Documentation Preparation
The key documents your organisation needs to meet its legal obligations - drafted in plain English, tailored specifically to you.

Choose Your Documentation

Privacy Notice - £175
Tells people what you do with their personal data - what you collect, why, how long you keep it, and what their rights are. Required by UK GDPR for almost all organisations.

Data Protection Policy - £175
Sets out your organisation's commitment to data protection and the practical steps taken to meet it. Covers security, retention, breach handling, training and individual rights.

Retention Schedule - £150
Sets out how long your organisation keeps different categories of personal data and what happens when that period ends.

Record of Processing Activities (ROPA) - £200
A practical record of the personal data your organisation processes, helping you understand what information you hold, why you hold it and how it is managed.
Specialist Documentation — price on request
Including Data Protection Impact Assessments (DPIAs), Legitimate Interests Assessments (LIAs), Transfer Impact Assessments (TIAs), bespoke policies and sector-specific documentation.
What's included
-
Tailored questionnaire, sent in advance
-
Draft document delivered within 10 working days
-
One amendment round, included as standard
-
Final document in Word format, ready to adopt immediately
-
Guidance notes explaining key decisions and anything to review over time
-
Fixed price, agreed before I begin - no additional charges
How it works
1. Questionnaire
I send you a short, plain English questionnaire covering how your organisation operates, what personal data you hold, and what the document needs to achieve. It usually takes around 30-40 minutes to complete.
2. Review
I review your responses carefully before I begin drafting, and may follow up with a clarifying question or two to make sure the final document reflects how your organisation actually works.
3. Drafting
Written in plain English, tailored to your organisation. You will usually receive a draft within 10 working days of returning the questionnaire.
4. Final document
You review the draft and let me know of any changes - one amendment round is included as standard. Once you're happy, I send the final version in Word format, ready to adopt. PDF versions are also available on request.
If you've previously had a data protection audit, I will already know your organisation - meaning a faster turnaround, a more accurate document, and no duplication of effort.
Other Documents Available
-
Breach Response Procedure - a step-by-step procedure for identifying, recording and managing personal data breaches, including ICO reporting and communication with affected individuals.
-
Staff Induction Training - workbook, self-assessment quiz, completion certificate and training log to help staff and volunteers understand their responsibilities.
-
Subject Access Request Pack - a practical toolkit including a step-by-step procedure, deadline-tracking log, and template response letters.
-
CCTV Policy and Guidance - covering signage, retention periods, access controls and individuals' rights.
-
Data Processing Agreement - a plain English contract for suppliers and third parties who process personal data on your behalf.
-
Data Processing Assessments - DPIAs, LIAs and Transfer Impact Assessments for specific circumstances requiring formal privacy risk assessment.
Frequently Asked Questions
1
Do I need to have an audit first?
No. These documents are available as a standalone service. If you've previously had a data protection audit with me, I already know your organisation, meaning a faster turnaround and less duplication of effort.
2
How long does it take?
You'll receive a draft within 10 working days of returning the questionnaire. The amendment round is usually completed within a further five working days. If you need something more urgently, just ask.
3
Can I get more than one document?
Yes. Bundle pricing is available, and organisations needing all four core documents often find a bundle more cost-effective than commissioning them individually.
4
What if our circumstances change after the document is finalised?
Data protection documents should be reviewed annually, or whenever your processing activities change significantly. If you need a document updated later, I'm happy to help.
