Talk to Alex, our AI data protection consultant. Get a personalised assessment of your GDPR compliance and a prioritised action plan delivered to your inbox — free, in under 10 minutes.
Or start from a specific situation
Alex Morgan
Senior Data Protection Consultant · CIPP/E
GDPR compliance becomes business-critical at specific moments. If any of these apply, you need to know your position.
Onboarding new staff creates new GDPR obligations — employment data, background checks, access controls. Know what you need to have in place before you grow.
Investors run data protection due diligence on every deal. A GDPR gap at the wrong moment can delay or derail a funding round. Know your position before they ask.
Enterprise procurement requires Data Processing Agreements, supplier security questionnaires, and evidence of a compliance programme. Fortify tells you exactly what is missing — and the portal vendor register tracks DPA status across every supplier.
Every assessment covers the areas that matter most for UK GDPR compliance. Higher-tier diagnostics extend coverage with deeper sections on supplier governance, high-risk processing, and enterprise compliance readiness.
What personal data your business collects, where it lives, and how it is categorised.
Whether you have a clear legal reason for collecting and using personal data — and whether consent is properly captured.
Your privacy notice, cookie consent mechanism, and how clearly you communicate data use to individuals.
Your processes for handling access requests, deletion, objections, and the other rights UK GDPR gives individuals.
Whether you would know how to respond to a data breach and meet the 72-hour ICO reporting requirement.
Whether data protection is owned day-to-day, backed by policy, and supported by staff training.
Whether supplier contracts and Data Processing Agreements are in place for every tool that touches personal data. The portal vendor register tracks DPA status across your full supplier list.
Cookie consent infrastructure, email marketing opt-in records, and suppression processes across all channels.
Whether risk assessments are completed before introducing new processing activities, AI tools, or automated decision-making.
Data transfer safeguards, DPO obligations under Article 37, ICO registration, and enterprise compliance programme maturity.
From conversation to compliance action plan in three steps.
Alex, our AI data protection consultant, guides you through a plain-English conversation covering the key areas of UK GDPR — no legal jargon, no trick questions.
Get a personalised findings report with a compliance score across each area, identified gaps, and a prioritised action checklist — delivered to your inbox.
Follow your action plan from quick wins you can tackle this week — like updating your privacy notice — to longer-term steps like implementing a DPIA process.
Start with the free exposure check, then upgrade based on the depth of review your business needs.
Exposure Check
Are we exposed?
Free
A quick, honest answer on whether your business has GDPR blind spots.
Gap Analysis
Are we doing the basics right?
£500
A structured review confirming what is in place and what needs addressing.
Compliance Programme
Are we safe to grow?
£1,500
Assess whether your data practices can handle growth, new staff, and new suppliers.
Due Diligence Ready
Are we investor and audit ready?
£3,000
A full programme review — ready for due diligence, enterprise contracts, and regulatory scrutiny.
| Free | Essentials | Growth Ready | Audit Ready | |
|---|---|---|---|---|
| Assessment areas | ||||
| Data You Hold | ✓ | ✓ | ✓ | ✓ |
| Lawful Basis & Consent | ✓ | ✓ | ✓ | ✓ |
| Privacy & Transparency | ✓ | ✓ | ✓ | ✓ |
| Individual Rights | ✓ | ✓ | ✓ | ✓ |
| Breach Awareness | ✓ | ✓ | ✓ | ✓ |
| Governance & Accountability | — | ✓ | ✓ | ✓ |
| Third-Party Processors | — | — | ✓ | ✓ |
| Marketing Compliance | — | — | ✓ | ✓ |
| DPIAs & High-Risk Processing | — | — | — | ✓ |
| International Transfers & DPO | — | — | — | ✓ |
| Report & support | ||||
| Report | AI-generated PDF | 2–3 page consultant-reviewed gap report | 5–7 page compliance roadmap | 8–10 page compliance programme |
| Produced by | AI | Fortify consultant | Senior consultant | Senior consultant |
| 1:1 sessions | — | — | 60-minute review session | Two dedicated sessions |
| Roadmap | Action checklist | Prioritised remediation actions | 30/60/90-day compliance roadmap | Full implementation plan |
We believe you should know exactly how your information is handled before you start.
Alex asks about your business processes and data practices — not about individuals. Please avoid sharing personal data such as staff names, personal contact details, or customer information during the assessment.
At the end of the assessment you will be asked for your name and email address to deliver your report. This information is stored securely and is never processed by AI.
Fortify uses the Anthropic Claude API to power assessments. Anthropic does not use data submitted via the API to train its models. Your responses are used solely to generate your report.
Your assessment responses and contact details are never sold to third parties or shared with any external organisation. They are used only to deliver your report and, if you choose, to follow up on your results.
Plain-English answers to the GDPR questions we hear most often.
Yes. Since Brexit, UK businesses are subject to UK GDPR, administered by the Information Commissioner's Office (ICO). The rules are substantially the same as EU GDPR but enforced separately. If you also sell to EU customers, you may have EU GDPR obligations too — Alex will ask about your jurisdiction at the start of the assessment.
Most organisations that process personal data must pay the ICO's data protection fee (£40–£2,900 per year depending on your size and type). Some narrow exemptions apply. If you're unsure whether you need to register, the free assessment will flag it.
Only in specific circumstances — primarily public authorities, organisations carrying out large-scale systematic monitoring, or those processing special category data at scale. Most SMEs do not legally require a DPO, but should designate a named responsible person internally. Alex will assess your position.
The free assessment covers breach awareness and response readiness. If you've had an incident, the paid tiers include a deeper review of your incident response capability and whether a notification to the ICO was or still is required.
For most micro-businesses and sole traders, the free check will identify obvious gaps and tell you what to fix first. If you hold significant customer data, use marketing automation, or work with enterprise clients, the Gap Analysis or Compliance Programme tier will give you a more complete and defensible picture.
Free, no sign up required, and you'll have your compliance report in under 10 minutes.
Start free GDPR check