UK Data Protection Consultancy

Data Protection & Information Security Experts

Data Protection Made Easy.

GDPR Support Cyber Security Support
Cate and Jas Chatting
Join our extensive list of clients who have their data privacy under control

Accelerate Your Data Protection Compliance

Save Time, Save Money and Relax: You’re In Safe Hands

Discover the comprehensive range of data protection services at Data Protection People. Tailored to meet the unique needs of your organisation, our expert team has successfully handled every challenge imaginable. Whether you’re navigating compliance complexities or enhancing data security, trust DPP to be your partner in safeguarding information.

SAR Support

Explore our Subject Access Request (SAR) Handling Service and understand how Data Protection People can support your organisation

Contact Us

Data Protection Support

Data Protection People's world-class GDPR Support Desk. If you're navigating the complex landscape of data protection, PCI DSS, and cybersecurity, our support desk is your reliable compass.

Contact Us

Outsourced DPO

A data protection officer doesn't have to be a full time employee and in many respects it's better to have a company like DPP take on the role. Watch the video below to find out more about our outsourced DPO and privacy officer services or reach out and get in touch with us.

Contact Us

Data Protection Audit & GDPR Audit Services

A range of high level reviews, detailed audits and mid-range assessments to test compliance with data protection laws and standards

Contact Us
View All

Need Help With Cyber Security Compliance?

We Have You Covered!

At Data Protection People, our cyber security services are designed to fortify your digital defences. With a proven track record spanning diverse sectors in the UK, our seasoned team brings a wealth of experience in handling a wide array of cybersecurity challenges. Reach out to us and explore how DPP can enhance your organisation’s cyber resilience.

PCI DSS Compliance Services for Merchants

A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.

Contact Us

PCI DSS Compliance Services for Service Providers

A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.

Contact Us

External Attack Surface Management

Our experts can support you with Dark Web Monitoring - Data Protection People offer a free dark web scan for your organisation.

Contact Us

PCI DSS

A PCI assessment is an audit for validating compliance with the Payment Card Industry Data Security Standard (PCI DSS), a set of security standards for merchants who accept, process, store or transmit credit card information.

Contact Us
View All
Rofi Hendra Support Desk Data Protection People

Supporting DPOs

Flexible Support When You Need It

At Data Protection People, we recognise the dynamic challenges and unique responsibilities of the Data Protection Officer (DPO) role. Beyond offering standard support, we provide a comprehensive suite of services crafted to empower DPOs at every step.

Collaborative Community: Navigating the intricate landscape of data protection can be isolating. That’s why we’ve fostered a collaborative community of privacy professionals. As a DPO with us, you’re never alone. Our network serves as a forum for insightful discussions, sharing solutions, and building a sense of camaraderie.

Expert Guidance and Advice: The journey of a DPO is often filled with complex decisions. Our seasoned team of experts is your reliable resource, offering timely advice and strategic guidance. We’re not just a service provider; we’re your dedicated partners in overcoming challenges and making informed decisions.

Advanced Training for Continuous Growth: Stay ahead in your role with our advanced training programs. Tailored for DPOs, our courses delve into intricate aspects of data protection, providing you with a competitive edge. It’s not just about meeting the present challenges but ensuring your continuous growth and excellence in your role.

Audits, Assessments, and Document Reviews: Our services extend beyond conventional boundaries. From comprehensive audits and assessments to meticulous document reviews, we ensure that your data protection strategies are not only compliant but also optimised for efficiency.

Simplifying Complexity for Future Ease: Beyond addressing current challenges, our mission is to simplify the complexities inherent in data protection. By partnering with Data Protection People, you’re not just solving problems – you’re ensuring a smoother, more efficient role in the future. We streamline processes, making your responsibilities more manageable and your decisions more impactful.

Diverse Sector Experience

Access to a Team of Industry Experts

At Data Protection People, our expertise spans across diverse sectors, ensuring that businesses of all sizes and orientations receive tailored Data Protection and Cyber Security solutions. From the dynamic commercial sector and agile SMEs to the impactful third sector and expansive multi-nationals, we extend our services to fortify the digital defences of every business entity.

Skyline vertical

Commercial Sector

Elevate your data protection and cybersecurity standards in the bustling landscape of the Commercial Sector. We offer tailored solutions designed to safeguard your sensitive information, ensuring compliance and resilience against evolving threats. Partner with us to fortify your digital assets and foster a secure environment for sustained growth.

Card DPP Payment

SMEs

Small and Medium Enterprises (SMEs) form the backbone of innovation. Our data protection and cybersecurity services are crafted to match the agility of SMEs. Navigate the digital landscape securely, optimize your operations, and scale confidently with our tailored solutions that prioritize your unique business needs.

Third Sector

Third Sector

For organisations in the Third Sector driven by purpose, our data protection and cybersecurity expertise align with your mission. Safeguard sensitive data, build stakeholder trust, and amplify your positive impact. Let our solutions be the backbone of your technology infrastructure, ensuring that your focus remains on making a difference.

Boat in water

Multi Nationals

For the global footprint of Multi Nationals, our data protection and cybersecurity services provide a comprehensive shield. Navigate the complexities of international regulations with confidence. From compliance strategies to threat intelligence, we've got your data security needs covered, empowering your multinational endeavors with resilience.

Certification in cyber

Public Sector

In the Public Sector, trust and accountability are paramount. Our data protection and cybersecurity consultancy ensures that your operations align seamlessly with regulatory requirements. From confidential citizen data to streamlined governance, our solutions empower public entities to serve with integrity and technological excellence.

Caratina consulting

Why Use Our Outsourced DPO Services?

Save Time, Money and Guarantee Compliance

Navigating the intricate landscape of data protection demands more than just a DPO — it requires a dedicated team committed to excellence. Our Outsourced DPO Services extend beyond the traditional role, offering a comprehensive approach to legal compliance and pragmatic solutions.

Why Choose Outsourcing?

An outsourced DPO brings a wealth of experience, not just in the law but also in crafting workable solutions. Their impartiality is fortified by a team of privacy practitioners, ensuring that your organization benefits from a spectrum of expertise. Should the need arise, seamless coverage during absences is guaranteed, eliminating the vulnerability associated with a single in-house DPO.

Staying Headache-Free

Concerned about the disruption if your DPO moves on? With an outsourced model, transitions are smooth, and you won’t experience the sudden headache of a critical role vacancy. The continuity provided by a team ensures that your data protection responsibilities are seamlessly handled.

Compliance Tailored to You

Our Outsourced DPO Services align seamlessly with your legal obligations, whether you’re mandated to appoint a DPO or choose to do so voluntarily. We understand that compliance is not just about ticking boxes but about ensuring a robust, practical approach to data protection. Choose Data Protection People for a worry-free, compliance-driven outsourced DPO solution — because your data protection journey should be as smooth as it is secure.

eastlight housing

“I cant recommend Data Protection People enough, they have helped me in so many different areas, no matter how complex the challenge or how large the obstacle, DPP always has the answer.

I can call the team at any time and have built an amazing relationship with them, in times of frustration they are here to calm me down and create a plan, they are a pleasure to work with.”

Mark Leete
Eastlight Community Homes
TDC_logo

‘I found the FOI training session to be highly informative and well-structured. It covered all the key areas comprehensively and provided clear, practical guidance throughout. The content was easy to follow, and the delivery by Gary was engaging, making complex topics accessible and understandable’. 

‘The training session has really helped me to understand the IG rep role a bit more and what I need to be thinking about when receiving a request for information’. 

Charlene Haynes & Team
Tendring District Council
dyslexia-action-logo-client

“I have worked with the Data Protection People for some time now. Their expertise has been drawn upon to assist us with our GDPR compliance gap analysis project, ROPA design and production through to conducting objective reviews and surveys. They are always available to help us out and their advice and guidance is excellent and delivered in a timely way. Special mentions to Kathy Midgley, Phil Brining, and David Hendry. A great, reliable and dependable service!”

Judy Barker
Dyslexia Action
Veritau client

“A great service and peace of mind. Data Protection People provides a well-rounded service to ensure customers are fully supported in their approach to GDPR compliance. My interaction has largely been with the following people: Kathy Midgley – another great asset to the organisation. Always approachable, always helpful and consistently supportive to the team and customers.

Julie Ferguson
Veritau
Woodgate & Clark

“We have been working with the Data Protection People for many years now, and have found them to be insightful, helpful, and knowledgeable in all areas of Data Protection Compliance. Data Protection People have taken the time to understand our business, the regulatory environment we sit under, and the unique challenges we face in the industry. They have supported us in all areas of Information and Data Security, assisting in assessments of our policies and changes to our processes. They are always willing to go the extra mile and prioritise support where required.”

Nia Roberts
Woodgate & Clarke

Data Protection People Blogs & Podcasts

Data Privacy Learning & Guidance

Data Protection People have the UK’s #1 Data Protection Podcast with over 250 episodes available across all audio streaming platforms, we also post regular content designed to simplify complex areas of data protection and cyber security, check out some of the podcasts and articles below and make data protection easy today.

STAIRs publication scheme: what housing associations must publish from 1 October 2026

The short answer: Since 1 October 2026, private registered providers of social housing in England must have a STAIRs publication scheme. It covers information they hold about governance, spending, homes, performance, services, registers and housing management. Providers do not have to create new records. Appropriate redaction is allowed. The separate requirements for tenant information requests begin on 1 April 2027.

What is a publication scheme?

A publication scheme explains what information your organisation makes available routinely and where tenants can find it. They should not have to make a formal request to understand how you run homes and services.

The government’s STAIRs policy statement sets out the requirements. STAIRs now forms part of the Regulator of Social Housing’s Transparency, Influence and Accountability Standard.

For the wider background, read STAIRs: What Housing Associations Need to Know. This article focuses on the publication scheme itself.

Who needs a STAIRs publication scheme?

The requirements apply to private registered providers of social housing in England. This includes housing associations. The policy does not provide a general exemption for small providers.

Local authority landlords are already subject to the Freedom of Information Act. Do not assume STAIRs applies to every housing organisation across the UK. Check your registration and the services you provide.

What must it include?

Your scheme must cover information you hold within seven areas. The examples below help you identify existing material. They are not a substitute for checking the policy statement.

1. Governance and decision making

Explain who runs the organisation and how decisions are made. Examples include senior staff roles, governance arrangements, decision-making policies and information about tenant consultations.

2. Spending

Show how money is used. Existing financial reports, grant information and explanations of how service charge revenue is spent can help cover this area.

3. Housing stock management

Include information about managing and maintaining homes. Examples include maintenance plans, stock transfers and progress towards net zero.

4. Performance

Help tenants understand how services are performing. Examples include inspection outcomes, Tenant Satisfaction Measures, complaint figures, health and safety assessments and maintenance performance.

5. Housing services

Describe the services tenants can use. Link to existing advice, guidance and service information, including how tenants can access support.

6. Lists and registers

Review information held in legally required registers and other lists relating to social housing management. Assess what can reasonably be published without exposing protected information.

7. Social housing management

Include policies and strategies for managing social housing. Your existing housing management policies may already provide much of this information.

What does a publication scheme not require?

You do not have to create new records. Start with information your organisation already holds. This does not remove the need to identify it and make it accessible.

You do not have to publish every document without checks. Appropriate and reasonable redaction is permitted. Record why information is withheld and apply the policy statement’s safeguards.

It is not a one-off upload. Providers must review and update the information regularly. Assign an owner and choose a review cycle that fits your organisation.

How should you publish it?

Tenants must be able to identify and access the information. These five practical steps can help:

  1. Create an easy-to-find starting point. A dedicated website page can link to information you already publish. Check that the links work.
  2. Group information under the seven areas. Make it clear what each link contains and flag gaps for action.
  3. Make access practical. Use plain English and accessible documents. Provide a route for tenants who need another format or cannot use the website.
  4. Explain how to contact you. Include questions about missing information and the STAIRs review process.
  5. Keep it current. Show a review date, assign owners and check for changes to policies, services and published figures.

These are implementation suggestions. A particular page layout or quarterly review cycle is not prescribed by the policy statement.

Missed 1 October? Here’s how to catch up.

If your scheme is not ready, start by identifying the gaps. Keep a clear record of your actions and who is responsible for them.

  1. Order existing information. Check annual reports, policies, service pages, performance reports and governance material against the seven areas.
  2. Prioritise missing items. Identify information you hold but have not made available. Give each action an owner and a realistic completion date.
  3. Check before publishing. Review accuracy, accessibility and any information that needs redaction.
  4. Publish checked material promptly. Keep working on gaps. A first version does not, by itself, establish that you have met every requirement.
  5. Tell tenants where to find it. Explain the contact and review routes, then schedule your next check.

If you need help identifying gaps, explore our STAIRs Readiness Assessment.

How do you protect personal data before publishing?

Transparency does not mean publishing personal information without a lawful reason. Review documents for names, contact details, complaint information and details that could identify a tenant indirectly.

Do not automatically remove every name. Some information, such as senior staff roles, may be appropriate to publish. Assess the purpose and legal basis for each disclosure.

Where redaction is needed, remove the information securely. Check comments, tracked changes, hidden data and searchable text. A coloured box over text may leave the underlying information accessible.

Keep a record of decisions and have someone check the final public version. Our STAIRs housing FAQs cover further practical questions.

How is a STAIRs request different from a SAR?

A STAIRs request concerns relevant information about the management of social housing. A subject access request (SAR) concerns a person’s own personal data.

For example, a request for a repairs policy is different from a request for personal information in a tenant’s repair records. One message may contain both.

Assess each part and route it correctly. The STAIRs policy directs providers towards the appropriate statutory route where a separate legal right of access applies. Do not apply the STAIRs 18-hour limit to a SAR.

The ICO’s right of access guidance explains the separate SAR requirements.

What changes on 1 April 2027?

From 1 April 2027, tenants or their designated representatives can make written requests for relevant information. Providers should acknowledge them promptly.

  • 30 calendar days: Respond promptly and no later than 30 calendar days from receipt. Extra time is permitted only in exceptional circumstances specified in the policy. Explain any delay and when a response is expected.
  • 18-hour staff-time limit: A provider may refuse where the work involved would exceed 18 hours. This is a refusal threshold, not an automatic charge. Record the reasoning behind any estimate.
  • Internal review: If the tenant is dissatisfied, they should first complain to the provider. The review should normally finish within 30 calendar days, with additional time possible in certain circumstances.
  • Housing Ombudsman: A tenant dissatisfied with the review can escalate under the Housing Ombudsman Scheme.

The publication scheme has its own review and escalation route already. Do not wait until April 2027 to explain how tenants can raise missing information.

For earlier sector context, see our STAIRs update for housing associations.

Your STAIRs publication scheme checklist

  • Identify the information you hold under all seven areas.
  • Check what is already public and prioritise gaps.
  • Review personal data and record withholding decisions.
  • Check links, readability and access in other formats.
  • Explain the contact, review and escalation routes.
  • Tell tenants where to find the scheme.
  • Assign owners and regular review dates.
  • Prepare request-handling processes for April 2027.

Frequently asked questions

When did STAIRs publication schemes become mandatory?

The publication-scheme requirements apply from 1 October 2026 to private registered providers of social housing in England.

Do housing associations have to create new records?

No. The publication scheme covers information already held. Providers still need to identify relevant information and make it accessible.

Can we redact information before publishing?

Yes, where appropriate and reasonable. Apply the policy statement’s safeguards, assess personal data carefully and record the reasons for redaction.

When do tenant information requests begin?

The separate information-request requirements begin on 1 April 2027. Providers must respond promptly, normally within 30 calendar days of receipt.

Where do publication-scheme complaints go?

Tenants should first use their provider’s STAIRs review process. If dissatisfied with the review, they can escalate to the Housing Ombudsman under its Scheme.

Is STAIRs the same as the Freedom of Information Act?

No. STAIRs is a separate framework for private registered providers. It supports tenant access to housing management information but does not make those providers subject to FOI simply because STAIRs applies.

How can Data Protection People help?

Need help reviewing your publication scheme or preparing your team for information requests? We can help you work through information rights and data protection questions.

Speak to our team about Information Rights Support.

Sources

Finding What’s Exposed With EASM

External Attack Surface Management, usually shortened to EASM, is the continuous discovery and monitoring of everything your organisation exposes to the internet, domains, subdomains, cloud services, servers and applications, including the ones nobody currently has on a list.

What “attack surface” actually means

Your external attack surface is every point an attacker could potentially reach from outside your network. That includes the systems your IT team knows about and manages deliberately, but it also includes things that accumulate without anyone fully tracking them, a test server spun up for a project and never decommissioned, a marketing microsite built by an agency years ago, a cloud storage bucket set up for a one-off task, a subdomain nobody remembers creating. None of these are necessarily malicious or even risky on their own, but each one is a potential entry point, and you can’t secure what you don’t know exists.

Why this differs from a pentest or a vulnerability scan

Penetration testing and vulnerability scanning both work against a defined, known scope, systems you’ve already identified and agreed to test. EASM works the other way round, it starts from the outside, mapping what’s actually visible on the internet under your organisation’s name, and works to identify assets you may not have deliberately included in any existing security process at all. It’s the discovery layer that should logically come before testing, since a pentest against a scope that’s missing half your real exposure only gives you confidence in the part you already knew about.

How EASM actually works

EASM tools and services continuously scan public sources, DNS records, certificate transparency logs, IP ranges and cloud provider metadata, to build and maintain a live map of everything associated with your organisation that’s reachable from outside. That map gets checked for common exposure issues, out of date software, exposed admin panels, misconfigured cloud storage, expired certificates and anything genuinely concerning gets flagged for investigation. Because it’s continuous rather than a one-off exercise, new exposure gets caught close to when it appears, not months later during the next scheduled review.

Why this has become more important

Organisations’ external footprints have grown substantially with the shift to cloud services, third-party tools and distributed teams who can spin up new infrastructure without necessarily going through a central IT process. That’s not a criticism of how modern organisations operate, it’s simply a consequence of how much easier it now is to stand up a new service, and it means the gap between what security teams officially track and what’s actually exposed has grown alongside it. EASM exists specifically to close that gap.

Questions organisations usually ask about EASM

How is this different from just asking IT for a list of our systems? An internally maintained list only ever reflects what was deliberately recorded, and in practice things get missed, a project ends, a subdomain stays live, a cloud account gets set up outside the usual process. EASM discovers assets independently of any internal list, which is exactly the point, it finds what the list doesn’t know about.

Is this a one-off exercise or does it need to run continuously? It works best as continuous monitoring rather than a single scan, since new external assets appear constantly as an organisation operates. A one-off discovery exercise gives you an accurate picture on the day it runs, but that picture starts going out of date almost immediately.

What happens once something unexpected is found? Typically the finding gets triaged, confirmed as genuinely belonging to your organisation, assessed for how exposed or risky it actually is, and then either brought under proper management or decommissioned if it’s no longer needed. Not everything found is a problem, some of it is simply forgotten infrastructure that just needs tidying up.

Do we need this if we already do regular penetration testing? The two work together rather than replacing each other. A pentest assesses depth against an agreed, known scope. EASM addresses breadth, finding what should be in scope in the first place. Testing against an incomplete scope only ever gives you confidence in the part you already knew about.

Is EASM right for your organisation

It’s particularly valuable for organisations of meaningful size or with a history of mergers, acquisitions, agency-built projects, or multiple teams independently provisioning their own infrastructure, all situations where an accurate, centrally held inventory of external assets is unlikely to exist without deliberate effort. Even smaller organisations benefit from an initial discovery exercise, since the honest answer to “do you know everything your organisation exposes to the internet” is very often no, and finding that out is the necessary first step before any other security work can be properly scoped.

If you want an accurate picture of what your organisation actually exposes to the outside world, our External Attack Surface Management service is built to find out.

Can Schools Use Generative AI Tools Under UK GDPR?

Generative AI tools like ChatGPT, Microsoft Copilot and Gemini can be used in schools under UK GDPR if used safely and effectively, with appropriate data protection policies in place.

To remain GDPR-compliant, schools should avoid using free versions of generative AI tools, as they may lack the necessary safety features. Instead, schools should use enterprise tools integrated into a broader workspace of educational tools, such as Copilot in Microsoft 365 or Gemini in Google Workspace.

What Data Risks Do Generative AI Tools Present in Schools?

Generative AI tools themselves don’t pose data protection risks; the risks depend on how they are used. These include:

  • Data Breaches – If staff members paste sensitive data into AI tools without notifying parents and pupils that their data will be used in this way, it may constitute a data breach.
  • GDPR Compliance Risks – Many AI tools are operated by US companies, so without data residency controls, personal data may be processed and stored outside the UK, creating GDPR compliance risks.
  • Intellectual Property – When a student completes a piece of work, the intellectual property belongs to them. Submitting this work to a free generative AI tool for feedback could result in the data being used to improve the AI’s systems, potentially raising issues regarding intellectual property rights and data protection compliance.

What Data Protection Policies Should Schools Follow When Using Generative AI Tools?

Consult a Data Protection Officer

Before using generative AI for any activity, schools should consult their appointed Data Protection Officer (DPO). A DPO can review the chosen AI tool(s), ensure that appropriate data policies are in place and advise staff on how to use them effectively.

Carry Out a DPIA

The ICO requires a Data Protection Impact Assessment (DPIA) before using AI in high-risk processing activities, including any use of AI involving children’s personal data. A DPIA should outline how the data is processed and its purpose, assess necessity and identify and mitigate risks.

Be Transparent About Data

Government advice recommends that personal data not be used in generative AI tools in educational settings.

If it is necessary for schools to use personal data in AI tools, they must:

  • Be open and transparent about how they are considering using automation and AI
  • Ensure that pupils, parents and guardians understand that their personal data is being processed using AI
  • Seek consent to use data within AI

Use The Right Tools

Government advice further recommends that staff members only use AI tools provided by their institution. This is likely to include:

  • Microsoft Copilot under a Microsoft 365 for Education licence
  • Gemini under a Google Workspace for Education licence

These paid tools keep data within a managed school environment, don’t use data to train public AI models and respect existing security and privacy controls.

Provide Data Protection Training to Staff

Data protection training can help staff understand UK GDPR compliance and what constitutes a data breach. Staff must understand what data should never be entered into AI tools and which AI platforms are approved for work use.

Ensure Your School Is GDPR Compliant with Data Protection People

Generative AI can transform education, but it must be balanced with the responsibility to protect personal data and meet GDPR requirements.

At Data Protection People, we have extensive experience working with the education sector and can help schools implement generative AI securely. From outsourced DPO services to ongoing data protection advice, we can ensure your use of AI is compliant. Contact us today to understand how we can support you.

How Penetration Testing Actually Works

Pentesting, short for penetration testing, is an authorised, simulated attack on your organisation’s systems, carried out by a security professional using the same techniques a real attacker would, to find exploitable vulnerabilities before someone with genuinely bad intentions does.

How pentesting differs from a vulnerability scan

These two are often confused but they’re not the same thing. A vulnerability scan is largely automated, it checks systems against a database of known issues and flags what it finds, quickly and at relatively low cost. A penetration test goes further, a skilled tester actively tries to exploit what they find, chains weaknesses together the way a real attacker would and looks for issues automated tools simply can’t identify, like flawed business logic or weaknesses that only appear when several small issues are combined. A scan tells you what might be wrong, a pentest tells you what’s actually exploitable.

The types of pentesting

Penetration testing covers several distinct areas, and which ones matter depends on your organisation’s systems. Network pentesting examines your internal or external network infrastructure for exploitable weaknesses. Web application testing looks specifically at custom-built websites and applications, often where the most organisation-specific vulnerabilities sit. Testing can also extend to wireless networks, cloud environments and even physical or social engineering scenarios, depending on scope. A good testing provider will help you scope the right combination for your actual risk, rather than defaulting to a generic package.

How a pentest actually runs

A typical engagement starts with agreeing scope, exactly which systems are in play and what’s explicitly out of bounds, since testing without clear boundaries carries real risk to live systems. The tester then works through reconnaissance, identifying the attack surface, active testing, attempting to exploit what they find, and reporting, a detailed account of what was found, how it was exploited, and how serious each issue actually is, not just a raw list of findings. The report should prioritise issues by real-world risk, so you know what needs fixing first.

Why pentesting matters beyond ticking a box

It’s tempting to treat pentesting as something done purely to satisfy a client requirement or an insurance condition, and it often is required for exactly those reasons. But the underlying value is real, independent, expert verification that the controls you believe are in place are actually working, tested the way a genuine attacker would test them rather than assumed to be effective because they were configured correctly on paper.

Questions organisations usually ask about pentesting

Will a pentest disrupt our live systems? Scope and timing are agreed in advance specifically to manage this, testing can be scheduled outside business hours, restricted to non-production environments where appropriate, and any potentially disruptive technique is discussed with you before it’s attempted, not sprung on you mid-test.

What’s the difference between a pentest and a red team exercise? A pentest works against an agreed, defined scope over a set time. A red team exercise is broader and more adversarial, simulating a real attacker’s full approach, often without your internal security team knowing it’s happening, to test detection and response as well as raw vulnerability. Most organisations start with pentesting and consider red teaming once their basics are already solid.

Do we need a pentest if we already run vulnerability scans regularly? Scanning and testing serve different purposes, and most well-run security programmes use both, scanning as a frequent, automated check, and pentesting periodically for the deeper, human-led assessment that a scan genuinely can’t replicate.

What happens after the report lands, do you help fix what’s found? A pentest report should give you enough detail to remediate the issues found, prioritised by real risk, and many providers offer follow-up retesting once fixes are in place to confirm the issue is genuinely closed, not just addressed on paper.

How often you should test

There’s no single universal answer, but common triggers include a set annual or biannual schedule, any significant change to your systems, a new application, a major infrastructure change, before a security-conscious client or partner requires evidence, and after any security incident, to confirm the underlying issue is genuinely resolved rather than just patched on the surface. Systems and threats both change continuously, so a test from two years ago tells you very little about your risk today.

If you want to know where your organisation’s systems would actually give way under real attack, our Penetration Testing service is built to find out properly.

S2 Ep32: GDPR Radio- Data Protection News Of The Week

S2 Ep32: GDPR Radio – Data Protection News of the Week

Caine Glancy and Amber Sivill discuss the latest developments affecting data protection professionals.

In this episode of the Data Protection Made Easy podcast, Caine and Amber examine several stories raising important questions about privacy, cyber security, artificial intelligence and accountability.

Their conversation covers proposed changes to UK data protection law, a cyber incident affecting airport customers, facial recognition technology, smart glasses, personal data breaches and online safety.

Could the UK Replace GDPR?

The episode begins with a discussion about reports that Reform UK wants to replace GDPR with a lighter-touch approach.

Caine and Amber consider whether data protection law genuinely prevents organisations from innovating. They also discuss what weaker enforcement and reduced individual rights could mean in practice.

Amber explains that GDPR is based on principles. This allows organisations to consider the purpose, necessity and risk involved in their processing.

“Whenever you look at anything within GDPR or data protection, it is always a matter of risk, what is proportionate to that risk and what is necessary.”

What Can Organisations Learn From the Airport Cyber Incident?

Caine and Amber discuss a reported cyber incident involving customer information collected through airport Wi-Fi registrations and car park bookings.

The conversation focuses on the volume of information affected, how connected systems can increase the impact of an incident and why organisations should only collect the personal data they genuinely need.

Amber also raises the importance of separating systems and databases. This is known as network segmentation, which means dividing a network into smaller sections to limit unauthorised access.

Should Retention Periods Be Based on Systems or Purposes?

The hosts explore whether organisations should assign retention periods to entire systems or connect them to individual processing purposes.

A single system may hold several types of personal data. Each type may be needed for a different reason and for a different length of time.

“Storage limitation is based on the purpose of processing and how long you require the information for that purpose.”

Amber explains that a more detailed approach can help organisations meet legal requirements and avoid retaining information for longer than necessary.

What Are the Risks of Automated Identity Checks?

The episode examines a case involving an eVisa identification problem which reportedly prevented a UK resident from boarding a return flight.

Caine and Amber consider the risks of relying on automated identity systems. These include inaccurate matches, a lack of effective human review and difficulties correcting errors.

They connect this discussion to the wider use of facial recognition by police forces and other organisations.

Smart Glasses, Facial Recognition and Covert Recording

Caine and Amber discuss smart glasses that can record people or use facial recognition technology.

Although this technology may support accessibility and language interpretation, it can also create privacy concerns when people do not know they are being recorded.

The hosts consider whether every function is necessary and whether useful features could operate without recording or identifying individuals.

Why Does Context Matter When Assessing a Data Breach?

The Metropolitan Police reportedly exposed the email addresses of people receiving updates about the investigation into Mohamed Al-Fayed.

An email address may appear low risk when viewed alone. However, the surrounding circumstances could reveal a connection to an investigation, witness group or affected individual.

“The context is ultimately so important with everything. It is a big decider when assessing risk.”

This example shows why organisations need clear breach-reporting processes. A proper assessment should consider who is affected, what the information may reveal and the possible consequences for those individuals.

Can Better Training Reduce Email-Related Breaches?

Caine and Amber discuss how simple email mistakes can lead to serious incidents, including using CC instead of BCC.

They explain that effective training should build awareness without making employees afraid to report mistakes or ask questions.

“If you do not know something, how do you know it is wrong?”

Staff need practical guidance, clear reporting routes and the confidence to raise concerns quickly.

Age Assurance and the Online Safety Debate

The episode closes with a discussion about age-assurance measures under the Online Safety Act.

Caine and Amber consider whether strict controls could push children towards less responsible websites. They also discuss the challenge of protecting children without creating systems that people simply try to bypass.

The discussion highlights the need for proportionate controls which protect users while recognising how people behave online.

Key Takeaways

  • Data protection law allows organisations to assess risk and act proportionately
  • Organisations should only collect personal data they genuinely need
  • Retention periods should reflect the purpose of processing
  • Automated identity systems need accuracy checks and effective human oversight
  • The context of a breach can make seemingly ordinary information highly sensitive
  • Training should help employees recognise and report mistakes without creating fear
  • New technologies need privacy safeguards from the beginning

Meet Your Hosts

Caine Glancy

Caine is the Data Protection Support Desk Manager at Data Protection People. He brings practical insight from supporting organisations with their everyday data protection responsibilities.

Amber Sivill

Amber joins Caine to examine the practical risks behind the latest data protection stories and explain what organisations should consider.

About the Data Protection Made Easy Podcast

The Data Protection Made Easy podcast turns complex privacy and data protection topics into clear, practical conversations.

GDPR Radio examines recent news, regulatory developments and emerging technology to help organisations understand what has happened and why it matters.

S2 Ep31: What Happens When Your DPO Is OOO?

S2 Ep31: What Happens When Your DPO Is OOO?

The hidden liability gap: what happens when your DPO leaves?

Your organisation’s data protection responsibilities do not pause when its Data Protection Officer is unavailable.

In this episode of the Data Protection Made Easy podcast, Caine Glancy and Gbenga Onojobi discuss how organisations can maintain accountability when their DPO is on annual leave, absent unexpectedly or has left the organisation.

The Latest Data Protection News

Before exploring the main topic, Caine and Gbenga discuss several recent stories from across data protection and technology.

  • The proposed use of live facial recognition at Scottish football matches
  • The importance of human review when automated systems identify people
  • Concerns about addictive features on social media platforms
  • Unauthorised access to patient records by a former NHS employee

The discussion highlights a recurring concern. Technology may support decision-making, but organisations still need appropriate oversight, accountability and safeguards.

Does Accountability Leave With the DPO?

A DPO may take annual leave, become unwell, resign or retire. An outsourced DPO arrangement may also come to an end. However, the organisation remains responsible for its data protection compliance.

“The DPO leaving or being out of office does not remove the organisation’s responsibility. Accountability does not leave with them.”

Gbenga compares the DPO to a navigator on a ship. The navigator advises on the route and watches for danger, but the captain and the organisation remain responsible for the journey.

Why Organisations Need a Continuity Plan

Organisations need to plan for temporary and permanent DPO absences. Staff should know who can provide advice, receive an escalation and take ownership of urgent work.

This is particularly important for matters with strict deadlines, including personal data breaches, subject access requests and other individual rights requests.

“Being able to have another trusted individual who helps you, whether that is upwards or downwards, is really quite vital.”

Policies and procedures should explain what happens when the usual DPO contact is unavailable. The plan may involve a deputy, trained managers, data champions or access to external data protection support.

Data Protection Is Not One Person’s Responsibility

Caine and Gbenga discuss the risks of allowing every data protection matter to sit with the DPO.

Senior leaders remain accountable. Managers and staff also need to understand how data protection applies to their work and when an issue must be escalated.

Training should reflect each person’s responsibilities. Board members, managers, data champions and frontline staff do not need identical training. They need practical knowledge that helps them recognise and manage the situations they may face.

Independence and Conflicts of Interest

When a DPO leaves, appointing the nearest senior employee may appear to solve the immediate problem. However, organisations must consider whether that person has the necessary expertise, time and independence.

A person should not be expected to make decisions about how personal data is used and then independently monitor their own decisions.

“Organisations should not solve a vacancy by creating an additional conflict. A rushed appointment may fill the box while leaving the organisation with a DPO who cannot properly perform the role.”

Protecting Time-Sensitive Work

A subject access request can arrive anywhere in an organisation. It may be sent to HR, reception, a manager or through social media. It may also be made verbally.

The individual does not need to use the words “subject access request” for the request to be valid. This means staff need to recognise a possible request and know where to send it, even when the DPO is unavailable.

Clear ownership and an appropriate quality assurance process can reduce the risk of missed deadlines, inappropriate disclosures or information being withheld incorrectly.

Questions to Ask Your Organisation

  • Who provides cover when the DPO is unavailable?
  • Do staff know where to send urgent data protection matters?
  • Who monitors subject access request and breach deadlines?
  • Are key decisions, risks and responsibilities properly recorded?
  • Does any temporary replacement have suitable expertise and independence?
  • Can the organisation access additional support when internal capacity is limited?

The Final Takeaway

“A DPO leaving an organisation should not create a compliance vacuum. The organisation itself remains accountable.”

Good continuity means recording important knowledge, clearly allocating responsibilities and making sure somebody suitable is ready to step in.

Meet Your Hosts

Caine Glancy

Caine is the Data Protection Support Desk Manager at Data Protection People. He brings practical insight from helping organisations manage everyday data protection questions, breaches and individual rights requests.

Gbenga Onojobi

Gbenga is a Data Protection Consultant at Data Protection People. He supports organisations with practical compliance, governance and data protection risk management.

Watch or Listen

📺 Watch on YouTube: https://youtu.be/hqokBvSh-Ho

🎧 Listen on Spotify: https://open.spotify.com/episode/7ukmE70eDsPsMYQG39O8kf

S2 Ep30: GDPR Radio – Data Protection News of the Week

S2 Ep30: GDPR Radio – Data Protection News of the Week

Practical discussion on the latest data protection news

In this episode of GDPR Radio, Caine Glancy and Catarina Santos discuss recent developments affecting data protection, workplace monitoring, media reporting and information security.

They explore the risks behind misleading headlines, AI systems that claim to detect employee emotion, smart glasses and a reported NHS data breach involving an unsecured pager network.

What This Episode Covers

  • A Court of Appeal decision on misleading headlines and the fair processing of personal data
  • Why images and headlines can shape public perception before people read the full story
  • AI emotion-detection tools and the risks of monitoring employees based on facial expressions, voice or body language
  • Why organisations must consider necessity, fairness, transparency and less intrusive alternatives before introducing workplace monitoring
  • Smart glasses, hidden recording and the need for clear acceptable-use policies
  • Lessons from a reported NHS pager network data breach
  • Why access controls, staff awareness and practical policies all matter

Key Discussion Points

“Someone who only saw the headlines and photographs together could just reasonably get the impression that actually it was Vince, the person that the article was referring to.”

The hosts discuss why data protection law can apply even where a full article clarifies the facts. The way a headline, image and article appear together can still affect whether personal data has been processed fairly.

“Could you not achieve the same objective with a completely less intrusive way?”

Caine and Catarina question the value of emotion-detection technology in the workplace. They explore why one-to-one conversations, objective work outputs and appropriate management may be more proportionate than analysing an employee’s voice, face or behaviour.

“Technical controls can only go so far, which is why the emphasis in the law is on technical and organisational measures.”

The episode also looks at why information governance needs to work in practice. Policies must reflect how an organisation operates, staff need to understand them and clear action needs to follow when rules are not followed.

Why This Episode Matters

Data protection risks do not always start with a major cyber incident. They can arise through misleading content, new workplace technology, weak access controls or policies that exist on paper but are not understood in practice.

This episode helps organisations consider where their own controls may need attention and why proportionate, people-focused

S2 Ep29: How AI Is Reshaping the DPO Role in 2026

S2 Ep29: How AI Is Reshaping the DPO Role in 2026

Data Protection Made Easy podcast with Caine Glancy and Amber Sivill

Artificial intelligence is changing how Data Protection Officers work.

AI tools can help with research, training, risk assessments and routine administration. However, they can also produce inaccurate advice, encourage confirmation bias and create new governance risks.

In this episode of the Data Protection Made Easy podcast, Caine Glancy and Amber Sivill discuss how AI is affecting DPO workloads and why professional knowledge and meaningful human oversight remain essential.

What Does This Episode Cover?

During the episode, Caine and Amber discuss:

  • The increase in AI-generated Subject Access Requests
  • How AI is affecting DPO workloads
  • The risks of using AI for data protection advice
  • How AI could support RoPAs, DPIAs and LIAs
  • The importance of checking AI-generated policies
  • Confirmation bias in AI responses
  • Why human oversight and professional knowledge still matter

How Is AI Affecting Subject Access Requests?

The discussion explored the growing number of Subject Access Requests, or SARs, that appear to have been generated using AI.

These requests can look formal and detailed. However, they may ask for information that does not fall within the normal scope of a SAR.

Amber explained:

“It also fuels a lot of misunderstanding. A lot of the time, you see a request and most of it does not even fall under the scope of what a SAR generally covers.”

Caine also shared that SAR-related cases handled through the DPP Support Desk have increased significantly.

AI may make it easier for people to create requests, complaints and follow-up correspondence. This can place additional pressure on data protection teams, particularly where requests are vague or based on incorrect information.

Can DPOs Rely on AI for Data Protection Advice?

AI can provide a useful starting point. However, it should not replace professional knowledge.

Amber explained:

“You need to have the base knowledge in order to be able to use these systems.”

An experienced practitioner may recognise when an AI response refers to the wrong legislation, misses important context or provides an answer that is too confident.

Someone with less experience may not spot those problems.

Data protection decisions are rarely black and white. The correct answer often depends on the organisation, the processing activity and the people who may be affected.

Could AI Support RoPAs, DPIAs and LIAs?

AI may help DPOs complete some routine or administrative tasks.

For example, it could help pre-populate a Record of Processing Activities, or RoPA, using information about an organisation’s activities and data sharing.

It may also provide a starting point for a Data Protection Impact Assessment, or DPIA, and a Legitimate Interests Assessment, or LIA.

However, organisations must consider what information they enter into an AI system. DPIAs and other assessments may contain sensitive or confidential information.

Amber said:

“There is a limit as to what you can provide the model with in terms of confidentiality and not oversharing any information.”

Any AI-generated assessment must be checked against the organisation’s actual processing, systems and risks.

Why Does Human Oversight Matter?

AI can produce clear and convincing answers even when those answers are incomplete or incorrect.

It may also agree with the direction of a prompt instead of challenging the user’s assumptions. This is known as confirmation bias, which means favouring information that supports an existing view.

Caine explained:

“It is a fantastic tool that will hopefully be able to help in the role as a DPO. But what matters is that you can supplement it with your pre-existing knowledge.”

Amber added:

“The human element needs to be someone overlooking it who actually knows what they are talking about.”

Human oversight must be meaningful. The person reviewing an AI output needs the knowledge and authority to identify problems, challenge the result and make the final decision.

Is an AI-Generated Policy Better Than No Policy?

An AI-generated policy is not useful simply because it exists.

A policy must reflect how the organisation actually works. It must be practical, accurate and followed by staff.

Amber explained:

“If you have a policy in place and it does not align with your business, it is not workable and people are not following it, then there is ultimately not really anything there in place anyway.”

AI may help structure a first draft. However, the final policy should be reviewed by someone who understands the organisation, its legal duties and its operational risks.

What Should DPOs Take Away?

AI can support DPOs, but it should not replace them.

Organisations should:

  • Use AI to support work rather than make final decisions
  • Check AI outputs against current law and ICO guidance
  • Avoid entering unnecessary personal or confidential information
  • Keep meaningful human oversight in place
  • Document how AI tools are approved, monitored and reviewed
  • Make sure policies and assessments reflect real business practices

The DPO role is becoming broader and more connected to technology, governance and organisational risk.

AI creates opportunities to work more efficiently. It also makes professional judgement, scepticism and accountability more important.

Meet Your Hosts

Caine Glancy

Caine is the Data Protection Support Desk Manager at Data Protection People. He works with organisations every day to help them understand and respond to practical data protection challenges.

Amber Sivill

Amber is a Data Protection Consultant at Data Protection People. She supports organisations with data protection compliance, governance and emerging technology risks.

Watch or Listen to the Episode

Watch the full episode on YouTube or listen on Spotify.

Watch on YouTube

Listen on Spotify

Need Support With AI Governance?

If your organisation is adopting AI, Data Protection Made Easy can help you understand the risks, strengthen governance and meet your data protection responsibilities.

Contact Our Team

Our Events & Webinars

Expert-led Discussions

We host events on a weekly basis for the community of data protection practitioners and have built up a network of over 1,700 subscribers. Members receive weekly invites, exclusive offers, early access to selected content, our monthly newsletter, and first access to in-person events. Check out our upcoming events and become part of our growing community.

View All
_GDPR Radio - Data Protection News of the Week
23 October 26 12:30 - 1:15 pm

S2 Ep40: GDPR Radio – Data Protection News of the Week

Why Most DPIAs Get Signed Off Too Late to Matter
16 October 26 12:30 - 1:15 pm

S2 Ep39:Why Most DPIAs Get Signed Off Too Late to Matter

Get Support With Data Protection And Cyber Security

Our mission is to make data protection and cyber security easy: easy to understand and easy to do. We do that through the mantra of benchmark, improve, maintain.