← Back to blog

Is Your Business Automation GDPR Compliant? What Changed in the UK in 2026

Aaron Allen

Is Your Business Automation GDPR Compliant? What Changed in the UK in 2026

If you've connected a website form to your CRM through Zapier or Make, or you've got an automation pulling customer emails into a spreadsheet for follow-up, you've probably had the thought at some point: is this actually allowed? You're moving someone's name, email address and maybe more between two or three different pieces of software without them clicking through a lengthy consent screen each time. It feels like it should need more paperwork than it does.

The good news is that connecting apps together isn't inherently a GDPR problem. The less good news is that as of 19 June 2026, the rules changed, and most small business owners running automations haven't looked at what that means for them.

What actually changed on 19 June 2026

The Data (Use and Access) Act 2025 (DUAA) finished coming into force that day, after being phased in gradually from June 2025. It's not a full rewrite of UK GDPR, but it adjusts several things that matter if you're automating customer-facing processes.

The two changes most relevant to a small business using tools like Zapier, Make, or a custom-built workflow are around automated decision-making and complaints handling. Businesses can now rely on "legitimate interests" as a lawful basis for some automated decisions, where previously that route was more restricted. That sounds like good news for automation, and mostly it is, but it comes with a catch: it doesn't apply to special category data (health information, for example, or anything revealing someone's religion, sexuality or similar), and you still need to show you've put safeguards in place, not just that you had a legitimate reason.

Separately, if you handle any personal data at all, you're now expected to have an accessible way for people to complain (an online form is fine, you don't need a phone line) and to acknowledge complaints within 30 days. If a customer emails you asking why an automated email keeps chasing them for a review after they've already left one, that's a complaint, and it needs a response, not just a shrug.

The automated decision-making part is the one to actually think about

Most small business automation isn't making decisions about people in the way the rules are worried about. Sending a welcome email when someone fills in a form isn't a decision with legal or similarly significant effect. But some setups edge closer to that line than owners realise. An automation that scores leads and automatically routes "low value" enquiries to a slower response queue, or one that auto-rejects a booking based on postcode, is making a decision that affects how someone is treated, without a person reviewing it first.

If that sounds like something you've built, the practical fix isn't to rip it out. It's to document what the automation does, why, and make sure there's a way for someone to ask a human to look at their case if they think it got it wrong. That's a page of notes, not a legal project, but it needs to exist somewhere other than in your head.

Whose job is compliance when five different tools touch the data?

This is the question we get asked most often, and the honest answer is: it's shared, but you don't get to hand it all off to the software.

When you use Zapier or Make to move data between your website form, your CRM and your invoicing tool, each of those companies is a data processor for that slice of the journey, and you're the data controller who decided the data should move in the first place. Zapier, for instance, builds its Data Processing Addendum into its terms automatically, and you can generate a signed copy free through their site if you need one for a supplier register or an audit. Make offers something similar. That covers Zapier's or Make's own handling of the data. It does not cover what happens once the data lands in the next tool along the chain, and it doesn't make the automation itself compliant if the reason you built it in the first place doesn't hold up.

Worth knowing too: most of these platforms process data on US servers, using the EU-US Data Privacy Framework as their main transfer safeguard, with Standard Contractual Clauses as a fallback. For the vast majority of small business use cases, that's a settled, workable arrangement. It matters more if you're handling anything sensitive, or if a client contract specifically requires EU-only data residency, in which case it's worth checking with the platform directly before assuming it's covered.

A practical starting point, not a full audit

You don't need a data protection consultant to get the basics right. Here's what actually moves the needle for most small businesses running a handful of automations:

None of this requires slowing down or undoing the automations that are actually saving you time. It's closer to housekeeping: the kind of thing that's fast to do properly now and expensive to reconstruct later if a customer, or the ICO, asks a question you can't answer.

If you're not sure whether a specific automation you're running (or one you're planning) crosses into decision-making territory, or you want a second pair of eyes on what's actually connected to what, that's a conversation worth having before you build the next one, not after. Digital Hand offers a free 15-minute consultation if you'd like to talk it through.