Data protection that holds up to scrutiny
Tailored UK GDPR and EU GDPR compliance for small and mid-sized businesses, from data mapping to breach response.
GDPR sets the standard for how personal data is collected, used and protected. Since Brexit the UK follows its own UK GDPR, which mirrors the EU regulation closely. If you serve customers in both, you will likely need to meet both, and the work overlaps almost entirely.
Getting compliant
Compliance starts with understanding what personal data you collect and why, then closing the gaps between your current practices and what the regulation expects.
- Data mapping and records of processing
- A lawful basis for each processing activity
- Privacy notices and consent mechanisms
- Processes for data subject rights requests
- Technical and organisational security measures
- DPIAs for high-risk processing
- Breach detection and response planning
The paperwork we prepare
- Data protection policy
- Website and customer privacy notices
- Data processing agreements with suppliers
- Retention schedule
- Breach response plan and log
Roles
Some organisations must appoint a Data Protection Officer. We offer the DPO role as a service, alongside vCISO support and training for HR, marketing, IT and customer-facing teams.
What is at stake
Under UK GDPR, the most serious infringements can attract fines of up to £17.5 million or 4% of global annual turnover, whichever is higher. The reputational damage, legal claims and disruption that follow a breach are often the larger cost.
Get a clear plan for better security
Tell us where you are today and we will recommend the quickest, most cost-effective path forward. We reply within one to two business days.