Personal Data and Programme Management

One of the main reasons programmes that involve personal data become delayed or go over budget is because there hasn't been proper planning for handling personal data as part of the programme design. Often, organisations will plan their timelines around technical or organisational changes. But, they will not necessarily consider

Read more
Identifying Records for Preservation

Identifying Records for Preservation: A Practical Guide for Organisations Information is created at unprecedented scale, so organisations face a paradox. On one hand, they must retain certain records for legal, operational, or historical reasons. On the other, they must avoid excessive retention that increases risk, cost, and complexity. The ability

Read more
An Introduction to Clinical Governance

Understanding Clinical Governance: How It Differs from Corporate and Information Governance In complex organisations—particularly within healthcare—governance is not a single concept but a constellation of interrelated disciplines. Among these, clinical governance, corporate governance, and information governance each play distinct yet complementary roles. Understanding their differences is essential for ensuring accountability,

Read more
Data Breach and Reputation

When organisations think about the consequences of a data breach the first thing that usually comes to mind is not reputation, but financial penalties. Headlines about multi-million pound fines issued by regulators can create the impression that the biggest risk is monetary. In reality, the reputational damage caused by a

Read more
When GDPR Does Not Apply

What is the scope of the GDPR? The UK GDPR is often described as a comprehensive framework governing the use of personal data. However, it is important to recognise that not everything people consider personal data falls within its scope. One key question for GDPR compliance is whether the GDPR

Read more
The Fraud Triangle and Conflicts of Interests

________________________________________________________________________________________________ [su_box title="About the Author" box_color="#020a4a"]Michael has over 15 years experience supporting, developing and improving effective conflicts of interests systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star

Read more
Knowingly or Recklessly Obtaining Personal Data

We were working with a client recently to support data protection and a contract we were asked to review read that if the other party received personal data they should from our client they would keep it and use it. We flagged this up as inappropriate partly because it could

Read more
Policies Procedures and SOPs

  Understanding the Hierarchy of Policies, Procedures, and SOPs     Organisations run on clarity. When expectations are clear, decisions are consistent, and processes are repeatable, performance improves. But many teams confuse policies, procedures, and standard operating procedures (SOPs) — using the terms interchangeably when they actually serve very different

Read more
What is Data Processing?

What Is — and Is Not — “Data Processing” Under the UK GDPR? One of the most misunderstood aspects of the UK GDPR is the breadth of “data processing.” Many organisations assume it only refers to complex data analytics or IT-driven activity. In reality, the definition is far wider. If

Read more
Multi Purpose DPIAs – one DPIA to rule them all

A Data Protection Impact Assessment (DPIA) doesn’t always need to focus on a single, isolated processing activity. In many organisations—especially those with interconnected systems and overlapping workflows—it makes sense to complete one DPIA that covers multiple related processing activities, provided it remains clear, usable, and defensible. Done properly, a “multi-activity

Read more
Writing Your Employee Privacy Notice

What Employers Must Include in an Employee Privacy Notice (Worker-Facing Privacy Statement) to Be GDPR Compliant An employee privacy notice (sometimes called a privacy statement or privacy policy) sets out how an employer collects, uses, stores, and shares personal data about its workforce. Under the UK GDPR, this notice plays

Read more
GDPR for HR: Lawful Bases for Employee Data Processing

GDPR Basics for HR: why is it important to understand the lawful bases for employee data processing? Employee data is core to HR functions. This is true before, during, and after employment. For example, during recruitment, for payroll, absence management, performance reviews, learning and development, safeguarding, workplace investigations, references and

Read more