SME Intelligence — GDPR Compliance Kit

GDPR Compliance Kit

Audit your data practices, generate the documents you need, and track your compliance — all guided, all in plain English, all in your browser.

← Back to Shop
👁 Interactive Preview — explore all 6 modules and see exactly what's included.
Policy generation, templates, and exports unlock with purchase.
Buy Now — £19.99 →
6
Modules
Art.30
Processing Register
23
ICO Checklist Items
5
SAR Templates

Your business details

Check at ico.org.uk — most businesses processing personal data must register

What personal data do you collect?

Tick everything that applies. This drives your privacy policy and processing register.

Who do you share data with?

Data processing register (Article 30)

UK GDPR Article 30 requires you to maintain a record of your processing activities. The full version auto-populates this from your audit answers.
Processing ActivityData CategoriesLawful BasisRetentionShared With
Customer enquiriesNames, email, phoneLegitimate interest2 years
Order processingNames, address, paymentContract6 years (HMRC)Accountant
Employee recordsHR, payroll, NI numbersContract / Legal6 years after leavingPayroll provider
🔒
Purchase to edit & export your register
The full version auto-populates from your audit data, lets you edit every row, add activities, and export as CSV.
Buy Now — £19.99 →

Privacy policy generator

Generates a full UK GDPR-compliant privacy policy based on your audit data. Configure your cookie and international settings below.

1. Who we are

Acme Ltd is the data controller responsible for your personal data.

Registered address: 1 High Street, London, SW1A 1AA

2. What personal data we collect

We may collect and process the following categories of personal data:

Names and contact details, email addresses, phone numbers, postal addresses, payment and bank details...

3. How we collect your data

We collect personal data through website contact forms, email correspondence, phone calls, in person meetings...

4. Why we process your data

Under UK GDPR, we must have a lawful basis for processing your personal data...

🔒
Purchase to generate your privacy policy
The full version generates a complete, tailored privacy policy you can copy as text or HTML and paste straight onto your website.
Buy Now — £19.99 →

Subject access request (SAR) procedure

Under UK GDPR Article 15, anyone can ask what personal data you hold about them. You must respond within one calendar month.
1
Receive and log the request
A SAR can arrive by any channel — email, letter, phone, even verbally. The person does not need to say "subject access request" or cite GDPR. Log the date received immediately — the clock starts now.
2
Verify identity
If you are not certain who is asking, request proof of identity (photo ID + address confirmation). The one-month deadline pauses until you receive verification.
3
Search all systems
Search email, CRM, spreadsheets, paper files, backups, HR records, CCTV — everywhere personal data might be held.
4
Review and redact
You must not disclose personal data about other people. Redact third-party names and identifying details.
5
Prepare the response
Provide: what data you hold, why you process it, who you share it with, how long you keep it, and their rights.
6
Send within one month
Respond securely. Free of charge. If you need more time, you can extend by two months — but you must tell them within the first month.

Templates included

📤
Acknowledgement Letter
📂
ID Verification Request
📄
SAR Response Letter
🕛
Extension Notice
📑
SAR Log Template
🔒 Templates unlock with purchase — pre-populated with your business details

Data breach response plan

If personal data is lost, stolen, or accessed by someone who shouldn't have it, you may need to report it to the ICO within 72 hours.
Immediately (Hour 0)
Contain the breach
Stop it getting worse. Change passwords, revoke access, disconnect affected systems, retrieve lost devices. Do not destroy evidence.
Within 1 hour
Assess severity
What data was involved? How many people affected? What's the likely harm? Is data encrypted?
Within 24 hours
Decide: report to ICO?
You must report to the ICO if the breach is likely to result in a risk to people's rights and freedoms. If in doubt, report.
Within 72 hours
Report to ICO (if required)
Report via ico.org.uk. You'll need: what happened, what data, how many people, likely consequences, and what you've done.
As soon as possible
Notify affected individuals (if high risk)
If the breach is likely to result in high risk to individuals, you must tell them directly.
Within 1 week
Investigate root cause
How did it happen? Document everything — the ICO may ask for this.
Within 1 month
Implement preventive measures
What changes will prevent this from happening again? Document the changes and who is responsible.
🔒 Breach assessment form, severity calculator, and breach log export unlock with purchase

ICO compliance checklist — sample

Score your business against the ICO's key requirements. The full version has 23 questions across 5 categories.
📜 Lawfulness & Transparency
You have identified a lawful basis for every type of personal data you process
Article 6
You have a privacy policy that explains what data you collect and why
Articles 13 & 14
Your privacy policy is easy to find on your website
Article 12
🔒 Data Security
Personal data is protected by passwords, encryption, or access controls
Article 32
🔒 19 more questions + compliance scoring + gap analysis unlock with purchase
✅ What's included in the full version
Get GDPR-ready today. Everything you need for less than the cost of an hour with a solicitor.
Buy Now — £19.99 →
🔒 Everything runs in your browser. No data is uploaded or sent anywhere.