Data protection laws govern how businesses collect, use, store, and share personal information. In the UK, the key legislation includes the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Together, these laws impose obligations on businesses of all sizes, requiring that personal data be handled lawfully, fairly, and transparently — and that you can demonstrate compliance at any time. The Information Commissioner’s Office (ICO) enforces these rules and can impose significant fines. In addition to regulatory penalties, inadequate data protection can harm your reputation and damage commercial relationships. Compliance is not just a legal requirement; it is also good business practice.
Contact Us TodayRelated services
How data protection impacts your business
Whenever your business processes information about an identifiable individual — such as a customer, supplier contact, or website visitor — data protection laws apply.
Processing activities arise across your organisation every day, including:
- Customer and client records — contact details, purchase histories, account information and correspondence.
- Marketing — sending promotional emails or direct mail and managing consent and opt-out preferences.
- CCTV — images captured on business premises constitute personal data and require proper governance and defined retention periods.
- Suppliers and processors — engaging third parties (such as payroll bureaus, IT providers or marketing agencies) to handle data on your behalf requires a written contract, containing specific mandatory clauses.
- Commercial contracts — where two businesses independently determine the purposes of processing (such as in a referral or co-marketing arrangement), both may be acting as joint controllers, with obligations that must be clearly allocated in the contract.
- Website visitors — cookies, analytics tools, chat functions and contact forms all collect personal data, requiring a compliant privacy notice and cookie policy and, where necessary, freely given consent.
- International transfers — sharing personal data with organisations outside the UK requires a lawful transfer mechanism and, in most cases, a Transfer Risk Assessment (now known as the data protection test).
Our data protection services
Our Commercial team advise businesses across all sectors on building and maintaining a compliant data protection framework. Our services include:
- Assessment of the status of parties to a commercial transaction, i.e. whether the parties are independent controllers, joint controllers or one party is a processor to the other’s controller. The status of the parties determines the nature of the clauses to be included in contract, whether it is best practice or required by law. Our commercial team can prepare standalone data sharing agreements as well as clauses for inclusion with overarching commercial transactions.
- Data Protection Impact Assessments (DPIAs) — A DPIA is mandatory before undertaking any processing likely to result in a high risk to individuals, such as large-scale processing of special category data (such as data concerning an individual’s health). We advise when a DPIA is required and assist you through the process.
- Preparation of bespoke data protection policies tailored to your organisation’s processing activities.
- Advice concerning direct marketing and compliance with Privacy and Electronic Communications Regulations.
- Preparation of privacy notices, setting out clear information about how your business will process personal data, whether directed at customers, clients or visitors to your website.
- Preparation of cookie policies, for use on websites.
- Preparation and advice concerning data sharing agreements, defining the purpose and scope of the sharing, each party’s responsibilities, applicable security standards and arrangements for handling data subject rights requests and breaches.
- Advice concerning data transfers outside of the UK, including application of Adequacy Regulations, use of International Data Transfer Agreements/Standard Contractual Clauses and the Data Protection Test. Our Commercial team can prepare the relevant documentation and – where required – assist you with the preparation of any ancillary compliance documents.
How We Can Help
At Nelsons, our Commercial Team regularly advises businesses on data protection compliance. We collaborate with you to understand your data processes, identify potential risks, and develop tailored documentation that protects your business and ensures ongoing compliance.
We’re based in Nottingham, Leicester, and Derby, but advise businesses throughout the UK and internationally.
Call us: 0800 024 1976 or complete our online enquiry form.
Make an enquiry
If you wish to contact us, please complete the form below. A member of our team will be in touch as soon as possible.
When you submit this form, you are consenting to a member of our team to contact you via phone or email regarding your request.
We encourage you to review our Privacy Notice
Main Contact Form
Used on contact page
Get in touch
Speak to us now on 0800 024 1976Email Us