Does my business need to register with the ICO?
Almost certainly yes. Most UK organisations that process personal data must pay the ICO an annual data protection fee, which is £40 to £60 for the majority of small and mid-sized businesses. A small number of narrow exemptions exist, and checking your tier takes a few minutes on the ICO website. Paying the fee is not the same as being compliant, but not paying it when you should is the easiest enforcement letter there is.
Do we need a Data Protection Officer?
Most small and mid-sized UK businesses do not legally need a DPO. One is mandatory only for public authorities, or where core activities involve large scale monitoring of people or large scale special category data. Outside those cases you still need a named person who is accountable for data protection decisions, and it should not be whoever happens to be free. Many firms cover this with an outsourced data protection officer service rather than a hire, which is one of the things we provide.
How much does GDPR help cost in the UK?
For a small or mid-sized UK business, a one-off GDPR gap analysis and remediation typically runs to a few thousand pounds, and ongoing outsourced DPO support across the market ranges from roughly £300 to £5,000 a month depending on depth. We work fixed scope and fixed price, quoted before anything starts, so the number you agree to is the number you pay. The scoping review that produces that quote is itself fixed fee, and the findings note is yours either way.
How quickly do we have to report a data breach?
Within 72 hours of becoming aware, where the breach is likely to put people at risk. That clock includes the weekend. Not every breach is reportable to the ICO, but every one must be recorded internally, and if the risk to the people involved is high you have to tell them directly as well. This is why a breach plan written before you need it matters more than almost any other document.
How long do we have to answer a subject access request?
One calendar month from the day it arrives. You can extend by up to two further months where a request is genuinely complex or someone has made several, but you must tell them within the first month and explain why. The clock does not pause while you decide whether the request is awkward, and it applies to requests from employees just as much as customers.
Can we use personal data to train an AI model?
Sometimes, and it turns on four questions: what lawful basis you relied on when the data was collected, whether training is compatible with that original purpose, what your privacy notice told people, and whether you can meet their rights over the trained model. Training is its own processing purpose, so it has to be assessed on its own terms rather than assumed to be covered. Settling this at the first sprint is cheap; settling it at legal review is not.
Do we actually need a consultant, or can we do this ourselves?
Plenty of businesses handle UK GDPR in-house, and the ICO publishes good free guidance. A consultant earns their fee in three situations: when nobody inside has time to own it properly, when something has already gone wrong, or when what you want to do with data is unusual enough that template answers stop working. If your situation is simple, we will tell you so on the call and point you at the guidance.
Where are you based, and who do you work with?
We are a data protection and data science consultancy registered in Birmingham, working with businesses across the United Kingdom. Most of our clients are UK companies between ten and 250 people: startups whose product runs on customer data, and manufacturing, logistics, retail and service firms with operational data going unused. Almost all of the work happens remotely, with on-site days where they genuinely help.