Stories from June, 2025

The Data Use and Access Act

The Data Use and Access Act changes the Data Protection Act, the UK GDPR, and the Privacy and Electronic Communication Regulations. In this briefing we cover some of the main changes, what they mean, and crucially what they mean for you. Be sure to scroll down to the bottom and join

Read more
Data Portability and the Right of Access: GDPR Rights Compared

The General Data Protection Regulation (GDPR) provides individuals with several rights regarding their personal data. Two of the most important — but often confused — rights are: Right of Access (Article 15) Right to Data Portability (Article 20) Below is a comparison and contrast of these two rights, including practical

Read more
Email and Subject Access Requests

Email and subject access requests do not go together well. Under the UK GDPR and Data Protection Act 2018, organisations are required to respond to a Subject Access Request (SAR) within one calendar month. While this timeframe may seem manageable in theory, the reality is that emails often present the

Read more
Why IT Projects Fail

IT projects frequently fail or run over time and budget due to a complex mix of technical, organisational, and human factors. While many of these issues are not unique to IT, they are amplified in this domain due to the rapid pace of technological change, complexity of systems, and lack

Read more
Fraud by Abuse of Position

The Fraud Act 2006 introduced a comprehensive statutory framework to address various types of fraudulent behaviour in the UK. One of the most significant and far-reaching provisions is found in Section 4, which deals with fraud by abuse of position. This offence is particularly relevant to individuals who occupy roles

Read more
Conflicts of Interests Checklist

A conflicts of interests checklist will help you develop and implement robust systems for managing this key governance activity. In this article we set out a comprehensive checklist, and you can download a copy for your own use too.   ________________________________________________________________________________________________ [su_box title="About the Author" box_color="#020a4a"]Michael has over 15 years

Read more
When to Close a Risk

In enterprise risk management (ERM), the concept of closing a risk refers to formally removing it from active monitoring and reporting processes. This decision, however, should never be taken lightly. The closure of a risk must be based on evidence, critical evaluation, and alignment with organisational risk appetite and strategic

Read more
Step by Step Guide to FOI Requests

The Freedom of Information Act 2000 (FOIA) sets clear statutory timescales for public authorities in the UK to respond to FOI requests. Meeting this timescales is a crucial aspect of FOIA compliance. ________________________________________________________________________________________________ [su_box title="About the Author" box_color="#020a4a"]Michael is an expert in governance and information governance, with many years’ experience

Read more
Fraud by Failure to Disclose

Like fraud by false representation, fraud by failure to disclose information is a specific offence defined in Section 3 of the Fraud Act. This offence applies when a person is under a legal duty to disclose information but intentionally fails to do so in order to make a financial gain

Read more