⚠ ICO fines for UK GDPR breaches now reach £17.5m or 4% of global turnover. DSAR clock is 30 days. Breach window is 72 hours. Free 60-second compliance check →

UK GDPR sorted.
£19 a month.

You're a data controller the moment you collect a name or an email — and ICO fines start at £400 and reach £17.5m. DSAR 30-day clock, breach 72-hour timer, privacy notices, DPAs. Plain English. Built for the plumber with a website, not a DPO.

Free 60-second GDPR compliance check
5.5m
UK businesses must comply
30 days
DSAR statutory deadline
72 hours
Breach ICO notification window
£17.5m
Max ICO fine · 4% global turnover

What you get

UK GDPR compliance, written in plain English. Reviewed by qualified privacy operators in our QA team. Not a "free" privacy generator, not a £600/mo enterprise tool — a working SME compliance product.

📋

Privacy notice generator

Plain-English privacy notice tailored to what you actually do. Updates when ICO publishes new guidance (cookies, AI processing, biometrics). Embeddable on your site in one line.

DSAR 30-day clock

The moment a Subject Access Request lands, we start the 30-day clock. Auto-extends to 90 days only when you formally notify — and we draft that notification. Templated response packs for the eight most-asked DSAR formats.

🚨

Breach 72-hour timer (Growth)

Breach happens, you log it in 60 seconds. We run the risk-to-data-subjects decision tree, draft the ICO notification, draft the data-subject communications, and bank everything in your audit trail before the window closes.

📄

DPA generator (Growth)

Data Processing Agreements for the third parties you actually use — ChatGPT, Mailchimp, Stripe, Xero, Slack, every cloud tool you've added. Human-QA reviewed before delivery. Covers controller-processor and joint-controller patterns.

🏛

ICO registration guide

Most data controllers must register with the ICO (£40-£2,900/yr depending on size). We tell you whether you must, what fee band, and walk you through the form. We do NOT submit on your behalf — you stay in control.

🛡

DPO advisory hours (Pro)

Two hours a month with a qualified UK DPO via our partner network. White-label option lets accountants, MSPs and agencies offer gdpr.law to their own clients under their brand. Multi-entity dashboard included.

The two clocks every UK controller is on

If you collect a single name or email, both of these statutory windows apply to you. We track them so they don't track you.

DSAR · 30 days
Subject Access Request. Any individual can ask what data you hold on them, why, who you share it with, and to be sent a copy — and you have 30 calendar days to respond. Free of charge. Extendable to 90 days only with formal notification. Failure = ICO complaint = fine. Our clock starts the second the request lands in your inbox.
Breach · 72 hours
Personal-data breach. If a breach poses risk to data subjects, ICO must be notified within 72 hours. "Late notification" is itself a tracked enforcement category. Most SMEs have no playbook. We give you the decision tree, the notification template, and the audit trail — start to finish, inside the window.
ICO registration · annual
Data Protection Fee. Most data controllers must register and pay an annual fee (£40 / £60 / £2,900 depending on size). Renewable each year. Non-registration is the first thing ICO checks on every complaint. We tell you whether you need to register, what band you're in, and remind you before renewal.
ROPA · live
Records of Processing Activities. A documented inventory of every personal-data flow in your business. Mandatory for most controllers. We auto-build a ROPA from the third parties you connect (Mailchimp, Stripe, Xero, ChatGPT etc.) and keep it current. Inspection-ready.

Pricing

Pay-as-you-grow. No setup fee. Cancel any time. Most SMEs start on Starter and upgrade to Growth the moment their first DSAR or DPA need lands.

Starter
£19/mo
2-9 staff · privacy notice + DSAR clock + ICO guide
  • Privacy notice generator
  • ICO registration guide
  • DSAR 30-day clock
  • Cookie consent banner
  • Plain English (plumber, not DPO)
  • 14-day free trial
Start free trial
Pro
£79/mo
Accountant, MSP, agency · white-label to clients
  • Everything in Growth
  • 2 hours/mo DPO advisory (UK qualified)
  • Multi-entity dashboard (manage clients)
  • White-label option (your brand)
  • Cross-vertical reseller agreement
  • Priority Human QA queue (2h SLA)
Start free trial

FAQ

Are you a law firm? Do you give legal advice?

No. We are a GDPR compliance tool, not a law firm. Every output we generate is reviewed by qualified privacy operators in our human QA team before delivery. Privacy notices, DPAs and breach communications carry the caveat "AI-generated, reviewed by gdpr.law human QA team." If your situation needs legal advice — an active ICO investigation, a contested DSAR, a serious breach — we route you to a partner solicitor at a disclosed referral fee.

Do I actually have to register with the ICO?

Probably yes. Most UK organisations that process personal data must register and pay the Data Protection Fee — currently £40, £60 or £2,900 a year depending on size. There are limited exemptions (some not-for-profits, very small public-task processing). The Starter tier walks you through the question set and tells you whether you must register, what fee band you're in, and how to do it. We do not submit on your behalf — you stay in control of the registration.

What is a DSAR and why is the 30-day clock so important?

A Subject Access Request is when an individual asks what personal data you hold on them, why, who you share it with, and to be sent a copy. Anyone can make one. You have 30 calendar days from receipt to respond (extendable to 90 only with formal notification you've sent on time). Failure to respond is one of the most common ICO complaints. We start the clock the moment the request lands, draft the response, package the data, and bank the audit trail — so it doesn't slip.

What counts as a "breach" — does losing a laptop count?

A personal-data breach is a security incident that leads to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Yes, a lost or stolen laptop with unencrypted personal data on it counts. So does a misdirected email containing customer data, a ransomware incident, a misconfigured cloud bucket, a stolen phone with work email. If the breach poses risk to data subjects, you must notify ICO within 72 hours. The Growth tier's breach timer runs the decision tree for you.

I use ChatGPT / Claude / Gemini for my business — what does that mean for GDPR?

It means you've added a third-party processor to your data chain. You need a DPA in place with that processor (most AI vendors provide one, some don't), your privacy notice needs updating to disclose the processing, and your ROPA needs to log the data flow. The Growth tier handles all three. The 2025 ICO guidance on AI processing turned this from a theoretical risk into an active enforcement focus.

What if my business is already in employ.law / landlord.tax / sole.tax?

You're already a data controller — staff, tenants and customers are all "data subjects" under UK GDPR. Your existing AMAYA subscription does not cover GDPR; you need gdpr.law on top. Customers who add gdpr.law from the Week-4 cross-sell get the first month at 50% (£9.50 Starter). The advantage of being in the AMAYA flywheel is that your ROPA auto-pulls from your other verticals — your staff records, tenant data, customer data are already inventoried.

What's the QA team's role?

Every DPA, breach notification, and DPO advisory output passes human QA before it reaches you. Reviewers score 1-5; 4+ passes, 3 is flagged for re-draft, 2 or below is failed and routed to a senior reviewer. They are qualified privacy operators (UK-GDPR trained) and they own the quality bar. AI does the draft; humans own the quality. Queue depth and SLA are visible in your dashboard.

What if I cancel?

Cancel any time. Export all your privacy notices, DSAR history, DPAs, breach logs, ROPA entries as PDF + CSV. We retain your data for the statutory period (6 years for breach evidence, ROPA evergreen until you formally request deletion). No contracts lock you in. The free trial is 14 days, no card needed.

60-second GDPR compliance check

Free. No card. Find out exactly which UK GDPR obligations apply to your business.

Run free check

Want this for your business?

Leave your details and we'll come back to you with what it does for your situation specifically — not a brochure.

£349 one-off when it opens — no card needed to join the list.