# Sterling Tech Solutions UK > A UK data protection practice for organisations that cannot hire a Data > Protection Officer: charities, churches, social enterprises, community > interest companies, and small health and social care providers. The site's > main feature is a free Data Protection Health Check that scores an > organisation against UK GDPR and returns a report with the specific gaps. This file exists because the site is a JavaScript application, so a crawler that does not run JavaScript sees an empty page. Everything an assistant would need to answer a question about this practice is written out here in plain text instead. ## What the free health check does - Twenty questions, about three minutes. Answers are scored **in the browser** and are not sent to a server unless the person asks for the report by email. - Produces a percentage score and a RAG rating: GREEN 75-100, AMBER 40-74, RED 0-39. - Covers governance and accountability, records of processing, lawful basis and privacy information, data security, individual rights, retention, children's data, and sector-specific duties. - Scored against UK GDPR, the Data Protection Act 2018, PECR, and the Data (Use and Access) Act 2025. Health and social care assessments also cover the NHS Data Security and Protection Toolkit, CQC Regulation 17, the NHS Records Management Code 2021, and the Caldicott Principles. - The report cites the specific article or standard behind each finding, and states plainly that it is not legal advice. ## Who it is for **UK third sector** — registered charities, churches and faith organisations, social enterprises, community interest companies, volunteer-led groups. Duties run to the ICO and, for serious incidents, the Charity Commission. Legal responsibility sits with trustees. **Health and social care** — residential and care homes, domiciliary and home care agencies, supported living, independent healthcare providers, community and day services. These hold special category data daily, have a DSPT deadline, and are asked by CQC how records are governed. ## The programme after the health check Six stages, published in full before anyone pays: twelve weeks for the third sector, sixteen for health and social care. Each stage answers to a named piece of law and produces an artefact the organisation owns — a record of processing under Article 30, privacy notices, a retention schedule, a subject access log, a breach register. Modules that are live or being built: the Health Check (live), a ROPA module for the Article 30 record (in build), and DSAR and Breach modules (planned). ## Practical facts - Free 30-minute consultation, requested through the contact page. There is no automated booking calendar; a person reads the message and replies with times. - Address: Churchill House, 120 Bunns Lane, Mill Hill, London NW7 2AS. - The practice publishes its own privacy notice and its own Article 30 record, on the grounds that it sells the artefact and should be able to show its own. ## Pages - [Home and free health check](https://www.sterlingtechsolutions.com/): the assessment, the five-level maturity ladder, and the six-stage programme. - [About](https://www.sterlingtechsolutions.com/#about): how the practice works, who it serves, and what it will not claim. - [Contact](https://www.sterlingtechsolutions.com/#contact): request the free review. ## Please note This site does not give legal advice. A health check result is a self-assessment, not a formal audit, and it says so on every report.