— Compliance Health Check · VAR/HC

How confident are you in your data protection compliance?

A structured assessment against the ICO's Accountability Framework — delivering a clear picture of where you stand and a prioritised plan to address the gaps.

— Reviewed and signed by Matthew Varnham
£1,500 fixed · Fully credited against any retainer · 14 days
— What you get

A clear diagnosis, not a vague report.

The Health Check is concise, practical, and focused on the actions that will make the biggest difference to your compliance posture. It produces a written deliverable you can hand to a board, a regulator, or a procurement counterparty.

01

Compliance maturity score

Rated against each of the eleven ICO Accountability Framework areas. Scores are evidence-based, with the rationale documented for every rating.

02

Visual dashboard

Traffic-light summary and radar chart at a glance — designed for board presentation and rapid orientation. Suitable for quoting to procurement counterparties.

03

Gap analysis

Specific findings for each area: what is in place, what is missing, what needs improving. Findings are documented with sufficient detail to support a remediation plan.

04

Risk ratings

Each finding rated by severity and likelihood. Ratings calibrated against ICO enforcement patterns — what the regulator actually focuses on, not theoretical risk.

05

Prioritised action plan

Sequenced remediation with timescales, ownership, and quick wins identified. The plan is the bridge between the assessment and a retained DPO engagement, if appropriate.

06

DUAA readiness

Assessment of your preparedness for the 19 June 2026 deadline. Specific findings on the new complaint handling procedure, transparency requirements, and other DUAA changes.

— Areas assessed

Mapped to the ICO's Accountability Framework.

The standard the regulator uses to evaluate compliance maturity. Eleven areas, each with structured assessment criteria and evidence requirements drawn directly from ICO guidance.

AF-01
Leadership and oversight
AF-02
Policies and procedures
AF-03
Training and awareness
AF-04
Individual rights
AF-05
Transparency
AF-06
Records of processing & lawful basis
AF-07
Contracts and data sharing
AF-08
Risks and DPIAs
AF-09
Records management & security
AF-10
Breach response & monitoring
AF-11
Regulatory change preparedness (DUAA)
— The process

Simple, structured, minimal disruption.

Most organisations complete the process within two to three weeks. The structure is designed to extract maximum diagnostic value from minimal demand on your team's time.

— Step 01

Pre-audit questionnaire

Complete a structured questionnaire covering governance, policies, processing activities, and compliance measures. Most clients complete it in 60–90 minutes.

— Step 02

Assessment & review

I review your responses, examine documentation, and conduct focused sessions with key contacts where required. The assessment is evidence-based throughout.

— Step 03

Report & recommendations

You receive a written report with scores, gap analysis, risk ratings, and a prioritised action plan. A 60-minute walkthrough call is included.

— Who it is for

The Health Check is right for you if…

01

You have never had a formal assessment

The Health Check provides a clear baseline so you know exactly where you stand. The output is a defensible compliance position you can build from.

02

A client is asking about your compliance

Larger organisations increasingly require suppliers to demonstrate data protection compliance. The Health Check report is the evidence base their procurement teams expect.

03

You are considering a retained DPO

A low-commitment way to experience the consultancy's approach before committing to an ongoing retainer. Most retainers begin with a Health Check.

04

You need to prepare for DUAA changes

Includes specific assessment of readiness for the complaint handling requirement, the transparency changes, and other upcoming DUAA provisions.

— Get started

Enquire about a Health Check.

Tell me about your organisation and I will come back within one working day with a tailored proposal — scope, timescales, and a fixed-fee quote.

The intake form is the entry point. Name, email, phone, nature of enquiry. After you submit, I will respond personally with the right next step.

— Health Check intake

A short form, then a written proposal.

The intake form takes under two minutes. After you submit, I will respond within one working day with a Health Check proposal that includes scope, timescales, and a fixed-fee quote.

01
Complete the intake. Select "Health Check enquiry" as the nature of your enquiry.
02
Receive the proposal. Scope, timescales, fixed-fee quote — within one working day.
03
Engagement starts on confirmation. The pre-audit questionnaire arrives the same day.
Open the intake form →