General Data Protection Regulation compliance, in plain English, in one afternoon.
A free 30-question self-assessment, built for small businesses with European customers, visitors, or staff. With it comes a three-tier toolkit: templates, deepened guides, and Excel workbooks. The assessment runs in your browser. Your answers never leave your device.
Three tiers, one-time purchase, files you own forever.
Existing $99 buyers have been grandfathered to the new SMB tier and continue to receive every new asset as it ships. Tier 3 buyers also receive the quarterly law-update bulletin by email.
- 30-question self-assessment
- 72-hour breach decision tree
- Single-operator Records of Processing Activities workbook
- Privacy notice cheat-sheet and consent copy library
- Three-letter Data Subject Access Request pack
- Everything in Solo
- Five deepened compliance guides (~160 pages)
- 13 working toolkit PDFs (Data Processing Agreement template, Breach Register, Retention Schedule Builder, and more)
- Five Excel workbooks with formulas pre-set
- Annual Compliance Calendar
- Everything in SMB
- Data Protection Impact Assessment template
- Industry case gallery
- Lead Supervisory Authority directory
- Quarterly law-update bulletin by email
- Optional agency add-on ($199) for white-label / co-brand rights
Two paths into the toolkit.
1. Take the free assessment
30 questions across data collection, processing, storage, sharing, and breach response. About ten minutes. Returns a score across all five areas, names your weakest area, and lists priority actions. Runs entirely in your browser — no email required, no data transmitted.
Take the free assessment →2. Browse the SMB Edition contents
See the full list of guides, workbooks, and templates before you buy. The lead magnet ("The 5 Most Common GDPR Mistakes") gives you a sense of the tone and depth in three minutes.
Read the free 5-mistakes guide →Also commonly bought together
If you handle EU customer data and need a security baseline, the SMB Security Assessment covers the controls cyber insurers ask about and overlaps usefully with Article 32 of GDPR.