If your business keeps customer names, phone numbers and emails in a CRM, UK GDPR applies to you. That is not a reason to panic. For most small businesses, being compliant comes down to a handful of sensible habits and choosing tools that make those habits easy. This checklist covers the basics. It is general guidance, not legal advice, so speak to a qualified adviser about your own situation.
Check where your CRM provider hosts your data. Data stored in the UK keeps things simple. If data is stored or processed outside the UK, the provider should explain the safeguards they use. You should be able to find this on their website, usually on a trust or security page.
When a software company stores customer data for you, they are acting as your data processor. UK GDPR expects a written agreement between you, often called a DPA. A good provider will have a standard one ready to send.
Most CRMs rely on other services for things like email delivery, text messages and payments. These are called subprocessors. The provider should publish a list, say what each one does, and tell you before adding new ones.
Collect the details you actually use, and no more. If you never post anything to customers, you probably do not need their date of birth. Less data means less risk and less to manage.
Every marketing email should carry a clear, working unsubscribe link, and people who unsubscribe should stop getting marketing straight away. Keep marketing and service messages separate, so someone who unsubscribes from offers still gets their booking confirmations.
If an email bounces or someone marks it as spam, keep sending and you damage your reputation with email providers. Your CRM should stop further emails to that address on its own.
People can ask to see the data you hold about them, or ask you to delete it. You normally have one month to respond. Check that your CRM can export a customer's record and delete it properly when asked.
Not everyone in your team needs access to everything. Use roles so staff see what they need for their job. Switch on two-step login for anyone with admin access.
If there is a data breach that risks people's rights, you may need to report it to the ICO within 72 hours. Your provider should commit to telling you quickly if a breach affects your records.
Good GDPR practice is mostly about using a well-built system and a few steady habits. If you want to see how we handle these points, read our trust centre, which lists where data lives, our subprocessors and our monthly security updates.
UK hosted, one-click unsubscribes and encrypted backups as standard.
Start free trial →