Skip to content

Stratgik — technology strategy and business systems engineering.
Delivery across the USA, UK, UAE and India.

Talk about a problem

UK GDPRData (Use and Access) Act in force from 5 February 2026

UK GDPR compliance, implemented in your systems. Fixed fees from £1,450.

The Data (Use and Access) Act 2025 changed how UK organisations handle legitimate interests, cookies, subject access requests, automated decisions and complaints. We map your data, update notices and processes, and build the changes into your website, CRM and products, for a fixed fee.

  • Fixed fees in £
  • Implemented in your systems, not just a policy
  • Engineers, working alongside your lawyers

What is at stake

Enforcement under UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025

The Information Commissioner’s Office sets the amount based on seriousness, duration, harm and what you did to put it right. These are statutory maximums.

  1. £17.5m / 4%

    Breaches of the core principles, lawful basis, individuals’ rights or international transfer rules

  2. £8.7m / 2%

    Failures in obligations such as records, security measures or breach notification

  3. £17.5m / 4%

    Electronic marketing and cookie breaches under PECR, now aligned with UK GDPR maximums

What the law asks, in plain words

Eight things to get right in United Kingdom

  • Transparent privacy notice

    Tell people what you collect, why, the lawful basis, who receives it and how long you keep it, in clear language.

  • Lawful basis, including recognised legitimate interests

    The 2025 Act lists recognised legitimate interests such as security and fraud prevention that no longer need a balancing test. Everything else still needs a documented basis.

  • Cookies and PECR

    Some analytics and functionality cookies can now rely on an opt-out. Advertising and tracking cookies still need prior consent.

  • Subject access requests

    Respond within one month. Searches must be reasonable and proportionate, and the clock can pause while you wait for information you genuinely need.

  • Breach reporting

    Report notifiable personal data breaches to the ICO within 72 hours of becoming aware, and tell affected people when the risk is high.

  • Complaints procedure

    Give people a way to complain about how their data is handled, acknowledge complaints within 30 days and respond without undue delay.

  • Automated decisions and AI

    Significant automated decisions need safeguards: information about the decision, a way to contest it and access to human review.

  • Processors and transfers

    Contracts with every processor, and an International Data Transfer Agreement or Addendum where data leaves the UK.

Free self-check

How ready is your organisation?

Ten questions, two minutes. Nothing is sent anywhere unless you ask for help.

0/ 100

Answer the questions to see your score

0 of 10 answered

  1. 1Do you have an up-to-date record of what personal data you hold, where, and why?
  2. 2Does your privacy notice reflect the Data (Use and Access) Act changes?
  3. 3Is every processing purpose tied to a documented lawful basis?
  4. 4Does your cookie banner separate consent-based cookies from the new opt-out categories?
  5. 5Can you locate and export one person’s data within a month?
  6. 6Do you have a written complaints procedure with a 30-day acknowledgement?
  7. 7Would you know within 72 hours whether a breach must be reported to the ICO?
  8. 8Are high-risk projects, including AI, covered by a DPIA?
  9. 9Do all processors have UK GDPR-compliant contracts?
  10. 10Are transfers outside the UK covered by an IDTA, Addendum or adequacy decision?

How we get you compliant

Four steps, done with your team

  1. 1

    Discover

    Find every copy of personal data

    Website, apps, CRM, ERP, spreadsheets, messaging tools and vendors.

  2. 2

    Decide

    Rank the gaps by risk

    Each gap scored against enforcement exposure and effort, so the serious ones get fixed first.

  3. 3

    Implement

    Fix it in your systems

    Notices, consent, request workflows, access controls, retention and vendor terms.

  4. 4

    Hand over

    Train people, rehearse a breach

    A live session for the staff who handle data and a practice run of breach reporting.

Pricing

Fixed fees. No surprises.

For organisations with one website or product and up to five systems holding personal data. Larger scope is quoted in writing before you pay anything.

Readiness Audit

Know where you stand against UK GDPR and the 2025 Act.

£1,450one-time
+ VAT

Report in 7 working days

Choose Readiness Audit
  • Discovery session with an engineer
  • Data map across website, CRM, product and key vendors (up to 5 systems)
  • Gap report against UK GDPR, DPA 2018 and the 2025 Act
  • Gaps ranked by enforcement risk
  • 90-day action plan

Recommended

Compliance Setup

We implement the changes in your systems.

£4,900one-time
+ VAT

Typically 3 to 5 weeks

Choose Compliance Setup
  • Everything in Readiness Audit
  • Updated privacy notice and records of processing
  • Cookie banner aligned with PECR changes
  • DSAR intake, search and response workflow
  • Complaints procedure and tracking
  • Breach response playbook with 72-hour ICO template
  • Processor contract and transfer checklist
  • Live staff training session

Data Protection Care

Stay compliant as systems, vendors and guidance change.

£690per month
+ VAT

Cancel any month

Choose Data Protection Care
  • DSAR and complaint handling support
  • Quarterly review of new systems and vendors
  • Breach support during UK business hours
  • Updates when ICO guidance changes
  • Annual refresher training

Free readiness call

Talk to an engineer, not a salesperson

An engineer replies within one working day with a suggested approach and a fixed quote.

  1. 1
    You send the formTwo minutes. Tell us the problem, not the solution.
  2. 2
    We talk it throughA short call at a time that suits your working hours.
  3. 3
    You get a fixed quoteIn writing, in £. Nothing is billed until you approve it.

Book your free readiness call

Interested in

See our privacy policy.

Questions

UK GDPR questions we get asked

Also see how Stratgik works with United Kingdom businesses.

Does UK GDPR apply to businesses outside the UK?

Yes, if you offer goods or services to people in the UK or monitor their behaviour. Organisations without a UK establishment may also need a UK representative.

What did the Data (Use and Access) Act 2025 change?

Among other things: recognised legitimate interests, relaxed consent for some low-risk cookies, clearer rules for subject access searches, reformed automated decision-making rules, a duty to handle data protection complaints, and PECR fines raised to UK GDPR levels.

We are already GDPR compliant for the EU. Is that enough?

Mostly, but UK and EU rules are now diverging. UK-specific changes to cookies, legitimate interests, complaints handling and international transfers need their own review.

Do we need a Data Protection Officer?

Only public authorities and organisations whose core activities involve large-scale monitoring or special category data must appoint one. Everyone else still needs someone accountable for data protection.

Is this legal advice?

No. Stratgik is a technology firm. We implement notices, workflows, consent, logging and security in your systems, and work alongside your solicitor where a legal opinion is needed.

Are prices fixed?

Yes, for organisations with one website or product and up to five systems holding personal data. Larger scope is quoted in writing before any work starts. VAT is added where applicable.

Find the gaps before a regulator does.

A readiness audit takes 7 working days and gives you a ranked, costed plan.

The Stratgik model

Strategy first. Technology that follows through.

Four stages, in order. Most businesses need them one at a time.