Skip to main content

Display options

These change how this site looks in your browser and are remembered on this device. They do not replace your own browser or device settings, which apply everywhere and will usually do more.

Text size
Reading
Colour and clarity
Movement and controls
Accessibility statement
SectorsAboutBlogNewsContactCall 01444 222889Book a Consultation

Data Protection Services and GDPR Consultancy

Strengthen your data protection, stay compliant, and reduce risk with tailored audits, training and ongoing support.

Infographic comparing UK GDPR, PECR and data protection, showing what each covers and how they work together

Data protection is more than a privacy policy on your website. UK GDPR, PECR, and the Data (Use and Access) Act 2025 place real obligations on how you collect, use, and protect personal data, and getting it wrong carries both financial and reputational risk. We provide full-spectrum data protection support, from a one-off gap analysis through to ongoing advisory and outsourced DPO support, matched to your size and risk.

What this covers

We help you meet your obligations under UK GDPR, PECR, and the Data (Use and Access) Act 2025. That spans your policies and privacy notices, how you handle data subject access requests, data protection impact assessments, and the practical day-to-day handling of personal data.

How we work with you

We start by finding the gaps between where you are and where you need to be, then help you close them in a proportionate way. For organisations that need more, we offer ongoing advisory support and can act as your outsourced Data Protection Officer.

Why it matters

Strong data protection is increasingly something your clients, partners, and regulators expect you to demonstrate, not just claim. Getting it right protects you from enforcement and builds trust with the people whose data you hold.

The laws behind UK data protection

In the UK, data protection rests mainly on the UK GDPR and the Data Protection Act 2018, which together set the rules for how organisations collect, use, store and share personal data. Alongside them sit the Privacy and Electronic Communications Regulations, known as PECR, which cover electronic marketing, cookies and similar technologies. The Data (Use and Access) Act 2025 amends parts of this framework, and its changes are being brought into force in stages, so rules that many organisations learned a few years ago are shifting in places. The ICO regulates this area and publishes guidance as changes take effect. Our GDPR consultancy keeps track of these developments and helps you understand which ones actually affect the way you work. We support organisations in Sussex, London and across the UK, much of it remotely.

Subject access requests and the one month deadline

Individuals have the right to ask for a copy of the personal data you hold about them. These data subject access requests can be made verbally or in writing, including by email or social media, and can be sent to anyone in your organisation, not just a named contact. In most cases you must respond within one month of receiving the request, although that period can be extended by up to two further months where requests are complex or numerous, provided you tell the person why. You usually cannot charge a fee. Requests often involve searching email, shared drives and business systems, then removing information about other people before anything is released. We help you set up a clear process, templates and staff awareness so requests are recognised quickly, logged and answered properly.

Data breaches and when to tell the ICO

A personal data breach is wider than a cyber attack. It includes an email sent to the wrong person, a lost laptop, or information made available to someone who should not see it. Where a breach is likely to result in a risk to people's rights and freedoms, you must usually report it to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. If the breach is likely to result in a high risk to individuals, you will usually need to tell them too. Whatever the outcome, you should keep a record of every breach, what happened and what you did about it. We help you put a breach procedure in place before you need it, so staff know who to tell and decisions are made calmly and in time.

PECR, cookies and electronic marketing

PECR sits alongside the UK GDPR and is often overlooked. In general, you need consent before placing cookies or similar tracking technologies that are not strictly necessary, and your cookie banner should give people a genuine choice. Marketing emails and texts sent to individuals usually need their consent, although a limited exception, often called the soft opt-in, can cover similar products and services offered to existing customers who were given a clear chance to opt out. Rules for marketing to companies are different, and sole traders and some partnerships are treated like individuals. The Data (Use and Access) Act 2025 changes parts of PECR, including some of the cookie rules, so it is worth checking your current approach. Our data protection services review your website, forms and marketing so they reflect the rules as they stand.

Where we work

We work with organisations across the UK. Much of our work is delivered remotely, so we support clients wherever they are based, with particular strength in London and the Southeast. We are based in Haywards Heath, West Sussex, and the areas we cover include London, Brighton and Hove, Crawley, Horsham, Haywards Heath, Burgess Hill, Worthing, Guildford, Tunbridge Wells, Reading, Slough, Newbury, Swindon and Bristol.

Want to know if this is the right fit for your organisation? We will talk it through with you, with no obligation.

Get in touch

Full-spectrum data protection support covering UK GDPR, PECR and the Data (Use and Access) Act 2025, from one-off gap analysis to ongoing advisory and outsourced DPO support.

Pricing and tiers

Bronze
£1,900
  • Basic UK GDPR gap analysis and report identifying key compliance gaps
  • Template-based data protection policy and privacy notice
  • One-hour online training session on UK GDPR basics for key staff
  • Guidance on appointing a DPO or responsible person
  • Checklist for ongoing compliance
Silver
Enquire for pricing
  • Comprehensive gap analysis with detailed report and recommendations
  • Customised policy, privacy notices and data processing agreements
  • Two 90-minute training sessions for staff and leadership
  • Assistance with DSAR processes and templates
  • Support for DPIAs for one high-risk process
Gold
Enquire for pricing
  • In-depth audit with ongoing monitoring and quarterly reviews
  • Fully customised documentation suite of policies, notices and contracts
  • DPIA support for high-risk processes during engagement
  • Comprehensive DSAR process setup and staff training
  • Outsourced DPO service or ongoing DPO mentoring for in-house staff

Ready to get started?

Book a consultation and we will tailor this service to your organisation and the risks it faces.

Book a consultation
Questions

Frequently asked questions

Yes. Many providers focus only on UK GDPR, but PECR (which governs electronic marketing and communications) and the Data (Use and Access) Act 2025 are part of the picture, and we cover all of them.

Some organisations are legally required to, depending on what they do and the data they handle. We can assess whether you need one, and if so, act as your outsourced DPO or mentor someone in-house.

Yes. We scale the support to your size and risk, from a focused gap analysis and templates at the Bronze level up to a fully customised programme. You are not paying for more than you need.

Yes. After Brexit the EU GDPR was kept in UK law as the UK GDPR, and it works alongside the Data Protection Act 2018. It has since been amended in places, including by the Data (Use and Access) Act 2025. If you offer goods or services to people in the EU, or monitor their behaviour, the EU GDPR may also apply to you.

In most cases, yes. Organisations that process personal data generally have to pay the data protection fee to the ICO unless an exemption applies. Exemptions exist, for example where personal data is used only for purposes such as staff administration, promoting your own business or keeping accounts, but the conditions are specific. The ICO offers a self assessment to check your position, and we can help you work through it.

The UK GDPR sets out seven principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality, which covers security; and accountability. Accountability means you must be able to show how you comply, not simply state that you do. A good gap analysis tests your policies, records and everyday practice against each of these principles.

For most organisations, the consequences of breaching the UK GDPR are regulatory, such as ICO reprimands, enforcement notices or fines, along with reputational harm and possible claims from individuals. The Data Protection Act 2018 also creates some criminal offences, such as knowingly or recklessly obtaining or disclosing personal data without the controller's consent. Those offences are punishable by a fine, although related conduct, such as hacking into systems, can fall under other laws that carry prison sentences.

A GDPR consultant helps you understand how personal data moves through your organisation, identifies where you fall short, and helps you close the gaps proportionately. With us, that can include a gap analysis, policies and privacy notices, processes for access requests, staff training and support with data protection impact assessments. Where a matter needs formal legal advice, a solicitor is the right route.

Interested in GDPR, PECR and Data Protection?

Book a consultation and we will tailor the right level of support to your organisation.

Book a Consultation