Our Services

Data protection compliance, delivered

From a full retained DPO function to standalone compliance projects — flexible services built around the ICO’s Accountability Framework, tailored to your organisation.

Core Service

Retained DPO Service

Your named Data Protection Officer on a retained basis — embedded in your governance, available when you need them, at a fraction of the cost of hiring.


Included in your retainer*EssentialsStandardPremium
Named DPO — dedicated point of contact
ICO liaison — registered as your DPO contact
Annual compliance review
Board-level reporting
Breach management — triage, assessment, ICO notification
Regulatory newsletter
Ad-hoc advisory supportEmailEmail & phoneEmail, phone & Teams
Governance meetings with written summaryQuarterlyMonthlyFortnightly
Regulatory monitoring and reporting — ICO, DUAAQuarterlyMonthlyMonthly + alerts
Staff training1 session/year2 sessions/year

Flexible, transparent pricing

Retainer fees are based on your organisation’s size, complexity, and sector risk profile. We’ll recommend the right tier after an initial conversation. Out-of-scope work is always quoted separately before we begin.

Get in Touch for a Quote

Extended Services

Compliance projects & specialist support

Discrete project engagements for specific compliance needs — available to retainer clients and as standalone commissions.

Data Protection Impact Assessments

DPIA screening, full assessments, and ICO consultation advice for high-risk processing — including AI, cloud migration, and new technology adoption.

Supplier Due Diligence & Processor Management

Due diligence assessments, Article 28 data processing agreements, sub-processor management, and international transfer assessments.

International Data Transfer Guidance

Transfer Risk Assessments, UK IDTA and UK Addendum implementation, supplementary measures, and transfer mapping across your supplier estate.

Compliance Audit & Health Check

Point-in-time assessment against the ICO’s Accountability Framework producing findings, risk ratings, and a prioritised remediation plan.

Learn more →

Records of Processing Activities (ROPA)

Building your Article 30 ROPA from scratch or reviewing an existing register — including data mapping, lawful basis identification, and maintenance.

Data Protection Policy Suite

Comprehensive policies tailored to your organisation: DP policy, privacy notices, DSAR procedure, breach procedure, retention schedule, and more.

Legitimate Interest Assessments

Formal LIAs following the ICO’s three-part test: identifying the interest, demonstrating necessity, conducting the balancing test.

ICO Investigation & Complaint Support

Expert support during ICO investigations: reviewing correspondence, preparing responses, and managing the regulatory relationship strategically.

Standalone Products

Tools for every stage of compliance

Expert-quality compliance materials without an ongoing commitment.

Compliance Starter Kit

ROPA template, privacy notices, DSAR procedure, breach procedure, retention schedule, LIA template, DPIA screening questionnaire, and Accountability Framework checklist.

Purchase — £[Price]

Secure payment via Stripe. Instant digital delivery.

E-Learning Training Modules

UK-specific data protection e-learning: awareness, DSAR recognition, breach reporting, role-specific modules. Quizzes, certificates, completion tracking.

Purchase — £[Price]

Secure payment via Stripe. Per-user licensing.

Regulatory Briefing Service

Monthly subscription: ICO guidance, enforcement actions, legislative developments, practical implications — for non-specialists.

Subscribe — £[Price]/mo

Secure payment via Stripe. Cancel anytime.

Every organisation is different

We’ll recommend the right combination of services based on your size, sector, and compliance maturity. The first conversation is always free.

Book a Free Consultation