Data and privacy pack
Under UK GDPR a personal data breach likely to risk people's rights must be reported to the ICO within 72 hours, and a subject access request answered within one month. Both deadlines are missed most often by businesses with no written procedure to follow on the day.
Core pack · 11 documents · 68 pages
The short answer
Under UK GDPR a personal data breach likely to risk people's rights must be reported to the ICO within 72 hours, and a subject access request answered within one month. Both deadlines are missed most often by businesses with no written procedure to follow on the day.
Who this pack is for
- Any UK business holding customer or staff records, which is all of them
- Ecommerce and service businesses handling online enquiries
- Employers storing HR files, payroll and health information
- Businesses asked for a data processing agreement by a larger client
- Anyone who has received a subject access request and does not know the deadline
Not for you if: You are a large organisation required to appoint a statutory data protection officer and need bespoke governance.
What it solves
A customer asks for everything you hold on them and the clock starts.
A laptop is lost and nobody knows whether the ICO must be told.
A corporate client refuses to sign until you produce a processor agreement.
What the law requires
Breaches: 72 hours
A personal data breach must be reported to the ICO without undue delay and within 72 hours of becoming aware, unless it is unlikely to risk people's rights. High risk breaches must also be told to the individuals. A breach log is required whether or not the breach is reportable.
Source: ICO, personal data breaches guidance
Subject access: one month, usually free
You must respond within one calendar month, extendable by two months for complex requests. There is no fee except where the request is manifestly unfounded or excessive. Identity checks pause the clock only if made promptly.
Source: ICO, right of access guidance
You must know what you hold
Most organisations must keep a record of processing activities covering purposes, categories of data, recipients, transfers and retention. It is the first document the ICO asks for, and it is what makes a retention schedule possible.
Source: ICO, documentation and ROPA guidance
What is in the pack
| ID | Document | Pages |
|---|---|---|
| DAT-01 | Privacy notice (customers)ICO privacy notice checklist | 6 |
| DAT-02 | Privacy notice (employees)ICO employment practices guidance | 6 |
| DAT-03 | Cookie policy and consent textPECR; ICO cookies guidance | 4 |
| DAT-04 | Data retention scheduleICO storage limitation | 5 |
| DAT-05 | Record of processing activitiesUK GDPR Article 30 | 7 |
| DAT-08 | Subject access request procedure and lettersICO right of access | 8 |
| DAT-09 | Breach log and response planICO breach reporting | 6 |
And four more: data protection policy, DPIA template, data processor agreement, staff training record.
How updates work
Every document carries a version number and a reviewed date. On the first Tuesday of each month the pack is checked against its primary sources. If anything has changed you receive the updated file and one line explaining what moved and why. If nothing has changed you receive an email saying so.
April and the Budget are the months when most figures move.
Questions
Do I need a data protection officer?
Most small businesses do not. A DPO is required for public authorities and for large scale monitoring or special category processing. The pack includes a named data contact instead.
Is a cookie banner enough?
No. Non-essential cookies need consent before they are set, and the policy has to describe them. The pack includes the policy text and the consent wording.
Does this cover EU customers?
The documents are written for UK GDPR. If you offer goods or services into the EU you may also need an EU representative, which is outside this pack.
What if I use cloud tools like Google or Microsoft?
Those are processors. The pack includes the processor agreement template and a supplier list for your ROPA.
How is it delivered?
By email, as Word and PDF files, personalised with your company details.
Sources
Built from published UK primary sources only: ICO, documentation and ROPA guidance, ICO, personal data breaches guidance, ICO, right of access guidance. No secondary or aggregator sources are used.
Order the data and privacy pack, or ask about an association licence covering your whole membership.
Email support@kaeltripton.comThese documents are drafted from published UK primary sources and are a starting point you adapt to your own circumstances. They are not legal, tax or immigration advice, and documents you edit become your responsibility.