Many Business Owners Assume GDPR Is Finished
You updated your privacy policy years ago. So why is data protection suddenly a boardroom topic again?
It arrived in 2018. Privacy policies were updated. Marketing databases were reviewed. New consent processes were introduced. After months of preparation, most organisations breathed a sigh of relief and moved on.
So why are we still talking about GDPR in 2026?
The answer is surprisingly simple.
The underlying principles haven’t changed very much, but the way businesses collect, store and use data has changed dramatically. AI has entered the workplace, cloud applications have multiplied, customers have become more privacy aware, and organisations are increasingly asking one question: “Where exactly is our data stored?”
As a result, data protection is back on the agenda for many UK businesses.
- GDPR’s core principles haven’t changed — but AI, cloud tools and customer expectations have made applying them harder.
- Your organisation stays responsible for data, whether it’s handled by a person, CRM or AI platform.
- Good compliance starts with good data: clean, centralised, and auditable.
- Data residency doesn’t guarantee compliance, but it simplifies governance and builds trust.
- The businesses in the strongest position are those with clean data and sensible processes — not the biggest compliance teams.
The Fundamentals Haven’t Changed
The good news is that GDPR has not been completely rewritten. Businesses are still expected to:
Most organisations already understand these principles. The challenge today isn’t understanding GDPR — it’s applying those principles consistently across an increasingly complex technology landscape.
GDPR Didn’t Expect AI. Your Business Needs To.
When GDPR arrived in 2018, most compliance discussions centred around email marketing, privacy notices and cookie banners. Eight years later, businesses are dealing with something GDPR’s original authors could never have fully anticipated: the widespread adoption of Artificial Intelligence across everyday business operations.
GDPR itself has not been rewritten, but this has happened repeatedly since its introduction. New technologies emerge, businesses adopt them quickly, and regulators are then required to interpret how existing privacy principles apply in a changing environment. AI is simply the latest example.
Problem
Employees are using AI assistants to summarise meetings, draft emails, analyse spreadsheets and answer customer enquiries. Many of these tools sit within the wider Microsoft 365 ecosystem, where organisations are increasingly looking to bring together Outlook, Teams and customer data through a Microsoft 365 CRM integration. Many organisations have adopted these tools far more quickly than they have developed policies to govern them.
The issue is not necessarily the AI itself — it’s understanding what data is being shared, which systems can access it, whether it’s being stored, and who remains responsible for protecting it.
Where you stand
The answer, from a GDPR perspective, is straightforward: your organisation remains responsible. Whether personal information is viewed by an employee, processed by a CRM system or analysed by an AI platform, responsibility for handling it lawfully still sits with the organisation that collected it.
For business owners, this has pushed data governance back into the spotlight. Suddenly, questions that looked settled in 2018 are being asked again:
The businesses that can answer those questions confidently are typically in a much stronger position than those relying on spreadsheets, inboxes and disconnected systems. This is where customer data management becomes essential — good GDPR starts with good customer data management.
Good GDPR Starts With Good Data
Many compliance issues have nothing to do with legal documents. They start with duplicate records, outdated contact information, multiple versions of the same customer, and information scattered across spreadsheets and inboxes.
If customer information exists in five different places, how can you confidently respond to a Subject Access Request?
Poor data quality creates operational headaches and compliance risks. This is one of the reasons CRM systems remain so important: a centralised CRM creates a single source of truth and the visibility needed to manage customer information properly.
OpenCRM’s duplicate management, auditing and reporting tools help organisations maintain cleaner, more accurate records and stronger governance.
Free Download: GDPR in 2026 Health Check
A practical two-page checklist for reviewing:
- ✓ Data quality
- ✓ Retention policies
- ✓ AI governance
- ✓ User access controls
- ✓ Consent management
Data Retention Is Becoming Increasingly Important
Many businesses continue to hold information indefinitely simply because storage is inexpensive and nobody has reviewed their data for years. GDPR takes a different approach — organisations should understand what information they hold, why they hold it, how long they need it, and when it should be reviewed or removed.
Having a documented retention policy is no longer just good practice. It is becoming an essential part of responsible data management.
OpenCRM includes tools to support data retention processes, identify inactive records and manage Right to be Forgotten requests, alongside wider GDPR tools and guidance available to customers.
Privacy Has Become a Trust Issue
Five years ago, customers rarely asked where their information was stored. Today, many do. The rapid growth of AI, cloud software and high-profile cyber incidents has made organisations far more aware of how valuable their information has become.
Customers increasingly want reassurance that their information is secure, being used responsibly, and that they can access or correct it if needed.
Good privacy practices are no longer just about compliance. They are about trust.
In many sectors, trust has become a competitive advantage. The ability to explain where customer data is stored, how it is protected and who can access it can be every bit as important as the software features themselves.
“Over the past year we’ve noticed a significant increase in customers asking where their data is stored and how AI tools interact with customer information. Five years ago, those conversations were relatively rare. Today they’re often part of the very first sales discussion.”
GDPR Is Not a Paper Exercise
Whilst many organisations feel GDPR became yesterday’s news, regulatory scrutiny has continued to increase.
The Information Commissioner’s Office (ICO) continues to investigate data breaches, marketing practices, security controls and the way organisations handle personal information. In recent years, businesses ranging from global brands through to smaller organisations have received significant fines and enforcement action where they failed to adequately protect personal data.
The scale of regulatory activity often surprises business owners.
Data protection remains an active regulatory issue for UK organisations of all sizes, with thousands of incidents continuing to be reported every year.
Including monetary penalties, enforcement notices, reprimands and prosecutions issued against organisations that failed to meet their data protection obligations.
The message is clear. GDPR is no longer a new regulation, but neither has it become irrelevant. Regulators continue to scrutinise how organisations collect, protect, store and process personal information, particularly as new technologies and AI-powered tools become part of day-to-day business operations.
For most businesses, GDPR is no longer about preparing for a new law. It’s about maintaining good operational discipline, protecting customer trust and ensuring that the systems, processes and technologies adopted today continue to meet the same core principles that were introduced back in 2018.
Why More Organisations Are Asking About Data Residency
One of the most noticeable trends in recent years is the growing interest in data residency — organisations wanting to know exactly where their data is stored. This is common across:
To be clear, UK data residency does not automatically make an organisation GDPR compliant. However, it can simplify governance and reduce complexity — offering greater clarity around jurisdiction, fewer concerns over international transfers, simpler supplier assessments and greater confidence during procurement.
UK-hosted, UK-owned. As a UK-owned CRM provider with UK-based support and UK-hosted infrastructure, OpenCRM is frequently chosen by organisations looking for greater visibility and control over their customer data.
Consent Still Matters
Many people associate GDPR with consent forms and email marketing. Whilst consent remains important, particularly for marketing communications, it is only one part of the picture. Businesses should still maintain clear records of communication preferences, marketing subscriptions, consent decisions and customer contact choices.
OpenCRM includes tools to help organisations manage consent and communication preferences as part of a wider customer data management strategy.
GDPR: your data, your rules
We’ve always put data protection at the heart of OpenCRM, with the tools you need to implement your policies and achieve compliance.
Find out more →What Should Businesses Focus On in 2026?
You probably don’t need another major GDPR project. Most organisations will benefit more from focusing on the fundamentals:
Businesses that get these fundamentals right are typically in a much stronger position than those searching for a quick compliance fix.
GDPR Isn’t Over. It’s Just Evolved.
Perhaps that’s the real story. GDPR didn’t disappear after 2018 — it became part of everyday business.
The organisations managing customer information most effectively today are not necessarily those with the largest compliance teams. They’re the organisations with clean data, sensible processes, reliable systems and a culture of accountability.
Whether you’re reviewing an AI tool, responding to a customer request, managing a retention policy or assessing where your data is stored, good GDPR starts with good information. And good information starts with good CRM.
For further reading, the ICO publishes UK GDPR guidance from the ICO, and the UK Government has published guidance on managing AI responsibly.
How OpenCRM Can Help
Whilst we cannot provide legal advice, we can help organisations implement the systems and processes needed to manage customer information more effectively and support their wider compliance objectives.
Data retention tools
Identify inactive records and manage what should be reviewed or removed.
Right to be Forgotten
Manage erasure requests through a structured, auditable process.
Consent & subscriptions
Keep communication preferences and consent decisions in one place.
Audit logging
Full visibility over who accessed or changed what, and when.
Duplicate management
Merge records so you’re always working from a single source of truth.
Customer portal
Let customers view and manage their own information directly.
UK-hosted infrastructure
Customer data stays within UK data centres.
UK-based support
Talk to a UK team who understand your compliance questions.
Frequently Asked Questions
Has GDPR changed since 2018?
The core principles haven’t changed significantly. What’s changed is the technology landscape around them — AI tools, cloud applications and rising customer expectations mean those principles now need to be applied across a far more complex set of systems.
Who is responsible when AI tools process customer data?
Your organisation. Whether personal information is viewed by an employee, processed by your CRM or analysed by an AI platform, responsibility for handling it lawfully still sits with the organisation that collected it.
Does storing data in the UK make us GDPR compliant?
Not automatically. UK data residency doesn’t guarantee compliance on its own, but it does simplify governance — reducing concerns over international transfers and making supplier assessments and procurement more straightforward.
Why does data quality matter for compliance?
Many compliance issues aren’t legal problems — they’re data problems. Duplicate records and information scattered across spreadsheets and inboxes make it hard to respond to Subject Access Requests or confirm deletion. A centralised CRM gives you one accurate source of truth.
Do we still need a data retention policy?
Yes. Organisations should understand what data they hold, why, for how long, and when it should be reviewed or removed. A documented retention policy is increasingly considered essential rather than optional.
Does the ICO really enforce GDPR?
Yes. The Information Commissioner’s Office (ICO) continues to investigate data breaches, cyber security incidents, unlawful marketing activities and the way organisations collect, store and process personal information.
Enforcement is not limited to large corporations. The ICO has taken action against organisations of all sizes, including public sector bodies, charities, SMEs and multinational businesses. Depending on the circumstances, enforcement can include fines, reprimands, enforcement notices and prosecutions.
The reality is that GDPR is no longer a new regulation, but it remains an active area of scrutiny. As organisations adopt new technologies such as AI, cloud applications and automated processes, the ICO continues to assess whether personal data is being handled lawfully, securely and responsibly.
For most businesses, GDPR is less about avoiding fines and more about demonstrating good governance, protecting customer trust and maintaining clear, auditable processes around the information they hold.
Can OpenCRM help with GDPR compliance?
OpenCRM includes data retention tools, Right to be Forgotten processes, consent and subscription management, audit logging, duplicate management and a customer portal, all hosted on UK infrastructure with UK-based support. We can’t provide legal advice, but we can help you implement the systems behind good data governance.
Free Download: GDPR in 2026 Health Check
A practical two-page checklist for reviewing:
- ✓ Data quality
- ✓ Retention policies
- ✓ AI governance
- ✓ User access controls
- ✓ Consent management
Good GDPR starts with good CRM
See how OpenCRM helps you manage customer data with confidence.
Book a demo