Data Accuracy: The Fourth GDPR Privacy Principle

Data accuracy - keeping accurate personal data are essential for lawful, fair and effective data processing and decision making. The Accuracy Principle is often overlooked because it appears deceptively simple. Many organisations reduce it to "keep records up to date." In reality, it is about ensuring that decisions are based

Read more
PESTLE Analysis: A Key Risk Management Tool

A PESTLE analysis provides a structured framework for systematically identifying external risks and opportunities, ensuring that political, economic, social, technological, legal and environmental influences are all considered. Many organisations struggle to identify risks consistently. A PESTLE analysis is one important tool to help them do this. Where Does PESTLE sit

Read more
Data Minimisation: The Third GDPR Privacy Principle

Data minimisation is the third of the seven core principles of the UK GDPR. It requires organisations to collect, use, share and retain only the personal data that are adequate, relevant and limited to what is necessary for the purposes for which they are processed. At first glance, this may

Read more
Understanding the Freedom of Information Act 2000: A Practical Guide for Schools

Freedom of information for schools presents its own challenges. Schools receive requests for information from parents, journalists, governors, campaign groups and members of the public every year. Some requests are simple. Others involve sensitive issues such as safeguarding, finances, admissions or complaints. The Freedom of Information Act 2000 (FOIA) gives

Read more
Purpose Limitation: The Second GDPR Privacy Principle

Purpose limitation is one of the seven core principles of the General Data Protection Regulation (GDPR). It requires organisations to be clear about why they need personal data before they collect it and to ensure that information is not used in ways that are incompatible with those original purposes. The

Read more
How Long Should Policies Be?

Organisations often produce long, detailed policy documents designed to cover a topic or activity comprehensively. These unified or combined super policies have a range of attractions. They cover every eventuality in one document, can be applied across the whole organisation, and mitigate risks around policy proliferation and version control. But

Read more
GDPR Privacy Principles: Lawful, Fair and Transparent

Article 5(1)a of the GDPR is simple. It sets out the first of the GDPR privacy principles: “personal data shall be processed in a lawful, fair and transparent manner in relation to the data subject”. These means the GDPR requires organisations to process personal data lawfully, fairly, and transparently. These

Read more
Risk Assurance: Strategies and Processes

Risk assurance is the final part of the risk management cycle. Identifying risks and implementing controls is only part of effective risk management. Organisations must also understand whether those controls are working as intended and whether risk management arrangements remain effective over time. Risk assurance provides that confidence, and as

Read more
Data Privacy Principles: What They Are and What They Mean

Article 5 of the GDPR introduces the seven core privacy principles on which GDPR compliant data processing rests. The principles apply to all personal data processing and most GDPR obligations flow from them. Because of this compliance is easier when organisations understand the principles rather than focusing only on individual

Read more
Conflicts of Interests and Human Resources: A Practical Guide for HR Professionals

Conflicts of interests are a key concern for human resources (HR) for several reasons. Firstly, the identification and management of any actual or potential conflicts of interests should form part of the recruitment process. Do not do it only for senior or sensitive posts. Secondly a failure to properly manage

Read more
Privacy By Design and By Default

Privacy by design and by default is one of the GDPR's most important accountability requirements. Key Messages Privacy should not be an afterthought. Organisations should consider privacy before collecting or using personal data. Privacy by design and privacy by default apply to far more than technology projects. The concept is

Read more
Introduction to the GDPR: Key Concepts and Principles

The General Data Protection Regulation (GDPR) is a comprehensive legal framework that governs the collection, processing, and storage of personal data belonging to individuals within the European Union and the European Economic Area. Although the UK has left the European Union it has retained the GDPR as the UK GDPR.

Read more