Custom Policies & Procedures

We provide tailored policies and procedures to ensure compliance with data protection regulations. Whether you need custom-made policies or a thorough review of existing ones, we offer expert solutions to enhance your compliance framework.

We can review all your existing Policies and procedures, and redraft where necessary, or supply you with new Policies.

What We Cover:

Data Protection & GDPR Compliance Documents

✅ Change Management Policy
✅ System & Application Access Review Procedure
✅ Incident Response Plan / Security Incident Management Policy
✅ Backup & Business Continuity Policy
✅ Disaster Recovery Plan (DRP)
✅ Supplier & Third-Party Risk Management Policy
✅ Information Transfer Policy (email, file sharing, removable media)
✅ Monitoring & Logging Policy
✅ Penetration Testing & Vulnerability Assessment Procedure
✅ Physical Security Policy
✅ Secure Disposal & Media Destruction Policy
✅ Staff Awareness & Security Training Policy
✅ Information Security Roles and Responsibilities Matrix

✅ Information Security Policy
✅ Access Control Policy
✅ Asset Management Policy
✅ Acceptable Use Policy (AUP)
✅ Bring Your Own Device (BYOD) Policy
✅ Cryptographic Controls Policy
✅ Data Classification & Handling Policy
✅ Email & Communication Security Policy
✅ Endpoint Security Policy
✅ Mobile Device Management (MDM) Policy
✅ Cloud Services Usage Policy
✅ Network Security Policy
✅ Firewall & Intrusion Detection Policy
✅ User Account & Password Policy
✅ Remote Working / Remote Access Policy
✅ Patch Management & Vulnerability Management Policy
✅ Secure Software Development Policy

Information Security Policies

✅ Data Protection Policy
✅ Privacy Policy (internal and external versions)
✅ Subject Access Request (SAR/DSAR) Procedure
✅ Data Breach Response Plan / Breach Notification
✅ Data Retention & Erasure Policy
✅ Record of Processing Activities (ROPA)
✅ Lawful Basis Assessment Records
✅ Data Minimisation and Purpose Limitation
✅ Data Subject Rights Procedure (access, rectification, erasure, restriction, objection, portability)
✅ Consent Management Procedure
✅ Legitimate Interests Assessment (LIA) Template
✅ Data Protection Impact Assessment (DPIA) Template & Register

✅ Third Party Data Sharing Register
✅ Data Sharing Agreements / MOUs

✅ Data Processing Agreements (DPA)
✅ International Data Transfer Risk Assessments
✅ Standard Contractual Clauses (SCCs) / Transfer Impact Assessments (TIAs)
✅ Children’s Data and Parental Consent Procedures (if applicable)
✅ Data Classification & Handling Policy
✅ CCTV & Surveillance Policy
✅ Cookies & Tracking Technologies Policy
✅ Automated Decision-Making & Profiling Notice
✅ Accountability & Governance Framework Document
✅ Staff Data Protection Training Records
✅ Policy Management and Version Control Log
✅ Data Protection Officer (DPO) Appointment Record (where required)
✅ Freedom of Information / Environmental Information Request Procedure (public sector) here...