GDPR Starter Pack
What’s included:
Our GDPR Starter Pack is designed specifically for small and medium-sized businesses that want to get GDPR-ready without unnecessary complexity or legal jargon. It covers the most essential documents and practical steps required to demonstrate compliance, build customer trust, and reduce regulatory risk.
Whether you’re launching a new business or reviewing your existing data practices, this starter pack gives you a strong compliance foundation. Quickly, affordably, and clearly available.
Privacy policy
A clear, compliant privacy policy that explains how your business collects, uses, stores, and protects personal data. Written in plain language and aligned with GDPR transparency requirements, it helps you inform customers and website visitors with confidence.
Data Breach response plan
A straightforward plan outlining what to do if a personal data breach occurs — including internal reporting, assessment, notification duties, and documentation. Designed to help SMEs respond calmly and correctly.
Data retention & deletion guidelines
Clear guidance on how long personal data should be kept and when it should be securely deleted, helping you avoid unnecessary data storage risks.
Cookie notice
A GDPR-compliant cookie notice that explains what cookies you use, why you use them, and how users can manage their preferences. Ideal for websites using analytics, marketing, or functional cookies.
Record of Processing Activities (ROPA)
A simplified record that documents what personal data you process, why you process it, and who you share it with. Tailored to SMEs that don’t need overly complex registers but still want to meet accountability requirements.
GDPR compliance checklist
A practical, step-by-step checklist to help you understand what GDPR expects from your business. It highlights key obligations, common gaps, and simple actions you can take to move toward compliance.
Lawful basis assessment
A practical tool to help you identify and document the lawful basis you rely on for processing personal data (such as consent, contract, or legitimate interests).
Data Subject Access Request (DSAR) procedure
A simple internal procedure explaining how your business should recognise, log, and respond to data subject requests within GDPR timeframes. Helps ensure consistency and avoid missed deadlines.
Employee data privacy
Dedicated standards for staff and contractors explaining how employee data is handled, stored, and retained, a commonly overlooked GDPR requirement for small businesses.