Data protection: the basics every business needs
Organisations tend to treat data protection as a documentation exercise: find the right policy, publish it, file it away and consider the matter settled. The documents are the least demanding part of it. The exposure sits in the ordinary running of the business, in places nobody has ever designated as a system.
United Kingdom data protection law applies to personal data, meaning information about identifiable living people, and that category is wider than businesses tend to picture when they think of their database. It covers staff, applicants who were never hired, the person who filled in a form and bought nothing, the individual named in a supplier's email signature, the visitor recorded by a camera at the entrance. Personal data accumulates as a by-product of trading rather than as the result of a decision, which is why an accurate picture of it is so seldom available inside the organisation holding it.
The second difficulty is that nobody owns it. Marketing holds lists. Finance holds payment records. Human resources holds material considerably more sensitive than anything in the customer database. Support holds a shared inbox in which customers set out their circumstances in detail, because they are trying to get a problem fixed. None of those functions thinks of itself as running a data operation, and responsibility is commonly given to whoever was least able to decline it. The name on the privacy notice frequently belongs to the person with the least visibility of where anything is actually kept.
The estate is larger than the systems list
Ask a business where personal data lives and the answer is the systems it pays for: the customer platform, the accounting package, the email tool. The answer is accurate, and it is a fraction of the picture.
What is missing tends to be everything that was created for convenience. Exports pulled for a board pack and left in a shared folder. Attachments sitting in individual inboxes. A laptop belonging to somebody who has since left, and the account that was never closed. Backups nobody has considered since the day they were configured. A chat channel where a complaint is discussed by name, because that was the quickest way to get it resolved.
Then there are the tools that arrived without a decision being taken. A scheduling app. A transcription service somebody began using for client calls. An analytics script added to the website by an agency. A survey tool bought on a personal card and reclaimed on expenses. Each becomes part of the data estate at the moment the first record enters it. The estate grows fastest during the periods when the business itself is growing fastest, which is precisely when nobody has the appetite to stop and write any of it down.
Handing data to a supplier does not hand over the responsibility
Where an organisation engages another business to handle personal data on its behalf, the choice of that supplier, and the written arrangements with them, remain the organisation's own obligation. The comfortable assumption is that using a large and well known provider disposes of the question. It disposes of part of it, and leaves the part concerning what your business asked that provider to do, and what it allowed to be done with the records afterwards.
Where the data physically sits is a related question with a definite answer, and the answer is very often unknown at the point a tool is adopted. Cloud services mean personal data can leave the United Kingdom without anyone having consciously decided that it should, and transfers out of the United Kingdom carry requirements of their own.
The commercial reality is that all the leverage over a supplier's data terms exists before adoption. Once workflows are built around a tool, the team depends on it and the appetite to migrate over a contractual point has gone. The question is cheap to ask while a business is still choosing, and close to unanswerable once it has chosen.
Marketing runs on rules of its own
The rules governing electronic marketing messages sit alongside general data protection rather than inside it, and the two do not always produce the same answer. A justification that comfortably supports the rest of an organisation's processing will not necessarily support sending marketing to the same people, and this is one of the more common places where a business reasons its way to a conclusion the law does not reach.
Provenance is the recurring weakness. Lists acquired along with a business, compiled from an event, gathered under an older form of wording, or bought from a supplier who gave assurances nobody kept, all carry their history with them. Where a list came from becomes an important question years after the person who could have answered it has left.
Marketing is also where complaints tend to surface first, for the plain reason that the recipient can see it. Much of what an organisation holds is invisible to the people it concerns. An unwanted message is visible to them, and it arrives carrying a reply address.
Requests rarely arrive from the merely curious
Individuals have a right to be told what personal data an organisation holds about them and to receive a copy of it. In practice the request seldom comes from a customer with an academic interest. It arrives with a grievance, or shortly after a dismissal, or from a counterparty in a commercial dispute, or from somebody who has already taken advice. The right exists for its own purposes and is used for others, and there is nothing improper in that.
Two things follow. The window for responding is fixed and short, and it is short relative to the work of locating material spread across everything described above. And the material falling within scope is not confined to the tidy record in the customer system. It can extend to what colleagues wrote about that person in the course of ordinary business, at a time when it did not occur to any of them that the subject would one day read it.
Deciding what is within scope, what may properly be withheld, and what has to be obscured because it concerns somebody else as well, is a set of judgements made at speed and under pressure. Organisations that have never handled such a request tend to underestimate every part of it.
Keeping everything is a decision, even when nobody takes it
The instinct is to retain, because storage costs little and deletion feels irreversible. United Kingdom data protection law expects personal data to be kept no longer than the purpose requires, and the practical case for holding on to something outweighs that expectation only when somebody has actually examined it, which is uncommon.
Every record retained beyond its purpose is a record that can be requested, disclosed in litigation, exposed in an incident, and searched at your own cost when any of those things happen. A smaller estate is quicker to answer for and less damaging when something goes wrong, which makes retention the discipline that quietly reduces the price of everything else.
The characteristic failure is the retired system. A business migrates to a new platform, keeps the old one available for reference, and then keeps it indefinitely because nobody wishes to be the person who authorises switching it off. It stops being maintained, stops appearing in access reviews, and remains full of personal data about customers and former staff. It becomes the least governed part of the estate, and a natural place for a problem to begin.
What is not worth doing
Money is regularly spent on data protection in ways that improve nothing, and being candid about that matters more than the rest of this page. Policy packs are the clearest example. A document describing an organisation that does not resemble yours is worse than holding nothing at all, because it is a written record of what you said you do, and it is among the first things produced when a regulator or a claimant begins asking questions. The distance between the policy and the practice then becomes the point at issue.
Certification schemes, appointing officers where the law does not require one, and commissioning an external mapping exercise are usually wasted on a small business running a single system and a mailing list. So is a consultancy engagement producing a folder nobody in the business will open again.
What is worth doing costs almost nothing and rarely gets done: knowing which tools hold data about customers and staff, closing the accounts of people who have left, and deleting what no longer serves a purpose. For a straightforward business, that is most of the distance covered.
Advice becomes worth buying at identifiable points. When the business handles data about health, finances or children. When it processes on behalf of other businesses as well as itself. When a customer's procurement team, an insurer or an investor starts asking questions in writing. When a request or a complaint has already arrived, and the answer given will stand as the record of how the organisation behaved. Before those points, restraint is usually the better use of the budget.
Letting the response to an individual's request be assembled by the manager the request is really about. They know the file better than anyone, which is why the task lands with them, and they also have the strongest interest in what stays out of it. Whatever is omitted tends to be found later, and an incomplete response becomes a second and separate problem sitting on top of the first.
This guide is general information about how these matters usually run. It is not advice, and nothing becomes advice until terms are agreed in writing. Brandleys Legal Ltd delivers reserved legal activities alongside regulated partners.