The UKs #1 Data Protection Consultancy

Data Protection & Information Security Experts

Data Protection Made Easy.

GDPR Support Cyber Security Support
Cate and Jas Chatting
Join our extensive list of clients who have their data privacy under control

Accelerate Your Data Protection Compliance

Save Time, Save Money and Relax: You’re In Safe Hands

Discover the comprehensive range of data protection services at Data Protection People. Tailored to meet the unique needs of your organisation, our expert team has successfully handled every challenge imaginable. Whether you’re navigating compliance complexities or enhancing data security, trust DPP to be your partner in safeguarding information.

GDPR Training

Data Protection People have a wide range of training services catering for every need. Whether its general training for operational or admin staff or specific training for specialist roles, we have something for you. watch the short video below to meet the team and find out more about our training services.

Contact Us

Information Management Software

DataWise is the original privacy tech platform designed to simplify GDPR compliance management. Since its inception in 2011, DataWise has continuously evolved, solidifying its reputation as the pioneering "privacy tech" solution.

Contact Us

Data Protection Consultancy

Unlock Compliance Excellence with Our GDPR Consultancy Services. Navigating the intricate realm of data protection laws and standards demands expert guidance.

Contact Us

Outsourced DPO

A data protection officer doesn't have to be a full time employee and in many respects it's better to have a company like DPP take on the role. Watch the video below to find out more about our outsourced DPO and privacy officer services or reach out and get in touch with us.

Contact Us
View All

Need Help With Cyber Security Compliance?

We Have You Covered!

At Data Protection People, our cyber security services are designed to fortify your digital defences. With a proven track record spanning diverse sectors in the UK, our seasoned team brings a wealth of experience in handling a wide array of cybersecurity challenges. Reach out to us and explore how DPP can enhance your organisation’s cyber resilience.

PCI DSS Compliance Services for Merchants

A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.

Contact Us

PCI DSS Compliance Services for Service Providers

A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.

Contact Us

External Attack Surface Management

Our experts can support you with Dark Web Monitoring - Data Protection People offer a free dark web scan for your organisation.

Contact Us

ISO 27001

Our tailored program, guided by industry-certified experts, supports your ISO 27001 compliance journey. Whether you need advice on certification scope, assistance with remediation work, or comprehensive ISO 27001 consultancy, we’re here to guide you every step of the way.

Contact Us
View All
Rofi Hendra Support Desk Data Protection People

Supporting DPOs

Flexible Support When You Need It

At Data Protection People, we recognise the dynamic challenges and unique responsibilities of the Data Protection Officer (DPO) role. Beyond offering standard support, we provide a comprehensive suite of services crafted to empower DPOs at every step.

Collaborative Community: Navigating the intricate landscape of data protection can be isolating. That’s why we’ve fostered a collaborative community of privacy professionals. As a DPO with us, you’re never alone. Our network serves as a forum for insightful discussions, sharing solutions, and building a sense of camaraderie.

Expert Guidance and Advice: The journey of a DPO is often filled with complex decisions. Our seasoned team of experts is your reliable resource, offering timely advice and strategic guidance. We’re not just a service provider; we’re your dedicated partners in overcoming challenges and making informed decisions.

Advanced Training for Continuous Growth: Stay ahead in your role with our advanced training programs. Tailored for DPOs, our courses delve into intricate aspects of data protection, providing you with a competitive edge. It’s not just about meeting the present challenges but ensuring your continuous growth and excellence in your role.

Audits, Assessments, and Document Reviews: Our services extend beyond conventional boundaries. From comprehensive audits and assessments to meticulous document reviews, we ensure that your data protection strategies are not only compliant but also optimised for efficiency.

Simplifying Complexity for Future Ease: Beyond addressing current challenges, our mission is to simplify the complexities inherent in data protection. By partnering with Data Protection People, you’re not just solving problems – you’re ensuring a smoother, more efficient role in the future. We streamline processes, making your responsibilities more manageable and your decisions more impactful.

Diverse Sector Experience

Access to a Team of Industry Experts

At Data Protection People, our expertise spans across diverse sectors, ensuring that businesses of all sizes and orientations receive tailored Data Protection and Cyber Security solutions. From the dynamic commercial sector and agile SMEs to the impactful third sector and expansive multi-nationals, we extend our services to fortify the digital defences of every business entity.

Skyline vertical

Commercial Sector

Elevate your data protection and cybersecurity standards in the bustling landscape of the Commercial Sector. We offer tailored solutions designed to safeguard your sensitive information, ensuring compliance and resilience against evolving threats. Partner with us to fortify your digital assets and foster a secure environment for sustained growth.

Card DPP Payment

SMEs

Small and Medium Enterprises (SMEs) form the backbone of innovation. Our data protection and cybersecurity services are crafted to match the agility of SMEs. Navigate the digital landscape securely, optimize your operations, and scale confidently with our tailored solutions that prioritize your unique business needs.

Third Sector

Third Sector

For organisations in the Third Sector driven by purpose, our data protection and cybersecurity expertise align with your mission. Safeguard sensitive data, build stakeholder trust, and amplify your positive impact. Let our solutions be the backbone of your technology infrastructure, ensuring that your focus remains on making a difference.

Boat in water

Multi Nationals

For the global footprint of Multi Nationals, our data protection and cybersecurity services provide a comprehensive shield. Navigate the complexities of international regulations with confidence. From compliance strategies to threat intelligence, we've got your data security needs covered, empowering your multinational endeavors with resilience.

Certification in cyber

Public Sector

In the Public Sector, trust and accountability are paramount. Our data protection and cybersecurity consultancy ensures that your operations align seamlessly with regulatory requirements. From confidential citizen data to streamlined governance, our solutions empower public entities to serve with integrity and technological excellence.

Rob Wilkinson answering a call

Why Use Our Outsourced DPO Services?

Save Time, Money and Guarantee Compliance

Navigating the intricate landscape of data protection demands more than just a DPO — it requires a dedicated team committed to excellence. Our Outsourced DPO Services extend beyond the traditional role, offering a comprehensive approach to legal compliance and pragmatic solutions.

Why Choose Outsourcing?

An outsourced DPO brings a wealth of experience, not just in the law but also in crafting workable solutions. Their impartiality is fortified by a team of privacy practitioners, ensuring that your organization benefits from a spectrum of expertise. Should the need arise, seamless coverage during absences is guaranteed, eliminating the vulnerability associated with a single in-house DPO.

Staying Headache-Free

Concerned about the disruption if your DPO moves on? With an outsourced model, transitions are smooth, and you won’t experience the sudden headache of a critical role vacancy. The continuity provided by a team ensures that your data protection responsibilities are seamlessly handled.

Compliance Tailored to You

Our Outsourced DPO Services align seamlessly with your legal obligations, whether you’re mandated to appoint a DPO or choose to do so voluntarily. We understand that compliance is not just about ticking boxes but about ensuring a robust, practical approach to data protection. Choose Data Protection People for a worry-free, compliance-driven outsourced DPO solution — because your data protection journey should be as smooth as it is secure.

eastlight housing

“I cant recommend Data Protection People enough, they have helped me in so many different areas, no matter how complex the challenge or how large the obstacle, DPP always has the answer.

I can call the team at any time and have built an amazing relationship with them, in times of frustration they are here to calm me down and create a plan, they are a pleasure to work with.”

Mark Leete
Eastlight Community Homes
TDC_logo

‘I found the FOI training session to be highly informative and well-structured. It covered all the key areas comprehensively and provided clear, practical guidance throughout. The content was easy to follow, and the delivery by Gary was engaging, making complex topics accessible and understandable’. 

‘The training session has really helped me to understand the IG rep role a bit more and what I need to be thinking about when receiving a request for information’. 

Charlene Haynes & Team
Tendring District Council
dyslexia-action-logo-client

“I have worked with the Data Protection People for some time now. Their expertise has been drawn upon to assist us with our GDPR compliance gap analysis project, ROPA design and production through to conducting objective reviews and surveys. They are always available to help us out and their advice and guidance is excellent and delivered in a timely way. Special mentions to Kathy Midgley, Phil Brining, and David Hendry. A great, reliable and dependable service!”

Judy Barker
Dyslexia Action
Veritau client

“A great service and peace of mind. Data Protection People provides a well-rounded service to ensure customers are fully supported in their approach to GDPR compliance. My interaction has largely been with the following people: Kathy Midgley – another great asset to the organisation. Always approachable, always helpful and consistently supportive to the team and customers.

Julie Ferguson
Veritau
Woodgate & Clark

“We have been working with the Data Protection People for many years now, and have found them to be insightful, helpful, and knowledgeable in all areas of Data Protection Compliance. Data Protection People have taken the time to understand our business, the regulatory environment we sit under, and the unique challenges we face in the industry. They have supported us in all areas of Information and Data Security, assisting in assessments of our policies and changes to our processes. They are always willing to go the extra mile and prioritise support where required.”

Nia Roberts
Woodgate & Clarke

Data Protection People Blogs & Podcasts

Data Privacy Learning & Guidance

Data Protection People have the UK’s #1 Data Protection Podcast with over 250 episodes available across all audio streaming platforms, we also post regular content designed to simplify complex areas of data protection and cyber security, check out some of the podcasts and articles below and make data protection easy today.

When Two Rulebooks Collide: Data Protection and Financial Crime Regulation

When Two Rulebooks Collide: Data Protection and Financial Crime Regulation

Financial services firms are often expected to do two things at once: know more about their customers and collect less data about them.

This is the practical tension between financial crime regulation and data protection law. Both carry serious regulatory consequences, but they ask different questions of the same customer record.

Financial crime rules focus on whether a firm knows enough to identify and manage risk. Data protection law asks whether each item of personal data is necessary, lawful, secure and retained for no longer than needed.

The challenge affects customer onboarding, transaction monitoring, retention, technology, supplier management and the evidence a firm can produce when challenged. Firms that treat data protection and financial crime compliance as separate workstreams often only address the overlap when something goes wrong.

The Core Challenge

The practical question is whether a firm can show that each item of customer data has a defined regulatory purpose, a proportionate risk trigger, a controlled access route and a clear retention outcome.

This means considering where the two regimes overlap and where they create tension, particularly around collection, retention, outsourcing, governance and emerging technology.

Collection: Need to Know vs Just in Case

The first point of friction is collection.

The Money Laundering Regulations 2017 require customer due diligence and, in higher-risk situations, enhanced due diligence. In practice, this can mean collecting detailed information about source of funds, source of wealth, beneficial ownership, corporate structures and transaction behaviour.

At the same time, the UK GDPR requires organisations to collect personal data that is adequate, relevant and limited to what is necessary. This is known as data minimisation.

Data minimisation does not mean collecting as little information as possible in every situation. It means being able to explain why each data point is needed for a defined purpose.

Problems arise when firms collect more information simply because they can, or because teams are worried about getting anti-money laundering requirements wrong. This can lead to data being collected just in case without a clear risk-based reason.

A stronger approach is to apply the risk-based logic already built into the Money Laundering Regulations. Enhanced information gathering should be linked to a genuine, documented risk trigger. Standard-risk customers should not automatically be subject to the same level of collection.

For each category of data, firms should be able to explain:

  • Which legal or regulatory obligation supports collection
  • What risk factor triggered the request
  • Who can access the information
  • When the need for the information will be reviewed

Retention: Delete Less, Delete More

Retention is another area where financial crime obligations and data protection expectations can appear to conflict.

The UK GDPR requires personal data to be kept in an identifiable form for no longer than necessary. However, the Money Laundering Regulations require relevant records to be retained for five years after the end of a business relationship or the completion of an occasional transaction, subject to the detailed requirements of the Regulations.

This does not mean anti-money laundering obligations automatically override data protection law. It means firms need a precise retention analysis.

The lawful basis for retaining anti-money laundering records will often be compliance with a legal obligation under Article 6(1)(c) UK GDPR. However, a robust retention schedule should distinguish between different record types, including:

  • Customer identification records
  • Verification evidence
  • Risk assessments
  • Transaction monitoring alerts
  • Suspicious activity escalation material
  • Sanctions screening results
  • Call recordings
  • Suitability files and advice records

Each category may have a different legal basis, retention trigger and deletion point. Some records may need to be retained because anti-money laundering law requires it. Others may be retained because FCA rules, limitation periods or advice obligations apply. Others should be deleted, anonymised or access-restricted once their purpose has expired.

Delete records too early and the firm may be unable to evidence adequate due diligence or monitoring. Keep everything indefinitely and the firm risks unlawful over-retention, greater breach impact and weaker accountability.

Outsourcing, Suppliers and Operational Resilience

A single supplier can create several overlapping compliance requirements.

A cloud provider, KYC screening tool, transaction monitoring platform or credit reference relationship may require an Article 28 processor assessment, international transfer analysis where relevant, an information security review, financial crime due diligence, an outsourcing assessment and an operational resilience assessment.

These reviews overlap, but they are not the same.

Data protection asks about processing instructions, sub-processors, security, deletion, audit rights and international transfers. Financial crime asks whether a tool supports effective due diligence, screening, monitoring and escalation. Operational resilience asks whether the service supports an important business service, what happens if it fails and whether exit plans are credible.

Running these reviews separately can create duplicated effort and regulatory blind spots. A supplier may pass a data protection assessment but fail to meet operational resilience expectations. Another may offer strong functionality but have weak deletion controls, access management or transfer transparency.

The answer is integrated supplier governance. This means one intake process, one risk classification, one evidence pack and the right specialist sign-off at each stage.

The FCA and ICO’s March 2026 joint statement on vulnerability-related data makes a similar point. Data protection law does not prevent firms from delivering good outcomes under the Consumer Duty, but firms must still meet their data protection obligations. One regulatory regime should not become an excuse for failing another.

Independence Does Not Mean Isolation

Closer coordination should not compromise the independence of the Data Protection Officer.

Article 38 UK GDPR requires that a DPO is not instructed on how to perform their tasks and is not placed in a conflict of interest. However, independence of judgement is not the same as isolation from the process.

A DPO can remain independent while being involved early in retention design, supplier assessment, model governance, data protection impact assessments and data mapping.

In fact, late-stage review can weaken effective oversight. By the time a system is configured, data has been collected or a supplier has been appointed, the commercial decision may already be difficult to change.

The same applies to financial crime teams. Data protection should not be seen as a paper exercise that slows down effective controls. Good minimisation, access control and retention practices can make financial crime information more accurate, better governed and easier to evidence.

Emerging Technology

Privacy-enhancing technologies may eventually help firms reduce the tension between financial crime detection and data minimisation.

These are technologies designed to gain insight from data while reducing unnecessary exposure of the underlying information. Examples include federated learning, secure multi-party computation, fully homomorphic encryption and differentially private synthetic data.

They could be valuable for anti-money laundering and fraud detection, where suspicious patterns are often easier to identify across wider datasets. Developments such as Singapore’s COSMIC platform also show the direction of travel towards more controlled, purpose-specific information sharing.

However, these technologies should be treated as emerging developments rather than immediate compliance fixes. Many remain difficult to deploy at scale due to cost, technical complexity, immature supplier tooling, performance limitations and evolving regulatory expectations.

They also do not remove the need for strong governance. A firm using privacy-enhancing technology would still need a clear lawful basis, a documented assessment of necessity and proportionality, appropriate retention rules, supplier controls and security assurance.

What Good Practice Looks Like

Firms that manage this tension well tend to do five things.

  1. Maintain one reliable data inventory. A single data inventory should support both Article 30 records of processing and financial services governance records. Separate teams should not maintain inconsistent versions of the same information.
  2. Build retention schedules together. The DPO, MLRO, legal, operations and records teams should agree the legal basis, retention period and deletion point for each record category.
  3. Apply risk-based collection. Enhanced data gathering should be linked to documented risk triggers, not habit, fear or supplier defaults.
  4. Join up supplier governance. Data protection, financial crime, information security and operational resilience reviews should work through one coordinated process.
  5. Involve data protection early. Data protection should be part of model governance, transaction monitoring design and customer decision-making from the beginning. Automated or analytics-led controls should be explainable, proportionate and supported by clear data lineage.

One Operating Model, Not Two Separate Rulebooks

The firms best placed to manage this challenge recognise the overlap and deliberately design governance that works across both regimes.

The answer is not to prioritise data protection over financial crime regulation, or vice versa. It is to build an operating model that supports proportionate collection, lawful retention, controlled sharing, resilient outsourcing and evidence that can stand up to scrutiny.

For firms under pressure to detect financial crime, protect customers and minimise personal data, that joined-up approach is essential.

This article provides general information and is not legal advice.

Do Schools Need a Data Protection Officer?

Under UK GDPR, all schools must have a designated data protection officer (DPO). This can be achieved by:

  • Assigning the responsibility to a current staff member
  • Sharing a DPO between a group of schools and academies
  • Using an outsourced DPO service

What Is a DPO’s Responsibility In a School?

A DPO in a school is responsible for:

  • Monitoring compliance and conducting regular data audits.
  • Developing and updating data protection policies and privacy notices.
  • Answering data protection enquiries from staff, parents and pupils.
  • Advising staff on data protection rules and responsibilities.
  • Organising data protection training for staff.

Why Does a School Need a DPO?

Guidance on AI Technology

Tools such as ChatGPT and Microsoft Copilot are increasingly used in most workplaces, but their use in schools remains a grey area. Staff often want to know whether these tools can be used in schools and, if so, what controls need to be in place.

A DPO can carry out a Data Protection Impact Assessment (DPIA) to identify risks before advising schools on how best to implement AI technologies safely and effectively.

Support with Subject Access Requests

Schools often need support with SARs to understand:

  • Requests made by parents on behalf of their children.
  • When a child is mature enough to exercise their right to access information.
  • How to manage requests involving safeguarding information.
  • How to handle third-party information within pupil records.
  • What information shouldn’t be disclosed.

A DPO supports staff in managing complex SARs, whether they involve pupils, parents, other staff members or safeguarding information. This can include reviewing records, applying appropriate exemptions and advising on what information can be disclosed.

Provide Policies on Photography, Videos and Marketing

The rules around taking photographs and videos in schools are often misunderstood.

Schools must inform parents and guardians how photographs of their children will be used and have a valid ‘lawful basis’ for publishing them. While it is not illegal for parents to film and photograph their own children during school performances and sports days, some schools may have policies restricting this for safeguarding and child protection purposes.

A DPO helps schools create clear privacy policies and processes, establish safe storage rules and define a ‘lawful basis’ for capturing and using images, ensuring these practices comply with UK GDPR and Data Protection Act (DPA) standards.

Why Should a School Outsource a DPO?

Gain Access To Expert Knowledge

Schools rarely have internal data protection expertise. An outsourced DPO brings specialist knowledge without the need to train someone internally. They can also provide staff with the necessary UK GDPR and data protection training.

Eliminate Conflict of Interest

Data protection regulations require a DPO to act independently. Roles such as Headteacher or IT Manager can’t serve as a DPO because they make key decisions about the school’s data processing and systems, meaning they can’t objectively monitor their own practices. An outsourced DPO provides impartial advice and identifies security risks that internal employees might overlook.

Cost-Effective

Employing an internal DPO can be expensive, as most schools rarely require full-time data protection work. Outsourcing DPO services provides access to a wider team of experts while replacing a fixed salary with a predictable service fee tailored to the level of support needed.

Get Expert DPO Support from Data Protection People

At Data Protection People, we provide ongoing data protection support for education organisations. Whether you’re a school, Multi-Academy Trust (MAT), college or university, we can advise on everything from data processes and safeguarding procedures to SAR requests.

Get in touch with our data specialists today.

Workplace Monitoring DPIAs

Around one in three UK organisations now monitor employees’ digital activity, up from one in five just a few years ago. The government has opened a consultation on whether that growth needs new rules around it, a statutory code, a duty to consult workers, or just better guidance. It runs until the end of September, and it’s not proposing to change the law yet.

Here’s the bit that matters right now, though, regardless of what the consultation eventually decides: if your monitoring is likely to be high-risk (and, let’s face it, monitoring is likely to be deemed to be intrusive, a potential abuse of power, and difficult to effectively object to), you already need a Data Protection Impact Assessment. That obligation isn’t new and isn’t waiting on this consultation.

What I want to talk about isn’t the consultation itself, there’ll be plenty written about its eight principles and three options for intervention. It’s the DPIA employers are already required to do, and how often, in my experience, it ends up being a document written to justify a decision that’s already been made rather than one that tested it.

Here are a few honest questions your own workplace monitoring DPIA should be able to answer.

Is there real human involvement, or a rubber stamp?

The law already requires meaningful human oversight where monitoring feeds into decisions with a significant effect on someone. In practice, “human involvement” too often means a manager clicking approve on whatever the system flagged, without the time, training or genuine authority to disagree with it. If the person signing off couldn’t tell you why the system flagged what it flagged, that’s not oversight, it’s a signature.

Could you explain this to the people it monitors, in a sentence, without reaching for a privacy notice?

The consultation itself makes a good point here: a privacy notice isn’t the same as workers actually understanding what’s being collected and why. If your explanation only exists in a document nobody reads, you don’t have transparency, you have a compliance artefact. The test I’d apply is simpler: could someone on the team explain, in plain terms, what’s being monitored and what it’s used for, without looking anything up?

Was “least intrusive” actually tested, or decided after the tool was already chosen?

This is the one I see skipped most often. The tool gets picked first, usually because it’s already been bought, or IT already uses it for something else, and the DPIA gets written afterwards to justify it. A genuine assessment asks what you’re actually trying to achieve and works backwards to the least intrusive way of achieving it, not the other way round.

What actually happens when the system’s wrong about someone?

Every monitoring tool will misread someone eventually, a slow week that wasn’t laziness, a flagged message that wasn’t what it looked like. The question worth answering honestly is whether there’s a real route for someone to challenge that, or whether the data just sits there as fact once it’s been recorded.

None of this needs to wait for the consultation to conclude. If anything, this is a good moment to go back through the DPIAs already sitting in a folder somewhere and ask whether they’d survive being read properly, by a regulator, an employment tribunal, or the people they’re actually about.

I was asked to review a DPIA only this week about a fingerprint scanning system installed in a medium-sized workplace for the purpose of fire evacuation roll calls. Crikey, talk about a sledgehammer to crack a nut. “Why” was the obvious question to ask, but I seemed to be the only person interested in pursuing this line of enquiry.

I’m often told that the reason for using biometrics for time and attendance management in a workplace is to stop people clocking in or out for someone else. A typical scenario is that Billy knocks off early for a round of golf, and Frank clocks him out using his physical RFID pass hours after Billy has teed off. So in that scenario, Billy is alleging to remain in the workplace when he’s actually on the fairway. But that scenario doesn’t work for fire evacuation. Billy is hardly going to say, “Hey Frank, is that the fire alarm I hear? Listen, I’m going to stay here and sit it out. Do me a favour, take my pass and pretend I’ve left the building for the roll call!” Who in their right mind would do that?

So what’s the justification for using such advanced biometric technology to automate fire evacuation roll call information. Where is the risk assessment? In addition to the technical risk, you know how it is trying to unlock your phone. One, two, three, or more attempts is often the way it works. Imagine the queue to clock out.

Then there’s the risk of scope creep. What’s stopping the clocking data being used for monitoring time and attendance more generally? And that brings me to another conversation I had this week. “Hey Phil, I’m worried that Billy is going AWOL when he’s working from home as his Teams availability flag is set to unavailable which means his laptop is not active.” But a Teams flag isn’t there for monitoring productivity and presenteeism, for a start, Billy could be doing paperwork, or by contrast, he could be on the fairway with his Teams active on his mobile phone.

I guess the point I am rambling about is that DPIAs are a mechanism that has been around in the UK for almost 20 years and still, the vast majority of those I read fail to describe and explain the envisaged processing and are extremely weak in the risk identification section.

If it’s been a while since your monitoring DPIAs were properly stress-tested, that’s exactly the kind of thing we help clients work through.

Written by Phil Brining

How Can Data Protection Risks Affect Printing Service Providers?

How Can Data Protection Risks Affect Printing Service Providers?

Whether producing photographs, wedding invitations, business cards, direct mail, marketing materials or personalised documents, printing service providers routinely receive files containing names, postal addresses, email addresses, telephone numbers and, in some cases, special category personal data, e.g. membership records for a political party or campaign.

Given the nature and volume of the information entrusted to them, organisations operating within the printing industry should ensure that data protection is embedded into their operational processes from the outset.

Compliance should not be viewed merely as a regulatory obligation but as an integral part of business operations. In practice, this requires implementing appropriate technical and organisational measures, configuring printing equipment with data protection-focused settings by default and ensuring that personal data is processed in accordance with the UK GDPR and the Data Protection Act 2018.

Set out below are some of the principal data protection risks that organisations operating in the printing sector should consider.

1. Data Retention

One of the most significant compliance risks concerns the retention of customer data.

Printing companies frequently receive photographs, mailing lists and other files for the purpose of completing a particular order. Once that purpose has been fulfilled, organisations should ensure that personal data is not retained for longer than is necessary unless there is a lawful basis for continued retention.

The UK GDPR requires organisations that process personal information, whether acting as controllers or processors, to comply with the storage limitation principle. This means ensuring that personal data is not kept for longer than is necessary for the purposes for which it is processed unless there is a lawful reason for continued retention.

Retaining customer files indefinitely without an established retention policy or a legitimate business justification may therefore constitute a breach of the legislation.

From a risk management perspective, excessive data retention also increases the potential impact of a personal data breach. The greater the volume of historic customer information retained, the greater the number of individuals likely to be affected in the event of unauthorised access or a cyber incident.

Such incidents may expose organisations not only to regulatory scrutiny by the Information Commissioner’s Office (ICO) but also to reputational damage and loss of customer confidence.

2. Data Stored on Printing Devices

Data protection measures should extend beyond email systems, online ordering platforms and file transfer services.

Modern multifunction printers frequently contain internal hard drives or solid-state drives (SSDs) capable of retaining copies of print, scan and copy jobs.

In addition, organisations may use cloud-managed print solutions, retained scan repositories and manufacturer cloud services, all of which can store or process documents containing personal data.

Unless these systems are appropriately configured and personal data is securely erased or deleted in accordance with documented retention periods, information may remain accessible long after the relevant work has been completed.

For this reason, organisations should ensure that printing devices form part of their information security programme.

Appropriate measures may include:

  • Encrypted storage
  • Secure print functionality
  • Controlled administrator access
  • Regular firmware updates
  • Secure deletion of stored print jobs

3. Disposal of Printing Equipment

When printers, scanners, multifunction devices or servers reach the end of their operational life, organisations should ensure that all storage media are securely sanitised before disposal, resale or return to leasing providers.

Failure to securely erase stored information may result in personal data being recovered by unauthorised third parties.

Such incidents may amount to a personal data breach requiring assessment under the UK GDPR and, where applicable, notification to the Information Commissioner’s Office and affected individuals.

Organisations should therefore implement documented asset disposal procedures and obtain appropriate certification where third-party disposal providers are engaged.

4. Confidentiality, Access Control and Staff Awareness

Employees working within printing environments routinely have access to customer artwork and documents containing personal information.

Consequently, organisations should ensure that access to such information is limited strictly to those individuals who require it for the performance of their duties.

The following measures can help reduce the likelihood of unauthorised access:

  • Robust role-based access controls
  • Confidentiality obligations within employment contracts
  • Regular privacy training
  • Documented internal procedures

It is equally important to recognise that personal data does not need to be copied, disclosed externally or published for a reportable incident to arise.

Unauthorised internal access to customer information may itself constitute a personal data breach under the UK GDPR, depending on the circumstances. Organisations should investigate and manage these incidents in accordance with their incident response procedures.

How Can Data Protection People Assist Printing Organisations?

As discussed above, organisations operating within the printing industry are exposed to a range of data protection and information security risks.

Given the volume and nature of the personal data they process, obtaining specialist data protection advice can assist organisations in demonstrating compliance with the UK GDPR while reducing operational and regulatory risk.

At Data Protection People, we work closely with organisations to develop practical, proportionate compliance frameworks tailored to their business operations.

Our support may include:

  • Identifying and documenting personal data processing activities: This enables organisations to understand how personal data flows throughout the business and maintain accurate Records of Processing Activities (RoPA), where required.
  • Assessing data protection and security risks: We can recommend appropriate technical and organisational measures to protect personal data throughout its lifecycle.
  • Developing data retention and deletion policies: This helps ensure that personal data is retained only for as long as necessary and disposed of securely in accordance with the storage limitation principle under the UK GDPR.
  • Reviewing existing business processes and internal procedures: This helps organisations embed data protection obligations into day-to-day operations and adopt a privacy-by-design approach where appropriate.
  • Preparing or reviewing data protection documentation: This may include privacy notices, internal policies, processor agreements and data processing procedures.
  • Supporting organisations with data subject rights requests: This includes requests for access, erasure, rectification, restriction of processing and objection.
  • Providing practical guidance following personal data breaches: This may include incident assessment, regulatory notification obligations and remediation measures.
  • Delivering staff awareness training: This helps employees understand their responsibilities when handling customer information and reduces the likelihood of human error.

Building Data Protection Into Printing Operations

Printing organisations process significant volumes of personal data and must ensure that appropriate safeguards are in place throughout the entire data lifecycle.

Compliance with the UK GDPR and the Data Protection Act 2018 extends beyond securing customer files. It requires effective governance, appropriate technical and organisational measures, clear retention practices and ongoing staff awareness.

By adopting a proactive, risk-based approach to data protection, organisations can reduce the likelihood of personal data breaches, demonstrate accountability and strengthen customer trust.

Ultimately, robust data protection practices are not only a legal requirement but also an essential element of responsible business operations.

Speak to Our Team

If your organisation needs support with data protection, information security or staff training, contact Data Protection People.

Contact Our Team

S2 Ep30: GDPR Radio – Data Protection News of the Week

S2 Ep30: GDPR Radio – Data Protection News of the Week

Practical discussion on the latest data protection news

In this episode of GDPR Radio, Caine Glancy and Catarina Santos discuss recent developments affecting data protection, workplace monitoring, media reporting and information security.

They explore the risks behind misleading headlines, AI systems that claim to detect employee emotion, smart glasses and a reported NHS data breach involving an unsecured pager network.

What This Episode Covers

  • A Court of Appeal decision on misleading headlines and the fair processing of personal data
  • Why images and headlines can shape public perception before people read the full story
  • AI emotion-detection tools and the risks of monitoring employees based on facial expressions, voice or body language
  • Why organisations must consider necessity, fairness, transparency and less intrusive alternatives before introducing workplace monitoring
  • Smart glasses, hidden recording and the need for clear acceptable-use policies
  • Lessons from a reported NHS pager network data breach
  • Why access controls, staff awareness and practical policies all matter

Key Discussion Points

“Someone who only saw the headlines and photographs together could just reasonably get the impression that actually it was Vince, the person that the article was referring to.”

The hosts discuss why data protection law can apply even where a full article clarifies the facts. The way a headline, image and article appear together can still affect whether personal data has been processed fairly.

“Could you not achieve the same objective with a completely less intrusive way?”

Caine and Catarina question the value of emotion-detection technology in the workplace. They explore why one-to-one conversations, objective work outputs and appropriate management may be more proportionate than analysing an employee’s voice, face or behaviour.

“Technical controls can only go so far, which is why the emphasis in the law is on technical and organisational measures.”

The episode also looks at why information governance needs to work in practice. Policies must reflect how an organisation operates, staff need to understand them and clear action needs to follow when rules are not followed.

Why This Episode Matters

Data protection risks do not always start with a major cyber incident. They can arise through misleading content, new workplace technology, weak access controls or policies that exist on paper but are not understood in practice.

This episode helps organisations consider where their own controls may need attention and why proportionate, people-focused

S2 Ep29: How AI Is Reshaping the DPO Role in 2026

S2 Ep29: How AI Is Reshaping the DPO Role in 2026

Data Protection Made Easy podcast with Caine Glancy and Amber Sivill

Artificial intelligence is changing how Data Protection Officers work.

AI tools can help with research, training, risk assessments and routine administration. However, they can also produce inaccurate advice, encourage confirmation bias and create new governance risks.

In this episode of the Data Protection Made Easy podcast, Caine Glancy and Amber Sivill discuss how AI is affecting DPO workloads and why professional knowledge and meaningful human oversight remain essential.

What Does This Episode Cover?

During the episode, Caine and Amber discuss:

  • The increase in AI-generated Subject Access Requests
  • How AI is affecting DPO workloads
  • The risks of using AI for data protection advice
  • How AI could support RoPAs, DPIAs and LIAs
  • The importance of checking AI-generated policies
  • Confirmation bias in AI responses
  • Why human oversight and professional knowledge still matter

How Is AI Affecting Subject Access Requests?

The discussion explored the growing number of Subject Access Requests, or SARs, that appear to have been generated using AI.

These requests can look formal and detailed. However, they may ask for information that does not fall within the normal scope of a SAR.

Amber explained:

“It also fuels a lot of misunderstanding. A lot of the time, you see a request and most of it does not even fall under the scope of what a SAR generally covers.”

Caine also shared that SAR-related cases handled through the DPP Support Desk have increased significantly.

AI may make it easier for people to create requests, complaints and follow-up correspondence. This can place additional pressure on data protection teams, particularly where requests are vague or based on incorrect information.

Can DPOs Rely on AI for Data Protection Advice?

AI can provide a useful starting point. However, it should not replace professional knowledge.

Amber explained:

“You need to have the base knowledge in order to be able to use these systems.”

An experienced practitioner may recognise when an AI response refers to the wrong legislation, misses important context or provides an answer that is too confident.

Someone with less experience may not spot those problems.

Data protection decisions are rarely black and white. The correct answer often depends on the organisation, the processing activity and the people who may be affected.

Could AI Support RoPAs, DPIAs and LIAs?

AI may help DPOs complete some routine or administrative tasks.

For example, it could help pre-populate a Record of Processing Activities, or RoPA, using information about an organisation’s activities and data sharing.

It may also provide a starting point for a Data Protection Impact Assessment, or DPIA, and a Legitimate Interests Assessment, or LIA.

However, organisations must consider what information they enter into an AI system. DPIAs and other assessments may contain sensitive or confidential information.

Amber said:

“There is a limit as to what you can provide the model with in terms of confidentiality and not oversharing any information.”

Any AI-generated assessment must be checked against the organisation’s actual processing, systems and risks.

Why Does Human Oversight Matter?

AI can produce clear and convincing answers even when those answers are incomplete or incorrect.

It may also agree with the direction of a prompt instead of challenging the user’s assumptions. This is known as confirmation bias, which means favouring information that supports an existing view.

Caine explained:

“It is a fantastic tool that will hopefully be able to help in the role as a DPO. But what matters is that you can supplement it with your pre-existing knowledge.”

Amber added:

“The human element needs to be someone overlooking it who actually knows what they are talking about.”

Human oversight must be meaningful. The person reviewing an AI output needs the knowledge and authority to identify problems, challenge the result and make the final decision.

Is an AI-Generated Policy Better Than No Policy?

An AI-generated policy is not useful simply because it exists.

A policy must reflect how the organisation actually works. It must be practical, accurate and followed by staff.

Amber explained:

“If you have a policy in place and it does not align with your business, it is not workable and people are not following it, then there is ultimately not really anything there in place anyway.”

AI may help structure a first draft. However, the final policy should be reviewed by someone who understands the organisation, its legal duties and its operational risks.

What Should DPOs Take Away?

AI can support DPOs, but it should not replace them.

Organisations should:

  • Use AI to support work rather than make final decisions
  • Check AI outputs against current law and ICO guidance
  • Avoid entering unnecessary personal or confidential information
  • Keep meaningful human oversight in place
  • Document how AI tools are approved, monitored and reviewed
  • Make sure policies and assessments reflect real business practices

The DPO role is becoming broader and more connected to technology, governance and organisational risk.

AI creates opportunities to work more efficiently. It also makes professional judgement, scepticism and accountability more important.

Meet Your Hosts

Caine Glancy

Caine is the Data Protection Support Desk Manager at Data Protection People. He works with organisations every day to help them understand and respond to practical data protection challenges.

Amber Sivill

Amber is a Data Protection Consultant at Data Protection People. She supports organisations with data protection compliance, governance and emerging technology risks.

Watch or Listen to the Episode

Watch the full episode on YouTube or listen on Spotify.

Watch on YouTube

Listen on Spotify

Need Support With AI Governance?

If your organisation is adopting AI, Data Protection Made Easy can help you understand the risks, strengthen governance and meet your data protection responsibilities.

Contact Our Team

S2 Ep28 GDPR Radio – Data Protection News of the Week

S2 Ep28: GDPR Radio – Data Protection News of the Week

Amber Sivill and Mark Farrell discuss recent data breaches, AI risks and privacy enforcement.

From preventable spreadsheet errors to AI-generated decisions, this episode explores the changing risks facing organisations and data protection professionals.

Amber and Mark examine recent incidents involving government departments, exposed AI conversations, employee access to personal data and the growing use of facial recognition technology.

What This Episode Covers

In this episode, Amber and Mark discuss:

  • The Ministry of Defence data breach and the importance of basic software training
  • The cyber attack affecting the Department for Education
  • How AI can support both cyber attacks and defensive security measures
  • Claude conversations appearing in Google search results
  • AI-generated information being used in public-sector decisions
  • New transparency requirements under the EU AI Act
  • The risks created by unsecured paper records
  • Unauthorised employee access to personal data
  • AI-generated inferences and the future of anonymised data
  • Facial recognition, smart surveillance technology and privacy
  • Recent ICO action relating to nuisance marketing messages

When Basic Training Is Overlooked

The episode begins with the Ministry of Defence data breach involving information about Afghan relocation applicants.

Amber and Mark discuss reports that the breach could have been prevented through basic spreadsheet training. They also consider what this tells organisations about accountability and the importance of practical training.

Mark explains:

“AI is going to be leveraged to launch cyber attacks, it also has to be leveraged to combat them.”

The discussion also covers the cyber attack affecting the Department for Education. This demonstrates why organisations need both effective security systems and staff who understand how to recognise potential threats.

Privacy by Design and AI Tools

Amber and Mark discuss reports that shared Claude conversations appeared in Google search results.

The incident raises questions about transparency, default privacy settings and whether users understand when their conversations may become publicly available.

Amber says:

“You need to embed that sort of privacy, privacy by design, privacy by default, making sure that you know the default setting isn’t that my personal conversations are being shared publicly for other people to see.”

Organisations should understand how an AI service handles information before employees enter personal, confidential or commercially sensitive data into it.

AI Decisions and Regulatory Oversight

The hosts examine a case involving information believed to have been generated by AI and used during an asylum decision.

They discuss the risks of relying on AI-generated material without proper fact-checking or meaningful human oversight. Meaningful human oversight means a person genuinely reviews the information and can challenge or change the outcome.

The conversation also covers EU AI Act transparency requirements and the need for clearer UK rules.

Amber explains:

“I think this just goes to show that the current legislation doesn’t fit. I think it fits in so many ways in terms of the principles, but we need more specifics that are tailored towards AI use.”

Paper Records and Employee Access

Not every data protection incident involves sophisticated technology.

Amber and Mark discuss confidential paper records reportedly found in an unsecured former council building. They also examine cases involving employees accessing personal records without authorisation.

These stories show why organisations must protect information throughout its lifecycle. This includes digital files, archived documents and paper records.

Access controls should also ensure that employees can only view information they genuinely need for their role.

AI Inferences and Anonymised Data

The episode considers how AI may infer sensitive information from data that appears to be aggregated or anonymised.

Anonymised data is information that can no longer be linked to an identifiable person. However, more capable technology may make it easier to identify patterns or combine information from different sources.

Amber and Mark discuss whether existing definitions and safeguards will remain effective as AI develops.

Facial Recognition and Smart Surveillance

The hosts also examine AI-enabled street technology that can use cameras and facial recognition to identify people or detect potential offences.

These tools may support law enforcement and public safety. However, they also create questions about proportionality, transparency and function creep. Function creep happens when information or technology is gradually used for purposes beyond the reason it was originally introduced.

Mark summarises one of the central concerns:

“You behave differently when you’re being watched.”

Recent ICO Enforcement

The episode closes with recent action from the Information Commissioner’s Office relating to nuisance marketing about motor finance claims.

Amber and Mark discuss the use of search warrants and cooperation between different regulators. They also consider whether enforcement is being applied consistently across organisations and sectors.

Practical Takeaways for Organisations

Organisations should:

  • Include practical software skills in data protection training
  • Review the privacy settings of AI tools before using them
  • Avoid entering sensitive information into systems without appropriate safeguards
  • Apply meaningful human oversight to AI-supported decisions
  • Protect paper records as carefully as digital information
  • Regularly review employee access permissions
  • Assess whether anonymised information could be re-identified
  • Consider privacy risks before introducing surveillance technology

Watch or Listen

Watch or listen to the full episode of GDPR Radio:

📺 Watch the episode on YouTube

🎧 Listen to the episode on Spotify

Meet Your Hosts

Amber Sivill

Amber explores how emerging technology, AI governance and privacy risks affect organisations in practice.

Mark Farrell

Mark examines recent data protection developments and the practical lessons organisations can take from them.

Data Protection Made Easy

Data Protection Made Easy helps organisations understand and meet their responsibilities under UK GDPR and related data protection law.

S2 Ep27: Creating Training Which Changes Behaviour

Creating Training Which Changes Behaviour

Data Protection Made Easy podcast with Caine Glancy and Amber Sivill

Data protection training should do more than record attendance. It should help people recognise risks, understand their responsibilities and know what action to take.

In this episode of the Data Protection Made Easy podcast, Caine Glancy and Amber Sivill discuss why generic training often fails to engage staff. They explore how organisations can make training practical, relevant and easier to apply during everyday work.

Why Generic Training Often Falls Short

Training can be technically accurate without being effective.

A presentation may explain the law correctly, but staff are unlikely to remember it if the content does not relate to their role. Long presentations, legal language and broad examples can make data protection feel more complicated than it needs to be.

Amber explained:

“Poor training for me is where organisations design training and it may be very well researched, but it is not tailored.”

Training should connect data protection requirements to real decisions. Staff need to understand how the subject affects their work, their customers and the personal data they handle.

Make Training Relevant to Each Role

Different teams use personal data in different ways.

Human resources teams, senior managers, IT staff and customer service teams may face very different risks. Giving everyone exactly the same training can leave important gaps.

Amber said:

“Tailoring it to different departments and different scenarios, and bringing some sort of personal element in, really makes people think.”

Role-based training allows an organisation to focus on the situations each team is likely to encounter. This could include recognising a subject access request, reporting a personal data breach or handling sensitive information securely.

Build Trust Rather Than Fear

Training should make people feel able to ask questions and report mistakes.

Using fear to encourage compliance can have the opposite effect. Staff may become less willing to report an incident if they believe they will automatically be blamed or disciplined.

Amber explained:

“Leading by fearmongering can push people towards being less open and honest about the things they may be doing wrong or the difficulties they are facing.”

A supportive approach does not remove accountability. It helps staff understand that mistakes should be reported quickly so the organisation can assess the risk and respond appropriately.

Caine highlighted the importance of education alongside formal training:

“Education is also the time spent with people to help them understand an element of the law that is relevant to them and their role.”

Make Training Conversational

People often learn more when they can ask questions and discuss realistic examples.

A conversational session gives the trainer an opportunity to understand where staff are struggling. It also helps employees connect data protection principles with situations they have experienced.

Amber said:

“It needs to be more conversational and more on a case-by-case basis.”

Quizzes, practical exercises, visuals and group discussions can all help. A mixture of formats also supports different learning styles.

Support Staff After the Session

Training should not end when the presentation closes.

Staff need somewhere to find clear information when they face a data protection question. This could be a company handbook, an intranet page or a central collection of practical guidance.

Amber explained:

“It is always good to have some sort of central archive, a company handbook or an intranet, where people can easily access that information.”

Resources should answer practical questions, including:

  • How to recognise a potential personal data breach
  • Who to contact when something goes wrong
  • How to recognise a request for personal information
  • Where to find the organisation’s policies and procedures
  • What responsibilities apply to a particular role

Create a Culture of Accountability

Effective training needs support from across the organisation.

The Data Protection Officer cannot build a strong data protection culture alone. Senior leaders, line managers, IT teams and other key employees all have a part to play.

Amber described accountability as the overarching principle:

“Ultimately, it is about accountability. You look at what has gone wrong, what you could do better next time and what you can put in place.”

When leaders take training seriously, staff are more likely to do the same. This helps turn data protection from an annual exercise into part of everyday decision-making.

Key Takeaways

Effective data protection training should:

  • Relate directly to the employee’s role
  • Use clear language rather than legal jargon
  • Include practical examples and realistic scenarios
  • Encourage questions and open conversations
  • Help staff feel confident reporting mistakes
  • Use different formats to support different learning styles
  • Provide guidance that remains available after the session
  • Receive visible support from senior leaders and managers

Good training does not simply tell people what the law says. It helps them understand what good data protection looks like in practice.

Watch or Listen to the Full Episode

Watch the full conversation on YouTube or listen through Spotify.

Explore Data Protection Training

Data Protection Made Easy provides training designed to help organisations understand their responsibilities and apply data protection requirements in practice.

View Training Courses

Our Events & Webinars

Expert-led Discussions

We host events on a weekly basis for the community of data protection practitioners and have built up a network of over 1,700 subscribers. Members receive weekly invites, exclusive offers, early access to selected content, our monthly newsletter, and first access to in-person events. Check out our upcoming events and become part of our growing community.

View All
S2 Ep30 GDPR Radio - Data Protection News of the Week
14 August 26 12:30 - 1:15 pm

S2 Ep30: GDPR Radio – Data Protection News of the Week

S2 Ep29 How AI Is Reshaping the DPO Role in 2026 (1)
07 August 26 12:30 - 1:15 pm

S2 Ep29: How AI Is Reshaping the DPO Role in 2026

Get Support With Data Protection And Cyber Security

Our mission is to make data protection and cyber security easy: easy to understand and easy to do. We do that through the mantra of benchmark, improve, maintain.