Most agencies only think about a DPIA once the campaign's live.
It's meant to happen before higher-risk work starts: profiling at scale, tracking people across sites for ad targeting.
After launch, it's evidence the risk came late.
Before or after, for yours? #DataProtection
Most small recruitment agencies don't realise a subject access request doesn't need those exact words.
If a candidate emails asking what you hold on them, that's a SAR. The clock starts when it lands, not when someone notices.
Does your inbox catch it by day 20?
#DataProtection
I've seen charity intake forms where a dietary requirement or health condition sits in the same column as name and address.
Health data is special category under GDPR, needing its own lawful basis, not the one covering the rest.
Does yours treat it differently? #UKCharity
A laptop goes missing. An email goes to the wrong person.
The clock on telling the ICO starts immediately, not once it's fixed. 72 hours to decide and start containing, not to have it solved.
20 plain-English questions, no sign-up: certoa.co.uk/free-assessment
A funder or bigger client asks for "your GDPR policy." What exists is usually a vague sense one's needed, not a document.
It's the one that ties the rest together: what you do with people's data, and who's responsible.
20 plain-English questions: certoa.co.uk/free-assessment
A funder or a bigger client asks for "your GDPR policy," and what exists is a vague sense one's probably needed, not a document you can send. It's meant to tie the rest of your GDPR paperwork together, not a box-ticking extra.
Most small agencies I talk to don't think about a data processing agreement until a client's due diligence form lands, deadline attached. It always wants the same things: what data you hold, who processes it, how long you keep it. Worth having those answers ready first. #GDPR
Ask most small businesses how long they keep customer records and the honest answer is nobody's ever decided, it's just never been deleted. Keeping everything forever isn't the safe option it feels like. Deleting the wrong thing too early is worse.
Most small agencies I talk to send marketing emails because they always have, not because anyone checked the legal basis.
Consent and legitimate interest aren't interchangeable, and picking the wrong one is the gap a complaint finds first.
Which one covers your list? #GDPR
Most small charities I talk to have a retention line that just says "as long as necessary". That's a placeholder, not a period. A funder or ICO check wants real timeframes for donor records, safeguarding notes, volunteer files. Does yours name one, or just the phrase? #UKCharity
Somebody fills in your contact form or joins your newsletter. UK GDPR expects you to have told them what happens to their data, not to explain it once they ask. A generic notice copied from a template site doesn't hold up, it has to describe what your business actually does.
Most small recruitment agencies I talk to have a privacy policy on the website. Almost none have one covering the CVs already sitting in their database.
Does yours say what's held, why, and for how long, or does it stop at the contact form?
#DataProtection
Most small charities I talk to don't have a RoPA. Not because they're careless. Nobody ever explained what it is or why a funder or an ICO check would ask for one.
It's just a log: what data you hold, why, where it lives, who sees it. An afternoon's work, not a project.
Working with GDPR since 2018, the deadline that catches small businesses out most is the one-month subject access request window. A customer or ex-employee can ask what data you hold on them, and the clock starts the day the request lands, ready or not. certoa.co.uk
Launching a CRM, CCTV, or an app? You might need a DPIA first. It is required when a project is likely to cause high risk: sensitive data at scale, public monitoring, automated decisions, or location tracking. Catch the problem before you build, not after. certoa.co.uk
Had a data breach? You have 72 hours to notify the ICO, but only if it is likely to put people at risk. Not every incident needs reporting. Knowing which do, and having a short response process ready, is what actually saves you on day one. certoa.co.uk
A subject access request gives you one calendar month to respond, not once you get round to it. Most businesses get caught out on the clock, not the substance, often when it lands on a Friday with no owner. Sort a process before you need one. certoa.co.uk/downloads
A subject access request gives someone one calendar month to see their data. Most businesses that get caught out aren't wrong on the substance, they're wrong on the clock. Have a short process ready before a request lands. certoa.co.uk
The Certoa template library is live at certoa.co.uk.
7 UK GDPR document templates, written the way I'd write them for a paying client as a certified DPO. From £29, or the full bundle for £149.
Not sure where to start? Free 2-minute assessment: certoa.co.uk/assessment