Ask most small businesses and not-for-profits what would happen if a regulator turned up, and the answer tends to focus on the same thing: the size of the fine. That's a reasonable thing to think about, but for the overwhelming majority of small organisations it's the wrong risk to be worried about. Large fines follow large, deliberate, or repeated failures against organisations with the scale to absorb regulatory attention in the first place. What actually trips up a small organisation is smaller and much more mundane: someone asks a direct, ordinary question — "what do you hold on me, and why?" — and nobody can answer it cleanly.

That's the moment the real exposure shows up, and for most small organisations it's mainly a trust problem rather than a legal one. It's the loss of trust that follows from an organisation, however well-meaning, visibly not being in control of information it was trusted with. A donor, a member, a supporter who asks a fair question and gets a shrug, a guess, or a scramble through old email threads walks away with a very different impression than one who gets a clear, confident answer — even if the underlying data handling was, in substance, perfectly reasonable all along.

It isn't only reputational, though. That same question, asked formally, is a subject access request under Article 15 — and Article 12(3) attaches a statutory one-month response window to it, extendable to three for a genuinely complex request. An organisation that can't answer cleanly isn't just risking an awkward impression; it's risking a legal deadline the ICO can act on directly, independent of how reasonable the underlying data handling actually was.

Reasonable isn't the same as demonstrable

Most small organisations aren't doing anything obviously wrong with the personal data they hold. The gap is usually that nobody has ever written any of it down. Data ends up spread across a personal inbox, a shared drive, a treasurer's spreadsheet, and a messaging app, accumulated gradually over years by whoever happened to be doing the job at the time, with no single place that says what's held, why it's kept, or when it should be deleted. None of that is necessarily unreasonable — but "we've never really thought about it" and "we thought about it and made a defensible decision" produce identical outcomes right up until someone actually asks, and only one of them survives the question. That distinction is precisely what UK GDPR's accountability principle (Article 5(2)) is for: a controller has to be able to demonstrate compliance, not merely have been compliant in fact.

The fix is smaller than the fear

Closing that gap doesn't require a compliance department. It requires a short, honest inventory — what's held, where, why it's needed, roughly how long it's kept — written down once and revisited occasionally rather than left to live only in the heads of whoever's currently involved. In substance, that's a lightweight record of processing. The formal Article 30 duty to keep one only binds organisations outright once they reach 250 employees, or earlier if the processing is non-occasional, carries a real risk to people's rights, or touches special category or criminal-offence data — most small clubs, societies, and charities sit below that line on paper. Do it anyway. The accountability principle behind it has no size carve-out, and the same short document is what turns "we don't really know" into an answer somebody can actually give — which is the difference that matters far more often than the theoretical size of a penalty that, for the vast majority of small organisations doing ordinary, well-intentioned work, will never come into play at all.