Stories from December, 2023

Vital Interests and the GDPR

Of all the lawful bases for data processing under the GDPR, one stands out for urgent and life-saving situations —vital interests. As we embark on this exploration, our journey begins with understanding the critical importance of vital interests in the broader landscape of lawful data processing. Please note: this article

Read more
What is a Record of Processing Activity?

A record of processing activity (ROPA) is a document that organisations are required to maintain under the General Data Protection Regulation (GDPR). It is a detailed inventory of an organisation's data processing activities, providing insights into the types of personal data processed, the purposes for which it is processed, and

Read more
Statutory Duty and Data Processing for GDPR

In this article we explore how a statutory duty and data processing work together as set out in the General Data Protection Regulations (GDPR). Understanding the lawful bases for processing is paramount whatever lawful basis you are using. This article delves into the often nuanced yet powerful concept of statutory

Read more
Sustainable Governance Improvements

We’re always proud to work with our clients and leave them with sustainable governance improvements. However, after delivering a project and completing our work we often wonder: will the improvements we devised and implemented will be sustained. In other words, have we been truly successful? After all, the point of

Read more
How to Score a Risk

Knowing how to score a risk is a key part of the risk management process. Defining and evaluating risks tells you what risks you have. Risk scoring helps you prioritise risks for action based on your appetite for, and tolerance of risk. in this article we will explore how to

Read more
How to Respond to a Subject Access Request

Under the GDPR every organisation must know how to respond to a subject access request. At its simplest a subject access request is when a person, a data subject, asks for access to data held about them. However, the GDPR sets certain standards that take this right further than simply

Read more
People and Systems: How Governance Helps

Introduction: People and Systems People and systems are a natural fit. We build systems to enable us to work together, and achieve shared goals. In the modern world those systems are technical, financial, and operational. However, that also means within systems there is one element that consistently proves to be

Read more
Legitimate Interests under GDPR

Legitimate interests under the GDPR can be a lawful basis for data processing. Navigating the General Data Protection Regulation (GDPR) requires a full understanding of the different lawful bases for processing personal data. "Legitimate Interests” can give organisations with a pathway for responsible and lawful data processing. This article delves

Read more
What is Governance?

What is governance? Governance refers to the framework of rules, policies, and procedures that set the direction and control of an organisation. It establishes the organisation's purpose, values, and principles, and it outlines the responsibilities of those who govern the organisation. Governance ensures that the organisation is operating in a

Read more
Root Cause Analysis: Methods and Examples

A Root Cause Analysis (RCA) is a systematic process for identifying the underlying causes of problems or events. It goes beyond addressing surface-level issues, aiming to uncover the fundamental reasons behind incidents. In this article we will explore what a root cause analysis is, what it is for, and how

Read more