GDPR

Privacy By Design and By Default

Privacy by design and by default is one of the GDPR's most important accountability requirements. Key Messages Privacy should not be an afterthought. Organisations should consider privacy before collecting or using personal data. Privacy by design and privacy by default apply to far more than technology projects. The concept is

Read more
Introduction to the GDPR: Key Concepts and Principles

The General Data Protection Regulation (GDPR) is a comprehensive legal framework that governs the collection, processing, and storage of personal data belonging to individuals within the European Union and the European Economic Area. Although the UK has left the European Union it has retained the GDPR as the UK GDPR.

Read more
Inappropriate Access is a Data Breach

People often labour under the impression that a data breach is some form of external malicious action or an IT or technical failure exposing people’s data. In fact a data breach under the GDPR is much broader than that. Article 4(12) of the GDPR defines it as: a breach of

Read more
Data Privacy is Good for Business

Fascinating research by Moffat et. al. on Customer Data Privacy Stewardship (July 2025, Journal of Marketing) set out compelling evidence that data privacy practices are not just a compliance activity. They can also generate meaningful business growth. The paper highlights that putting in place privacy systems both increases costs and

Read more
Does it Matter if you Breach Timescales for SARs?

Subject Access Requests, or SARs, are the most commonly used GDOR right that people have. They can place a material burden on organisations and therefore it is not uncommon for deadlines or information to be missed. However, even missing the deadline is itself a breach of GDPR, regardless of whether

Read more
Data Retention: Why Organisations Might Keep Personal Data

Data retention and disposal are key elements of data flows. As part of this retention schedules and Records of Processing Activities (RoPAs) are essential tools for GDPR compliance. They set out how long personal data should be kept and when it should be deleted. In principle, this supports the storage

Read more
Fairness is Not the Same as Nice

When it comes to the GDPR fairness is not the same as nice. The first data protection principle of the UK GDPR requires that personal data is processed lawfully, fairly, and transparently. These three elements are closely connected, but each carries its own weight. Of the three, fairness is often

Read more
Personal Data and Programme Management

One of the main reasons programmes that involve personal data become delayed or go over budget is because there hasn't been proper planning for handling personal data as part of the programme design. Often, organisations will plan their timelines around technical or organisational changes. But, they will not necessarily consider

Read more
Data Breach and Reputation

When organisations think about the consequences of a data breach the first thing that usually comes to mind is not reputation, but financial penalties. Headlines about multi-million pound fines issued by regulators can create the impression that the biggest risk is monetary. In reality, the reputational damage caused by a

Read more
When GDPR Does Not Apply

What is the scope of the GDPR? The UK GDPR is often described as a comprehensive framework governing the use of personal data. However, it is important to recognise that not everything people consider personal data falls within its scope. One key question for GDPR compliance is whether the GDPR

Read more
Knowingly or Recklessly Obtaining Personal Data

We were working with a client recently to support data protection and a contract we were asked to review read that if the other party received personal data they should from our client they would keep it and use it. We flagged this up as inappropriate partly because it could

Read more
What is Data Processing?

What Is — and Is Not — “Data Processing” Under the UK GDPR? One of the most misunderstood aspects of the UK GDPR is the breadth of “data processing.” Many organisations assume it only refers to complex data analytics or IT-driven activity. In reality, the definition is far wider. If

Read more