Stories from February, 2026

Knowingly or Recklessly Obtaining Personal Data

We were working with a client recently to support data protection and a contract we were asked to review read that if the other party received personal data they should from our client they would keep it and use it. We flagged this up as inappropriate partly because it could

Read more
Policies Procedures and SOPs

  Understanding the Hierarchy of Policies, Procedures, and SOPs     Organisations run on clarity. When expectations are clear, decisions are consistent, and processes are repeatable, performance improves. But many teams confuse policies, procedures, and standard operating procedures (SOPs) — using the terms interchangeably when they actually serve very different

Read more
What is Data Processing?

What Is — and Is Not — “Data Processing” Under the UK GDPR? One of the most misunderstood aspects of the UK GDPR is the breadth of “data processing.” Many organisations assume it only refers to complex data analytics or IT-driven activity. In reality, the definition is far wider. If

Read more
Multi Purpose DPIAs – one DPIA to rule them all

A Data Protection Impact Assessment (DPIA) doesn’t always need to focus on a single, isolated processing activity. In many organisations—especially those with interconnected systems and overlapping workflows—it makes sense to complete one DPIA that covers multiple related processing activities, provided it remains clear, usable, and defensible. Done properly, a “multi-activity

Read more
Writing Your Employee Privacy Notice

What Employers Must Include in an Employee Privacy Notice (Worker-Facing Privacy Statement) to Be GDPR Compliant An employee privacy notice (sometimes called a privacy statement or privacy policy) sets out how an employer collects, uses, stores, and shares personal data about its workforce. Under the UK GDPR, this notice plays

Read more