Skip to main content
Stuart Parkins
Stuart Parkins
Helping small businesses work smarter.

Data Privacy and Protection

Practical data protection for small businesses — built into your systems and documented properly, rather than filed away and forgotten.

Book A Data Privacy and Protection Call

About my Data Privacy and Protection Services

Every business holding customer, patient, client, employee or supplier data has data protection obligations, and there's no small business exemption from UK Privacy law. What varies is how much work it takes to meet them. A simple fact find can answer that.


My data privacy service and advice is practical and is based on ICO guidance.My advice is not legal advice.


I've spent over 25 years working with business data, and data protection sits inside every migration, automation, reporting build and AI project I run. If you run a business at the very least you need a suitable mininal level of data protection and associated documentation towards compliance.

What I offer

Data Privacy Fact Find

A free introductory conversation about what personal data your business holds, which systems it sits in, and where your obligations are likely to bite. Enough to tell you whether you have a real gap or a documentation exercise.

Privacy Audit

A structured review of how personal data is handled across your systems: what you hold, where it came from, who has access, how long it's retained, where it's transferred, and how each of those stands against UK GDPR expectations. You get a written report with prioritised, plain-English actions.

ROPA and Document Set

Your Record of Processing Activities, plus the supporting documents that go with it — data inventory, retention schedule, subject access request process, data protection complaints process, breach response steps, and supporting content for your privacy notice. Written so you can maintain them, not filed and forgotten.

Implementation

Putting the findings into practice in your systems: access controls and permissions, retention and deletion rules, field-level restrictions, secure export and transfer routes, audit logging, and the automation to make retention happen rather than depend on someone remembering.

Ongoing Advisory

Regular input as your systems and obligations change — new tools, new integrations, new AI use. Where a business needs a formally appointed Data Protection Officer we can discuss that separately, though most small businesses aren't required to appoint one.


Areas of Data Privacy I cover

Data inventory and mapping 

Establishing what personal data you hold and where, across CRM, accounts, email, helpdesk, spreadsheets and backups. Most compliance questions become straightforward once this exists, and it's the piece most often missing.

Lawful basis and purpose 

Documenting why you hold each category of data and what you use it for. The Data (Use and Access) Act 2025 added a "recognised legitimate interests" basis for certain processing, which is worth understanding before defaulting to consent.

Retention and deletion 

Agreeing how long each type of record is kept and building rules that action it. Retention is one of the areas where automation genuinely helps.

Access control 

Who can see, export and delete what, across every system. Usually the quickest meaningful improvement available.

Subject access and complaints 

A working process for handling requests from individuals, and the formal data protection complaints procedure that became a statutory requirement for UK organisations in June 2026.

Data transfers and third parties 

What leaves your systems, where it goes, and what your processor arrangements say. Integrations and AI tools both belong in this conversation.

AI and privacy 

What can safely go into which AI tool, what your provider's data terms actually say, and the guardrails that keep AI use inside your obligations.

Backup and recoverability 

Data protection includes being able to protect and recover data, which connects directly to my backup and restore work.


Who is my Data Privacy and Protection Service for?

This is for UK small businesses holding personal data in business systems, which is nearly all of them.


A frequent trigger is a customer or contract requiring evidence — a tender question, a supplier due diligence form, or an enterprise client asking for your ROPA and retention policy. Producing those from scratch under time pressure is uncomfortable; having them ready is straightforward.


It also suits businesses about to do something significant with their data: a migration, a new CRM, a first AI project, or connecting systems that have never shared data before. Handling privacy as part of that work costs far less than revisiting it afterwards.


Businesses that have grown into several systems often reach a point where nobody can say confidently where all the personal data sits. That's a mapping exercise, and it's usually a day's work rather than a project.


And if you've registered with the ICO, written a privacy notice at some point, and done little since, a review will tell you where you genuinely stand.

Benefits of my Data Privacy and Protection Service 

What this gives you:

  • A clear picture of what personal data you hold and where it sits.
  • Documentation you can hand over when a client or tender asks for it.
  • Retention and access rules that operate in your systems, not just on paper.
  • Privacy handled as part of migrations, automations, reporting and AI work.
  • Plain-English actions in priority order, sized for a small business.
  • A named person who understands both the obligations and your systems.

How my Data Privacy and Protection Service works

Following your enquiry:

  1. I  start with a free Data Privacy Fact Find — a conversation about what data your business holds, which systems hold it and where you are with data protection.
  2. From there I carry out the Privacy Audit: a structured review across your systems, resulting in a written report with initial ROPA and  prioritised actions.
  3. I produce your ROPA and supporting document set, written to be maintained rather than shelved.
  4. Implementation follows: access, retention, transfer and logging changes made in your systems, tested and documented.
  5. You have direct access to me throughout, and I can stay involved as your systems and obligations change.

Pricing of my Data Privacy and Protection Service

Privacy Fact Find

Free 30 Minutes

Privacy Audit

From £199*

Privacy Document Pack

By Quotation*

*All privacy and compliance quotes are based on the number of systems, the volume and sensitivity of data, and the documentation required. I also work to fixed price project rates, or day/hourly rate consultancy pricing based on my current contract rates. 

Frequently Asked Data Privacy and Protection Questions

Does UK Privacy/GDPR apply to a very small business?

Yes. There's no exemption based on size, turnover or number of staff — if you hold personal data about customers, employees or suppliers, the obligations apply. What scales with size is how much work meeting them takes. A sole trader with one CRM and an accounts package has a much simpler position than a business running six systems, but both need to know what they hold and why.

Do I need to register with the ICO?

My suggestion - yes register if you are processing perosnal data.Most UK businesses processing personal data need to pay the annual data protection fee, with some exemptions. Fees are tiered by size, with the lowest tier applying to organisations of no more than 10 staff or turnover up to £632,000. Being exempt from the fee doesn't exempt you from UK GDPR itself. The ICO's own guidance covers whether you need to pay: https://ico.org.uk/for-organisations/data-protection-fee/data-protection-fee/

What is a ROPA and do I need one?

A Record of Processing Activities documents what personal data you process, why, who it's shared with, how long it's kept and how it's protected. Formally, smaller organisations have some scope for a reduced record, but in practice most businesses benefit from having one. It's also the natural output of mapping where your data sits, which is worth doing regardless.

https://ico.org.uk/for-organisations/advice-and-services/audits/data-protection-audit-framework/toolkits/records-management/data-mapping-and-recording/

What changed under the Data (Use and Access) Act 2025?

The UK ICO is a good reference poin to see the changes and stay up to date. e.g. A separate requirement for organisations to operate a formal data protection complaints process took effect in June 2026. The ICO's guidance is the reference point: https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/

How long should we keep customer data?

There's no single answer — retention periods depend on the type of record and why you hold it. Some are set by other obligations, such as accounting records for tax purposes; others are a judgement about how long the data remains necessary for the purpose you collected it for. The practical approach is to agree a period for each category, write it down, and build rules that action it.  See the ICO :https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/storage-limitation/

Can we use AI with customer data?

It depends on the tool and the data. Business-grade AI services with a proper data processing agreement generally keep your data within your account and don't use it to train shared models; you are responsible for the AI Guardrails and privacy so check the settings in your AI tools.  Document in your ROPA and cross check the provider's terms, what categories of data you're proposing to use, whether individuals would reasonably expect that use, and what your lawful basis is. Avoid explicit private data use within general tools.

https://ico.org.uk/for-organisations/advice-and-services/audits/data-protection-audit-framework/toolkits/artificial-intelligence/governance-and-accountability-in-ai/

What should we do if data is lost or exposed?

Have a process agreed before you need it: how a suspected breach is reported internally, who assesses it, what gets recorded, and the criteria for notifying the ICO and affected individuals within the required timeframes. Alongside that, being able to recover data matters — protection includes availability, which is where backup and restore connects directly to compliance.

https://ico.org.uk/for-the-public/i-m-worried-about-how-an-organisation-has-handled-my-information/what-is-a-data-breach/

Is your Privacy service legal advice?

No. I provide practical, systems-side data protection support and the documentation that goes with it. Where a question needs a legal opinion — a complex lawful basis assessment, contract drafting, or a regulatory dispute — I'll tell you, and you should take advice from a data protection solicitor. Most routine compliance work doesn't require one if you follow the ICO guidance.

Get In Touch For Data Privacy and Protection Services

Could you say today exactly what personal data your business holds, and where?

If the answer isn't a confident yes, that's the place to start. Let's have a chat.

Get In Touch About Data Privacy