Compliance without a department.
WHAT MATTERS MOST WITH LIMITED CAPACITY
Knowing what you hold Collecting less Securing what remains Being able to respond to requests Being able to handle a breach
WHAT TO DO FIRST
The inventory.
WHY
Every other obligation depends on it, and it takes a day.
WHAT TO DO SECOND
Delete what has no purpose.
WHY
It is the fastest risk reduction available.
WHAT TO DO THIRD
Write an accurate privacy notice.
WHAT TO DO FOURTH
Establish who is responsible.
WHY THAT MATTERS IN A SMALL ORGANISATION
Without a name, it is nobody.
WHAT TO PREPARE
A simple process for rights requests A simple breach plan with contacts
WHAT TO AVOID
Copying a large organisation's documentation Policies describing practices you do not follow
WHY THAT SECOND POINT
It is evidence against you.
WHAT TO DOCUMENT
What you actually do.
WHAT TO REVIEW ANNUALLY
The inventory The notice Access to systems Retention
WHAT TO SPEND MONEY ON
Advice, once, on whether you are in scope and what applies.
WHY
It is cheaper than getting the scope wrong.
WHAT TO BUILD HABITUALLY
Asking whether you need a field before adding it.