← Everything we do
Security and compliance

Advice on privacy and security, with you in charge.

Help with GDPR, security policies and the questionnaires large customers send their suppliers, for a small or growing business. We review what you have, explain what the rules and the questions are really asking, point out the gaps and help you close them. Your team makes the decisions and owns the documents. We have built a GDPR programme of around a hundred documents, written twenty security policies, and prepared and answered 140 question due diligence packs for large financial firms, so the advice comes from practice.

What a review looks at

Tap a person to ask for erasure
0data flows checked
0copies found and erased
0gaps found and fixed

What a review checks: every flow of personal data in a small business, in turn. Click a person to send an erasure request and see what a working procedure has to find.

An illustration of what a well run setup looks like. The systems and the gaps are the ordinary ones a small business has.

How we help

Review, advice and a second pair of eyes.

  • Reviewing your GDPR setup against what you actually do
  • Helping you write a record of processing
  • Explaining lawful basis, and reviewing your legitimate interest assessments
  • Checking your privacy notice and cookie policy match the site
  • Walking your team through a data subject request, erasure included
  • Deciding when a DPIA is needed, and reviewing yours
  • Showing you how to check processors and keep a sub-processor register
  • Reviewing your international transfer assessments
  • Running a breach drill with your team and going over what it showed
  • Reviewing your information security policies, or helping you draft them
  • Advising on an AI register and an AI use policy
  • Explaining what a due diligence question is really asking
  • Reviewing questionnaire answers before they go back to a customer
  • Helping you set up a policy review so nothing goes stale

This is practical advice and review. We do not give legal advice or issue certificates, so for a legal question you still want a solicitor. The decisions and the answers stay yours. When you go for Cyber Essentials or ISO 27001, we can help you get ready for the assessor.

What you get

A setup you understand and own.

Grounded in what you do

We start from the tools you use and where your data really goes, and check your registers and policies against that. You come away knowing what each document is for and who on your team owns it.

Honest questionnaire answers

We go through your customer's pack with you, covering cloud, privacy, security and AI use, and explain what each question is looking for. Where the true answer would be no, we point out the gap and help you close it, such as switching on two factor sign in, so your answer can honestly be yes.

A review that keeps going

We help you set up a regular review of your policies, with owners and dates, so your team notices when something has gone stale. A year on, the programme still matches the business.

Been sent a questionnaire?

Send it over and we will go through it with you. Tell us who sent it and when it is due, or what you have in place today.

hello@bitwrighttechnologies.com