General Data Protection Regulation compliance, in plain English, starting this afternoon.
A free 30-question self-assessment, built for small businesses with European customers, visitors, or staff. With it comes a three-tier toolkit: templates, deepened guides, and Excel workbooks. The assessment runs in your browser. Your answers never leave your device.
Two paths into the toolkit.
1. Take the free assessment
30 questions across data collection, processing, storage, sharing, and breach response. About ten minutes. Returns a score across all five areas, names your weakest area, and lists priority actions. Runs entirely in your browser — no email required, no data transmitted.
Take the free assessment →2. Read the free 5-mistakes guide
"The 5 Most Common GDPR Mistakes" gives you a sense of the tone and depth in three minutes — and the full list of guides, workbooks, and templates is in the toolkit below.
Read the free 5-mistakes guide →This is for getting GDPR-ready before anything goes wrong.
It's the readiness work (mapping data, closing gaps, and building the records the General Data Protection Regulation expects), not a live incident. If a breach is happening right now, GDPR Breach Response runs the 72-hour clock; if you also want a security baseline (useful for the Article 32 security-measures requirement), see the SMB Security Assessment.
Three tiers, one-time purchase, files you own forever.
Tier 3 buyers receive the quarterly law-update bulletin by email for as long as the product is in our catalogue.
- 72-hour breach decision tree
- Single-operator Records of Processing Activities workbook
- Privacy notice cheat-sheet and consent copy library
- Three-template Data Subject Access Request letter pack
- Data-mapping starter — trace where one named person's data actually lives
Enough if you’re a one-person business that needs a defensible baseline fast.
Buy Solo — $49- Everything in Solo
- Five deepened compliance guides (~160 pages)
- 27 more documents — the five guides above plus the working toolkit: Data Processing Agreement template, Breach Register, Retention Schedule Builder, and more (40 documents in all)
- Consent and cookie-banner checks — the dark-pattern traps and the ePrivacy line
- Key registers and worksheets also come as editable Excel workbooks, ready to fill in
- Annual Compliance Calendar
Choose this when you need a documented programme, not just a checklist.
Buy Team — $129- Everything in Team
- Data Protection Impact Assessment template
- Industry case gallery
- Lead Supervisory Authority directory
- Quarterly law-update bulletin by email, while the product is in our catalogue
- DSAR (Data Subject Access Request) surge operations guide — the lawful levers and the process that survives a co-ordinated wave
- Enforcement lessons file — eight worked enforcement patterns and the demonstration test behind each
- Profiling and Article 22 guide — when your analytics turns into a decision the law watches
- AI and data-protection note — what to check before you ship an AI feature
- The standard Pro licence: use the toolkit with as many clients as you serve, and deliver your work under your own name — no add-on to buy
Step up here if you advise others or run privacy as an ongoing, audited function.
Buy Pro — $299Every tier is a one-time purchase with a 30-day money-back guarantee, no questions asked, and free updates while the toolkit is in our catalogue.
How access works: the documents in every tier are downloads you keep, and the assessment app unlocks in your browser with the licence key from your purchase receipt — no account, no sign-in. The key activates on up to 3 devices on the solo tier, 7 on the middle tier, and 13 on the top tier.
The companion books: the field guide and the workbook behind this toolkit.
The books teach the discipline; the toolkit does the work with you. GDPR Compliance covers the judgement; the Operator's Workbook carries the records and templates.
If this is your situation, one of these usually is too
Two products pair naturally with the Checklist. If you also need a security baseline, the SMB Security Assessment covers the controls cyber insurers ask about and overlaps usefully with Article 32 of GDPR. And if a breach actually happens, GDPR Breach Response is the tactical companion that runs the 72-hour clock — the Checklist gets you ready; Breach Response handles the live incident.
SMB Security Assessment
The other half of the compliance-plus-security picture for European-facing SMBs: 12-question security self-assessment + a full toolkit of policies, templates, and training decks.
GDPR Breach Response
The live-incident companion. When a breach actually happens, this is the 72-hour toolkit — Article 33/34 notification templates, supervisory-authority filing, and the board briefing. The Checklist gets you ready; Breach Response runs the clock.
The situation this toolkit is built for, written up.
Which GDPR lawful basis actually applies? — ~10 min read.