I've recently started a working relatonship with a property maintainence company who will hopefully be putting some work my way (just the usual grass cutting outside flats etc). They have just emailed to say that the data protection laws are changing in May and that "every organisation needs to undertake a risk assessment and formulate an action plan to demonstrate how they collect, store, use and remove client data beyond the 25th May 2018". They now want something from me that shows I have "assessed procedures in some way and have robust systems in place". Does anyone have any experience of this? Or any idea of what a data protection risk assessment would look like?