You're a data controller the moment you collect a name or an email — and ICO fines start at £400 and reach £17.5m. DSAR 30-day clock, breach 72-hour timer, privacy notices, DPAs. Plain English. Built for the plumber with a website, not a DPO.
UK GDPR compliance, written in plain English. Reviewed by qualified privacy operators in our QA team. Not a "free" privacy generator, not a £600/mo enterprise tool — a working SME compliance product.
Plain-English privacy notice tailored to what you actually do. Updates when ICO publishes new guidance (cookies, AI processing, biometrics). Embeddable on your site in one line.
The moment a Subject Access Request lands, we start the 30-day clock. Auto-extends to 90 days only when you formally notify — and we draft that notification. Templated response packs for the eight most-asked DSAR formats.
Breach happens, you log it in 60 seconds. We run the risk-to-data-subjects decision tree, draft the ICO notification, draft the data-subject communications, and bank everything in your audit trail before the window closes.
Data Processing Agreements for the third parties you actually use — ChatGPT, Mailchimp, Stripe, Xero, Slack, every cloud tool you've added. Human-QA reviewed before delivery. Covers controller-processor and joint-controller patterns.
Most data controllers must register with the ICO (£40-£2,900/yr depending on size). We tell you whether you must, what fee band, and walk you through the form. We do NOT submit on your behalf — you stay in control.
Two hours a month with a qualified UK DPO via our partner network. White-label option lets accountants, MSPs and agencies offer gdpr.law to their own clients under their brand. Multi-entity dashboard included.
If you collect a single name or email, both of these statutory windows apply to you. We track them so they don't track you.
Pay-as-you-grow. No setup fee. Cancel any time. Most SMEs start on Starter and upgrade to Growth the moment their first DSAR or DPA need lands.
No. We are a GDPR compliance tool, not a law firm. Every output we generate is reviewed by qualified privacy operators in our human QA team before delivery. Privacy notices, DPAs and breach communications carry the caveat "AI-generated, reviewed by gdpr.law human QA team." If your situation needs legal advice — an active ICO investigation, a contested DSAR, a serious breach — we route you to a partner solicitor at a disclosed referral fee.
Probably yes. Most UK organisations that process personal data must register and pay the Data Protection Fee — currently £40, £60 or £2,900 a year depending on size. There are limited exemptions (some not-for-profits, very small public-task processing). The Starter tier walks you through the question set and tells you whether you must register, what fee band you're in, and how to do it. We do not submit on your behalf — you stay in control of the registration.
A Subject Access Request is when an individual asks what personal data you hold on them, why, who you share it with, and to be sent a copy. Anyone can make one. You have 30 calendar days from receipt to respond (extendable to 90 only with formal notification you've sent on time). Failure to respond is one of the most common ICO complaints. We start the clock the moment the request lands, draft the response, package the data, and bank the audit trail — so it doesn't slip.
A personal-data breach is a security incident that leads to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Yes, a lost or stolen laptop with unencrypted personal data on it counts. So does a misdirected email containing customer data, a ransomware incident, a misconfigured cloud bucket, a stolen phone with work email. If the breach poses risk to data subjects, you must notify ICO within 72 hours. The Growth tier's breach timer runs the decision tree for you.
It means you've added a third-party processor to your data chain. You need a DPA in place with that processor (most AI vendors provide one, some don't), your privacy notice needs updating to disclose the processing, and your ROPA needs to log the data flow. The Growth tier handles all three. The 2025 ICO guidance on AI processing turned this from a theoretical risk into an active enforcement focus.
You're already a data controller — staff, tenants and customers are all "data subjects" under UK GDPR. Your existing AMAYA subscription does not cover GDPR; you need gdpr.law on top. Customers who add gdpr.law from the Week-4 cross-sell get the first month at 50% (£9.50 Starter). The advantage of being in the AMAYA flywheel is that your ROPA auto-pulls from your other verticals — your staff records, tenant data, customer data are already inventoried.
Every DPA, breach notification, and DPO advisory output passes human QA before it reaches you. Reviewers score 1-5; 4+ passes, 3 is flagged for re-draft, 2 or below is failed and routed to a senior reviewer. They are qualified privacy operators (UK-GDPR trained) and they own the quality bar. AI does the draft; humans own the quality. Queue depth and SLA are visible in your dashboard.
Cancel any time. Export all your privacy notices, DSAR history, DPAs, breach logs, ROPA entries as PDF + CSV. We retain your data for the statutory period (6 years for breach evidence, ROPA evergreen until you formally request deletion). No contracts lock you in. The free trial is 14 days, no card needed.
Free. No card. Find out exactly which UK GDPR obligations apply to your business.
Run free checkLeave your details and we'll come back to you with what it does for your situation specifically — not a brochure.
£349 one-off when it opens — no card needed to join the list.