GDPR Knowledge Base

Plain-English compliance guides for UK and EU businesses — no legal jargon, no enterprise budget required.

Subject Access Requests
How to Respond to a Subject Access Request: A Step-by-Step Guide for UK SMEs

Under UK GDPR, you have 30 days to respond to a SAR — free of charge. This guide walks you through every step of the process, from identity verification to response delivery.

Read guide →
RoPA & Article 30
What is a Record of Processing Activities? A Plain-English Guide for UK SMEs

Article 30 of UK GDPR requires most organisations to keep a written record of every way they use personal data. Here's what it needs to contain and how to build one.

Read guide →
Data Retention
How Long Should You Keep Business Documents? A UK GDPR Retention Guide

Keeping documents too long is a GDPR risk. Deleting them too soon is an employment law problem. This guide sets out the recommended retention periods for the most common document types.

Read guide →
AI & Document Privacy
Is It Safe to Upload Sensitive Documents to AI Tools? A UK GDPR Guide

AI tools have become routine. But uploading documents containing personal data to external services triggers GDPR obligations most businesses haven't considered.

Read guide →
Personal Data & PII
What is PII? A Plain-English Guide for Small Businesses

PII — Personally Identifiable Information — is broader than most people think. Does an IP address count? A job title? A first name? This guide answers the questions clearly.

Read guide →
Compliance Checklist
UK GDPR Compliance Checklist for SMEs in 2025

A practical checklist covering the core UK GDPR requirements — from lawful basis and RoPA to breach response and individual rights. Identify your gaps and prioritise what to fix.

Read guide →