Compliance tools · Cybersecurity and data protection · A-001
GDPR compliance tool
Regulation (EU) 2016/679 · European Union · Binding instrument
Appoint the compliance person you already employ. The system trains them.
A member of your own staff, with no compliance background, reads the training module, answers the interview, and finishes with your GDPR documentation cited article by article. The knowledge stays in the business.
Free with a free ComplianceSME account
Free to download. Runs in your own Claude account. Membership keeps it current when the law changes.
Get it freeThe instrument
GDPR is Regulation (EU) 2016/679, a binding instrument in the European Union. Personal data processing obligations for any business handling EU residents' data.
Scope
The free assessment screens for GDPR when a business handles personal data.
Screen your business against all 87 instruments, free →
The problem it solves
Trained compliance people are scarce and expensive. A compliance consultant charges €800 to €1,500 a day, and when the engagement ends the knowledge leaves with them. Enterprise GRC platforms run to €50,000 and more in setup, then charge per seat, per framework, per year, and most assume you already employ a specialist to drive them.
So in most small and medium businesses the work lands on whoever sits closest to IT, tracked in a spreadsheet. That is a single point of failure carrying the compliance position of the whole company, with no training behind it.
The compliance system
The system is built to take a person who has never read the instrument to a completed, cited compliance report. The training module teaches the regulation first, in plain language. Then the system interviews them about your organisation in your own Claude account: upload the files, type START, and answer one question at a time. The working files collect the evidence the instrument asks for and record what is in place and what is missing, and your documentation is produced with article citations an auditor can check against the law.
No consultant, no sales call, no per-seat pricing, no platform you are locked into. A one-time purchase you keep, completed without hiring anyone.
What you finish with
- Your exact position under GDPR: what is in place, what is missing, and what to do about each gap.
- Documentation with article citations, ready for auditors, insurers, customers and public buyers.
- A trained person inside the business who understands what the regulation requires, and stays.
- Evidence files you keep on your own systems, with no recurring fee to read your own assessment.
- All of it completed in-house, at your own pace, without booking a single meeting.
Why not just ask an AI?
Ask a general AI whether it can produce your compliance documentation and it will tell you it can. Models are built to agree with you. It cannot, in one sitting or a thousand, because the capability does not live in the model: it lives in the machine engineering around it, the obligations dictionary, the evidence structure, the citation discipline and the current text of the law.
A general model also answers from its training data, and regulation moves faster than training data. An agentic system improvises around the gaps and answers with confidence either way, and you cannot tell which of its answers are current. That is how a business ends up documented against a version of the law that no longer exists.
The ComplianceSME system removes the gamble. Agentic behaviour is engineered out: the AI works inside structured files that hold the accurate, current regulation, it follows the interview, and every finding is produced with article citations you can verify against the regulation itself. The system carries the regulation in full, so nobody in your business is burdened with reading it cold.
The gap between what you think AI can achieve, what AI will say it can achieve, and what it can really achieve is huge. That gap is the first thing every toolkit teaches: the training module opens with AI literacy before it opens the regulation, so the person running the system understands the tool in their hands before they trust it with the law.
Why trust it
Every system in the register is built against a frozen dictionary of 9,904 obligations across 87 instruments, through a documented build method. ComplianceSME's EU AI Act work has been covered in Solicitors Journal. The register, the catalogue and every price are public on this site: no demo call, no quote form, no pipeline.
With the membership, every system you own is updated in your dashboard as the law shifts. ComplianceSME monitors compliance globally and is contributing to the deferred 2027 provisions still to come, the only voice in that process representing 31.6 million SMEs across our 28 nations.
Questions businesses ask
Does GDPR apply to my business?
The free assessment screens for GDPR when a business handles personal data. The free assessment at compliancesme.com screens your business against all 87 instruments in the register at once, and takes about ten minutes.
What is GDPR?
GDPR is Regulation (EU) 2016/679, a binding instrument in the European Union. Personal data processing obligations for any business handling EU residents' data.
How much does the GDPR compliance system cost?
The GDPR compliance system is free. It needs a free ComplianceSME account, and it runs inside your own Claude account. An optional membership at £500 per month keeps it current when the law changes.
Do I need a consultant to comply with GDPR?
No. The system runs in your own Claude account, interviews you in plain language one question at a time, collects the evidence the instrument asks for, and produces your compliance documentation with article citations. It is a documentation tool, not legal advice.
Who in my business should run the GDPR system?
Any member of staff who is comfortable with a computer. The training module teaches the regulation before the interview begins, so no compliance background is required. Owners typically appoint an operations manager, an office manager or an IT lead, and the system takes that person from first reading to finished, cited documentation.
Related in cybersecurity and data protection: ePrivacy Directive · NIS2 Directive · CER Directive · DORA