GDPR

Legitimate Interests as a Lawful Basis for GDPR

When can an organisation process personal data because it is in its legitimate interests, and how does it demonstrate that those interests do not override people's rights? Legitimate interests is one of the lawful bases available under Article 6. It can be flexible, but that does not make it a

Read more
Responding to Subject Access Requests: A Step By Step Guide

Subject Access Requests can present a significant burden on organisations. They are the most frequently exercised GDPR right and organisations need a clear process to handle subject access requests. This ensures they meet their statutory duties under the Data Protection Act and can cope with the work involved. The risks

Read more
Consent and GDPR: processing data lawfully

Consent is one of the lawful bases for sharing data under GDPR but it is only one – and suitable for only limited situations. Here we discuss when it does, and does not, work.

Read more
The Lawful Bases for Processing Personal Data Under the UK GDPR

Every organisation that processes personal data must understand the lawful bases for processing personal data. Under the UK GDPR, these reasons are known as the lawful bases for processing. Choosing the correct lawful basis is an important part of data protection compliance. It affects whether you can process personal data

Read more
The Principle of Accountability

The Principle of Accountability means organisations cannot simply claim to comply with the GDPR. They must be able to demonstrate that compliance through policies, records, governance arrangements and day-to-day practices. This is the purpose of the accountability principle. It requires organisations to take responsibility for protecting personal data and to

Read more
Integrity and Confidentiality: The Sixth GDPR Principle

Every organisation that processes personal data has a responsibility to protect it. Whether information is stored electronically, on paper or shared verbally, individuals expect it to remain accurate, available when needed and protected against unauthorised access, loss or misuse. The GDPR's integrity and confidentiality principle establishes the security and governance

Read more
Storage Limitation: GDPR Privacy Principles

Storage limitation matters because every item of personal data has a lifecycle. Information is collected, used, shared and eventually reaches a point where it is no longer needed. The GDPR recognises that retaining personal data indefinitely increases privacy risks, creates unnecessary costs and undermines public trust. The storage limitation principle

Read more
Data Accuracy: The Fourth GDPR Privacy Principle

Data accuracy - keeping accurate personal data are essential for lawful, fair and effective data processing and decision making. The Accuracy Principle is often overlooked because it appears deceptively simple. Many organisations reduce it to "keep records up to date." In reality, it is about ensuring that decisions are based

Read more
Data Minimisation: The Third GDPR Privacy Principle

Data minimisation is the third of the seven core principles of the UK GDPR. It requires organisations to collect, use, share and retain only the personal data that are adequate, relevant and limited to what is necessary for the purposes for which they are processed. At first glance, this may

Read more
Purpose Limitation: The Second GDPR Privacy Principle

Purpose limitation is one of the seven core principles of the General Data Protection Regulation (GDPR). It requires organisations to be clear about why they need personal data before they collect it and to ensure that information is not used in ways that are incompatible with those original purposes. The

Read more
GDPR Privacy Principles: Lawful, Fair and Transparent

Article 5(1)a of the GDPR is simple. It sets out the first of the GDPR privacy principles: “personal data shall be processed in a lawful, fair and transparent manner in relation to the data subject”. These means the GDPR requires organisations to process personal data lawfully, fairly, and transparently. These

Read more
Data Privacy Principles: What They Are and What They Mean

Article 5 of the GDPR introduces the seven core privacy principles on which GDPR compliant data processing rests. The principles apply to all personal data processing and most GDPR obligations flow from them. Because of this compliance is easier when organisations understand the principles rather than focusing only on individual

Read more