GDPR and AI governance support for growing UK businesses

Find your GDPR and AI risks, then get a clear plan to address them.

BridgeLayer helps growing UK businesses identify privacy, GDPR and workplace AI risks, prioritise what matters and turn each finding into a practical action with a responsible owner and target date.

Built for UK businesses UK GDPR, ICO, PECR and workplace AI governance.

Nine multiple choice questions. No account, card details or payment. Your result appears immediately.

Based in London. Built for UK businesses. Practical GDPR, privacy and workplace AI governance for growing teams.

Based in London. Supporting businesses across the UK. UK GDPR, ICO, PECR and workplace AI governance.

Free diagnostic

Find your highest priority GDPR and AI gaps in three minutes

Answer nine practical questions about privacy notices, subject access requests, processing records, direct marketing, breach readiness, suppliers and workplace AI use. You will receive an immediate indicative risk profile and a short list of the areas most worth addressing.

Your risk profile

See whether your current operational position appears Low, Moderate or Elevated.

Your priority areas

Identify the GDPR, privacy and AI matters most worth addressing.

Your next step

Receive links to support that matches your answers.

All nine questions are multiple choice, so you are never asked to type confidential business information.

Your answers are processed to generate your result. The scanner gives an indicative operational risk profile. It is general operational information, not legal advice, not a compliance determination and not a rating or certification of any kind. BridgeLayer Advisory is a compliance and operations consultancy and does not provide reserved legal services. Detail in our privacy notice.

BridgeLayer signature review

One complete operational review. One prioritised plan.

We review GDPR, privacy and workplace AI as one operating picture. You receive a clear assessment of the important gaps, a practical implementation sequence and a named owner and target date for every action.

What we review

Scope

  • GDPR and privacy practices
  • Privacy notices
  • Processing records
  • Subject access request readiness
  • Breach response
  • Direct marketing and PECR
  • Suppliers and processors
  • Workplace AI tools and rules

What you receive

Deliverables

  • Operational risk summary
  • Prioritised findings
  • Named action owners
  • Target completion dates
  • Thirty day implementation sequence
  • Agreed policy and process documents
  • Sixty minute founder walkthrough

Final position

Where it leaves you

  • Responsibilities assigned
  • GDPR records organised
  • SAR process ready
  • Breach response route established
  • Marketing controls documented
  • AI tools placed under clear rules
  • Management evidence prepared

Many reviews stop after identifying the problem. BridgeLayer converts each finding into a clear action with a priority, responsible owner and target date.

The final output is a working business plan, not a folder of generic policies.

Illustrative example using a fictional business
FindingPriorityOwnerTarget
AI use rules not agreedHighDirectorsWeek 1
Marketing contacts not categorisedHighMarketingWeek 2
SAR responsibility unclearMediumOperationsWeek 3

Ongoing Governance Support

Available after an initial review

Periodic review, change support and a standing point of contact as your business and the rules move. Scope and fees are agreed case by case once a review has been completed, so we are working from a real picture rather than a guess.

Founding Client Launch Offer

Secure one of ten Founding Client places

Ten eligible UK businesses can receive the complete Privacy, GDPR and AI Operations Review at the Founding Client Rate.

Founding clients are the first ten UK businesses we work with. You receive the complete review, the written action plan and the founder walkthrough at the Founding Client Rate.

The application takes approximately two minutes. No payment is required to apply. Scope and engagement terms are confirmed in writing before work begins.

Paid engagements begin from September 2026.

Read the full illustrative plan first

We are confirming current availability.

Ten places in total. Availability being confirmed.

Current availability will be confirmed with your application.

Founding Client Rate

£950

Planned standard price from September 2026: £1,900

  • GDPR and privacy practice review
  • Workplace AI use review
  • Review of important processes and documents
  • Prioritised findings
  • Named action owners
  • Target dates
  • Thirty day implementation sequence
  • Sixty minute founder walkthrough
Apply for a Founding Client place

The application takes approximately two minutes. No card, no deposit, no commitment.

Support areas

What do you need help with?

Start with the issue that brought you here. We can review it on its own or include it in the complete Operations Review.

GDPR compliance review

You suspect the business has drifted from what the UK GDPR expects, but nobody has looked properly.

  • GDPR health check across your systems and practices
  • Data-protection gap assessment
  • Privacy documentation review
  • Accountability-process review
  • Prioritised GDPR action plan
Explore GDPR support

ICO registration support

You are not sure whether your business needs to pay the ICO data protection fee, or what the registration asks for.

  • Assessment of whether registration is likely to apply to you
  • Gathering the business information the ICO asks for
  • Walking you through the registration process
  • Preparing the information needed to complete it
Ask about ICO registration

Subject access request support

Someone has asked for their data and the clock is running, or you want a process before that happens.

  • SAR process design and request logging
  • Identity-verification workflow
  • Data-location coordination across your systems
  • Response process and deadline tracking
  • Redaction and escalation workflow
Get help with a subject access request

Privacy notices

Your privacy notice was written years ago and describes a business that no longer exists.

  • Website privacy notice review and rewrite
  • Employee privacy notices
  • Customer privacy information
  • Notice-to-practice alignment
  • Checking the notice reflects your actual data use
Review privacy notice support

Data mapping and processing records

Nobody can say exactly what personal data the business holds, where it lives or why.

  • Data inventory and data-flow mapping
  • Processing-purpose records
  • Systems and vendor mapping
  • Retention responsibilities
  • Records proportionate to your processing, not a template
Ask about data mapping

Data breach readiness

If something went wrong tomorrow, nobody is quite sure who decides what, or how fast.

  • Breach reporting workflow and staff reporting route
  • Internal escalation and incident logging
  • Responsibility assignment
  • 72-hour assessment process
Prepare a breach response process

Direct marketing and PECR

Your list has grown organically and you cannot show which rules apply to which contacts.

  • Marketing-list categorisation by recipient type
  • Corporate and individual subscriber distinctions
  • Contact-source review
  • Opt-out and suppression processes
  • Email and SMS process review, and record-keeping
Review direct marketing

Workplace AI governance

Your team is already using AI tools and nobody has agreed what may be typed into them.

  • AI-tool inventory and approved-tool list
  • Data-handling rules and prohibited uses
  • One-page staff AI policy
  • Vendor assessment and human-review requirements
  • AI-risk screening process
Create workplace AI rules

Vendor and processor support

A client's procurement team has asked what your suppliers do with their data, and the answer is an assumption.

  • Vendor inventory and processor identification
  • Contract-document collection
  • Due-diligence questionnaires
  • Responsibility tracking
  • Renewal review process
Review suppliers and processors

Why BridgeLayer

Why businesses choose BridgeLayer

The service is built for growing teams that need practical controls, clear responsibilities and work that can be maintained after the review ends.

Founder led delivery

You work directly with our founders rather than an account-management layer. The people who review your business are the people who wrote the plan, and both of them run businesses themselves.

GDPR and AI in one operating model

Privacy and workplace AI are reviewed together, because the same customer, employee and supplier information now moves through both traditional systems and AI tools.

Practical implementation

We do not stop at identifying a problem. Findings become named actions, owners, priorities and target dates, so the plan tells you who does what by when.

Designed for growing SMEs

Recommendations are proportionate to the size, systems, team and risk profile of your business. Enterprise frameworks bolted onto a fifteen-person company help nobody.

Clear fixed scope

You know the scope, the deliverables and the fee before work begins. No hourly meter, no scope creep, no invoice that arrives as a surprise.

Visible deliverables

You receive a written action plan designed to be used rather than filed. You can read the whole illustrative version on this site before you speak to us.

The final operational position

What completion looks like

The review is designed to leave the business with clear responsibilities, documented processes and evidence that priority actions have been completed.

Completed: GDPR data map complete

The business has an up to date record of its important personal data activities, systems and owners.

Completed: Subject access request process ready

Requests have a clear intake route, named responsibility and deadline tracking.

Completed: Workplace AI rules approved

Approved tools, prohibited uses and human review responsibilities are documented.

Completed: Marketing records organised

Contacts are categorised and opt out and suppression processes are maintained.

Completed: Breach response route active

Staff know how to report an incident and who owns the assessment.

Completed: Privacy ownership assigned

Each important privacy responsibility has a named owner and review date.

Sample deliverable

The illustrative GDPR and AI action plan

See exactly what you receive before you speak to anyone. Below is a preview. The full version is on the site and available as a PDF.

Illustrative example. Fictional organisation.

GDPR and AI Operations Review: Action Plan

XYZ Recruitment Ltd. 14 staff. London. Prepared by BridgeLayer Advisory.

Business profile

A 14-person recruitment agency placing permanent candidates with UK employers. Holds candidate CVs, client contacts and employee records. Runs its own email marketing. Consultants use AI tools informally to speed up shortlisting and drafting.

Overall risk position

Moderate operational risk

XYZ Recruitment Ltd is a well-run agency with careful people in it. The findings below are typical of a business that has grown faster than the documents written for it. Three would become difficult quickly under scrutiny from a candidate, a client procurement team or the regulator. None require a large project to address.

Key findings

Extract: four of eleven findings shown. The full plan is in the PDF.
FindingWhy it mattersPriorityOwnerTarget date
Marketing list is not categorised by recipient type Different direct-marketing rules apply to corporate subscribers and to individual subscribers such as sole traders. Without categorisation the team cannot show which approach applies to which contacts. HighMarketing leadWeek 2
Candidate CVs pasted into consumer AI tools Personal data leaves controlled systems with no record of where it went, what the tool retains, or whether the candidate would expect it. HighDirectorsWeek 1
Privacy notice describes an earlier version of the business The notice omits tools and activities now in daily use, so it no longer describes what actually happens to candidate data. HighOperations leadWeek 3
No named owner for the 72-hour breach decision A decision with a statutory deadline needs an owner appointed before the day it is needed. MediumDirectorsWeek 2

Thirty-day action sequence

  1. Week 1: circulate the one-page workplace AI rules. Approved tools, what may be entered, what never may, and who to ask when it is not obvious.
  2. Week 2: categorise the marketing list by recipient type and source, document the position for each group, and suppress contacts that cannot lawfully be used.
  3. Week 3: build the processing record in one working session, focused on regular and higher-risk activity.
  4. Week 4: name owners for breach and subject access request decisions, then walk both routes through as a dry run.

XYZ Recruitment Ltd is a fictional organisation created solely to demonstrate the format of a BridgeLayer action plan. It is not a client and any resemblance to a real business is coincidental. Findings, owners and dates are illustrative. Real plans are built from your operations and remain operational documents. They are not legal advice and not a compliance determination.

Download the full illustrative plan Read it on this page instead

PDF. Fictional business. Sample content. 36 KB, three pages.

Process

How the review works

Four steps. We tell you what we need at each one, so nothing stalls waiting on a document nobody knew we wanted.

Initial assessment

We review your scanner result or discuss the specific concern that prompted the call, then confirm scope and fee in writing before anything else happens.

You provide: a short conversation. We provide: a written scope and fixed fee.

Evidence and working session

We review the documents, tools and working practices that matter, then sit with the people who actually do the work rather than reading about it.

You provide: existing notices, key vendor list, tool access, one working session. We provide: the questions and the structure.

Prioritised action plan

We set out what needs attention now, what can reasonably wait and who should own each action, with target dates against every item.

You provide: names for the owner column. We provide: the written plan and the agreed artefacts.

Founder walkthrough

Sixty minutes with one of our founders to explain the plan, answer operational questions and mark clearly where specialist legal advice is recommended.

You provide: the people who will do the work. We provide: the walkthrough and a clear next-step sequence.

Who you work with

Founders

BridgeLayer is a two person, founder led consultancy. You work directly with the people whose names are on it.

Tushant Rathod

Co-founder

Tushant's background is technology and business operations. He has spent his career running customer-facing businesses rather than advising from the outside, which means he has sat on the client side of compliance advice for years and knows which recommendations survive contact with a working week.

He holds the Practitioner Certificate in Data Protection through PDP Training and has completed contract-law training with HarvardX. His current focus is the practical implementation of GDPR and AI governance in small teams: which tools are in use, what data reaches them, and what rules people will realistically follow.

  • Practitioner Certificate in Data Protection, PDP Training
  • Contract law training, HarvardX
  • Technology and operations background, customer-facing businesses
Tushant on LinkedIn (opens in a new tab)

Anish Agrawal

Co-founder

Anish brings decades of business ownership across several sectors, including real estate, trading and supply. That experience is operational rather than academic: licences, registrations, inspections, documentation, supplier terms and the paperwork that regulated operating environments demand, carried personally as the owner.

At BridgeLayer he leads the commercial side and applies the scrutiny an owner applies. Every recommendation is tested against whether a working business would adopt it, resource it and still be running it six months later. If the answer is no, it goes back.

  • Business ownership across real estate, trading and supply
  • Operator-side compliance: licences, documentation, suppliers and contracts
  • Commercial lead, BridgeLayer

BridgeLayer combines formal privacy and contract training with decades of practical business-operating experience. Every recommendation is tested against two questions: does it address the real risk, and can a small team realistically maintain it?

Founding Client Launch Offer

Apply for one of ten Founding Client places

Approximately two minutes. No payment is required to apply, and applying commits you to nothing. We review the fit and confirm availability before anything is agreed.

Founding Client application

No payment is required to apply. We review the fit and confirm availability before anything is agreed.

  1. Business details
  2. Current priority
  3. Review and submit

Business details

FAQ

Questions we are asked

What does a GDPR consultant do?

A GDPR consultant reviews how a business collects, stores, uses and shares personal data, identifies where practice has drifted from what the UK GDPR expects, and helps put working processes in place. Our GDPR compliance reviews cover privacy notices, records of processing, subject access requests, direct marketing, breach readiness, vendors and workplace AI use, and produce a prioritised action plan with named owners and target dates.

Does my business need an ICO registration?

Most UK organisations that process personal data must pay the ICO data protection fee, though exemptions exist and the position depends on what your business actually does. We help you assess whether registration is likely to apply, gather the information the registration asks for and understand the process. The determination and the registration itself remain yours to make with the ICO. We are not the ICO and we cannot approve or confirm your position for it.

Can BridgeLayer help with a subject access request?

Yes, on the operational side. We help you organise and manage the process: logging the request, verifying identity, locating the information across your systems, tracking the deadline, and coordinating review and redaction. Where a request raises a complex exemption question, we identify it and recommend you take advice from an appropriately qualified solicitor. More on SAR support.

Can BridgeLayer review our privacy notice?

Yes. We review website, employee and customer privacy information against what your business actually does with personal data, which is usually where the gap sits. Notices tend to describe an earlier version of the business. We identify the differences and rewrite the notice so it matches practice. More on privacy-notice support.

What is a GDPR compliance review?

A structured look at how your business manages personal data day to day: documentation, processes, responsibilities and records. We identify practical gaps, rate them by real risk to your business, and set out what to fix first. You receive a written action plan rather than a list of regulatory extracts. You can read the full illustrative plan before you speak to us.

Can BridgeLayer help us create a workplace AI policy?

Yes. We inventory the AI tools your team actually uses, agree an approved-tool list, set rules for what information may and may not be entered, define where human review is required, and issue a one-page policy staff will follow. Rules nobody reads change nothing, so we keep it to a page. More on workplace AI governance.

What happens if our business has a data breach?

You need to know quickly who assesses it and whether it meets the threshold for reporting to the ICO within 72 hours. We help you build that route in advance: how staff report an incident, who logs it, who decides, and what evidence is kept. We support the operational response. Where a breach raises questions of legal exposure, we identify the boundary and recommend you take advice from an appropriately qualified solicitor. More on breach readiness.

Who is the Founding Client Offer for?

The first ten UK businesses we work with, typically 10 to 50 staff, holding customer or employee data, running their own marketing, or with teams already using AI tools. We speak most often with recruitment agencies, marketing agencies, professional-services firms and growing B2B technology businesses. Requesting a place costs nothing and is not binding. See the Founding Client Offer.

Is the risk scanner legal advice?

No. The scanner gives an indicative operational risk profile based on nine multiple-choice answers. It is general operational information. It is not legal advice, not a compliance determination, and not a rating, score or certification of any kind. It cannot account for your contracts, your sector rules or the specifics of your processing, which is what a proper review is for.

What information does the scanner collect?

Nine multiple-choice answers and nothing else. There are no free-text questions, so you are never invited to enter personal or confidential business information. Your answers are processed to generate your result. If you request a written copy by email, we hold that email address so that we can send it and reply to you. Our privacy notice sets out every processor involved and how long we keep things.

Is BridgeLayer UK-based?

Yes. We are based in London and work with businesses across the United Kingdom. The service is built around UK GDPR, the Data Protection Act 2018, ICO expectations and PECR, and around how UK small businesses actually operate day to day.

When do paid engagements begin?

Paid engagements begin from September 2026. Requesting a Founding Client place before then costs nothing and is not binding on either side.

Contact

Tell us what is prompting the review

Whether you want to discuss a scanner result, request a Founding Client place, or sense-check whether the service is appropriate for your business, send us a short note. One of our founders will respond, normally within one working day.

Prefer to talk? Choose a convenient time for a 15 minute intro call.

Or email us at contact@bridgelayeradvisory.com.

We use your details to respond to your enquiry. Marketing updates are sent only if you tick the box, and the two are kept separate. Privacy notice.

← Back to the site

Privacy, cookies and technology notice

Last updated 21 July 2026

This is written the way we would want to read it: short, accurate and in plain English. It describes the technology actually running on this website, not the technology we might add later. If anything is unclear, email us and a person will answer.

Who we are

This site is operated by the founders of BridgeLayer Advisory during a pre-launch period. For anything in this notice, contact contact@bridgelayeradvisory.com.

What we collect and why

Analytics, cookies and local storage

We do not use advertising trackers or visitor-identification technology at initial launch. We do not build behavioural profiles, we do not run advertising pixels, and we do not use session recording or fingerprinting.

We use privacy-conscious aggregate analytics, provided by Plausible, to understand page visits and how far people get through the scanner. It sets no cookies and does not follow you across other websites, but it does process limited technical information such as your approximate country, device type and referring page in order to produce those aggregate counts.

We also count a small number of named events: a scan being started and completed, which of the three risk bands the result fell into, which service links were followed, an enquiry or application being sent, and which stage of the application form was reached. These are counts only. Nothing you typed into a form, and no name, email address, company name or scanner answer, is ever sent to analytics.

We store two small preference values on your device, and nothing else. One is kept in local storage and remembers that you dismissed this notice, so it does not reappear on every visit. The other is kept in session storage and remembers that you closed the quick-action bar on a mobile screen; it is discarded when you close the tab. Each holds a single value, neither identifies you, and neither is read by any third party. You can clear both in your browser at any time, or use the notice settings link in our footer.

Because we currently use no cookies or similar technologies that require your consent, we show a short notice rather than a consent banner. If that ever changes, for example if we add advertising conversion tracking or any visitor-identification tool, we will complete a lawful-basis assessment, update this notice and put a proper consent mechanism in place before the technology loads, not after.

Who processes data for us

Anthropic states that it does not use commercial API inputs and outputs to train its models by default. Retention depends on the account and API configuration in use, and we will state our production configuration here before launch.

Some providers store data outside the UK. Where they do, transfers rely on recognised safeguards such as adequacy regulations or the UK international data transfer addendum.

We do not load fonts, images or scripts from third-party servers other than the analytics script named above, so visiting this page does not send your IP address to advertising or font providers.

How long we keep things

Enquiries are kept for up to twelve months after our last exchange and then deleted, unless we go on to work together, in which case engagement records are kept for as long as our professional and tax obligations require. Launch-update contacts are removed at launch unless you have consented to continue hearing from us.

Your rights

You can ask for a copy of your data, ask us to correct or delete it, object to or restrict our use of it, ask us to transfer it, and withdraw consent at any time. Email contact@bridgelayeradvisory.com and we will act promptly. If you are unhappy with how we handle your data you can complain to the Information Commissioner's Office at ico.org.uk.

Changes

If this notice changes we will update this page and the date at the top.

← Back to the site

← Back to the site

Illustrative example. Fictional organisation.

The full illustrative GDPR and AI action plan

XYZ Recruitment Ltd, a fictional 14 person agency. Version 1.0, July 2026.

Real plans are built from your operations, so no two are alike. The shape is always this: findings in plain English, why each one matters, a priority, a named owner and a target date. Nothing below describes a real business.

Download the full illustrative plan, PDF

PDF. Fictional business. Sample content. 36 KB, three pages.

GDPR and AI Operations Review: Action Plan

XYZ Recruitment Ltd, 14 staff, London. Prepared by BridgeLayer Advisory.

1. Business profile

A 14-person recruitment agency placing permanent candidates with UK employers. Holds candidate CVs, client contacts and employee records across a cloud applicant tracking system, shared drives and email. Runs its own email marketing to a list built over six years. Consultants use AI tools informally to speed up shortlisting and drafting.

2. Overall risk position

Moderate operational risk

XYZ Recruitment Ltd is a well-run agency with careful people in it. The findings below are typical of a business that has grown faster than the documents written for it. Three would become difficult quickly under scrutiny from a candidate, a client procurement team or the regulator. None require a large project to address.

3. Key findings

All findings, ordered by priority.
FindingWhy it mattersPriorityOwnerTarget date
Marketing list is not categorised by recipient typeDifferent direct-marketing rules apply to corporate subscribers and to individual subscribers such as sole traders and unincorporated partnerships. Without categorisation the team cannot demonstrate which approach applies to which contacts, or evidence it if asked.HighMarketing leadWeek 2
Candidate CVs pasted into consumer AI toolsPersonal data leaves controlled systems with no record of where it went, what the tool retains, or whether the candidate would expect it.HighDirectorsWeek 1
Privacy notice describes an earlier version of the businessThe notice omits tools and activities now in daily use, so it no longer describes what actually happens to candidate data.HighOperations leadWeek 3
No named owner for the 72-hour breach decisionA decision with a statutory deadline needs an owner appointed before the day it is needed.MediumDirectorsWeek 2
Processing record incomplete for higher-risk activityDocumentation expectations scale with the nature of the processing. Candidate screening sits at the end where records matter most.MediumOperations leadWeek 3
Subject access requests handled ad hocRequests are answered by whoever sees them first, with no log and no record that the deadline was met.MediumOperations leadWeek 4
Vendor terms not reviewed for processor obligationsClient procurement reviews routinely ask for this, and the answer is currently an assumption rather than a document.MediumOperations leadWeek 4
ICO data protection fee position not documentedThe registration position has never been assessed or recorded, so nobody can confirm it if a client asks.MediumDirectorsWeek 2
Candidate data retained without a stated periodOld records accumulate in shared drives, increasing what would be exposed by any single incident.LowOperations leadMonth 2
No AI-risk screening before adopting a new toolNew tools arrive through individual consultants rather than a decision, so nobody assesses them before candidate data reaches them.LowDirectorsMonth 2
Staff have had no data-protection refresherProcesses only work if the people running them know they exist.LowOperations leadMonth 3

4. Thirty-day action sequence

  1. Week 1: circulate the one-page workplace AI rules. Approved tools, what may be entered, what never may, and who to ask when it is not obvious.
  2. Week 2: categorise the marketing list by recipient type and source, document the position for each group, and suppress or remove contacts that cannot lawfully be used.
  3. Week 2: name the owner for breach decisions and put the escalation route on one page. Document the ICO fee position.
  4. Week 3: run a single working session to build the processing record, focused on regular and higher-risk activity rather than every conceivable field.
  5. Week 3: update the privacy notice so it describes the business as it operates today.
  6. Week 4: walk one subject access request and one breach scenario through as a dry run, and fix whatever the dry run exposes.

5. One-page workplace AI policy (preview)

  • Approved tools: the named tools on the approved list, accessed through business accounts only.
  • Never enter: candidate CVs, contact details, salary information, client commercial terms, or anything you would not send to a stranger.
  • Always: check output before it reaches a candidate or client. The tool drafts; a person is accountable.
  • When unsure: ask the named owner before pasting. Asking is never the wrong call.

6. Where specialist legal advice is recommended

Two items sit at the boundary of legal interpretation rather than operational implementation: the retention position for candidate records tied to an existing client contract, and one clause in a client's data-processing agreement. We have organised the facts for both and recommend that XYZ Recruitment Ltd obtains advice from an appropriately qualified solicitor. We are happy to prepare the brief.

XYZ Recruitment Ltd is a fictional organisation created solely to demonstrate the format of a BridgeLayer action plan. It is not a client, has never been a client, and any resemblance to a real business is coincidental. Findings, owners, dates and the legal-boundary examples above are illustrative. Real plans are built from your operations after a review and remain operational documents. They are not legal advice and not a compliance determination.

← Back to the site