Understanding Data Protection Duties for Small Practices

Understanding Data Protection Duties for Small Practices

Why This Matters More Than You Might Think

If you run a small practice — whether you are an accountant, a solicitor, a therapist, an architect or a consultant — you probably hold more personal information than you realise. Client files, contact details, notes from meetings, invoices, employee records, enquiries that never turned into work. All of it is covered by UK data protection law, and the rules apply to a two-person practice just as much as they do to a large firm.

The good news is that compliance is mostly about common sense written down. You do not need a legal team or an expensive consultant. You need to know what you hold, keep it safe, answer people honestly when they ask about their information, and review things now and then. The Information Commissioner's Office (ICO) is the regulator, and it is generally far more interested in practices that have made a genuine effort than in those that have done nothing at all.

Know What You Hold and Why

You cannot protect information you have not thought about. Start with a simple exercise: list every place personal data lives in your practice.

  • Client records — paper files, case management software, spreadsheets, email folders.
  • Enquiries and marketing — website contact forms, mailing lists, notes from initial calls.
  • Financial records — invoices, bank details, payment records.
  • Staff information — contracts, payroll, sickness records, appraisals.
  • Devices — laptops, phones, tablets, backup drives, and any cloud services you use.

For each item, ask two questions: why do we have it and how long do we need it. Every piece of information needs a reason — usually because you have a contract with the client, a legal obligation, or a legitimate interest in running your business. And every category needs a sensible retention period. Tax and accounting records typically need to be kept for at least six years; client files often follow a similar pattern, but it depends on your sector and any professional body rules. Once the period is up, delete or securely destroy the information. Keeping old files "just in case" is one of the most common and easily avoided risks.

Storing Information Securely in Practice

Security does not have to mean enterprise software. It means removing the obvious ways information goes astray.

  • Turn on encryption for laptops and phones, and use a password manager rather than reused passwords.
  • Use two-factor authentication on email, cloud storage and any client portal.
  • Lock paper files away when the office is empty, and use a shredder rather than a bin.
  • Be careful with email. Send sensitive documents via a secure link or encrypted attachment rather than a plain message, and double-check recipients before hitting send.
  • Check your suppliers. If a cloud provider stores client data for you, you need a written agreement covering how they handle it, and you should know where the data is held.
  • Back up regularly and test that you can actually restore from that backup.

Remote working deserves a mention. If you or your team work from home, client information should sit on encrypted, password-protected devices, not on a shared family laptop or a personal email account.

Handling Requests from Clients

People have the right to ask what information you hold about them, and to receive a copy. This is known as a subject access request, and it can arrive in any form — a letter, an email, even a verbal request. You cannot insist on a particular form or charge a fee except in narrow circumstances.

In most cases you must respond within one month of receiving the request, and you can extend that by up to two further months if the request is genuinely complex. Before responding, satisfy yourself that the person is who they say they are — ask for identification if you are unsure, but do not use that as an excuse to stall. Provide the information in a clear, commonly used format. Remember that some material may be exempt or may include information about other people, which usually needs to be redacted.

Other rights work in a similar way. People can ask you to correct inaccurate information, delete data you no longer need, or stop using it for marketing. Have a simple internal note of who handles these requests and where the clock starts.

Policies, Notices and Keeping Things Current

You do not need a shelf of documents, but you do need a few basics. A privacy notice on your website and in your client engagement materials should explain what you collect, why, how long you keep it, and who to contact with questions. A short retention schedule tells everyone how long different types of records are kept. A simple security policy covering passwords, devices, remote working and reporting incidents keeps everyone on the same page.

Review these once a year, or whenever something significant changes — new software, a new service line, a new member of staff. Note the date of each review so you can show you are keeping on top of it. If you use a professional body, check whether it publishes template policies you can adapt.

When Something Goes Wrong

Mistakes happen: an email to the wrong address, a lost laptop, a misdirected letter. If a breach is likely to result in a risk to people's rights and freedoms, you must report it to the ICO within 72 hours of becoming aware of it. If the risk is high, you also need to tell the individuals affected.

Keep a short record of every incident, even minor ones, noting what happened, what you did and what you changed as a result. A calm, documented response is worth far more than a perfect record. And if you are ever unsure, the ICO's helpline and guidance pages are there precisely for small practices like yours.

3 comments