What does a GDPR consultant do?
A GDPR consultant reviews how a business collects, stores, uses and shares personal data, identifies where practice has drifted from what the UK GDPR expects, and helps put working processes in place. Our GDPR compliance reviews cover privacy notices, records of processing, subject access requests, direct marketing, breach readiness, vendors and workplace AI use, and produce a prioritised action plan with named owners and target dates.
Does my business need an ICO registration?
Most UK organisations that process personal data must pay the ICO data protection fee, though exemptions exist and the position depends on what your business actually does. We help you assess whether registration is likely to apply, gather the information the registration asks for and understand the process. The determination and the registration itself remain yours to make with the ICO. We are not the ICO and we cannot approve or confirm your position for it.
Can BridgeLayer help with a subject access request?
Yes, on the operational side. We help you organise and manage the process: logging the request, verifying identity, locating the information across your systems, tracking the deadline, and coordinating review and redaction. Where a request raises a complex exemption question, we identify it and recommend you take advice from an appropriately qualified solicitor. More on SAR support.
Can BridgeLayer review our privacy notice?
Yes. We review website, employee and customer privacy information against what your business actually does with personal data, which is usually where the gap sits. Notices tend to describe an earlier version of the business. We identify the differences and rewrite the notice so it matches practice. More on privacy-notice support.
What is a GDPR compliance review?
A structured look at how your business manages personal data day to day: documentation, processes, responsibilities and records. We identify practical gaps, rate them by real risk to your business, and set out what to fix first. You receive a written action plan rather than a list of regulatory extracts. You can read the full illustrative plan before you speak to us.
Can BridgeLayer help us create a workplace AI policy?
Yes. We inventory the AI tools your team actually uses, agree an approved-tool list, set rules for what information may and may not be entered, define where human review is required, and issue a one-page policy staff will follow. Rules nobody reads change nothing, so we keep it to a page. More on workplace AI governance.
What happens if our business has a data breach?
You need to know quickly who assesses it and whether it meets the threshold for reporting to the ICO within 72 hours. We help you build that route in advance: how staff report an incident, who logs it, who decides, and what evidence is kept. We support the operational response. Where a breach raises questions of legal exposure, we identify the boundary and recommend you take advice from an appropriately qualified solicitor. More on breach readiness.
Who is the Founding Client Offer for?
The first ten UK businesses we work with, typically 10 to 50 staff, holding customer or employee data, running their own marketing, or with teams already using AI tools. We speak most often with recruitment agencies, marketing agencies, professional-services firms and growing B2B technology businesses. Requesting a place costs nothing and is not binding. See the Founding Client Offer.
Is the risk scanner legal advice?
No. The scanner gives an indicative operational risk profile based on nine multiple-choice answers. It is general operational information. It is not legal advice, not a compliance determination, and not a rating, score or certification of any kind. It cannot account for your contracts, your sector rules or the specifics of your processing, which is what a proper review is for.
What information does the scanner collect?
Nine multiple-choice answers and nothing else. There are no free-text questions, so you are never invited to enter personal or confidential business information. Your answers are processed to generate your result. If you request a written copy by email, we hold that email address so that we can send it and reply to you. Our privacy notice sets out every processor involved and how long we keep things.
Is BridgeLayer UK-based?
Yes. We are based in London and work with businesses across the United Kingdom. The service is built around UK GDPR, the Data Protection Act 2018, ICO expectations and PECR, and around how UK small businesses actually operate day to day.
When do paid engagements begin?
Paid engagements begin from September 2026. Requesting a Founding Client place before then costs nothing and is not binding on either side.