GDPR

Pseudonymisation and Personal Data: a How to Guide

Pseudonymisation is a vital tool in the data protection arsenal, particularly in light of regulations such as the General Data Protection Regulation (GDPR). By reducing the link between personal data and the individual, it helps organisations process data securely while maintaining compliance. This guide provides a step-by-step approach to pseudonymising

Read more
GDPR and ISO 27001: Working Together for Data Protection

GDPR and ISO 27001 are frameworks that together ensure robust data protection. ISO 27001 is an internationally recognised standard for information security, and the General Data Protection Regulation (GDPR), a broad set of rules designed to safeguard personal data across the UK and the European Economic Area. Together, these frameworks

Read more
The Computer Misuse Act and GDPR

The Computer Misuse Act 1990 is one of the first, and most important, examples of cybersecurity legislation in the UK. It was introduced in response to the growing threat of cybercrime and was designed to address unauthorised access to computer systems and data. At its core, the legislation seeks to

Read more
Data Controllers and Data Processors under the GDPR

Data controllers and data processors are key roles under the General Data Protection Regulation (GDPR). The GDPR assigns responsibilities to people involved in handling personal data and data controllers and data processors determine how personal information is handled, protected, and shared. Understanding these roles is not just a matter of

Read more
Special Category Data under the GDPR

The General Data Protection Regulation (GDPR) distinguishes special category data from regular personal data due to its highly sensitive nature. This category includes information revealing: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic and biometric data, health data, data concerning a person’s sex life

Read more
Penalties for GDPR Breaches

The consequences of GDPR breaches can be both legal and civil, and apply to both businesses and individuals. There can also be reputational and operational consequences from a data breach as well as financial penalties. In this article we will explore what those consequences are and how to avoid them.

Read more
The Common Law Duty of Confidentiality

The Common Law Duty of Confidentiality is a key principle that underpins trust in many professional and personal relationships. It serves as a crucial element in maintaining discretion and privacy across various sectors. Therefore it ensures that sensitive information is not misused or improperly disclosed. In essence, the duty of

Read more
Key Performance Indicators for the GDPR

The General Data Protection Regulation (GDPR) is the foundation of data privacy legislation in the UK and the EU. Since its implementation in 2018, it has shaped how businesses handle personal data. One of the most effective ways to ensure consistent compliance is by using Key Performance Indicators (KPIs). KPIs provide

Read more
The Right to Object and Direct Marketing

As businesses increasingly rely on data to tailor their marketing efforts, the protection of this information has become paramount. The General Data Protection Regulation (GDPR) is at the forefront of these efforts, placing a strong emphasis on individual rights. Among these rights, the right to object to the use of

Read more
Pseudonymising Personal Data

Pseudonymising personal data is way of enhancing privacy and complying with the GDPR. It means taking the identifiable information within a dataset and replacing it with artificial identifiers or pseudonyms. Unlike anonymisation, pseudonymisation allows you to re-identify the data subject if necessary, making it a very useful tool in processing

Read more
Facial Recognition Technology

Facial recognition is an example of personal data processing and is covered by the GDPR. The General Data Protection Regulations (GDPR) stands as a robust framework protecting personal data both in the UK and across Europe. One of the ideas behind the GDPR was to make it forward looking. Who

Read more
GDPR and children: what are the rules?

When is comes to the GDPR and children - of children's data to be exact - special care must be taken. What's the best way to handle children's data? It has always been, in information governance both pre- and post-GDPR, one of the weakest areas of knowledge. In terms of

Read more