GDPR IMPLEMENTATION TOOLKIT · FOR UK & EU SMEs

GDPR done without the overwhelm

Clear guidance, a choose-your-path plan, and the templates you need to evidence what you’re doing — so data protection stops being a never-ending project and becomes something you actually finish.

Instant download Word, Excel & PowerPoint Edit in your own name

images of the gdpr toolkit documents

GDPR usually fails for two reasons: people don’t know where to start, and they overcomplicate it. I built this toolkit to fix both.

It’s the practical kit I wish I’d had when I started out — guidance in plain English, a plan you can actually follow, and templates you can put your name on today. No jargon, no never-ending project, no big-consultancy invoice.

– Alan Parker, founder of Iseo Blue

WHAT YOU GET

Three things that work together

Understand it, plan it, then prove it — the toolkit gives you all three in one download.

Understand

A plain-English fundamentals guide

What GDPR actually requires (and what it doesn’t), explained for a non-specialist. Read it once, and you’ll know what applies to your business.

plan

A choose-your-path implementation guide

A route map you tailor to your business. Pick an area — staff data, customers, suppliers, marketing — and follow the steps that matter to you.

evidence

Ready-to-use templates

Privacy notices, a ROPA, DPIA & LIA, DSAR handling, retention, breach response and supplier checks — everything you need to show you’re in control.

HOW IT WORKS

A clear route from “where do I start?” to “done”

The toolkit scales up or down with the size and risk of the personal data you handle. Move as fast or as carefully as you need to.

Step 1

Get your bearings

Read the Fundamentals Guide and the Implementation Guide so you know the lay of the land.

Step 2

Decide your path

Work out what’s relevant to your business and what you can safely leave out.

Step 3

Pick an area

Choose one aspect — say, employee data — and follow the guide for that area.

Step 4

Implement & evidence

Drop in the templates, fill the gaps, and you’ve got proof you can show.

The 1-day plan

In a hurry or low-risk? Follow the fast track and get the essentials in place in a single focused day.

The full roadmap

Higher risk or more data? Follow the detailed roadmap at your own pace, area by area.

Inside the toolkit

33 templates, grouped by what you need first

Start with the Core pack for minimal viable compliance, then add the Conditional and Boost packs as they apply to you. Everything is supplied in Microsoft Word, Excel or PowerPoint — click any pack to see what’s included.

GDPR Fundamentals Guide (Introduction)

A plain-English overview of GDPR, designed to help you understand what the law expects and what “good” looks like in real organisations. It covers the core principles, lawful bases, data subject rights, controller/processor responsibilities, and the practical nuts and bolts, such as cookie compliance, retention, DSARs, and breach handling.

The GDPR Fundamentals Guide also flags higher-risk areas (such as DPIAs, children’s data, and complex international transfers) so you know when to pause, escalate, or treat them as later-phase work items.

GDPR Fundamentals Guide Book Summary

Contents of the GDPR implementation guidebook

GDPR Implementation Guide (SME Route Map)

A practical, step-by-step guide designed to get you to a defensible GDPR baseline quickly, using a “Minimal Viable Compliance” approach.

The GDPR Implementation Guide provides a clear roadmap (so you only do what’s relevant), a Day 1 plan for core essentials, and optional modules for areas such as marketing/cookies, higher-risk processing (DPIAs), and international transfers. It also walks you through an 8-stage delivery process, with clear outputs at each step and direct pointers to the templates in the toolkit.


Templates and Working Documents

The toolkit templates are organised into three packs, so you only create paperwork that’s relevant to you.

Core (MVC Pack): the “minimum viable compliance” set that gets you to a solid, defensible baseline. It covers governance and scope, a gap and action plan, data flow mapping, your Article 30 ROPA, a modular privacy notice, a full DSAR procedure plus request log, training logs and a ready-to-deliver staff training deck, a security baseline checklist, supplier/processor register and DPA template, and an incident/breach plan with supporting flowcharts and logs.

Conditional (Triggered Pack): only used if you need it. Includes a consent tracker, DPIA template and register, international transfer inventory plus transfer mechanism checklist and TIA template, and practical checklists for PECR/direct marketing and cookies/tracking.

Boost (Enhancement Pack): for stronger maturity and clearer evidence over time. Includes a lawful basis register, legitimate interests assessment template, SME-friendly information security policy, regulatory updates log, and a data retention schedule template.

Contents of the GDPR Toolkit
Guides

Plain-English guidance and your route map

Guide: GDPR Fundamentals

An introduction & overview of GDPR concepts, roles, principles, and what “good” looks like for SMEs.

Guide: GDPR Implementation Guide

Step-by-step route map to implement your toolkit — minimal viable compliance first, then optional add-ons. Your primary guide to implementing GDPR.

Core – Minimal Compliance Pack

Your minimal viable compliance. Start here.

GDPR Governance & Scope Record

Capture governance basics: scope, accountability, ownership, key decisions, and how GDPR is managed.

GDPR Gap & Action Plan Workbook

Record current gaps and track actions, owners, priorities, and progress to completion.

Data Flow Map Example

Worked example to show what a completed data flow map can look like.

Data Flow Map

Map how personal data moves through your organisation (systems, sources, recipients, transfers).

GDPR ROPA Master (Processing Register)

Maintain the Article 30 Record of Processing Activities (ROPA) in a structured register.

GDPR Privacy Notice (Modular Terms)

Create or update an external privacy notice using modular clauses for common processing scenarios.

Data Subject Rights Procedure

Define how you handle data subject rights requests (DSARs) end-to-end, consistently and on time.

Data Subject Rights Procedure Flow

Visual flow to help staff follow the DSAR process and decision points.

Data Subject Request Log

Log DSARs (dates, identity checks, scope, deadlines, outcomes, exemptions, responses).

Training & Awareness Log

Track GDPR training, briefings, and awareness activities (who / when / what).

Security Baseline Checklist & Action Log

Baseline security checklist and action tracker for minimum appropriate safeguards for personal data.

Supplier & Processor Register

Register suppliers / processors, due-diligence checks, contract status, and risk notes.

Data Processing Agreement (DPA) Template

Template clauses for controller–processor arrangements (and common GDPR contract requirements).

Incident & Breach Response Plan

Define roles, steps, timelines, and reporting approach for personal data incidents / breaches.

Incident & Breach Response Plan Procedure Flow

Visual flow showing the incident triage and breach decision / reporting pathway.

Incident & Breach Log

Log incidents, assessments, decisions, containment, notifications, and lessons learned.

Documentation & Change Index

Index all toolkit docs used by the organisation and track versions / changes over time.

Basic Staff Training Guide

Ready-to-deliver GDPR staff awareness training deck (core do’s / don’ts and practical guidance).

Conditional Pack

Use upon triggers – add these only when they apply

Consent Record Tracker

Track where consent is used, evidence captured, withdrawal handling, and refresh requirements.

DPIA Template

Run a Data Protection Impact Assessment when processing is likely to be high risk.

DPIA Register

Log DPIAs, outcomes, actions, and review dates in a central register.

International Transfer Inventory

Identify and record international transfers (data flows, recipients, and context).

Transfer Mechanism Checklist

Check / record which transfer mechanism applies (SCCs, adequacy, derogations, etc.).

Transfer Impact Assessment (TIA) Template

Assess transfer risks and safeguards when using SCCs / other mechanisms, as needed.

PECR & Direct Marketing Checklist

Assess and record compliance for email / SMS marketing, privacy rules, opt-in / opt-out, etc.

Cookie & Tracking Checklist

Document cookie / tracking use, consent needs, categories, and required notices / settings.

Boost Pack

Enhancements & maturity – go further once the basics are in

Lawful Basis Register

Record lawful bases per processing activity (and link to notices / ROPA where relevant).

Legitimate Interests Assessment (LIA) Template

Document the legitimate interests test (purpose, necessity, balancing) where you rely on it.

Information Security Policy

A stand-alone information security policy aligned to protecting personal data (SME-friendly).

Regulatory Updates Log

Track regulatory changes, ICO guidance updates, and what you changed internally as a result.

Data Retention Schedule Template

Define retention periods, justification, and disposal methods by record / data type.

WHO IT’S FOR

Built for the person GDPR landed on

Used by SMEs who need to implement GDPR rapidly and correctly — without turning it into a project that never ends.

You’re an SME that handles personal data and wants a practical way to get GDPR under control.

You work with suppliers, SaaS tools, staff data, customer data or marketing lists.

GDPR has landed on your desk (IT, ops, HR, marketing or founder) alongside the day job.

You need templates and evidence you can actually use — not theory.

You want clarity on what to do, and in what order, without the fluff.

You don’t need to be a lawyer or a DPO. The language is plain, and the steps are clear.

Hi, I’m Alan Parker

I’m an ISO 27001 and data protection consultant and the founder of Iseo Blue. Over 30+ years in IT governance, I’ve helped small businesses across the UK and beyond get their information security and GDPR in order — usually without a dedicated team or a big budget.

I wrote this toolkit so you don’t have to start from a blank page. If anything isn’t clear or doesn’t fit your situation, email me directly — I’ll help.

B.Sc (Hons) Information Systems

CISMP

ITIL v4

PRINCE2 Practioner

GET THE TOOLKIT

Stop kicking GDPR down the road

Instead of starting in a blank document or stitching together templates from the internet, give yourself a straightforward, proven way to get GDPR under control — and keep it there.

You’re buying a licence to use these documents within your own organisation.

Customise them freely — you just can’t resell them as your own toolkit.

Using them with clients? You’ll need a consultant licence — get in touch.

GDPR TOOLKIT

Everything, in one download

£125

one-off payment

one-off payment

GDPR Fundamentals Guide (plain-English)

Step-by-step implementation guide + choose-your-path plan

Editable documents in Word, Excel & PowerPoint

Structured for minimal viable compliance first, then optional add-ons

Instant download — no waiting

Free updates to the toolkit

Write a Review