Skip to main content
☰

G&G verified business evidence

Data-protection leadership among UK employers handling personal data

In 2025 to 2026, 56% of UK businesses with employees that handled digitised personal data had someone whose role included leading data-protection compliance.

56 percent

What the evidence means

The denominator is employing businesses that handle digitised personal data. The measure does not specify whether the role is full-time or a formally appointed data protection officer.

Conditional estimate among employing businesses handling digitised personal data.

Original source

Department for Science, Innovation and Technology

UK Business Data Survey 2026

The report records 56% with someone leading data-protection compliance as part of their role.
View original evidence

Department for Science, Innovation and Technology. UK Business Data Survey 2026. 18th of June, 2026. https://www.gov.uk/government/statistics/uk-business-data-survey-2026/uk-business-data-survey-2026

Back to all statistics

Why this matters to UK SMEs

Many SMEs cannot justify a full-time data-protection specialist, but responsibility still needs to be explicit. The size breakdown shows that formal leadership becomes more common as organisations grow, which makes role clarity especially important in smaller employers.

Key breakdowns

Among employing businesses handling digitised personal data, 56% had someone whose role included leading data-protection compliance. This rose from 53% among microbusinesses to 64% among small businesses, 74% among medium businesses and 92% among large businesses. Separately, 46% had at least one full-time-equivalent employee whose primary role involved data-protection compliance, while 44% had none.

How to interpret this evidence

The measure includes responsibility as part of a wider role and does not mean that 56% employed a dedicated data protection officer. A named lead can improve accountability, but the statistic does not assess the person’s expertise, authority, time allocation or the organisation’s compliance.

Limitations

The denominator is businesses with employees handling digitised personal data, and the report’s question sequence also refers to time spent understanding data-protection law. Results are weighted and self-reported. The survey does not establish whether a statutory data protection officer was required or appointed.

Practical considerations

G&G perspective: name a responsible person, document the limits of the role, provide sufficient time and escalation access, and keep specialist external support available for higher-risk questions. Responsibility should be supported by a current data inventory, incident process and periodic review rather than relying on the title alone.