SME

duaa compliance checklist uk smes a upright grooved slab

DUAA Compliance: Essential SME Checklist to Avoid Costly Fines

The Data (Use and Access) Act 2025 is fully commenced and there is no small-business exemption from the parts that matter. This checklist is written for the firm with no data protection officer and one person watching the shared inbox: a three-question scoping test, the five-item baseline every UK controller must meet, the conditional duties that only fire for some businesses, the new universal complaints procedure and its 30-day clock, the cookie audit behind a PECR ceiling that rose from £500,000 to £17.5 million, automated decisions hiding inside off-the-shelf SaaS, an honest hour-and-cost budget, the nine-artefact evidence pack, seven small-business failure patterns, and a ninety-day plan with owners.

Read more
data governance framework for smes a three stacked hexagonal plates

Data Governance Framework: Proven SME Guide to Avoid Risk

Almost every published data governance framework assumes a team that a small business does not have. This guide is written for the reality of ten to two hundred and fifty people: the six components that carry the value, who owns each one in a firm with no chief data officer, how to build a system inventory in a fortnight rather than a year, three classification tiers with handling rules people will actually follow, the four data quality measures worth tracking, a one-page retention schedule with UK periods and triggers, access reviews and processor contracts, what AI changes, which tooling is already inside licences you own, a ninety-day implementation plan, realistic first-year costs, six metrics to report quarterly, and the five failure modes that end most attempts.

Read more
CHAT