Nygontech Book thirty minutes

Nygontech Data science and UK GDPR Working with British SMEs

Data science and UK GDPR consultancy

Make more of your data. Without hearing from the ICO.

Most companies we meet are sitting on numbers they do not fully trust, in systems nobody has mapped, governed by a policy someone downloaded in 2019. We work on both halves of that: what the data can tell you, and what the law lets you do with it.

Book thirty minutes See the fixed-price services Free. Nobody presents anything.

Analyst reviewing an operations dashboard with a UK business team
Fig. 01 Operational reporting, rebuilt from source systems

Your data, stage by stage

Gain
A written answer to what you actually capture, from which form, into which system. Most teams find three things they collect and nobody uses.
Owe
A lawful basis for each purpose, and a privacy notice that describes what really happens rather than what the template said.
Gain
One version of the truth instead of six spreadsheets, each slightly out of date and each defended by someone.
Owe
Access control that reflects who needs the data today, and a retention clock running on every record you keep.
Gain
Forecasts, segments and cohort views you can put in front of a board without someone asking where the number came from.
Owe
Purpose limitation. The data was gathered for a reason, and analysis is not automatically that reason.
Gain
Partners, processors and tools that genuinely improve the picture rather than adding another export nobody reconciles.
Owe
Article 28 contracts with every processor, and a defensible route for any personal data that leaves the UK.
Gain
A smaller estate. Lower storage cost, faster queries, and far less to hand over when a subject access request lands.
Owe
Evidence that you deleted it, including from backups, rather than an intention to get round to it.

01 PositionWhy the two disciplines belong together

Analytics and compliance are usually bought from different people. That is the problem.

The data agency builds something clever and leaves you to work out whether you were allowed to. The compliance firm charges a four-figure day rate to hand over templates that quietly make the clever thing impossible. The software platform sells you a dashboard that needs a team of its own to run. We do the first two jobs ourselves, at a fixed price, so the trade-off between what the data can do and what the law allows gets made once, early, by the same people.

What the data can tell you

Which customers are about to leave. Which sites are absorbing cost. What next quarter probably looks like, with an honest range rather than a single confident number.

What the law lets you do

UK GDPR and the Data Protection Act 2018 are not a wall. They are a set of conditions. Meet them properly and most of what you wanted to do is available to you.

Data pipeline diagram with privacy controls marked at each stage
Fig. 02 Privacy controls mapped at every stage of the pipeline

02 ServicesFour engagements. Fixed scope, fixed price.

What you can hire us for

Analytics

Reporting that holds up

You almost certainly have dashboards. The question is whether anyone believes the numbers on them. We go back to the source systems, agree what each metric actually means, and rebuild the reporting so the figure in Monday stand-up matches the figure in the board pack.

You get
Metric definitions, one working dashboard, handover notes
Typical run
4 to 8 weeks
Good for
Teams whose reporting has grown by accident

Compliance

UK GDPR, done once and properly

A gap analysis against what you actually do, a record of processing that matches reality, DPIAs for the projects that warrant one, and a breach plan your team could follow at four o clock on a Friday. Written so an ICO caseworker and your operations manager can both read it.

Covers
Article 30 records, DPIAs, retention, DSAR handling, breach response
Typical run
3 to 6 weeks
Good for
First proper compliance programme, or one that has drifted

Retainer

Someone to ring

A fractional, outsourced data protection officer service for companies that do not need a full-time hire but do need an answer before Thursday. Quarterly reviews, dashboard upkeep, and a named person who already knows your systems and does not need the background explained again. The person you meet on the first call is the person who does the work.

You get
Named contact, quarterly review, ad-hoc advice
Typical run
Monthly, 3 month minimum
Good for
Teams past the initial build who want it to stay true

Build

Shipping something with AI

Model ideas tend to die at legal review, or worse, ship without one. We join at the first sprint instead of the last: an honest AI readiness check on your data, lawful basis settled up front, training data documented as it is assembled, minimisation decided while changing it is still cheap.

Covers
Lawful basis, DPIA, minimisation, Article 22, documentation
Typical run
Alongside your build
Good for
Product teams putting a model in front of customers

03 DeadlinesThe clocks you are already running

Three numbers worth knowing before you need them

These are statutory, not marketing. If a breach happened this afternoon, the first clock would already be running.

72 hours hours to report a breach To the ICO, from becoming aware, where there is a risk to people. Not every breach qualifies, but every one must be logged.
1 month month to answer a DSAR One calendar month from receipt. Extendable by two more if the request is genuinely complex, provided you say so in the first month.
£17.5 million upper penalty tier Or four per cent of worldwide annual turnover, whichever is higher. Most enforcement lands nowhere near it, but the ceiling is real.

04 MethodWhat the four stages are

What actually happens

  1. Thirty minutes on the phone

    You describe what is broken. We say whether we can help, and if we cannot, who might. Nobody presents anything.

    Thirty minutes, free

  2. We go and look

    We look at your systems, your existing records and your reporting. You get a written findings note with problems in priority order, each with a cost against it. The note is yours whether or not you continue.

    1 to 2 weeks, fixed fee

  3. The work

    Fixed scope, fixed price, one named lead who stays on it. Fortnightly check-ins. If the scope needs to change we tell you before it does, not on the invoice.

    3 to 8 weeks, typically

  4. We hand it over and go

    Documentation your own team can maintain, and a session walking them through it. We would rather you did not need us every month.

    Included

05 FitRead this before booking

Who this suits, and who it does not

We work well with

  • UK businesses between roughly 10 and 250 people
  • Startups and SaaS companies whose product runs on customer data
  • Manufacturing, logistics, retail and service firms with operational data going unused
  • Teams who have been asked for an AI plan and want to answer honestly

We are the wrong call if

  • You need a one-page policy by Friday to clear a procurement form
  • You want someone to sign off work they have not been allowed to see
  • The goal is a badge for the website footer rather than a change in practice

Plenty of firms will do those. We would rather say so now than three weeks in.

06 QuestionsThe five we are asked most

Questions we get every week

Does my business need to register with the ICO?

Almost certainly yes. Most UK organisations that process personal data must pay the ICO an annual data protection fee, which is £40 to £60 for the majority of small and mid-sized businesses. A small number of narrow exemptions exist, and checking your tier takes a few minutes on the ICO website. Paying the fee is not the same as being compliant, but not paying it when you should is the easiest enforcement letter there is.

Do we need a Data Protection Officer?

Most small and mid-sized UK businesses do not legally need a DPO. One is mandatory only for public authorities, or where core activities involve large scale monitoring of people or large scale special category data. Outside those cases you still need a named person who is accountable for data protection decisions, and it should not be whoever happens to be free. Many firms cover this with an outsourced data protection officer service rather than a hire, which is one of the things we provide.

How much does GDPR help cost in the UK?

For a small or mid-sized UK business, a one-off GDPR gap analysis and remediation typically runs to a few thousand pounds, and ongoing outsourced DPO support across the market ranges from roughly £300 to £5,000 a month depending on depth. We work fixed scope and fixed price, quoted before anything starts, so the number you agree to is the number you pay. The scoping review that produces that quote is itself fixed fee, and the findings note is yours either way.

How quickly do we have to report a data breach?

Within 72 hours of becoming aware, where the breach is likely to put people at risk. That clock includes the weekend. Not every breach is reportable to the ICO, but every one must be recorded internally, and if the risk to the people involved is high you have to tell them directly as well. This is why a breach plan written before you need it matters more than almost any other document.

How long do we have to answer a subject access request?

One calendar month from the day it arrives. You can extend by up to two further months where a request is genuinely complex or someone has made several, but you must tell them within the first month and explain why. The clock does not pause while you decide whether the request is awkward, and it applies to requests from employees just as much as customers.

Can we use personal data to train an AI model?

Sometimes, and it turns on four questions: what lawful basis you relied on when the data was collected, whether training is compatible with that original purpose, what your privacy notice told people, and whether you can meet their rights over the trained model. Training is its own processing purpose, so it has to be assessed on its own terms rather than assumed to be covered. Settling this at the first sprint is cheap; settling it at legal review is not.

Do we actually need a consultant, or can we do this ourselves?

Plenty of businesses handle UK GDPR in-house, and the ICO publishes good free guidance. A consultant earns their fee in three situations: when nobody inside has time to own it properly, when something has already gone wrong, or when what you want to do with data is unusual enough that template answers stop working. If your situation is simple, we will tell you so on the call and point you at the guidance.

Where are you based, and who do you work with?

We are a data protection and data science consultancy registered in Birmingham, working with businesses across the United Kingdom. Most of our clients are UK companies between ten and 250 people: startups whose product runs on customer data, and manufacturing, logistics, retail and service firms with operational data going unused. Almost all of the work happens remotely, with on-site days where they genuinely help.

08 ContactA person reads these

Tell us what is actually going on

The messy version is fine. It is more useful than the tidy one, and if we are not right for it we will say so on the call rather than after the invoice.

We use what you send here to answer your enquiry, and for nothing else. We do not add you to a mailing list. Full detail is in our privacy notice.

Email
hello@nygontech.com
Registered office
Nygon Technologies Ltd
Office 1
Izabella House
24-26 Regent Place
City Centre
Birmingham
B1 3NJ
United Kingdom