Data protection for small businesses
Get compliant without becoming a data protection expert.
Answer plain-English questions about how your business works. The Register turns your answers into the formal records the law requires, tells you what needs attention and why, and keeps everything current as your business changes. No specialist needed.
No credit card needed. Map your business and see your gaps free.
Get your GDPR records sorted for less than £30 a month.
UK/EU hosted · encrypted · strict tenant isolation
The Data (Use and Access) Act 2025 is now in force. See what changed for small businesses, what you can ignore, and whether you still need a ROPA.
Compliance records are easy to write and hard to keep
Records drift out of date
A ROPA written once and filed away stops matching reality the moment a process, vendor, or system changes, and nobody notices until an audit.
The same facts, re-entered everywhere
A single processing activity feeds your ROPA, your DPIAs, your transfer assessments. Maintained separately, they drift apart and contradict each other.
Audits become a scramble
When the regulator or a customer asks, you shouldn't be reconstructing months of changes from email threads and spreadsheets.
And the law is specific about it
Read the plain-English primers →- Written records are mandatory for most organisations
- Article 30 requires them, and the small-business exemption falls away for regular processing. Run payroll and you are almost certainly in scope.
- Compliance has to be demonstrable
- Article 5(2) requires you to show how you comply, not merely to comply. The proof is your records.
- Risk assessments are a legal trigger
- Article 35 makes a DPIA mandatory before high-risk processing. It is not optional best practice.
- A stale record is its own finding
- A ROPA that no longer matches reality shows the organisation does not currently know what it does with personal data.
How it works
Three stages, and you only ever do the first.
Answer guided questions
Describe each processing activity once, guided through the standard Article 30 information: purpose, lawful basis, data subjects, recipients, transfers, retention, and security.
Your ROPA assembles itself
The Record of Processing Activities is built directly from your answers and updates automatically as your business changes. There is no document to regenerate: change an activity and the register reflects it.
Generate the assessments
Where the law requires judgement (DPIAs, legitimate interests and transfer risk assessments), Claude drafts the assessment from your records, and it is flagged for review whenever the underlying facts change.
One shared foundation feeds every record, which is what keeps them consistent:
- ROPA Record of Processing Activities
- DPIA Data Protection Impact Assessment
- TRA Transfer Risk Assessment
- LIA Legitimate Interests Assessment
Not sure where you stand?
Eight plain-English questions, about two minutes. You get a readiness score and a prioritised action list for your business, free.
Built for businesses like yours
If you employ people or hold customer data, you have records to keep.
Agencies & consultancies
Client lists, candidate CVs and contractor details spread across email, CRMs and shared drives.
Ecommerce & retail
Customer orders, delivery addresses and marketing lists, with the consent rules that come with them.
Clinics & private practices
Patient and client health data, which is special category data and often needs a DPIA.
Accountants & professional services
Client financial records you are trusted to hold, and clients who increasingly ask how you protect them.
Charities & non-profits
Donor, member and beneficiary data, sometimes sensitive, usually managed on a shoestring.
SaaS & startups
User data from day one, and enterprise customers whose security questionnaires you need to pass.
Secure by default
Read our security approach →Your records can themselves contain personal data, so the security you would need a specialist to set up elsewhere is simply how the Register works.
- UK/EU data residency
- Encrypted in transit & at rest
- Strict tenant isolation
- Append-only audit log
- Minimal data to AI
- MFA-capable sign-in
Frequently asked questions
Do I need any data protection knowledge to use this?
No. You answer questions about how your business actually works: who you employ, what tools you use, who you share data with. The Register turns those answers into formal records, and its built-in review explains in plain English anything that needs attention and why it matters.
We're a small business. Isn't this overkill?
It's built for you. Most compliance products are designed for enterprises with privacy teams; the Register assumes you have neither. And the legal duty to keep records reaches far smaller organisations than most people expect: if you run payroll, it almost certainly includes you. The resources section explains why.
Where is my data stored?
In the EU. The product is built to treat your records, which can contain personal data, with a security baseline from day one (encryption, tenant isolation, audit logging).
How is AI used, and is my data used to train models?
Your ROPA involves no AI at all: it is assembled directly from your answers. AI drafts the judgement documents (DPIAs, LIAs, compliance reviews), server-side, sending only the minimum necessary data and logging every call. Business data sent to the Anthropic API is not used to train models.
Does this replace legal advice?
No. The Register helps you produce and maintain your records efficiently; it is not a substitute for professional data-protection or legal advice.
Get your records in order
Create a free account, capture your processing activities, and see exactly where you stand in minutes. No credit card needed.
Not ready yet? Take the 2-minute readiness check or download the free GDPR checklist.