← Insights

Data protection

A GDPR compliance dashboard that tells the truth

July 2026 · 6 min read

Ask most small businesses how their data protection is going and you get a feeling, not a figure. "Fine, I think." The trouble with a feeling is that it is usually a month behind the facts. There is an open access request nobody has diarised, a breach logged in an email thread and never risk-assessed, and a retention rule that lapsed in spring. None of it is visible, because it lives in four different places.

A compliance dashboard exists to replace the feeling with a number. Not a certificate, not a score out of a hundred - just an honest, current picture of the things a regulator would actually ask about, gathered onto one page you can open before any review.

Why four spreadsheets always drift apart

The natural way to keep data-protection records is one file per job: a RoPA here, a DSAR tracker there, a breach log somewhere else, a retention list in a fourth tab that nobody has opened since it was made. Each is fine on its own. The problem is that no single view ever pulls them together, so the overall position is something you have to reconstruct by hand, which means in practice nobody does. The record that falls behind is always the one you are not looking at.

Putting all four registers in one workbook and rolling them into a single dashboard fixes the structural flaw, not just the tidiness. When the summary reads from the same rows you enter your data into, it cannot be out of date. The dashboard is the registers, counted.

The two clocks that matter most

Of everything a data-protection dashboard can show, two numbers carry disproportionate weight, because they are the two a regulator asks about first.

The one-month DSAR clock. A subject access request must be answered within a calendar month. Miss it and you have breached the individual's rights - a clean, bright-line failure with no ambiguity to hide behind. A good dashboard shows how many requests are open and how many have already gone overdue, without you counting a single day.

The 72-hour breach window. A reportable personal-data breach must reach the ICO within 72 hours of detection. In the middle of an incident, the deadline is the easiest thing to lose. The dashboard should surface how many breaches are in play this year and how many have passed their report-by window - and it should turn that red on its own, not wait for you to notice.

The point of computing these rather than tracking them by hand is not convenience. It is that the failure mode of manual tracking is silence: nothing tells you the deadline has passed. A clock that works itself out fails loudly instead, which is the only kind of failure you can act on.

What belongs on the page

Beyond the two clocks, a dashboard earns its place by answering the questions a review actually asks:

Each of these is a single figure or a small chart. Together they are the difference between "fine, I think" and "here, look."

Using it as an instrument, not an ornament

A dashboard only tells the truth if the records underneath it are kept current, so the discipline is simple: log the request when it arrives, record the breach when it is detected, set the retention rule when the record type is created. Do that and the summary maintains itself. Then open it at every management or data-protection review and let the flagged work set the agenda - the overdue rows have already put their hands up.

That is the whole idea. Not a compliance theatre of green ticks, but one page that reflects reality closely enough that you would be comfortable turning the screen round.

Four registers, one honest page

RoPA, DSAR log, breach log and retention schedule in a single workbook, rolled into a dashboard where the one-month and 72-hour clocks compute themselves and flag what is overdue. A template to run your records, not legal advice.

Get the GDPR Compliance Tracker on Etsy

Never miss a guide

New articles and templates, straight to your inbox. Plus a free tool to start.

By subscribing you consent to receive emails from Axiom. Your address is stored with Kit, our email provider, and never shared. Unsubscribe any time via the link in every email. Privacy policy.