GDPR for contact data: what UK small businesses actually need
You don't need a legal team to hold contact data properly. You need four things written down. Here they are.
Most small businesses hold contact data the anxious way: a spreadsheet nobody's sure is allowed, and a vague hope that a data request never lands. GDPR feels enormous, but for a shared contact list the practical requirements come down to a short, manageable list.
This isn't legal advice — every business is different and if you're unsure, ask a professional. But here's the plain-English shape of what you actually need.
1. A lawful basis for each contact
You need a reason you're allowed to hold someone's details. For business contacts that's often 'legitimate interest'; for marketing it's usually consent. The point isn't the label — it's that you can name the basis and it's honest.
2. A consent (or basis) record
For each contact, write down the purpose, the basis and when it was captured. This is the answer to the only question that really matters in an audit: 'why do you hold this?' If that answer is already recorded, the scary part of GDPR mostly evaporates.
3. An audit trail
Who changed what, when, and on what basis. You don't need a compliance department — you need a system that keeps this automatically, so the evidence exists without anyone maintaining it.
4. A way for people to exercise their rights
- Access — they can see what you hold.
- Rectification — they can correct it.
- Erasure — they can ask you to remove it.
- Objection — they can opt out of certain uses.
The simplest way to honour these is to let the person do it themselves. A private portal, secured by a one-time code, lets a contact confirm, correct or control their own details — which handles most requests before they ever become a request.
Compliance stops being a scramble when consent and the audit trail are built into the contact, not bolted on afterwards.
How CentralContacts makes this the default
Every contact carries a consent record and an audit trail automatically. People get their own portal to exercise their rights. Verification is positive-only — a 'verified' badge that reassures, never a blacklist that accuses. And your data is hosted in the UK/EU and exportable anytime. The result is that doing the right thing is simply the path of least resistance.