Xelvio

GDPR audit and remediation

Audit

A fixed-fee, fixed-scope review. We map the personal data you process — where it is held, why, on what lawful basis, for how long, with whom it is shared, and how it is protected — and test your privacy notices, consent mechanisms, subject rights processes, breach procedures, supplier contracts and international transfers against UK GDPR. You receive a gap analysis rated by risk.

Remediation

A prioritised plan, with documents drafted for your organisation rather than supplied as templates: records of processing, retention schedule, privacy notices, DPIAs where required, data sharing and processor agreements, subject access procedure, breach response plan. Where the remedy is a system change, we can specify it or build it.

Ongoing

Following remediation, most organisations take the fractional DPO retainer. Those that do not require a DPO can take an annual review with Toolkit access to keep the registers current.

Situations we deal with regularly

Special category data held by charities and community groups; reporting and casework systems with vulnerable data subjects; the practical effect of the Data (Use and Access) Act 2025; cookie and tracking compliance; subject access requests that have become contentious; ICO correspondence.

Terms

Audit at a fixed fee scaled to organisation size. Remediation quoted from the audit. [Insert.]