GDPR is one of those subjects that makes people glaze over! And there is quite a lot of information about it out there, some of it being quite complicated and very often it still talks about EU GDPR, as if nothing has changed since Brexit.
So, as a Virtual Assistant operating in the UK, what do you need to know?
Don't panic - it's not as scary as it sounds!
The first thing I want to say is don’t panic; it really isn’t as complicated and scary as it sounds.
When GDPR first came into force as part of the UK GDPR and Data Protection Act 2018, it sent the VA Industry into a spin, only for us to find it was actually quite manageable; we just had to add a couple of extra considerations and actions into the way we worked.
There have since been some recent changes as well to consider following the passing of the Data (Use and Access) Act 2025, which took effect in June 2026.
So, let’s break it down and have a look at what it means for you in straight-forward language.
What is Personal Data?
Personal data is basically any information that means you can identify a living individual.
This could be something like their name, address, telephone number or email address, and there are lots of other types of information that can identify someone.
As virtual assistants, we would normally have access to personal data on a daily basis, in an inbox (our own and our customer’s), CRM systems, databases, invoices and invoicing software, email marketing software and much, much more.
There is also a particular category of personal information called Special Category Data, which needs extra protection under UK GDPR. This includes information about somebody’s health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data used for identification, and information about their sex life or sexual orientation.
Even if that information does not belong to you (e.g it is your client’s information), you are still handling it, and that means that we have to be registered with the ICO because, as virtual assistants, we are both ‘Data Controllers’ and ‘Data Processors’.
What are Data Controllers and Data Processors?
When you register for the ICO you will be asked if you are a Data Controller or a Data Processor.
The majority of Virtual Assistants are both. You are usually a controller for the personal information you process for your own business, and it is probable that you act as a processor when handling personal data on a client’s instructions.
In simple terms, a Data Controller decides why and how personal information is being used.
So, for example, you are normally a controller for the client contact information you decide to keep in your own inbox, CRM or accounting system for the purpose of running your VA business.
You are a Data Processor if you are, for example, accessing a client’s database to update records, invoice people or send out emails for them – you are processing that data on the controller’s instructions.
Data Processors have responsibilities under UK Data Protection Law too, and controllers are expected to make sure that processors they appoint can handle personal information properly.
This is why, where a VA is acting as a processor, the contract with the client needs to contain the appropriate data processing clauses. These may sit within your main client contract or in a separate Data Processing Agreement.
So, what should Virtual Assistants be doing?
You will be pleased to know that nobody expects you to become a super Data Protection expert overnight! But you should know the basics of how to handle personal data within your business. And the earlier you start doing this, the better it is for you in the long run.
- Know what personal data you actually hold, where you hold it and who can access it.
- Look into how secure that data is, how is it protected, how long do you hold it for and what happens when a client leaves?
- What would you do if your data was stolen, lost, accidentally shared or accessed by someone that shouldn’t see it?
- Look at the suppliers of the software you use (this is called doing your due diligence) and see where their servers are based and what they do to ensure your data on their servers is secure. This is often on their website somewhere or you can get in touch with them and ask.
- IMPORTANT ONE: Do not keep personal data just because you may think you need it one day!
Do Virtual Assistants need to register with the ICO?
In the majority of cases, a VA handling personal information as a data controller and a data processor is likely to need to pay the ICO data protection fee, unless an exemption applies.
As part of SVA professional standards, we strongly recommend that VAs check their position and have the appropriate ICO registration in place and it is a criteria for SVA Approved Membership.
When you fill in the ICO’s Self Assessment Form, you must make it clear that you are both a Data Controller and a Data Processor.
The UK VA Survey tracks whether VAs are registered with the ICO every year. In 2025 96% of VAs were registered with the ICO.
The survey also found that Established VAs, Multi VAs and Super VAs had all reached 100 per cent across Terms and Conditions, insurance and ICO registration, which is a fantastic reflection of increasing professional standards within the industry.
It is a small piece of housekeeping when you start your business, but it’s a very important one.
Website Policies & Legal Requirements
Privacy Policy: If your business or website collects personal information, you will normally need a clear Privacy Policy (sometimes called a Privacy Notice) explaining what you collect and what you do with it.
Cookie Banner & Policy: If your website uses cookies or tracking or advertising cookies, you also need to provide a cookie consent banner and a cookie policy.
Data Protection Complaints Policy: Since June 2026, organisations must also give people a clear way to raise a data protection complaint, acknowledge complaints within 30 days and deal with them without undue delay.
Website Terms and Conditions are strongly recommended, particularly to explain acceptable use, copyright, links and limitations around website content, but they are not automatically a legal requirement for every basic business website.
Software and Cloud Systems
There’s no doubt about it; as VAs, we all really love shiny new software and online tools to play with.
But before you jump in headfirst, just do your due diligence and check the following:
- Where do they store your data?
- Who can access your data?
- Does the supplier use the information for anything else?
- Can you delete it permanently?
- Could the data be transferred outside of the UK?
If you do not get satisfactory answers to any of the above, then think twice before sharing personal data and particularly special category data. This is a particularly timely warning with AI becoming more and more relied upon.
Passwords and Security
It is our responsibility as Virtual Assistants to ensure that data is sufficiently protected. And this means using strong and sensible security measures.
Strong passwords, multi-factor authentication where available, secure backups, appropriate antivirus or device security and sensible access controls should all form part of your security arrangements. A VPN may also be appropriate depending on how and where you work.
And remember, if you use sub-contractors/Associates, the buck stops with you. It is your job to ensure that they are meeting those requirements too.
Never give someone access to an entire client system; for example, if they only need to see one small part of it.
Consent for Marketing Emails
GDPR has changed the way we can send marketing emails too.
If you are sending unsolicited marketing emails to individuals, sole traders or some partnerships, you will need to gain their consent unless you can rely on one of the PECR* soft opt-ins.
Consent must be a genuine choice (not ‘Do not tick this box if you do not not want to receive emails from us!’)
This means that the recipient must take a clear and positive action to indicate that they want to receive your emails, such as ticking an unticked box, verbal consent or written consent.
You cannot use pre-ticked boxes or take silence or inactivity as consent.
The rules are different when emailing limited companies and other corporate subscribers, where PECR* does not generally require prior consent, although UK GDPR may still apply if you are using personal information such as a named individual’s email address.
Whatever the circumstances, you must identify yourself and give people a clear and easy way to unsubscribe from future marketing.
What if it goes wrong?
It sometimes does! And it can happen to anyone.
Data breaches aren’t just caused by someone hacking into your computer; it can happen if someone emails a spreadsheet to the wrong person (one reason we ask our Approved Members not to use free email accounts), it can happen by leaving a USB drive in a public place or working in a cafe when others can see your screen.
If you are acting as a processor for a client and become aware of a personal data breach, you must tell the client without undue delay.
Where the client is the controller, they will then need to assess what has happened and decide whether the breach needs to be reported to the ICO.
Where a breach is reportable, the controller generally needs to notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it.
Do not quietly try to fix a breach and hope nobody notices.
Have a simple process in place before you ever need it.
Know who needs to be told, what information needs to be recorded and what steps you need to take.
Summing it all up
Data protection can become tricky, particularly when you get into sensitive information, international transfers, large databases or unusual processing activities.
But for most VAs, a good starting point is simply knowing:
- What information do I have?
- Why do I have it?
- Where does it go?
- Who can access it?
- How do I protect it?
- How long am I keeping it?
- What would I do if something went wrong?
The days of keeping every email, spreadsheet and client document forever “just in case” really need to be behind us.
Good data protection is not simply about avoiding trouble with the ICO.
It demonstrates to clients that you take their business, their customers and their confidential information seriously.
And that is simply part of being a professional Virtual Assistant.
If you are unsure about your responsibilities, the Information Commissioner’s Office should always be your first port of call for current UK data protection guidance.
For legislation itself, GOV.UK should also be one of your main reference points.
For Contracts, Data Protection Agreements and Policies, check out our Affiliates Page for recommended suppliers.
This article provides general information for UK Virtual Assistants and is not legal advice. Data protection requirements will depend on the individual circumstances of your business and the work you carry out for clients.
*What is PECR?
PECR stands for the Privacy and Electronic Communications Regulations. It sits alongside UK data protection law and covers things such as electronic marketing, marketing emails and texts, telephone marketing, cookies and other technologies that store or access information on somebody’s device. For Virtual Assistants, PECR is particularly relevant if you manage newsletters, mailing lists, email campaigns, websites or online marketing for clients. It is worth remembering that PECR and UK GDPR are not the same thing, but they often work together. PECR sets specific rules around how certain types of electronic marketing and online tracking can be carried out, while UK GDPR governs how personal information is processed more broadly. (ico.org.uk)