Data Privacy and Protection
Practical data protection for small businesses — built into your systems and documented properly, rather than filed away and forgotten.
About my Data Privacy and Protection Services
Every business holding customer, patient, client, employee or supplier data has data protection obligations, and there's no small business exemption from UK Privacy law. What varies is how much work it takes to meet them. A simple fact find can answer that.
My data privacy service and advice is practical and is based on ICO guidance.My advice is not legal advice.
I've spent over 25 years working with business data, and data protection sits inside every migration, automation, reporting build and AI project I run. If you run a business at the very least you need a suitable mininal level of data protection and associated documentation towards compliance.
What I offer
Data Privacy Fact Find
A free introductory conversation about what personal data your business holds, which systems it sits in, and where your obligations are likely to bite. Enough to tell you whether you have a real gap or a documentation exercise.
Privacy Audit
A structured review of how personal data is handled across your systems: what you hold, where it came from, who has access, how long it's retained, where it's transferred, and how each of those stands against UK GDPR expectations. You get a written report with prioritised, plain-English actions.
ROPA and Document Set
Your Record of Processing Activities, plus the supporting documents that go with it — data inventory, retention schedule, subject access request process, data protection complaints process, breach response steps, and supporting content for your privacy notice. Written so you can maintain them, not filed and forgotten.
Implementation
Putting the findings into practice in your systems: access controls and permissions, retention and deletion rules, field-level restrictions, secure export and transfer routes, audit logging, and the automation to make retention happen rather than depend on someone remembering.
Ongoing Advisory
Regular input as your systems and obligations change — new tools, new integrations, new AI use. Where a business needs a formally appointed Data Protection Officer we can discuss that separately, though most small businesses aren't required to appoint one.
Areas of Data Privacy I cover
Data inventory and mapping
Lawful basis and purpose
Retention and deletion
Access control
Subject access and complaints
Data transfers and third parties
AI and privacy
Backup and recoverability
Who is my Data Privacy and Protection Service for?
This is for UK small businesses holding personal data in business systems, which is nearly all of them.
A frequent trigger is a customer or contract requiring evidence — a tender question, a supplier due diligence form, or an enterprise client asking for your ROPA and retention policy. Producing those from scratch under time pressure is uncomfortable; having them ready is straightforward.
It also suits businesses about to do something significant with their data: a migration, a new CRM, a first AI project, or connecting systems that have never shared data before. Handling privacy as part of that work costs far less than revisiting it afterwards.
Businesses that have grown into several systems often reach a point where nobody can say confidently where all the personal data sits. That's a mapping exercise, and it's usually a day's work rather than a project.
And if you've registered with the ICO, written a privacy notice at some point, and done little since, a review will tell you where you genuinely stand.
Benefits of my Data Privacy and Protection Service
What this gives you:
- A clear picture of what personal data you hold and where it sits.
- Documentation you can hand over when a client or tender asks for it.
- Retention and access rules that operate in your systems, not just on paper.
- Privacy handled as part of migrations, automations, reporting and AI work.
- Plain-English actions in priority order, sized for a small business.
- A named person who understands both the obligations and your systems.
How my Data Privacy and Protection Service works
Following your enquiry:
- I start with a free Data Privacy Fact Find — a conversation about what data your business holds, which systems hold it and where you are with data protection.
- From there I carry out the Privacy Audit: a structured review across your systems, resulting in a written report with initial ROPA and prioritised actions.
- I produce your ROPA and supporting document set, written to be maintained rather than shelved.
- Implementation follows: access, retention, transfer and logging changes made in your systems, tested and documented.
- You have direct access to me throughout, and I can stay involved as your systems and obligations change.
Pricing of my Data Privacy and Protection Service
Privacy Fact Find
Free 30 Minutes
Privacy Audit
From £199*
Privacy Document Pack
By Quotation*
*All privacy and compliance quotes are based on the number of systems, the volume and sensitivity of data, and the documentation required. I also work to fixed price project rates, or day/hourly rate consultancy pricing based on my current contract rates.
Frequently Asked Data Privacy and Protection Questions
Yes. There's no exemption based on size, turnover or number of staff — if you hold personal data about customers, employees or suppliers, the obligations apply. What scales with size is how much work meeting them takes. A sole trader with one CRM and an accounts package has a much simpler position than a business running six systems, but both need to know what they hold and why.
A Record of Processing Activities documents what personal data you process, why, who it's shared with, how long it's kept and how it's protected. Formally, smaller organisations have some scope for a reduced record, but in practice most businesses benefit from having one. It's also the natural output of mapping where your data sits, which is worth doing regardless.
The UK ICO is a good reference poin to see the changes and stay up to date. e.g. A separate requirement for organisations to operate a formal data protection complaints process took effect in June 2026. The ICO's guidance is the reference point: https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/
There's no single answer — retention periods depend on the type of record and why you hold it. Some are set by other obligations, such as accounting records for tax purposes; others are a judgement about how long the data remains necessary for the purpose you collected it for. The practical approach is to agree a period for each category, write it down, and build rules that action it. See the ICO :https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/storage-limitation/
It depends on the tool and the data. Business-grade AI services with a proper data processing agreement generally keep your data within your account and don't use it to train shared models; you are responsible for the AI Guardrails and privacy so check the settings in your AI tools. Document in your ROPA and cross check the provider's terms, what categories of data you're proposing to use, whether individuals would reasonably expect that use, and what your lawful basis is. Avoid explicit private data use within general tools.
Have a process agreed before you need it: how a suspected breach is reported internally, who assesses it, what gets recorded, and the criteria for notifying the ICO and affected individuals within the required timeframes. Alongside that, being able to recover data matters — protection includes availability, which is where backup and restore connects directly to compliance.
No. I provide practical, systems-side data protection support and the documentation that goes with it. Where a question needs a legal opinion — a complex lawful basis assessment, contract drafting, or a regulatory dispute — I'll tell you, and you should take advice from a data protection solicitor. Most routine compliance work doesn't require one if you follow the ICO guidance.
Could you say today exactly what personal data your business holds, and where?
If the answer isn't a confident yes, that's the place to start. Let's have a chat.

