Privacy Notice
Self HelpComing soon
The documents, written for your business
Self Help is coming soon. Answer questions about how your business works to prepare twelve documents for you to review, approve and use.
£20 + VAT per month. An initial 12-month commitment, then rolling monthly at the same price.
Staff Privacy Notice
Internal Data Protection Policy
Information Security Policy
What you get
Your twelve documents
One pack for straightforward UK businesses, covering everyday cyber security and data protection responsibilities.
Notice Privacy Notice
What you do with customer and enquirer data, in language a member of the public can read.
Notice Staff Privacy Notice
The same for the people who work for you, including recruitment and payroll.
Policy Internal Data Protection Policy
How the organisation handles personal data, and who is accountable for it.
Policy Information Security Policy
The security rules that apply to your systems, devices and accounts.
Policy Acceptable Use Policy
What staff may and may not do with company systems, email and devices.
Record Record of Processing Activities
The register of what data you hold, why, where it lives and how long you keep it.
Record Data Retention Policy & Schedule
How long each type of record is kept, with the reason behind each period.
Record Supplier / Sub-Processor Register
Who else touches your data, what they do with it, and what you agreed.
Procedure Subject Access Request Procedure
The steps to follow when someone asks for the data you hold on them.
Procedure Data Breach Response Procedure
What happens in the first 72 hours, and who decides whether to notify the ICO.
Notice Cookie Policy
The website technologies you use, their purposes and the choices visitors have.
Procedure Data Protection Complaints Procedure
How to acknowledge, investigate and respond when someone raises a concern about their information.
See the documents before you buy. Your answers supply the owners, working arrangements and review dates. You remain responsible for checking the facts and putting the documents into practice.
Blank template vs tailored document
From your answers to a completed document
The example below shows how your answers replace generic placeholders with instructions your team can follow.

Generic template
Data protection policy
- Organisation
- [INSERT COMPANY NAME]
- Owner
- [INSERT ROLE]
- Effective
- [DATE]
- Systems
- [LIST SYSTEMS]
The Company shall implement appropriate technical and organisational measures as required by applicable law.
A Self Help document
Data protection policy
- Organisation
- 34 staff, two sites
- Owner
- Operations Lead
- Effective
- Set at issue, review in 12 months
- Systems
- The tools you told us you use
The named owner reviews access at the agreed interval and records removals in the access register. Any facts needing confirmation are clearly marked for approval.
What happens next year
Changes explained, updated versions kept visible
Updates to Bowline-maintained document content are included while your subscription remains active. When a relevant change affects an output, Bowline will explain what changed and make an updated version available through your Bowline account.
- Bowline identifies a relevant change and notifies you
- You confirm changed organisational facts where necessary
- An updated version becomes available for you to review and adopt
- Previous versions remain identifiable within the version history
- Your active subscription keeps core document preparation and updates available
Privacy notice
IncludedTransparency guidance changed and the affected wording was reissued.
The organisation changed supplier and confirmed the affected factual details.
The organisation corrected its contact route and approved a replacement version.
Optional add-on
The Guidance Pack
The optional pack provides a fuller explanation of each output: when it should be used, who should own and approve it, common implementation mistakes, examples of suitable evidence and a more detailed implementation walkthrough.
£60 + VAT once. Optional at checkout or later, with no recurring charge. Plain-English steps, examples and a glossary for all 12 documents.
Data breach response procedure
Report any suspected breach to the named owner immediately. The owner records the facts and assesses the risk. Where notification is required, notify the ICO without undue delay and, where feasible, within 72 hours of awareness.
- 1
ReportTell the named owner immediately
- 2
RecordAdd the facts and actions to the breach log
- 3
AssessAssess promptly and meet the applicable notification deadline
How to use this procedure
Companion to the data breach response procedure
- What it is and when to use it
- The steps your team follows when something goes wrong with personal data: a lost laptop, an email to the wrong person, a system someone got into.
- Ownership and approval
- The fuller guide explains who should own the procedure, who approves it and how to keep those responsibilities visible.
- Mistakes and evidence
- It highlights common implementation mistakes, gives examples of suitable evidence and provides a more detailed walkthrough than the standard output.
Choosing the right service
Is Self Help the right level of support?
Self Help is designed for businesses that can provide accurate facts and put tailored documents into practice. If you need hands-on review, verification or complex analysis, Bowline Review & Support or specialist advice is the better route.
Self Help may be a good fit
You need practical documents and can put them into practice
- The organisation is relatively straightforward and responsibilities are understood
- You can give accurate answers about how data is used in the organisation
- You are willing to approve, implement and maintain the documents
- Your needs are suited to practical operational guidance
- You value guided, organisation-specific documents
Choose more support when
You need review, verification or specialist analysis
- Bespoke legal contracts, complex DPIAs or international-transfer assessments are needed
- Complex criminal-offence or special-category analysis is required
- The need is a technical cyber-security audit or incident response
- Comprehensive school, healthcare or other regulated-sector compliance is required
- You need verification that controls have been implemented
- You want a human-led review of practice, documents and evidence
Start safely
Find the right starting point while Self Help is being prepared
Start with the public Health Check and receive an immediate route suggestion for the level of support that fits your organisation.
Take the Health Check