Data protection for small businesses
Know exactly what your business does with people's data.
Answer plain-English questions about how your business actually works. The Register turns your answers into a clear, honest account of what you do with people's information, flags what's vague, inconsistent, or genuinely needs attention, and keeps that account current as your business changes. No specialist needed.
No credit card needed. See where you stand in minutes.
Know it, and be able to show it, for less than £30 a month.
UK/EU hosted · encrypted · strict tenant isolation
The Data (Use and Access) Act 2025 is now in force. See what changed for small businesses, what you can ignore, and whether you still need a ROPA.
It's easy to lose track of what you actually do with people's data
Records drift out of date
A ROPA written once and filed away stops matching reality the moment a process, vendor, or system changes, and you stop having a true answer to what you actually do with people's information.
The same facts, re-entered everywhere
A single processing activity feeds your ROPA, your DPIAs, your transfer assessments. Maintained separately, they drift apart and contradict each other, so no single document tells the truth.
Gaps hide until they matter
A new tool gets adopted, an assumption goes unchecked, a vendor changes hands, and normally nobody notices until the moment someone's data is the thing that actually gets mishandled.
What doing this properly actually involves
Read the plain-English primers →- Written down, not just understood in your head
- If what you do with people's data only lives in your head, you don't have an answer you can check or share, and neither does anyone else at the business. It's also a legal requirement for most organisations: Article 30 requires it in writing, and the small-business exemption falls away once processing is regular.
- Able to show it, not just do it
- Handling data carefully is only half of it. Being able to show exactly how, to a customer, a new hire, or yourself in a year's time, is what makes it real rather than assumed, and it's what Article 5(2) actually asks for: not just complying, but being able to demonstrate it.
- Some decisions deserve real thought
- Where what you're doing could genuinely affect someone, that's worth a proper look before you proceed, not an assumption that it's probably fine. The law treats it the same way: Article 35 makes a DPIA mandatory before high-risk processing, not optional best practice.
- A record that no longer matches reality isn't protecting anyone
- Documentation describing a business you no longer run isn't a safeguard for the people whose data it's supposed to cover, it's just paperwork, and a stale ROPA is itself a compliance gap: it shows the organisation doesn't currently know what it does with personal data.
How it works
Three stages, and you only ever do the first.
Answer guided questions
Describe each processing activity once, guided through the standard Article 30 information: purpose, lawful basis, data subjects, recipients, transfers, retention, and security.
Your ROPA assembles itself
The Record of Processing Activities is built directly from your answers and updates automatically as your business changes. There is no document to regenerate: change an activity and the register reflects it.
Generate the assessments
Where the law requires judgement (DPIAs, legitimate interests and transfer risk assessments), Claude drafts the assessment from your records, and it is flagged for review whenever the underlying facts change.
One shared foundation feeds every record, which is what keeps them consistent:
- ROPA Record of Processing Activities
- DPIA Data Protection Impact Assessment
- TRA Transfer Risk Assessment
- LIA Legitimate Interests Assessment
Not sure where you stand?
Eight plain-English questions, about two minutes. See your readiness score, what's already solid, and what genuinely needs attention, free.
Built for businesses like yours
If you employ people or hold customer data, you have records to keep.
Agencies & consultancies
Client lists, candidate CVs and contractor details spread across email, CRMs and shared drives.
Ecommerce & retail
Customer orders, delivery addresses and marketing lists, with the consent rules that come with them.
Clinics & private practices
Patient and client health data, which is special category data and often needs a DPIA.
Accountants & professional services
Client financial records you are trusted to hold, and clients who increasingly ask how you protect them.
Charities & non-profits
Donor, member and beneficiary data, sometimes sensitive, usually managed on a shoestring.
SaaS & startups
User data from day one, and enterprise customers whose security questionnaires you need to pass.
Secure by default
Read our security approach →Your records can themselves contain personal data, so the security you would need a specialist to set up elsewhere is simply how the Register works.
- UK/EU data residency
- Encrypted in transit & at rest
- Strict tenant isolation
- Append-only audit log
- Minimal data to AI
- MFA-capable sign-in
Frequently asked questions
Do I need any data protection knowledge to use this?
No. You answer questions about how your business actually works: who you employ, what tools you use, who you share data with. The Register turns those answers into formal records, and its built-in review explains in plain English anything that needs attention and why it matters.
We're a small business. Isn't this overkill?
It's built for exactly this. Most compliance tools are designed for enterprises with a privacy team to catch what gets missed; smaller businesses usually have neither the team nor the spare time, which is exactly when things slip through. This gives you a way to check your own working without needing to become an expert first. And practically, the legal duty to keep these records reaches smaller organisations than most people expect: if you run payroll, you're almost certainly already in scope. The resources section covers the legal detail.
Where is my data stored?
In the EU. The product is built to treat your records, which can contain personal data, with a security baseline from day one (encryption, tenant isolation, audit logging).
How is AI used, and is my data used to train models?
Your ROPA involves no AI at all: it is assembled directly from your answers. AI drafts the judgement documents (DPIAs, LIAs, compliance reviews), server-side, sending only the minimum necessary data and logging every call. Business data sent to the Anthropic API is not used to train models.
Does this replace legal advice?
No. The Register helps you produce and maintain your records efficiently; it is not a substitute for professional data-protection or legal advice.
Know what you do with people's data
Create a free account, describe how your business actually works, and see exactly where things are unclear or need attention. No credit card needed.
Not ready yet? Take the 2-minute readiness check or download the free GDPR checklist.