Five questions, starting with the one nobody asks: who in your organisation actually ends up doing this work? No sign-up, and every assumption we make is shown and editable — because the answer is only useful if you can defend it to someone else.
What kind of organisation are you?
Different sectors face different obligations — public bodies handle FOI as well as subject access, and the volume profile varies enormously.
And what's your role?
So we show you the part that's actually relevant to you. A finance director and a privacy manager need very different things out of this.
Who actually ends up doing this work?
This is the question that matters most, and the one almost nobody asks. Select everyone who gets pulled in — not just whose job it officially is.
Roughly what scale are we talking about?
Estimates are fine — nobody has these to hand, and you can change them on the next screen.
Is the volume going up?
Across the organisations we talk to, roughly 20% a year is typical — and it's the single biggest thing missing from most compliance budgets.
—
—
—
—
Based on who you told us actually does this work
These are estimates, not your numbers. Adjust them and everything above updates. We'd rather you took a figure to your finance team that you can defend than one of ours you can't.
This is a directional estimate from the figures you entered, meant to show you where to look — not an audit. It deliberately excludes things we can't responsibly guess at, like regulatory exposure or the cost of a complaint, because inventing those numbers would make everything above easier to dismiss. A consultation is where you'd firm it up.
A worked example beyond the obvious staff-hours estimate.
When the statutory clock can legitimately be paused — and when it can't.
The resourcing case for identity-verified, pre-scoped requests.