Skip to main content
 
 

Compliance Without the Headache.

GDPR, SRA, FCA, and industry regulations made manageable. We help you understand what you actually need to do, then help you do it. Plain English, practical advice.

Compliance without the confusion

GDPR, industry regulations, data protection requirements. You know you need to comply, but working out exactly what that means for your business can be overwhelming. We help you cut through the jargon and actually get compliant.

🇪🇺

GDPR / UK GDPR

Data protection for all businesses

⚖️

SRA Standards

Solicitors Regulation Authority

💼

FCA Requirements

Financial Conduct Authority

📊

ICAEW / ACCA

Accountancy body requirements

What we help with

Practical compliance support for small businesses.

📋

Gap Analysis

We review what you’re currently doing against what you should be doing. Clear report on what’s working, what’s missing, and what needs fixing first.

📝

Policy Development

We write the policies you actually need. Data protection, acceptable use, information security. Written in plain English that your team will understand.

📊

Data Mapping

Work out what personal data you hold, where it lives, who has access, and how long you keep it. Essential for GDPR compliance.

🔍

Audit Preparation

Get ready for regulatory audits or client due diligence. We help you gather evidence, fill gaps, and present your compliance clearly.

👥

Staff Training

Train your team on their data protection responsibilities. What they can and can’t do with personal data. How to spot and report issues.

🚨

Breach Response

Prepare for data breaches before they happen. Know what to do, who to notify, and how to document everything properly.

GDPR: What it actually means for you

GDPR applies to every business that handles personal data. That’s names, email addresses, phone numbers, anything that identifies a person. The rules aren’t complicated, but there’s a lot to get right.

Key GDPR requirements:


Know what personal data you hold and why

Have a lawful basis for processing it

Keep it secure and only for as long as needed

Tell people what you’re doing with their data

Respond to subject access requests within a month

Report serious breaches within 72 hours

What happens if you get it wrong

  • Fines up to £17.5 million or 4% of turnover
  • Enforcement notices from the ICO
  • Reputational damage and lost business
  • Compensation claims from affected individuals
  • Professional body sanctions (for regulated firms)

The good news

The ICO wants to help businesses get it right, not catch them out. For small businesses doing their best to comply, enforcement is rare. What matters is showing you’ve made reasonable efforts and have proper processes in place.

Industry-specific compliance

Different industries have different requirements. We help you meet yours.

⚖️ Law Firms (SRA)

The SRA requires firms to have effective systems and controls for information security. Client confidentiality isn’t just ethical, it’s regulatory.

  • Information security policies
  • Client data protection measures
  • Breach notification procedures
  • Staff training and awareness

📊 Accountants (ICAEW/ACCA)

Professional body requirements around confidentiality, data handling, and client money. Plus increasing demands from clients for security assurance.

  • Client confidentiality controls
  • Secure document handling
  • Anti-money laundering systems
  • Practice management security

💼 Financial Services (FCA)

FCA-regulated firms have specific requirements around operational resilience, data security, and third-party risk management.

  • Operational resilience requirements
  • Outsourcing and third-party controls
  • Cyber security expectations
  • Incident reporting obligations

🏥 Healthcare

Patient data is special category data under GDPR. Healthcare providers have additional requirements around confidentiality and data sharing.

  • NHS Data Security Standards
  • Patient confidentiality
  • Secure clinical systems
  • Data sharing agreements

Questions people ask

Straight answers about compliance and regulations.

Do I need to register with the ICO?

Probably, if you process personal data. Most businesses do. Registration costs £40-60 per year for small organisations. There are some exemptions, but most businesses handling customer or employee data need to register. We can check whether you need to and help you register if so.

Do I need a Data Protection Officer?

Most small businesses don’t need a formal DPO. You only legally need one if you’re a public authority, do large-scale monitoring of individuals, or process special category data on a large scale. But you do need someone responsible for data protection. We can help you work out what’s appropriate for your size.

What policies do we actually need?

At minimum: a privacy policy (for your website and customers), a data protection policy (internal), and an information security policy. Depending on your industry, you might also need acceptable use policies, data retention schedules, and subject access request procedures. We’ll tell you exactly what you need.

How long does compliance take to sort out?

It depends where you’re starting from. A basic GDPR compliance project for a small business might take 4-8 weeks. Getting policies in place, mapping your data, fixing obvious gaps. It’s not a one-off project though. Compliance needs ongoing attention. We can help you build sustainable processes.

We had a data breach. What do we do?

Don’t panic, but act quickly. Contain the breach, assess what data was affected, and document everything. You have 72 hours to report serious breaches to the ICO. Not all breaches need reporting, but you need to make that decision quickly. If you’re not sure, call us. We can help you assess and respond.

Our clients are asking about our security. How do we respond?

This is increasingly common. Larger clients want assurance that their suppliers have proper security. We can help you complete security questionnaires, put together evidence packs, and get certifications like Cyber Essentials if that would help. Sometimes having clear documentation is all you need.

Need help with compliance?

Let’s talk about your regulatory requirements and work out what you actually need to do. Plain English, practical advice.

Book a Compliance Review

Or just email us: [email protected] – we usually reply within a day.