GDPR IMPLEMENTATION TOOLKIT · FOR UK & EU SMEs
GDPR done without the overwhelm
Clear guidance, a choose-your-path plan, and the templates you need to evidence what you’re doing — so data protection stops being a never-ending project and becomes something you actually finish.
✔Instant download ✔Word, Excel & PowerPoint ✔Edit in your own name
GDPR usually fails for two reasons: people don’t know where to start, and they overcomplicate it. I built this toolkit to fix both.
It’s the practical kit I wish I’d had when I started out — guidance in plain English, a plan you can actually follow, and templates you can put your name on today. No jargon, no never-ending project, no big-consultancy invoice.
– Alan Parker, founder of Iseo Blue
WHAT YOU GET
Three things that work together
Understand it, plan it, then prove it — the toolkit gives you all three in one download.
Understand
A plain-English fundamentals guide
What GDPR actually requires (and what it doesn’t), explained for a non-specialist. Read it once, and you’ll know what applies to your business.
plan
A choose-your-path implementation guide
A route map you tailor to your business. Pick an area — staff data, customers, suppliers, marketing — and follow the steps that matter to you.
evidence
Ready-to-use templates
Privacy notices, a ROPA, DPIA & LIA, DSAR handling, retention, breach response and supplier checks — everything you need to show you’re in control.
HOW IT WORKS
A clear route from “where do I start?” to “done”
The toolkit scales up or down with the size and risk of the personal data you handle. Move as fast or as carefully as you need to.
Step 1
Get your bearings
Read the Fundamentals Guide and the Implementation Guide so you know the lay of the land.
Step 2
Decide your path
Work out what’s relevant to your business and what you can safely leave out.
Step 3
Pick an area
Choose one aspect — say, employee data — and follow the guide for that area.
Step 4
Implement & evidence
Drop in the templates, fill the gaps, and you’ve got proof you can show.
The 1-day plan
In a hurry or low-risk? Follow the fast track and get the essentials in place in a single focused day.
The full roadmap
Higher risk or more data? Follow the detailed roadmap at your own pace, area by area.
Inside the toolkit
33 templates, grouped by what you need first
Start with the Core pack for minimal viable compliance, then add the Conditional and Boost packs as they apply to you. Everything is supplied in Microsoft Word, Excel or PowerPoint — click any pack to see what’s included.
GDPR Fundamentals Guide (Introduction)
A plain-English overview of GDPR, designed to help you understand what the law expects and what “good” looks like in real organisations. It covers the core principles, lawful bases, data subject rights, controller/processor responsibilities, and the practical nuts and bolts, such as cookie compliance, retention, DSARs, and breach handling.
The GDPR Fundamentals Guide also flags higher-risk areas (such as DPIAs, children’s data, and complex international transfers) so you know when to pause, escalate, or treat them as later-phase work items.


GDPR Implementation Guide (SME Route Map)
A practical, step-by-step guide designed to get you to a defensible GDPR baseline quickly, using a “Minimal Viable Compliance” approach.
The GDPR Implementation Guide provides a clear roadmap (so you only do what’s relevant), a Day 1 plan for core essentials, and optional modules for areas such as marketing/cookies, higher-risk processing (DPIAs), and international transfers. It also walks you through an 8-stage delivery process, with clear outputs at each step and direct pointers to the templates in the toolkit.
Templates and Working Documents
The toolkit templates are organised into three packs, so you only create paperwork that’s relevant to you.
Core (MVC Pack): the “minimum viable compliance” set that gets you to a solid, defensible baseline. It covers governance and scope, a gap and action plan, data flow mapping, your Article 30 ROPA, a modular privacy notice, a full DSAR procedure plus request log, training logs and a ready-to-deliver staff training deck, a security baseline checklist, supplier/processor register and DPA template, and an incident/breach plan with supporting flowcharts and logs.
Conditional (Triggered Pack): only used if you need it. Includes a consent tracker, DPIA template and register, international transfer inventory plus transfer mechanism checklist and TIA template, and practical checklists for PECR/direct marketing and cookies/tracking.
Boost (Enhancement Pack): for stronger maturity and clearer evidence over time. Includes a lawful basis register, legitimate interests assessment template, SME-friendly information security policy, regulatory updates log, and a data retention schedule template.

Plain-English guidance and your route map
Guide: GDPR Fundamentals
An introduction & overview of GDPR concepts, roles, principles, and what “good” looks like for SMEs.
Guide: GDPR Implementation Guide
Step-by-step route map to implement your toolkit — minimal viable compliance first, then optional add-ons. Your primary guide to implementing GDPR.
Your minimal viable compliance. Start here.
GDPR Governance & Scope Record
Capture governance basics: scope, accountability, ownership, key decisions, and how GDPR is managed.
GDPR Gap & Action Plan Workbook
Record current gaps and track actions, owners, priorities, and progress to completion.
Data Flow Map Example
Worked example to show what a completed data flow map can look like.
Data Flow Map
Map how personal data moves through your organisation (systems, sources, recipients, transfers).
GDPR ROPA Master (Processing Register)
Maintain the Article 30 Record of Processing Activities (ROPA) in a structured register.
GDPR Privacy Notice (Modular Terms)
Create or update an external privacy notice using modular clauses for common processing scenarios.
Data Subject Rights Procedure
Define how you handle data subject rights requests (DSARs) end-to-end, consistently and on time.
Data Subject Rights Procedure Flow
Visual flow to help staff follow the DSAR process and decision points.
Data Subject Request Log
Log DSARs (dates, identity checks, scope, deadlines, outcomes, exemptions, responses).
Training & Awareness Log
Track GDPR training, briefings, and awareness activities (who / when / what).
Security Baseline Checklist & Action Log
Baseline security checklist and action tracker for minimum appropriate safeguards for personal data.
Supplier & Processor Register
Register suppliers / processors, due-diligence checks, contract status, and risk notes.
Data Processing Agreement (DPA) Template
Template clauses for controller–processor arrangements (and common GDPR contract requirements).
Incident & Breach Response Plan
Define roles, steps, timelines, and reporting approach for personal data incidents / breaches.
Incident & Breach Response Plan Procedure Flow
Visual flow showing the incident triage and breach decision / reporting pathway.
Incident & Breach Log
Log incidents, assessments, decisions, containment, notifications, and lessons learned.
Documentation & Change Index
Index all toolkit docs used by the organisation and track versions / changes over time.
Basic Staff Training Guide
Ready-to-deliver GDPR staff awareness training deck (core do’s / don’ts and practical guidance).
Use upon triggers – add these only when they apply
Consent Record Tracker
Track where consent is used, evidence captured, withdrawal handling, and refresh requirements.
DPIA Template
Run a Data Protection Impact Assessment when processing is likely to be high risk.
DPIA Register
Log DPIAs, outcomes, actions, and review dates in a central register.
International Transfer Inventory
Identify and record international transfers (data flows, recipients, and context).
Transfer Mechanism Checklist
Check / record which transfer mechanism applies (SCCs, adequacy, derogations, etc.).
Transfer Impact Assessment (TIA) Template
Assess transfer risks and safeguards when using SCCs / other mechanisms, as needed.
PECR & Direct Marketing Checklist
Assess and record compliance for email / SMS marketing, privacy rules, opt-in / opt-out, etc.
Cookie & Tracking Checklist
Document cookie / tracking use, consent needs, categories, and required notices / settings.
Enhancements & maturity – go further once the basics are in
Lawful Basis Register
Record lawful bases per processing activity (and link to notices / ROPA where relevant).
Legitimate Interests Assessment (LIA) Template
Document the legitimate interests test (purpose, necessity, balancing) where you rely on it.
Information Security Policy
A stand-alone information security policy aligned to protecting personal data (SME-friendly).
Regulatory Updates Log
Track regulatory changes, ICO guidance updates, and what you changed internally as a result.
Data Retention Schedule Template
Define retention periods, justification, and disposal methods by record / data type.
WHO IT’S FOR
Built for the person GDPR landed on
Used by SMEs who need to implement GDPR rapidly and correctly — without turning it into a project that never ends.
You’re an SME that handles personal data and wants a practical way to get GDPR under control.
You work with suppliers, SaaS tools, staff data, customer data or marketing lists.
GDPR has landed on your desk (IT, ops, HR, marketing or founder) alongside the day job.
You need templates and evidence you can actually use — not theory.
You want clarity on what to do, and in what order, without the fluff.
You don’t need to be a lawyer or a DPO. The language is plain, and the steps are clear.
Hi, I’m Alan Parker
I’m an ISO 27001 and data protection consultant and the founder of Iseo Blue. Over 30+ years in IT governance, I’ve helped small businesses across the UK and beyond get their information security and GDPR in order — usually without a dedicated team or a big budget.
I wrote this toolkit so you don’t have to start from a blank page. If anything isn’t clear or doesn’t fit your situation, email me directly — I’ll help.
B.Sc (Hons) Information Systems
CISMP
ITIL v4
PRINCE2 Practioner
GET THE TOOLKIT
Stop kicking GDPR down the road
Instead of starting in a blank document or stitching together templates from the internet, give yourself a straightforward, proven way to get GDPR under control — and keep it there.
You’re buying a licence to use these documents within your own organisation.
Customise them freely — you just can’t resell them as your own toolkit.
Using them with clients? You’ll need a consultant licence — get in touch.
GDPR TOOLKIT
Everything, in one download
£125
one-off payment
one-off payment
GDPR Fundamentals Guide (plain-English)
Step-by-step implementation guide + choose-your-path plan
Editable documents in Word, Excel & PowerPoint
Structured for minimal viable compliance first, then optional add-ons
Instant download — no waiting
Free updates to the toolkit