← Insights

Data protection

Getting your GDPR house in order without a consultant

July 2026 · 7 min read

Most small organisations meet UK GDPR the same way: a scare, a search, and an afternoon spent copying a free policy that mentions clauses nobody in the building has ever kept a record against. The policy goes in a folder. The records it promises never get made. And the first person to ask "show me" - a customer, an auditor, or the ICO after a complaint - finds a document with nothing behind it.

Compliance in practice is not one grand document. It is a small, coherent set of things: two documents that say what you do, and a handful of live records that prove you actually do them. Get that set right and you are in genuinely good shape. This is the map.

The two documents that face outward and in

Everything starts with two policy documents, and it helps to be clear which audience each serves.

The Data Protection Policy faces inward. It is your internal statement of how the organisation handles personal data: the principles you work to, the lawful bases you rely on, how you honour individual rights, who owns what, how you deal with a breach, how long you keep records, and when the policy itself gets reviewed. Staff should be able to read it and know what is expected of them.

The Privacy Notice faces outward. It is the plain-language explanation you owe the people whose data you hold - customers, website visitors, anyone: what you collect, why, the lawful basis for it, who you share it with, how long you keep it, and how someone exercises their rights or complains to the regulator. This is the one that belongs on your website.

Write both in your own words and edit them until they describe how you genuinely operate. A policy that overclaims is worse than an honest one, because every promise it makes is a record someone can later ask to see.

The six records that make it real

A policy is a claim. The registers are the evidence. Six of them carry the practical weight of small-business GDPR.

None of these is exotic. Each is a spreadsheet you keep current. The discipline is not in building them once; it is in the records staying alive after the initial push - which is exactly why the deadlines that matter should compute themselves rather than depend on somebody remembering to count days.

How the pieces connect

The reason to treat these as one set, not eight separate downloads, is that they are supposed to agree with each other. Your Privacy Notice tells people how long you keep their data; your Retention Schedule is where that promise is actually set. Your policy says you handle access requests within a month; your DSAR Log is where that is timed and proven. When the documents and the records are written together, they line up. When they are collected piecemeal from five different sources, they contradict each other, and the contradictions are what an assessor notices first.

A realistic order of work

You do not need to do all of it in one sitting. A sensible sequence:

A consultant would charge for the map more than the templates. The map is not complicated. The work is in doing it honestly and keeping it current - and having a coherent set of documents that already agree with one another removes most of the friction that stops people finishing.

The whole set, built to agree with itself

Data Protection Policy and Privacy Notice plus the six working registers - RoPA, DSAR, breach, DPIA, retention and a compliance tracker - written to one standard so the policy and the records actually line up. Templates to adapt, not legal advice.

Get the GDPR Compliance Pack on Etsy

Never miss a guide

New articles and templates, straight to your inbox. Plus a free tool to start.

By subscribing you consent to receive emails from Axiom. Your address is stored with Kit, our email provider, and never shared. Unsubscribe any time via the link in every email. Privacy policy.