Free · No sign up required · Takes 10 minutes
ICO fines up to £17.5m · Most UK SMEs don't know where they stand

Find out exactly where your business stands on GDPR

Talk to Alex, our AI data protection consultant. Get a personalised assessment of your GDPR compliance and a prioritised action plan delivered to your inbox — free, in under 10 minutes.

Free to start · deeper compliance analysis included in every bundle from £149/mo

AM

Alex

AI Data Protection Advisor · UK GDPR

AM
Hi, I'm Alex. Before we dive in — is your business primarily based in the UK, the EU, or do you operate across both?
We're UK-based.
AM
Good — so we'll be working to UK GDPR as administered by the ICO. Let's start with the data you hold. What kinds of personal information does your business collect or store?

Who this is for

GDPR compliance becomes business-critical at specific moments. If any of these apply, you need to know your position.

Growing your team

Onboarding new staff creates new GDPR obligations — employment data, background checks, access controls. Know what you need to have in place before you grow.

Raising investment

Investors run data protection due diligence on every deal. A GDPR gap at the wrong moment can delay or derail a funding round. Know your position before they ask.

Working with enterprise clients

Enterprise procurement requires Data Processing Agreements, supplier security questionnaires, and evidence of a compliance programme. Fortify tells you exactly what is missing — and the portal vendor register tracks DPA status across every supplier.

A complete picture across 10 GDPR areas

Every assessment covers the areas that matter most for UK GDPR compliance. Higher-tier diagnostics extend coverage with deeper sections on supplier governance, high-risk processing, and enterprise compliance readiness.

Not sure if you need to register with the ICO? We'll cover that in the assessment.
1

Data You Hold

What personal data your business collects, where it lives, and how it is categorised.

2

Lawful Basis & Consent

Whether you have a clear legal reason for collecting and using personal data — and whether consent is properly captured.

3

Privacy & Transparency

Your privacy notice, cookie consent mechanism, and how clearly you communicate data use to individuals.

4

Individual Rights

Your processes for handling access requests, deletion, objections, and the other rights UK GDPR gives individuals.

5

Breach Awareness

Whether you would know how to respond to a data breach and meet the 72-hour ICO reporting requirement.

6
Essentials and above

Governance & Accountability

Whether data protection is owned day-to-day, backed by policy, and supported by staff training.

Show 4 more assessment areas
7
Growth Ready and above

Third-Party Processors

Whether supplier contracts and Data Processing Agreements are in place for every tool that touches personal data. The portal vendor register tracks DPA status across your full supplier list.

8
Growth Ready and above

Marketing Compliance

Cookie consent infrastructure, email marketing opt-in records, and suppression processes across all channels.

9
Audit Ready only

DPIAs & High-Risk Processing

Whether risk assessments are completed before introducing new processing activities, AI tools, or automated decision-making.

10
Audit Ready only

International Transfers & DPO

Data transfer safeguards, DPO obligations under Article 37, ICO registration, and enterprise compliance programme maturity.

How it works

From conversation to compliance action plan in three steps.

01

Talk to Alex

Alex, our AI data protection consultant, guides you through a plain-English conversation covering the key areas of UK GDPR — no legal jargon, no trick questions.

02

Receive your report

Get a personalised findings report with a compliance score across each area, identified gaps, and a prioritised action checklist — delivered to your inbox.

03

Take action

Follow your action plan from quick wins you can tackle this week — like updating your privacy notice — to longer-term steps like implementing a DPIA process.

Free check — and deeper diagnostics in portal plans

The free automated GDPR check is available to everyone. GDPR Tier 1, 2, and 3 diagnostics are included in Fortify portal plans — no separate purchase required.

Exposure Check · Free

Are we exposed?

A quick, honest answer on whether your business has GDPR blind spots.

  • ✓AI-guided check across 5 GDPR areas
  • ✓Automated compliance score
  • ✓Prioritised action checklist
  • ✓Delivered by email in minutes
Start free GDPR check

Essential · Strategic · Advanced

GDPR Diagnostics

Included in Fortify portal plans — no separate purchase required.

  • ✓GDPR Tier 1 — Essential plan and above
  • ✓GDPR Tier 2 — Strategic plan and above
  • ✓GDPR Tier 3 — Advanced plan
View portal plans

Your privacy, clearly explained

We believe you should know exactly how your information is handled before you start.

Keep the chat about your business

Alex asks about your business processes and data practices — not about individuals. Please avoid sharing personal data such as staff names, personal contact details, or customer information during the assessment.

Your email is handled separately

At the end of the assessment you will be asked for your name and email address to deliver your report. This information is stored securely and is never processed by AI.

Your data is never used to train AI

Fortify uses the Anthropic Claude API to power assessments. Anthropic does not use data submitted via the API to train its models. Your responses are used solely to generate your report.

No data is sold or shared

Your assessment responses and contact details are never sold to third parties or shared with any external organisation. They are used only to deliver your report and, if you choose, to follow up on your results.

Common questions

Plain-English answers to the GDPR questions we hear most often.

Does GDPR apply to my business if I'm based in the UK?

Yes. Since Brexit, UK businesses are subject to UK GDPR, administered by the Information Commissioner's Office (ICO). The rules are substantially the same as EU GDPR but enforced separately. If you also sell to EU customers, you may have EU GDPR obligations too — Alex will ask about your jurisdiction at the start of the assessment.

Do I need to register with the ICO?

Most organisations that process personal data must pay the ICO's data protection fee (£40–£2,900 per year depending on your size and type). Some narrow exemptions apply. If you're unsure whether you need to register, the free assessment will flag it.

Do I need a Data Protection Officer (DPO)?

Only in specific circumstances — primarily public authorities, organisations carrying out large-scale systematic monitoring, or those processing special category data at scale. Most SMEs do not legally require a DPO, but should designate a named responsible person internally. Alex will assess your position.

What if we've already had a data breach?

The free assessment covers breach awareness and response readiness. If you've had an incident, the paid tiers include a deeper review of your incident response capability and whether a notification to the ICO was or still is required.

Is the free check enough for a small business?

For most micro-businesses and sole traders, the free check will identify obvious gaps and tell you what to fix first. If you hold significant customer data, use marketing automation, or work with enterprise clients, the Gap Analysis or Compliance Programme tier will give you a more complete and defensible picture.

Working with NHS data?

GDPR alone doesn't cover NHS-specific requirements

If your organisation processes NHS patient data or connects to NHS systems, you'll also need an annual DSPT submission — a separate, mandatory self-assessment against 10 National Data Guardian standards.

Learn about DSPT →

Ready to find out where you stand on GDPR?

Free, no sign up required, and you'll have your compliance report in under 10 minutes.

Start free GDPR check