— Services

Senior DPO support, structured around how SMEs actually work.

Three retainer tiers, distinguished by the hours included each month. The substantive scope is the same across all three: a named DPO on the ICO register, regulatory monitoring, advisory time, and ongoing governance. Beyond the retainer, the £1,500 gap analysis and additional-rate work are available for one-off engagements.

of VARNHAM&CO.
All retainer engagements include a named DPO on the ICO register
— What every retainer includes

A named DPO, on the ICO register. The substantive scope is the same across every tier.

Tiers differ in the hours included each month, not in the substance of the engagement. Every retained client gets the same scope of professional service — and the same person delivering it.

— 01

Named on the ICO register

Formal appointment as your organisation's Data Protection Officer, recorded with the Information Commissioner's Office. The person of record under Article 37 UK GDPR — accountable, contactable, and identified to the regulator. Not advisory cover; an actual appointed DPO.

— 02

Article 39 duties carried

The substantive Article 39 duties carried as standard: informing and advising on obligations, monitoring compliance, providing guidance on DPIAs, cooperating with the ICO, and acting as the contact point for the regulator and for data subjects on request.

— 03

Continuous regulatory monitoring

Ongoing tracking of UK GDPR developments, ICO guidance, the Data (Use and Access) Act 2025 implementation, and sector-specific regulatory changes. You are told what matters for your organisation as it happens, not when it appears in a quarterly newsletter.

— 04

Breach response support

If something goes wrong, I am reachable. Initial assessment, containment guidance, notification decision support, and ICO communication where required. The retainer includes the response capacity itself; substantial breach investigation work is at the additional rate.

— 05

DSAR support — for your team

Guidance on running data subject access requests correctly, including the structural decisions, redaction approach, and statutory timing. The actual DSAR work remains with your team because it is resource-intensive; the retainer ensures the work is done correctly and to the required standard.

— 06

Annual governance review

A formal annual review of your data protection posture, signed off in person, ready for board reporting. The standing audit-readiness check that demonstrates compliance maturity to regulators, insurers, professional referrers, and prospective clients.

— Retainer tiers

Three tiers. The same substance. Different hours.

The meaningful difference between tiers is the hours included each month — and therefore the price. Tier names are calibrated to organisation scale and to how much ongoing data protection work the engagement is expected to involve.

— Tier 01

Foundation

For smaller SMEs with well-bounded data processing. The retainer covers the named DPO appointment and the substantive duties; included hours are sufficient for routine advisory work and standing governance.

Included hours
3 hours / month
Price
£1,000 / month + VAT
— Tier 02

Operational

For growing SMEs where data work has structural weight. The tier most engagements settle at — sufficient hours for active advisory work, project input on new processing, and material breach response without immediately moving to overflow.

Included hours
5 hours / month
Price
£1,500 / month + VAT
— Tier 03

Strategic

For established SMEs where data protection is a board-level concern. Sufficient hours for substantive ongoing engagement, regular governance presence, and meaningful project input. The tier suited to organisations with FCA-regulated activity, complex international transfers, or sustained regulatory exposure.

Included hours
9 hours / month
Price
£2,500 / month + VAT
All three tiers share the same scope and the same person delivering it. The right tier is the one whose hours match how much DPO support your organisation actually needs — not a feature comparison.
— Additional-rate work

Beyond the retainer — work paid additionally.

Two categories of work sit outside the retainer hours: substantive one-off projects with a defined scope (handled at a fixed price), and additional ad-hoc advisory time where retained hours have been used (handled at the published hourly rate).

— £1,500 + VAT

The granular gap analysis

A detailed gap analysis report against the ICO Accountability Framework — line by line, prioritised, with practical remediation steps. The substantive paid product that follows the free compliance snapshot. Available as a standalone engagement, or as the natural lead-in to a retainer.

This is the work that needs to happen anyway to scope a retainer properly — delivered as a product in its own right, with a fixed price and a defined deliverable. More on the assessment-to-gap-analysis path →

— £200 / hour + VAT

Hourly overflow rate

Where retained hours have been used and additional advisory time is needed in the month, time is billed at the published hourly rate. The same rate underwrites the tier pricing, applied transparently when work runs beyond the included hours.

No surprises, no markup, no premium for being outside the retainer. The hourly rate is what the time is worth, applied transparently.

— Project work

Substantive one-off engagements

Specific projects scoped and priced individually: full DPIAs on novel processing arrangements, breach investigation and reporting on substantial incidents, training pack development for staff, custom advisory work beyond routine. Scoped following the free assessment or initial conversation.

— DSAR

DSAR support, not delivery

Data subject access requests are resource-intensive and remain with your team. The retainer ensures DSARs are run correctly — structural advice, redaction approach, statutory timing, sign-off where DPO sign-off is required. Substantial DSAR engagements are handled at the additional rate or scoped as project work.

— Training

Staff training and awareness

Tailored training packs for general staff, line managers, and board members. Built around your organisation's specific data flows and obligations rather than generic GDPR content. Available as a one-off engagement or as a recurring annual programme.

— Getting started

The path from question to engagement.

Most engagements begin with the free compliance snapshot, not with the services page. The snapshot is what makes a sensible conversation about retainer or project work possible.

— Step 01
The free compliance snapshot
An assessment against the ICO Accountability Framework — around 200 questions across the eleven Framework areas. Output is a written snapshot you keep.
Commitment Free
— Step 02
A no-obligation conversation
A 30-minute call with me to walk through the snapshot and the right next step for your circumstances.
Commitment Free
— Step 03
The granular gap analysis
Detailed gap analysis against the ICO Framework — the substantive paid product, also the natural input to retainer scoping.
Commitment £1,500 + VAT

From the gap analysis, organisations that benefit from continuing engagement move to the appropriate retainer tier. The decision rests on the gap analysis output — a deliberate decision, made with clear evidence of what the engagement would cover.

— Get in touch

Two ways in. The free assessment for the snapshot route. The intake form for everything else.

If you are evaluating tier fit or considering a one-off engagement, the intake form is the way in. If you would prefer to start with the free compliance snapshot, the assessment page is the route.

No automated marketing. No follow-up sequence. No surprises.

— Two routes in

Pick the one that fits.

The snapshot is the entry route for compliance assessment. The intake form is for general queries — referrals, retainer interest, specific questions, anything that doesn't fit the snapshot route.

01
The free compliance snapshot. Around 200 questions across the ICO Accountability Framework. 45–60 minutes. Snapshot delivered shortly after submission. Yours to keep regardless of what happens next.
02
The intake form. Two minutes. For general queries — retainer interest, specific questions, referrals, anything that doesn't fit the snapshot route.
Start the free assessment → Open the intake form →