Stories from June, 2026

How Long Should Policies Be?

Organisations often produce long, detailed policy documents designed to cover a topic or activity comprehensively. These unified or combined super policies have a range of attractions. They cover every eventuality in one document, can be applied across the whole organisation, and mitigate risks around policy proliferation and version control. But

Read more
GDPR Privacy Principles: Lawful, Fair and Transparent

Article 5(1)a of the GDPR is simple. It sets out the first of the GDPR privacy principles: “personal data shall be processed in a lawful, fair and transparent manner in relation to the data subject”. These means the GDPR requires organisations to process personal data lawfully, fairly, and transparently. These

Read more
Risk Assurance: Strategies and Processes

Risk assurance is the final part of the risk management cycle. Identifying risks and implementing controls is only part of effective risk management. Organisations must also understand whether those controls are working as intended and whether risk management arrangements remain effective over time. Risk assurance provides that confidence, and as

Read more
Data Privacy Principles: What They Are and What They Mean

Article 5 of the GDPR introduces the seven core privacy principles on which GDPR compliant data processing rests. The principles apply to all personal data processing and most GDPR obligations flow from them. Because of this compliance is easier when organisations understand the principles rather than focusing only on individual

Read more
Conflicts of Interests and Human Resources: A Practical Guide for HR Professionals

Conflicts of interests are a key concern for human resources (HR) for several reasons. Firstly, the identification and management of any actual or potential conflicts of interests should form part of the recruitment process. Do not do it only for senior or sensitive posts. Secondly a failure to properly manage

Read more
Privacy By Design and By Default

Privacy by design and by default is one of the GDPR's most important accountability requirements. Key Messages Privacy should not be an afterthought. Organisations should consider privacy before collecting or using personal data. Privacy by design and privacy by default apply to far more than technology projects. The concept is

Read more
Introduction to the GDPR: Key Concepts and Principles

The General Data Protection Regulation (GDPR) is a comprehensive legal framework that governs the collection, processing, and storage of personal data belonging to individuals within the European Union and the European Economic Area. Although the UK has left the European Union it has retained the GDPR as the UK GDPR.

Read more