GDPR is the law governing how organisations collect, store and use personal data. Despite a widespread belief that it stopped applying after Brexit, it did not: the EU GDPR was retained in domestic law as the UK GDPR, and works alongside the Data Protection Act 2018. If you handle information about living people — customers, staff, patients, pupils, suppliers — it applies to you. It applies to sole traders and volunteers-run charities just as it applies to corporations. There is no small-business exemption.
At a glance: Nexis CPD offers a £9 CPD-accredited online Data Protection and GDPR Awareness course, 100% online with a verifiable e-certificate on passing.

What counts as personal data?
Personal data is any information relating to an identified or identifiable living person. That is broader than most people expect. It includes names and addresses, but also IP addresses, staff ID numbers, CCTV footage, call recordings, vehicle registrations and opinions expressed about someone.
A separate, tighter category — special category data — covers information about racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetics, biometrics used for identification, health, sex life and sexual orientation. You need both a lawful basis and an additional condition to process it. Criminal offence data is handled under its own separate rules.
Health and social care employers process special category data constantly, which is why data protection sits close to duty of care in those sectors.
What are the seven principles?
Article 5 of the UK GDPR sets out the principles that everything else hangs from:
- Lawfulness, fairness and transparency — you need a lawful reason, and people must know what you are doing
- Purpose limitation — collected for specified purposes, not reused for unrelated ones
- Data minimisation — adequate, relevant and limited to what is necessary
- Accuracy — kept accurate and up to date; inaccuracies corrected without delay
- Storage limitation — kept no longer than necessary
- Integrity and confidentiality — appropriate security against unauthorised access, loss or damage
- Accountability — you must be able to demonstrate compliance, not merely assert it
Accountability is the one that catches organisations out. Doing the right thing is not enough; you have to be able to evidence it. Records of processing, policies, training logs and documented decisions are what turn a defensible position into a provable one.
Is consent always needed?
No — and treating consent as the default is one of the most expensive misconceptions in UK data protection.
Consent is one of six lawful bases under Article 6, and it is often the weakest, because it must be freely given, specific, informed and unambiguous, and it can be withdrawn at any time. The six are:
- Consent
- Contract — necessary to perform a contract with the person
- Legal obligation — required by law
- Vital interests — to protect someone’s life
- Public task — for an official function or task in the public interest
- Legitimate interests — necessary for your interests, balanced against the person’s rights
An employer paying staff relies on contract and legal obligation, not consent. Asking for consent you do not need is worse than useless: it implies people can refuse, and when they do, you have to stop.

What rights do people have over their data?
The UK GDPR gives individuals eight rights: to be informed; of access; to rectification; to erasure; to restrict processing; to data portability; to object; and rights relating to automated decision-making and profiling.
The one organisations meet most often is the subject access request. Anyone can ask for a copy of their personal data, usually free of charge, and you must respond within one month. That can be extended by up to two further months for complex or numerous requests, but only if you tell the person within the first month. A request does not have to mention the GDPR, be in writing, or go to a particular person to be valid — an email to any staff member counts, which is why front-line training matters more than a policy document.
The right to erasure — “the right to be forgotten” — is not absolute. It does not apply where you must keep the data to meet a legal obligation.
What do you do about a data breach?
A personal data breach is not only hacking. It includes losing a laptop or paper file, sending an email to the wrong recipient, putting addresses in the “To” field instead of “Bcc”, and improper disposal of records. Accidental breaches are the majority.
If a breach is likely to result in a risk to people’s rights and freedoms, you must report it to the Information Commissioner’s Office without undue delay and within 72 hours of becoming aware of it. Report on time with incomplete information rather than late with the full picture — the ICO expects follow-up detail.
Where the risk is high, you must also tell the affected individuals directly, without undue delay. And you must record every breach internally, including those you decide not to report, along with your reasoning.
What are the penalties?
The Data Protection Act 2018 sets two tiers. The standard maximum is £8.7 million or 2% of total annual worldwide turnover, whichever is higher. The higher maximum — for breaches of the principles, the lawful bases or individuals’ rights — is £17.5 million or 4% of total annual worldwide turnover, whichever is higher.
In practice the ICO issues far more reprimands and enforcement notices than fines, and takes cooperation and remediation into account. Most organisations should worry less about the headline figure and more about the everyday obligations: registering with the ICO and paying the data protection fee unless exempt, keeping records, and training staff.
Frequently asked questions
Does GDPR still apply in the UK after Brexit?
Yes. The EU GDPR was retained in domestic law as the UK GDPR and works alongside the Data Protection Act 2018. The obligations on UK organisations are substantially the same. Organisations offering goods or services to people in the EU, or monitoring their behaviour, may also still need to comply with the EU GDPR separately.
Do you always need consent to process personal data?
No. Consent is only one of six lawful bases under Article 6, alongside contract, legal obligation, vital interests, public task and legitimate interests. It is often the weakest option because it must be freely given and can be withdrawn at any time. An employer paying its staff relies on contract and legal obligation, not consent. Asking for consent you do not need implies people can refuse.
How long do you have to respond to a subject access request?
One month from receipt. This can be extended by up to two further months where the request is complex or where you have received a number of requests from the same person, but you must tell the individual about the extension within the first month. A request is valid even if it does not mention data protection, is made verbally, or is sent to any member of staff.
When must a data breach be reported to the ICO?
Where the breach is likely to result in a risk to people's rights and freedoms, it must be reported without undue delay and within 72 hours of becoming aware of it. If the risk is high, affected individuals must also be told directly without undue delay. All breaches must be recorded internally, including those you decide not to report, together with the reasoning for that decision.
What are the maximum fines under UK GDPR?
The Data Protection Act 2018 sets two tiers. The standard maximum is £8.7 million or 2% of total annual worldwide turnover, whichever is higher. The higher maximum, which applies to breaches of the data protection principles, the lawful bases or individuals' rights, is £17.5 million or 4% of total annual worldwide turnover, whichever is higher. In practice the ICO issues far more reprimands and enforcement notices than fines.
Data protection and GDPR training
Our Data Protection and GDPR Awareness course covers the principles, lawful bases, individual rights, subject access requests and breach handling for staff at any level. It sits naturally alongside AML awareness and workplace conduct training in a compliance induction.
£9 per course. CPD accredited, 100% online, verifiable e-certificate. Pay for 2, get 3 — any 3 courses for £18.
This article is general information, not legal advice. A CPD awareness course is not a regulated qualification and does not make anyone a qualified Data Protection Officer. Where the UK GDPR requires a DPO, or where processing is high-risk, take specialist advice. Always follow your organisation’s data protection policy and refer to the ICO for authoritative guidance.
