Get Ahead Of Rules That Just Got Significantly Tougher

The Data (Use and Access) Act 2025 rewrote the risk profile for UK businesses in 2026 — and most small businesses haven't caught up yet.


  • Marketing fines now match GDPR levels: the maximum fine for unlawful marketing calls, texts, or emails (PECR) rose from £500,000 to £17.5m or 4% of global turnover — whichever is higher.
  • A brand-new legal requirement, with a hard deadline: every organisation must now run a formal data protection complaints process, with a 30-day response obligation, in place by 19 June 2026.
  • Win the contracts that gate on it: major supply chains — defence, public sector, and their contractors — now check your GDPR position and your Cyber Essentials status together before they'll even consider you.

Why “We're Too Small For This” Is The Mistake That Costs Businesses

The idea that small businesses sit outside UK GDPR is one of the most persistent myths in UK data protection — and the ICO has consistently rejected it. In 2025 alone, the regulator issued fines and reprimands to dozens of organisations with fewer than fifty employees, typically for the basics: inadequate security, ignored data requests, or marketing sent without valid consent. One business was fined £150,000 for 2.6 million unlawful marketing calls — the kind of activity plenty of small businesses run without realising the exposure.

Get compliant properly — before it costs you.

https://www.

The review is free and takes 20 minutes. No obligation, no legal jargon.

Real Compliance Over A Downloaded Privacy Policy Template

A privacy policy copied from a template site doesn't reflect what your business actually does with data — and it won't hold up if the ICO ever asks.

The Actually-Compliant Guarantee

Generic templates don't cover your specific data flows, your marketing consent records, or the new mandatory complaints process.


  • We map what your business genuinely collects, stores, and sends — not a generic checklist.
  • We build and implement your new formal complaints procedure so you meet the 19 June 2026 deadline properly, not in a panic the week before.
  • Guaranteed to reflect how your business actually operates.

Skip The Data Protection Lawyer's Hourly Clock

Data protection solicitors charge premium hourly rates for a report — then leave the actual implementation to you.


  • They tell you what's wrong; we fix it, including your website's cookie consent, forms, and marketing sign-up flow.
  • One fixed engagement, not an open-ended legal bill.
  • We already handle your hosting and website — compliance gets built into what we're already maintaining, not bolted on separately.

Zero Legal Jargon. Zero Guesswork.

You shouldn't need to read the Data (Use and Access) Act yourself to run a compliant business.


  • No legal training required on your end — we translate every requirement into what it actually means for your business.
  • Your cookie banner, consent flows, and complaints process get fixed, not just flagged.
  • We tell you plainly what's required, what's optional, and what's overkill for a business your size.
Genuinely Compliant, Not Just Paper-Compliant

Know Exactly Where You Stand Before The ICO Does

We map your real data protection position, fix what's exposed, and get your new complaints process live before the June 2026 deadline — without you needing to become a data protection expert to get there. If you're also working toward Cyber Essentials, most supply chains check both together — worth doing at the same time, not separately.