What policies do you need?
In the UK, businesses are legally required to have certain policies and procedures in place. The specific policies that a business needs to have can depend on factors such as its size, the sector it operates in, and the activities it undertakes. Below we have listed some of the key policies that you are likely to need to have in place, or be preparing to develop.

Health and safety policy
Every business, regardless of its size, must have a health and safety policy. This policy outlines the company’s commitment to providing a safe and healthy working environment for employees, as well as visitors. It should identify hazards, specify safety procedures, and describe the responsibilities of employees and management. The Health and Safety Executive has a full guide on writing a Health and Safety Policy.
Equal opportunities and anti-discrimination policy
To promote fairness and prevent discrimination, businesses are legally required to have an equal opportunities and anti-discrimination policy. This policy should outline the company’s commitment to diversity and inclusion and provide guidance on preventing discrimination based on factors such as gender, race, age, disability, religion, and sexual orientation. ACAS provide a template to help you get started.
Data Protection (including GDPR compliance)
If your business processes personal data, you must have a data protection policy and comply with the Data Protection Act, which incorporates the General Data Protection Regulation (GDPR). This policy should explain how you handle personal data, the rights of data subjects, and your data protection procedures. The Information Commissioner’s Office (ICO) has guidance on the principles and what they mean in practice.
Whistleblowing policy
A whistleblowing policy is required for businesses with 50 or more employees. It provides a framework for employees to report concerns about wrongdoing within the company while protecting them from retaliation. The Government has provided guidance on creating a whistleblowing policy and related issues.
Environmental policies
Depending on the nature of your business, you may be required to have environmental policies in place to address issues like waste management, energy efficiency, and pollution control. A broad guide to writing an environmental policy is available from NI Business Info.
Anti-bribery and corruption policy
Businesses may wish to establish an anti-bribery and corruption policy to comply with the UK Bribery Act 2010. This policy outlines the company’s stance on preventing bribery and corruption and may include procedures for reporting and addressing potential violations. Although it is not a legal requirement to have a bribery policy for your business, it can be useful to refer to in defence if bribery takes place within the business. The Government has a guidance document for commercial organisations about putting anti-bribery provisions in place.
Privacy and cookie policies
If your business operates a website or processes online data, you must have privacy and cookie policies that comply with data protection and privacy regulations. Openli provides a comprehensive overview of the requirements and how to implement it on your site.
Fire Safety Policy
Businesses are legally required to have a fire safety policy and conduct regular fire risk assessments. These policies help protect employees and visitors in case of fire. The Government has guidance available for those with legal responsibilities (such as business owners).
Please note that this list is not exhaustive, and the specific policies your business needs may vary depending on its size and the sector you operate in. You may wish to consult with legal and compliance experts to check your business is currently compliant. Be aware that regulations and legal requirements may change over time, so it’s important to stay informed and update your policies as needed.

Learn more
Articles
New one stop shop Business Growth Service roadshow kicks off to support firms in the North East
Small Businesses across the UK will benefit from a new support service, bringing together central, devolved, and local support in one place for the first time.
Communications for Small Businesses: Webinar Series
Communications, marketing, PR – these can be complicated to navigate as a small business. But Hey Me is here to help. Our communications workshops have been specially designed to help small businesses just like yours reach your target customers and increase your potential for growth.
Fully Funded Automation & Efficiency Webinar Series
Step into digital with Data Stream's Automation & Efficiency Webinar series. Designed to support small businesses make day-to-day work smoother. This series gives a balanced overview of everything needed to streamline everyday work, through a well-rounded introduction to the digital tools and techniques that make running your business smoother and more managea
Events
25th November 202510:00 am - 4:00 pmFREE
[FULL] Smartphone Video Masterclass: York
Join our one-day hands-on video workshop designed to help businesses of all types and sizes take their first confident steps into video marketing. Whether you're B2B or B2C, a sole trader or a growing team, this workshop will equip you with the essential skills to produce professional, social-media-ready video content in-house. The Growth Hub are happy to be offering these workshops, following exceptional demand last year under North Yorkshire Council’s UKSPF programme.
26th November 202510:00 am - 4:00 pmFREE
Smartphone Video Masterclass: Northallerton
Join our one-day hands-on video workshop designed to help businesses of all types and sizes take their first confident steps into video marketing. Whether you're B2B or B2C, a sole trader or a growing team, this workshop will equip you with the essential skills to produce professional, social-media-ready video content in-house. The Growth Hub are happy to be offering these workshops, following exceptional demand last year under North Yorkshire Council’s UKSPF programme.
28th November 202510:00 am - 11:30 amFREE
🟣 Steps into Digital: AI Agents, Chatbots & LLMs in Business
ChatGPT and AI agents are transforming how businesses interact with data and customers. This session focuses on natural language processing (NLP), chatbots and large language models (LLMs), showing how they can streamline customer service, automate reporting and make company data more accessible to non-technical staff.
Resources
Webinar Series: How to Run a Pop-Up
From pop-up department stores to kitchen takeovers, cool things are popping up and popping off everywhere. In this exciting project, you’ll get to meet some of the teams behind these pop-ups and get their top tips for running a great pop-up.
Webinar Recording: 🟢 Data Protection Essentials
In this engaging and practical webinar series, Privacy Protect Group Ltd will guide you through everything you need to know to build a confident, compliant, and resilient approach to data protection in your business. Whether you’re just starting out or looking to refine your practices, each session is designed to build your understanding step-by-step.
Webinar Series: Data Analytics for Smarter Decisions
Data Analytics for Smarter Decisions, is a nine part online workshop series designed to help businesses at every stage of their data journey, from those just starting out to those ready to explore artificial intelligence and compliance. Each session is practical, jargon free and grounded in real business use cases, ensuring participants leave with tools and knowledge they can apply immediately.









