Home › GDPR compliance

GDPR compliance

How we handle personal information, how to exercise your rights, and how we support customers with UK data protection requirements. Guidance updated: September 2026.

Not legal advice. This page explains our own practices and gives general information about UK data protection law. It is not a substitute for advice on your particular circumstances. Where it matters — and for anything involving health data, children's data, or large-scale profiling — take proper legal advice.

Your information and rights

We act as a controller for our own customer accounts, billing and business correspondence. When we host or maintain a customer's website and handle information on their instructions, we generally act as their processor.

Our privacy policy explains the personal information we collect, our purposes and lawful bases, who receives it and how long it is kept. Our cookie policy explains cookies and similar technologies. This page provides supporting guidance and does not replace those notices.

Depending on the circumstances, you can ask for access to your information, correction, erasure, restriction or portability, and object to certain processing. Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of earlier processing. These rights are subject to legal conditions and exemptions.

To exercise a right or make a data protection complaint, email [email protected]. Tell us what your request concerns; we may ask for proportionate information to confirm your identity. You can also contact the Information Commissioner's Office.

Security data we hold

We record the IP address used to create an account and to sign in, kept for 12 months. The lawful basis is legitimate interests (Article 6(1)(f)) — specifically preventing fraud and unauthorised access to customer accounts, which is expressly recognised as a legitimate interest in Recital 47. We show each person their own IP on the sign-in form so the processing is transparent rather than hidden.

Six-digit sign-up codes are held for 15 minutes and deleted on use.

Who is responsible for what

This distinction matters and is often misunderstood, so it is worth being precise.

Article 28 of the UK GDPR requires a written contract between a controller and a processor. Our terms of service include the required processor terms, so this is covered from the day you sign up rather than being something you have to chase.

What we do as your processor

What we build into your website

Compliance is easier when the site is built for it rather than patched afterwards.

The law as it stands

UK data protection is governed by three pieces of legislation working together:

All three were amended by the Data (Use and Access) Act 2025, which received Royal Assent on 19 June 2025. Its provisions were phased in: the majority came into force on 5 February 2026, with the data protection complaints provisions following on 19 June 2026. The DUAA amends this framework rather than replacing it — the UK GDPR still exists and still applies.

What changed under the DUAA, in plain terms

You must now have a complaints process

Since 19 June 2026, section 164A of the Data Protection Act 2018 gives people a statutory right to complain directly to an organisation about how it has handled their personal data. If you are a controller, you must provide an accessible way to make that complaint, acknowledge it within 30 days, and respond without undue delay. This is the change most likely to catch a small business out, because it requires something to actually exist rather than something to be written down.

Every website we build includes a route for this, and the wording for it goes in your privacy notice.

A new lawful basis: recognised legitimate interests

The DUAA adds a seventh lawful basis to Article 6(1) of the UK GDPR. Where processing falls within a defined list of "recognised legitimate interests", you no longer need to carry out the balancing test that ordinary legitimate interests require. This basis is limited to the purposes defined in law; it is not a general exemption for ordinary commercial activities. Other data protection requirements still apply.

Automated decision-making rules rewritten

Article 22 of the UK GDPR has been repealed and replaced by new Articles 22A to 22D. The rules permit a wider range of significant solely automated decisions, subject to safeguards and additional restrictions for special category information. If you operate in both jurisdictions, you cannot assume one set of rules covers you for both.

Subject access requests

The DUAA confirms that when you receive a subject access request you are required to carry out a reasonable and proportionate search, not an exhaustive one. The normal response deadline remains one calendar month, subject to the statutory rules on extensions and any permitted pauses. Requests can be made verbally or in writing; no special form is required.

Your own obligations

We can build the site correctly, but some things only you can do.

  1. Check whether you must pay the data protection fee. Organisations and sole traders processing personal information must pay unless an exemption applies. Use the ICO fee guidance and self-assessment to check your position and the current amount. Exemption from the fee does not remove your other data protection duties.
  2. Know what you hold and why. Article 30 requires records of processing activities, with a partial exemption for organisations under 250 staff that does not apply where processing is regular or involves special category data.
  3. Set retention periods and stick to them. "We keep everything forever" is a storage limitation breach under Article 5(1)(e).
  4. Answer subject access requests within one month, extendable by two further months for complex requests.
  5. Handle complaints under the section 164A process described above.
  6. Get marketing consent right. PECR regulation 22 governs electronic marketing. The "soft opt-in" for existing customers is narrower than most people assume.

What non-compliance costs

Under the UK GDPR the maximum penalty is £17.5 million or 4% of total worldwide annual turnover, whichever is higher. The DUAA raised PECR penalties to the same level, which is a substantial increase from the previous £500,000 cap — relevant to anyone doing email or text marketing.

In practice the ICO's approach to small businesses is proportionate, and it has confirmed it will assess conduct against the law and guidance as they stood at the time. The realistic risk for a small business is not a headline fine. It is a complaint from one annoyed customer that turns into correspondence you have to deal with, and a reputational problem you did not need.

Common questions

Does GDPR still apply after Brexit?

Yes. The UK GDPR is UK law and applies in full. If you have customers in the EU, the EU GDPR may apply to you as well — and the two are now diverging, so what satisfies one may not satisfy the other.

I'm a sole trader with a simple website. Does this really apply to me?

Yes. There is no small-business exemption. If you collect names, email addresses or phone numbers, you are processing personal data. The obligations are lighter at your scale, but they exist.

Do I need a data protection officer?

Almost certainly not. Article 37 requires one only for public authorities, or where core activities involve large-scale regular monitoring or large-scale special category data. A small business website does not meet that threshold.

Can I email past customers about a new service?

Possibly, under the soft opt-in in PECR regulation 22, if you obtained their details during a sale of a similar product or service and gave them an easy way to opt out then and every time since. If in doubt, ask for consent.

What happens if my site is hacked?

Where we act as your processor, we notify you of a personal data breach without undue delay and help you assess it. You then have 72 hours from becoming aware to notify the ICO if the breach is likely to result in a risk to people's rights and freedoms, and you must tell affected individuals if the risk is high. Our monitoring and off-server backups exist so that this is a recoverable incident rather than a catastrophe.

Where to check for yourself

We would rather you verified this than took our word for it.

Our own compliance. Splash Nodes is a trading name of Alan Alaei, a sole trader, of 32 Blenheim View, Leeds, West Yorkshire, LS2 9QB, registered with the ICO as a data controller. Our privacy policy sets out what we collect and why, our cookie policy covers what we store in your browser, and our terms and conditions contain the Article 28 processor terms that govern our handling of your customers' data. To make a data protection complaint or a subject access request, email [email protected], or use the Data Subject Access Request page for the fastest route. We acknowledge data protection complaints within 30 days, investigate them and communicate the outcome without undue delay. Subject access requests are different: we respond without undue delay and normally within one calendar month. Where the law permits an extension, we explain the reason and the revised deadline within the initial month. You do not have to use our online form to exercise your rights. You can also raise concerns with the ICO.

Not sure where you stand?

Contact us about your information, a data protection concern or the privacy features of your website.

Contact us