Asked and answered
Frequently asked questions
The questions UK businesses bring to us before starting GDPR work, answered plainly: what a consultant does, what it costs, and what a gap analysis, audit or DPIA actually involves. Anything these do not cover, we will talk through plainly on the scoping call.
What is a GDPR consultant?
A GDPR consultant is a data protection specialist who helps an organisation meet its obligations under the UK GDPR and the Data Protection Act 2018. The work is practical: assessing where you stand, running audits and gap analyses, completing DPIAs, building your records of processing, drafting the policies and notices you are missing, and putting a costed plan in place to close whatever is not compliant.
It is project work with a defined start and end, not an ongoing role. Our consultants scope the piece you need, deliver it against a fixed fee, and hand you evidence you can show a client, an auditor or the ICO. If your organisation instead needs a named Data Protection Officer on an ongoing basis, that is a separate role and a separate service.
Do I need a GDPR consultant?
You do not need one to be compliant, and plenty of small organisations manage their own data protection using the ICO's free guidance. A consultant earns their fee when the stakes or the complexity rise: a client or tender is asking for evidence you cannot yet produce, you are launching something that handles sensitive data, you have had a breach or a data subject complaint, or you simply do not have the time or in-house expertise to work through it properly.
The real test is whether the risk of getting it wrong outweighs the cost of getting help. A short scoping call will tell you which camp you are in, and if the answer is that you can handle it yourself, we will say so.
How much does GDPR consultancy cost?
Indicative fixed-fee pricing is published on our pricing page, banded by organisation size and by deliverable. Project work starts from £1,450, and the fee for your organisation depends on how much personal data you process, how complex your systems are, and which deliverables you need across gap analysis, audit, DPIA and a full compliance project.
Where nearly every other provider keeps its fees behind a call, we set out indicative 'from' prices up front and put the fixed fee in writing once the scoping call has settled the detail. Ad-hoc support that falls outside a fixed scope runs at a day rate.
How much does a DPO cost?
A Data Protection Officer is a distinct, ongoing role rather than a one-off project, so it is priced differently from the consultancy work on this site. The cost of an outsourced or part-time DPO varies with the size of the organisation, the volume and sensitivity of the data, and the level of cover required, and it is charged as a recurring retainer rather than a fixed project fee.
That ongoing DPO role sits with a dedicated data protection officer service, which is separate from what we deliver here. This site handles GDPR project work: audits, gap analyses, DPIAs, records of processing, policies and remediation. If you tell us on a scoping call what you are trying to achieve, we will point you to the right option.
What is a GDPR gap analysis?
A GDPR gap analysis measures your current data protection practices against the requirements of the UK GDPR and identifies exactly where you fall short. It looks at how you collect and use personal data, your lawful bases, your notices and consent, your security measures, your data sharing, retention and your ability to handle data subject rights, then sets out each gap in plain terms.
The output is a prioritised, costed action plan: what to fix, in what order, and what it will take. It is the natural first step for most organisations because it turns a vague sense of exposure into a defined piece of work, and it feeds directly into a fuller audit or a remediation project if you need one.
What is a DPIA, and when is one required?
A Data Protection Impact Assessment is a structured way of identifying and reducing the data protection risks of a project before it goes ahead. It documents what personal data you will process and why, assesses the risk to the people whose data it is, and records the measures you will put in place to keep that risk proportionate.
Under Article 35 of the UK GDPR a DPIA is legally required whenever processing is likely to result in a high risk to individuals. That includes large-scale use of special category data, systematic monitoring of a public area, and the use of new technologies for profiling or automated decisions. The ICO also publishes a list of processing that always requires one. Where you are unsure, a DPIA is good practice and cheap insurance, and we can run it for you or review one you have drafted.
How do you conduct a GDPR audit?
A GDPR audit is a structured review of how your organisation actually handles personal data, tested against the UK GDPR and the ICO's audit framework rather than against what your policies claim. It works through the areas the regulator examines: accountability and governance, records of processing, lawful bases and consent, transparency, data subject rights, security, data sharing and international transfers, retention and breach handling.
In practice we scope the review with you, gather evidence from your systems, documents and the people who run the processes, then test each area and report. The output is a findings report with a red, amber and green rating against each area and a prioritised action plan, so you know what is compliant, what is not, and what to do about it first.
What are the 7 golden rules of GDPR?
The seven rules people mean are the seven data protection principles set out in Article 5 of the UK GDPR, and everything else in the regulation flows from them. They are: lawfulness, fairness and transparency; purpose limitation, meaning you only use data for the reason you collected it; data minimisation, collecting no more than you need; accuracy; storage limitation, keeping data no longer than necessary; integrity and confidentiality, meaning you keep it secure; and accountability.
Accountability is the one that catches organisations out. It is not enough to follow the other six principles; you have to be able to demonstrate that you do, with records, policies and evidence. That is exactly what an audit or gap analysis produces, and why the ICO treats documentation as central to compliance rather than optional.
Does GDPR apply to small businesses and sole traders?
Yes. The UK GDPR applies to any organisation that processes personal data in connection with its activities, and there is no exemption for small businesses or sole traders. A one-person business holding customer or supplier contact details is a data controller with the same core obligations as a large company, including having a lawful basis, being transparent, keeping data secure and honouring individual rights.
What does scale with size is the depth of the paperwork expected of you, not whether the law applies. Most small organisations also need to pay the ICO's annual data protection fee unless they qualify for a specific exemption. The practical answer is to size your compliance to the personal data you actually hold, which is precisely what a gap analysis helps you do.
What is the minimum company size for GDPR?
There is no minimum. The UK GDPR is triggered by the processing of personal data, not by headcount or turnover, so it applies from the first employee, customer or supplier record you hold. The common belief in a size threshold usually comes from one specific provision: organisations with fewer than 250 employees are relieved of part of the formal record-keeping duty under Article 30.
That relief is narrow and heavily caveated. It falls away if your processing is likely to result in a risk to individuals, is not occasional, or involves special category or criminal offence data, which covers a great many small organisations in practice. It is safer to assume the full regime applies and to keep proportionate records regardless.
A question we missed?
Bring it to the scoping call
That is what the scoping call is for: 45 minutes, free, on where your GDPR compliance stands, the scope you need and the indicative fixed fee, whether or not you go on to instruct the work. It is taken by a data protection consultant, not a salesperson.