{"id":1011,"date":"2021-08-17T00:00:00","date_gmt":"2021-08-17T00:00:00","guid":{"rendered":"https:\/\/www.simplybusiness.co.uk\/\/knowledge\/articles\/data-protection-act-principles-for-small-business\/"},"modified":"2025-07-11T10:30:13","modified_gmt":"2025-07-11T10:30:13","slug":"data-protection-act-principles-for-small-business","status":"publish","type":"knowledge","link":"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/","title":{"rendered":"A guide to the Data Protection Act and GDPR for small businesses"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">If you\u2019re running a business, chances are you\u2019re also dealing with personal information. Whether that\u2019s details about customers, suppliers, or your own staff, it\u2019s important to follow certain data protection regulations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Read on to understand more about the Data Protection Act (DPA), UK GDPR and the key principles you need to be aware of as a small business.<\/p>\n\n\n\n<div class=\"wp-block-group alignfull is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<p class=\"wp-block-paragraph\">The pandemic brought everything online, but with that came additional data privacy challenges. App-based ordering in pubs, teaching on Zoom, and contact tracing has meant organisations and third-parties are collecting more of our personal data. But the UK\u2019s privacy body, the <a href=\"https:\/\/www.bbc.co.uk\/news\/business-58230932\" rel=\"noopener noreferrer\" target=\"_blank\">Information Commissioner\u2019s Office (ICO), has reminded people that they have a choice whether to hand over their personal data<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Learn more about how to navigate these data protection challenges as a small business in our simple guide:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><a href=\"#dpa\">Data Protection Act 2018 and UK GDPR<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"#meaning\">what the Data Protection Act means for businesses<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"#employers\">responsibilities for employers<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"#key-principles\">7 key principles<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"#consent\">getting consent from customers<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"#register\">when to register with the ICO<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"#checklist\">GDPR checklist \u2013 tips for small businesses<\/a><\/li>\n<\/ul>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group alignfull is-layout-flow wp-block-group-is-layout-flow\" id=\"dpa\">\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading\" id=\"dpa\">What is the Data Protection Act 2018?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/www.legislation.gov.uk\/ukpga\/2018\/12\/contents\/enacted\/data.htm\" rel=\"noopener noreferrer\" target=\"_blank\">Data Protection Act 2018<\/a> is a piece of UK legislation that\u2019s designed to protect the privacy of personal data. It replaces the Data Protection Act 1998 and now incorporates GDPR legislation into UK law.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In essence, the law aims to:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1. Give citizens and residents more control of their personal data<\/strong> \u2013 everyone has a right to find out what information the government and organisations hold about them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2. Simplify regulations for all businesses to help them protect personal data<\/strong> \u2013 making sure that information is used lawfully, fairly, and transparently.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Although you may think that this only applies to larger companies, in fact most businesses hold some personal data \u2013 for example customer contact details, or HR information about staff.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you do use or store personal information, and this information relates to someone that can be identified, you&#8217;re referred to in the Act as a \u2018data controller\u2019.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"whatdoesgdprstandforanddoesgdprstillapply\">What does GDPR stand for \u2013 and does GDPR still apply?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The European General Data Protection Regulation (GDPR) came into force in the UK in May 2018. However, since the UK left the European Union and the transition period ended on 31 December 2020, the GDPR has now been incorporated into the Data Protection Act 2018.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You may need to comply with both the UK GDPR and the EU GDPR if your business operates in Europe, or you offer goods or services to people in Europe.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<div id=\"nba-body-001\" class=\"wp-block-group is-layout-flow wp-block-group-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><\/p>\n<\/div>\n<\/div>\n<\/div>\n\n\n\n<div id=\"nba-body-001\">\n<\/div>\n\n\n\n<div class=\"wp-block-group alignfull is-layout-flow wp-block-group-is-layout-flow\" id=\"meaning\">\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading\" id=\"meaning\">What does the Data Protection Act mean for my business?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Data Protection Act 2018 and UK GDPR applies to any business established in the UK.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The main question to ask yourself is, how often does your business deal with <strong>personal data<\/strong>? This includes your customer data of course, but have you factored in supplier data? Past and present employees?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019re collecting any of this data routinely, you need to comply with the UK GDPR, whether the data is stored on a spreadsheet, your computer, mobile phone, or in the cloud. It applies for both manual data collection and automated digital capture.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Even as a small business you must follow the law and take responsibility for handling personal data. Beyond that, it can help you demonstrate to potential and existing customers that you\u2019re doing everything you can to protect their data from being lost, stolen, damaged,  misused, or shared \u2013 this level of trust is invaluable and could even help you bring in more business.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/www.simplybusiness.co.uk\/wp-content\/uploads\/sites\/3\/2024\/08\/AdobeStock_562456221_a4dd65-scaled.jpeg?w=1024\" alt=\"\" class=\"wp-image-25004\"\/><figcaption class=\"wp-element-caption\">Image credit: Supachai<\/figcaption><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<h3 class=\"wp-block-heading\" id=\"isyourdatasensitive\">Is your data \u2018sensitive\u2019?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The Data Protection Act 2018 offers stronger legal protection for more sensitive information, such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">race<\/li>\n\n\n\n<li class=\"wp-block-list-item\">ethnic background<\/li>\n\n\n\n<li class=\"wp-block-list-item\">political opinions<\/li>\n\n\n\n<li class=\"wp-block-list-item\">religious beliefs<\/li>\n\n\n\n<li class=\"wp-block-list-item\">trade union membership<\/li>\n\n\n\n<li class=\"wp-block-list-item\">genetics<\/li>\n\n\n\n<li class=\"wp-block-list-item\">biometrics<\/li>\n\n\n\n<li class=\"wp-block-list-item\">health<\/li>\n\n\n\n<li class=\"wp-block-list-item\">sex life or orientation<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Generally, you\u2019ll need explicit consent from individuals if you want to collect or process sensitive information.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group alignfull is-layout-flow wp-block-group-is-layout-flow\" id=\"employers\">\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading\" id=\"employers\">The Data Protection Act \u2013 employers&#8217; responsibilities<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As an employer, you&#8217;ll have a number of unique responsibilities. Firstly, workers have a legal right to access information that their employer may hold on them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Meanwhile, employers should also make sure that staff comply with data protection regulations in their day-to-day work, and have a duty to monitor the likes of telephone calls, emails, and CCTV where necessary.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Data controllers have a series of important responsibilities, and must follow the seven data protection principles.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group alignfull is-layout-flow wp-block-group-is-layout-flow\" id=\"key-principles\">\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading\" id=\"key-principles\">The Data Protection Act \u2013 7 key principles<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If your organisation deals with personal data, you must consistently act in accordance with the seven key principles set out in the DPA.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"1personaldatamustbeprocessedlawfullyfairlyandinatransparentmanner\">1. Personal data must be processed lawfully, fairly, and in a transparent manner<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This is among the most important requirements of the DPA. To comply, you must provide people with the name of your business, and details of how their information will be used. You should make it clear that the individual can access and correct the information that you hold about them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Crucially, you must also tell them if the information will be used in any way that\u2019s not immediately obvious. For example, you must tell the individual if their details will be passed on to credit reference agencies.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"2personaldatamustbeprocessedforspecifiedexplicitandlegitimatepurposes\">2. Personal data must be processed for specified, explicit, and legitimate purposes<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You must be clear why you\u2019re collecting someone\u2019s personal data and how you intend to use it. This clearly links to the lawfulness, fairness, and transparency principle mentioned above.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can\u2019t use the data collected for another, \u2018incompatible\u2019, or unlawful purpose. For example, if your purpose changes over time and this isn\u2019t \u2018compatible\u2019 with the original purpose, you\u2019ll need to get the individual\u2019s specific consent for the new purpose.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"3personaldatamustbeadequaterelevantandnotexcessive\">3. Personal data must be adequate, relevant, and not excessive<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You should only collect the bare minimum; you may not collect information that isn\u2019t immediately relevant to the specified purpose, and you may not collect more information than you need.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"4personaldatamustbeaccurateanduptodate\">4. Personal data must be accurate and up to date<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Any information you hold must be factually accurate, and updated where necessary. Depending on the nature of your business, you may need to develop mechanisms that allow people to update their details quickly.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"5personaldatashouldntbekeptanylongerthanisnecessary\">5. Personal data shouldn\u2019t be kept any longer than is necessary<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This storage limitation principle states that you shouldn\u2019t keep data any longer than needed. If you collected data for a purpose that\u2019s time-limited then you should make sure that the information isn\u2019t retained beyond that point. Reducing how long you hold data also helps you to reduce the risk of storing personal data that\u2019s inaccurate or out of date.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s good practice to tell people how long you intend to keep the data for and you might find it useful to set retention periods for your data.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"6personaldatamustbeprocessedsecurely\">6. Personal data must be processed securely<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You must take adequate steps to maintain the integrity and confidentiality of personal data. Having an information security policy in place can help demonstrate that you\u2019re looking after personal data and reducing the risk of it being compromised.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"7thecontrollerisresponsibleforgdprandmustdemonstratecompliance\">7. The controller is responsible for GDPR and must demonstrate compliance<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This final principle sets out the law when it comes to accountability. As a data controller, you\u2019re responsible for what you do with personal data and must demonstrate how you\u2019re looking after people\u2019s privacy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">More information on the <a href=\"https:\/\/ico.org.uk\/for-organisations\/guide-to-data-protection\/guide-to-the-general-data-protection-regulation-gdpr\/\" rel=\"noopener noreferrer\" target=\"_blank\">GDPR principles<\/a> can be found on the ICO website.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group alignfull is-layout-flow wp-block-group-is-layout-flow\" id=\"consent\">\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading\" id=\"consent\">How do I get consent from my customers to use their data?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Here are some key things to think about when it comes to collecting individual\u2019s data:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">check your consent practices and existing records \u2013 and refresh where necessary<\/li>\n\n\n\n<li class=\"wp-block-list-item\">offer people genuine choice and control<\/li>\n\n\n\n<li class=\"wp-block-list-item\">where using an opt-in, don\u2019t rely on pre-ticked boxes or default options<\/li>\n\n\n\n<li class=\"wp-block-list-item\">explicit consent means a very clear, specific statement of consent<\/li>\n\n\n\n<li class=\"wp-block-list-item\">keep your consent requests separate from other terms and conditions<\/li>\n\n\n\n<li class=\"wp-block-list-item\">be specific, granular, clear, and concise<\/li>\n\n\n\n<li class=\"wp-block-list-item\">name any third parties who will rely on the consent<\/li>\n\n\n\n<li class=\"wp-block-list-item\">make it easy for people to withdraw consent (and tell them how)<\/li>\n\n\n\n<li class=\"wp-block-list-item\">keep evidence of the consent (who, when, how, and what you\u2019ve told people)<\/li>\n\n\n\n<li class=\"wp-block-list-item\">avoid making consent a precondition of your business services<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Ultimately, consent should put individuals in control, build trust and engagement, and enhance your reputation.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group alignfull is-layout-flow wp-block-group-is-layout-flow\" id=\"register\">\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading\" id=\"register\">Do I need to register with the ICO?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As well as following the key principles above, you may also need to pay a data protection fee to the Information Commissioner&#8217;s Office (ICO). The DPA works on the basis that all data controllers notify the ICO, but there are some exemptions. If you\u2019re not exempt but you fail to notify the ICO, you risk prosecution.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You may be exempt if you <strong>only<\/strong> process personal data for one (or more) of the following purposes:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">staff administration<\/li>\n\n\n\n<li class=\"wp-block-list-item\">payroll<\/li>\n\n\n\n<li class=\"wp-block-list-item\">advertising, marketing and PR<\/li>\n\n\n\n<li class=\"wp-block-list-item\">not-for-profit purposes<\/li>\n\n\n\n<li class=\"wp-block-list-item\">personal, family, or household affairs<\/li>\n\n\n\n<li class=\"wp-block-list-item\">maintaining a public register<\/li>\n\n\n\n<li class=\"wp-block-list-item\">judicial functions<\/li>\n\n\n\n<li class=\"wp-block-list-item\">or if no automated system, like a computer, is used in the processing of data<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"registrationandthedataprotectionfee\">Registration and the data protection fee<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You can use the <a href=\"https:\/\/ico.org.uk\/for-organisations\/data-protection-fee\/self-assessment\/\" rel=\"noopener noreferrer\" target=\"_blank\">ICO&#8217;s online checker tool<\/a> to see if your business is exempt from registration. Even if you\u2019re exempt from paying a fee, you still need to comply with other data protection obligations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you do need to register, you\u2019ll need to <a href=\"https:\/\/ico.org.uk\/for-organisations\/data-protection-fee\/\" rel=\"noopener noreferrer\" target=\"_blank\">pay a data protection fee<\/a>. Registration generally costs between \u00a340 and \u00a360 a year.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you don\u2019t comply with the Data Protection Act, you could face serious penalties. The maximum fine under UK GDPR and the DPA is now \u00a317.5 million or four per cent of the total annual worldwide turnover in the preceding financial year, whichever is higher.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-group alignfull is-layout-flow wp-block-group-is-layout-flow\" id=\"checklist\">\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading\" id=\"checklist\">GDPR checklist \u2013 tips for small businesses<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1. Know your data<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Demonstrate an understanding of the types of personal data you\u2019re holding (such as name, address, email, bank details, photos, IP addresses) and sensitive data (for example health details or religious views), as well as where the data is coming from, where it\u2019s going and how it\u2019ll be used.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2. Identify when you\u2019re relying on consent<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019re relying on personal consent to process personal data (for example, as part of your marketing) then you need to be clear, specific, and explicit as to your purpose.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3. Review your security measures<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Make sure you have strong security measures and policies. Broad use of encryption, for example, could be a good way to reduce the risk of a security breach.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>4. Meet access requests<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Everyone has a right to access any personal data you may hold. The right of access under GDPR states that you must respond to a request within one month. This can only be extended in mitigating circumstances.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>5. Train your employees<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Staff should report a serious personal data breach within 72 hours. Make sure that everyone knows the process for reporting and who to report a breach to.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>6. Conduct due diligence on your supply chain<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Make sure your suppliers and contractors are compliant with UK GDPR to avoid being impacted by any breaches.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>7. Regularly review your privacy policies<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">People have a right to be informed of how you\u2019re using their personal data. This should be included in your privacy policies and information should be reviewed regularly to make sure it\u2019s up to date.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>8. Check if you need to employ a Data Protection Officer<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Most small businesses will be exempt. However, if your company\u2019s core activities involve \u2018regular or systematic\u2019 monitoring of data subjects on a large scale, or which involve processing large volumes of sensitive data, you must employ a Data protection Officer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For more information, check out these resources from the ICO:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/ico.org.uk\/for-organisations\/sme-web-hub\/\" rel=\"noopener noreferrer\" target=\"_blank\">small business web hub<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/ico.org.uk\/for-organisations\/sme-web-hub\/checklists\/assessment-for-small-business-owners-and-sole-traders\/\" rel=\"noopener noreferrer\" target=\"_blank\">data protection checklist<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/ico.org.uk\/for-organisations\/guide-to-pecr\/what-are-pecr\/\" rel=\"noopener noreferrer\" target=\"_blank\">Privacy and Electronic Communications Regulations<\/a><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019re not sure about anything, seek guidance from the Information Commissioner\u2019s Office (ICO), or from an independent legal professional.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"whattodoifyouretakentocourtoveragdprbreach\">What to do if you&#8217;re taken to court over a GDPR breach<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you have <a href=\"\/business-insurance\/business-legal-protection-insurance\/\">legal expenses insurance<\/a> as part of your Simply Business policy, you have access to a number of useful services through <a href=\"https:\/\/www.aragbusinesslaw.co.uk\/\" rel=\"noopener noreferrer\" target=\"_blank\">Arag Businesslaw<\/a> (you\u2019ll just need your voucher code found in your policy documents to register).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Arag has a legal advice helpline, available whether you\u2019re facing a serious legal issue or just want to check something with an adviser. They also offer a range of legal templates and guides, including a GDPR checklist and handbook, video guides to handling information requests and templates for GDPR privacy notices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Is there anything else you\u2019d like to know about data protection? Let us know in the comments.<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Useful guides for small businesses<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><a href=\"\/knowledge\/business-structure\/legal-obligations-of-a-business\/\" data-type=\"knowledge\" data-id=\"986\">Do you know about these four legal obligations of a business?<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"\/knowledge\/business-tax\/hmrc-scam-email\/\" data-type=\"knowledge\" data-id=\"1400\">Have you got an HMRC scam email, call or text? Here\u2019s how to check it\u2019s genuine<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"\/knowledge\/business-structure\/consumer-protection-act-summary-guide-for-small-businesses\/\" data-type=\"knowledge\" data-id=\"800\">Consumer Protection Act: summary guide for small businesses<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"\/business-insurance\/faq\/do-i-need-professional-indemnity-insurance\/\">Do I need professional indemnity insurance?<\/a><\/li>\n<\/ul>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<div id=\"nba-upsell-001\" class=\"wp-block-group has-azure-200-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-94e519ba wp-block-group-is-layout-constrained\" style=\"padding-top:var(--wp--preset--spacing--80);padding-right:var(--wp--preset--spacing--40);padding-bottom:var(--wp--preset--spacing--80);padding-left:var(--wp--preset--spacing--40)\">\n<h3 class=\"wp-block-heading has-text-align-center\" id=\"lookingforselfemployedinsurance\">Looking for self-employed insurance?<\/h3>\n\n\n\n<p class=\"has-text-align-center wp-block-paragraph\">With Simply Business you can build a single <a href=\"\/business-insurance\/self-employed-insurance\/\">self employed insurance<\/a> policy combining the covers that are relevant to you. Whether it&#8217;s <a href=\"\/business-insurance\/public-liability-insurance\/\">public liability insurance<\/a>, <a href=\"\/business-insurance\/professional-indemnity-insurance\/\">professional indemnity<\/a> or whatever else you need, we&#8217;ll run you a quick quote online, and let you decide if we&#8217;re a good fit.<\/p>\n\n\n\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-is-layout-a89b3969 wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/quote.simplybusiness.co.uk\/business\">Start your quote<\/a><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n\n\n\n<div id=\"nba-body-end\">\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Does GDPR still apply? The Data Protection Act 2018 controls how businesses process personal data. Check you\u2019re complying with the law.<\/p>\n","protected":false},"author":3,"featured_media":25000,"comment_status":"open","ping_status":"closed","template":"","meta":{"sb_hreflang":"","sb_hreflang_url":"","disable_breadcrumbs":false,"sb_breadcrumbs":[],"sb_reviewed_by":"","sb_review_date":"","sb_enable_content_gating":true,"footnotes":""},"categories":[336],"hidden-category":[],"coauthors":[50],"class_list":["post-1011","knowledge","type-knowledge","status-publish","has-post-thumbnail","hentry","category-business-structure"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.2 (Yoast SEO v27.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Data Protection Act | Guide for UK businesses<\/title>\n<meta name=\"description\" content=\"Does GDPR still apply? The Data Protection Act 2018 controls how businesses process personal data. Check you\u2019re complying with the law.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"7 key principles of the Data Protection Act\" \/>\n<meta property=\"og:description\" content=\"If you collect personal data, make sure your business is compliant with GDPR and the Data Protection Act.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/\" \/>\n<meta property=\"og:site_name\" content=\"Simply Business UK\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/simplybusiness\" \/>\n<meta property=\"article:modified_time\" content=\"2025-07-11T10:30:13+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.simplybusiness.co.uk\/wp-content\/uploads\/sites\/3\/2024\/06\/data-protection-act-principles-for-small-business.jpg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"A guide to the Data Protection Act and GDPR for small businesses\" \/>\n<meta name=\"twitter:site\" content=\"@simplybusiness\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"11 minutes\" \/>\n\t<meta name=\"twitter:label2\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data2\" content=\"Simply Business Editorial Team\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/\"},\"author\":{\"@type\":\"Person\",\"name\":\"Simply Business Editorial Team\",\"description\":\"\\n\"},\"headline\":\"A guide to the Data Protection Act and GDPR for small businesses\",\"datePublished\":\"2021-08-17T00:00:00+00:00\",\"dateModified\":\"2025-07-11T10:30:13+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/\"},\"wordCount\":2191,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.simplybusiness.co.uk\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.simplybusiness.co.uk\/wp-content\/uploads\/sites\/3\/2021\/08\/Manager-of-car-service-shop-working-on-a-computer-in-the-office-by-Drazen-scaled.jpeg\",\"articleSection\":[\"Business structure\"],\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/\",\"url\":\"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/\",\"name\":\"Data Protection Act | Guide for UK businesses\",\"isPartOf\":{\"@id\":\"https:\/\/www.simplybusiness.co.uk\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.simplybusiness.co.uk\/wp-content\/uploads\/sites\/3\/2021\/08\/Manager-of-car-service-shop-working-on-a-computer-in-the-office-by-Drazen-scaled.jpeg\",\"datePublished\":\"2021-08-17T00:00:00+00:00\",\"dateModified\":\"2025-07-11T10:30:13+00:00\",\"description\":\"Does GDPR still apply? The Data Protection Act 2018 controls how businesses process personal data. Check you\u2019re complying with the law.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/#primaryimage\",\"url\":\"https:\/\/www.simplybusiness.co.uk\/wp-content\/uploads\/sites\/3\/2021\/08\/Manager-of-car-service-shop-working-on-a-computer-in-the-office-by-Drazen-scaled.jpeg\",\"contentUrl\":\"https:\/\/www.simplybusiness.co.uk\/wp-content\/uploads\/sites\/3\/2021\/08\/Manager-of-car-service-shop-working-on-a-computer-in-the-office-by-Drazen-scaled.jpeg\",\"width\":1500,\"height\":1000,\"caption\":\"Image credit: Drazen\/stock.adobe.com\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.simplybusiness.co.uk\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Knowledge\",\"item\":\"https:\/\/www.simplybusiness.co.uk\/knowledge\/%category%\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"A guide to the Data Protection Act and GDPR for small businesses\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.simplybusiness.co.uk\/#website\",\"url\":\"https:\/\/www.simplybusiness.co.uk\/\",\"name\":\"Simply Business UK\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.simplybusiness.co.uk\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.simplybusiness.co.uk\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.simplybusiness.co.uk\/#\/schema\/person\/73ec77668d0ec554cd7df8942c664049\",\"name\":\"elliottstocks\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.simplybusiness.co.uk\/wp-content\/themes\/simply-business\/dist\/images\/default-author-avatar.webp9df6147f02078f0218660330fdfbacf3\",\"url\":\"https:\/\/www.simplybusiness.co.uk\/wp-content\/themes\/simply-business\/dist\/images\/default-author-avatar.webp\",\"contentUrl\":\"https:\/\/www.simplybusiness.co.uk\/wp-content\/themes\/simply-business\/dist\/images\/default-author-avatar.webp\",\"caption\":\"elliottstocks\"}},{\"@type\":\"PostalAddress\",\"@id\":\"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/#local-main-place-address\",\"streetAddress\":\"Hylo, 105 Bunhill Row\",\"addressLocality\":\"London\",\"postalCode\":\"EC1Y 8LZ\",\"addressCountry\":\"GB\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/#local-main-organization-logo\",\"url\":\"https:\/\/www.simplybusiness.co.uk\/wp-content\/uploads\/sites\/3\/2024\/05\/logo.png\",\"contentUrl\":\"https:\/\/www.simplybusiness.co.uk\/wp-content\/uploads\/sites\/3\/2024\/05\/logo.png\",\"width\":533,\"height\":187,\"caption\":\"Simply Business UK\"}]}<\/script>\n<meta name=\"geo.placename\" content=\"London\" \/>\n<meta name=\"geo.region\" content=\"United Kingdom (UK)\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Data Protection Act | Guide for UK businesses","description":"Does GDPR still apply? The Data Protection Act 2018 controls how businesses process personal data. Check you\u2019re complying with the law.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/","og_locale":"en_GB","og_type":"article","og_title":"7 key principles of the Data Protection Act","og_description":"If you collect personal data, make sure your business is compliant with GDPR and the Data Protection Act.","og_url":"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/","og_site_name":"Simply Business UK","article_publisher":"https:\/\/www.facebook.com\/simplybusiness","article_modified_time":"2025-07-11T10:30:13+00:00","og_image":[{"url":"https:\/\/www.simplybusiness.co.uk\/wp-content\/uploads\/sites\/3\/2024\/06\/data-protection-act-principles-for-small-business.jpg","type":"","width":"","height":""}],"twitter_card":"summary_large_image","twitter_title":"A guide to the Data Protection Act and GDPR for small businesses","twitter_site":"@simplybusiness","twitter_misc":{"Est. reading time":"11 minutes","Written by":"Simply Business Editorial Team"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/#article","isPartOf":{"@id":"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/"},"author":{"@type":"Person","name":"Simply Business Editorial Team","description":"\n"},"headline":"A guide to the Data Protection Act and GDPR for small businesses","datePublished":"2021-08-17T00:00:00+00:00","dateModified":"2025-07-11T10:30:13+00:00","mainEntityOfPage":{"@id":"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/"},"wordCount":2191,"commentCount":0,"publisher":{"@id":"https:\/\/www.simplybusiness.co.uk\/#organization"},"image":{"@id":"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/#primaryimage"},"thumbnailUrl":"https:\/\/www.simplybusiness.co.uk\/wp-content\/uploads\/sites\/3\/2021\/08\/Manager-of-car-service-shop-working-on-a-computer-in-the-office-by-Drazen-scaled.jpeg","articleSection":["Business structure"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/","url":"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/","name":"Data Protection Act | Guide for UK businesses","isPartOf":{"@id":"https:\/\/www.simplybusiness.co.uk\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/#primaryimage"},"image":{"@id":"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/#primaryimage"},"thumbnailUrl":"https:\/\/www.simplybusiness.co.uk\/wp-content\/uploads\/sites\/3\/2021\/08\/Manager-of-car-service-shop-working-on-a-computer-in-the-office-by-Drazen-scaled.jpeg","datePublished":"2021-08-17T00:00:00+00:00","dateModified":"2025-07-11T10:30:13+00:00","description":"Does GDPR still apply? The Data Protection Act 2018 controls how businesses process personal data. Check you\u2019re complying with the law.","breadcrumb":{"@id":"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/#primaryimage","url":"https:\/\/www.simplybusiness.co.uk\/wp-content\/uploads\/sites\/3\/2021\/08\/Manager-of-car-service-shop-working-on-a-computer-in-the-office-by-Drazen-scaled.jpeg","contentUrl":"https:\/\/www.simplybusiness.co.uk\/wp-content\/uploads\/sites\/3\/2021\/08\/Manager-of-car-service-shop-working-on-a-computer-in-the-office-by-Drazen-scaled.jpeg","width":1500,"height":1000,"caption":"Image credit: Drazen\/stock.adobe.com"},{"@type":"BreadcrumbList","@id":"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.simplybusiness.co.uk\/"},{"@type":"ListItem","position":2,"name":"Knowledge","item":"https:\/\/www.simplybusiness.co.uk\/knowledge\/%category%\/"},{"@type":"ListItem","position":3,"name":"A guide to the Data Protection Act and GDPR for small businesses"}]},{"@type":"WebSite","@id":"https:\/\/www.simplybusiness.co.uk\/#website","url":"https:\/\/www.simplybusiness.co.uk\/","name":"Simply Business UK","description":"","publisher":{"@id":"https:\/\/www.simplybusiness.co.uk\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.simplybusiness.co.uk\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Person","@id":"https:\/\/www.simplybusiness.co.uk\/#\/schema\/person\/73ec77668d0ec554cd7df8942c664049","name":"elliottstocks","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.simplybusiness.co.uk\/wp-content\/themes\/simply-business\/dist\/images\/default-author-avatar.webp9df6147f02078f0218660330fdfbacf3","url":"https:\/\/www.simplybusiness.co.uk\/wp-content\/themes\/simply-business\/dist\/images\/default-author-avatar.webp","contentUrl":"https:\/\/www.simplybusiness.co.uk\/wp-content\/themes\/simply-business\/dist\/images\/default-author-avatar.webp","caption":"elliottstocks"}},{"@type":"PostalAddress","@id":"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/#local-main-place-address","streetAddress":"Hylo, 105 Bunhill Row","addressLocality":"London","postalCode":"EC1Y 8LZ","addressCountry":"GB"},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/#local-main-organization-logo","url":"https:\/\/www.simplybusiness.co.uk\/wp-content\/uploads\/sites\/3\/2024\/05\/logo.png","contentUrl":"https:\/\/www.simplybusiness.co.uk\/wp-content\/uploads\/sites\/3\/2024\/05\/logo.png","width":533,"height":187,"caption":"Simply Business UK"}]},"geo.placename":"London","geo.region":"United Kingdom (UK)"},"parsely":{"version":"1.1.0","canonical_url":"https:\/\/simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/","smart_links":{"inbound":0,"outbound":0},"traffic_boost_suggestions_count":0,"meta":{"@context":"https:\/\/schema.org","@type":"NewsArticle","headline":"A guide to the Data Protection Act and GDPR for small businesses","url":"http:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/","mainEntityOfPage":{"@type":"WebPage","@id":"http:\/\/www.simplybusiness.co.uk\/knowledge\/business-structure\/data-protection-act-principles-for-small-business\/"},"thumbnailUrl":"https:\/\/www.simplybusiness.co.uk\/wp-content\/uploads\/sites\/3\/2021\/08\/Manager-of-car-service-shop-working-on-a-computer-in-the-office-by-Drazen-scaled.jpeg?w=150&h=150&crop=1","image":{"@type":"ImageObject","url":"https:\/\/www.simplybusiness.co.uk\/wp-content\/uploads\/sites\/3\/2021\/08\/Manager-of-car-service-shop-working-on-a-computer-in-the-office-by-Drazen-scaled.jpeg"},"articleSection":"Business structure","author":[{"@type":"Person","name":"Simply Business Editorial Team"}],"creator":["Simply Business Editorial Team"],"publisher":{"@type":"Organization","name":"Simply Business UK","logo":"https:\/\/www.simplybusiness.co.uk\/wp-content\/uploads\/sites\/3\/2024\/04\/icon-512x512-1.png"},"keywords":[],"dateCreated":"2021-08-17T00:00:00Z","datePublished":"2021-08-17T00:00:00Z","dateModified":"2025-07-11T10:30:13Z"},"rendered":"<script type=\"application\/ld+json\" class=\"wp-parsely-metadata\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@type\":\"NewsArticle\",\"headline\":\"A guide to the Data Protection Act and GDPR for small businesses\",\"url\":\"http:\\\/\\\/www.simplybusiness.co.uk\\\/knowledge\\\/business-structure\\\/data-protection-act-principles-for-small-business\\\/\",\"mainEntityOfPage\":{\"@type\":\"WebPage\",\"@id\":\"http:\\\/\\\/www.simplybusiness.co.uk\\\/knowledge\\\/business-structure\\\/data-protection-act-principles-for-small-business\\\/\"},\"thumbnailUrl\":\"https:\\\/\\\/www.simplybusiness.co.uk\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2021\\\/08\\\/Manager-of-car-service-shop-working-on-a-computer-in-the-office-by-Drazen-scaled.jpeg?w=150&h=150&crop=1\",\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.simplybusiness.co.uk\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2021\\\/08\\\/Manager-of-car-service-shop-working-on-a-computer-in-the-office-by-Drazen-scaled.jpeg\"},\"articleSection\":\"Business structure\",\"author\":[{\"@type\":\"Person\",\"name\":\"Simply Business Editorial Team\"}],\"creator\":[\"Simply Business Editorial Team\"],\"publisher\":{\"@type\":\"Organization\",\"name\":\"Simply Business UK\",\"logo\":\"https:\\\/\\\/www.simplybusiness.co.uk\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2024\\\/04\\\/icon-512x512-1.png\"},\"keywords\":[],\"dateCreated\":\"2021-08-17T00:00:00Z\",\"datePublished\":\"2021-08-17T00:00:00Z\",\"dateModified\":\"2025-07-11T10:30:13Z\"}<\/script>","tracker_url":"https:\/\/cdn.parsely.com\/keys\/simplybusiness.co.uk\/p.js"},"_links":{"self":[{"href":"https:\/\/www.simplybusiness.co.uk\/wp-json\/wp\/v2\/knowledge\/1011","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.simplybusiness.co.uk\/wp-json\/wp\/v2\/knowledge"}],"about":[{"href":"https:\/\/www.simplybusiness.co.uk\/wp-json\/wp\/v2\/types\/knowledge"}],"author":[{"embeddable":true,"href":"https:\/\/www.simplybusiness.co.uk\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.simplybusiness.co.uk\/wp-json\/wp\/v2\/comments?post=1011"}],"version-history":[{"count":9,"href":"https:\/\/www.simplybusiness.co.uk\/wp-json\/wp\/v2\/knowledge\/1011\/revisions"}],"predecessor-version":[{"id":39492,"href":"https:\/\/www.simplybusiness.co.uk\/wp-json\/wp\/v2\/knowledge\/1011\/revisions\/39492"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.simplybusiness.co.uk\/wp-json\/wp\/v2\/media\/25000"}],"wp:attachment":[{"href":"https:\/\/www.simplybusiness.co.uk\/wp-json\/wp\/v2\/media?parent=1011"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.simplybusiness.co.uk\/wp-json\/wp\/v2\/categories?post=1011"},{"taxonomy":"hidden-category","embeddable":true,"href":"https:\/\/www.simplybusiness.co.uk\/wp-json\/wp\/v2\/hidden-category?post=1011"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.simplybusiness.co.uk\/wp-json\/wp\/v2\/coauthors?post=1011"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}