Policy Development Privacy Notices & GDPR Documentation
Expert development of all GDPR-required documentation — data protection policies, privacy notices for customers, employees and website visitors, data retention schedules, breach procedures, processor agreements and consent mechanisms. Bespoke to your organisation, not generic templates.
Documentation We Develop
Every document you need for UK GDPR compliance.
Data Protection Policy
Your overarching data protection policy covering principles, responsibilities, processing rules, security standards, breach procedures and individual rights. Tailored to your organisation.
Privacy Notices
Transparent privacy notices for every audience — customers/clients, employees, job applicants, website visitors, pupils/parents, patients, donors. Covering all Article 13/14 requirements.
Cookie & Website Policies
Cookie consent mechanisms, cookie policies and website privacy notices compliant with UK GDPR and the Privacy and Electronic Communications Regulations (PECR).
Retention Schedules
Data retention schedules specifying how long you keep each type of personal data and the lawful basis for retention. Sector-specific schedules for schools (IRMS), healthcare and regulated industries.
Processor Agreements
Data processor agreements (Article 28) for every third party processing personal data on your behalf — payroll, cloud services, CRM, email marketing, IT support and outsourced functions.
Breach Procedures
Data breach detection, assessment, notification and recording procedures. 72-hour ICO notification templates. Individual notification templates. Post-breach review process.
Consent Mechanisms
GDPR-compliant consent collection for marketing, cookies, photography, research and any processing relying on consent as lawful basis. Granular, specific, informed and freely given.
Rights Procedures
Procedures for handling individual rights requests — access, rectification, erasure, restriction, portability, objection and automated decision-making. Timescales, exemptions and response templates.
Risk Assessments for Your Sector
Every industry has different hazards. We tailor every assessment to your specific sector and operations.
Factories & Warehousing
Machinery, forklift, racking, noiseTransport & Logistics
Depot safety, loading bays, vehiclesConstruction
CDM, excavations, heights, demolitionSchools & Education
Classrooms, labs, playgrounds, tripsCare & Healthcare
Patient handling, clinical, infectionChemical
Process safety, COSHH, DSEARHospitality
Kitchens, fire, slips, public safetySMEs & Offices
DSE, fire, general workplaceCharities
Events, lone working, volunteersHow We Carry Out a Risk Assessment
Processing Audit
We understand your actual data processing — what data, whose, why, how, where, who has access and how long you keep it. This drives every document we produce.
Documentation Plan
We identify every document you need based on your processing activities, sector requirements and organisational structure.
Drafting
We draft all documents — policies, notices, procedures, agreements and templates. Written in clear language, specific to your organisation, professionally formatted.
Review & Approval
Draft documents reviewed with you, adjusted for any operational considerations, approved by management and formatted for publication.
Annual Updates
Scheduled annual review of all documentation to reflect changes in processing, technology, regulations and organisational structure.
Policy Development FAQ
What GDPR documents do I need?
At minimum: a data protection policy, privacy notices for every audience whose data you process, a data retention schedule, breach notification procedure, SAR procedure, ROPA and processor agreements for all third parties. Additional documents depend on your specific processing activities.
Can I use template policies?
Templates are a starting point but rarely sufficient. Your documentation must reflect your actual processing activities, your specific data flows and your organisational arrangements. Generic templates that don't match your reality fail to demonstrate accountability and can be misleading.
How often should policies be reviewed?
At least annually and whenever there are significant changes to your processing activities, systems, third-party arrangements or relevant legislation. RADCaT provides annual review services for retained clients.
Do you write privacy notices for websites?
Yes. We draft website privacy notices, cookie policies and cookie consent mechanisms compliant with UK GDPR and PECR. We also assess your website's data collection practices to ensure your notices accurately reflect what you actually do.
What are processor agreements?
Contracts required under Article 28 between a data controller and any third party that processes personal data on their behalf. Must specify the subject matter, duration, nature and purpose of processing, data types, categories of individuals and the processor's obligations. Required for payroll providers, cloud services, IT support, marketing platforms and any outsourced function handling personal data.
Do schools need specific documentation?
Yes. Schools need sector-specific privacy notices for parents, pupils and staff, retention schedules aligned with the IRMS toolkit, data sharing agreements with local authorities, safeguarding data procedures and specific policies for CCTV, biometrics and photography.
How much does policy development cost?
Based on the number of documents needed and complexity. Complete documentation packages offer better value than individual documents. Contact us for a quote based on your specific requirements.
Need GDPR Documentation?
Get in touch for a free discussion about your documentation needs.