— The retained service

Three retainer tiers, priced by time, scoped honestly.

Each tier is a committed number of hours per month at a fixed monthly retainer fee. Hours are used flexibly across DPO duties — governance, advisory, DSAR support, breach response, documentation. The right tier is determined by the scale of your data footprint and the regulatory exposure of your sector. The compliance health check is the quickest way to know which.

— Every output reviewed and signed by Matthew Varnham
CIPP/E · CIPM · ICO Registered
— How the retainer works

Hours-based, transparent, scoped to fit.

The retainer is structured the way professional services should be: a committed monthly fee for a defined number of hours, with overflow at a published hourly rate. You know what you are buying and you know what the worst case looks like financially.

01

A committed monthly hours budget

Each tier has a stated number of hours per month — used flexibly across DPO duties as your situation requires. Quiet months give you headroom; busy months use the budget you have already paid for.

02

Overflow at a published hourly rate

If a month exceeds your committed hours — typically because of a breach, a complex DSAR, or an unexpected DPIA — the overflow is billed at a published hourly rate, agreed in writing at engagement. No surprises.

03

Membership benefits regardless of hours

Some elements are part of the retainer relationship itself, not the hours commitment: named DPO designation, ICO registration as your DPO contact, and breach triage within four working hours. These do not draw down your monthly hours.

04

Tier movement when your needs change

You can move up or down a tier with one month's notice. Most clients start at the tier suggested by their Health Check; some scale up after the first quarter once we both understand the actual workload.

— Tier comparison

Each tier is a hours-per-month commitment.

Choose the tier that fits the time your organisation realistically needs each month. The Health Check report includes a recommendation; most clients land within one tier of that recommendation after their first quarter.

— Compare
Three tiers
Hours used flexibly across DPO duties. Overflow billed at a published hourly rate, agreed at engagement.
— Tier 01
Essentials
6 hrsper month
10–25 employees · lower-risk processing · light governance cadence
— Tier 02
Standard
12 hrsper month
25–100 employees · regulated sector or material processing · structured governance
— Tier 03
Premium
24 hrsper month
100–250 employees · high-risk processing · board-engaged compliance
— Membership benefits · always included regardless of hours
Named, accountable Data Protection Officer
Included
Included
Included
ICO registration as your DPO contact
Included
Included
Included
Initial breach triage call within 4 working hours
Included
Included
Included
Monthly regulatory update — brief written summary
Included
Included
Included
Annual structured review
1 hour
1 hour
2 hours
— What is typically done within the monthly hours
Governance meeting attendance and follow-up
As required
As required
As required
Ad-hoc advisory — email, phone, Teams
Within hours
Within hours
Within hours
DSAR triage and response support
Within hours
Within hours
Within hours
Privacy notice and policy maintenance
Within hours
Within hours
Within hours
DPIAs as required
Within hours
Within hours
Within hours
Records of Processing Activities (ROPA) maintenance
Within hours
Within hours
Within hours
Breach response beyond the initial triage call
Within hours
Within hours
Within hours
Sector-specific regulatory monitoring
Tier 02+ only
Within hours
Within hours
Board-level reporting
Tier 02+ only
Bi-annual
Quarterly
Named representation in regulatory correspondence
Tier 03 only
Tier 03 only
Included
— Pricing
Monthly retainer fee
Fee on application
Fee on application
Fee on application
Hourly rate for overflow beyond committed hours
Agreed at engagement
Agreed at engagement
Agreed at engagement
— On pricing

Why pricing is not on the page.

Retainer fees are calibrated to the scale and complexity of each engagement — and to the right outcome being a long, productive relationship rather than a transaction. The fixed monthly fee, the hourly rate for overflow, and the indicative hours commitment are all confirmed in writing as part of the services agreement before the engagement begins.

The tier indication and a tailored fee proposal follow the initial conversation — typically within one working day of the intake form being completed.

— How an engagement begins

Four steps from referral to first deliverable.

Every engagement follows the same path. The structure ensures that what is in scope, what is committed, and what costs what is agreed in writing before any meaningful effort is committed.

— Step 01

Initial conversation

A thirty-minute call after you complete the intake form. We discuss your organisation, current arrangements, and whether the consultancy is the right fit. No charge, no obligation either way.

— Step 02

Compliance health check

The eleven-area assessment, returned as a written report with a prioritised action plan and a tier recommendation. Fixed fee at £1,500, fully credited against any retainer that follows.

— Step 03

Tailored fee proposal

Based on the Health Check findings, a written proposal — recommended tier, monthly retainer fee, hourly overflow rate, and a description of how the hours are likely to be used in the first quarter.

— Step 04

Engagement begins

Services agreement signed. The retainer commences from the first of the following month. The agreed cadence of governance, documentation, and review begins immediately.

— Extended services

Specialist projects beyond the retainer.

Discrete project engagements — available to retainer clients (drawing on hours or quoted as additional work) and as standalone commissions for organisations not yet on a retainer.

— VAR/DPIA

Data Protection Impact Assessments

DPIA screening, full assessments, and ICO consultation advice for high-risk processing — including AI, cloud migration, and new technology adoption. Delivered to ICO methodology with stakeholder engagement.

— VAR/AN

Supplier due diligence & processor management

Due diligence assessments, Article 28 data processing agreements, sub-processor management, and international transfer assessments. Built to satisfy enterprise procurement scrutiny.

— VAR/INT

International data transfer guidance

Transfer Risk Assessments, UK IDTA and UK Addendum implementation, supplementary measures, and transfer mapping across your supplier estate. Banking-grade methodology applied at SME scale.

— VAR/HC

Compliance audit & health check

Point-in-time assessment against the ICO's Accountability Framework producing findings, risk ratings, and a prioritised remediation plan. The starting point for most engagements.

Read more →
— Standalone engagements

Where a retainer is not yet right, fixed-fee products instead.

For organisations that need a specific piece of work delivered well rather than an ongoing relationship. Each is a fixed-fee engagement with a defined scope and a written deliverable.

— VAR/HC

Compliance health check

The eleven-area assessment, returned as a written report with prioritised action plan. The fastest way to know where you stand. Fully credited against any retainer that follows — effectively free for clients who go on to retain.

— VAR/DPIA

DPIA delivery

A complete Data Protection Impact Assessment for a defined processing activity, delivered against ICO methodology with stakeholder engagement.

— VAR/ROPA

ROPA construction

A complete Records of Processing Activities document for an organisation without one — discovery, drafting, validation, and embedding.

— VAR/DSAR

DSAR programme review

A standalone review of how subject access requests are received, handled, and responded to. Written report, recommendations, draft templates.

— VAR/INT

International transfers

Transfer Impact Assessment, SCC review, and supporting documentation for organisations with non-UK processors or controllers.

— VAR/TR

Staff training session

A 90-minute facilitated session for the senior team or the whole organisation. Sector-tailored, with materials retained for ongoing reference.

— VAR/PDB

Breach management retainer

72-hour SLA breach response — triage, assessment against the notification threshold, ICO liaison, root-cause analysis, and remediation. Available as a standalone retainer for organisations not on a full DPO retainer.

— VAR/AN

Policies & documentation

Privacy notices, data protection policies, retention schedules, DPAs — written for the people who actually use them, mapped to ICO Accountability Framework requirements.

— On pricing and getting a quote

Tailored, transparent, fixed at engagement.

Retainer fees are calibrated to the scale and complexity of your organisation. Standalone product fees are fixed against a defined scope. Out-of-scope work is always quoted separately before any commitment is made.

No hourly billing without an agreed rate. No scope creep. No surprise invoices. You will know what an engagement costs before you commit to it.

Get a tailored proposal →
— How a quote works

Intake form, then a tailored written proposal.

Tell me about your organisation through the intake form. Within one working day I will respond — typically with an introductory call slot and an indicative tier recommendation.

01
Complete the intake. Name, email, phone, nature of enquiry.
02
Initial conversation. 30 minutes by video or phone, no obligation.
03
Health Check, then proposal. The Health Check produces a tier recommendation; the proposal puts a fee against it.
Open the intake form →