← Back to Blog
Checklist

A GDPR checklist for your CRM: what UK small businesses should check

7 min read

If your business keeps customer names, phone numbers and emails in a CRM, UK GDPR applies to you. That is not a reason to panic. For most small businesses, being compliant comes down to a handful of sensible habits and choosing tools that make those habits easy. This checklist covers the basics. It is general guidance, not legal advice, so speak to a qualified adviser about your own situation.

1. Know where your data is stored

Check where your CRM provider hosts your data. Data stored in the UK keeps things simple. If data is stored or processed outside the UK, the provider should explain the safeguards they use. You should be able to find this on their website, usually on a trust or security page.

2. Have a data processing agreement

When a software company stores customer data for you, they are acting as your data processor. UK GDPR expects a written agreement between you, often called a DPA. A good provider will have a standard one ready to send.

3. Check who the provider shares data with

Most CRMs rely on other services for things like email delivery, text messages and payments. These are called subprocessors. The provider should publish a list, say what each one does, and tell you before adding new ones.

4. Keep only what you need

Collect the details you actually use, and no more. If you never post anything to customers, you probably do not need their date of birth. Less data means less risk and less to manage.

5. Make unsubscribing easy

Every marketing email should carry a clear, working unsubscribe link, and people who unsubscribe should stop getting marketing straight away. Keep marketing and service messages separate, so someone who unsubscribes from offers still gets their booking confirmations.

6. Handle bounces and complaints automatically

If an email bounces or someone marks it as spam, keep sending and you damage your reputation with email providers. Your CRM should stop further emails to that address on its own.

7. Be ready for access and deletion requests

People can ask to see the data you hold about them, or ask you to delete it. You normally have one month to respond. Check that your CRM can export a customer's record and delete it properly when asked.

8. Control who can see what

Not everyone in your team needs access to everything. Use roles so staff see what they need for their job. Switch on two-step login for anyone with admin access.

9. Check the security basics

10. Know what to do if something goes wrong

If there is a data breach that risks people's rights, you may need to report it to the ICO within 72 hours. Your provider should commit to telling you quickly if a breach affects your records.

Keep it simple

Good GDPR practice is mostly about using a well-built system and a few steady habits. If you want to see how we handle these points, read our trust centre, which lists where data lives, our subprocessors and our monthly security updates.

A CRM built with UK GDPR in mind.

UK hosted, one-click unsubscribes and encrypted backups as standard.

Start free trial →