GDPR Compliance for Small Businesses: A Practical Checklist
Why GDPR Matters for Your CRM
If your small business uses a CRM system to store customer names, email addresses, phone numbers, or purchase history, you are processing personal data — and that means GDPR applies to you. The UK retained GDPR after Brexit as UK GDPR, enforced by the Information Commissioner's Office (ICO), so the obligations are very much live and legally binding.
Fines for non-compliance can reach £17.5 million or 4% of annual global turnover. For a small business, even a modest ICO enforcement action can be devastating to your reputation and finances.
Step 1 — Audit What Data Your CRM Holds
Start by listing every type of personal data your CRM collects. This includes names, contact details, appointment history, payment records, and marketing preferences. Tools like HubSpot CRM (free tier available) and Jobber (from £49/mo) both allow you to export data records, making an audit far more straightforward.
Ask yourself: do you actually need all the data you are storing? The principle of data minimisation means you should only collect what is strictly necessary for your stated business purpose.
Step 2 — Establish a Lawful Basis for Processing
Under UK GDPR, you must have a valid lawful basis for processing each category of data. The most common bases for small businesses are consent, legitimate interests, and contractual necessity. For example, storing a client's booking history in Fresha or Treatwell Connect (£25/mo) to fulfil an appointment is typically justified under contractual necessity.
If you rely on consent — particularly for email marketing — that consent must be freely given, specific, and easy to withdraw. Pre-ticked boxes do not count as valid consent under UK law.
Step 3 — Review Your CRM Software's Data Practices
Your CRM provider is classed as a data processor, and you are the data controller. You must ensure a Data Processing Agreement (DPA) is in place with your software provider. Reputable platforms like HubSpot, Commusoft (£119/mo), and Mindbody (£129/mo) all provide DPAs within their terms of service, but you should confirm this is signed and accessible.
Also check where your data is stored. Since Brexit, transfers of personal data to countries outside the UK require additional safeguards. Many platforms store data on US-based servers, so verify that adequate protections — such as Standard Contractual Clauses (SCCs) — are in place.
Step 4 — Build Your Practical Compliance Checklist
Use the following checklist to work through your key obligations. This applies whether you use a dedicated CRM like Jobber for field services, Tidio AI for customer communications, or a booking platform like Fresha or Mindbody.
- Publish a clear, plain-English Privacy Notice on your website and booking pages
- Record your lawful basis for each type of data processing in a Register of Processing Activities
- Ensure all Data Processing Agreements are signed with CRM and software providers
- Set up a process to handle Subject Access Requests (SARs) within 30 days
- Enable a straightforward opt-out mechanism for marketing communications
- Configure data retention policies — do not keep records indefinitely
- Restrict access to personal data on a need-to-know basis within your team
- Enable two-factor authentication on your CRM accounts to prevent breaches
- Know your breach notification obligation — reportable breaches must be flagged to the ICO within 72 hours
Step 5 — Keep Consent Records and Manage Opt-Outs
If you send marketing emails or SMS reminders via your CRM — as many businesses do using platforms like Treatwell Connect or Tidio AI — you must maintain clear records of when and how consent was obtained. Automated reminder systems are convenient, but they must only contact clients who have actively agreed to receive communications.
Review your unsubscribe process regularly. If a customer opts out and then receives a marketing message, that is a breach of both UK GDPR and PECR (Privacy and Electronic Communications Regulations).
Staying Compliant Long-Term
GDPR compliance is not a one-off task — it requires ongoing attention. Schedule a quarterly review of your CRM data, update your Privacy Notice whenever your practices change, and train any new staff on data handling basics. The ICO's website offers free guidance specifically aimed at small businesses and is an excellent starting point.
Choosing CRM software that is built with privacy controls in mind — including role-based access, data export tools, and clear DPAs — makes compliance considerably easier to maintain day to day. Get the foundations right, and protecting your customers' data becomes a natural part of how your business operates.