.png)
Most founders don’t get privacy wrong because they don’t care. They get it wrong because the setup that worked at ten people quietly stops working at fifty.
Nobody notices until an enterprise customer sends over a privacy questionnaire, an investor asks for evidence during due diligence, or the ICO raises a question nobody can confidently answer.
For a growing business, UK GDPR compliance quickly becomes more than having a privacy policy on your website. Privacy is a system. And, like any system, it needs to keep working as the business grows.
Why does data protection seem to get harder just as things start going right? Because growth multiplies everything you need to keep track of.
More customers mean more personal data. More markets mean more rules. More colleagues mean more people handling that data, some of whom may never have been told quite how broad “personal data” is.
The privacy policy someone wrote over a weekend during your seed round might have helped you get live. It probably wasn’t designed for the business you’re building now. It’s a familiar shift for founders moving from laying the foundations to scaling up: what worked at one stage won’t always survive the next.
And people will ask. Enterprise customers want to know how you handle data before they sign. Investors look at data protection as part of operational due diligence. Regulators expect accountability, which means being able to show what you do, not just saying you take privacy seriously.
You can put the 40-page policy nobody reads to one side for a moment. A privacy programme that scales needs a handful of working parts, each with a job to do:
It should be practical, proportionate and owned by someone who can act when something needs fixing. A data protection audit can help you see which of these parts are working and which need attention before a customer or investor asks.
Not every scale-up needs a Data Protection Officer (DPO). Some, however, are legally required to appoint one.
Under Article 37 of the UK GDPR, you must appoint a DPO if you’re a public authority, if your core activities involve regular and systematic monitoring of people on a large scale, or if your core activities involve large-scale processing of special category or criminal offence data.
If those tests don’t apply, you still need somebody responsible for privacy. Give them a clear remit and the authority to do the job. An interested volunteer with twelve other priorities will struggle.
The difference between “we should probably have a DPO” and “we legally need one” is worth checking properly, particularly if the way you use data has changed as you’ve scaled.
If you haven’t looked at your privacy processes for a while, now is a good time.
Most of the remaining data protection changes under the Data (Use and Access) Act 2025 took effect on 5 February 2026. A further requirement came into force on 19 June 2026: organisations must now have a way to handle data protection complaints. That includes a clear route for people to complain, acknowledging complaints within 30 days, investigating them appropriately and communicating the outcome. The requirement applies to small businesses too.
The Act also introduced recognised legitimate interests as a separate lawful basis for certain specified public-interest purposes. Where it applies, you do not need to carry out the usual legitimate interests balancing test. It also changed parts of the rules on subject access requests and how organisations deal with complaints.
In plain English: check how people can complain to you, who handles those complaints, what your privacy notice says and how your team responds to subject access requests (SARs). Even if the rest of your business hasn’t changed, the rules have.
The UAE does not have one privacy regime that works the same way everywhere.
Businesses subject to the federal Personal Data Protection Law (PDPL) need to consider its requirements. The Dubai International Financial Centre (DIFC) has its own Data Protection Law and regulator. So does Abu Dhabi Global Market (ADGM), under its Data Protection Regulations 2021.
They may sound similar, but the details differ. Where your business is established and what it does will affect which obligations you need to consider. If you’re expanding into the UAE, work that out early, before you copy your UK privacy documents across and assume the job is done. UK and UAE data protection legal advice can help you build a programme that reflects where you operate.
You don’t need a perfect-looking folder of policies. You need to be able to answer, calmly and specifically, when someone asks how you handle their data.
That someone might be a regulator. It might be an enterprise customer’s legal team. Or it might be an investor’s diligence lawyer three weeks before you hope to close a round.
Get the foundations right and privacy becomes easier to manage as you grow. Leave it until a deal is on the table and it can become the question holding everything up. If you’d like to see what ongoing support looks like, we’ve written about how we help clients stay on top of data protection.
Has your privacy programme kept up with your business? Our free Data Privacy Audit gives you a straightforward look at where things stand today, benchmarked against ICO guidance and ISO standards.
If you need data protection legal support as you scale, we can help you work out what’s required and what to tackle first.
Get in touch with our team to find out more →