Free · No sign up required · Takes 10 minutes
ICO fines up to £17.5m · Most UK SMEs don't know where they stand

Find out exactly where your business stands on GDPR

Talk to Alex, our AI data protection consultant. Get a personalised assessment of your GDPR compliance and a prioritised action plan delivered to your inbox — free, in under 10 minutes.

AM

Alex Morgan

Senior Data Protection Consultant · CIPP/E

AM
Hi, I'm Alex. Before we dive in — is your business primarily based in the UK, the EU, or do you operate across both?
We're UK-based.
AM
Good — so we'll be working to UK GDPR as administered by the ICO. Let's start with the data you hold. What kinds of personal information does your business collect or store?

Who this is for

GDPR compliance becomes business-critical at specific moments. If any of these apply, you need to know your position.

Growing your team

Onboarding new staff creates new GDPR obligations — employment data, background checks, access controls. Know what you need to have in place before you grow.

Raising investment

Investors run data protection due diligence on every deal. A GDPR gap at the wrong moment can delay or derail a funding round. Know your position before they ask.

Working with enterprise clients

Enterprise procurement requires Data Processing Agreements, supplier security questionnaires, and evidence of a compliance programme. Fortify tells you exactly what is missing — and the portal vendor register tracks DPA status across every supplier.

A complete picture across 10 GDPR areas

Every assessment covers the areas that matter most for UK GDPR compliance. Higher-tier diagnostics extend coverage with deeper sections on supplier governance, high-risk processing, and enterprise compliance readiness.

Not sure if you need to register with the ICO? We'll cover that in the assessment.
1

Data You Hold

What personal data your business collects, where it lives, and how it is categorised.

2

Lawful Basis & Consent

Whether you have a clear legal reason for collecting and using personal data — and whether consent is properly captured.

3

Privacy & Transparency

Your privacy notice, cookie consent mechanism, and how clearly you communicate data use to individuals.

4

Individual Rights

Your processes for handling access requests, deletion, objections, and the other rights UK GDPR gives individuals.

5

Breach Awareness

Whether you would know how to respond to a data breach and meet the 72-hour ICO reporting requirement.

6
Essentials and above

Governance & Accountability

Whether data protection is owned day-to-day, backed by policy, and supported by staff training.

Show 4 more assessment areas
7
Growth Ready and above

Third-Party Processors

Whether supplier contracts and Data Processing Agreements are in place for every tool that touches personal data. The portal vendor register tracks DPA status across your full supplier list.

8
Growth Ready and above

Marketing Compliance

Cookie consent infrastructure, email marketing opt-in records, and suppression processes across all channels.

9
Audit Ready only

DPIAs & High-Risk Processing

Whether risk assessments are completed before introducing new processing activities, AI tools, or automated decision-making.

10
Audit Ready only

International Transfers & DPO

Data transfer safeguards, DPO obligations under Article 37, ICO registration, and enterprise compliance programme maturity.

How it works

From conversation to compliance action plan in three steps.

01

Talk to Alex

Alex, our AI data protection consultant, guides you through a plain-English conversation covering the key areas of UK GDPR — no legal jargon, no trick questions.

02

Receive your report

Get a personalised findings report with a compliance score across each area, identified gaps, and a prioritised action checklist — delivered to your inbox.

03

Take action

Follow your action plan from quick wins you can tackle this week — like updating your privacy notice — to longer-term steps like implementing a DPIA process.

Choose your level

Start with the free exposure check, then upgrade based on the depth of review your business needs.

Exposure Check

Are we exposed?

Free

A quick, honest answer on whether your business has GDPR blind spots.

  • AI-guided check across 5 GDPR areas
  • Automated compliance score
  • Prioritised action checklist
  • Delivered by email in minutes
Start free GDPR check

Gap Analysis

Are we doing the basics right?

£500

A structured review confirming what is in place and what needs addressing.

  • Deeper assessment across 6 GDPR areas
  • Human-reviewed compliance gap report
  • 2–3 page findings with prioritised actions
  • Governance and accountability review
Get started

Compliance Programme

Are we safe to grow?

£1,500

Assess whether your data practices can handle growth, new staff, and new suppliers.

  • Comprehensive review across 8 GDPR areas
  • Full expert review (2–3 hours)
  • 5–7 page compliance roadmap
  • Processor management and DPIA guidance
Get started

Due Diligence Ready

Are we investor and audit ready?

£3,000

A full programme review — ready for due diligence, enterprise contracts, and regulatory scrutiny.

  • Complete assessment across 10 GDPR areas
  • Full review and implementation planning
  • 8–10 page compliance programme report
  • DPO readiness and Article 37 assessment
Get started
Compare what's included in each level
FreeEssentialsGrowth ReadyAudit Ready
Assessment areas
Data You Hold
Lawful Basis & Consent
Privacy & Transparency
Individual Rights
Breach Awareness
Governance & Accountability
Third-Party Processors
Marketing Compliance
DPIAs & High-Risk Processing
International Transfers & DPO
Report & support
ReportAI-generated PDF2–3 page consultant-reviewed gap report5–7 page compliance roadmap8–10 page compliance programme
Produced byAIFortify consultantSenior consultantSenior consultant
1:1 sessions60-minute review sessionTwo dedicated sessions
RoadmapAction checklistPrioritised remediation actions30/60/90-day compliance roadmapFull implementation plan

Your privacy, clearly explained

We believe you should know exactly how your information is handled before you start.

Keep the chat about your business

Alex asks about your business processes and data practices — not about individuals. Please avoid sharing personal data such as staff names, personal contact details, or customer information during the assessment.

Your email is handled separately

At the end of the assessment you will be asked for your name and email address to deliver your report. This information is stored securely and is never processed by AI.

Your data is never used to train AI

Fortify uses the Anthropic Claude API to power assessments. Anthropic does not use data submitted via the API to train its models. Your responses are used solely to generate your report.

No data is sold or shared

Your assessment responses and contact details are never sold to third parties or shared with any external organisation. They are used only to deliver your report and, if you choose, to follow up on your results.

Common questions

Plain-English answers to the GDPR questions we hear most often.

Does GDPR apply to my business if I'm based in the UK?

Yes. Since Brexit, UK businesses are subject to UK GDPR, administered by the Information Commissioner's Office (ICO). The rules are substantially the same as EU GDPR but enforced separately. If you also sell to EU customers, you may have EU GDPR obligations too — Alex will ask about your jurisdiction at the start of the assessment.

Do I need to register with the ICO?

Most organisations that process personal data must pay the ICO's data protection fee (£40–£2,900 per year depending on your size and type). Some narrow exemptions apply. If you're unsure whether you need to register, the free assessment will flag it.

Do I need a Data Protection Officer (DPO)?

Only in specific circumstances — primarily public authorities, organisations carrying out large-scale systematic monitoring, or those processing special category data at scale. Most SMEs do not legally require a DPO, but should designate a named responsible person internally. Alex will assess your position.

What if we've already had a data breach?

The free assessment covers breach awareness and response readiness. If you've had an incident, the paid tiers include a deeper review of your incident response capability and whether a notification to the ICO was or still is required.

Is the free check enough for a small business?

For most micro-businesses and sole traders, the free check will identify obvious gaps and tell you what to fix first. If you hold significant customer data, use marketing automation, or work with enterprise clients, the Gap Analysis or Compliance Programme tier will give you a more complete and defensible picture.

Ready to find out where you stand on GDPR?

Free, no sign up required, and you'll have your compliance report in under 10 minutes.

Start free GDPR check