— Outsourced DPO · UK GDPR · ICO Accountability

A data protection consultancy built for what comes next.

Banking-grade senior expertise — eight years in data protection, most recently at a top-five UK bank — applied to UK SMEs through a single-consultant practice run with deliberate care. Led by Varnham, supported by carefully-deployed AI tooling.

Matthew Varnham
Founder
CIPP/E · CIPM
8 years data protection · UK banking
of VARNHAM&CO.
Established 2021 · CIPP/E · CIPM
— How this is built

Senior judgement at the centre. Modern tooling around it. Nothing in between.

— 01

The substantive judgement is personally mine

For the work where judgement matters — the granular gap analysis, every advice note, every signed assessment — the substantive interpretation is personally mine. Eight years in data protection, most recently inside a top-five UK bank, applied directly to your circumstances. The framework that produces your free compliance snapshot is one I designed and maintain; the snapshot itself is generated automatically from your responses.

— 02

Modern tooling carries the administrative weight

Maintaining records of processing, drafting first-pass artefact structure, monitoring regulatory developments, generating the structured compliance snapshot from your assessment responses, assembling audit-ready documentation. The work that is mechanical, repeatable, and weighs heavily on a sole practitioner — handled by carefully-deployed AI tooling within frameworks I design, validate, and maintain.

— 03

I stand behind both

A data protection consultancy that uses AI must be exemplary in its own AI deployment. The banking-sector experience is precisely what qualifies the consultancy to use these tools safely and lawfully — and to advise clients on doing the same. The substance and the operating model are accountable to the same person.

The result is a consultancy that delivers banking-grade depth at SME price points — without scaling by hiring juniors, and without compromising the personal accountability that makes professional judgement worth paying for.
— How to start

A clear path from question to confidence.

Most engagements begin with a free assessment of where you stand. From there, the path is structured so that each step is the right step — and the work that needs to happen, happens.

— Step 01
The free compliance snapshot
An assessment against the ICO's Accountability Framework — around 200 questions covering UK GDPR readiness, DUAA preparation, breach response, transfer governance, AI governance, and the rest. The output is a written compliance snapshot, delivered shortly after submission and yours to keep, no obligation.
Commitment Free
— Step 02
A no-obligation conversation
A 30-minute call with me to walk through the snapshot — what it shows, what matters most, and what a sensible next step looks like for your specific circumstances. Honest advice, even if it is that no engagement is currently warranted.
Commitment Free
— Step 03
The granular gap analysis
A detailed gap analysis report against the ICO Accountability Framework — line by line, prioritised, with practical remediation steps. The work that needs to happen anyway to scope a retainer, delivered as a standalone product. The natural lead-in to ongoing engagement, or a complete piece of work in its own right.
Commitment £1,500 + VAT

From the gap analysis, organisations that benefit from continuing engagement move to a retained DPO arrangement. Three retainer tiers are available, distinguished by the hours included each month. Standalone work — a one-off DPIA, a breach response, a training pack — is also available at the published hourly rate.

— Where there is genuine depth

Specialist work, in the sectors where specialism matters most.

Engagements come from organisations across many sectors. Three are named here because the consultancy carries verified, hands-on experience that goes beyond regulatory familiarity — the kind of depth that comes from operating inside the sector, not from advising it from outside.

— Banking-grade financial services

Financial services and regulated finance

Eight years in the data protection function, most recently inside a top-five UK bank — FCA-ICO dual reporting, banking-grade DSAR handling, breach response under regulatory scrutiny, complex international transfer governance. The depth informs every engagement with a regulated financial services client, and it informs the consultancy's standards across all sectors.

— Trustee-grounded charities

Charities and not-for-profits

Trustee at Derwent Rural Counselling Service, a Derbyshire-based therapy charity. Direct experience of how data protection obligations land at trustee level — beneficiary data, funder data sharing, safeguarding records, vulnerable-data governance. Charity work is approached from inside the sector, not from outside it.

— Governor-grounded education

Education and children's services

School governor at Whittington Green School. Direct experience of how parental consent, safeguarding records, SEN data sharing, and statutory data sharing with local authorities work in practice — including under the ICO's Age Appropriate Design Code. Education work is approached with the operational reality understood.

Engagements from organisations in any other sector are welcome — including healthcare, professional services, technology, retail, and manufacturing. Where the work is substantive, the depth is built around your specific obligations. More on how sector-specific work is approached →

A consultancy built on the obligations of senior judgement, the discipline of careful AI deployment, and the responsibility of personal accountability — and treating all three as preconditions of the work, not differentiators of it.
Matthew Varnham · Founder CIPP/E · CIPM Established 2021
— Get in touch

Two ways in. The free assessment for the snapshot route. The intake form for everything else.

Most engagements begin with the free compliance snapshot — that route is on the assessment page. If you have a general query, a specific question, or want to discuss something that doesn't fit the snapshot route, the intake form is the way in.

No automated marketing. No follow-up sequence. No surprises.

— Two routes in

Pick the one that fits.

The snapshot is the entry route for compliance assessment. The intake form is for general queries — referrals, retainer interest, specific questions, anything that doesn't fit the snapshot route.

01
The free compliance snapshot. Around 200 questions across the ICO Accountability Framework. 45–60 minutes. Snapshot delivered shortly after submission. Yours to keep regardless of what happens next.
02
The intake form. Two minutes. For general queries — retainer interest, specific questions, referrals, anything that doesn't fit the snapshot route.
Start the free assessment → Open the intake form →