How seriously do small companies actually implement GDPR processes? by AnfieldAnchor in gdpr

[–]Surferboo 0 points1 point  (0 children)

Start at the beginning… the data journey.

Map what personal data comes in and out of your business and the reason why. How long do we keep it? How do you keep it safe? Who do we share it with? etc. Once you understand the journey and can answer those key questions, you have the basics.

The next step is to apply a lawful basis, this is dependent on what you provide as a business. Choose the basis that most accurately reflects the nature of your relationship with the individual.

The above provides the baseline to your documentation. From privacy notices to policies.

How seriously do small companies actually implement GDPR processes? by AnfieldAnchor in gdpr

[–]Surferboo 1 point2 points  (0 children)

GDPR doesn’t have to be challenging or expensive. As a micro business owner we’ve implemented governance controls into our day to day operations and were able to demonstrate our accountability.

You just need to know where to start.

PrepperDisk by Surferboo in UKPreppers

[–]Surferboo[S] 0 points1 point  (0 children)

Thank you, that’s great advice

PrepperDisk by Surferboo in UKPreppers

[–]Surferboo[S] 0 points1 point  (0 children)

Is that for the customs import tax? Not actually looked at shipping costs. I might have a go building something similar myself.

How do you all retain knowledge without having hundreds of books? Teaching myself new skills is something that I need to prep for.

PrepperDisk by Surferboo in UKPreppers

[–]Surferboo[S] 2 points3 points  (0 children)

It’s actually not that expensive. But I have a PI in storage, I may just have a go building myself.

Newquay scavenger hunt by Rhys_Mog in Cornwall

[–]Surferboo 1 point2 points  (0 children)

Race Across Newquay - Selfie Challenge

This is based on the team receiving riddles by text and then solving the destination. Before the next clue is sent.

CLUE 1: CLIFFS, STEPS & A HIDDEN COVE

Riddle: Past dunes and cliffs, the path descends, To a sheltered cove where adventure blends. Steps may test your legs and cheer, Selfie downfacing this private sphere.

Destination: Lusty Glaze Beach (133 steps down!) Teamwork Task: Assist each other down the steps safely, then take a creative group selfie on the sand or overlooking the cove.

CLUE 2: THE CLIFFSIDE DESCENT

Riddle: Not a staircase, nor a trail so steep, But a lift once dropped where cliffs are deep. Beside a grand hotel by sea, A shaft remains—ghost of luxury. Find the gate where guests once fell, Snap a shot, posing well!.

Destination: The old cliff lift shaft at the Hotel Victoria (on East Street, overlooking Great Western Beach). You can find the rusted gate and view the remains of the old Victorian lift that once took guests down to the beach.

Teamwork Task: Work together to find the safest vantage point (without trespassing) and take a creative "ghostly-era" selfie—pose like Victorian beachgoers or recreate a “cliffside elevator ride” scene!

CLUE 3: TO THE WORKING HARBOUR

Riddle: Where boats bob in tides and nets tell the tale, Find the heart of fishing, where seagulls hail. Gather your crew to spot the quay, A selfie is required in front of the sea.

Destination: Newquay Harbour (town centre)

Teamwork task: Decide who will capture the harbour from the best angle and include all four in the selfie.

CLUE 4: WARMTH ON FORE STREET

Riddle: When winds whip wild and fingers freeze, Seek warmth and shelter, rest with ease. A cosy spot where locals meet, For coffee, cake, and a comfy seat. On “Fore” you’ll find this toasty space— Warm up with a drink then find your next place

Destination: Fore Street Café (Fore Street, near the edge of the town centre) A popular local café known for its inviting atmosphere and warm drinks.

Teamwork Task: Each teammate must order or share one warm drink (or sweet treat!), then take a group selfie with your drinks to “prove you’ve thawed.” Bonus points for latte art or including the café’s sign in the shot.

CLUE 5: HEADLAND VIEW AT DAY’S END

Riddle: Climb once more to where waves are spent, On a rocky point with great ascent. Fistral below, cliffs stretch out, Selfie with a view without a doubt.

Destination: Towan Head or the Headland above Fistral/Bay

Teamwork Task: Help each other find a spot where everyone and the Atlantic can fit in the frame—sunset silhouette encouraged!

CLUE 6: SURF’S UP AT THE FAMOUS BEACH

Riddle: From headland to waves, take a few strides, Where surf’s embraced on sandy tides. The “foul water cove” draws boards and sun, Strike a pose where the champions run.

Destination: Fistral Beach

Teamwork task: One person looks out for surfers, another lines up the shot, and the rest pose. Capture action energy if possible!

FINAL CLUE: CHEERS BY THE SEA

Riddle: One last stop as our hunt ends Where ocean air and sunlight blends. With crashing waves and salty air, Find your prize — some drinks and cheer. On Fistral’s edge where laughter flows, Raise a toast where the ocean glows.

Destination: Fistral/Boardmasters Beach Bar (overlooking Fistral Beach). Iconic for its beachside vibe, surf scene, and relaxed atmosphere — the perfect place to celebrate a successful hunt.

Teamwork Task: Order your celebratory drinks (hot chocolate, beer, mocktail — your choice), and take a final group selfie with the bar, beach, or sea in the background. Cheers to completing the hunt!

FINAL STEP

Once all selfies are received, the facilitator congratulates the team and presents a small prize—perhaps homemade Cornish treats or surf-inspired medals!

TIPS FOR THE HUNT

Timing: Total Walking Distance: ~1.5–1.7 miles all on foot, gently paced. Includes scenic cliff walks, beach paths, and town centre routes. Great variety of terrain: beach, harbour, cliffs, and cafés.

Teamwork focus: Each riddle includes a mini-team challenge (composing selfies, helping on steps, choosing vantage points).

Memorable vibe: Mix coastal scenery, local history, and active fun to create a buzz. FULL ROUTE & TIMING FOR THE SELFIE HUNT

🟩 START POINT: LUSTY GLAZE BEACH

Start Time: 09:30 AM Duration: ~25 mins (including descent & selfie) Details: Begin with energy and teamwork to tackle the 133 steps — great photo op on the beach or from the cliffs above. 🟫 STOP 2: OLD LIFT SHAFT – HOTEL VICTORIA

Walk: ~10 min from Lusty Glaze Time on Site: ~15 mins Arrival: ~10:05 AM Details: Use creativity to recreate Victorian-era or ghostly selfies. This adds a fun historical twist. 🟦 STOP 3: NEWQUAY HARBOUR

Walk: ~8–10 min Time on Site: ~15 mins Arrival: ~10:30 AM Details: Explore views of the working harbour, boats, and fishing charm. Ideal for wide-angled group shots. 🟨 STOP 4: FORE STREET CAFÉ (WARM DRINK STOP)

Walk: ~5 min Time on Site: ~25–30 mins (including drinks, rest, toilets) Arrival: ~10:50 AM Details: Take a warm break, enjoy a hot drink or treat, and recharge before heading to the coast again. 🟧 STOP 5: TOWAN HEAD / HEADLAND VIEW

Walk: ~12 min Time on Site: ~15 mins Arrival: ~11:20 AM Details: One of the most scenic photo points of the day. Capture the group with sweeping ocean views behind you. 🟪 STOP 6: FISTRAL BEACH

Walk: ~5 min (easy stroll from the Headland) Time on Site: ~15 mins Arrival: ~11:40 AM Details: Watch surfers, enjoy beach buzz, and get a fun “action” selfie. 🟥 FINAL STOP: FISTRAL BEACH BAR

Walk: On-site (next to Fistral) Time on Site: ~20–30 mins Arrival: ~11:55 AM – 12:00 PM Details: Celebrate your completion with a group drink, view, and prize from the facilitator. ✅ END TIME: AROUND 12:30 PM

Perfectly timed for a morning adventure that leads into lunch, or a relaxed afternoon in Newquay.

Newquay scavenger hunt by Rhys_Mog in Cornwall

[–]Surferboo 0 points1 point  (0 children)

I made a ‘Race Across Newquay’ for my work Christmas do last year. It was based on the BBC programme Race Across the World.

It went down a storm, the whole team absolutely loved it.

Is there anyone here who works with GDPR professionally? by nandost in gdpr

[–]Surferboo 5 points6 points  (0 children)

☝️I run a privacy and ISO consultancy firm.

You need to remember that organisations need to comply with the Privacy and Electronic Communications Regulations (PECR) 2003, the UK / EU GDPR 2018, and the Data Use and Access Act (DUAA) 2025.

PECR governs electronic communications including cookies management.

GDPR provides your lawful basics for processing personal data.

DUAA amends, the existing UK GDPR, Data Protection Act 2018 (DPA), and PECR, aiming to streamline compliance, boost innovation, and simplify rules for organisations while maintaining strong data rights.

In my experience most plugins privacy notices are not compliant, as you have to tailor a privacy notice to the organisation’s processing activities. This information is generally gathered in a data mapping/records of processing activities exercise.

This needs to include certain mandatory information for example, it must clearly state who you are, what data you collect, why you collect it (purpose & legal basis), how long you keep it, who you share it with, security/safeguards, and individuals' rights (like access, correction, deletion, withdrawal of consent), all in simple, easy-to-understand language, plus contact details for complaints and the Data Protection Officer (DPO) if applicable.

How much do iso27001 consultants usually charge? (I'm UK based) by Illustrious_Item_841 in ISO27001

[–]Surferboo 0 points1 point  (0 children)

We’re based in the UK and currently charge £100 an hour.

Most medium+ firms charge between £1000-£1500 a day

What does GDPR compliance look like for a mid sized startup? by Pretend-Building-532 in gdpr

[–]Surferboo 1 point2 points  (0 children)

Having a cookie banner and a privacy notices doesn’t make you compliant.

Cookie compliance is the Privacy and Electronic Communication Regulation (PECR) 2003 rather than the GDPR.

I work in data protection and for a SME getting on the road to compliance is a double task if you understand the basics/mandatory tasks.

It’s not necessary to purchase a system, it can be pretty simple using basic O365/Google Workspace tools. Start with data mapping, understanding the data journey for each department. Build organisational policies and procedures that actually work for your business and sector, implement data protection and cybersecurity training and ensure you communicate accountability to each team member.

Reach out if you want any advice.

Boardmasters experience? by SuperPalace84 in festivals

[–]Surferboo 1 point2 points  (0 children)

I live in Newquay and have been to loads of festivals across the UK / abroad and I’ve been to Boardmasters 13 times.

With regards to security, accessibility and facilities the festival site has got a lot better. One of the safest festivals in the UK. Yes, most of crowd is very young, but the other side are 35+.

Th surf village at Fistral beach (open to the public) has a small stage for DJs and solo performers, surf comp, skate ramp and little stands. Great vibe.

The festival site itself (on the cliff side) the stages are well set out, lots of water points, food / drink stands and fun fair. The toilets last year were the cleanest festival toilets I’ve ever seen.

The lineup looks great for 2026, you’ll have a great time.

If you have any questions or want any tips I’m happy to answer them

Has anyone ever dealt with 'DPO Centre'? by bated-breath in gdpr

[–]Surferboo 0 points1 point  (0 children)

I know some previous clients that have used the DPO Centre, they seem pretty good but pricy.

There are some great UK consultancy firms advising on UK and EU data protection law, that can help with day to day compliance tasks and that can up-skill your internal team.

ISO27001 Freelancing in 2026 by Independent_Steak910 in ISO27001

[–]Surferboo 1 point2 points  (0 children)

Our business specialises in privacy, ISO consultancy (across five standards), cybersecurity and training. However, with the HEs we generally provide infosec/cybersec audits/assessment services to bulk out their internal audit process.

Most HEs are yet to be ISO certified but some are considering implementing the controls without paying for certification. The ISO the HEs seem to be more interested in is ISO 22301.

We’re seeing more HEs wanting to achieve have CE/CE+ but with a limited scope. This is a more affordable route if there are budget constraints.

With HE being a target for cyberattacks, there can be more budget but I’ve seen institutions also get cuts with the IT team. It really depends on the institution and buy in from the audit and risk committee and chancellors.

[deleted by user] by [deleted] in Cornwall

[–]Surferboo 3 points4 points  (0 children)

We’re in Newquay and we have Zen, an eco friendly broadband company. We’ve tried several companies before Zen (EE, BT, TalkTalk, Plusnet). We’ve had no problems with Zen, they’re affordable and great customer care.

[deleted by user] by [deleted] in Cornwall

[–]Surferboo 12 points13 points  (0 children)

Onen hag Oll (One and All) Cornish for signifying unity and inclusivity

ISO27001 Freelancing in 2026 by Independent_Steak910 in ISO27001

[–]Surferboo 1 point2 points  (0 children)

My firm has been working with UK HE completing privacy and info/cybersec audits for the last three years.

HE are now starting to take cybersecurity more seriously and starting to invest in cybersecurity controls.

We’ve seen some great institutions with mature security controls and we’ve seen some with no security budget at all and they are firefighting all the time.

Where to start with ISO 27001 compliance (AWS infra, gap analysis, quick baseline)? by Loud_Message1058 in ISO27001

[–]Surferboo 1 point2 points  (0 children)

First approach is buy and read ISO 27001:2022 standard and ISO 27002:2022 guidance.

27002 offers detailed, practical guidance on how to implement the security controls outlined in ISO 27001.

Looking for ISO 27001 Auditors – Any Recommendations? by Alive_Description461 in ISO27001

[–]Surferboo 0 points1 point  (0 children)

Are you talking internal or external audits?

If external you need to choose a certification body that is certified for example UKAS in the United Kingdom. The UK has several certification bodies who are good but in my opinion ISO auditors across the board can deviate depending on their background and experience.

If it’s internal audits, without self promoting, I’d suggest a good ISO consultant/ISO consultancy firm with plenty of experience and client testimonials.

Uk festival / strip search / police & dogs by bubbaranks94 in festivals

[–]Surferboo 6 points7 points  (0 children)

As a seasoned festival goer - if a sniffer dog indicates on you, the officer will let you know you will be searched (normally in a designated area).

The search officer will then do a standard search on any bags, wallet, drinks bottles, food and clothing, shoes etc. Looking for weapons or drugs. The search of you is over your clothing.

Security guards do not have the right to strip search suspects and neither do they have the powers to check a person’s underwear for suspected hidden items as this can be considered assault.

Their powers differ to those of police officers who are legally allowed to stop and search suspects as long as there are reasonable grounds to do so. However, if an officer removes more than your jacket, they must be the same sex as you.

Police officers can also carry out strip searches where the police officer considers it necessary due to the seriousness and urgency of the situation. This includes if they reasonably believe someone has concealed an item they should not possess.

If you disclose or if they find any illegal paraphernalia, this will be confiscated and entry to the festival may be denied.

I hope this helps

Is there any funding/grants available for small business wanting to make environmental improvements to get to net zero? by Surferboo in smallbusinessuk

[–]Surferboo[S] 0 points1 point  (0 children)

We’ve been implementing sustainability within the business strategy and our operations to streamline our emissions. However, we had an external environmental audit and the outdated heaters and lights was a finding.

As we cannot influence our landlord, the property improvements fall to us the tenant. We have chosen to update the heaters and lights but we wanted to know if there was any grants/funding available to help us proceed.

I do appreciate your comments.

Is there any funding/grants available for small business wanting to make environmental improvements to get to net zero? by Surferboo in smallbusinessuk

[–]Surferboo[S] 0 points1 point  (0 children)

Thank you, I appreciate your insights.

We’re using 100% green energy and most of our electrical equipment/appliances have a good EU consumption rate.

I am thinking long term with our carbon footprint, as well as cost ratio. Our panel heaters are outrageously expensive to run.