GDPR readiness
Be ready when a customer asks
how you handle their data.
Tenders, insurers and bigger customers increasingly want proof of how you handle their data, not just a promise. This pack holds the records and documents that answer that properly — and a dashboard that shows you, honestly, where your gaps still are.
01 / The principle
Being small doesn't exempt you from GDPR. Article 5(2) expects you to demonstrate compliance, not just claim it.
It's the internal evidence you produce when someone asks: collated in one place, with the gaps listed so you know what to close first.
02 / What's inside
Everything a small business needs to evidence GDPR — and nothing it doesn't.
- Article 30 ROPA
- A live record of every processing activity — lawful basis, data, retention, risk and status — the backbone of accountability.
- Processor register
- Who processes data on your behalf, the DPA or safeguard in place, and the international-transfer position for each.
- Retention schedule
- How long each category of data is kept and how it's disposed of — so nothing is held “just in case.”
- Privacy notices
- Article 13/14 notices for customers, staff and suppliers, ready to publish and issue.
- LIA & DPIA screening
- Legitimate-interests balancing tests and DPIA screening decisions, documented rather than assumed.
- Breach & rights procedures
- A 72-hour breach procedure and a subject-rights procedure, so you're not improvising under pressure.
- Data protection policy
- A plain-English internal policy your staff can actually follow, plus a folder-access standard.
- Article 32 evidence
- A technical verification report showing the security controls protecting the data are real and tested.
03 / See it working
A complete pack, live. Click around it.
A fully working pack for The Copper Still, a fictional Dublin gastropub. Every record and document is real and clickable — only the business is invented. This is exactly what yours would look like, filled in with your processing instead.
Open the live demo- Processing activities
- 06
- Controlled documents
- 17
- Governance actions tracked
- 13
04 / Why ProVibed
Built by someone who does this for a living.
ProVibed is run by an IT security and audit professional — CISSP, CDPO, CISM, CISA. This pack is that discipline, packaged so a small business can hold it, understand it, and stand over it.
More about who's behind ProVibed05 / Start here
Someone asking how you handle their data?
Tell us what your business does and what you've been asked for, and we'll show you what your pack would look like and where your gaps are. This stands on its own — you don't need anything else from us first.
Get in touch