- We are a small company — do we really need a program?
- You need a proportionate one. A short, well-documented set of policies you actually follow protects you far better than a large framework nobody uses.
- What happens if we receive a regulator inquiry?
- Contact us before responding. Early responses set the tone of the whole process, and we can help you gather the right documentation and reply accurately.
- Do you handle data protection specifically?
- Yes — privacy notices, processing records, vendor terms, and breach response are a core part of our compliance work.
- How often should policies be reviewed?
- Annually as a baseline, and immediately after a regulatory change, a significant incident, or a shift in what your business actually does. Undated policies are the first thing a regulator picks up on.
- What should we do in the first 24 hours of a data breach?
- Contain it, preserve the logs, and start a written incident record. Reporting deadlines can be as short as 72 hours, so involve us early — the assessment of whether it is notifiable is itself a legal judgement worth documenting.
- Do we need a data protection officer?
- Only where you carry out large-scale monitoring or process special-category data at scale. Where you do not, we help you appoint a responsible owner and document why a formal DPO is not required.
- How do we manage compliance risk in our supply chain?
- Risk-tier your vendors, apply proportionate due diligence, and put the obligations in the contract — data processing terms, audit rights, and anti-bribery warranties — rather than relying on a questionnaire alone.
- Do you deliver staff training?
- Yes. We run short, role-specific sessions for boards, managers, and front-line teams, with attendance records and refresher materials you can keep as evidence of your program.