250-Employee Exemption
The 250-Employee Exemption refers to a limited relief under data protection law that reduces the record-keeping obligations for organisations with fewer than 250 staff. It is commonly misunderstood as a blanket exemption from data protection rules for smaller organisations, but this is not correct, it only narrows one specific documentation duty, and even that relief falls away in certain situations. Organisations under 250 employees still generally have to comply with the rest of their data protection obligations.
The term describes the qualified derogation associated with Article 30(5) of the UK GDPR (and the corresponding EU GDPR provision) concerning the obligation to maintain records of processing activities (ROPA). Per ICO guidance, an organisation employing fewer than 250 people needs only to document processing in more limited circumstances rather than being wholly relieved of the record-keeping duty; the relief is subject to conditions, so that an organisation below the threshold may still be required to keep records where its processing is likely to result in a risk to the rights and freedoms of data subjects, is not occasional, or involves special category or criminal offence data (practitioners should verify the precise conditions against the current text of Article 30(5)). The label '250-employee exemption' is widely characterised as a myth insofar as it does not confer a general exemption from the GDPR as a whole, it addresses only one accountability documentation obligation and does not affect other duties such as lawful basis, transparency, security, or data subject rights. Note that the EU and UK regimes may diverge over time and that member state or national implementing law can affect the position; readers should confirm current requirements against the applicable regulatory text and guidance.
Why it matters
The 250-Employee Exemption is one of the most persistently misunderstood provisions in data protection practice. Many smaller organisations and startups assume that having fewer than 250 employees means they are exempt from the GDPR, or at least from the bulk of its obligations. This is incorrect. As the ICO's guidance and commentary on the so-called '250-employee myth' make clear, the relief attaches only to the duty to maintain records of processing activities (ROPA) under Article 30(5), it is not a general exemption from the Regulation as a whole. Treating it as such can leave an organisation exposed on obligations it never addressed, including lawful basis, transparency, security, and data subject rights.
The practical significance is that the relief is both narrow and conditional. Even the limited documentation relief typically falls away where an organisation's processing is likely to result in a risk to the rights and freedoms of data subjects, is not occasional, or involves special category or criminal offence data. Because many businesses, regardless of headcount, carry out processing that meets one of these triggers, a large number of sub-250 organisations may in practice still need to maintain records. Practitioners should verify the precise conditions against the current text of Article 30(5) rather than relying on the headcount figure alone.
Misreading the exemption also risks distracting from the broader accountability principle. Documentation is only one element of demonstrating compliance, and an organisation that assumes it is off the hook for record-keeping may fail to build the wider governance it still needs. The scope of the relief, and any divergence between the EU and UK regimes over time, should be confirmed against current regulatory guidance and the applicable text.
Who it's relevant to
Inside 250-Employee Exemption
Common questions
Answers to the questions practitioners most commonly ask about 250-Employee Exemption.