ICAEW.com works better with JavaScript enabled.

Common data protection fails and how to prevent them

Author: ICAEW Insights

Published: 01 Oct 2026

As the Information Commissioner’s Office becomes the Information Commission, we look at nine data protection pitfalls and offer advice for smaller organisations on ways to avoid them.

Key takeaways

  • Effective data protection: depends on a company’s ability to maintain control and visibility over data.
  • Have a process: document what personal data you collect, why you need it, where it goes, who can access it and who is responsible.
  • Set clear policies: that manage the entire data lifecycle, from collection to storage and deletion.
  • Don’t ignore use of AI: the technology introduces additional risk around personal data, automated decision-making, transparency and fairness. 

Growing use of artificial intelligence (AI), widespread remote working and an evolving regulatory landscape mean it’s easier than ever to fall foul of data protection rules.

Being in breach of the UK GDPR and the Data Protection Act 2018 can result in serious consequences for small businesses. Depending on the nature of the infringement, the Information Commission can issue warnings, reprimands or enforcement notices, and for higher-tier infringements can impose significant fines.

Prefer to listen?

Allow SoundCloud audio

This audio player is provided by Soundcloud, a third-party service. We ask for your permission before anything is loaded as SoundCloud places cookies on our site. For more information on how we handle cookies, please see our privacy policy and cookies policy. To listen to this content on the website, please accept Statistics cookies and continue. Alternatively, you can access ICAEW podcasts on Spotify, Apple podcasts or YouTube.

Disclaimer

This audio file was produced by AI and has been adapted from the original article for audio purposes.

Businesses may also face customer complaints, compensation claims and additional costs following data breaches, and the risks of non-compliance go much further. Breaches can damage a company's reputation, reduce customer trust and disrupt normal business operations. Here experts offer advice on avoiding common pitfalls.

Assuming the rules don’t apply to SMEs

“Smaller companies often assume that data protection rules are mainly a concern for large organisations, but this is one of the most common mistakes. Size does not remove the obligations under the GDPR and Data Protection Act 2018,” says Rob McKellar, Legal Services Director at Peninsula.

The good news is that smaller organisations do not need a large compliance department, but McKellar suggests they do need:

  • a clear owner for data protection;
  • a straightforward data map;
  • current privacy notices;
  • a retention and deletion schedule;
  • appropriate security controls; and
  • a simple process for dealing with subject access requests and suspected breaches.

Not reporting breaches

If personal data that the company is responsible for is lost, inaccurate, shared with the wrong people or used for an unintended purpose, that is a data breach. 

“For every company that doesn’t recognise a breach when it happens, there’s another rushing to notify the Information Commission and the affected data subjects when it isn’t necessary to do so,” says Will Richmond-Coggan, a partner specialising in data protection disputes at law firm Freeths. 

While even fairly minor breaches need to be taken seriously, and might need reporting to the Information Commission, it is only necessary to notify data subjects where there is a real risk of the breach causing them harm, he clarifies.

Failing to respond to data access requests

If a company holds personal data about someone, then they can make an access request for copies of that information and details of how it is used and who it is shared with. 

“These data subject access requests (DSARs) can take any form. They don’t have to be formal, they don’t even have to be in writing,” explains Richmond-Coggan. “But fail to respond to one within 30 days and there is a good chance that the Information Commission will uphold a complaint.”

Thinking you have to delete everything

The Right to Erasure – commonly known as the ‘right to be forgotten’ – is a legal principle under the UK and EU GDPR that allows individuals to request the deletion or removal of their personal data from organisations’ records.

Many companies think that the right to be forgotten means that they must delete information about someone if they are asked to. In reality, there are only very limited circumstances in which it is necessary or appropriate to delete information, unless you have decided you no longer have any need for it.

“Companies can get themselves into real difficulties by erasing all of the data they hold about someone in response to a request, only to then find themselves on the receiving end of litigation with no evidence left to enable them to answer the claim,” says Richmond-Coggan.

Forgetting cookies

If you operate a website that places cookies, the Privacy & Electronic Communications Regulations (PECR), alongside the UK GDPR, require you to collect consent from website visitors for many categories of non-essential cookies, including those used to track users, serve targeted ads.

“Visitors to the site are absolutely entitled to complain, if they find that cookies are placed on their machine when they have not consented to them, or remain on their machine when consent is withdrawn,” explains Richmond-Coggan.

It’s important to get this right, but if a mistake happens, he warns businesses to not be persuaded by those that can improperly placed cookie entitles them to hundreds or thousands of pounds of compensation.

Not having an effective data governance strategy

Retaining large amounts of data ‘just in case’ is not an effective governance strategy. Companies need to set clear policies for managing the entire data lifecycle, from collection to storage and deletion, and implement structured grading systems to ensure teams can prioritise effectively, according to Myles Bray, CEO of CyberSentriq.

He says: “Ultimately, effective data protection isn’t defined by a company’s size or access to different security products. It’s more about their ability to maintain control and visibility over their data estate, which is best achieved through better governance and strategic intent.”

Not keeping records of processing activity

Records of Processing Activity (RoPAs) remain a much under-used tool by many businesses. Although not mandatory for many small organisations, you should document:

  • what personal data you collect,
  • why you need it,
  • where it goes,
  • who can access it, and
  • who is responsible. 

“If you suffer a breach, or even if you are updating your privacy notice, having a set of RoPAs gives you an easy reference point for what data needs to be thought about and provided for,” explains Richmond-Coggan. “And of course, many small businesses hope to become bigger businesses one day, which is when having put the right discipline in place early really pays off.”

Not thinking about how you use AI

Use of AI doesn’t change underlying data protection rules, but it does introduce additional risk around personal data, automated decision-making, transparency and fairness under the UK GDPR and Data Protection Act 2018.

“In practice, that means identifying a lawful basis before using personal data to train or run AI, respecting purpose limitation and transparency, minimising what's collected and retained, and checking that outputs are accurate and fit for purpose,” says Shane Tierney, Senior Program Manager, GRC at cyber security company Drata.

AI does not replace data governance rules; it makes poor data governance riskier, especially when third-party tools are involved.

Not training staff appropriately

Weak passwords, shared accounts, poor access controls and the use of unapproved AI ('shadow AI') or cloud tools can all create significant risks in the way you handle data.

McKellar says: “Employees and managers should be trained to check email recipients and attachments, use strong passwords and multi-factor authentication, report incidents immediately and avoid entering personal or confidential information into unapproved tools.”

Online training from the Information Commission has been designed to give smaller organisations, their employees and sole traders clarity on data protection. Data Protection Essentials offers practical advice and know-how to apply the basics confidently in their everyday work, including real-world examples tailored to professional services settings.

Join your peers...

ICAEW's Annual Conference 2026 is themed "Turning business complexity and change into value" and offers practical support to help you respond to economic, political and technological disruption.

Blurred cars on a busy cross roads at night.

Further support

Resources
Resources for ICAEW members in business
Business support

Thought leadership, insights, technical resources and professional guidance to support ICAEW members working in industry with their professional development.

Browse resources
Resources and support
How to grow

Support from ICAEW on starting, growing and renewing businesses in the UK, and supporting the government's mission of kickstarting sustainable economic growth.

More support Policy recommendations
ICAEW support
A group of people in a meeting room with their laptops, woman at the whiteboard with sticky notes
Training and events

Browse upcoming and on-demand ICAEW events and webinars offering support on technical areas, such as assurance, reporting and tax, as well as personal development.

Events and webinars A-Z of courses
Open AddCPD icon