What personal data your business actually holds, listed once
- Aug 29
- 3 min read
Updated: 2 days ago
Introduction
A business is asked what personal data it holds and answers that it has a customer list. In practice it holds employee records, job applications from four years ago, supplier contacts, CCTV footage, email correspondence going back a decade, a spreadsheet on somebody's laptop and two systems nobody has logged into since a former employee left.
Every obligation in data protection depends on knowing what you hold, where it is and why. Without that list you cannot write an accurate privacy notice, respond to a request, assess a breach or decide what to delete. It is the foundation, and it is almost universally missing. It is also the only item on the list that takes an afternoon rather than a project.
1. What personal data your business actually holds is broader than the customer list
Start by widening the definition.
Personal data is any information relating to an identifiable person. That includes employees, applicants, contractors, supplier contacts, enquirers who never bought, and anybody appearing in correspondence or footage.
2. Work through where information physically lives
The locations, not the categories.
Accounting software, the customer system, email accounts, shared drives, personal laptops and phones, paper files, the website, backup systems, and any third-party service you use. Data on somebody's phone is still your responsibility. Not knowing about it removes your ability to protect it, not your obligation to.
3. Record why you hold each set
The question that drives everything else.
For each category, what it is used for and what your lawful basis is. This is the part most businesses have never articulated, and it determines what you may do with the data and how long you may keep it.
4. Note who has access
Both internally and externally.
Which staff can reach each system, and which suppliers process data on your behalf. Access that was appropriate three roles ago is frequently still in place, and this exercise is what reveals it.
5. Identify anything sensitive
It carries stricter requirements.
Health information, criminal records, biometric data and other special categories attract additional obligations in most regimes. Small businesses hold more of this than they realise, usually in employee files. Sickness records and occupational health reports are the most common examples.
6. Establish how long each category is kept
Rarely defined at all.
Indefinite retention is the default and is generally not lawful. Setting a period for each category, based on why you hold it, converts a growing liability into a managed one.
7. Find the data nobody is responsible for
Where the risk concentrates.
Old systems, a departed employee's mailbox, spreadsheets on a shared drive, and backups from a previous provider. These are the sources that produce the awkward answers during a breach or a request.
8. Keep the record and update it
An obligation in many regimes.
Several frameworks require a record of processing activities for businesses of certain sizes or activities. Even where it is not required, the document is what makes every other obligation manageable.
9. Use it to decide what to stop holding
The immediate practical benefit.
Most businesses completing this exercise find categories they do not need at all. Deleting those reduces the risk, the storage and the scope of any future incident, at no cost whatsoever.
Do it once properly, in an afternoon, rather than treating it as a project. A simple table listing category, location, purpose, access, retention and lawful basis is sufficient for a small business, and it makes every subsequent question straightforward to answer.
Conclusion
Write the list, because every other obligation depends on knowing what you hold.
Widen the definition beyond customers to include staff, applicants, suppliers and correspondence, work through the physical locations including personal devices and old systems, record the purpose and lawful basis for each category, note who has access internally and externally, identify anything in a special category, set a retention period for each set, find the data nobody currently owns, keep the record updated, and delete what you have no reason to hold.
.png)



Comments