GDPR applies, even if your company is based elsewhere. The rules cover customer, employee, and supplier data alike.

The key principles of GDPR

The UK GDPR is built around a few core principles. Think of them as the “don’t be creepy with people’s data” rules.  

Businesses must:

  • Collect data lawfully, fairly, and transparently  
  • Only use data for clear purposes  
  • Keep data accurate and up to date  
  • Collect only the data they actually need  
  • Store information securely  
  • Delete data when it is no longer needed  

Businesses are also responsible for proving they follow these rules. This is called accountability. According to the ICO’s GDPR guidance, these principles apply to both customer and employee data.

What counts as personal data under GDPR?

Under GDPR, personal data is any information that can identify a person, either directly or indirectly.

This includes:

  • Names and home addresses  
  • Email addresses and phone numbers  
  • Payroll and bank details  
  • IP addresses and online activity  
  • Employee records and CVs  
  • CCTV footage and ID numbers  

If the information can identify a worker, customer, or supplier, it falls under data protection rules. The ICO’s guide to personal data explains this in detail.

Your key GDPR obligations as a business

If your business handles personal data, GDPR compliance is not optional for you.  

Key GDPR obligations include:

  • Having a lawful reason to collect data  
  • Keeping customer and employee data secure  
  • Explaining how data is used in a privacy policy  
  • Reporting serious data breaches promptly  
  • Respecting GDPR data subject rights, such as access or deletion requests  
  • Training staff on data protection practices  

The ICO says serious GDPR breach notifications must usually be reported within 72 hours. Small businesses are not exempt, although the level of compliance expected depends on the type and volume of data handled.

Data subject rights under GDPR

Under GDPR, individuals have legal rights over how their personal data is used. Businesses must respond properly and within set time limits.

Key GDPR data subject rights include:

  • The right to access their data  
  • The right to correct inaccurate information  
  • The right to request deletion of data  
  • The right to restrict or object to data processing  
  • The right to move their data elsewhere

ICO’s guide to individual rights under UK GDPR says most requests should be handled within one month. Ignoring them is a quick way to upset both regulators and customers.

GDPR compliance checklist for UK SMEs

GDPR for small businesses does not need to be painfully complicated. A few sensible processes go a long way.

Here is a simple GDPR compliance checklist:

  • Audit what personal data you collect  
  • Update your privacy policy  
  • Secure devices, passwords, and files  
  • Limit employee access to sensitive data  
  • Create a process for handling data requests  
  • Train staff on data protection compliance  
  • Review how long you keep records  
  • Have a GDPR breach notification process in place

What are the penalties for non-compliance?

Businesses that fail to protect personal data may face ICO investigations, reputational damage, and financial penalties.

Under UK GDPR, serious breaches can lead to fines of up to £17.5 million or 4% of annual global turnover, whichever is higher.  

The ICO’s guidance on fines and penalties explains that penalties depend on factors such as negligence, the severity of the breach, and how the business responded afterwards.

At Black Piano, businesses can hire remote talent in India without the usual worries around contracts, compliance, or sensitive employee data being mishandled. Clean processes. Transparent support. Far fewer headaches. Learn about our EOR services.

Contents

Related terms

XaaS (Anything as a Service)
XaaS (Anything as a Service) delivers technology over the internet through flexible subscription or usage-based models.
Read more
Zero-hours contract
A simple guide to how zero-hours contracts work, when they’re used, and what employers and workers need to know.
Read more
Yield ratio
A recruitment metric measuring how effectively candidates move from one hiring stage to the next, helping spot bottlenecks.
Read more
Year to date (YTD)
The period from the start of a calendar or fiscal year to today, used to track revenue, payroll and expenses.
Read more
Work from anywhere
A flexible model letting employees work from almost any location, provided they have the right tools and connection.
Read more
Wages
The money an employee earns for work done, usually based on hours worked or shifts completed each pay period.
Read more

About Us

We’re a UK-based talent partner helping SMEs build brilliant remote teams with skilled professionals from India. We support businesses across the UK, United States, South Africa, Australia and Europe, often on their first international hire. Our straightforward, inclusive service provides guidance, reassurance and hands-on support while taking the hassle out of global hiring and helping every team member settle in smoothly.

Read our blogs

Everything you need to know about hiring, HR, and offshoring to India - practical advice for business owners, view all blogs.