UK GDPR · PECR · Data (Use and Access) Act 2025

UK data self-score: your picture as of today.

Ten questions a small business can answer in five minutes. Type your domain first and we read what is visible from outside, the way a customer or the ICO would. Marketing fines rose to £17.5m on 5 February 2026; a complaints procedure has been mandatory since 19 June 2026; the ICO's first letter is usually about a £52 fee. Nothing you enter here is stored.

Step 1 · What we can see from outside

Public pages and DNS only, the way a visitor sees them. Or skip this and answer the ten yourself.

Step 2 · The ten questions

  1. 1 · ICO fee paid

    Have you paid this year's ICO data protection fee? For most small businesses it is £52.

    ICO fee paid
  2. 2 · Privacy notice at collection

    When you collect someone's details (form, booking, sign-up), do they see a short privacy notice that says who you are, why you need the data, and how long you keep it?

    Privacy notice at collection
  3. 3 · Lawful basis and retention on file

    For each thing you do with personal data, is the legal reason written down, with how long you keep it?

    Lawful basis and retention on file
  4. 4 · Marketing consent

    Do you only send marketing emails, texts or calls to people who agreed, or to existing customers you told they could opt out, and does unsubscribe work in one click?

    Marketing consent
  5. 5 · Cookies and tracking

    Do your cookies and tracking run only after consent, except for strictly necessary ones and statistics or appearance cookies that offer a free opt-out?

    Cookies and tracking
  6. 6 · Breach plan, 72 hours

    If personal data leaked tonight, would you record it, assess the risk, tell the ICO within 72 hours if there is a risk, and tell the people affected if the risk is high, from a plan you already have?

    Breach plan, 72 hours
  7. 7 · Security measures

    Is personal data encrypted in transit and at rest, is access limited to named people with two-factor sign-in, and are systems patched and backed up?

    Security measures
  8. 8 · Suppliers under contract

    Does every supplier that touches your customers' data (hosting, CRM, email, booking, WhatsApp or SMS provider, AI tools) work under a written contract with the required data terms?

    Suppliers under contract
  9. 9 · Subject access in a month

    If someone asked for everything you hold on them, could you find it and send it within one month?

    Subject access in a month
  10. 10 · Complaints procedure

    Do you have a published complaints procedure for data questions, with an online form or an email address, that acknowledges within 30 days?

    Complaints procedure
0 of 10 answered; unanswered counts as cannot say

What this is. A self-score, not legal advice. Each question maps to the article or regulation that creates the duty and to the fine ceiling the ICO can apply; the mapping is shown after you answer. The outside read reports only what is present or absent on public pages and DNS. It never scans, never logs in, never rates severity.

Your control. Answers stay in your browser. The domain read is not kept beyond an hour of cache and is never tied to a person. Copy the line, redraw the questions for your sector, disagree in public. That is what it is for.