Compliance7 min read15 September 2026

GDPR and Website Security: What UK Businesses Are Legally Required to Do

UK GDPR requires businesses to implement appropriate technical security measures. Here is what that actually means for your website, and the fines for getting it wrong.

By Yrzo AI — UK cybersecurity specialists

GDPR and website security: what UK businesses are legally required to do

UK GDPR does not tell you which security tools to buy. What it does is hold you legally responsible for the outcome if your website is breached and customer data is exposed — regardless of whether you knew about the vulnerability.

Article 32 of UK GDPR requires data controllers and processors to implement "appropriate technical and organisational measures" to ensure a level of security appropriate to the risk. Here is what it means in practice for businesses operating websites that handle personal data.

What counts as personal data on a website

If your website collects names, email addresses, phone numbers, IP addresses, browsing behaviour, purchase history, health information, or any other information that can identify an individual — directly or in combination — it is processing personal data under UK GDPR.

This covers almost every business website that has a contact form, an account registration system, an e-commerce checkout, a booking system, or a newsletter signup.

What "appropriate technical measures" means

The ICO has published guidance and enforcement decisions that make clear what it expects. Appropriate technical measures include encryption of personal data in transit and at rest, access controls that limit who can reach the data, regular testing of security measures, and the ability to detect and respond to breaches.

That last point — regular testing — is where most small businesses fall short. Implementing HTTPS is not sufficient. Having a privacy policy is not sufficient. Appropriate security means actively verifying that your systems are not vulnerable to known attack techniques.

The fines for getting it wrong

Under UK GDPR, the ICO can issue fines up to £17.5 million or 4% of global annual turnover. In 2023, a dental practice was fined £50,000 after patient records were accessed through an unsecured database. In 2024, a law firm received a £60,000 penalty following a ransomware attack the ICO determined could have been prevented with basic security testing.

The pattern in these decisions is consistent: businesses that had not tested their security were treated as negligent rather than simply unlucky.

Does GDPR require penetration testing specifically?

Not by name. UK GDPR requires regular testing, assessing, and evaluating the effectiveness of technical measures — Article 32(1)(d). The ICO does not mandate a specific tool or method, but penetration testing is the recognised industry standard for fulfilling this obligation.

The National Cyber Security Centre (NCSC) recommends regular penetration testing as part of a proportionate security programme. Most cyber insurance policies now require evidence of regular security testing before issuing coverage.

What this means for your business

If your website handles personal data and has never been security tested, you are operating in a gap between what the law requires and what you have actually done. After a breach, the ICO's investigation will establish when you last tested your systems and what you did with the results.

Yrzo AI runs 44 automated security checks against your website and produces a report documenting what was tested, what was found, and what needs to be fixed. The report serves as evidence of due diligence.

A scan takes under 20 minutes and starts at £399. The ICO fine for a preventable breach starts at tens of thousands of pounds.

Find out if your website has these vulnerabilities

Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.

Scan your website →