Data Protection Audits
Everything your organisation needs to understand its obligations, identify the gaps, and start putting things right.

Choose Your Audit

Remote Audit - £395
Conducted by video call and/or email. Ideal for most small organisations with largely digital records.

On-site Audit - £695
Includes a half-day visit to your premises. Best suited to organisations with significant paper records, CCTV, or those who prefer a face-to-face approach.
What's included - both options
-
Pre-audit questionnaire - a straightforward, plain English form I send before the audit, so your time is spent on what matters.
-
The audit itself - a structured review of what personal data you hold, how you use it, who you share it with, and whether your current arrangements meet your legal obligations.
-
Written audit report - a clear, prioritised report: what I found, what needs to change, and what to do first.
-
Suite of blank template documents - ready to use or adapt, provided free with every report.
-
Staff awareness poster - a branded, print-ready A4 poster covering the seven habits that prevent most data protection problems.
-
Follow-up Q&A - a brief call or email exchange once you've had a chance to read the report.
How the audit works
1. Questionnaire
I send you a short, plain English questionnaire covering what your organisation does, what data you hold, and how. It should take no more than 45 minutes to 1 hour to complete.
2. Review
I review your answers so our time together is focused on the areas that need the most attention.
3. The audit
I work through your organisation's data practices - what you hold, why, where, and how it's protected. Remote audits are conducted by video call and email; on-site audits take half a day and include a physical review.
4. Report & templates
You receive a written report within 14 working days, along with your suite of blank template documents. A short follow-up exchange is included.
What your report will cover
The written report is designed to be readable by everyone in your organisation, so it can be shared with your committee, trustees, or management team. It includes:
-
A summary of findings and overall assessment
-
A single prioritised action list, so you know exactly where to start
-
Privacy notices and transparency
-
Legal basis for the data you hold
-
Data subject rights and complaints handling
-
Marketing and communications permissions
-
Data sharing and third-party agreements
-
CCTV (where relevant)
-
Data security - digital and physical
-
Retention and disposal
-
Breach history and procedures
-
Staff training and awareness
-
Written policies
-
Use of AI tools
Frequently Asked Questions
1
Do I have to do anything before the audit?
Just complete the pre-audit questionnaire, which I'll send in advance. It should take no more than 45 minutes to 1 hour and can be completed by whoever knows your organisation's data practices best.
2
How disruptive is it?
Remote audits require minimal time from your team - typically a call of one to two hours. On-site audits take half a day but are designed to cause as little disruption as possible.
3
What happens after the audit?
You receive your report and templates within 14 working days. Some clients implement the recommendations themselves; others ask for help with specific documents, training, or ongoing support — see my other service guides for details.
4
We're very small - is this really for us?
Yes. The audit is designed specifically for small organisations, and everything is proportionate to your size. I work with organisations ranging from sole traders and charities with a handful of staff to medium-size retail and hospitality businesses.
