Data protection
Getting your GDPR house in order without a consultant
Most small organisations meet UK GDPR the same way: a scare, a search, and an afternoon spent copying a free policy that mentions clauses nobody in the building has ever kept a record against. The policy goes in a folder. The records it promises never get made. And the first person to ask "show me" - a customer, an auditor, or the ICO after a complaint - finds a document with nothing behind it.
Compliance in practice is not one grand document. It is a small, coherent set of things: two documents that say what you do, and a handful of live records that prove you actually do them. Get that set right and you are in genuinely good shape. This is the map.
The two documents that face outward and in
Everything starts with two policy documents, and it helps to be clear which audience each serves.
The Data Protection Policy faces inward. It is your internal statement of how the organisation handles personal data: the principles you work to, the lawful bases you rely on, how you honour individual rights, who owns what, how you deal with a breach, how long you keep records, and when the policy itself gets reviewed. Staff should be able to read it and know what is expected of them.
The Privacy Notice faces outward. It is the plain-language explanation you owe the people whose data you hold - customers, website visitors, anyone: what you collect, why, the lawful basis for it, who you share it with, how long you keep it, and how someone exercises their rights or complains to the regulator. This is the one that belongs on your website.
Write both in your own words and edit them until they describe how you genuinely operate. A policy that overclaims is worse than an honest one, because every promise it makes is a record someone can later ask to see.
The six records that make it real
A policy is a claim. The registers are the evidence. Six of them carry the practical weight of small-business GDPR.
- Record of Processing Activities (RoPA). Article 30 asks you to keep a record of what personal data you process and why. This is the backbone - everything else refers back to it.
- DSAR Log. When someone asks for their data, a one-month statutory clock starts. The log times every request so none quietly runs past its deadline.
- Data Breach Register. A reportable breach must reach the ICO within 72 hours of detection. The register runs that clock and records the decision either way.
- DPIA. For higher-risk processing, a Data Protection Impact Assessment records the risks and how you have reduced them, before you start.
- Data Retention Schedule. How long you keep each type of record and when you dispose of it - the answer to "why do you still have this?"
- Compliance Tracker. A single dashboard that pulls the live position together so you can walk into a review knowing where you stand.
None of these is exotic. Each is a spreadsheet you keep current. The discipline is not in building them once; it is in the records staying alive after the initial push - which is exactly why the deadlines that matter should compute themselves rather than depend on somebody remembering to count days.
How the pieces connect
The reason to treat these as one set, not eight separate downloads, is that they are supposed to agree with each other. Your Privacy Notice tells people how long you keep their data; your Retention Schedule is where that promise is actually set. Your policy says you handle access requests within a month; your DSAR Log is where that is timed and proven. When the documents and the records are written together, they line up. When they are collected piecemeal from five different sources, they contradict each other, and the contradictions are what an assessor notices first.
A realistic order of work
You do not need to do all of it in one sitting. A sensible sequence:
- Start with the RoPA. Listing what data you actually process forces the honest conversation and informs everything downstream.
- Adapt the two policy documents to match what the RoPA revealed - replace the placeholders, cut what does not apply, and publish the Privacy Notice.
- Stand up the live logs - DSAR, breach, retention - so that the day a request or an incident arrives, the record already exists and the clock starts on its own.
- Keep the tracker open at reviews. Compliance is not a project that finishes; it is a habit that shows.
A consultant would charge for the map more than the templates. The map is not complicated. The work is in doing it honestly and keeping it current - and having a coherent set of documents that already agree with one another removes most of the friction that stops people finishing.
The whole set, built to agree with itself
Data Protection Policy and Privacy Notice plus the six working registers - RoPA, DSAR, breach, DPIA, retention and a compliance tracker - written to one standard so the policy and the records actually line up. Templates to adapt, not legal advice.