Only 34% of UK sole traders said they "strongly agree" they understand their obligations under GDPR and the Data Protection Act 2018, according to the UK government's Business Data Survey 2021, fielded November 2020 to January 2021 among 3,630 businesses that handle personal data. Micro businesses scored barely higher at 39%, against 73% for large businesses in the same survey.

That gap is the clearest, most recent government measurement of a pattern regulators and business groups have flagged for years: small firms are legally covered by GDPR the moment they handle personal data, but a large share of them are not confident they actually understand what that means in practice.

Only 34% of UK sole traders strongly agree they understand their GDPR requirements 34% of UK sole traders strongly agreethey understand their GDPR duties

How many small businesses actually understand their GDPR obligations?

The UK's Department for Science, Innovation and Technology (formerly DCMS) commissioned IFF Research to run a telephone survey of thousands of UK businesses, asking each to rate how strongly it agreed with the statement that it understands its GDPR and Data Protection Act 2018 requirements. Across every business size, 82% tended to or strongly agreed, but "tend to agree" and "strongly agree" describe very different levels of confidence, and the strong-agreement figure is where the small-business gap shows up clearly.

Sole traders sit lowest at 34% strong agreement, micro businesses (1 to 9 employees, excluding sole traders) at 39%, and large businesses (250 or more employees) at 73%, based on a subsample of 1,216 sole traders, 1,200 micro businesses, and 150 large businesses. The size gradient tracks resources: larger firms are more likely to have a dedicated compliance function or outsourced legal advice, while sole traders and micro firms are more likely to be handling data protection alongside every other operational task themselves.

Business sizeStrongly agree they understand GDPR/DPA 2018 (2021)Sample size
Sole traders34%1,216
Micro businesses (1-9 employees)39%1,200
Large businesses (250+)73%150

Figure 1: Strong-agreement gap between the smallest and largest UK businesses. Source: DCMS, UK Business Data Survey 2021, detailed findings (n=3,630).

This is not a measurement of whether a business is legally covered. It is a measurement of self-reported confidence, and confidence tracks size far more closely than legal exposure does, since GDPR's obligations apply the same way to a sole trader's mailing list as to a large enterprise's customer database.

Does GDPR actually apply to your business?

Yes, in almost every case where a business handles personal data at all, regardless of headcount or revenue. Under Article 3 of GDPR, the regulation applies to any organization established in the EU or UK that processes personal data, and separately to any organization anywhere in the world that offers goods or services to EU or UK residents, or monitors their behavior, even without a local office. Size changes which specific duties apply, such as whether a formal data protection officer is required, not whether the underlying law applies.

Figure 2: The territorial-scope test from GDPR Article 3, simplified. Source: GDPR Regulation (EU) 2016/679, Article 3.

A sole trader running an online shop that ships to EU customers, or a one-person consultancy that keeps a spreadsheet of client contact details, is covered by exactly the same territorial-scope test as a multinational. The most direct way to close the compliance gap that gap in confidence points to is to generate a GDPR-ready privacy policy that documents the legal basis, retention period, and data-subject rights the regulation requires, rather than assuming a general-purpose template covers it.

Is small business awareness of the regulator improving over time?

Partially. DCMS's UK Business Data Survey has asked UK businesses whether they have heard of the Information Commissioner's Office, the UK's data protection regulator, and whether they know what it is, across three separate survey waves: 2021 (fieldwork November 2020 to January 2021, n=4,500), 2024 (fieldwork October 2023 to February 2024, n=3,911), and 2026 (fieldwork October 2025 to January 2026, n=4,450).

Micro-business awareness on this measure rose from 42% in 2021 to 58% in 2024, then eased slightly to 56% in 2026. Large-business awareness moved the other way, slipping from 87% in 2021 to 80% in 2024 and 73% in 2026. The net effect is a shrinking gap: 45 percentage points separated large and micro businesses in 2021, narrowing to 17 points by 2026.

Business size202120242026
Large businesses (250+)87%80%73%
Micro businesses42%58%56%

Figure 3: Large-business awareness of the ICO has drifted down while micro-business awareness has risen, narrowing the gap. Source: DCMS, UK Business Data Survey, 2021, 2024, and 2026 editions.

Awareness of a regulator's name is not the same as understanding a business's own obligations under the law that regulator enforces, so this trend and the strong-agreement figures above are measuring related but distinct things. Read together, they suggest small-business familiarity with data protection as a general topic is improving, even while deep, confident understanding of the specific rules remains uneven.

What do small businesses actually do in response to GDPR?

Most take at least some concrete action. Among UK businesses that collect personal data, 52% said they had rewritten or introduced a privacy notice, 51% introduced new processes to implement data protection measures, 50% rewrote their terms and conditions, and 40% introduced opt-in consent mechanisms, per the same 2021 DCMS survey. A quarter of businesses said they had done none of these things.

Actions UK businesses took in response to GDPR and DPA 2018 Rewrote or introduced privacy notice52Introduced new data protection processes51Rewrote terms and conditions50Introduced opt-in consent mechanisms40

Figure 4: The most common actions UK businesses took after GDPR and DPA 2018 took effect. Source: DCMS, UK Business Data Survey 2021, Summary Report (n=3,630).

The most common actions cluster around exactly the documents a small business owner is most likely to have written once, early on, and never revisited: a privacy notice and a set of terms and conditions. Both age quickly as a business adds new tools, new data flows, or new markets, which is part of why confident, current understanding trails a one-time compliance action.

How many small firms think GDPR does not apply to them at all?

More than a third, in the most direct survey to ask the question this bluntly. 38% of UK small and medium business leaders said they believed GDPR did not apply to the customer data their business acquires and processes, according to a November 2019 survey of 293 senior SME leaders (businesses with 250 or fewer employees) conducted by the UK's Data & Marketing Association in partnership with Xynics. That is an older, single-source measurement rather than a government survey, so treat it as directional evidence of a widely held misconception rather than a precise current figure.

SMEs who believe GDPR does not apply to their customer data 38%believe GDPR does not apply0100

Figure 5: Over a third of surveyed UK SME leaders believed GDPR did not cover their own customer data. Source: Data & Marketing Association and Xynics, GDPR Small Business Survey, November 2019 (n=293).

The same 2019 survey found that 68% of respondents claimed good or moderate GDPR awareness, yet only 10% believed their business was fully compliant, and 44% admitted they did not always obtain proper consent before using personal data. Claimed awareness, actual understanding, and real compliance behavior are three different things, and the gap between them is where most small-business GDPR risk sits.

DMA/Xynics 2019 UK SME survey findingShare of respondents
Claimed good or moderate GDPR awareness68%
Believed GDPR does not apply to customer data they acquire and process38%
Believed they were fully GDPR compliant10%

The Bottom Line

No credible survey suggests most small businesses are unaware that data protection law exists. The gap is narrower and more specific than that: a meaningful share of the smallest firms, sole traders most of all, do not confidently understand what GDPR requires of them, and some still believe, incorrectly, that their size or informality exempts them. Neither is true under GDPR's own scope rules, which apply the same territorial test to a one-person shop as to a global platform.

The trend data is at least mildly encouraging. Micro-business awareness of the UK's regulator has risen since 2021 even as large-business awareness has drifted down, narrowing what was once a wide gap. But awareness of a regulator's name is a weak proxy for actually knowing what to document, disclose, and retain. The most common actions small businesses already take, rewriting a privacy notice or terms and conditions, are the right instinct; keeping those documents current as the business changes is the part that self-reported confidence surveys suggest is still missing for a lot of the smallest firms. The same pattern shows up in adjacent research on how small businesses document privacy internally, and in open questions this data does not yet answer, such as how many small online stores meet applicable privacy laws in practice, or how many new start-ups launch without any legal pages at all.

Frequently Asked Questions

What percentage of small businesses understand GDPR applies to them? In the UK government's most detailed measurement, only 34% of sole traders and 39% of micro businesses strongly agreed they understand their GDPR and Data Protection Act 2018 requirements, compared with 73% of large businesses, per DCMS's UK Business Data Survey 2021, based on 3,630 businesses that handle personal data.

Does GDPR apply to a one-person or very small business? Yes. If a business collects or processes any personal data and is established in the EU or UK, or offers goods or services to (or monitors) EU or UK residents, GDPR or UK GDPR applies regardless of headcount. Business size affects which specific duties are triggered, such as needing a data protection officer, not whether the law applies at all.

Is small business awareness of data protection rules improving over time? On one tracked measure, yes. Micro businesses that said they had heard of the ICO and knew what it was rose from 42% in 2021 to 58% in 2024, easing slightly to 56% in 2026, per three waves of DCMS's UK Business Data Survey. Large-business awareness on the same measure slipped from 87% to 73% over the same span, narrowing the gap between big and small firms from 45 points to 17 points.

How many small businesses think GDPR does not apply to them? 38% of small and medium business leaders said they believed GDPR did not apply to the customer data their business acquires and processes, according to a November 2019 survey of 293 senior SME leaders by the UK's Data & Marketing Association and Xynics. The same survey found only 10% of respondents believed their business was fully GDPR compliant.

Where the Numbers Come From

  1. Department for Digital, Culture, Media and Sport. (2022). "UK Business Data Survey 2021: Detailed Findings." Strong-agreement figures on understanding GDPR/DPA 2018 requirements by business size, published 17 May 2022, fieldwork November 2020 to January 2021 (n=3,630 businesses handling personal data).
  2. Department for Digital, Culture, Media and Sport. (2021). "UK Business Data Survey 2021: Summary Report." ICO awareness by business size and GDPR/DPA 2018 response actions, published 13 May 2021 (n=4,500 UK businesses, survey by IFF Research).
  3. Department for Science, Innovation and Technology. (2024). "UK Business Data Survey 2024." ICO awareness by business size, published 27 June 2024, fieldwork October 2023 to February 2024 (n=3,911).
  4. Department for Science, Innovation and Technology. (2026). "UK Business Data Survey 2026." ICO awareness by business size, published 18 June 2026, fieldwork October 2025 to January 2026 (n=4,450).
  5. Data & Marketing Association and Xynics. (2019). "GDPR Small Business Survey." Belief that GDPR does not apply, claimed awareness, and compliance confidence, November 2019 (n=293 senior SME leaders at businesses with 250 or fewer employees).

Note: All figures verified as of September 2026. The 2019 DMA/Xynics figures are the most recent survey found that asks directly whether small business leaders believe GDPR applies to their own customer data; more recent UK government surveys measure related but distinct questions, such as agreement with understanding requirements and awareness of the regulator, which are cited separately above rather than blended into the 2019 figure.