Five solicitor-drafted documents and one consultation that gets a small Irish business GDPR-ready in days, not months
Built for Irish SMEs after the Data Protection Commission shifted enforcement focus to small and medium businesses in 2025. Reviewed by a Law Society regulated Irish solicitor. Maps to the Irish Data Protection Act 2018 + EU GDPR. Editable templates — keep them, reuse them. Fixed fee €395 inc. VAT, no subscription.
What’s included — five documents + a call
- Website Privacy Notice — externally-facing, plain-English, Article 13/14-compliant
- Internal Data Protection Policy — staff-facing, including breach response steps
- DPIA template — for any processing that would require a Data Protection Impact Assessment
- Data Subject Access Request (DSAR) procedure — log + response template + 30-day workflow
- Cookie banner copy & configuration notes — wording, categories, “reject all” requirement
- 30-minute solicitor consultation by video or phone, walking you through the pack
What’s not included
- Acting as your appointed Data Protection Officer (separate engagement)
- Defending an active DPC investigation (separate engagement)
- Custom Data Processing Agreements with specific third parties (we can quote these separately)
Why this matters in 2026
The Data Protection Commission has been clear in its 2025–26 strategy that small and medium enterprises, healthcare providers, and local-service businesses are now in scope for active enforcement. The penalty range under the GDPR remains up to €20 million or 4% of annual turnover, whichever is higher — but the more common SME outcome is a corrective order, a public finding, and reputational damage with customers.
Most small businesses get caught not because they tried to flout the rules, but because they relied on a cobbled-together UK template, a free “compliance generator”, or no documentation at all. This pack fixes that in one purchase.
How the process works
- Order online for €395 inc. VAT.
- Short intake form — 5 questions about your business, the data you handle, and any third-party processors you use.
- 30-minute consultation with your solicitor — usually within 5 working days.
- You receive the five documents, tailored to your business, by encrypted email.
- You implement. The pack includes a one-page implementation checklist so nothing gets missed.
Frequently asked questions
Do I need a Data Protection Officer (DPO)?
Most Irish SMEs do not need a DPO. A DPO is required only in specific cases (large-scale systematic monitoring, large-scale processing of special-category data, public bodies). Your solicitor will confirm in your call whether you need one.
Will this cover my use of MailChimp / HubSpot / Stripe / etc.?
The privacy notice covers the use of common third-party processors at a category level. If you need formal Data Processing Agreements with specific named processors, those are quoted separately at a fixed per-DPA fee.
What if I receive a Subject Access Request?
The pack includes a DSAR procedure with a tracking log, response template, and 30-day workflow. You’ll know exactly what to do. If a request becomes complex (e.g. third-party data, legal-privilege exclusions), book a 30-minute follow-up consultation.
Are the templates editable?
Yes. You receive both a print-ready document and an editable .docx version, keyed to your business name, address, and the categories of data you handle.
What about the EU AI Act / Data Act?
Out of scope for this pack — those obligations apply differently and we offer a separate briefing for businesses building or deploying AI products.
