Home › GDPR compliance
GDPR compliance
How we handle personal information, how to exercise your rights, and how we support customers with UK data protection requirements. Guidance updated: September 2026.
Not legal advice. This page explains our own practices and gives general information about UK data protection law. It is not a substitute for advice on your particular circumstances. Where it matters — and for anything involving health data, children's data, or large-scale profiling — take proper legal advice.
Your information and rights
We act as a controller for our own customer accounts, billing and business correspondence. When we host or maintain a customer's website and handle information on their instructions, we generally act as their processor.
Our privacy policy explains the personal information we collect, our purposes and lawful bases, who receives it and how long it is kept. Our cookie policy explains cookies and similar technologies. This page provides supporting guidance and does not replace those notices.
Depending on the circumstances, you can ask for access to your information, correction, erasure, restriction or portability, and object to certain processing. Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of earlier processing. These rights are subject to legal conditions and exemptions.
To exercise a right or make a data protection complaint, email [email protected]. Tell us what your request concerns; we may ask for proportionate information to confirm your identity. You can also contact the Information Commissioner's Office.
Security data we hold
We record the IP address used to create an account and to sign in, kept for 12 months. The lawful basis is legitimate interests (Article 6(1)(f)) — specifically preventing fraud and unauthorised access to customer accounts, which is expressly recognised as a legitimate interest in Recital 47. We show each person their own IP on the sign-in form so the processing is transparent rather than hidden.
Six-digit sign-up codes are held for 15 minutes and deleted on use.
Who is responsible for what
This distinction matters and is often misunderstood, so it is worth being precise.
- You are the data controller for the personal information collected through your website — enquiries, bookings, customer records. You decide why it is collected and what happens to it.
- We are a data processor acting on your instructions when we host your site, store your enquiries and maintain your systems.
- We are a controller in our own right for our own business records — your account with us, our invoices, our correspondence with you.
Article 28 of the UK GDPR requires a written contract between a controller and a processor. Our terms of service include the required processor terms, so this is covered from the day you sign up rather than being something you have to chase.
What we do as your processor
- We process only on your instructions. We do not use your customers' data for our own purposes, and we never sell it.
- Security appropriate to the risk, as Article 32 requires: encrypted connections, access controls, patched servers, and backups held separately from the machine they came from.
- Breach notification. If something happens that affects your data, we tell you without undue delay so you can meet your own obligation under Article 33 to notify the ICO within 72 hours where the breach is likely to pose a risk.
- Hosting and international transfers. Hosting arrangements and authorised sub-processors are set out in the applicable service information and contract. International-transfer checks must cover overseas access as well as storage locations. Where a restricted transfer occurs, an applicable adequacy regulation, appropriate safeguards or a permitted exception is needed. Hosting in the UK or EEA alone does not settle every transfer question.
- Sub-processors named. We tell you which third parties we use and give you notice before that changes.
- Deletion or return on request. At the end of the service, we delete or return personal data at your choice in accordance with the processor contract, unless applicable law requires retention. The contract should explain backup deletion timescales.
What we build into your website
Compliance is easier when the site is built for it rather than patched afterwards.
- A cookie banner that actually works. Cookies and similar storage or access technologies require consent before use unless a PECR exception applies. Following the DUAA, certain statistical and functionality uses may qualify for exceptions, but only where all relevant conditions are met. Where consent is required, the technology must remain off until you agree.
- Analytics that can be cookieless. We assess analytics by what the technology actually does, not simply whether it is labelled “cookieless”. Accessing or storing information on a device can engage PECR without cookies; processing personal information also requires compliance with UK GDPR. Any applicable exception and its conditions must be checked before deployment.
- Forms that collect only what you need. Data minimisation under Article 5(1)(c) is a legal principle, not a preference. Every extra field is another thing to justify, secure and eventually delete.
- A clear privacy notice meeting the Articles 13 and 14 requirements, linked from every page.
- Separate marketing consent. A tick box for your newsletter, unticked, separate from the enquiry itself. Pre-ticked boxes are not consent.
- A complaints route satisfying the new section 164A duty.
- Encryption in transit as standard — SSL on every site, every page.
The law as it stands
UK data protection is governed by three pieces of legislation working together:
- The UK General Data Protection Regulation (UK GDPR) — the retained version of Regulation (EU) 2016/679, as it forms part of UK law.
- The Data Protection Act 2018 — which supplements the UK GDPR and covers areas outside it, such as law enforcement processing.
- The Privacy and Electronic Communications Regulations 2003 (PECR) — which governs cookies, marketing emails, texts and calls, and sits on top of the UK GDPR rather than replacing it.
All three were amended by the Data (Use and Access) Act 2025, which received Royal Assent on 19 June 2025. Its provisions were phased in: the majority came into force on 5 February 2026, with the data protection complaints provisions following on 19 June 2026. The DUAA amends this framework rather than replacing it — the UK GDPR still exists and still applies.
What changed under the DUAA, in plain terms
You must now have a complaints process
Since 19 June 2026, section 164A of the Data Protection Act 2018 gives people a statutory right to complain directly to an organisation about how it has handled their personal data. If you are a controller, you must provide an accessible way to make that complaint, acknowledge it within 30 days, and respond without undue delay. This is the change most likely to catch a small business out, because it requires something to actually exist rather than something to be written down.
Every website we build includes a route for this, and the wording for it goes in your privacy notice.
A new lawful basis: recognised legitimate interests
The DUAA adds a seventh lawful basis to Article 6(1) of the UK GDPR. Where processing falls within a defined list of "recognised legitimate interests", you no longer need to carry out the balancing test that ordinary legitimate interests require. This basis is limited to the purposes defined in law; it is not a general exemption for ordinary commercial activities. Other data protection requirements still apply.
Automated decision-making rules rewritten
Article 22 of the UK GDPR has been repealed and replaced by new Articles 22A to 22D. The rules permit a wider range of significant solely automated decisions, subject to safeguards and additional restrictions for special category information. If you operate in both jurisdictions, you cannot assume one set of rules covers you for both.
Subject access requests
The DUAA confirms that when you receive a subject access request you are required to carry out a reasonable and proportionate search, not an exhaustive one. The normal response deadline remains one calendar month, subject to the statutory rules on extensions and any permitted pauses. Requests can be made verbally or in writing; no special form is required.
Your own obligations
We can build the site correctly, but some things only you can do.
- Check whether you must pay the data protection fee. Organisations and sole traders processing personal information must pay unless an exemption applies. Use the ICO fee guidance and self-assessment to check your position and the current amount. Exemption from the fee does not remove your other data protection duties.
- Know what you hold and why. Article 30 requires records of processing activities, with a partial exemption for organisations under 250 staff that does not apply where processing is regular or involves special category data.
- Set retention periods and stick to them. "We keep everything forever" is a storage limitation breach under Article 5(1)(e).
- Answer subject access requests within one month, extendable by two further months for complex requests.
- Handle complaints under the section 164A process described above.
- Get marketing consent right. PECR regulation 22 governs electronic marketing. The "soft opt-in" for existing customers is narrower than most people assume.
What non-compliance costs
Under the UK GDPR the maximum penalty is £17.5 million or 4% of total worldwide annual turnover, whichever is higher. The DUAA raised PECR penalties to the same level, which is a substantial increase from the previous £500,000 cap — relevant to anyone doing email or text marketing.
In practice the ICO's approach to small businesses is proportionate, and it has confirmed it will assess conduct against the law and guidance as they stood at the time. The realistic risk for a small business is not a headline fine. It is a complaint from one annoyed customer that turns into correspondence you have to deal with, and a reputational problem you did not need.
Common questions
Does GDPR still apply after Brexit?
Yes. The UK GDPR is UK law and applies in full. If you have customers in the EU, the EU GDPR may apply to you as well — and the two are now diverging, so what satisfies one may not satisfy the other.
I'm a sole trader with a simple website. Does this really apply to me?
Yes. There is no small-business exemption. If you collect names, email addresses or phone numbers, you are processing personal data. The obligations are lighter at your scale, but they exist.
Do I need a data protection officer?
Almost certainly not. Article 37 requires one only for public authorities, or where core activities involve large-scale regular monitoring or large-scale special category data. A small business website does not meet that threshold.
Can I email past customers about a new service?
Possibly, under the soft opt-in in PECR regulation 22, if you obtained their details during a sale of a similar product or service and gave them an easy way to opt out then and every time since. If in doubt, ask for consent.
What happens if my site is hacked?
Where we act as your processor, we notify you of a personal data breach without undue delay and help you assess it. You then have 72 hours from becoming aware to notify the ICO if the breach is likely to result in a risk to people's rights and freedoms, and you must tell affected individuals if the risk is high. Our monitoring and off-server backups exist so that this is a recoverable incident rather than a catastrophe.
Where to check for yourself
We would rather you verified this than took our word for it.
- ico.org.uk — the regulator, with genuinely good plain-English guidance for small businesses
- The data protection fee, including a self-assessment to check whether you need to pay
- The ICO's DUAA guidance for what the 2025 Act changed
- Data Protection Act 2018 on legislation.gov.uk
Our own compliance. Splash Nodes is a trading name of Alan Alaei, a sole trader, of 32 Blenheim View, Leeds, West Yorkshire, LS2 9QB, registered with the ICO as a data controller. Our privacy policy sets out what we collect and why, our cookie policy covers what we store in your browser, and our terms and conditions contain the Article 28 processor terms that govern our handling of your customers' data. To make a data protection complaint or a subject access request, email [email protected], or use the Data Subject Access Request page for the fastest route. We acknowledge data protection complaints within 30 days, investigate them and communicate the outcome without undue delay. Subject access requests are different: we respond without undue delay and normally within one calendar month. Where the law permits an extension, we explain the reason and the revised deadline within the initial month. You do not have to use our online form to exercise your rights. You can also raise concerns with the ICO.
Related pages
Not sure where you stand?
Contact us about your information, a data protection concern or the privacy features of your website.
Contact us