Introduction to Risk Management

Any introduction to risk management must recognise risk is an inherent part of everyday life. Individuals, organisations, and governments all make decisions in uncertain environments where outcomes cannot be guaranteed. Whether launching a new product, investing money, managing staff, or implementing new technology, there is always the possibility that things

Read more
Case Study: Perceived Conflicts of Interests

Perceived conflicts of interests can be uniquely challenging. However, as recent events show (in the sense of how not to do it), there are ways of managing and potential issues.   ________________________________________________________________________________________________ [su_box title="About the Author" box_color="#020a4a"]Michael has over 15 years experience supporting, developing and improving effective conflicts of interests

Read more
Inappropriate Access is a Data Breach

People often labour under the impression that a data breach is some form of external malicious action or an IT or technical failure exposing people’s data. In fact a data breach under the GDPR is much broader than that. Article 4(12) of the GDPR defines it as: a breach of

Read more
Freedom of Information Flowchart

Navigating the steps of freedom of information requests can be complex. Considering requests, seeking clarification and applying exemptions is a normal part of obtaining and sharing data. It can, however be difficult to get everything right when dealing with a large volume of requests or when requests are complex. That's

Read more
The Role of NEDs and Trustees in the Management of Conflicts of Interests

Non-executive directors (NEDs) and charity trustees have a key role in supporting and assuring the identification and management of conflicts of interests in their organisation. The focus should not be on declaring and managing their own interests and conflicts of interests (although that is part of it). Their focus should

Read more
Data Privacy is Good for Business

Fascinating research by Moffat et. al. on Customer Data Privacy Stewardship (July 2025, Journal of Marketing) set out compelling evidence that data privacy practices are not just a compliance activity. They can also generate meaningful business growth. The paper highlights that putting in place privacy systems both increases costs and

Read more
Freedom of Information Policy: Free Template

The Freedom of Information Act 2000 (FOIA) places clear obligations on public authorities to provide access to recorded information, and with those obligations comes the need for consistency, clarity, and control. This is where a well-designed Freedom of Information (FOI) policy becomes indispensable. Without one, organisations risk delays, inconsistency, and

Read more
Does it Matter if you Breach Timescales for SARs?

Subject Access Requests, or SARs, are the most commonly used GDOR right that people have. They can place a material burden on organisations and therefore it is not uncommon for deadlines or information to be missed. However, even missing the deadline is itself a breach of GDPR, regardless of whether

Read more
Freedom of Information Request Tracker

For any public authority or organisation subject to the Freedom of Information Act 2000, receiving a request can feel like a disruption to the "real" work. However, treating FOI requests as an afterthought is risky because of your statutory duties and the role FOI has in building openness and trust.

Read more
Data Retention: Why Organisations Might Keep Personal Data

Data retention and disposal are key elements of data flows. As part of this retention schedules and Records of Processing Activities (RoPAs) are essential tools for GDPR compliance. They set out how long personal data should be kept and when it should be deleted. In principle, this supports the storage

Read more
Staff Data and Freedom of Information

What Staff Data Can Be Disclosed Under the UK Freedom of Information Act? Many public sector organisations struggle when people make freedom of information requests  that involve information about staff and other workers. There is no automatic exemption for personal data about anyone other than the requestor under FOI. Therefore

Read more
Fairness is Not the Same as Nice

When it comes to the GDPR fairness is not the same as nice. The first data protection principle of the UK GDPR requires that personal data is processed lawfully, fairly, and transparently. These three elements are closely connected, but each carries its own weight. Of the three, fairness is often

Read more