GDPR Starter Kit — Templates for Small Business
Everything your small business needs to get GDPR-compliant — without hiring a solicitor.
This pack contains 5 editable Word templates and a plain-English guidance document, written specifically for Irish and EU small businesses. No legal jargon. No generic templates copied from a US website. Just practical, expert-written documents you can fill in and use today.
**What's included:**
- Privacy Policy — customer and website-facing, with tables for data types, legal bases, and retention periods
- Cookie Policy — covers strictly necessary, analytics, marketing, and functional cookies with a consent guidance section
- Record of Processing Activities (ROPA) — the register the DPC expects every business to have, with 5 worked examples (customer management, email marketing, employee records, website analytics, CCTV)
- Subject Access Request (SAR) Response Template — step-by-step process, response letters (including refusal), SAR log, and guidance on third-party and employee SARs
- Data Breach Log & Response Template — breach assessment form, DPC notification template, individual notification letter, breach log, plus guidance on processor breaches, cyber insurance, and reporting to An Garda Síochána
- Guidance Notes — plain-English guide explaining every template: what it is, how to fill it in, common mistakes to avoid, and Irish-specific retention periods
**Also includes:**
- Privacy Policy annexes for children's data, special category data, and direct marketing (ePrivacy)
- Joint controller and processor ROPA guidance
- Irish legislation references throughout (Data Protection Act 2018, ePrivacy Regulations S.I. No. 336 of 2011)
- DPC contact details and complaint process
**Who is this for?**
Small businesses (1–50 employees) in Ireland and the EU — shops, cafés, salons, clinics, trades, startups, professional services. If you process customer data, have a website, or keep a mailing list, this pack is for you.
**Format:** Editable Word (.docx) files. Fill in the [bracketed sections], delete what doesn't apply, and you're done.
**Important:** These templates are practical guidance, not legal advice. They are designed as a basic draft to cover the needs of most small businesses. If you handle high-risk data (e.g. health data, children's data), we recommend also consulting a data protection professional.