✅ Tailored Data Protection and Information Governance Policy
We develop a bespoke policy that reflects your organisation’s structure, data handling activities, and legal obligations. The policy sets out how you manage personal data in line with the UK GDPR and Data Protection Act 2018. It provides a clear framework for lawful, secure, and accountable information handling across your organisation.
✅ Staff and Service User Privacy Notices
We create clear, easy-to-understand privacy notices tailored for different audiences, such as staff, customers, clients, or service users. These explain what personal data you collect, why you collect it, how it is used, who it is shared with, and what rights individuals have over their data.
✅ Subject Access Request (SAR) Procedure and Workflow
We provide a clear and practical process for handling Subject Access Requests. This includes a step-by-step workflow, responsibilities, template responses, and guidance on handling exemptions and redactions. The procedure helps you meet legal deadlines and respond lawfully and efficiently to data access requests.
✅ Data Breach Response Procedure and Reporting Forms
We supply a complete data breach response plan, including how to identify, contain, investigate, and report breaches. This comes with incident reporting forms and guidance on when and how to notify the Information Commissioner’s Office (ICO) and affected individuals, helping you reduce risk and maintain trust.
✅ Information Sharing and Data Processing Agreement Templates
We provide ready-to-use templates for data sharing and data processing agreements. These documents clearly set out the responsibilities of all parties when sharing or processing personal data. They are fully aligned with UK GDPR requirements and can be adapted for suppliers, partners, or contractors.
✅ Records Management and Retention Policy
We produce a records management policy that outlines how long different types of records should be kept, how they should be stored, and when they should be securely disposed of. This helps you meet legal and regulatory obligations and ensures information is managed consistently.
✅ Acceptable Use, Security, and Remote Working Policies
We develop practical policies covering how staff should use your systems and data safely—whether in the office or working remotely. These include rules on device use, passwords, email, cloud storage, and data transfers, supporting good cybersecurity and data protection habits across the organisation.
✅ Clear Allocation of IG Responsibilities (e.g. DPO, SIRO, Caldicott Guardian)
We help define and document who is responsible for data protection and information governance in your organisation. This includes assigning roles such as Data Protection Officer (DPO), information leads, or board-level accountability. Clear roles and responsibilities reduce confusion and improve oversight.
✅ Document Versioning and Review Guidance
We provide practical guidance on how to manage and track changes to policies and procedures. This includes version control, approval logs, and scheduled review timelines—ensuring your documents stay current, compliant, and ready for audit.