Subject access requests
How a request is logged, answered and recorded within the deadline.
Technology alone cannot protect a business. Written procedures make sure staff know what to do, apply security consistently, and leave a record that proves you comply.
Firewalls, passwords and malware protection only work if people use them properly. Clear, written procedures mean security does not depend on who happens to be in the office, and they give you evidence for UK GDPR and Cyber Essentials.
The right set depends on the size and type of your business. These are the ones we recommend most often.
What each new person can reach from day one, and who authorises it.
Accounts disabled, devices recovered and access removed the day someone leaves.
How a request is logged, answered and recorded within the deadline.
Who decides, how quickly, and when the ICO must be told.
Encryption, lost devices and the use of personal phones for work.
How long each kind of data is kept and how it is deleted.

A procedure nobody reads is not a procedure. We help you write short, practical procedures that fit how your business works, train staff on them, and create a clear audit trail without slowing down the day.
UK GDPR expects you to be able to show how you protect personal data. Short written procedures are the simplest way to do that, whatever the size of the business.
We put these controls in place for small and medium businesses, and keep them there. Tell us how your business works.
See also
What UK GDPR and the Data Protection Act 2018 require of a small business, what the fines are, and the practical steps that protect client d
Role-based access control for small businesses: staff see only the data their job needs. Meets UK GDPR and Cyber Essentials access control r
Secure business laptops, phones and tablets: encryption, two-factor sign-in, password managers and device management, for UK GDPR and Cyber