The UKs #1 Data Protection Consultancy

Data Protection & Information Security Experts

Data Protection Made Easy.

GDPR Support Cyber Security Support
Join our extensive list of clients who have their data privacy under control

Accelerate Your Data Protection Compliance

Save Time, Save Money and Relax: You’re In Safe Hands

Discover the comprehensive range of data protection services at Data Protection People. Tailored to meet the unique needs of your organisation, our expert team has successfully handled every challenge imaginable. Whether you’re navigating compliance complexities or enhancing data security, trust DPP to be your partner in safeguarding information.

GDPR Training

Data Protection People have a wide range of training services catering for every need. Whether its general training for operational or admin staff or specific training for specialist roles, we have something for you. watch the short video below to meet the team and find out more about our training services.

Contact Us

Information Management Software

DataWise is the original privacy tech platform designed to simplify GDPR compliance management. Since its inception in 2011, DataWise has continuously evolved, solidifying its reputation as the pioneering "privacy tech" solution.

Contact Us

Data Protection Consultancy

Unlock Compliance Excellence with Our GDPR Consultancy Services. Navigating the intricate realm of data protection laws and standards demands expert guidance.

Contact Us

Outsourced DPO

A data protection officer doesn't have to be a full time employee and in many respects it's better to have a company like DPP take on the role. Watch the video below to find out more about our outsourced DPO and privacy officer services or reach out and get in touch with us.

Contact Us
View All

Need Help With Cyber Security Compliance?

We Have You Covered!

At Data Protection People, our cyber security services are designed to fortify your digital defences. With a proven track record spanning diverse sectors in the UK, our seasoned team brings a wealth of experience in handling a wide array of cybersecurity challenges. Reach out to us and explore how DPP can enhance your organisation’s cyber resilience.

PCI DSS Compliance Services for Merchants

A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.

Contact Us

PCI DSS Compliance Services for Service Providers

A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.

Contact Us

External Attack Surface Management

Our experts can support you with Dark Web Monitoring - Data Protection People offer a free dark web scan for your organisation.

Contact Us

ISO 27001

Our tailored program, guided by industry-certified experts, supports your ISO 27001 compliance journey. Whether you need advice on certification scope, assistance with remediation work, or comprehensive ISO 27001 consultancy, we’re here to guide you every step of the way.

Contact Us
View All
Rofi Hendra Support Desk Data Protection People

Supporting DPOs

Flexible Support When You Need It

At Data Protection People, we recognise the dynamic challenges and unique responsibilities of the Data Protection Officer (DPO) role. Beyond offering standard support, we provide a comprehensive suite of services crafted to empower DPOs at every step.

Collaborative Community: Navigating the intricate landscape of data protection can be isolating. That’s why we’ve fostered a collaborative community of privacy professionals. As a DPO with us, you’re never alone. Our network serves as a forum for insightful discussions, sharing solutions, and building a sense of camaraderie.

Expert Guidance and Advice: The journey of a DPO is often filled with complex decisions. Our seasoned team of experts is your reliable resource, offering timely advice and strategic guidance. We’re not just a service provider; we’re your dedicated partners in overcoming challenges and making informed decisions.

Advanced Training for Continuous Growth: Stay ahead in your role with our advanced training programs. Tailored for DPOs, our courses delve into intricate aspects of data protection, providing you with a competitive edge. It’s not just about meeting the present challenges but ensuring your continuous growth and excellence in your role.

Audits, Assessments, and Document Reviews: Our services extend beyond conventional boundaries. From comprehensive audits and assessments to meticulous document reviews, we ensure that your data protection strategies are not only compliant but also optimised for efficiency.

Simplifying Complexity for Future Ease: Beyond addressing current challenges, our mission is to simplify the complexities inherent in data protection. By partnering with Data Protection People, you’re not just solving problems – you’re ensuring a smoother, more efficient role in the future. We streamline processes, making your responsibilities more manageable and your decisions more impactful.

Diverse Sector Experience

Access to a Team of Industry Experts

At Data Protection People, our expertise spans across diverse sectors, ensuring that businesses of all sizes and orientations receive tailored Data Protection and Cyber Security solutions. From the dynamic commercial sector and agile SMEs to the impactful third sector and expansive multi-nationals, we extend our services to fortify the digital defences of every business entity.

Commercial Sector

Elevate your data protection and cybersecurity standards in the bustling landscape of the Commercial Sector. We offer tailored solutions designed to safeguard your sensitive information, ensuring compliance and resilience against evolving threats. Partner with us to fortify your digital assets and foster a secure environment for sustained growth.

SMEs

Small and Medium Enterprises (SMEs) form the backbone of innovation. Our data protection and cybersecurity services are crafted to match the agility of SMEs. Navigate the digital landscape securely, optimize your operations, and scale confidently with our tailored solutions that prioritize your unique business needs.

Third Sector

Third Sector

For organisations in the Third Sector driven by purpose, our data protection and cybersecurity expertise align with your mission. Safeguard sensitive data, build stakeholder trust, and amplify your positive impact. Let our solutions be the backbone of your technology infrastructure, ensuring that your focus remains on making a difference.

Multi Nationals

For the global footprint of Multi Nationals, our data protection and cybersecurity services provide a comprehensive shield. Navigate the complexities of international regulations with confidence. From compliance strategies to threat intelligence, we've got your data security needs covered, empowering your multinational endeavors with resilience.

Public Sector

In the Public Sector, trust and accountability are paramount. Our data protection and cybersecurity consultancy ensures that your operations align seamlessly with regulatory requirements. From confidential citizen data to streamlined governance, our solutions empower public entities to serve with integrity and technological excellence.

Why Use Our Outsourced DPO Services?

Save Time, Money and Guarantee Compliance

Navigating the intricate landscape of data protection demands more than just a DPO — it requires a dedicated team committed to excellence. Our Outsourced DPO Services extend beyond the traditional role, offering a comprehensive approach to legal compliance and pragmatic solutions.

Why Choose Outsourcing?

An outsourced DPO brings a wealth of experience, not just in the law but also in crafting workable solutions. Their impartiality is fortified by a team of privacy practitioners, ensuring that your organization benefits from a spectrum of expertise. Should the need arise, seamless coverage during absences is guaranteed, eliminating the vulnerability associated with a single in-house DPO.

Staying Headache-Free

Concerned about the disruption if your DPO moves on? With an outsourced model, transitions are smooth, and you won’t experience the sudden headache of a critical role vacancy. The continuity provided by a team ensures that your data protection responsibilities are seamlessly handled.

Compliance Tailored to You

Our Outsourced DPO Services align seamlessly with your legal obligations, whether you’re mandated to appoint a DPO or choose to do so voluntarily. We understand that compliance is not just about ticking boxes but about ensuring a robust, practical approach to data protection. Choose Data Protection People for a worry-free, compliance-driven outsourced DPO solution — because your data protection journey should be as smooth as it is secure.

“I cant recommend Data Protection People enough, they have helped me in so many different areas, no matter how complex the challenge or how large the obstacle, DPP always has the answer.

I can call the team at any time and have built an amazing relationship with them, in times of frustration they are here to calm me down and create a plan, they are a pleasure to work with.”

Mark Leete
Eastlight Community Homes
TDC_logo

‘I found the FOI training session to be highly informative and well-structured. It covered all the key areas comprehensively and provided clear, practical guidance throughout. The content was easy to follow, and the delivery by Gary was engaging, making complex topics accessible and understandable’. 

‘The training session has really helped me to understand the IG rep role a bit more and what I need to be thinking about when receiving a request for information’. 

Charlene Haynes & Team
Tendring District Council
dyslexia-action-logo-2023

“I have worked with the Data Protection People for some time now. Their expertise has been drawn upon to assist us with our GDPR compliance gap analysis project, ROPA design and production through to conducting objective reviews and surveys. They are always available to help us out and their advice and guidance is excellent and delivered in a timely way. Special mentions to Kathy Midgley, Phil Brining, and David Hendry. A great, reliable and dependable service!”

Judy Barker
Dyslexia Action
Veritau

“A great service and peace of mind. Data Protection People provides a well-rounded service to ensure customers are fully supported in their approach to GDPR compliance. My interaction has largely been with the following people: Kathy Midgley – another great asset to the organisation. Always approachable, always helpful and consistently supportive to the team and customers.

Julie Ferguson
Veritau
Woodgate & Clark

“We have been working with the Data Protection People for many years now, and have found them to be insightful, helpful, and knowledgeable in all areas of Data Protection Compliance. Data Protection People have taken the time to understand our business, the regulatory environment we sit under, and the unique challenges we face in the industry. They have supported us in all areas of Information and Data Security, assisting in assessments of our policies and changes to our processes. They are always willing to go the extra mile and prioritise support where required.”

Nia Roberts
Woodgate & Clarke

Data Protection People Blogs & Podcasts

Data Privacy Learning & Guidance

Data Protection People have the UK’s #1 Data Protection Podcast with over 150 episodes available across all audio streaming platforms, we also post regular content designed to simplify complex areas of data protection and cyber security, check out some of the podcasts and articles below and make data protection easy today.

The ICO’s New Focus: Training and Evidence for Compliance

The ICO’s New Focus: Training and Evidence for Compliance

Every organisation handling personal data today should ask itself: are our data protection practices truly up to the ICO’s current standards, or are we merely ticking boxes? The ICO has made it clear that policies alone do not equal compliance. Staff training, role-specific awareness, and regular refreshers play a critical role. Falling short can expose your organisation to reputational harm, regulatory risk, and loss of trust.

Why This Matters Now

Data protection has never been more in the spotlight. With increasing public awareness of data rights, stricter regulatory scrutiny, and emerging risks from technology (AI, cloud etc.), the ICO has sharpened its expectations. Organisations that rely on minimal compliance risk being exposed when the next audit or incident happens. The ICO’s updated guidance demands meaningful actions, not just a good looking policy document, especially when resources are tight or operations overlap in small teams.

What’s Changed / What’s New

The ICO has clarified several areas that often cause complacency. First, training must be tailored to each staff member’s role. A general GDPR overview is no longer sufficient. New starters must receive induction training that directly relates to their daily data-handling duties. Second, refresher or follow-up training is essential. It cannot be a one-off event. Organisations must test and evaluate staff understanding over time. Third, organisations must show evidence of effectiveness. This includes proof that training produces results: fewer errors, improved practice and proper handling of data in day-to-day operations.

Why It Matters for Data Protection

Data protection is more than legal compliance. It directly affects your reputation, risk exposure, and customer trust. When staff lack proper training, one small mistake, such as sending personal data to the wrong recipient, can escalate into a breach. UK GDPR demands accountability and transparency. The ICO’s Accountability Framework highlights that regulators will look for evidence of training, understanding, and relevant role-based responsibilities.

What You Should Be Doing Now

Begin by reviewing your training programmes. Ensure induction training clearly explains data protection obligations relevant to each role. For example, customer service, HR, marketing and IT staff should each understand how their work impacts personal data protection. Then, schedule regular refresher courses. Reinforce learning through quizzes, scenario-based exercises and real-world examples. Collect evidence: track training completion, gather feedback, measure error rates. Use that data to improve your training and show you are meeting ICO expectations.

Next, align your documentation and policies with actual practice. Your privacy notice, internal policies and procedures must reflect how your staff operate. Don’t rely on generic policies; ensure they match how data flows, who handles what and where risks are highest. Also ensure you have a plan for external support if you lack in-house expertise. Outsourced training or specialist consultants can help fill capability gaps.

Finally, audit your accountability: use internal or external assessments to test how well your team applies data protection in daily work. Simulate real incidents, review SAR responses, check for secure handling of data, and ensure clear ownership of responsibilities. Transparency internally supports compliance externally.

Our View / Final Thoughts

At Data Protection People we believe that the ICO’s updated expectations are both necessary and achievable. Policies and roles must align, training must be role-specific and ongoing, and evidence must accompany claims of compliance. Organisations that treat data protection as culture, not just a legal requirement, will protect themselves better. Habits of complacency cost more in the long run than investing in capable people and well-practiced processes.

FAQs

Is a one‐time GDPR training enough?

No. The ICO expects regular refreshers and assessments of understanding. A single session or generic e-learning does not meet their current standards.

Do all roles need customised training?

Yes. Different roles handle different data risks. Training must reflect daily tasks. IT, HR, marketing and frontline staff all need bespoke briefings.

What evidence should we keep to prove compliance?

Keep records of who attended training, when, the content used, test results or follow-ups, how errors reduced, and whether your staff applied learning in real work. Evidence must be clear and relevant.

When should we consider external support?

If you lack time, budget or internal knowledge, external consultants or trainers can provide up-to-date materials, role-based delivery, and measurable outcomes. This helps meet ICO expectations without overburdening teams.

Contact Us

If you’re not sure whether your training and data protection practices truly match what the ICO requires, our GDPR Audits service can evaluate and identify gaps. If you’d prefer hands-on help updating your staff training or policies, check out our Data Protection Training and Data Protection Support services. Let’s make sure you’re compliant, not complacent.

EDPS v SRB: What It Means for Subject Access Requests

EDPS v SRB and Pseudonymisation: What It Means for Subject Access Requests

The recent judgment in EDPS v SRB (Case C-413/23 P, EU:C:2025:645) changes how we think about personal data. The court confirmed that opinions and views are personal data when they relate to an individual. It also ruled that pseudonymisation does not always take data outside the law. If your organisation handles Subject Access Requests, you must reassess what you disclose and how you decide whether information is personal.

Why This Matters Now

Organisations rely heavily on pseudonymisation for data sharing and analytics. At the same time, more people are exercising their rights and submitting SARs. The Two Birds article “Can pseudonymisation make data anonymous” explains that removing identifiers does not guarantee anonymity. The CJEU confirmed this point. Pseudonymised data remains personal if you hold the key to re-identify. Only when re-identification is practically impossible can you treat it as anonymous. This ruling matters because it affects what you disclose, what you explain in privacy notices, and how you manage third-party sharing. Getting this wrong can lead to complaints and regulatory action.

What’s Changed

The judgment provides two clear answers. First, opinions and comments that relate to a person are personal data. You must treat them as such. Second, pseudonymised data stays within scope when you hold re-identification keys or other means to link it back. A recipient who cannot realistically re-identify may treat it as anonymous, but only after checking risk carefully. The Two Birds article stresses that true anonymity is rare. You must consider technology, cost, time, and available information. These factors can change over time, so reviews should be ongoing.

Impact on Data Protection and SARs

This case has a direct impact on Subject Access Requests. When a person asks for their data, you must include any opinions or feedback about them. You must also check pseudonymised data and disclose it if you can re-identify the subject. Your privacy notices must explain what happens to the data you collect, including sharing with third parties in pseudonymised form. Clear notices build trust and show compliance. You must also assess identifiability using real-world conditions, not theory. If re-identification is reasonably likely, treat the data as personal and respond to the SAR.

What You Should Do Now

Start by reviewing your SAR process. Make sure your teams treat opinions as personal data and include them in disclosures where no exemption applies. Map where you use pseudonymisation. Record who holds keys and how you control access. Update your privacy notices so people know when you share data and how you protect it. Train staff on assessing identifiability using practical tests. Keep a record of each decision where you exclude pseudonymised data from a SAR. When in doubt, disclose or seek advice. You can also run a GDPR audit to test your process and identify gaps. Data protection training helps teams apply the rules consistently and with confidence.

Our View

We welcome this judgment because it gives clarity. Opinions are clearly personal data, and pseudonymisation is not a free pass. The question is always whether you can identify the person, not what you call the dataset. We recommend a risk-based approach. Treat data as personal unless you have strong evidence that re-identification is not possible. Keep your privacy notices up to date and document your decisions. This approach will reduce risk, speed up SAR responses, and build trust with individuals.

FAQs

Are opinions always personal data for SARs?

Yes. If an opinion relates to a person you can identify, treat it as personal data and consider it for disclosure.

When can pseudonymised data be treated as anonymous?

Only when you cannot re-identify the data subject and re-identification is not reasonably likely in practice. You must be able to show your reasoning.

Do privacy notices need updating?

Yes. You must tell people if you share their data, including in pseudonymised form, and explain how you protect it.

What records should we keep when excluding data?

Keep a short note explaining the context, what re-identification methods exist, why you ruled out identifiability, and who approved the decision.

Contact Us

If you need help improving your SAR process or reviewing pseudonymisation risks, we can support you. Explore our GDPR Audits, Data Protection Training, Data Protection Support, or SAR Support services today.

EU Moves Towards Data Adequacy Agreement with Brazil

Brazil and the EU: One Step Closer to Free and Safe Data Flows

The European Commission has taken the first step towards adopting a data adequacy decision with Brazil. This move would enable the free flow of personal data between the EU and Brazil, offering major benefits for businesses, public authorities, and researchers operating across both regions.

Why This Matters

Brazil has been recognised by the Commission as offering an ‘adequate’ level of data protection, meaning its legal framework provides comparable safeguards to those set out under the EU’s General Data Protection Regulation (GDPR). Once formalised, this mutual recognition will remove barriers for data transfers between the EU and Brazil, creating one of the broadest adequacy frameworks to date.

A Step Toward Global Data Alignment

The decision aligns with the EU’s broader aim to strengthen ties with countries that uphold high standards of privacy and data protection. Brazil is a key international partner, with strong cultural and economic links to Europe. By recognising each other’s frameworks, both sides aim to reinforce consumer trust and digital trade.

Voices from the Commission

Henna Virkkunen, Executive Vice President for Tech Sovereignty, Security, and Democracy, commented: “In these uncertain times, we must work closer to our natural partners. Brazil is evidently one of them.” She added that the mutual adequacy decisions will help bring both economies closer together, benefiting over 670 million people.

Michael McGrath, Commissioner for Democracy, Justice, the Rule of Law and Consumer Protection, also welcomed the decision, highlighting Brazil’s robust legal framework for data privacy. He stated: “When personal data is protected, so too are consumer rights, ensuring individuals have control, transparency, and security in their interactions with businesses and services.”

What Happens Next?

The draft adequacy decision will now be reviewed by the European Data Protection Board (EDPB) and will need approval from EU member states. The European Parliament also retains the right to scrutinise the decision. Once this process is complete, the Commission can formally adopt the final adequacy decision.

Like other adequacy decisions, this one will be subject to periodic review to ensure it continues to offer a sufficient level of protection.

What This Means for You

This is great news for organisations involved in international operations with Brazil. It will simplify data flows, reduce the need for Standard Contractual Clauses or Transfer Impact Assessments, and enhance business agility across borders. It also sends a clear signal that robust privacy frameworks support, not hinder, global innovation and cooperation.

Frequently Asked Questions

What is a data adequacy decision?

A data adequacy decision is a ruling by the European Commission confirming that a non-EU country provides data protection that is essentially equivalent to the EU’s GDPR. It allows personal data to be transferred freely to that country without extra safeguards.

Why does the EU want a data adequacy agreement with Brazil?

Brazil has built a strong legal framework for protecting personal data, similar to the GDPR. The EU sees Brazil as a key economic and political partner, and mutual adequacy will simplify data transfers while maintaining high privacy standards.

How will this benefit UK businesses?

A similar decision will likely be adopted by the UK to grant an adequacy to Brazil, making it easier and faster for businesses to share personal data without needing Standard Contractual Clauses or other legal tools.

Is the EU–Brazil adequacy decision final yet?

No. The draft decision is currently under review by the European Data Protection Board, EU member states, and the European Parliament. It will become final once it passes through the formal adoption process.

Need help understanding how this impacts your organisation? Our consultancy team can support you in navigating international data transfers, assessing adequacy decisions, and updating your data transfer mechanisms. Contact us today to find out how we can help.

Updated PECR Guidance

Updated PECR Guidance: What You Need to Know

If your organisation uses cookies, tracking pixels, local storage or other tech that stores or accesses data on someone’s device, this update is for you. The ICO has released a refreshed draft of its guidance on the Privacy and Electronic Communications Regulations (PECR), following the Data (Use and Access) Act 2025. Here’s an easy-to-understand breakdown of what’s changed and what it means for you.

Why this update matters

This guidance explains how to stay compliant with PECR, particularly when using cookies and similar technologies. It now includes new chapters, better examples, and clearer expectations using the language of “must,” “should” and “could” to define compliance requirements.

It also reflects the changes introduced by the Data (Use and Access) Act 2025, including a new chapter on exceptions to the rules.

Key Changes You Need to Know

New: “What are the exceptions?”

A brand-new chapter explains the five exceptions to cookies that typically require the consent or similar technologies deployed on the website. This is vital for understanding when you may be exempt from needing consent.

Cookies do not require consent where they are used for:

  • Technical information for security, fraud detection, fault detection, authentication, recording user selection purposes
  • Website appearance and functionality
  • Collecting statistics for improvement to website service delivery
  • For providing emergency assistance

Updated: “What are storage and access technologies?”

This section now provides clearer explanations about the types of technologies PECR covers, beyond just cookies. It includes things like:

  • Tracking pixels
  • Local storage
  • Device fingerprinting
  • Scripts and tags
  • Link decoration

Clearer expectations for consent

A new chapter titled “How do we manage consent in practice?” includes updated examples of good and bad consent mechanisms and outlines what a compliant consent process looks like.

New focus: Online advertising

The new chapter on online advertising explains how PECR applies to targeted ads and audience profiling. This is a significant addition as the ICO has set clearer boundaries around tracking technologies used for ad purposes.

Refreshed enforcement chapter

The guidance reflects the evolving enforcement regime. If your organisation doesn’t follow the rules, expect increased scrutiny.

Minor updates throughout

The guidance also includes many small updates to existing chapters to align with changes in law and case law. These improve consistency and clarity.

Who should care about this update?

If you’re any of the following, this applies to you:

  • A website or app owner
  • A marketer using tracking tools
  • A developer working with analytics or ad platforms
  • A Data Protection Officer or compliance lead

Whether you use Google Analytics, embedded YouTube videos, chat widgets, or email marketing tools, you’re likely affected.

How to use the updated guidance

The ICO now uses three terms to guide your compliance:

  • Must = Legal requirement or binding case law
  • Should = Best practice we expect unless you have strong justification
  • Could = Optional methods or examples that can help you comply

This makes it easier to know what you have to do versus what is simply recommended.

Our take at DPP

This update is a step forward in clarifying how organisations should handle cookies and tracking. It brings PECR more in line with modern technology, while still focusing on protecting individual privacy.

We welcome the inclusion of practical examples and the clarification of consent expectations. However, the new rules also mean organisations can no longer rely on vague cookie banners or ignore tracking tools outside of traditional cookies.

FAQs: PECR & Cookies (Post-DUAA)

Do I still need consent for cookies after the DUAA?
Yes. Consent is still required unless one of the exceptions applies. 

What are the exceptions to the cookie rules?
You don’t need consent if the cookie is strictly necessary for a service explicitly requested by the user. The full list of five exceptions is detailed in the ICO guidance. 

Are analytics cookies exempt from consent?
No. Analytics cookies are not exempt and still require valid user consent. 

Can I use cookie walls to force users to consent?
Generally no. The ICO considers this practice to be non-compliant if users aren’t given a genuine choice. 

What’s changed for online advertising?
The ICO now expects clearer, more specific consent for targeting and profiling, with examples of good and bad practice. 

Does this guidance apply to mobile apps as well?
Yes. Any app storing or accessing data on a user’s device must follow PECR rules. 

What happens if we don’t comply?
You could face ICO enforcement, including audits, fines, or formal reprimands

Need help navigating PECR and cookies?

At Data Protection People, we help organisations:

  • Audit their tracking technologies
  • Redesign cookie consent mechanisms
  • Create compliant privacy and cookie policies

If you’re not sure whether your current approach is compliant, we’re here to support you.

Contact our consultancy team for help embedding these updates into your website, app or ad campaigns.

10 Years of Data Protection People

Celebrating 10 Years of Data Protection People & 5 Years of the Data Protection Made Easy Podcast

Last week we marked not one, but two major milestones, 10 years of Data Protection People and the 5th birthday of the Data Protection Made Easy Podcast. To celebrate, we hosted a special live session with Philip Brining, Caine Glancy, Catarina Santos, and returning host Joe Kirk. Together, we looked back at the Top 10 Most Streamed Episodes from the past five years, revisiting the conversations that have shaped our community.

Key Themes from the Session

  • Subject Access Requests (SARs) – still one of the most complex and frequently discussed areas of data protection.
  • Data Protection Impact Assessments (DPIAs) – exploring challenges around risk, practicality, and when a DPIA is truly needed.
  • Legislative Changes – including Brexit, the Data Protection and Digital Information Bill, and the new DUA Act.

The team also reflected on why topics like ROPA and audits don’t always feature as highly among listeners, and why broad themes resonate more strongly than sector-specific discussions.

Insights from Our Community

Our special guest Joe Kirk shared valuable insights from moving into an in-house DPO role, including the importance of tackling cookie compliance and ensuring correct ICO registration. The panel also discussed the ICO’s new guidance on complaints handling and recognised legitimate interests, highlighting the practical steps organisations should take ahead of expected implementation in June 2026.

The Return of Weekly Podcasts

To celebrate our 10-year anniversary and the continued growth of our community, we are excited to announce that the Data Protection Made Easy Podcast is returning to a weekly schedule. Every Friday at lunchtime, we’ll be live with fresh discussions, community insights, and practical guidance for data protection professionals.

You can sign up on our Events Page to join future live sessions, or contact us here to subscribe and become part of the UK’s biggest data protection community.

Listen Back to the Anniversary Episode

If you missed it live, you can catch up now on Spotify using the player below:

Here’s to 10 years of making data protection easier, and 5 years of building a community where professionals can learn, share, and grow together. Thank you to everyone who has been part of the journey so far.

Caught in the Act: The UK’s New Age Verification Law

Online Safety Act, age checks, and real world risks, highlights from Episode 218

Recorded on Friday 29 August 2025, this live episode of Data Protection Made Easy brings together Catarina Santos, Caine Glancy and Philip Brining to explain what the latest Online Safety Act changes mean in practice. The team walk through how age verification works, why VPN downloads have surged in the UK, and the real impact on privacy, user experience and compliance.

Episode: 218, Data Protection Made Easy
Recorded: late August, Leeds and online
Hosts: Philip Brining, Catarina Santos, Caine Glancy

We are Data Protection People, a consultancy and a community. More than 1,500 practitioners join our live sessions for practical help and straight talking advice. We keep things human, current, and useful.

Prefer Spotify in a new tab,
open the episode,
or browse the full show feed.

What we covered

  • Online Safety Act, where it fits with the Children’s Code, why it goes further on content and safety.
  • Age assurance, facial estimation, ID checks, open banking, and the privacy trade offs behind each approach.
  • Supply chain risk, real incidents in education and vetting, why processor controls and backups still fail.
  • Education, why literacy and resilience matter as much as technical gates.
  • Community update, weekly sessions return in September, likely in focused 30 minute formats.

Highlights and opinions

Scope and categories. Ofcom guidance gives the most usable overview. Scale drives duties, category one providers face the heaviest lift. Smaller services still need proportionate controls.

“The Act is about content, the Children’s Code is about design, together they set expectations for what people actually see and share.” — Philip

Age checks in practice. Facial estimation and ID checks can help, they are not perfect. People will try VPNs and workarounds, so policy and education must sit alongside technology.

“There is no magic potion for age checks, the solution cannot be technology alone.” — Catarina

“If suppliers rush controls without thinking about retention and purpose limitation, we move risk rather than reduce it.” — Caine

Supply chain failures. Contracts need clear migration and deletion steps, restore tests must be real, controller oversight must be active, not paper based.

“Where is the weak link, backups, migration steps, subprocessors, or the missing instructions in the DPA.” — Philip

Freedom of expression and harm. Public concern is real. The intent is to reduce harm to children, not silence debate. Practical application will need careful balancing.

Practical takeaways for organisations

  • Write a content risk assessment if your service can be accessed by children, update it on a schedule, record decisions.
  • Map processors and subprocessors, include precise steps for transfers and deletion, test restores, not only backups.
  • Choose proportionate age assurance, record lawful basis, retention, and vendor due diligence, avoid copying IDs unless necessary.
  • Blend controls with education, publish clear user guidance, support parents and teachers, avoid dark patterns.

About the community

Data Protection Made Easy is the live podcast and discussion space run by Data Protection People. More than 1,500 members join to share cases, templates, and practical steps. We will return to weekly sessions in September, short and focused, with time for questions.

Contribute to a future episode

We are always looking for contributors and topics, case studies, SAR puzzles, transfer questions, or views on the Online Safety Act. Get support or advice, or pitch a slot for an upcoming episode.

Explore more in our Resource Centre, including recent episodes and guides.

DUA Act – Part Two

The Data (Use and Access) Act 2025 – Podcast Part Two

On Thursday, 18th July 2025, we hosted Part Two of our DUA Act discussion, with over 200 live attendees joining us for a deeper dive into the Data (Use and Access) Act 2025.

Led by Phil Brining and Caine Glancy, this session focused on answering the questions raised in Part One, exploring complex scenarios, and sharing practical advice for professionals preparing for the new regulations.

If you couldn’t attend live or want to revisit the insights, you can now listen back to the full recording and access the presentation slides shared during the event.

Listen on Spotify

Click below to listen to Part Two on Spotify or search ‘Data Protection Made Easy’ on Apple Podcasts, Audible or any major platform.

Download the Slides

We’ve made the full slide deck from Part Two available to download and share:
Download Part Two Presentation Slides

What We Covered

  • Real-life scenarios and case study examples based on DUA Act principles
  • Detailed Q&A on legitimate interest balancing tests, soft opt-in rules, and data subject rights
  • Compliance challenges and how to overcome them using good governance frameworks
  • The DUA Act’s expected impact on privacy management programmes and internal policies
  • Preparing your teams, clients, and data flows for the changes ahead

Join the Data Protection Made Easy Community

By joining our free community, you’ll get:

  • Early access to upcoming podcast sessions and event invites
  • Weekly insights into legislation like the DUA Act and GDPR
  • Exclusive downloads including templates, tools, and guides
  • Invitations to in-person events across the UK
  • Access to session recordings and slides
  • A place to ask questions, share experiences, and stay ahead

We’re here to help you transition confidently into the new data protection landscape, making compliance clearer, simpler, and more achievable.

The Data (Use and Access) Act 2025

The Data (Use and Access) Act 2025 – Podcast Part One Recap

On Friday, 28th June 2025, we hosted our biggest podcast session ever, with 295 live attendees joining us to explore the Data (Use and Access) Act 2025.

Hosted by Phil Brining, Caine Glancy, and Catarina Santos, the session provided a clear and practical breakdown of the most significant changes to UK data protection law since the GDPR.

Whether you missed it live or want to listen again, you can catch the full episode now and download the slide deck shared during the session.

Listen back on Spotify

Click below to listen to the episode via Spotify or find us on Apple Podcasts, Audible and all major streaming platforms.

Download the Slides

We’ve made the full slide deck from the session available to download and share:
Download Presentation Slides

What We Covered

  • What the DUA Act is and how it evolved from the DPDI Bill
  • Key changes to Subject Access Requests, Legitimate Interests, and the role of the ICO
  • Updates to PECR enforcement powers and cookie consent exemptions
  • The Act’s impact on data sharing, organisational accountability, and regulatory expectations
  • What public and private sector organisations need to prepare for

Part Two – Live on Thursday 18th July

Due to overwhelming demand and brilliant questions from our community, Part Two is already confirmed. In this follow-up session, we’ll dig deeper into unanswered questions, explore real-world scenarios, and share practical next steps for compliance and governance.

Click here to visit the Part Two event page and register your place: View Part Two

Join the Data Protection Made Easy Community

By joining our free community, you’ll get:

  • Early access to future podcast sessions
  • Weekly email updates with analysis and guidance on the DUA Act
  • Exclusive content including white papers, practical templates, and checklists
  • Invites to free in-person events across the UK
  • Recordings and slides from every live session
  • A chance to ask questions and share challenges with other professionals

We’re committed to supporting our community through the transition to the DUA Act and beyond, making compliance simpler, clearer, and easier to manage.

Our Events & Webinars

Industry Leading Discussions

We host events on a weekly basis for the community of data protection practitioners and have built up a network of over 1200 subscribers, who tune in each week to listen to discussions about the hot topics from the fast-paced and evolving world of data protection and cyber security. Check out our upcoming events and become part of our growing community.

View All
19 September 25 12:30 - 1:00 pm

GDPR Radio Returns

Celebrating 10-Years of Data Protection People
12 September 25 12:30 - 1:30 pm

Celebrating 10 Years of Data Protection People

Get Support With Data Protection And Cyber Security

Our mission is to make data protection and cyber security easy: easy to understand and easy to do. We do that through the mantra of benchmark, improve, maintain.